Skip to main content

Posts

Rent-free Thoughts

Some thoughts that have been living rent-free recently in my head about AI... We should be more precise when we talk about it. We’ve had "AI" for decades. Google Translate, Alexa and Siri, computer vision in video games, OCR in mail sorting, protein folding models all fall under artificial intelligence, but there’s no mass panic over these. The current progress is in generative AI, and that's where most of the public concern is. I’m guilty of the shorthand myself, saying "AI" when I mean "generative AI". People are afraid of generative AI, but the real problem is concentrated power and corporate greed. Someone wanting to sow disinformation could do so without generative AI models, and deep-pocket organizations of state could finance extreme actors if they wanted to. The tools evolved, but the risks aren’t new. The bigger problem that few are talking about is corporations who are aligning the technology for their own goals; they increasingly dicta...

Can AI Break RSA Encryption?

We’re told that it will take powerful quantum computers to break RSA encryption, so for now the world is safe. But I wondered, in an era of increasingly sophisticated models, might AI pose a threat? These systems excel at finding patterns in data that humans miss, and if there were any subtle weaknesses in key generation, I would think AI could detect them. Yes, theory says it’s all but impossible to break RSA because it relies on the computational hardness of factoring large prime numbers. But theory and practice don’t always align, and sometimes the most interesting discoveries come from testing our assumptions. So I set up an experiment to test whether a transformer model could learn to reverse-engineer SSH private keys from their corresponding public keys. Experiment and Results I trained a T5-small transformer model (60 million parameters) on a dataset of 50,000 SSH key pairs, split into 70% training, 15% validation, and 15% test. Given a public key as input, the model was as...

Currencies Without Borders: How much is a million spesmiloj?

As I write more and more Esperanto fiction, I find myself referencing the currency spesmiloj in an attempt to create an immersive Esperanto environment for the reader. Here's an example from my mikronovelo La Kristala Ananso : “Kun aroga certeco, juna entreprenisto proponis unu milionon da spesmiloj. Neniu aŭdacis proponi pli.” The narrative doesn’t change whether it’s a million USD, a million CAD, or a million EUR... so why not a million spesmiloj? I’m certain most of my readers aren’t millionaires, so the exact amount really doesn’t mean much beyond “a lot of money.” But then I wondered: how much is a million spesmiloj, really? According to Wikipedia , the spesmilo was "equivalent to one thousand spesoj, and worth 0.733 grams (0.0259 oz) of pure gold (0.8 grams of 22 karat gold).” So 0.733 g × 1,000,000 = 733,000 g At the current spot price for gold per gram of 107.75 USD / 92.87 EUR, we get: 733,000 g × 107.75 USD = 78,980,750 USD 733,000 g × 92.87 EUR = 68...

The Case Against Coding Interviews

Continuing my reflections on how we can better hire software engineers, I'd like to next address the topic of coding interviews. They're a cornerstone of the interview process for software engineers and take many forms, including algorithm challenges, whiteboard sessions, and take-home exercises. On the surface, the practice sounds reasonable. If we're going to pay someone to write code for us, we should verify they know how to program, right? The core problem is that coding interviews focus on superficial indicators of skill rather than the qualities that matter in real-world engineering. They're a tradition that persists not because it works, but because it feels like we're doing something rigorous. Meanwhile, engineers are increasingly refusing to participate, leaving us with a less diverse talent pool. So, if coding interviews frustrate the very people we want to hire, and they don’t generate the insights we actually need, why are we still doing them? It’s ...

Sorry, Conceptual Fluency Won't Land You a Job

I saw a recent post where a software engineer/programming influencer was encouraging: If you know how to work with C#, you can learn Java. If you know how to work with JavaScript, you can learn TypeScript. If you know how to work with GitHub Actions, you can learn Jenkins. If you know how to work with SQL, you can learn SparkSQL. If you know how to work with Angular, you can learn React. If you know how to work with Databricks, you can learn Snowflake. If you know how to work with Event Hubs, you can learn Kafka. If you know how to work with Bicep, you can learn Terraform. It's not the tools that are important, it's the concepts. Kudos for speaking the truth. With 20 years of experience in software engineering myself, I whole heartedly agree with her post. But sadly, the market doesn’t value conceptual fluency. From a job search perspective, conceptual fluency presumes you're networking and already in contact with the hiring manager, they like you, and the...

