Orientation with Kojo Idrissa
Published October 23, 2025
This video features Kojo Idrissa at DjangoCon US 2022 in San Diego, California, USA.
This talk was presented at: https://2022.djangocon.us/talks/lightning-talks/
LINKS:
Follow Kojo Idrissa 👇
On Twitter: https://twitter.com/kojoidrissa
On GitHub: https://github.com/kojoidrissa
Website: http://kojoidrissa.com/
Follow DjangCon US 👇
https://twitter.com/djangocon
Follow DEFNA 👇
https://twitter.com/defnado
https://www.defna.org/
Kojo Idrissa compares generative AI to magic: prompts behave like spells whose results are unpredictable, making prompt engineering a real skill, but the metaphor is dangerous when it encourages people to overestimate AI’s abilities. The other lightning talks cover stenographic captioning and its open-source tooling, Scorpol’s machine-learning approach to predicting email engagement in ActionKit, Wagtail 4.0 snippets and permissions, and how an oversized animated GIF crashed a low-memory site. Speakers also show how profiling exposed a Django signal that doubled test time, explain the 12-factor principles for Django deployments, solve cross-subdomain session-cookie migration, and argue that programmers can make effective youth mentors.
Summarised automatically from the transcript.
Automatically transcribed, so expect mistakes in names and technical terms.
Speaker 1: Hey everyone, so yeah, I um promised that I was going to talk about two different like troublesome metaphors for AI. I did a run through, it doesn't fit five minutes, I'm just gonna give you one. I want to talk about AI and magic and wizardry. Right. There's so I've been playing with these new generative AI systems for the past year, and they are the most ethically complicated pieces of technology I have ever encountered in my entire career. Like on the one hand, you can do amazing things with them. You can generate images from text. GPT-3 is writing my blog entries for me now. It's pretty phenomenal. On the other hand, oh what the moment you look at how they're trained, you're like, wow I can't believe anyone would even do this, let alone get away with doing this. Um and there's the biases and the things baked into it. It's kind of uh it's a horror show.
Speaker 1: Right? But um one of the ways I like to think about working with these is that we get to be wizards now, right? We're using one of these generative AIs is much more like casting a spell. than it is like regular programming. Because with regular programming, I write out some Python and JavaScript and I can predict what it's going to do. That's the whole point. These are machines that do what exactly what you tell them. When you're writing a prompt for GPT-3 or Stable Diffusion or DALE, you have literally no idea what will happen when you cast these words into the machine. And neither do the people who created the models, right? Nobody knows what's going to happen when you cast this particular spell, which is Thrilling and exciting and so much fun and also deeply upsetting to me as somebody who's used to telling computers what to do and having them to do do that thing in a predictable way.
Speaker 1: But it really does feel like magic, you know. It's um one of the things so people make fun of prompt engineering as a discipline. I've seen people saying, can you believe you can get hired to be a prompt engineer now, to be somebody who prompts these AIs? But it's actually a very deep skill. There's a lot of depth to it. And what I find when I'm working with these things is you're basically collecting spells for your spell book. You're like, wow, it turns out if you say, explain this thing step by step. you get a bullet-pointed list of of steps, and it's a much better way of getting an explanation out. Or um or well the classic example with um AI image generation, if you say Greg Ritkowski, you get images that are sort of demons and and and clouds and dragons and really stylish. This guy's a living artist. He is very annoyed about this.
Speaker 1: He's like, everyone in the AI art world is using my name. They don't know who I am, but they're ripping off my style with with this with this again with this spell that people have added to their spell book. So we're casting spells, we're sharing spells with each other, we're building up a spell book of spells. And if we get the spells wrong, if we mispronounce them, you can get demons coming out at you. It feels like a very appropriate analogy to me So I've been promoting this quite a bit, talking about it on podcasts and things, and um then on Twitter some literally world-class AI researchers started shouting at me about it. They were like, it is totally irresponsible for you to call this stuff magic. And I was kind of intrigued because I'd thought this had worked out pretty well, as this this idea of us casting spells and having no idea what's going to happen
Speaker 1: But no, the argument here is that um the danger with with this AI stuff and with technology in general is when members of the public, when regular non-nerds think that it's magic and think that it can do things that it cannot do, that's when you make terrible decisions. That's when you get police departments who do the minority report thing and believe that an AI model will predict who's going to commit crimes. Now that's when you get um all of the like you watch TV and we'll get back with my apologize. enhance zoom on an image, which used to be a joke, and actually AIs can do that now, which is sort of reality catching up with fiction.
