Ken Thompson really did launch his "trusting trust" trojan attack in real life
niconiconi.neocities.org
niconiconi.neocities.org
The virus looks for a Delphi installation, modifies the SysConst.pas file, which is the source code of a part of the standard library and compiles it. After that, every program compiled by that Delphi installation will contain the virus.
The virus does nothing else, it is therefore harmless if you don't have Delphi installed.
It resulted in many software vendors releasing infected executables without realizing it, sometimes claiming false positives. After all, the executable was not tampered with, the compiler was.
Quick googling tells me this happened in August, 2009... which was 13 years ago. Quomodo fugit tempus!
The key thing about the Karger–Thompson attack — the thing that makes it so scary — is that all your source code can be absolutely clean, you can recompile the compiler from clean source code, and you're still compromised.
But if you recompiled the Delphi compiler from an infected installation...
What made it as horrifying as it was at the time was the closed nature of compilers, and the increasing unfamiliarity with what actual machine code looked like, and the non-existence of tooling to help recerse actual runtime behavior.
Popping in a hidden 'hunter2' login handler is still going to require hiding/deriving/comparing against that state/hash/input on that machine. That extra cruft is going to stick out.
Whether anyone can be bothered to dig into it is another question. Theoretically speaking though, all computation is human reading or writing, just implemented with circuits.
But I think the situation now, relative to then, is precisely the opposite of what you state. The C compiler Thompson backdoored was distributed as source code under a fairly liberal (but non-transferable) license; its compiled form was only a few tens of thousands of instructions, including all the libraries it was linked with; the people it was distributed to were very familiar with the machine code; and single-stepping through machine code was a common way to debug problems. An old boss of mine had his first system administrator job about that time; his first task as a sysadmin, as I recall it, was to port a program written in assembly language to the operating system they were using.
By comparison, today, many people use compilers they don't even have source code for; GCC and clang are tens of millions of instructions; many programmers even in C, C++, and other such low-level languages don't know assembly; most programmers work in high-level languages like Python, Java, or JS, and those have even less familiarity with assembly; and there are some eight orders of magnitude more useless computation being carried out in which such a backdoor could hide.
These days you probably could sneak something in with a good chance of getting away with it for a while with the complexity explosion and volume of code to go through. That doesn't mean it isn't unrecoverable from though, even if every compiler is infected.
It's just painful is all.
More generally, when groups of people are engaged in a power struggle, there's no guarantee that things will return to the status quo ante.
Basic asm/REing is still CS101 in most civilized places
Ghidra helps a lot these days. ldd and the other linker/binutils do the rest.
https://www.mail-archive.com/cryptography-digest@senator-bed...
https://groups.google.com/g/sci.crypt/c/PybcCHi9u6s/m/b-7U1y...
btw is there any public archive of ~old usenet (say, through 1999)? I was trying to remember things I learned from on alt.2600 but groups.google.com says it's "banned".
Just wondering if there's a good way to programmatically search "old" records like these.
fyi: the self reproducing cpp was installed on OUR machine and we enticed the unix support group
but without quotes. I know it's quixotic but I kind of wish altavista was still working (now yahoo owns the domain name).Unfortunately the completer archives that people had (magtapes etc) got donated to dejanews (which later became google groups) or Google directly. This was about 20 years ago when Google was seen as a safe place to put that stuff.
We know better now
The archive.org alt.2600.mbox covers only 2002-2013. Maybe after google gets broken up, we'll discover that this data is still preserved, and can be liberated. We can dream.
> If one reads the original paper, one only finds a description of this attack as a thought experiment, leading one to conclude that any claim of a real-world attack by Thompson was an urban myth due to exaggeration.
This is true although Thompson gives some tantalizing hints in the paper.
In the introduction, he writes " I would like to present to you the cutest program I ever wrote." So he definitely wrote it and at least played around with it.
Later on in the "Moral" section, he writes "The moral is obvious. You can't trust code that you did not totally create yourself. (Especially code from companies that employ people like me.)"
