Activity Stream

  • One SSH Key to rule them all

    I have searched high and low for a better way to use SSH key based authentication than what you learn in the default Linux tutorials. Those tutorials would have you generate one key per-machine/account and then on every box you SSH into add that to the authorized_keys file.

    What I want is a single key (that’s easy to rotate) that I can use on any machine quickly and easily to get up and running. This is because I reformat my computers a couple times a year and set them up fresh, and because I use all 3 major platforms for coding.

    When you search for single key ssh authentication, the most common set of results tells you to use a Yubikey. So I finally gave in, bought a couple Yubikeys to see what all the fuss was about in the DevOps community. I did manage to work through all the tutorials about how to use a YubiKey as a kind of secure single sign on where the YubiKey is your one true universal key for SSH login. After hours and hours of setting up special daemons for forwarding SSH authentication to PGP, I’ve come to the following conclusion: YubiKeys suck.

    They suffer from the same problems that all PGP and SSL encryption suffers from. Archaic tools with WAY too many options, no explanation for what any of the options do, and absolutely NO guidance around if flipping a particular set of switches makes you more or less secure.

    There is a better way and I’m here to tell you about it today. The answer my friends, is Krypton.

    Krypton is a phone app for iOS and Android that implements the U2F protocol and in general is a more sane approach to using a physical second factor (your phone) across all of the platforms I use: Mac, Linux and Windows1.

    There are two modes:

    1. General Web 2FA using U2F
    2. Developer Mode which allows you to use Krypton for your SSH authentication and as a bonus it handles automatic signing of Git commits if you want it to

    For the first mode, you just add the Krypton plugin to your browser of choice and then Pair your phone to that specific browser using a QR code similar to how WhatsApp desktop works. After that you can use Krypton anywhere U2F is supported2

    For Developer Mode: Install the kr daemon/tool and the rest is easy peasy. You type kr pair into a Terminal and a QR code appears in the console. Scan this with the Krypton app on your phone and you’re all set. The kr tool takes care of setting up the SSH daemon as well as the github signing if you’d like. You still need to add an entry into authorized_keys on every computer you’re going to be using for SSH authentication, but this time… magically… it’s the SAME key on every computer you pair Krypton with without having to manually move things around, figure out where to securely store the key (it’s in secure storage on your phone).

    To get your SSH public key just type kr me and voila!

    Krypton is focused on security and as such the default settings ask you to confirm your login every time on your phone. I found that a little annoying especially when running Terraform jobs (more on this later) but luckily they allow you to customize your paranoia level per-host right from the app. I do still have it ask me every 3 hours or so to confirm, but after that it doesn’t bother me with additional prompts.

    This is the first post in a series of posts about my home lab where I develop/prototype my applications. The next installment of this series is going to be how to use Terraform at home with your own setup that’s not a cloud provider.

    Footnotes

    1. Because of the SSL library Krypton uses it doesn’t place nicely with Windows out of the box. It works perfectly though with the Windows Subsystem for Linux (WSL) and so I use WSL for doing all my git and ssh work on Windows and have had zero problems.
    2. Not all platforms that support U2F seem to work. I use Firefox because I care about speed and privacy and while generally Krypton works just fine with sites like Gandi – I have had trouble getting it to be recognized by Google and I have no idea why. Yubikeys work fine on Google *shrug*
  • Year of Focus

    I like listening to Cortex because they are thoughtful about how they do work and they always give me something to consider. They recently had a discussion about how New Years Resolutions are terrible and instead you should have themes for the year.

    In the past I’ve been convinced that Goals are a really crappy way to do things. You set a goal, and are immediately in a mode of failure because you haven’t achieved it. Then you hit the goal and feel great for a little while, but a day or two later have to set another goal and be a failure again. It seems like you’re failing to meet your goals for much longer than you’re succeeding at them. While Goals may seem like a good way to ensure you have a growth mindset, in practice I think they have the opposite effect. Once you’ve reached a goal, you stop doing the thing you were doing that allowed you to achieve it (I did it! I ran a marathon, I can stop running now!)