Speaker 1: But it's very important for the sort of safety of our species that people don't Assume that these AI systems are impossible to understand and have like super powered capabilities. So if you're talking to regular human beings and you say, oh it's it's magic and we're all wizards wizards now. That's kind of harmful. You know that can lead people to having the wrong mental models. I feel like if you're talking to engineers who understand that it's just matrix multiplication You know, that's all it is. It's it's a bit of dumb math and some and some party tricks. At that point I feel like exp to thinking about it in terms of we're donning we're donning our capes and we're throwing spells at each other and trying to come up with new new incantations that trick the machine into into doing our whim. I I think that's kind of fun. But yeah, so It's fine to talk about AI as magic if you're talking to people who understand that AI is not magic.
Speaker 1: If you're not, you should you should stop doing that. Thank you very much.
Speaker 2: My name is Amanda Lundberg and I'm one of the captioners here today. Vanessa Stanton is over there captioning. Woo! Yeah. So we decided to talk real quick about captioners. How do you do that? And art we always are jokingly saying, I have no idea, because that's just how we roll. The steno court uh keyboard is shorthand. That's how we write. I actually brought one of my keyboards up here It looks like this. So you can see that there's the letters on the standard machine up there, but there are no letters on this keyboard. So the first thing you do when you're learning stenography is where are the letters? And then you'll also notice that there are not all the letters on the keyboard. So we use combinations of letters like a T and a K as a D.
Speaker 2: In this clay case I put up a bunch of good examples like the word fish is T-P-E-U-R-B. Makes perfect sense, right? Yeah? Alright. So that's uh and the way I read that is F -I -Sh And then we also can write brief forms. So I put up a couple that I use and I know Vanessa and I write completely differently. So if I were to hop onto her machine and hop onto her software. it would come out with a gobbledygook and it would be kind of entertaining. Um and then we also can write phrases. So we can if we know a phrase is coming, like people say things all the time, you know, the same time we write is how I read that
Speaker 2: but again I'm uh fluent in this language of stenography Now, we also have, you know, these are the keyboards. So this is Vanessa. She is a TikTok star as far as I know. because I don't do TikTok, but um she does a lot of um demonstrations and things. So I would recommend getting onto her TikTok and I'll have that at the on the last slide. Uh I'm not running too bad on time. Yes. So Django, how do we write it? I write it. All those letters and Vanessa writes it, all those letters. And can you spot the difference? She uses a long vowel. like jing because that the skwr is a j
Speaker 2: obviously and the a and the pb is a n and then a g. So I write it jang and she writes it jang. So obviously I'm writing it correctly. Okay, so if you want to learn more, there is a thriving open source community, um, openstenoproject. org, and there is free software. So Plover is the free software and it was created by set software developers but encouraged by Mira by Knight. She really tried to Um Rhydda, but she was she's not a developer, she's a stenographer like me. Um so and that's the other question we get all the time is how do you know all this lingo? And we're like, well, we just know the words. We really don't know what y'all are talking about. No offense Uh okay. Um but the other thing like I pointed out on here, if you're working on Plever
Speaker 2: and if you could make Plever talk to an encoder, that's like they use on TV stations and things. That would be wonderful because that would open up to a lot of people because the the bad thing about these machines and the software that we use is it's really expensive So in order to diversify the number of people, the amount of people, the type of people we get into the court reporting and captioning industry , I feel that we need to make it a little less cost prohibitive. And feel free to say hi to Vanessa and I. We are very f very friendly 93. 6% of the time. You can guess who's bringing down the uh The average there. I could get a little uh
Speaker 2: testy sometimes. But if you want to know more, um, we are with Whitecoat Captioning at this event. And Vanessa is on Miss Steno on Twitter, and you can also search that on TikTok. She's at Honti. And she has awesome videos. She is way better at social media than I am. I'm at Asignia. A little political political, so watch out. Um but yeah, so that's that's what we do. And if you have any questions, feel free to come up and ask. And I managed to get done in time Thank you.
Speaker 3: Okay, hello. I'm talking about Scorpol today, which is a machine learning system used in politics. I work on a project called ActionKit. ActionKit is a toolkit for online politics. It's built in Django. It does all the things that you see politicians doing online. It takes contributions, it sends mass email. It sends texts, it collects petitions, it sets up events. It's used by a lot of the biggest progressive campaigns, Bernie Sanders, Beto. AOC, et cetera, and some of the biggest nonprofits out there in the progressive space, moveon. org, color of change, ACLU. Over 150 groups use our system. Deliverability is a huge challenge for our clients. Anybody that sends a lot of email knows this. It's getting harder. ISPs are tightening up.
