April 8, 2023
Medley Interlisp Project, by Larry Masinter et al.
December 5, 2021
A year and a half into the project, I'm still having fun at Interlisp.Org.
Check out our Annual Report.
One of my favorite hacks: On April 1 some spring in the late 70s I changed the site GREET file (which everyone used) to use "Screen Melt" as a screen saver. No one was amused.
August 11, 2020
Restoring Medley Interlisp: running well on modern systems
and on GitHub (and see issue list)
It's great to work with old friends, as if 30 years hadn't passed.
We have a lispcore@googlegroups.com and interlisp@googlegroups.com mailing lists and weekly zoom calls.
Using old code feels like driving a vintage car. The quirks are more noticeable. I'm hoping we can smooth some of the rough edges of using it on different platforms and also bringing up some of the applications built in Interlisp.
July 5, 2020
The Office of the Future: the Officeless Office
(Economist video via YouTube)
Keeping expensive real estate and wasting time commuting to an office in a big building, to do a job on the off chance you might bump into someone is a waste
June 12, 2020
The Epidemiology of Bad Ideas
Lately there's been a lot of discussion about Section 230 and the responsibility (if there is) of the distributor of user opinions. But this discussion is misdirected.
The problem the Internet brings is that it allows for unfettered spread of bad ideas and lies (attributable to some combination of stupidity and malice).
Think of a bad idea like a virus, fact checking and filtering like testing and quarantine, and Twitter and Facebook postings like mass spreading events. From that perspective, what we need is the equivalent of washing hands and social distancing.
Any site distributing an idea,
a post, a share to more than N people should add some social distance -- a
time delay (depending on reach), fact checking, annotating the post or adding a click-through....
sufficient filtering/delay to flatten the curve. How much of their business model depends on posts going viral QUICKLY?
Recently, Carol tried to read me an article about the latest outrageous behavior. But I protested: I'd developed antibodies that protect me from the awfulness. By continued exposure, nothing was that bad anymore, we had all seen more. And there are teams of people all working full time developing new outrageous things.
Facebook and Twitter and Google and other social media sites need to implement thought-social distancing to reduce R(0) of a bad idea.
Facebook's ads promoting CDC would be OK if it weren't for the corruption of CDC management by the wave of bad ideas, spread by immune-compromised individuals (don't recognize ideas as bad) and allowed unchecked by those who exhibit no symptoms (outrage).
April 18, 2020
Building Going-Remote.Info
But the community group didn't quite jell because we didn't really agree on the scope of work.
So after considering lots of possibilities I decided to put up a stake for https://Going-Remote.info as a web site/wiki/discussion forum. This is old fashioned but I think it will appeal to the kind of community I think we can build.
Log into https://Going-Remote.info and check it out.
March 12, 2020
W3C: CoVid-19 Remote Meet, Work, Class Community Group created
Inviting experts in the current state of usable technology for remote meetings, classes, work from home, etc. to help put together best practices documents for the transition.
From the announcement:
The CoVid-19 Remote Meet, Work, Class Community Group has been launched:
http://www.w3.org/community/covid-19/
A clearinghouse for experience and guidelines for people who are suddenly called to avoid travel or meetings, work-at-home or do classes online. Focus on current capabilities and future needs.To join:
http://www.w3.org/community/covid-19/join
If you do not have one already, you will need a W3C account to join:
http://www.w3.org/accounts/request
This is a community initiative. W3C's hosting of this group does not imply endorsement of the activities.
The group must now choose a chair:
http://www.w3.org/community/about/faq/#how-do-we-choose-a-chair
For more information about getting started in the new group, see:
http://www.w3.org/community/about/faq/#how-do-we-get-started-in-a-new-group
and good practice for running a group:
http://www.w3.org/community/about/good-practice-for-running-a-group/
We invite you to share news of this new group in social media and other channels.
February 6, 2020
Building AI with computation and data distributed using cpus of autonomous vehicles
It might be a unique opportunity to develop distributed AI in an interesting computational base.
I'll update as I find out more.
December 8, 2019
I've been Wikipedia'd!
Is this typical? To see so many errors in Wikipedia articles?
- All of the Interlisp work was at Xerox. Although I was listed as a student at Stanford and didn't get my PhD until 1980, I was working at Xerox full-time after 1976.
- I had nothing to do with Interlisp-Jericho.
- There wasn't a port of Interlisp to the vax, there was an effort to build one, and I wrote a document trying to scope out how much work that was to be done. That document wasn't to "document the port".