    Themes are better, these are a process not an outcomes. My theme for 2018 is the Year of Focus. With a theme I have a framework for making decisions that affects every choice I make. There’s no “Drink less” goal, instead I’ve cut back on alcohol consumption because hangovers are anti-focus. I’ve started trying to schedule out my days a little more so I can have long blocks of uninterrupted time to really get into flow, and I’ve tried to cut out other sources of distraction in my life.

    Before I decided on the theme for 2018, in mid-late November I blocked Facebook and Twitter on all my devices. I did this after watching this video which made me realize that I would not really be missing out on much https://www.youtube.com/watch?v=3E7hkPZ-HTk and I might get back a few things I had lost – some time, ability to focus, and happiness.

    The first week felt weird, I didn’t know how to get news anymore. When I felt bored, my instinct was to type Facebook or Twitter into the URL bar (and then have it blocked by some software). It forced me to think of other things to do and other ways I could be spending my time, including ways of actually seeing my friends in real life.

    It worked though, I felt better, less distracted. It was amazing to me however that 6 weeks later the muscle memory of typing Facebook into a browser had not gone away and I was still doing it even though I had not been on the service for a long time.

    Within 3 days Facebook realized something was up and started sending me click-bait emails “So and so commented on something”, “Someone has posted for the first time in a long time”. After 3 weeks, they started texting me! It was like an ex who drunk dials you.

    As I type this I’ve begun the process of downloading all my Facebook data (photos, posts, etc.) and after that’s complete I think I’ll be removing my account permanently next week.

    If you’re thinking about doing the same, I’d say that Apple News is a great platform for getting news if you don’t want to hop from site to site.

    * My archive just completed, 96Mb for all of my Facebook activity including Photos over the last 10 years

  • Stock Options

    A colleague of mine today sent me this link from Hackernews that explains options ownership.  I think it’s great! More people need to understand this stuff, and I’m very happy this is out there.  It does remind me however of how complicated everything has gotten and that always makes me ask why?

    My colleague had a great observation:

    I used to grant people options and I thought I understood most of it, but it seems like in an effort to get billion dollar valuations later stage companies have added all sorts of complicated conditions

    When I was younger (so much younger than today) – I used to think that complexity was a sign of how smart everyone was, and I had a bit of imposter syndrome thinking I was not smart enough to be in the real world because I didn’t understand all of this stuff.

    Now that I am older (perhaps wiser? tbd) I now am more confident in my intelligence and what I see instead is people hiding in complexity.. specifically in levels of abstraction.  Dan Ariely did a test that I think is illustrative if not conclusive. He put 6 – $1 bills on a plate in a shared fridge in a college dorm. A week later he came back and they were all still there.  He then put 6 cokes in the fridge and a few hours later they were all gone! No one would steal money (that would be wrong!), but move the level of abstraction up 1 level (a coke = $1), and people suddenly have fewer issues taking the cokes. 

    I see the same thing in finance. People trade all these derivatives, each one of which is another layer of abstraction away from money. Options are a layer of abstraction above shares (they abstract time), while shares are an abstraction over ownership, which is an abstraction over assets, which is an abstraction over money which is itself an abstraction. It’s a long way between that awesome trade you made and the person paying real money for their mortgage whom you just screwed over.  It enables them to do some shady things they would never do to a real person (they would never go into a real person’s wallet and take their money physically).  

    I see the same with private companies and stock, stock options, etc.  I think people just assume they are not smart enough to understand, they just hear stories that stock is what you want, that’s how you get rich! But I agree with my colleague above, people are using levels of abstraction to confuse people so they can play games.

