To some extent, you might say they are like Cassandra; speaking the truth but not believed or listened to.
To some extent, you might say they are like Cassandra; speaking the truth but not believed or listened to.
I mean, maybe it's not too much charisma but I'd be glad if I had only like 10% of that...
But I believe grandparent didn't mean they lack charisma, but that they didn't have enough to swerve the general public.
impact = charisma * funding
so .1 charisma score of some faceless tech exec * 1B in VC funding goes alot more than 2.0 charisma score * 50k of grasroots funding.. funding = charisma * suitability for capitalism
so .1 charisma score of some faceless tech exec * 1B in VC funding goes alot more than 2.0 charisma score * 50k of socially oriented funding..1) He's not a hypocrite in any way. He's honest and you can tell that he has truly thought about his opinions.
2) In my country, I get bombarded with a ralentless stream of leftist ideology. The worst kind of leftism: the lazy 'slogan' leftism, from people too stupid to realize the full implications of their discourse. In comparison to them, Stallman is a moderate, thoughtful, sweet person.
3) I see his leftism as orthogonal to his software freedom ideology. I use and support free software, and I'm more pro-capitalism than Milton Friedman.
I think that's crucial. I remember he was discussing one of the aspects of software freedom with my friend and she said "I don't agree." He answered: "No problem, you have your view, I have mine, we don't have to agree on everything."
It struck me as I had expected he'll try to convince and win her over his ideas.
You need somebody as guideposts to stand at the extreme ends. I am glad RMS stands at his end.
They aren't meant to be widely adopted, but mean, rather, as a critique of the status quo.
Charisma means being able to persuade all kinds of individuals, regardless of their inclinations and initial positions.
Right now, only the people worried about paying more for performance, dev time, or security engineers are listened to. We need the legal teams inside companies to have something more substantial than possible negative publicity with which to motivate the CEO and CTO as a countervailing balance.
Just like the majority of industries, we need real negative consequences for when we dump incompetent code out into the world. We've tried the "no consequences at all" plan for a long time and it's gotten us, well, continual data breaches via the easiest possible things to control. S3 buckets and databases open to the world. An inability to patch known CVEs in under 3 months (hi Equifax!).
You also end up creating a lot of really perverse incentives, like nefarious companies not disclosing data breaches because disclosing them would result in liability even though that's necessary for the victims to take steps to mitigate the damage. There's a reason the NTSB does no-fault investigations.
And a lot of mediocre but still harmful incentives like cargo culting decades-old security checklists to satisfy compliance requirements even though they don't actually result in improved security, but do create a false sense of security.
More than that, the problem is that humans are fallible, so even if you do 99.9% of everything right you can still make a mistake. A company with one security vulnerability can get just as compromised as a company with ten thousand. Does it really make sense to destroy OpenBSD with fines as soon as they have one security vulnerability? Or every random company that uses OpenSSH on a day that a not publicly known 0-day is being exploited in the wild? Or a company that updates to the latest version of some software that claims to have fixed a CVE even though it didn't?
The real problem here is architectural. It shouldn't be possible for someone to breach Equifax and get all your information because they shouldn't have that information to begin with. They shouldn't exist. Your data should be yours, on your device, so that it isn't possible for someone to get it by breaching a third party because the third party doesn't have it.
For example, if Equifax faced a fine of $5B (more than 1/4 of their market cap) instead of $500M, you can bet they'd be more serious about audits in the future. However, we've conditioned business to expect minor consequences for breaches, so security becomes an afterthought. Likewise, the $5B fine against Facebook is unlikely to change anything, though a $200-300B (20-30% market cap) fine would be much more convincing.
The point isn't necessarily to ruin companies, but to set a precedent that says these types of issues will not be tolerated. It'll force companies to get insurance, and the insurance will have an incentive to avoid collection on the policy.
It also doesn't make any sense to base fines on market cap because the two things have nothing to do with one another. All that would really do is cause corporations to restructure their operations to separate the entity that does all the dirty work from the one that owns all the assets, so that the entity that exists in your jurisdiction and is susceptible to being fined is renting/leasing everything and has only a nominal market cap, whereas the one with all the assets is a totally independent company that isn't even in your jurisdiction and never does anything "wrong" because all it ever does is lease and license things to a different entity.
It also seems kind of obvious that even if you could try to impose a fine equal to 20-30% of a company's global market cap, all that would do is cause the local entity declare bankruptcy, dissolve and abandon your jurisdiction without actually paying the fine, because that large of a fine would exceed the long-term value of operating there. Especially when there isn't any guarantee it won't happen again if they stay. For that matter it would tend to make companies not want to operate there to begin with, because it's possible to do your best and still fail, and that kind of uncertainty is precisely how you drive businesses away.
But most importantly, it still generally isn't the large tech companies who are the ones with poor security. It's the other industries, especially finance and government, that are collecting just as much data but then doing a much worse job of securing it. What does a fine mean to the DMV or OPM?
Also:
> and google suddenly getting religion about you being able to mass-download your data.
They had that even before the GDPR.
