RSSAmplifier

Blog

tommorris.org

Recent content on tommorris.org

tommorris.orgRSS feed ↗43 posts

Latest posts

The invisible dragon discovered magical security vulnerabilities but they go to another school

Hey, at least being haunted by demons was metal AF.

European court lawsplains trade marks to Sam Altman

Court reckons ‘open’ means… something.

Impedance mismatch at the University of Chicago

The new chapter of thinking starts somewhere else on campus.

A trip report into agentic coding

A personal exploration of herding code-generating robots

Turn it off and run - upskilling for the AI age

The government have made a website where you can learn how you were prompting it wrong.

Irrelevant is better than fake: testing a legal AI tool

Professional AI tool is marginally better than consumer AI tool. That’s not saying much, sadly.

What does the government think an algorithm is?

Please do not click on any tags or links. They may or may not be illegal content recommendations.

TIL: track changes in Emacs with highlight-changes-mode

Getting Emacs to tell me what I haven’t yet made worse.

The adolescents are alright. So are the common people. Let’s make tech good for them.

Some meandering British socio-technical vibe checking, with reference to Adolescence, Black Mirror, Roblox and Balatro.

Beware government ministers hyping technologies

My dotfiles are actually an explosion of disruptive radical technical innovation, I’ll have you know.

Copyright anti-circumvention: an AI hypothetical

Does anti-circumvention law offer a route to legally challenging unwanted LLM web scraping?

Testing the Firefox alternatives

Let’s try LibreWolf, Floorp and Zen until Mozilla decides they want to make a browser again

A world run by tools

Computering is a series of bad life choices: here are mine.

TIL: Wikidata SPARQL trick - getting item and subclasses

Zigzag your way through the hundred million item graph with this one neat trick etc.

TIL: Setting default browser on macOS using Nix

Switch your browser around, declaratively.

Lies, damn lies, and business cases for AI hype

Wherein we learn that people who are sold on a technology are sold on a technology, and that’s about it

TIL: Using nix run to lint one-off Python scripts

Linting and autoformatting crappy little scripts as if they were proper software

Staying cool with OpenStreetMap

Choose an OSM tag, make it cool

A little Nix fix

A meandering wander around the scary magical future of package management.

TIL: Monorepo Makefile inheritance with shared variables and targets

Mingled Makefiles for a multirepo milieu.

TIL: Emacs Lisp - write a string to a file

Put some Hello World in a file.

TIL: Encode and decode text in Emacs Lisp

A short guide to string encoding in elisp.

Today I Learned: Background

Brief notes on the matter of sharing brief notes about the inner guts of technology.

Writing better API documentation: a few lessons from enterprise integration

Over many years working on API integrations, I’ve seen a whole lot of ways that the experience could be less frustrating. This isn’t a definitive list but a personal collection of a few recurring problems with documentation I’ve seen in different REST APIs that could be avoided. Explain what a field does Consider API documentation like this: String[] tags - “This field…

Possible vulnerability in Sainsbury's and Nectar website

In February, I discovered a potential vulnerability in the Sainsbury’s and Nectar website. Sainsbury’s is one of the UK’s main supermarkets, and Nectar is the loyalty card programme they own in partnership with a bunch of other retail brands like Argos, Esso and British Airways. The vulnerability is not that exciting and I have no way to know whether it is possible to misuse it…

iTerm2 URL matching is pretty neat

For many years, other developers told me about iTerm2 and I ignored them. I really shouldn’t have. The stock macOS Terminal was fine, I thought. What a mistake. There’s lots to love about iTerm2, including the ability to script it in Python. But a really amazing quick win is the support for Triggers. Triggers allow you to set a regular expression that gets acted on every time they…

Too sarcastic for the Twitter joke police: an adventure in automated moderation

For the first time in almost fifteen years, my Twitter acount got suspended. Here’s the backstory: my friend Dom and his wife Heather decided to put on a surprise “lockdown holiday” for their lovely daughter Scarlett. They put photos up of it as a Twitter thread. As with a lot of the weirder things Dom gets up to, it ended up getting press coverage on the BBC News website. And…

Never trust a Time Machine made by a computer company

A fun discovery: if you have two Macs, one running Catalina and the other running Big Sur, you may struggle to back up the Big Sur machine to a network share on the Catalina machine because Catalina formats Time Machine volumes as HFS+ and Big Sur expects Time Machine network shares to be APFS. Catalina can write HFS+ Time Machine backups to an APFS volume, but not vice versa. The only reason I…

Using AST parsing for deriving IAM rules

A nostalgic prelude Anyone remember building web apps in the old days? Write a PHP script, FTP it up to a server, hit refresh. No having to juggle React, npm, RubyGems, version locking, incompatible versions of Python or Ruby or Java or whatever. No Ansible, no Chef or Puppet, or Docker containers, or Terraform, or Kubernetes. If you came from that world, when Amazon launched AWS back in 2006, the…