- My work at Stanford was on the Dendral project as an employee (my Alternative Service), not as a student. The program was in Lisp.
- My work on document management was almost all at Xerox, not for Adobe. I didn't do "pioneering work on the PDF format" (for anyone).
- I remained an employee of Xerox PARC, becoming a "Principal Scientist", but never had the title "Chief Scientist" and never reported to "Xerox AI Systems".
- I wasn't "instrumental in the development of the PDF MIME type" (I helped publish it at best.)
- My work on internet standards through IETF and W3C was over many years, between Xerox, AT&T Labs and Adobe. But it was mainly a volunteer effort on my part.
- Internet standards are not published in "peer reviewed journals"; they are reviewed, but for different reasons than peer-reviewed journals.
- I never worked on Apache. I never collaborated with Nick Kew or Kim Veltman or anyone else on any book.
- The footnote references don't correspond very well to the topics discussed.
July 1, 2019
Why these odd anonymous comments?
- You have brought up a very wonderful details, thanks for the post
- Appreciate it for helping out, excellent info
- This site definitely has all the information I needed about this subject and didn't know who to ask.
- Hi Dear, are you actually visiting this web page on a regular basis, if so afterward you will definitely obtain fastidious know-how.
- Excellent post. I was checking continuously this blog and I am impressed! Extremely helpful info particularly the last part :) I care for such information much. I was seeking this certain info for a very long time. Thank you and best of luck.
- You have made some good points there. I checked on the web for additional information about the issue and found most individuals will go along with your views on this site.
- I am in fact pleased to glance at this webpage posts which contains lots of useful data, thanks for providing these kinds of statistics.
It wasn't until I had gotten 2 or 3 that I went from "Publish" to "Delete" to "Mark as spam" (the three options offered by blogger.)
The things that distinguish these comments:
- They exist. I rarely get comments. These happen once or twice a month
- They always are Anonymous
- They always have bad english grammar.
- They don't fit any known category of spam; not promoting anything or links anywhere
- They are flattering
- They contain nothing that would associate them with the content of the blog post they are commenting on.
- This is a data communication method, using steganography based on grammatical or punctuation or word choices.
- There is some grad student running experiments / training an AI etc. based on human spam detection
- Someone is running a background check for blogs that auto-publish anonymous comments.
May 9, 2019
On the nature of hierarchical URLs
Topic: URL
Dear Dr Masinter,
I am a French software engineer and have a technical question about RFC 3986, Uniform Resource Identifier (URI): Generic Syntax.
What do you mean exactly by “hierarchical data” in this paragraph?
The language "usually" in RFC 3986 indicates the text isn't normative, but rather explanatory. So the terms used may not be precise.“The path component contains data, usually organized in hierarchical form, that, along with data in the non-hierarchical query component (Section 3.4), serves to identify a resource within the scope of the URI’s scheme and naming authority (if any).”
For arbitrary URIs, interpretation of "/" and the hierarchy it established depends on the scheme. For http: and https: URIs, the interpretation depends on the server implementation. While many HTTP servers map the path hierarchy to hierarchy of file names in the server's file system, such mappings are not usually 1-1, and might vary depending on server configuration, case sensitivity or interpretation of unnormalized Unicode strings. For web clients, the WHATWG URL spec defines how web clients parse and interpret URLs (which correspond roughly to RFC 3987 IRIs).
For an idea of what was intended, a search for "hierarchical data" yields a Wikipedia entry for "Hierarchical data model" that has relevant examples and how there are many data models in use.
The choice of data model is up to your application, and you can decide for each application which model matches your use.When I look at a directed graph of resources (where resources are the vertices and links between them are the edges), I don’t know how to decide that a particular link between two resources A and B is “hierarchical” or “non hierarchical”. Should it be just antisymmetric (A → B, but not B → A)? Should it be more restrictive, for instance the inclusion relationship (A ⊃ B)? Or another property?
For instance, which of the following directed graphs of resources should I consider as having “hierarchical” links and which should I consider as having “non hierarchical” links?
1. animalia → mammalia → dog
2. Elisabeth II → Charles → William
3. 1989 → 01 → 31
4. Pink Floyd → The Dark Side of the Moon → Money
If we use antisymmetry as the criterion for being “hierarchical”, the links of all directed graphs will be “hierarchical”.
If we use inclusion as the criterion for being “hierarchical”, only the links of 1 will be “hierarchical”, since in 2 a child has two parents, in 3 a month is shared by every year and in 4 an album can be created by several artists.