    Once upon a time a stock would pay dividends because as a partial owner in a company you were entitled to a partial share of the profits. That dividend was that share of the profit! You could then turn around and use that dividend to buy more shares, and then the next time it was paid you’d get even more money!  This is essentially the proof Benjamin Graham used to show that stocks would outstrip bonds back in The Intelligent Investor and kicked off the era of value investing where calculating the price a company should be trading at was based on the profitability of the company and the number of shares outstanding.  Until the 1980s.. where you can blame Microsoft for coming up with the idea of “growth” companies that don’t pay dividends but instead pay back their shareholders with the growth of the value of the share price. Where it’s worth more because more people want it? <– This is some people’s definition of value, but I can’t use that to make a prediction about what the share price should be and so to me this is useless 

  • Minimum Viable Process

    The following are a set of thoughts I’ve had watching a company grow from 60 people to 600 people – it’s not a complete thesis, but I wanted to put it out there to start getting feedback from people.

    Thoughts on Organizations

    Processes are sets of rules in the same way that computer programs are just sets of rules.  In the case of programs, it’s the computer doing the work of executing the rules of the program and they have no choice but to take what you wrote literally.  In the case of processes, it’s people executing them.  However, both have bugs – unexpected outcomes of the rules.  With humans, you get some leeway because you can explain what you meant or you can say we’re implementing the ‘intent’ rather than what’s actually written but you will run into people who execute policies like they are computer programs and follow exactly what’s written, as opposed to what is intended.

    Making matters worse, policies often have very long feedback loops before the bugs are detected and can be addressed. As such I think we should try and avoid process until absolutely necessary. Too many people want to rush to create a process every time someone makes a mistake so that mistake can never happen again, without regard for the bugs that can be introduced as a result.

    Trust, Talent and Communication vs Rules

    Why create rules at all? I think this is the same as asking why society has laws and I think the reason is because you can’t trust people to do the right thing.  More specifically, there’s a limit to the number of people whose reputation you can keep in your head at any one time.  This limit is called the Dunbar number, named after the social scientist who studied why tribes separate into two tribes.  He found that after about ~120 relationships, we can no longer keep track of who owes whom money, who is trust worthy, who likes to short change people, etc.  Rules are an abstraction over behavior.  If we all agree to follow the rules, we can use them as a short cut for knowing someone’s reputation.  The reason I can go to the store and buy a bacon, egg and cheese from a complete stranger is because I have trust in the rules for proper food storage and preparation.

    I think that organizations that are growing don’t need any policies until they reach this 120 size. After that we start seeing faces around the office that we don’t recognize, and we hear about projects starting up being lead by people we have never heard of. People who’s reputations we don’t know/trust.

    Minimum Viable Process

    So what do we do? Policies (and laws) are really useful abstractions. They allow us to trust each other without actually knowing the individual’s reputation the same way I trust the food cart guy is not going to poison me because of the FDA. However, policies like all rules – have bugs.

    The #1 predictor of bugs in code is the number of lines of code.  Each line is a little rule, and the more rules you have the more likely you are to introduce bugs.  Since policies are rules that often contain more rules (the entire workflow is a set of rules to follow), the more policies you have (or the more complicated they are) the more likely they are to introduce bugs, and so the goal is to have the smallest set of effective policies possible.

    How do you accomplish this?

    Developers find bugs by compiling and executing their code, thus seeing that it does not do quite what they expected.  It’s a tight feedback loop that allows them to identify and resolve bugs quickly. What we need from policies is a similar feedback loop and the easiest way to do that is with this 1 weird trick.

    Make people feel the consequences of their decisions.

    That’s it.  Ok maybe the golden rule is nice too, do unto others as you would have them do to you is probably always a good rule.

    What does this mean?  It means one can never make a rule for someone else, that they themselves don’t have to follow.  The reason is so they can get immediate feedback on both the good and the bad of the rule and make adjustments accordingly. This is remarkably difficult in practice.  People really really don’t like feeling the pain of their decisions, and we set up all sorts of elaborate systems to protect ourselves from get that feedback.  I don’t think anyone making other people’s lives hell on purpose, we do this almost subconsciously.