This appears to be an admission but not quite strong or direct enough to validate he implemented and used the Trojan horse so it is great to read this post.
[1] https://csrc.nist.gov/csrc/media/publications/conference-pap...
> However, in 1995, Usenet poster Jay Ashworth, citing personal communications with Ken Thompson, provided strong evidence of the existence of a real-world experiment of this attack. Unfortunately, the full Usenet message is missing on the web. There are only quoted snippets of this Usenet post circulated around various blogs, reducing its authenticity.
> In 2021, I’ve rediscovered the full Usenet message after a search effort in multiple Usenet archives. My success was partial - it was still a repost by someone else, and I was unable to find the original message. However, this repost contains the full Usenet message, including complete headers and message body, with the poster name and its Message-ID, establishing the authenticity of the post beyond reasonable doubts.
Very cool to watch, indeed.
Perhaps we should go ahead and have a few hundred thousand emails printed with a special lasting ink on velum to pass it on to our successors ("Codex Electronicus"). On reflection, my own inbox is perhaps rather too nerdy - it would introduce a strong selection bias to posterity's view about us.
Do you have any evidence for this? Even assuming it’s true, doesn’t the volume of podcast/YouTube/email/facebook/HN posts more than make up for it?
Digital communications will decay and vanish beyond repair, leaving our current era's ephemera irrevocably lost to the ages.
Example: In my experience "The chad was good" and various jokes around "hanging chads" and "pregnant chads" still sometimes land with people who remember the 2000 election and Charlie's Angles, but anyone a little younger misses it.
Now I'm curious how many jokes in an episode of "John Oliver" or Southpark land even a year or two after the episode airs.
I run into this problem not just when watching old shows, but also when watching contemporary TV developed in other countries. Usually it's references to proper nouns I've never heard of, and I do often look those up, but even once you know what or who something was sometimes you'd have to be willing to go deep into various rabbit holes to really understand it.
Hello future people!
I just want to further call attention to this. We have the unspoken notion, an assumption that digital materials, once 'written' will remain forever.
And, for a short-term 'forever' this is true. Not so for longer 'forever', as the loss of the original Usenet post, despite replicated across many systems, demonstrates.
There needs to be bottom-up and top-down pressure for open data standards and also a re-thinking of digital ownership rather than digital licensing. We think people don't care, but the engineers who build these systems are a tiny minority, we only need to convince them to refuse to build walled gardens.
As I understand it, yt-dlp is considerably faster.
Downloading a handful of videos you personally care about is surprisingly affordable as a hobby. Mirroring and archiving the entirety of youtube is not.
Personally, although I couldn't say it was a hobby, I don't watch youtube on youtube anymore. Every youtube video I watch is downloaded first and viewed locally. I can't recommend it enough. Zero youtube comments, zero recommendations, VLC is a far better video player, Google has no idea how many times I've watched a video (or parts of it) or how I felt about it, and I never have to worry about videos I find valuable being removed. As long as I keep backing them up, I'll have them for as long as I care to.
For an enthusiast, a 720TB array is pretty reachable. A dedicated enthusiast can get a 1PB flash array in 2U.
It is probably possible to horde more Youtube videos than you could ever watch, probably including most of the ones that you might ever be interested in. And it is almost certainly impossible for any individual to capture every video which goes through Youtube.
Neither of these seem to address the issue of whether there exist videos which will retrospectively have archival value which are not captured.
Unless the entirety of youtube can be archived it's safe to assume that there will be something of value which isn't being preserved. It's an unsolved problem and not one Google wants to see solved.
That’s a really interesting question: how to determine videos that I might ever be interested in.
> whether there exist videos which will retrospectively have archival value which are not captured.
And that’s not really a question: there definitely exist videos that have a certain historical value which were deleted from YouTube, and most of them before I archived them cause I am lazy.