This information is needed to know if we should use the path component:
1. /animalia/mammalia/dog
2. /elisabeth-ii/charles/william
3. /1989/01/31
4. /pink-floyd/the-dark-side-of-the-moon/money
or the query component:
1. ?kingdom=animalia&class=mammalia&species=dog
2. ?grandparent=elisabeth-ii&parent=charles&child=william
3. ?year=1989&month=01&day=31
4. ?artist=pink-floyd&album=the-dark-side-of-the-moon&song=money
which one of these you use depends on not one case but the entire set of data you're trying to organize.to identify a resource.
In case 1, if you're identifying properties of groups of organisms by their taxonomic designation, the namespace is by definition hierarchical, established and managed by complex rules to resolve non-hierarchical conflicts, overlaps and disagreements. But the taxonomy of rankings has 7 or 8 levels (depending on how you count), not 3, and your example says "dog" and it's not clear if you mean Canis lupus familiaris or the entire family of Canidae. The inclusion relation is not hierarchical.
In case 2, you might have a hierarchy if you restricted the relationship to "heir apparent of".
In case 3, many use the hierarchy to organize the data such that 1989/01/13 is used to identify a resource from the first of January if the year 1983.
In case 4, many music organizers sort out files by inventing a new category of "artist" for the album-artist and using "A, B, C" for albums where there are multiple arists, and "Various Artists" for "albums" that have varieties of artists for each song.
People often invent hierarchies as a way of managing access control. WebDAV includes operations based on hierarchies.
Sometimes what is desired is a combination of different data models mixed, with the hierarchical model a "default" view, and the query parameters used to search the space and redirect to a canonical hierarchical URI.
If you're defining the space for an API, the JSON-HAL design pattern adds a layer of indirection using link relations rather than URL patterns, especially in applications where the hierarchical pattern is used for high-performance web servers which use the URL syntax for optimized load-balanced servers with multiple patterns.
Yours faithfully,
XXXX XXXX (name redacted)
May 8, 2019
Using Secret Sharing for National Archives
Topic: preservation
Reading about the National Archives budget woes: perhaps as digital material is becoming more prevalent, the volumes of paper documents isn't growing?What are the unique requirements of the National Archives for online storage of digital material?
Unlike most business archives, the lifetime of archived documents is measured in centuries.
The security of archives from both accidental and intentional loss is for that lifetime; unauthorized revelation most be prevented for at least decades.
For public records, LOCKSS (Lots of Copies Keeps Stuff Safe) might be a solution. Distribute copies to each state or region.
But for confidential records, the more copies, the more likely it is the information will be revealed.
But there is an approach worth investigating, using Secret Sharing where each State could maintain a separate secure facility under its own control.
This would allow some resilience to meddling, take-down, or premature release of information unless a large number of states agree.
April 9, 2019
The Paperless Office and the Horseless Carriage
Topic: preservation
You know the story of the horseless carriage with a buggy-whip holder (in case you needed to put a horse in front of it). But what we wound up with is a wide variety of forms: motorcycle, automobile, tank, train, etc. The transition was accompanied by corresponding developments in infrastructure.When Xerox started its Palo Alto Research Center nearly 50 years ago, part of its mission was the Paperless Office -- a world where work was done without the use of paper.
We're still in the middle of a long transition to paperless processes from billing, statements, advertising, news, receipts, insurance, medical records, government, textbooks, fiction, with documents still playing a major role in data-based activities. In most cases, these processes are turned from using paper documents to electronic ones, with PDF being an important carrier because of its ability to straddle the divide between the paper and electronic world.
In many of these processes, we're only seeing the beginnings of transition to another phase, of data connections, where electronic documents and email are being supplanted by sharing data, and documents only generated on demand by those who are outside of the data-centric roles.
HTML may have been originally designed as a document format for scientific papers at CERN, but its primary thrust in the last decade has been as a way of delivering applications to consumers.
The problem of the digital dark age is not so much technological obsolescence as it is that there are no document by-products of work done; this is not something that can be solved by new kinds of archival documents. In the records management community, documents must have or carry their own context which allows auditing of past behavior by examining the documents the process left behind.
We need some better ways of straddling the document and data world such that data archives are produced in a way that allows it to be audited, redacted, processed, without having all of the original context. Most data channels are, for efficiency reasons, context free. Metadata (embedded or supplemental) is a document-centric way of supplying context, but it isn't enough.
January 10, 2019
The Internet is a WMD (Weapon of Mass Delusion)
April 26, 2018
Debugging my brain
The ideal is "no symptoms, steady state", and each session has gotten better. For example, the strong impulse to close my eyes is less. My remote control (here wired to the PC) allows me to adjust the overall voltage slightly, and choose between the latest and one of three previously saved programs.