  • The other 95%

    Paul Grahm has decided to take up the old torch of more H1B immigration because “there are not enough great programmers”.  In the second paragraph he says that people who disagree with him are “anti-immigration” people who don’t understand the difference between good and great programmers.

    I’m all for completely open immigration; let people who want to work do so wherever they’d like. However, I am tired of hearing this false rationale that “it’s because there are not enough good programmers”. All I’m asking is for people who make this argument, not to base it on provably false accusations/assumptions. Make an economic argument for completely open borders. Talk about lifting the employer restrictions for H1B… but when you do it the way Paul has done, it’s completely transparent that what you want is NOT that.. what you want are cheaper programmers who can’t leave your company when you abuse them, or find a higher paying job elsewhere. You want indentured servants, and it’s unethical and gross to me.

    Is it really too much to ask that people base their opinions on evidence (data rather than anecdote)?  The problem is the evidence doesn’t support the “not enough great programmers” claim:

    A great meta-analysis type article that looks at several studies with links to each and a description of the pros and cons of the data: http://spectrum.ieee.org/at-work/education/the-stem-crisis-is-a-myth

    The most recent raw data I’ve seen on the subject: http://www.epi.org/publication/bp359-guestworkers-high-skill-labor-market-analysis/

    But while we’re talking about immigration, I’ve always wondered why it’s so important that the developers be great?  What about great business people?  Where’s the call for H1B CEOs?  Why is the onus of failed startups that they couldn’t get enough *great* developers, as opposed to the mediocre business idea that failed in the market?

    Why do I never hear this argument for immigration?  Why is it only STEM?  

    And why does this myth persist in the face of evidence?

    Eric Sink is disturbed by the tone of people’s reaction but I think it’s perfectly reasonable for people to be upset when someone starts off accusing anyone who disagrees with him as being anti-immigration, or questioning their knowledge.

  • Business Models

    I saw this tweet today

    New startup concept:

    1. Make something of value
    2. Charge money for it
    3. Spend less than you make

    I call it “business”. Thoughts?

    — https://twitter.com/awilkinson/status/517393404888875008

    I’ve been confused for a long time about why this isn’t how modern startups are run.   This is the exact model I had in my head in 2001 when I wanted to start my own business, and for every startup idea I’ve had. However, I’ve seen so many multi-billion dollar valuations of companies that essentially have no revenue that I’m starting to wonder…

    Is this a class thing? 

    I’ve gotten to know a few rich people in NY, and I can tell you that none of them thinks this way. I can’t tell if they’re rich because they see the world differently from other people (I sure see the world differently than my parents and have a lot more money) or are these people crazy and excited about no revenue business models because they don’t have to worry about making money?

    It is difficult for me to maintain my view of the world (businesses should make money) with the data I’m getting about 0 revenue businesses being valued in the billions.  I’ve heard it put this way: Having zero revenue is great because it allows you to sell the dream of, when we monazite, just imagine how much money we’ll make. Where as having a single dollar of revenue changes the conversation to why do you only have $1? And then the dream is *poof* gone when it’s confronted by actual data” (mostly I’ve heard this from Felix Salmon) This makes me think that it’s about duping people and not about creating value at all. :-/

    Thoughts?

    • Why Here?

      This winter in NYC was particularly long.  I am SOOO happy that it’s finally summer.  But season of polar vortex after polar vortex combined to make me really quite depressed, and I started wondering… why are we here?  Specifically I mean, why are we coding physically in NYC?

      It’s crazy expensive, the weather in the winter sucks, it can be crowded and smelly.  Given that we can code from anyplace we’d like that has power and internet access I understand a bit why silicon valley happened in California.  Who wouldn’t choose nice weather?