The 4 Worst Interview Questions and What to Ask Instead

Interviews are supposed to evaluate whether a candidate can do the job. All too often, though, they become tests of endurance, performance, or obedience. And some of the most common interview questions aren’t just unhelpful, rather lazy, intrusive, and manipulative, reflecting a deeper problem in how companies approach hiring. If we want real insight, we have to ask insightful questions. That sounds obvious, but it’s staggering how many interviews still fall back on unhelpful lines of questioning. You’ve invested hours wading through half-baked applications, irrelevant referrals, and now AI slop. After all that effort, why would you waste the actual interview, the most valuable moment, with questions that produce rehearsed answers and zero useful insight? Let’s look at four of the worst interview questions to ask, not just to call them out, but to push for a smarter, more respectful way of interviewing that both values people and leads to better hiring decisions. 1. Can you explai...

La orgeno: Reĝo de muzikiloj

La orgeno estas nekompareble kompleksa kaj kapabla instrumento. Antaŭ la tempo de elektronikaj maŝinoj, la orgeno, konata kiel la “reĝo de muzikiloj”, reprezentis la pinton de homa eltrovemo, kaj estis detronigita nur en la 19-a jarcento, kiam aperis la telefoncentralo. Tamen, la orgeno restas unika en siaj majesto kaj kompleksa strukturo. En ĉi tiu artikolo mi prezentas la historion kaj funkcion de la orgeno, espereble por instigi pli profundan aprezon pri tiu impona muzikilo. Gravuraĵo de “L’art du facteur d’orgues” (1766–78), kiu montras la funkcion de orgenoj. Tiam sen elektro, ludantoj bezonis asistanton por provizi la aerpremon. Historio de la orgeno La historio de la orgeno komenciĝas en antikva Grekujo kun la akvoorgeno. Inventita de Ktesibio el Aleksandrio, tiu instrumento uzis akvon por regi la aerpremon, kiu estis puŝita tra tuboj por krei sonon. La akvoorgeno rapide fariĝis populara en la publikaj spektakloj de Romio, disvastiĝante tra la imperio. Dum la malkr...

Kobalto-60: Kaj helpema kaj minaca

Dum mi interparolis kun aliaj esperantistoj ĉe lastatempa renkontiĝo en publika kafejo, mi aŭdis la konversacion de apuda ne-esperantista grupo. Ili estis universitataj studentoj, diskutantaj pri fiziko kaj radiado. Oportuno amikiĝi instigis min interrompi ilin, dirante (en la angla): “Pardonu la interrompon. Mi ne intence kaŝaŭskultis, sed kobalto-60 estas mia plej ŝatata.” Unu studento maltrankvile rigardis min. Studento: “Kiel vi scias pri tio?” Mi: “Nu… ĝi estas sufiĉe konata temo, ĉu?” Studento: “Ne… ne estas.” Esperantistoj: “Kio estas kobalto-60?” Anstataŭ komenci amikan interŝanĝon, en kiu ili eble demandos nin pri nia lingvo, mi senintence kreis impreson, ke ni estas grupo de esperantaj teroristoj! Por elturni ion bonan el mia socia mispaŝo, mi decidis, ke la temo taŭgas por artikolo en nia bulteno. Do… Superrigardo Kobalto estas brila, griza metalo kun multaj uzoj. Ĝi estas uzata en la fabrikado de reŝargeblaj piloj, fortaj magnetoj, veturilaj aerkusenoj, kaj j...

La irlanda semaforo de Sirakuso

En la kvartalo Tipperary Hill de Sirakuso, Novjorkio, staras neordinara semaforo, kiu defias la kutimajn normojn. Tiuj renversitaj trafiklumoj, kun verda ampolo super la ruĝa, estas simbolo de la irlanda komunumo en la urbo. Dum la deknaŭa jarcento, Sirakuso grande transformiĝis pro la konstruo de la kanalo Erie kaj rapida kresko de sia salindustrio. La urbo allogis milojn da homoj serĉantaj pli bonan vivon, inkluzive migrintojn el Irlando, kiuj fuĝis pro malsato. La irlandanoj kunportis siajn tradiciojn kaj morojn, kaj profunde influis la karakteron de la urbo. Ili nomis la kvartalon Tipperary Hill, omaĝe al sia hejmo, la graflando Tipperary en Irlando. En la 1920-aj jaroj la urbestroj instalis modernajn semaforojn en la urbo, inkluzive de unu en la kvartalo ĉe la vojkruciĝo de stratoj Tompkins Street kaj Milton Avenue. Sed tiu semaforo baldaŭ fariĝis neatendita batalkampo de kultura rezisto. La irlandaj junuloj koleriĝis, vidante ke la ruĝa koloro, ofte asociita kun Britujo, sta...

