Isn't he just the cutest little boy ever? He's finally waking up a little and peeping around instead of sleeping nonstop.
Saturday, May 26, 2007
Friday, May 25, 2007
a snowy treat
I almost burned to a crisp walking through the West Village today (easily 90F) so here's a nice, cool, snowy treat- Declan in a rare Seattle snowstorm!
Friday, May 18, 2007
Lullaby of London
I haven't posted about music in a long time, and certainly not the long essays I used to write. One part of that is that I've been too busy to track down new music much these days, and I'm now cut off from Amazon's great music editors.
One piece of music that I've recently fallen for, though, is "Lullaby of London" by the Pogues. It's probably about as old as I am these days but it's a beautiful song. When I first moved to NYC, I was working in Times Square, but moved down to Chelsea at the end of last summer. Midtown and Times Square are quite literally the canyons of NYC while Chelsea and the West Village area are not so tall. One bitterly cold day this winter, I set out up 7th Ave to walk to Penn Station, with the Pogues playing on my ipod. As I walked up 7th, wrapped and bundled in a coat and scarf to my eyes and still shivering, I sort of fell into this song. As I kept walking, the huge towers of Midtown started looming over me, making the wind sharper and colder and darker. It all fit together, the appearance of the gray bleakness near Penn Station, the cold, this incredibly beautiful song. Whenever I have to walk up 7th Ave, even now in the warm spring, I try to play it at least once, as it's so tied to this one area for me.
One piece of music that I've recently fallen for, though, is "Lullaby of London" by the Pogues. It's probably about as old as I am these days but it's a beautiful song. When I first moved to NYC, I was working in Times Square, but moved down to Chelsea at the end of last summer. Midtown and Times Square are quite literally the canyons of NYC while Chelsea and the West Village area are not so tall. One bitterly cold day this winter, I set out up 7th Ave to walk to Penn Station, with the Pogues playing on my ipod. As I walked up 7th, wrapped and bundled in a coat and scarf to my eyes and still shivering, I sort of fell into this song. As I kept walking, the huge towers of Midtown started looming over me, making the wind sharper and colder and darker. It all fit together, the appearance of the gray bleakness near Penn Station, the cold, this incredibly beautiful song. Whenever I have to walk up 7th Ave, even now in the warm spring, I try to play it at least once, as it's so tied to this one area for me.
Lilacs and Rhubarb
I left work early today, and my grandpa met me at the train station so that we could pick rhubarb. While we drove over to his farm, which is very close to the train, we talked about the Mets game I'd seen yesterday (I'm a lifelong Yankees fan, but I will happily admit that was a truly inspiring 9th inning yesterday!), and baseball games he went to when he grew up in Quincy, Mass. Then we went out to the field and picked tons and tons of rhubarb. As always, he tried to get me to take a bite of one of the stalks, which I didn't fall for. Rhubarb with strawberries and lots of sugar in a pie is wonderful. Raw rhubarb is...bitter.
Their lilacs are all blooming, so I also picked some of those, and a bit of arugula. What inspired this blogpost is that I just yawning and rubbing my forehead and I smelled the rhubarb and lilac on my fingers still. That's what spring always smells like to me, a sharp mixture of both tangled together.
Their lilacs are all blooming, so I also picked some of those, and a bit of arugula. What inspired this blogpost is that I just yawning and rubbing my forehead and I smelled the rhubarb and lilac on my fingers still. That's what spring always smells like to me, a sharp mixture of both tangled together.
Tuesday, May 15, 2007
Kate on the Train
and to go with my other train post, here is Kate riding the train into NYC
sunrise
Sometimes I wonder at the ability of my brain to drive down to the train station and get on the right train on basically autopilot every morning. My brain is not particularly functional before I've had 2 cups of coffee, and I only have one before I leave home. This morning was a nice example of how useless I am uncaffinated; last night I'd sat on the right side of the train heading out from NYC and had horrible sunglare in my eyes the whole way. This morning in picking a seat my logic was:
1. the right side of the train had glare going West
2. we are now going East this morning
3. so that means that the right side of the train is on the other side in this direction
4. I'm sitting on the right side
Of course, you see the flaw there, right? Yes... the sun comes up on one side and goes down on the other. So I'm riding along... with the sun right in my face again. Oh well!