And the smaller-than-FAANG companies... too many checklists, contracts and theater ("GDPR requires us to disable autofill on this form") and not enough actual rethinking what they're doing and if they should change their approach to data... so we'll still be seeing plenty of breaches where they shouldn't even be having the breached data
It'll probably be a decade before we see real effect from the GDPR...
With that as a barrier to entry , the only solution I could see working for security is: public domain hardware and software.
The only solution I believe
It seems like it might create some perverse incentives as the risk escalates.
If not, why do you think harsher punishments are needed here but not for crimes?
Street crimes have a far different cause and should be treated differently. I'm surprised I even have to type that, it seems obvious.
That's where we are atm with security breaches.
That's pretty exclusively the purview of white collar crime behind a corporation though.
Imagine if any other field said that. "Not burning people's houses down with electrical wiring is just really hard and we're really bad at it." "Keeping bridges standing is just really hard and we're really bad at it." "Flying across the country without killing any passengers is just really hard and we're really bad at it."
I only ask because that all makes perfect sense to me, but I see a lot of negativity about GDPR on here, that all it ever does is stifle innovation and produce ever more cookie-agreement popups.
I suspect when that happens the companies will launch a massive PR campaign and fight it in court but eventually lose. If they pull out of the EU or pay I have no idea.
Edit: seems like 4% of alphabets 2018 global revenue [1] is "only" 5.44 billion dollars. Wonder if it can be applied multiple times.
[1] https://www.statista.com/statistics/266206/googles-annual-gl...
There is a real social stigma with regard to committing robbery, burglary, breaking and entering, etc. I feel like there isn't so much with online crime. As a community we really pile the blame on the victim for not be prepared and seem to give the perpetrators a pass for taking advantage of the situation.
Also, there is a real tension between anonymity on the Internet and the ability to identify perpetrators. It is a difficult tradeoff.
It's not a tradeoff we can make because the nature of computer security is that unless you fix the software and networks, you can't even identify the criminals, let alone catch them, presuming they're even in your legal jurisdiction. There's a tremendous asymmetry between attacker and defender in terms of cost+benefit, and it heavily favors the attacker.
In any event, computer crimes are punished with an iron fist in the U.S. What's not criminally prosecuted and punished very well is harassment. Yes, if social media platforms offered less anonymity, we could deal with harassment easier. But organized criminal organizations don't need the anonymity of Twitter to pilfer and fence credit card numbers; they have the anonymity of zombie networks and stolen accounts. And you can't address that with harsher penalties. If you penalized that activity with summary execution, the problem would substantially remain. And in fact in some respects it could get worse by deterring security research.
We have no choice but to fix the vulnerabilities. We have to make it more difficult to execute these attacks from a technical perspective, dramatically increasing the likelihood of identification and capture, before we can even hope of using criminal penalties as a substantial deterrent. We're a long way off from that day.
IMO it's not that Linus has more charisma than Theo, it's simply the network effect of one project over the other.
The emergence of a GPL-licensed kernel was inevitable. If Linux didn't appear when it did, some other kernel would appear. Maybe folks would have more motivation to work on Hurd, and it would be the main kernel for everything now.
Its not really meaningful, because the firmware could be pretty much any arbitrary OS and it would make zero difference to any end user.
Tannenbaum himself didnt even know about Intel using MINIX in their ME firmware until recently, so that should show you how much relevance it has.
Not at all. MINIX was actually Intel's second choice, they tried first to fit Linux into their new x86 based ME. But the maintainers were uncooperative:
https://www.phoronix.com/scan.php?page=news_item&px=MTY4MzM
Intel then submitted similar patches to the MINIX kernel, which subsequently got accepted.
BSD licensed projects see plenty of contributions, they're just not as popular as Linux because of historical reasons. I and most BSD fans blame the AT&T lawsuit for BSD losing popularity and Linux gaining popularity. That being said, BSD is still quite popular, though somewhat niche.
Companies not upstreaming code will happen regardless of the license. Plenty of companies maintain Linux change sets because they're not obligated to release them, but plenty more upstream their changes when not strictly necessary. It just depends on the value proposition of releasing improvements.
TLDR is that prophecies are self-fulfilling. Tiresias is the OG self-fulfilling prophet.
1. Cassandra is usually at the center of attention, an object of desire to Agamemnon and his troops, an object of hatred and jealousy to Clytemnestra and Aegisthus. Tiresias isn't nearly as ostentatious, and mostly exists passively in the background, waiting until someone else asks his opinion on something. Tiresias gives off a kind of awkward vibe, much like Stallman, compared to Cassandra, who's totally a social butterfly.
2. Cassandra is cool and sexy, Tiresias is a blind old dude. Richard Stallman eats stuff off his foot and often looks like he hasn't showered since the last emacs release.
3. Cassandra's prophecies are very straightforward, Agamemnon and his buddies understand what she says and even listen to her to some degree, they just don't care enough to do anything. Tiresias is much more cryptic and is always derided until the denouement when it is revealed that he was right all along, just in a way that nobody else could have foreseen. Likewise, Stallman's insights into the future of our technological dystopia seem absurd and maniacal until they inevitably come true a few years later.
I like your comment though =)
Your assessment of charisma is foreign to me. I cannot imagine anybody who is more charismatic that these two men, theo and rms.