I would gladly pay for a personal archive.org - a solution that automatically archives each page I visited and video I watched. I guess the required storage amount will be pretty affordable.
> And that’s not really a question: there definitely exist videos that have a certain historical value which were deleted from YouTube, and most of them before I archived them cause I am lazy.
Sure, but you aren't the only one backing up YouTube videos. It seems at least plausible that the aggregate storage capacity of the entire data horder community and their propensity for backing up whatever they come across could result in a situation where if something is interesting, somebody ends up capturing it, right?
24 Mbps / 8 bit/byte * 60 seconds/minute * 60 minute/hour
= 10800 megabytes per hour of footage
= 10.8 gigabytes per hour of footage
At 500 hours of footage per minute, that means 5.4 terabytes are uploaded every minute. Your 720 TB array would be completely full a little over two hours' worth of content that is uploaded to YouTube every single day, day after day.At the current upload rate, 2,838.24 petabytes are uploaded every year.
I don't think you'll see hobbyist archives of YouTube any time soon.
[1]: https://www.tubefilter.com/2019/05/07/number-hours-video-upl...
[2]: https://support.google.com/youtube/answer/1722171?hl=en#zipp...
You're also going to limit to public videos (unlisted and private will make up some share of those uploads) and probably to those with non-zero views.
I suspect archiving only videos with >100 views would probably cut the amount you archive to 1/10th.
I'm aware that even a horde of data hoarders can't archive a drop in the YouTube ocean, but by archiving high-impact channels, they can backup both important and vast amounts of information.
> VLC is a far better video player
Not for my use case, but maybe someone here has a solution. I watch lectures and lessons, as I watch I will change the playback speed constantly. I use a Firefox add-on for keyboard control of the YouTube video stream speed.VLC also has keyboard control of the playback speed. However, when changing the speed VLC will skip a split second of audio. This drawback negates all the benefits of playing faster over the non-essential parts, because when we get to an essential part I'll lose some if it. This is on Kubuntu, across many versions over the years.
You can probably also create a single macro to do both actions with a single keypress although not with VLC alone which is fair enough since you're using an addon for the functionality you can't get with youtube's player already.
I quite enjoy using NewPipe on Android. Once you build up a list of subscriptions, it’s by far the most peaceful way to consume YouTube on a smartphone.
My neighbor has a collection of 12 years of city council meetings collected, for example.
e.g.
https://www.entrepreneur.com/en-in/technology/youtube-attemp...
https://www.makeuseof.com/tag/is-it-legal-to-download-youtub...
https://torrentfreak.com/major-record-labels-sue-youtube-dl-...
https://web.archive.org/web/20220121041452/https://www.nytim...
"I copied this page from the ACM, in fear that it would someday turn stale."
[1] https://web.archive.org/web/20080111144410/http://cm.bell-la...
https://bootstrappable.org/ https://reproducible-builds.org/
This would probably be a bit more difficult to pull off. If someone did pull it off, fully reproducible builds ought to make it readily detectable at least in the absence of some extreme rootkit contortions.
Reproducible builds wouldn't help here, since all binaries would be backdoored equally. They only help with situations where one build machine is compromised but another one isn't.
The much more common scenario would be bootstrapping something like Guix from within a running OS from a much smaller set of initial binaries than you otherwise might. And that host OS could in theory have been compromised. But I think that attack is a significantly higher bar than a compiler binary that compromises itself.
It's a valid question and has deep philosophical implications. Unfortunately, mathematicians are not tech workers, so they were not impressed, and closed the question as off-topic. I personally think the main reason resposible for the lack of enthusiasm from mathematicians is that formal methods are rarely used in our society, and mathematicians in general (with the exception of logicians) also do not really value formal axiomatic systems as the something especially important for setting a standard of truth. If formal methods are used in decision and policymaking in the far future, the picture will be different. Nevertheless, right now, malicious proofs are just a hypothetical thought experiment.
https://mathoverflow.net/questions/63816/consequences-of-tec...