      Well it seems like a few others in the NY community have had the same exact though (even the same exact location I was contemplating) :

      http://www.hackerparadise.org/

      Sounds like a blast, but even though I’m a freelancer I am at the whim of my current largest client who wants me to basically be a full time employee, on location and all.  The reality is that even though we technically can work remotely, there’s plusses and minuses to all of it and the powers that be have decided that it’s in the best interest of any particular company to make sure everyone is in the same place at approximately the same time.

      I’ve never worked for a company that let you work remotely the majority of the time, but it would sure be nice to be able to set my own schedule and location… at least for a few months… in beautiful Costa Rica!

    • Phone Screens

      The most recent trend in interviewing developer candidates is the normal phone screen, but with a live window in which you can type and the interviewer can see what you’ve typed. Something as simple as Skype with a chat window open, or a more complex website like collabedit which gives nice syntax highlighting and auto-indentation, etc. (but not VIM key bindings, grr). I’ve noticed with this new method the questions are more difficult, closer to standard whiteboard questions than standard phone screen questions where you do not share a code editor. I’ve also noticed with this new method that I’m suddenly doing much worse on interviews than when they were phone only and/or in person on a whiteboard but I think I’ve finally figured out why.

      Human behavior is complex and determined by lots of factors. All kinds of things can bias your decision making and your performance on tasks like this. I think the specific bug that’s being triggered is something called priming

      Priming is when something (usually unnoticed) in your environment changes your perception and thus your behavior.  When psychologists were testing to see if irrelevant details affected our behavior, it turned out they do.  The most famous example is that people who are holding hot cups (coffee) have a more favorable opinion of an interview candidate (hey, maybe  should ask my phone screeners to grab a cup of coffee before we begin ;)) as compared to those who had no beverage.  The exact opposite happens when people are holding cold beverages, they have a more negative view of a candidate.

      I think the fact that I’m sitting in front of a computer with a text editor open is affecting the way I think about problems.  I type very quickly, and normally when I have my editor up I already know how to solve the problem I’m attempting to solve because I’ve already white boarded it with a colleague.  Basically my instinct in this environment is to code, not think (if that makes sense), and this is hurting me.  When I’m at a whiteboard, I know that hand writing out the code is going to be slow and so I want to make sure that what I’m going to be writing out is already the near optimal solution before I start writing. This isn’t the case with the text editor open, my unconscious instinct is to start coding something that works quickly, and optimize later. 

      Hopefully now that I recognize what’s happening, I’ll be able to override my unconscious instincts and behave more like I’m in front of a white board, because I don’t think my request to not code live will go over so well 😉

    • Perka recruiting

      Every now and then I receive emails from various recruiters trying to find technology people for their company.  I was surprised when I came to New York that there were head hunters, and that they were looking for tech people.  I had heard of executive head hunters, but as far as I can tell there’s not really a head hunting/recruiting market on the west coast.  But the second I started working in NYC, the calls from LinkedIn started pouring in.

      Most of these recruiters are terrible, and know nothing about the technology they’re for which they’re recruiting.  In general, anecdotally I’ve seen that most founders of startups in NYC are not technical but rather sales/marketing people in Publishing, Marketing, or Fashion.  

      Anyway, I’m at the point in my career where I’m interviewing companies just as much as they’re interviewing me so I like to send back to these blanket emails some questions of my own.

      Here’s the most recent letter I received from Perka

      Hi Jim,

      I am reaching out because our engineering team is very interested in your engineering background. We are currently looking for Sr. Java Engineers to work with our Sr. team in building new frameworks, improving our architecture with sophistication and advancement and mentoring our engineers with projects. I would like to know if you would be open to a chat about Perka – I’ve included some info below. We are also looking for mid-level Java, Android, Software Developer in Test and JavaScript Engineers.

      Perka is on it’s way to conquering one of those categories yet to be conquered – Loyalty.Here is some info about us to give you an idea of where we are headed and why…

      Our current Engineering team scaled from 5 at acquisition to currently 13 and we will be adding 10 Engineers to support our Platform/Architecture, build new frameworks and tools, Mobile Products and Merchant web products. We are a relatively flat organization and this position reports directly into our CTO/Co-founder as well as work along side him and our other Sr. Engineers all like yourself with impressive backgrounds. This is a very smart team and we need to add to our talent in helping us deliver the world’s mobile loyalty brand and keeping up with the brand and trust as we grow.