Speaker 3: They don't want all the spam in your inbox. You don't like spam. They like you, they don't like us. Um, and they're reducing the amount of data they give to us, for instance Apple's MPP program and others. And spam filters are getting harder. They used to be content-based. Like if you weren't talking about Viagra, no big deal. They're not going to catch you. Now it's largely behavioral. So ISPs are looking at how you interact with your email. Which emails do you open? Which ones do you click on? Which ones do you forward to your friends? And the conclusion is if we want to be deliverable to these ISPs, if we don't want to get blocked, we need to send email to people that want to open it And that's just good business because those are the people we're trying to reach. We're not trying to reach you if you're not interested. And so enter a Score pool. This is a machine learning system. It uses aggregated data from all of our clients that want to be involved
Speaker 3: It's an optional feature in ActionKit. And it is the goal is to predict people's likeliness to engage with email that we send them. So are they a live address? Are they reading their email? If you're not, and if we can figure out that you're not, we don't want to send you an email and we'll improve our deliverability by not doing that. What goes into Scorpio? It's a machine learning system, so it needs lots of data. Anybody that does machine learning knows that this is the hard part. Getting all the data that goes into Scorpol is user data. You know, when did we when did we meet you? What email domain do you use? Have you opened, clicked? Have you taken action before? Have you unsubbed? Have you bounced? We also look at what happens with transactional mail, so not just the bulk stuff like the. Mail you get after a contribution, for instance, did you open it? Did you click on it? Um it doesn't have any
Speaker 3: user identifiable data, so it's uh it's a uh relatively privacy-safe system. Now of course, you know, there's always questions about that. How do we build this? So in ActionKit, every client has their own database. They all basically have their own little Django thing and it's separate. It's siloed off from the other clients. So let's say you had 150 clients, 150 databases, it's going to be hard to build a system like that without aggregating the data. So here we used Amazon Athena, which offers a great way to do this. And we do that by building org files. If you don't want to know what an org file is, I highly recommend looking at the spec. It is fantastic. It's like a little database in a file. We upload those to S3. We build them into Athena partitions. And then we get a SQL layer called Presto that Athena wraps around, which wraps around Hadoop queries. So you fire off an SQL query, Athena turns that into a Hadoop.
Speaker 3: Cluster operation, it's super fast, it's it's crazy powerful. Um the other thing I'm using is Scikit Learn. And if you ever want to do machine learning in Python, you could don't go anywhere else. They have an incredible selection of tools. Awesome tutorials. It's built on top of NumPy and Pandas, two of the most awesome and amazing Python libraries out there. I ended up using up something called the random forest classifier, but I tried a bunch of different options and maybe there are even other options that I should be trying. The output is for every user we send through the system, we get a score from 0 to 100, indicating how likely they are to engage. And that gives our clients the ability to target based on that information, say, I don't want to send to people that are only 10% likely to engage. or 20% likely to engage. And it's been pretty good. It's been about 80%
Speaker 3: accurate, which I think blew me away. I didn't think that it was possible to get that good. I don't have a lot of time to go into exactly what this looks like, but this kind of shows that the system is working okay. It's you know it's giving an unengaged score, it's giving a low score to people who mostly don't engage and a high score to people who mostly do engage. And it's better at figuring out who won't engage than who will, which is a reflection of how I build the system. If you're curious about this, if you want to know what it's like to work in politics, uh come talk to me or email me, sam. tragar at ngpvan. com. Uh or you can check out our site, actionkid. com, and we're always looking for smart people who'll want to work in politics. So that's my talk.
Speaker 4: Right. Hello, my name is Chrissy Wainwright. I work for Six Feet Up. I've been with them for several years now. So this is my first Django Con. I've been a part of the Plone community for many years. How many of you are familiar with Plone? A few, all right, cool, cool. Um so yeah, I've worked on a few Django projects over the past few years, but recently had the my first opportunity to work with Wagtail. And Koja already asked my question of how many people have used Wagtail. So I'm hoping part of this will be helpful for you to see like what Wagtail can do and also learn about some of the new features of it. I did write a blog post on this, so I have that up right here. If you go to sixpeedup. com slash blog, it's one of the top ones there
Speaker 4: to get more information. So I'm going to talk about, you know, we took advantage of some of the new features that are available in Wagtail 4. 0, which is compatible with Django 4. 1. So, you know, both of those recently came out here in the last couple months. And we had this project, finally one where we were able to you know make use of wagtail and specifically the snippets so the the snippets are like one of the cont kind of a content type in Wagtail um where you it's for like admins are able to add in whatever code that they want. So if we look inside in here.
