I'll have to check this later (job blocks Polyvore). What culture do you mean, Kevin? - Kamilah Gill
I got a free song from iTunes b/c I bought tickets for midnight. I don't know if I'll stay awake. - Joel
I have midnight tix too. *hides from Jessie* - Jess Lee
I have to wait to see it because "I am dragging my boyfriend to see it against his will because there is no way he'd want to see a teenage girl movie about vampires unless I made him." - Erica Baker
lol no need to hide, jess, i have no problem with people enjoying the movie. :-P my hangups are with the book and with fangirls convinced it's a fantastic work of literature. i've read crappy romance novels before but wow, "twilight" set a new standard for me. i didn't think writing that bad could actually get published. - Jessie
@ Jess Based on personal experience it is often safer to hide from Jessie. :) - Steve Craft
I'm at the midnight showing now. There are no men in this theater, save for a few disgruntled boyfriends. - Jess Lee
“Call me boring but the best Gmail theme is Classic.... It seems like, it is the most usable theme... I was visibly happy when I switched back to Classic from Graffiti””
“Is it safe to allow embed tags with arbitrary "src"? (assuming allowscriptaccess=never) I've read claims that it is not, however facebook and myspace seem to allow it.”
That's what I'm wondering. I should also mention setting type="application/x-shockwave-flash". The question is if the browsers are reliable enough to only allow flash (and not quicktime) and if the flash sandbox is reliable enough to stop cross-site scripting. - Paul Buchheit
There are some flaws in various versions of Flash that allow malformed SWF files to execute arbitrary code on the client. - Gabe
I'm pretty sure the HTTP Content-Type overrides the HTML type attribute. This would make you vulnerable to things like Quicktime movies with HREF tracks. Also, older versions of Flash don't support the allowscriptaccess attribute, so even if you could rely on the type attribute, users who don't upgrade their flash plugin would still be at risk. - Laurence Gonsalves
Any idea how Facebook and Myspace safely embed flash Laurence? - Paul Buchheit
I've never seen embedded flash on either, so I don't know. Can you send an example URL? Without seeing their HTML, my guess is that they'd either be using a "container" of some sort (eg: an off-domain iframe or their own flash container) or they're using a whitelist... assuming what they're doing is actually safe. myspace has certainly had their share of XSS vulnerabilities in the past. - Laurence Gonsalves
i can has embedded images in friendfeed comments? :-D - Karim
You can request the src attribute value on submit to check MIME, file size, and basic data on included libs or other identifiers. MySpace worked with Adobe for a few Flash 9 (AVM2) features. The allowNetworking parameter is one form of partial lock-down employed by MySpace for example. You format the embed code to your liking upon attempted save. - Niall Kennedy
"A new study by the MacArthur Foundation shows that all the time teens spend on the internet is actually not such a bad thing." - Richard Chen
via Bookmarklet
This was a talk by Dan Ariely, author of "Predictably Irrational" (http://tinyurl.com/6kn3l9). He was also one of my favorite (and insanely smart) professors from MIT -- one of those people where every time I'm heard him speak, I've gotten smarter. He's now a professor of behavioral economics at Duke and has a blog at http://predictablyirrational.c... - Tom Stocky
"It’s comparable to Google Docs or a wiki, but it’s far more useful. You start off by creating a new workspace. You type basic text on numbered lines at will. Then invite someone else in and have them type as well. Each user’s edits are highlighted a different color. Changes are made in absolute real time, something even Google hasn’t been able to do (Google docs update every fifteen seconds).
Users can also chat in the sidebar, save versions and make a few tweaks to the settings like removing line numbers. One great feature optionally highlights Javascript syntax (making this a great way to write code collaboratively)" - Paul Buchheit
via Bookmarklet
Etherpad may be a new tool in the Real Time Web kit. Collaboration on a non-flow basis. - Cliff Gerrish
Interesting - wasn't sure if AppJet was a worthwhile platform - this makes me much more interested - Christopher Galtenberg
Getting this for your try it link Paul: "EtherPad is under construction ... Sign up to be notified when we're back" - Philipp Lenssen
Try again, Philipp (nice icon btw). I think their fail whale is that signup box (not a bad idea, actually) - Christopher Galtenberg
Now it works thanks Christopher (it shows me as being alone in that document right now though). - Philipp Lenssen
Nice, a little slow, but I guess they shouldn't be waiting for all this traffic... Should be a nice tool once it adds other wiki-like functionalities (I'm thinking tiddlywiki). - Paulo Gomes
Love the tiddlywiki shoutout. (When will that tech come back to earth? So much potential) - Christopher Galtenberg
Oops, system failure again. We think we found the problem though. A nasty deadlock issue -- but hopefully fixable in short order. - Aaron Iba
Cheers Aaron. It's a huge hit here. And wow, hello AppJet! Nice tech, amigo. - Christopher Galtenberg
An interesting experience, to have typing and the other party reading be simultaneous... it removes the safety buffer of having to hit return, and has a different feel to it. Your sentence is seen by the other person as you're typing, correcting, shifting it... like when you're actually speaking in a conversation, where you may also correct yourself, look for words, etc. - Philipp Lenssen
superb substitute for paste in IRC on-the-fly collaborative coding situations: revisions acts as "version control," and multi-color highlighting representing users even works intra-line. - Adriano
I do just want to point out that this functionality has been around for 25 years with UNIX's talk program. It is definitely not a new idea. - Robert Felty
Why stop there... Native Americans sent simultaneous smoke signals into the sky. And you thought they were innovators? Nope, just rank copycats. Birdsong. That's where it all began. - Christopher Galtenberg
Superb execution of an old idea is every bit as good as innovation; perhaps better. - kris. nuttycombe
SubEthaEdit. It existed years before Writely (Google Docs) and this web app is an almost exact copy of it. - Bill Strathearn
Bill, Wikipedia says "SubEthaEdit is a collaborative real-time editor designed for Mac OS X," so it's not a browser-based app? - Philipp Lenssen
That's right, SubEthaEdit is a native Mac app, so Mr. Strathearn is completely missing the point, as are most of the "this is nothing new, I used to do this with my 300 baud modem" crowd. - ⓞnor
Of course the platform is different, but the interface and functionality are obvious copies. http://bit.ly/P5Se. Given the large time-span between the two, I just expected a bit more innovation. - Bill Strathearn