La ekesto de artefaritaj verkistoj

En la lasta numero mi verkis pri la populariĝo kaj problemoj de artefaritaj intelektoj (AI), kiuj kreas bildojn el tekstaj priskriboj. Ekzistas ankaŭ aliaj AI-sistemoj kiel ekzemple ChatGPT, kiuj respondas al demandoj kaj kreas tekstojn. Kaj simile, laŭdoj kaj plendoj pri ili abundas. En tiu ĉi artikolo mi prezentos informon pri ChatGPT, pri ĝiaj limoj, kaj kiel vi povas uzi ĝin Esperante. Kio estas ChatGPT? Genera antaŭtrejnita transformilo (GPT, angle: Generative Pretrained Transformer) estas speco de AI por fari tekstojn. OpenAI kreis la unuan version en 2018, konsistantan el 0,12 miliardo da parametroj kaj trejnitan per 4,5 GB da teksto por laŭkuntekste prognozi la sekvan vorton en frazo. Ekzemple, se oni dirus al vi, “Pasporto al la tuta ____”, verŝajne vi respondus, “mondo”. Sed, ĉu oni ne uzas pasporton por viziti specifajn landojn? Danke al la tiel nomata Esperanto-kurso, la vortoj “Pasporto al la tuta mondo” aperas pli ofte en Esperantaj tekstoj ol “Pasporto al la tu...

La ekesto de artefaritaj artistoj

“Bauhaus style dog house.” (de Midjourney) Artefaritaj intelektoj (AI) kiel DALL-E, Midjourney, kaj Stable Diffusion, kiuj kreas bildojn el teksto, ricevas multe da atento lastatempe pro siaj kapabloj krei unikajn kaj belegajn artaĵojn. Tamen la atento ne estas tute pozitiva. Multaj homoj timas pri la rezultoj de la teknologio, precipe, ke ĝi ŝtelos laboron de homaj artistoj. Estas ankaŭ diversaj etikaj, juraj, kaj sociaj zorgoj. Tiuj estas gravaj, ĉar la teknologio pliboniĝas rapide, kaj ĝia akcepto fariĝas pli kaj pli vasta. Kiel funkcias programoj por fari bildojn el teksto? La celo estas krei bildojn surbaze de tekstaj priskriboj, ekzemple, “duetaĝa rozkolora domo kun blanka barilo”. La programoj dependas de speciale trejnitaj AI-modeloj por kompreni la priskribojn. Esence, la modeloj estas kreitaj per granda kvanto da datumoj, per kiuj ili agordas reton de interligitaj nodoj. La nodoj agas kiel filtriloj, rekonante specifajn trajtojn. Kun sufiĉe da tempo, datumoj, kaj bonŝ...

La Espero

Preskaŭ ĉiu esperantisto konas la himnon La Espero, kies vortoj devenas de la samnoma poemo de d-ro Zamenhof. La plej vaste kantata melodio estas verkita en 1909 de Félicien de Ménil. Tamen ekzistas ne nur unu melodio – mi jam sciis, ke esperantistoj foje kantas la poemon laŭ melodio de Achille Motteau, kiu estis verkita ses jarojn pli frue ol la de-menila melodio. Kaj ekzistas kelkaj aliaj. Sed kiom? Tion mi scivolis, do mi komencis esploron en 2018, en kiu mi malkovris preskaŭ dudek versiojn de La Espero verkitajn inter 1891 kaj 2020. Bedaŭrinde nur kelkaj melodioj estas facile troveblaj en Interreto; la plej multon mi trovis per katalogo de iu arĥivo aŭ nacia biblioteko, kaj mi petis kopion. Ju pli da ekzempleroj mi kolektis, des pli forte mi deziris, ke la muziko ne estu forgesita. Tiu muziko apartenas al la kultura heredaĵo de nia movado; ĉiu himno staras kiel ekzemplo de muzika esprimado, inspirita de amo por Esperanto kaj kredo je ĝia celo. La esploro ŝanĝiĝis al ne-atendita p...