That's not what the law says: the coronavirus regulations

It should be fairly apparent to anyone who has lived through the Brexit referendum that the attention spans of both politicians and journalists in the UK is quite limited even at the best of times. The UK’s handling of the legalities of the COVID-19 crisis shows this in spades. What are the rules? For England, the rules are set out in The Health Protection (Coronavirus, Restriction)…

Hart contracts, not smart contracts

I was recently re-reading H.L.A. Hart’s “Positivism and the Separation of Law and Morality”, the opening salvo in the never-ending, intergenerational Hart-Fuller debate, and his description of the “core and penumbra” approach to reasoning about rules is a perfect illumination of the error behind so-called smart contracts, blockchain-based self-enforcing…

The NHS Data Commandments and the memory hole

Back in 2018, the British government published a document on the World Wide Web. This happens fairly often. In fact, they have a whole publishing platform for this. I started writing a post critiquing this document, as I felt it was a poorly considered idea. Before I got around to publishing it, the document disappeared from the Internet. Life went on. I was busy, and there are always many more…

Essential reading on the MIT Media Lab

The revelation in the last week or so that convicted paedophile Jeffrey Epstein had financial connections with MIT’s Media Lab has led to the lab director, Joi Ito, to resign. The Media Lab is certainly not the only connection between Epstein and academia: his links with, and funding of, various top scientists have been known for a while, and are quite extensive. I should note in passing that the…

Making QR codes with cloud functions

In a blog post I almost missed earlier this year, Jeremy Keith points to an interesting use case for print stylesheets, namely putting QR codes on the printed versions of, well, just about anything on the web. Jeremy rightly lamented Google’s deprecation of the Charts API. The existing Charts API is a simple service that lets you throw data at a URL and it renders it server-side into an…

Apple ID's two-factor and app-specific passwords leave a lot to be desired

Apple’s two-factor authentication and app-specific password implementation is bad. Let’s have a little tour. How it works The general idea behind Apple’s 2FA is sound if not perfect: instead of giving every crappy mail and calendar app you use your main password, you give it an app-specific password. To do this, you need to have two-factor authentication turned on. Apple’s…

Facebook Instant Articles: why hiding URLs hinders careful reading of media

Today, I saw a story doing the rounds on Facebook about a group of pro-Brexit buffoons attempting to block an Aldi supermarket warehouse as a protest against Britain’s failure to depart from the EU. Which is all very amusing and everything, but I was immediately a little sceptical (as you should be if you read a news article on Facebook that tickles that bit of your brain that makes you go…

Instamuseums and the Tyranny of Engagement Metrics

Pop-up “Instamuseums” are a thing, according to this video from Vox and this article by Sophie Haigney in The New Yorker: people will queue around the block and pay $40 for the privilege of taking photos of themselves alongside works of installation art specifically designed for social sharing at places like the Museum of Ice Cream in New York. I’ll spare you extensive thoughts on influencer…

Quietism

Techne If you are reading this, I have a new personal site. My previous site was down for a very long time: initially, the server had gone down because log files had grown too large and I hadn’t set up a proper log rotation system that discarded the old log files. Then I tried to upgrade the server, because the OS was massively out-of-date (thus opening up possible security vulnerabilities),…

Hello World

Greetings humans.

Open plan offices are basically terrible in every way

There’s a growing consensus in the scientific literature that open plan offices damage the mental and physical health of employees, destroy their morale and generally make their work lives less pleasant. Let us first look at some studies. Evans and Johnson, 2000: Forty female clerical workers were randomly assigned to a control condition or to 3-hr exposure to low-intensity noise designed to…

Why primary identity documents matter (and why the DVLA is incompetent at it)

I’ve been grumbling on Twitter about the DVLA. A long time ago, I applied for and received a provisional driving license with the intention to learn to drive. That provisional driving license expired (I had other things to do besides take driving lessons), so I renewed it recently. The license I had included a number of errors. Firstly, it had the wrong date of birth and it also had the wrong…

On showing URLs and why security and usability will always have a rocky relationship

Jeremy and Jake are debating the merits of Chrome’s plan to hide away the path segment of the URL. I have only a few things to say: If Firefox starts hiding the path of the URL I’m looking at, I’ll find whatever extension, plugin, haxie or user script I need to make it stop. It’s bad enough that it hides the protocol from me. I want to see what page I’m on.

How to quit vim's easy mode (vim -y)

[Ctrl]-L gets you back into normal mode, then you can :q! or whatever as usual. Just posting it here so that Google and future generations of frustrated Vim users can find it. I learned about vim -y today, and it is actually a pretty neat thing if you want to be able to basically give a Vim input to a newbie. Of course, GVim or MacVim (for Windows/Linux and Mac respectively), or indeed Cream, may…