1. the right side of the train had glare going West
2. we are now going East this morning
3. so that means that the right side of the train is on the other side in this direction
4. I'm sitting on the right side
Of course, you see the flaw there, right? Yes... the sun comes up on one side and goes down on the other. So I'm riding along... with the sun right in my face again. Oh well!
Saturday, March 10, 2007
Redhead
We went to Morristown today to watch the St Patrick's Day parade. Declan got quite into it- he said hello to every single person sitting near us, and he loved all the dogs walking by in the parade (Irish Setters! Irish Terriers! Irish Wolfhounds! Seeing Eye dogs!). He had a cute little shamrock kerchef around his neck, so he fit right in with all the dogs wearing green.
Sunday, February 11, 2007
Sunset at 7000 feet
Sunset as seen flying over NJ, heading back to Rhode Island last night. The Air and Space museum at Dulles was lots of fun!
Friday, February 02, 2007
I've been missing Dahlia Bakery and Macrina incredibly. There are some nice bakeries in NYC, but I got terribly attached to both of those places in Seattle, so nothing here is stacking up. To console my sweettooth, I recently bought Baking at Home with The Culinary Institute of America, which is an awesome baking cookbook. It has little sections on various dessert types, and each opens with some notes on technique. So far I've figured out how to make these:- sabayon (yum!)
- chocolate sabayon torte
- truffles
- buttercream cake
- sponge cake
- lemon buttermilk cake
- Raspberry coulis sauce
I've made a few other recipes, but I haven't exactly mastered them yet... created mushy messes would be more like it. One important recent discovery: the kitchenaid whisk mixer is a necessity for sponge cake, just as the recipe says. Fail to use it, and you will end up with something that falls in on itself.
Monday, January 08, 2007
Bounce
I love traveling, but somethings things start looking a little crazy. I'm trying to figure out my schedule for one weekend in Febuary, and this is what I think I'm going to be doing:
Friday morning: skiing in Vermont
Friday afternoon: go to NYC
Saturday morning: train to Providence, RI
Saturday afternoon: fly to Washington DC
Sunday morning: fly to Rhode Island
Monday morning: train to NYC
I believe I'm going to wake up on Monday and not know where on the east coast I am.
Friday morning: skiing in Vermont
Friday afternoon: go to NYC
Saturday morning: train to Providence, RI
Saturday afternoon: fly to Washington DC
Sunday morning: fly to Rhode Island
Monday morning: train to NYC
I believe I'm going to wake up on Monday and not know where on the east coast I am.
Friday, December 29, 2006
chili
Today over lunch at d.b.a. we discussed different chili recipes. My favorite is still black bean chili with masa harina, this is a recipe I've sort of made up a while ago from various recipies I've tried in the past.
2 Tbs. ancho chili powder
2 Tbs. ground cumin
1 tsp. coriander
1 can black beans (goya works fine)
1 28 oz can of whole tomatos (or you could use crushed or whatever)
Olive oil
1 small yellow onion
2 garlic cloves
2 Tbs. masa harina
2 Tbs. ancho chili powder
2 Tbs. ground cumin
1 tsp. coriander
1 can black beans (goya works fine)
1 28 oz can of whole tomatos (or you could use crushed or whatever)
Olive oil
1 small yellow onion
2 garlic cloves
2 Tbs. masa harina
- chop up the onion and garlic cloves, put it in a pot with some olive oil & cook for a few minutes
- add chili powder, cumin, coriander
- add black beans (drain off some of the extra water first if there's a lot in the can)
- stir
- add tomatos
- stir, bring to a boil over medium high heat
- let it boil for about 5 minutes then lower heat to low
- cook at least 30 minutes, but you can leave it on low heat for much longer if you need to
- 5 minutes before serving, mix in masa harina to thicken, stir until it thickens
Saturday, December 23, 2006
ice skating
Kate went ice skating for the first time yesterday, in the cutest teensy hockey skates. I had to hold her upright the whole time, but by the end her feet were only sliding out from under her every 3 seconds instead of every .0000001 seconds. Progress!!