Speaker 4: Just to show you what this looks like in here, there's not much to it. I mean you can add more, it's a model that you create. Um, but basically like have the ability to add whatever code you want in here. Um this can be dangerous, so that BY only admins can do it initially, so you don't have users that have permission to just add whatever JavaScript that they want. And then this can be reused in other parts of the site. In our case, we're taking these bits and actually displaying them into a separate site. So what we did with these, um I'll show you first how the model is created so like i said the snippet isn't
Speaker 4: it's not a model in itself but it uses this register snippet decorator that you add onto it Take that out. And then the new features that we used in Wagtail 4. 0 were being able to add, we added this draft state mix-in, revision mix-in, and previewable mix-in. So having that workflow of the draft to be able to have snippets either be in a draft state or in a published state And then the revision mix-in kind of goes with that so that you can see the history of changes that have happened with that particular snippet or you know whatever model that you are using. And then the previewable mix-in. gives you a little window to be able to see like okay what does this actually look like it renders the HTML for you. So this one we don't have much to it.
Speaker 4: The content field which is a text field and that's where we're entering all of our HTML. Uh the revision mix in, you also add uh revision field for that. And so then back in the site, I'm an admin right now, so I can do all of the things. You can see I can save this as a draft. I also have the option to publish it or unpublish it. And then going back on the list of all of our cards, you can see the status over here of whether it is live or if it's a draft. This icon up here in the upper right is the preview, so I can see you know exactly what this looks like.
Speaker 4: It's not very fancy. I don't have any custom CSS in there right now. But it is showing the rendered HTML to me. So something else that we wanted to do with these cards was add different permissions for it. So like I said, by default, only admins can do things. But inside of Django, or sorry, Wagtail, we have these groups. By default, there are editors and moderators, and we wanted to apply additional permissions for these two to be able to do things with snippets So like with editors, they are able to, we want them to be able to add card layouts and change them. And then moderators also have the option to publish. And these I then applied with
Speaker 4: a migration of applying all of these. And this code is in the in the blog post. The only custom thing we did, so if you can see in the site, under custom permissions is where the publish one was. And so I have this publish card commission here that then will let you apply that. And that one I'm I was surprised it just kind of magically worked. I don't know if there was anything special there, um, but I have test to make sure that everything is fine. And you were you hear you're gonna finish the talk for me now? Yep. Okay.
Speaker 5: Blacktail's great, everybody should use it.
Speaker 6: All right, my title today is Ma How I Killed My Sight with a Goat Chief. Um so this uh whole situation started out when I write it wanted to write a blog about testing. For those who are not familiar with Harry Percival's fabulous, fabulous book, Test-Driven Development with Python. There is a character in it that he calls the testing goat, like fear the testing goat, obey the testing goat. always test with tests and the testing goat. Now this is going to be the one time that I show you a GIF in this entire presentation. So if you're averse to movement, this is your warning to look away right now. I went and found a GIF
Speaker 6: that I wanted to include in my blog post on my Wagtail site. And, you know, I thought this one would be a pretty cool one to include. I checked it to make sure that the size requirements were below the limit that I set on my site and things like that, thinking, yeah, this will be no problem whatsoever. So some details on the site. Fortunately this was not a site that anybody but me cared about. It was my personal site. Right now I'm running Wagtail 2. 13 on that. Please don't tell my employers. But it's on a digital ocean droplet too. This is the first time I've ever had to manage a Linux server on my own, which was also a fun experience to set up. But I got Ubuntu, Gunicorn, Nginx, uh and I was pretty much running like the cheapest available
Speaker 6: level that you could get with a digital ocean droplet. So about five, twelve megs of memory. 10 gigs of SSD. And so the point being that that's like the lowest of the low. And it turns out that matters. So what happens? What do you mean part of my slide didn't I apparently did. What do you mean? Ah show anyway. Can you do that? Thank you. I don't care. All right, as long as the clicks work. Well, apparently I did break it with the goat
Speaker 6: chif because what what you're supposed to see is the goats, uh but not gif that it's just a screenshot, Google. What's wrong with you? Uh but the point being that I uploaded the GoatGIF, my site did that. Um what happened is I like could still log into the admin section of my Wagtail site, but there were Nginx errors all over the front end. And I was just like, I have no idea in the gobbledygook of logs that I got out of this situation what's going on. Uh and this is where like Paying the extra dollar a month to DigitalOcean for backcro bac for backups really saved my butt. And so I I restored the backup, uh, but being the person that I am, I'm like, you know what?