They call this "programming" but it's more like debugging; not modern debugging but the old-fashioned kind, where you're pawing through core dumps and using binary search.
Here's what I think is going on
The device implanted below my right collarbone communicates wirelessly with the programmer. There are eight contacts one after another on the end of the electrodes skewering my Globus Pallidus Interna on each side, different parts of which are connected to different parts of the brain, controlling movement of my legs and feet and hands and other parts. Each electrode can emit pulses at a given frequency (up to 179 hz) for a periodic burst (I think, the "pulse width") and a given voltage or amperage. Pulses can be monopolar or bipolar (not sure, but I'm guessing either negative only or negative and positive). The bipolar signals have a narrower effect; the monopolar signals are stronger.There's no exact map of which parts of the GPi connect to which function of the brain. I think the theory is that the pulses disrupt the beta-rhythms which synchronize the brain function. Anyway, the Boston Scientific device I have is new, giving the programmer lots of options not possible before.
February 7, 2018
My procedure
was on all the forms I had to sign, describing what was done to me...
"Stereotactic image" (the 3D result of an MRI scan on Tuesday and a CT scan Friday morning)
"... guided" (the team looked at the 3D image to plan the route of the wires into my brain)
"Implantation" (skewering)
"of bilateral" (both sides)
"GPi" (globus pallidus interna -- the part of my brain they were targeting)
"deep brain" (well, it was pretty deep in there, and hard to get to)
"stimulation electrodes" (two thin cables with 8 strands each leading to 8 points within the GPi)
"with volumetric analysis" (checking the path so they don't skewer something important)
"using Mazor robot" (a device they attached to a 'platform' that was screwed into my skull first thing Friday morning after first making me a numb-skull, then drilling pilot holes and screwing in; the Mazor robot then guides the surgery exactly)
"and implantation" (this one goes in a little pocket they cut in my chest)
"of right" (only one)
"infraclavicular" (under my collar bone, the electrode leads pushed under scalp, neck skin, down chest)
"pulse generator" (the thing that will send pulses to the electrodes)
Right now my brain is recovering from the trauma of this disturbance... my Parkinson's symptoms are mainly worse than usual -- both hands shaking, having trouble standing, using a walker to scoot around the house, speech soft and distorted enough that Alexa doesn't understand me, mild headache, among other indignities.
Today I get to shower! Yay!
My appointment for having the whole thing turned on and to start tuning the pulses to my body is February 16th. Happy Birthday!
The process of fine tuning can take 6 months of appointments every two weeks. Each of 8 leads on each side, with their own pulse intensity, frequency and width ... I'm assuming there's some method to it, will let you know.
January 25, 2018
Going Bionic
But progressive diseases progress, and interfere with getting on with life.
I'm mainly risk-averse, but (after declining 5 years ago) I'm now scheduled next week for a surgical treatment called "Deep Brain Stimulation": like a pacemaker, but for the brain rather than the heart, and more of a pace-disruptor than -maker.
The procedure is described as "minimally invasive" and "reversible" and it's been done 100,000 times (300 by my surgeon). But still, it requires MRI and CAT scan to place wires to the exact spot without hitting good brain or blood vessels. (I got a Rift VR tour of some patient's anonymized brain as part of the explanation.)
Besides the wires in my brain ("Will I be able to listen to the radio without a radio?"), there will be wires under skin from scalp down to a not-so-tiny controller implanted -- wirelessly charged and programmed, battery rated to last 15 years. The "programming" usually takes months of adjustment.
I remember ~40 years ago admiring someone's programming skills, to the point I told people "he's so good I'd let him program my pacemaker". I'm not going to ask Boston Scientific to review their source code, but I do hope they aspire to better than "five nines".
Wish me luck...
1/31 added: for all the good wishes, expressed and felt: thank you, its meant a lot...
October 22, 2017
Mea Culpa
I was dismayed to see a twitterstorm of complaints about the ODI report on PDF and data.
Whether something is "open" depends on the tools you have, as I explore in Open Data and Documents, the scale doesn't match what people actually value.
I love Twitter. I think the twitter responses have been useful in at least reaching the user community. Thanks.
Join in on the discussion.