First, the proofs were verified by a separate prover that was itself independently formally verified.
Second, the proofs were manually verified by multiple people. Once you know how to read first order logic notation (which is easier to learn than most programming languages), it's not hard to verify the steps by hand. The paper walks through the key parts.
For more details see the paper :-).
) we enticed the "unix support group"
) (precursor to usl) to pick it up
) from us by advertising some
) non-backward compatible feature."The more there are, the harder it would be to successfully execute this attack for any length of time.
However, it could and certainly has been done in specific targeted cases I bet.
That's exactly the point - a sufficiently deep supply chain attack can avoid detection just because no one bothers to look that deep.
https://dwheeler.com/trusting-trust/
This is an automatic process: you compile each compiler with the others a few times and compare the outputs. At the end it gives a criterion to decide which compilers contain trojan horses.
I'm the author of the DDC dissertation at https://dwheeler.com/trusting-trust/
If I understand you correctly, that doesn't counter DDC, as long as the system being generated is being covered by DDC.
If you're worrying about inserting code into "unused spaces" in the file that people typically call the "compiler", the solution is to check the compiler with DDC - that guarantees (given certain assumptions) that all of the executable can be explained by the source code. The source code could have malicious code, but developers know how to review source code.
If you're worrying about inserting code into "unused spaces" in other files of the larger system, the paper explains how to counter that too. Basically, treat the entire system as the "compiler" & regenerate it. More work, but now you've squeezed that out.
There's even a counter-example in the DDC paper. The tcc compiler had a subtle bug where 2 bytes were "free" (not controlled by the compilation process). That's because it was storing a 10-byte floating point value into a 12-byte memory area, leaving 2 bytes uncontrolled. DDC immediately detected a problem. DDC can detect 1 bit of difference. There's no "uncontrolled free space" for whatever is being verified by the DDC process.
Unlike most computer stuff, there's a mathematical proof in the DDC paper. If the assumptions hold, the conclusions necessarily follow. Attackers must take steps to invalidate at least one of the assumptions for the conclusion to fail. Of course, nothing is perfect - if an attacker subverts an assumption, then the defender can't rely on the conclusion. But the defender can take steps to make the assumptions true.
... if, of course, you also knew you could trust your examining tools, including the firmware and hardware. You can't provably do that unless you assembled the entire thing from transistor gates (and even then, you're still accepting somebody else's assertions about electron behavior in that material.) So at some point you have to just decide that there's some level of operations that you do trust.
These message keywords cracked me up.
How can we be sure that Ken (working for Google) didn't infect the toolchain used for Chrome to propagate that legend?
EDIT: just kidding - no "chrome-headless-c++ -c firefox.o firefox.cpp" (yet).
It does not.
There is no shared code between Firefox and Chrome. They use completely different rendering engines with independent histories (Chrome uses Blink originated from WebKit originated from KHTML, Firefox uses Gecko originated from Netscape originated from Mosaic).
The only shared component is that Firefox utilizes public APIs for Google SafeBrowsing.
Disclaimer: ex-Mozillian
The "on trusting trust" attack regards using your compiler as a mechanism to infect compiled executables -- including compilers themselves, and their generated code.
I didn't mean to suggest that the two browsers shared any code.
For some of these shared open source libraries, either Mozilla or Google is the primary contributor/maintainer, and both organizations usually make contributions. This is true across many things, even libraries in the open source space that are not involved in the browsers themselves but may be in the toolchain (Mozilla has produced robust open source CI/CD tooling, bug trackers, etc over its history).
ELI5: are you really sure that when you work on Firefox source code from VS Code, that what ends up in the saved file and what gets committed to Git is what you actually see on screen?
VSCode doesn't seem like a "on trusting trust" attack vector since we can easily observe the git outputs of the C/C++ source and these parts often reviewed by peers. Unlike object code -- we can always take a look at the disassembly but in practice it's not scrutinized.
It's probably frustrating to those who work on Firefox to suggest that it somehow depends on Chrome. I get that. But it wasn't where I was going.