Afterwards, we went over to Fosterfields to say Merry Christmas to the animals. Calvin and Hobbes (the Belgian draft horses) came over to say hello when we got there, and Hobbes decided that my scarf was dinner and tried to eat it. So I got horse slobber all over my shoulder. blech. But he's a cute guy so we forgave him. Their coats are really thick for winter already! Then it was time for all the animals to get dinner- the two farmers walked Calvin and Hobbes into their stable, rounded up the 3 cows (Calico was more interested in saying hi to us than going inside), and collected the turkeys. Kate said hello to the cat (named B.C. for barn cat) and all the chickens and roosters. We didn't stay around while the sheep were fed, but they were all clustered at the gate waiting their turn when we left.
When we got home, we made Red Velvet cupcakes for Ana's first birthday. Yum!
Afterwards, we went over to Fosterfields to say Merry Christmas to the animals. Calvin and Hobbes (the Belgian draft horses) came over to say hello when we got there, and Hobbes decided that my scarf was dinner and tried to eat it. So I got horse slobber all over my shoulder. blech. But he's a cute guy so we forgave him. Their coats are really thick for winter already! Then it was time for all the animals to get dinner- the two farmers walked Calvin and Hobbes into their stable, rounded up the 3 cows (Calico was more interested in saying hi to us than going inside), and collected the turkeys. Kate said hello to the cat (named B.C. for barn cat) and all the chickens and roosters. We didn't stay around while the sheep were fed, but they were all clustered at the gate waiting their turn when we left.
When we got home, we made Red Velvet cupcakes for Ana's first birthday. Yum!
Wednesday, December 20, 2006
so that's how you do it
From a Wall Street Journal book review of Citizen Marketers:
"The key was the more recent development known as Web 2.0. Powered by XMA, a computer language that makes it easy to merge data from any number of sources, Web 2.0 has transformed the Net from what was largely a platform for micropublishers to a free-floating community forum that encourages multimedia participation by anyone with a broadband connection."
Aha. So nice to learn that I haven't been writing multi-tiered database backed websites with AJAX web frontends and RSS/Atom feeds, I've just been doing XMA. ;-)
ps the article is over here if you have a wsj.com login
"The key was the more recent development known as Web 2.0. Powered by XMA, a computer language that makes it easy to merge data from any number of sources, Web 2.0 has transformed the Net from what was largely a platform for micropublishers to a free-floating community forum that encourages multimedia participation by anyone with a broadband connection."
Aha. So nice to learn that I haven't been writing multi-tiered database backed websites with AJAX web frontends and RSS/Atom feeds, I've just been doing XMA. ;-)
ps the article is over here if you have a wsj.com login
Friday, December 15, 2006
Javascript and XSRF
XSRF (or CSRF) stands for "Cross Site Request Forgery" and is a class of website application vulnerabilities. It's a fancy term for a fairly simple "exploit" -- really, I think exploit is far too fancy for this. Let's say that I'm logged into Blogger, writing this blog post, and I have a few other Safari tabs opened at the same time. My browser has blogger cookies that are "active" - when I send a HTTP request from my browser to blogger.com, the cookies that go along with it will match up with my current blogger session.
So now let's image that blogger has a form on its site for removing your blog. If you submit the form, you might post to "blogger.com/deleteblog?delete=true" or something along those lines, and your blog would be gone. If my friend decided that I'd been posting far too many annoying blog posts about Declan and wanted to nuke my blog, he might set up a page on his web site that has this HTML code on it:
<img src="http://blogger.com/deleteblog?delete=true">
He would then send me a link to the page, or post a comment on my blog- anything to get me to load the page that contains that image tag. When my browser loads that page, it would try to fetch that image by sending a GET request to blogger.com. And if I was still logged into my blogger account in another tab, it would send along my blogger cookies. So blogger would see a request to delete a blog, with my blogger cookies, and it would... delete my blog.
The generally recommended way to get around this is to also generate a "one time code" to use as a confirmation. Blogger would create a hard-to-guess token, and insert this code into its "Delete Your Blog" form:
<input type="hidden" name="secret" value="1234567890SECRET0987654321">
The value, of course, should really be something harder to guess than that code, and a new value should be generated every time that the page was served up. So now blogger will only delete my blog if I post to the "deleteblog" form with the current secret value. If it doesn't match, or is missing, my blog is not deleted.