October 21, 2017
September 10, 2016
IETF "Security Considerations" and PDF
Some background about PDF
Everyone has heard of PDF, but I'm not sure there's widespread understanding of its role and history. Wikipedia PDF isn't too bad; page independent data structures but based on Postscript, a way of getting licenses to embed fonts, first released in 1993. Originally a "distill" of a printed page, over the years, features were added: forms, 3D, compression, reflow, accessibility.PDF is over 20 years old ... "as old as the Web"-- I first heard about it at GopherCon '93. Has it run its course, time for something new? But PDF supplies a unique solution for an application that spans the work between paper documents and electronic, and assurances of fidelity: if I send you a document, and you say you got it and read it (using a conforming reader) then I know what you saw.
MIME types
In email and web, file types are labeled by a two part label, like text/html, image/jpeg, application/pdf. This "Internet Media Type" is (supposed to be) used in content-type headers in email and web as a way for the sender to say how a receiver should interpret the content (except for "sniffing" but that's another blog post).There's an official list of media types managed by IANA (in the news lately for other reasons, another blog post). IANA, Internet Assigned Numbers[sic] Auhority, is in charge of maintaining the
registries, as directed by the IETF.
IETF has a different decision-making process than other standards groups. However, as usual, the process involves creating and distributing a draft, and asking for comments. Comments need to be responded to, even if you don't make changes because of the comment. Different kinds of documents have different criteria for advancement, and it's sometimes hard to figure out what rules apply.
Getting draft-hardy-pdf-mime to RFC
I got into updating the registration of PDF a while back, while working on "PDF for RFCs", and, after consultation, took the path of revising the RFC which authorized the current registration, RFC 3778, in the form of a document that replaced 3778, including the registration template for application/pdf . That's the document I'm trying to get passed.There were lots of comments during the review period, and I responded to most of them last week, in a single email.
Which process?
I won't go into the detailed rules, but the path we chose involved getting IESG approval for an Informational specification, one of the paths laid out in RFC 6838, which lays out the rules for the IANA media type registry.But which rules apply? RFC 6838 Section 3.1 for types "registered by a recognized standards-related organization using the 'Specification Required' IANA registration policy [RFC5226]"? Or do we follow Section 6.1, "in cases where the original definition of the scheme is contained in an IESG-approved document, updates of the specification also requires IESG approval."?
And does the "DISCUSS" laid on the document's approval meet any of the criteria of the rules for a DISCUSS?
But I'd like to accommodate the common request that the document say more about security of PDF software. It's well-known that PDF has been a vector for several infamous exploits... why can't we say more?
"Security Considerations"
IETF has an unusual policy of requiring ALL documents (https://tools.ietf.org/html/rfc3552 Section 5) to consider security and document threats and possible mitigations. ISO has no such rule; security is considered the responsibility of the implementation. W3C nominally does through TAG review, I think, but WHATWG is more haphazard. The question remains: does a conforming implementation require that the implementation expose the user to security risks.I'm sure we could say more. And if this were a new registration or the PDF spec itself I'd try. But application/pdf has been around over 20 years, the exploits and their prevention publicized.
But there is no single valid account of software vulnerabilities; the paper suggested (in a COMMENT, not a DISCUSS) isn't anything I could cite; I disagree with too many parts.
I’ll go back to the question of the purpose of “Security Considerations” in MIME registrations; for whom should it be written? For a novice, it is not enough. For an expert, you wind up enumerating the exploits that are understood and can be explained. The situation is fluid because the deployment of browser-based PDF interpreters is changing for desktop and mobile, and PDF is just another part of the web.
I agreed with the reasoning behind the requirement, that requiring everyone to write about Security might make them think a little more about security.
But I think there’s another view, that Security is a feature of the implementation. It’s the implementation’s job to mitigate vulnerabilities. So any security problems, blame the implementation, not the protocol. And the implementors need to worry about not writing buggy code, not just about security per se.
And there is no point of saying “write your implementations carefully”, because there are so many ways to write software badly. Talking about the obvious easy-to-describe exploits isn’t really useful, because we know how to avoid those.
Now perhaps this is just "don't set a bad precedent". So maybe the clue is to follow text/html, and suggest that "entire novels" have been written about PDF security, but not here in the Internet Media Type registration.
Medley Interlisp Project, by Larry Masinter et al.
I haven't been blogging -- most of my focus has been on Medley Interlisp. Tell me what you think!
-
HTML5 If there are 300 implementations of a specification, all different, but you take the 4 "important implementations" and...
-
I hadn't talked about it publicly, but it's pretty obvious now if you see me in person: my hands (often) shake, my foot (often) drag...
-
w3c , html5 , representation , resource , angels , pins , uri , url ,iri Everyone knows what a URL is, right? It's just a simple...