Speaker 6: Let's see if it really was the GOAT ChIF. So I uploaded it again and crashed my site twice just to confirm that it was the actual GIF that was causing the problem. And it turns out it was. Um I went on to the community and started a discussion because, you know, I'm new enough to this and I've never dealt with server issues before before and I'm like, what is going on? Why is an animated GIF like these things that they use all the time across the internet crashing my site? And I learned a lot actually about how GIFs are managed on the back end and about how they really can be chaos engines to the point where like people are creating memes like this.
Speaker 6: Um, you know, this is from a uh blog post called Gifts Must Die by Paul Bacchus. Um It turns out for GIFs, it's not just size that matters, it's frame rate as well. If you have a GIF like I picked out here that has a lot of frame going by really quickly and if it's sufficiently long that can cause issues on your server. So the lessons from this are don't cheap out on memory, spend some money on it, also spend some money on backups. Consider converting GIFs to something else. A lot of people will convert them to videos or W WebP files these days, so that's something to consider in your setup of your site. And the final thing is please go check out Wagtail. It's lots of fun whether you build some cool things with it or you break it
Speaker 6: like I do.
Speaker 7: I'm David. I traveled here all the way from Poland, so my jet luck is so big that I think five minutes is like long enough to give a luck. Yeah, so today I wanted to tell you just a little bit about how to find those small things that can really affect your test performance. Because like when it's like git kommit, then you make a coffee and it's back coming back is it's fine, but when you du get a pizza delivered, eat it and it's key going on then something gets wrong. So your tests are most usually if they are written in Python, they are also Python code. So what can you do to it? You can profile it. So you can run the profiler. But yeah, the profiler in just on its own
Speaker 7: not much like of use like some text data. So we have to visualize the results. So for example you can uh use gproof to dot and like get those results in manageable format. Then you just like run and create a graph from that so you can actually visualize the results. Yeah, and then the hard part you have to find find the issues. The good thing here is that they color those, right? The things that take most take up most time go in red. So how Hopefully I can yeah zoom in. Yeah, it will be easier, right? So this is a like close to real production stack from the tests, from a real code. So it was a pretty big code. So it just yeah But then all of a sudden you get into the run cases and
Speaker 7: like all are like dark, right? They don't take up much time. But they all come into single point, right? So then we zoom in again, right, and we follow it. When we are setting up dealerships, it takes over f fifty two percent of the code execution. Why is that? Then I you just like follow the dots, try to make some some sense of it. Yeah, zoom out because it's hard to navigate a little bit. Yeah. And here right he di was a culprit in this pay in this case, right? A signal was added to the code which logs each safe. And it was running for all tests, all models, and was taking up fi 50-48% of its execution. Because the signal itself was pretty well instrumented. It was also it also had its
Speaker 7: own tests. So it was safe to disable this signal in the production code. Then the resulting neutral, right? There is like no a big green or like so everything seems like to be in some way like distributed among more all the tests. But was was this result? We came in from like 30 minutes on the tests to 14 minutes. So that's fine just for for disabling single signal. But if you just looked over the each terrorist performance, no none of those were slow, right? They were just like behaving weird and it was hard to like spot that at At first like it went like for weeks
Speaker 7: basically until like someone me in this case scared that this started taking up too much too much time And we didn't add that many tests like in the meanwhile, maybe a few hundred, but yeah. It shouldn't affect that way So if you would like to like check just the comment the comments, like try it yourself profile. showing maybe this should like could work the same way if you run just your the your manage pie with test and check like what's happened there or it look out those graphs so possibly it could end up the same way. Thank you.
Speaker 8: Hello everyone. My name is Gajindradesh Pandey, and today I'll be giving a lightning talk on the 12-factor methodology for Django application development. What are 12 factor apps? What and why? So it's popularized by Hiroku. It's used to develop stateless web applications, suitable for web applications and SaaS-based cloud applications. And we know that Django is used for web application development and it can be used for apps written in any programming language and any backing service. So, first one the first factor is the code base. So, one code base tracked in revision control and many deployments are possible. So, every app should have a single code base Multiple deployments are possible.