There is some kinda-out-there reality though -- with something like WASM or v8 you can theoretically run real toolchains like gcc and clang "in the browser". ;)
> frustrating to those who work on Firefox to suggest that it somehow depends on Chrome.
Maybe those developers should not look too closely at who ultimately pays their salaries :)
Then again, perhaps he also infected all those fancy PCB & IC supply toolchains…
[1] https://en.wikipedia.org/wiki/G%C3%B6del%27s_incompleteness_...
All the other theorems (Gödel, Church, Tarski, Turing) are basically the same if you squint your eyes hard enough.
) writing to news just causes more
) misunderstandings in the future. there
) is no way to win.
Pretty amazing insight!
Old-timers like Ken Thompson clearly have understood the nature of a social network since a long time ago.
Although Ken Thompson is responsible for popularising the idea through his Turing award speech in 1984.
Edit: Ken Thompson mentions the paper in the acknowledgements of his Turing award speech.
""" Acknowledgment. I first read of the possibility of such a Trojan horse in an Air Force critique [4] of the security of an early implementation of Multics. I cannot find a more specific reference to this document. I would appreciate it if anyone who can supply this reference would let me know. """
Always neat to have lost sources show up eventually. Librarians rule.
Can someone cooler/younger tell me: Is this the hand-off to the new generation, or is there a meta-meme I missed?
I'm in my mid 30's. I started blogging about cryptography and security under my furry handle (and with blog posts adorned with furry art) at the start of the pandemic.
It gave me something to do that was both productive and fun.
The loop continues.
If you are browsing in dark mode, there is no background image. You have to switch to light mode to see it.
So I guess we now know the heathens who drive in light mode ಠ_ಠ
Too old for this shxt: 80-col formatted plaintext
Greybeards: LaTeX-generated PostScript
Modern professionals: HTML doc with default browser stylesheet
Kids These Days: Anime girl sidebardamn. Got me.
Because I’m tacky…
Did not happen.
I don't think so. This was the default GNU style in the 90s, but even they started using CSS at some point.
Definitely my preference, but too old? They will have to pry my keyboard from my dead hands.
I don't know if the screenshot was doctored, or if the Amazon recommendation engine found a real cluster of customers who are interested in both programming books and programming socks. In any case, I suppose it doesn't really matter because when people spread funny memes ironically it's only a matter of time before people join in sincerely without the irony.
In short the answer to your question is "both".
Notice that an anime girl holding a programming book is in itself a (mild) subversion of gender roles. The stereotypical programmer is male, and the stereotypical programmer is not cute.
I don't think that is going on here, you have to consider that the anime girl is holding the book towards the viewer, my guess is that the implication is supposed to be "Will you explain it to me".
This is not correct. It's hard to explain if you've never seen them in context but rather than "will you explain it to me" they are actually saying "won't you read this?" or "will you learn this language for me?" kinda note. They used to be commonly posted as OP image in programming threads on /g/ with lines like "have you read sicp today /g/?" or similar. There's also another very common variation of this meme for gamedev communities on 4chan with the girl from the anime New Game (see this[0] clip, I couldn't find the meme itself) with a similar vibe.
? Why? There's nothing that indicates this, the history behind these images shows the clear opposite. This to me sounds more like your (unconscious?) biases are showing more than it actually being a thing. Trust me, it's not really how this meme works. If you actually look at most images in that repo the girls are either reading the book, explaining the book, or clearly pushing it (often aggressively) towards the viewer to make them read it.
EDIT: Are you familiar with Serial Experiments Lain? I think that was one of the first ones to pop up with these.
Reflecting upon my own impressions and how these changed, I am more conscious of these points and find it hard to ignore them. Assuming that I am not totally mistaken, which of course might be the case, knowing that others don't see these things pains me. More so when someone like the author of the link publically stands by it.
But you are right though that not every image is like this.
