Webapp security: Different DB permissions for different requests

January 12th, 2008

When a GET hits your server, your RESTful webapp should not alter the database. Why not enforce this at the permissions level?

Read full entry »

Proper implementation of friend groups: Request for input

December 17th, 2007

In my quest to bring the features of Livejournal (and other proprietary social networks) to the open, public internet, I'm stuck on how to properly implements friend groups. Friend groups determine which users are allowed to see your more sensitive blog entries. I've pulled together a description of several alternative models, and I'd like some input.

Read full entry »

OpenID: A mechanism for locked blog posts? (Or: Free at last)

December 9th, 2007

People are getting pissed at SixApart for their stupid modifications to LiveJournal, apparently in the name of cracking down on child porn. (They're doing it wrong.) The problem is that people want to move away from LJ to a decentralized system (such as the way email and web hosting works), but blogging software does not yet generally support locked posts. (Locked posts are blog entries that only selected friends have permission to read.) I'm thinking that OpenID could help with this situation.

Sorry for the disjointed, skimpy post: I just want to get these ideas out there for discussion.

Read full entry »

Germ Theory and the Five-Second Rule

October 16th, 2007

The five-second rule surely owes its existence to the popularization of germ theory. People who abide by the rule must believe (at some level) that pathogenic microbes are tiny little beasties crawling about on the ground, with nothing better to do than to clamber onto dropped potato chips.

Read full entry »

Brain dropping: Kinetic energy is a type of potential energy

October 10th, 2007

In Chemistry class today we talked about forms of energy. I've always been a little irked by the notion that there are two main forms of energy, kinetic and potential, but it's never been annoying enough to grab my focus. Today, however, I formed a definition of kinetic energy that puts it squarely within the realm of potential energy.

Read full entry »