Speaker 8: Say for production staging, then single app, multiple code base is a violation of the 12-factor methodology Distributed system, each app must confirm to 12 factor methodology. Second one is the dependencies A 12 factor app never relies on implicit existence of system-wide packages. It declares all dependencies explicitly via dependency declaration. So if you are using Python then you have to use p file and pip env and it has to be uh described using T O ML It uses dependency isolation tool during execution to ensure that no implicit dependencies leak in from surrounding system. Then third one is the config
Speaker 8: So, configuration is defined as anything that can vary between deploys of a code base. So, apps sometimes store config As constants in the code. So this is the violation of 12 factor. So the solution is use environment variables. So you can set the environment variables in settings. py Then next is the backing services. So a backing service is any service that app consumes over network. It can be a data store, it can be a queuing service, it can be a caching system. So the code for 12 factor app makes no distinction between local and third-party uh services. Resources can be attached and detached from uh deploys
Speaker 8: at will. So to achieve in Django, we need to change the Where connectivity to the database is configured. This happens via databases dictionary in the settings. py file. Then fifth one is the build, release, and run A code base is transformed into deploy through three stages that is build, release, and run. So the 12-factor app uses strict separation between the build, release, and run stages. Then sixth one is the processes. So here the 12-factor app methodology emphasizes applications as standalone processes that are stateless and share nothing. So at asset uh packagers like Django asset packager use the file system as a Cache for compiled assets.
Speaker 8: Then static asset measures like white noise can be used, which allows web app to serve its own static files. Then seventh one is port binding. So web apps are sometimes executed inside a web server container. So The 12 factor app is completely self-content and does not rely on runtime injection of a web server. So here web servers such as tornado , green unicorn and uvicorn can be used. So here basically we map the server web server to a port number Eighth one is the concurrency. So in twelve factor app, processes are first class citizens. So processes In the 12 factor app takes strong cues from Unix process model for running service
Speaker 8: demons. So using this model the developer can architect their app to Handle diverse workloads assigning each type of work to process type. For example, HTTP can be handled by the web process Ninth one is disposability. So here maximize robustness with fast startup and graceful shutdown So tenth one is dev slash product parity, keep development, staging and production as similar as possible. And you can see here that uh basically the tradition uh the time taken by traditional app and the 12 factor app. So 12 factor app always takes less time 11th one is the logs that is treat logs as event streams and twelfth one is admin processes run admin or management tasks as one of resources
Speaker 8: So you can go through these resources. There's a site that is 12factorapp. net. So it documents all the information. Yeah, thank you.
Speaker 5: So hello, I'm Rahul. Um I'm a software engineer at Hoover, and Hoover is a Event management software company that's based right here in San Diego.
Speaker 6: So I live 15 minute drive from here And yeah, I'm here to talk about a specific problem we had at the company and how we solved it. So it has to do with session cookie domain. So first before we talk about that, we can talk about how just review Django session management. And so Django uses uh Django manages user sessions through the session middleware middleware. And how it works is this middleware. So we have a client and a server. And first the client sends a login request to the server. And then assuming that the login was success and everything went well, server will reply um in the middleware, in the session middleware, the server will
Speaker 6: um res uh attach to the response a cookie that says, you know, it's or some hash about it's the user data and it sends it to the client and it also attaches a domain. So for our example it's going to say whova. com so that the client knows in the future when I send requests to whova. com that I should be Sending this cookie along with it. And then yeah, this is what this is doing for future requests. The cookie will be sent along. to the server. So we had a popular feature request from our organizers. One of them is so typically our events on our platform, this is the kind of URL they use, event. or yhova. com slash sum Event ID which is a randomly generated string, so it looks not very pleasant.
Speaker 6: And then they said, hey, we'll pay you more if you let us customize the URLs. So for example, DjangoCon could have done DjangoCon. com. And right. And in order to support this, we have some technical challenge, and that is the client does not attach the session cookie to requests send to subdomain. huva. com. So we need to modify the session cookie such that the cookie will be usable on hoover. com and subdomain. huva. com. So and we also have this other restriction that this is that we want to ensure that the users are not prompted to log in again when navigating from whova. com to a subdomain. So existing users who already have the Huva.
Speaker 6: com domain cookie, they're when they eventually click on a link that takes them to subdomain. huva. com, they're going to get prompted to log in again, and we don't want to want that to happen. So our first solution is updating the session cookie domain. Simple, right? This is what's recommended by the Django documentation where it's like if you want this kind of support. add this dot in front that should support all subdomains as well. So does this solve our problem? No. Because users already have the hoo. com cookie will not receive the updated cookie and they will never be
Speaker 5: or they will be prompted to log in again when they try to access subdomain. huva. com And this we don't want this to happen, so this is not enough as a solution. So we're gonna build on top of that. And our solution number two was to add custom middleware to force cookie update. So right next to the session middleware that we just talked about, we added our own Huva session middleware. And
Speaker 6: it does something very simple
Speaker 5: where it says Hey, if there is a session that's active and it's present , set this flag, modified flag, to true. What this does is as the response is being processed Um through the session middleware, this will force the session middleware to give out new cookies. So does this solve our problem?