      About Us

      Perka is a customer loyalty platform started in 2011. Our mobile and web apps have made millions of days a little brighter in free coffees, yoga classes, ice cream cones, and thousands of other ways of saying thanks.

      In October 2013, we were acquired by First Data — one of the world’s largest payment processors — as an independent subsidiary. That gives us access to enormous resources and infrastructure, while retaining our startup culture and values.

      Now we’re deploying our product at a scale that we could previously have only dreamt of. We’re building a team of inspired problem-solvers who want to help us reimagine the way that people all over the world interact with their favorite shops and restaurants. Join us.

      What we offer
      A clear product direction with a solid growth plan and balance and the extraordinary opportunity to work under the direction of very successful co-founders
      Really really really good company culture-you’ll be saying it’s your favorite place to work too!
      We open source and big fans of community development and events.
      Competitive salary according to market and experience
      Unique annual cash bonus program
      Full benefits (health, dental and vision)
      Life insurance coverage
      Flexible spending account options
      Generous PTO and paid holidays
      Super duper MacBook Pros and 27” thunderbolts
      Plenty of snacks for you and your super smart teammates along with super fun tees and great swag!
      In August 2014, we are expecting our swanky new loft build out in SoHo to be complete with yes a ping pong table!

      — Email from recruiter

      And here was my response questions

      Hello,

      Thanks for getting in touch. A few questions:

      You say your engineers have impressive backgrounds, but you don’t mention what they are. Can you elaborate?
      How big is the loyalty program market place and what percentage does your company have?
      What is the most pressing technological challenge your company currently faces?
      What is the most pressing business challenge that’s preventing you from having explosive growth?
      Would you describe your company as primarily technology driven (ideas for new products and services come from the engineering team who also implements them once vetted for soundness by the business) or sales and marketing driven (engineers are told what to do by the business)?
      When you have an idea for a new product or service, how do you test the idea in the marketplace?
      What does your technology stack look like today? What does it look like 5 years from now?

      Thanks,
      Jim

      It’s been a couple days and I haven’t heard anything, which makes me think they have little interest in an engineer who cares about the business and how it’s run but are rather just looking for someone who will do what they’re told. After all they’re the geniuses with all the brilliant ideas, and you’re just some code monkey who should be GRATEFUL for the OPPORTUNITY to be paid in fake money (shares/options) for working on such a great idea!  Know your place engineers, you’re the blue collar workers of the information economy and they’re the smart management.

      I’m being a bit hyperbolic here, but I don’t think I’m too far off the mark based on conversations and general discourse with ‘idea guys’ in NYC. I can’t help but feel that computer programming is definitely seen as a second class citizen (if only subconsciously).

    • Africa has better tech than NYC

      One of the most surprising things to me when moving to NYC was how often I would NEED CASH.  It seems, anecdotally, that most restaurants and bars in the village are CASH ONLY (also most cabs prefer you pay in cash, and can be real dicks if you try to pay with a card even though legally required to accept them)

      Personally I would rather not carry cash for security reasons, as well as convenience reasons and it seems like the rest of the world is headed in that direction (I remember when it was a big deal that McDonald’s started accepting credit cards).

      The other day I heard a story on Marketplace about how no one in Africa uses cash anymore, instead they all do mobile to mobile payments.

      NYC has always seemed a little techno-phobic to me (also obsessed with OLD things: antiques, old apartments, etc.) and I think this explains why many businesses here don’t accept mobile (or even credit card) payments just as much as the additional overhead cost (not to mention that you can better hide cash transactions from the tax man)

      But now I’m just embarrassed that Africa seems to have better payment and p2p transfer technology than NYC in the country that invented the mobile phone.