(I'm kinda repeating myself in this thread a bit, sorry but...) I can guarantee you that the anime girls holding programming books has been a thing for at least a decade, so the 2017 creation of that repository doesn't really mean much. Not sure about the programming sock meme but I think it's a bit more recent. However I do think it generates from certain "battlestation threads" on /g/ where people used to post photos of themselves sitting at their PC with those knee-high socks on and the meme kinda spread from there. Way before that screenshot itself.
Makes perfect sense that a meme combining anime and programming would come from 4chan's technology board.
I suppose what made the meme interesting enough to spread is the subversion of the traditional hacker aesthetic. Having a beard voluminous enough to carry The C Programming Language inside everywhere you went was a sign of great experience and wisdom. As a bonus, it also horrified "the suits", who were hackers' natural outgroup.
In the 21st century you just can't annoy the suits the same way because even large corporations don't demand people wear literal suits anymore. Baffling the HN crowd is what passes for iconoclasm these days.
Memes ensued
I'm friends with the both on steam and they are both very very very into gaming (like 4-5 hours a day at least) so I always thought it was related to that somehow.
Suppose it's challenging why having an anime character next to a blurb of text is embarrassing.
As much as I hate "both sides" discourse[0], it's interesting that I see the same memes in both right and left contexts - I wonder of a creation of a "second language" to discuss divisive politics is enough of a force to spread it, or of it is intentional coopting of another sides language to dilute it.
E: [0] HN is not the place for the rest of my feelings on this. Both sides aren't the same is enough to suffice here.
What exactly is embarrassing about this?
The author probably likes seeing an anime girl, and feels that displaying one on their page expresses an interest in anime, tech, and a casual tone for their writing.
I have no issue with it in its original Japanese setting and I wasn’t aware of its use by the LGBT community but it seems far less depressing in this case.
Watching someone be genuinely enthusiastic about something is wonderful. Society has far too much cynicism, and watching it beat that into children as they grow up is no fun. I see a lot of adults who treat things that way.
Maybe it's a generational thing, maybe it's my circles, but I've seen plenty people appreciating and gushing about people sharing their interests. It's even in the memes, here's an example:
> Everyone wants an autistic gf who infodumps abt video games and linguistics and whatever up until day 43 of the relationship when you get a paper cut and she starts trying to drink your blood
But isn't the question what they are being enthusiastic about? I would certiainly agree that there are some things that considered noble and respectable (helping the sick, science, the right kind of activism for the right kind of people, ...) that most admire. At the same time I think most recognize that there are destructive or non-productive things one can be enthusiastic about to the point of obsession. While having an anime girl on your website or being a furry is usually not destructive and ignore the cultural popular images of people like these, then they are at least non-productive in the sense that neither society nor the individual themselves grows from engaging with the topic. You can study engineering and improve human technology or write and learn how to better express yourself, but I don't see how anyone can progress as an anime weeaboo beyond a self-contained culture that might value if you know the names and details of all characters by heart. As soon as you step out of this bubble, the value disappears.
> Maybe it's a generational thing, maybe it's my circles, but I've seen plenty people appreciating and gushing about people sharing their interests.
I don't know what generation you are referring too. I'm Gen Z and obviously have different feelings about this. Sure, I enjoy talking to people who share my interests, but I know when and where the right place is. I don't go out with friends and insist on talking about e.g. Emacs, and I certainly don't want to be perceived as someone who superficially is only interested in my own topics, not caring to engage with topics that others care about.
(Btw. thank for your respectful tone, I appreciate that).
A lot of these people tend to be quite isolated from society in general, so they end up losing their sense of embarrassment entirely. Doing things that other people find weird or that make other people uncomfortable ends up becoming a sort of hobby for them (and often becomes their personality entirely) since they effectively have nothing to lose over it.
I’m in this picture and I don’t like it, but I vouched anyway. It’s an interesting perspective I hadn’t considered before, and broadened by horizons a bit.