Speaker 6: Yes, because
Speaker 5: Even for users who are sending requests from Huva. com, they'll be forced to reach the uh receive this new cookie and it'll be attached to the session uh to the response. And but are we happy with the solution? No, because this will add quite a bit of overhead because every single request will be will be will be generating a new cookie for the request. So our final solution was to use a new session cookie name as well, because this lets us distinguish between users with old cookies and the new cookie So we made a lip a minor adjustment to our middleware that checks if they already have this um new cookie or if they're still are using the old cookie, how to
Speaker 5: um replace that cookie with our new one. So and then all right. Feel free to talk to me about any questions, comments, concerns. Thank you.
Speaker 6: As Kojo said, I was g I was going to talk to you about ten reasons why you shouldn't be a youth mentor because you would probably be a bad one. And then I thought about it, and actually I think you would probably make a great youth mentor. Because it turns out that hanging out with kids is a lot like hanging out with other coders. And I'm gonna tell you why. I have been I've been a big sister with big brothers, big sisters for the last eight years. I've had the same match that entire time. Um
Speaker 4: Alex is not her real name, but I'm gonna call her Alex for the purposes of this talk.
Speaker 6: Um and it has become one of the most important relationships in my life, and I just want to encourage everyone to to think about doing this in your own community. Um, as Drew said this morning, we need more volunteers pretty much for everything. The pandemic was really hard on children. It was really hard. on programs that depend on volunteers to donate their time, especially. And so mentoring programs also suffered for that. So now is the great time to get involved in mentoring in your community. I'm not going to go through the benefits of youth mentoring. That's something that is Googleable, but I have screenshotted it for you here and I encourage you to Google it for yourself. You can also Google benefits for the mentor too. It's good for you to be a youth mentor. First of all, kids appreciate the design process. They like to design their experiences just like we do.
Speaker 6: For example, you get to decide what you're going to do with the person that you're going to be spending time with, with your new small friend. So for example, Alex and I were deciding to make cookies and we we went through that process together to design exactly the cookie that we were going to bake together. They were really tasty by the way. Kids appreciate the risk analysis process. They care about their own security and their safety. So for example, whenever Alex's mother got COVID, she knows that that means that we can't spend time together. And she reached out to me to let me know that And she also anticipated what I would ask her.
Speaker 2: That's why she said that her mother had everything that she needed and she was feeling better because she knew my first question was going to be, what is it that you need from me?
Speaker 6: What can I do to help you? Kids take joy in discovering new things. They like to do new stuff. And they want to respect your ability to have those positive experiences. So for example, you can get into a new to you show such as Riverdale, which jumps the shark so many times. Oh
Speaker 2: my gosh! So uh Alex got me into this show and I was I was texting her about my my impressions and as you can see she started to give me a spoiler but when I told her no spoilers she respected that which I appreciated. Kids like new stuff. They want to play with your new stuff. If you have like a Raspberry Pi or a Switch or something like that, they're gonna want to figure out how to play with that with you. They're also good at making sure that you are adopting whatever the latest technology is. Um I I
Speaker 6: don't know what all the new iOS settings are, but I have Alex there to help me with that, for which I am eternally grateful. She keeps me cool. Kids understand project trade-offs. So for example, we were making friendship bracelets and I was running late, but I had told her that I would bring not only thread but also beads and I had to buy beads and she got to make that trade-off choice. Do you want me to be A little late with no beads? Do you want me to be really late with beads? She chose the beads.
Speaker 2: Kids ask for help and they really like it whenever you give it to them. Um Alex, I've been her big sister since she was seven years old. She's now fifteen and her high school has a program where she does a work study at an architecture firm. And she was really nervous about it. She went to her first meeting and she had a lot of questions, but she wasn't sure what she was allowed to do and she was telling me about it and I asked her if I could give her some advice and she said yes and I said Ask your boss, you know, like I've I bet the answer is that you get to ask questions in meetings, but if you're not sure, you can ask your supervisor. And it turns out that was exactly the right thing to do. And she appreciated that feedback and implemented it. And that was This is honestly one of my favorite recent moments as a mentor is taking something that she was really scared to do and making it easier for her.
Speaker 2: Kids are also awesome teammates. They are caring. They they want to be a good part of your life as much as you want to be a good part of their life too. Um so I had to cancel an outing that she and I had together because my child was sick and she wanted to make sure that my child was okay and to let me know that I had not only her support but her family's support. So the relationship is not just between me and her, it's also between me and my family and her and her family. And that's just been such a joy. Kids like refactoring just like we do. And kids are not shy about letting you know what they want to refactor. Alex and I bake a lot together. And we we iterate. We like to figure out what is gonna work. So for example, if you're making lemon bars with a mixed berry sauce, they will taste better with a graham cracker crust as opposed to an Oreo crust.