If javascript did not have the cross-domain restrictions that it has, my friend could insert some javascript into that page he wants me to visit that:
1. create a hidden iframe
2. set the source of that iframe to the blogger "do you want to delete your blog?" page which holds the form (remember, my browser issues that request, so it gets issued to blogger.com with my current cookies)
3. grab the innerHTML of the iframe, regex out the "secret" value
4. set the image to send along my current secret:
<img src="http://blogger.com/deleteblog?delete=true&secret=1234567890SECRET0987654321">
Thankfully, javascript does have cross domain restrictions. My friend can set a hidden iframe on his site to be the blogger "do you want to delete your blog?" page, but he can't access the innerHTML that's returned, so I can continue to post crazy posts about my dog.
However...there's been an explosion in the last 2 years of dynamically generated sites that use javascript, and specifically JSON, to render their sites. What if blogger also generated their site using a ton of javascript, and slipped up and included my secret value inside a javascript file that they would send to my browser to assemble the form? There is no cross domain restriction on scripts included via <script src="http://someothersite.com">
So, in step #2 above, my evil friend would not set an iframe to be the blogger blog deletion page, but would instead set up tag like <script src="http://blogger.com/scripts/secret.js"> and then pull out the secret code. He would then create that image HTML, write it out to the page, and my blog would be gone.
JSON is a great technology, but there are a lot of web developers out there who don't realize how it ties in with vulnerabilities like this one. Think very carefully when building a site about what information to put into a javascript file on your site, and what information you include in a JSON feed from your site.
So now let's image that blogger has a form on its site for removing your blog. If you submit the form, you might post to "blogger.com/deleteblog?delete=true" or something along those lines, and your blog would be gone. If my friend decided that I'd been posting far too many annoying blog posts about Declan and wanted to nuke my blog, he might set up a page on his web site that has this HTML code on it:
<img src="http://blogger.com/deleteblog?delete=true">
He would then send me a link to the page, or post a comment on my blog- anything to get me to load the page that contains that image tag. When my browser loads that page, it would try to fetch that image by sending a GET request to blogger.com. And if I was still logged into my blogger account in another tab, it would send along my blogger cookies. So blogger would see a request to delete a blog, with my blogger cookies, and it would... delete my blog.
The generally recommended way to get around this is to also generate a "one time code" to use as a confirmation. Blogger would create a hard-to-guess token, and insert this code into its "Delete Your Blog" form:
<input type="hidden" name="secret" value="1234567890SECRET0987654321">
The value, of course, should really be something harder to guess than that code, and a new value should be generated every time that the page was served up. So now blogger will only delete my blog if I post to the "deleteblog" form with the current secret value. If it doesn't match, or is missing, my blog is not deleted.
If javascript did not have the cross-domain restrictions that it has, my friend could insert some javascript into that page he wants me to visit that:
1. create a hidden iframe
2. set the source of that iframe to the blogger "do you want to delete your blog?" page which holds the form (remember, my browser issues that request, so it gets issued to blogger.com with my current cookies)
3. grab the innerHTML of the iframe, regex out the "secret" value
4. set the image to send along my current secret:
<img src="http://blogger.com/deleteblog?delete=true&secret=1234567890SECRET0987654321">
Thankfully, javascript does have cross domain restrictions. My friend can set a hidden iframe on his site to be the blogger "do you want to delete your blog?" page, but he can't access the innerHTML that's returned, so I can continue to post crazy posts about my dog.
However...there's been an explosion in the last 2 years of dynamically generated sites that use javascript, and specifically JSON, to render their sites. What if blogger also generated their site using a ton of javascript, and slipped up and included my secret value inside a javascript file that they would send to my browser to assemble the form? There is no cross domain restriction on scripts included via <script src="http://someothersite.com">
So, in step #2 above, my evil friend would not set an iframe to be the blogger blog deletion page, but would instead set up tag like <script src="http://blogger.com/scripts/secret.js"> and then pull out the secret code. He would then create that image HTML, write it out to the page, and my blog would be gone.
JSON is a great technology, but there are a lot of web developers out there who don't realize how it ties in with vulnerabilities like this one. Think very carefully when building a site about what information to put into a javascript file on your site, and what information you include in a JSON feed from your site.
Wednesday, December 13, 2006
a flickr xmas gift

the bestest easter egg I've ever seen! Draw a note with the tag "ho ho ho hat" and you get a spiffy xmas hat. wonderful.
Subscribe to:
Posts (Atom)