Safely Identify Dependencies for Chrooting

The most difficult part of setting up a chroot environment is identifying dependencies for the programs you want to copy to the jail. For example, to make cp available, not only do you need to copy its binary from /bin and any shared libraries it depends on, but the dependencies can have their own dependencies too that need to be copied. The internet suggests using ldd to list a binary’s dependencies, but that has its own problems. The man page for ldd warns not to use the script for untrusted programs because it works by setting a special environment variable and then executes the program. What’s a security-conscious systems administrator to do? The ldd man page recommends objdump as a safe alternative. objdump outputs information about an object file, including what shared libraries it links against. It doesn’t identify the dependencies’ dependencies, but it’s still a good start because it doesn’t try to execute the target file. We can overcome the dependencies of depende...

A Unicode fgetc() in PHP

In preparation for a presentation I’m giving at this month’s Syracuse PHP Users Group meeting, I found the need to read in Unicode characters in PHP one at a time. Unicode is still second-class in PHP; PHP6 failed and we have to fallback to extensions like the mbstring extension and/or libraries like Portable UTF-8 . And even with those, I didn’t see a unicode-capable fgetc() so I wrote my own. Years ago, I wrote a post describing how to read Unicode characters in C , so the logic was already familiar. As a refresher, UTF-8 is a multi-byte encoding scheme capable of representing over 2 million characters using 4 bytes or less. The first 128 characters are encoded the same as 7-bit ASCII with 0 as the most-significant bit. The other characters are encoded using multiple bytes, each byte with 1 as the most-significant bit. The bit pattern in the first byte of a multi-byte sequence tells us how many bytes are needed to represent the character. Here’s what the function looks like: f...

Some Go Irks and Quirks

Now that Jump Start MySQL is published, I’m taking advantage of the spare time I have on my hands while it lasts. I’ve helped organize the Syracuse PHP Users Group , reconnected with some old friends, and gave some love to Kiwi , my forever-project programming language. Moreover, I decided to rewrite Kiwi using Go as it’s one of those languages I found interesting but never had a reason to use in any serious fashion. And now that I’ve got some real experience with it, while I still find myself impressed by some of Go’s features, some things have become really annoying. I still really like Go’s data typing; it’s static, but it feels dynamic because the compiler is smart enough to deduce a value’s type. If you write your code well then you’ll rarely see a type name outside of a function signature or struct or interface definition. It’s nice to have type safety without the verbosity (yes I’m looking at you, PHP7). I wish := behaved slightly different, though. Instead of always an allo...

PHP Frameworks Don't Save Time

Experience has shown me frameworks can be useful for maintaining structure in large code base developed by multiple teams. Every developer has different abilities and a framework enforces structure and consistency throughout the code. But I've not experienced saving any substantial amount of time on a PHP project because of a framework. The other day someone posted in the PHP subreddit asking for advice. He was about to begin work on a small project and wanted to know whether he should use a framework, and if so then which framework would be appropriate. I should have known better than to offer my two cents but I did anyway. Slim + NotORM + Twig is nice. If it's a simple project, you probably don't need much more than that. I'm not a fan of frameworks in the slightest but I do enjoy the aforementioned combination. They're lightweight and stay out of my way, allowing me to write my functionality. Another redditor picked up on my distaste for frameworks and ask...

New Writers Guide now on GitHub

Writing can be a fun and rewarding way to share your knowledge, experience, and opinions with others. Unfortunately, it can also be intimidating or frustrating for some people. When I was managing editor for SitePoint's PHPMaster property, I prepared a guide to help alleviate some of the frustration and self-doubt that new writers (and even experienced writers) might experience. The guide wasn't something commissioned by SitePoint; I wrote it on my own for my authors. And though it's been about eight months since PHPMaster was absorbed into the main SitePoint site and I stepped down as managing editor, people continue to ask me about it. So, I've decided to make the guide publicly available. The New Writers Guide offers advice for finding inspiration, structuring an article's content, growing one's self-confidence, and overcoming other challenges that programming writers may face. Hopefully it'll continue to help people write awesome articles and realiz...

Ajax File Uploads with JavaScript's File API

Developers have been using Ajax techniques for years to create dynamic web forms, but handling file uploads using Ajax was always problematic. The crux of the problem was security – it's not a good idea to allow arbitrary code access to any file it wants on a user's system so JavaScript was intentionally restricted in how it could interact with things like file input elements. Uploading a file with JavaScript was essentially a standard form submission that targeted a hidden iframe. It felt dirty but it got the job done. The W3C began work on standardizing a File API for JavaScript sometime between 2006 and 2009 and we're now at the point with browser support where developers can take advantage of it. Developers supporting web apps on IE8 and 9 still need to use iframes, but those of us targeting newer browsers can finally take a pure JavaScript approach to file uploads. And as more users migrate from IE8/9, the iframe approach will eventually be left in th...