Speaker 2: And you didn't know that before now Kids want to test.
Speaker 6: Kids like testing. They like testing you. They have hot takes like red vines being better than Twizzlers. Alex is wrong. We have been talking about this for eight years. She won't budge and neither will I.
Speaker 2: Kids also like to celebrate your milestone. So for example, they like to uh use a lot of emojis to talk to you and tell you Happy New Year and to celebrate the the other important events in both of your lives. If this sounds interesting to you, there are a lot of ways to be a youth mentor.
Speaker 6: I'm going to keep talking while I shut down.
Speaker 2: It doesn't have to be a formal relationship, so
Speaker 6: like with but with Big Brothers, Big Sisters, but please come chat with me about it. It is one of the best things that I do. So
Speaker 5: thank you, Lacy.
People may assume AI has mysterious or super-powered capabilities and make bad decisions, such as trusting systems to predict who will commit crimes. The public needs an accurate mental model of AI's limitations.
Discussed at 3:28It can be a useful metaphor when speaking with engineers who understand that AI is ultimately mathematical machinery. With people who may take the metaphor literally, it is harmful because it encourages exaggerated ideas about what AI can do.
Discussed at 5:02Stenographers use combinations of keys rather than individual letters, along with shorthand forms and phrases. For example, a combination of keys can represent a single sound or an entire commonly used phrase.
Discussed at 5:09The Open Steno Project provides an open-source community and free software called Plover. Captioning machines and software can be expensive, so making compatible low-cost tools is important for broadening access to the field.
Discussed at 7:26Scorpol is an optional machine-learning feature in ActionKit that predicts how likely each recipient is to engage with an email. Campaigns can avoid sending to people unlikely to engage, which helps prevent blocking by increasingly strict ISP spam filters.
Discussed at 11:09It uses aggregated behavioral and account data, including email domain, opens, clicks, previous actions, unsubscribes, bounces, and engagement with transactional messages. It does not use personally identifiable data.
Discussed at 11:09The system produces a score from 0 to 100 and was about 80 percent accurate. It was particularly good at identifying people who were unlikely to engage.
Discussed at 12:43Wagtail 4.0 lets snippets use draft, revision, and preview functionality. Editors can keep snippets unpublished, review their change history, and preview the rendered HTML before publishing.
Discussed at 16:27Wagtail groups and custom permissions can limit actions by role. In the example, editors could add and change card layouts, while moderators also received permission to publish them.
Discussed at 17:57GIF processing depends not only on file size but also on frame rate and the number of frames. A long GIF with many rapidly changing frames can consume enough server resources to overwhelm a low-memory server.
Discussed at 23:18Use more memory and reliable backups, and consider converting GIFs to video or WebP. The speaker also recommends not judging a GIF only by its file size, since frame complexity matters too.
Discussed at 23:18Profile the test run and visualize the profiler output as a graph. Following the nodes that consume the most time can reveal a shared setup function or signal that individual test timings would not make obvious.
Discussed at 24:56A signal that logged every save was running across all tests and models, consuming roughly half of execution time. Because the signal had its own tests and was safe to disable in that context, removing it substantially reduced the suite's runtime.
Discussed at 26:27It is a set of practices for building stateless, cloud-ready web applications. Its twelve factors cover code bases, explicit dependencies, environment-based configuration, backing services, build/release/run separation, processes, port binding, concurrency, disposability, environment parity, logs, and admin processes.
Discussed at 27:52Configuration that varies between deployments should not be hard-coded as constants. It should be supplied through environment variables and read by Django's settings.
Discussed at 29:25The speaker says mentoring is a deeply important relationship and encourages people to volunteer because children and volunteer-dependent programs were especially affected by the pandemic. Mentoring also offers familiar experiences for programmers, such as designing activities, assessing risks, learning new things, and making project trade-offs.
Discussed at 38:04Children often enjoy designing shared activities, thinking about safety, exploring new technology, and making trade-offs—activities that resemble software development. They also ask for help and can benefit from practical advice, such as asking a supervisor questions at work.
Discussed at 38:54Note: We understand that names change, people change, and bodies change. We respect each individual's journey and privacy. If you have any concerns about a video or need us to remove content, please don't hesitate to contact us. We will handle your request with care and promptly address any issues.
Published July 15, 2026
Published July 15, 2026
Published July 15, 2026
Published July 15, 2026
Published July 15, 2026
Published July 14, 2026