The comment I responded to was dead. I don’t feel it really violates the site guidelines. Although some people might take it personally, which could make it sort of flame-bait-y and result in flags.
In at least one case I know of, by being so outrageously competent that they know it won't hurt their ability to get a job.
https://en.wikipedia.org/wiki/Itasha
As an example, I believe to recall the first time I felt this way as a child, perhaps age 4 or 5. There was some sort of a meeting and somehow a kid felt prompted to go up to the whiteboard and start explaining everyone the Bionicle alphabet (https://bionicle.fandom.com/wiki/Matoran_Alphabet) with unreasonable enthusiasm. I was into Bionicles myself, but remember thinking to myself, "Don't you know how you look like? Don't you know that nobody cares? Have you no sense of how others perceive you? If I hadn't seen how this looks like, would I have done something like this eventually?". I don't know how others brush these impressions away with a "Good for him".
Anyway, to answer your question: I'm not sure there's any personality traits I would call "embarrassing". There are some I would call harmful, sure, and there are some that are associated with being socially inept or less cool, but I don't think there's a category of personality traits that are just embarrassing.
To your specific example: Being enthusiastic about things isn't embarrassing; it invites others to share that enthusiasm, either because of a shared interest or simply because watching someone be enthusiastic about something is enjoyable.
Proof: https://www.jwz.org/blog/2021/01/i-told-you-so-2021-edition/
absolutely not
...I think I like it
Yet here I am with a random username. I do also have a public professional website though.
Again, to me "easrng" means nothing. When starting to read your comment I had no idea what perspective you were coming from, if you were about to agree with me or not. All I know about you are the 99 words you have written in this comment.
Setting aside scams, if you meet someone online, when you get along well and become friends, would you reject the opportunity to meet them in real life instead of communicating virtually? I think most people would take that opportunity. I guess I am still young, and I think that most people my are inclined to agree with me -- especially after the lockdowns.
But what you say is interesting: When I hear "I can craft and change representations of all that I am", I hear someone saying that they can make up a fake persona, instead of being the person they actually and inherently are. An online persona starts blank, just like I have no image of you before our first message. Even the most generic person has something that makes them ever so different from most other people, that they cannot deny.
On the contrary, I think that anonymity makes people more honest, because they don't have to fear the repercussions of saying something that either a real person or an online persona. They both have to hide, while the lack of an identity makes you free.
> I kinda like it, and kinda wish it was just totally cool to have a waifu on my site too without having to lean into irony or identity to "justify" it against this cringe instinct.
it's only once you accept that you are cringe, that you are are free to become truly based.
"anime is trash... and so am I"
I was originally going to say "Hey, just do you" but then I totally get that feeling of "I'm into X just because I like it but for some stupid reason X signifies Y which I really don't care for" and it sucks.
What's risqué in OP's picture?
Combine with a greater acceptance of non-traditional personal identities, and you get professionals using anime and furry avatars and decorations. Practically speaking, it's not really any more or less professional than O'Reilly using animals to create an identity for its programming book covers (so long as you're not wearing a fursuit or sailor moon leotard to work).
Back then, me and friends spent an insane amount of time on reverse engineering a Japanese file sharing app so that we could build our own server version (like Deluge nowadays) and then we built our own IRC server and our own XDCC download bots so that we could get Anime raws onto a university server and then recode them to make download over ISDN (64kb/s) feasible.
Also, a lot of the Animes featured socially awkward nerd guys who by accident stumbled into their own harem...
With that context, posters of Anime girls together with nerd stuff sold extremely well at Connichi (a big Anime convention in Germany). A friend of mine (who's now CTO of a C++ dev shop) even bought a wax printer so that we could make really high quality A3 posters.
So I guess it's an in-joke for Europeans born in the 80s.
[edit] Oh, right, I should explain what Furcadia is. It's apparently based on Multi-User Dungeon type technology, but has a graphical frontend and was driven by user-generated content. Essentially, it was Habbo Hotel for furries, four years before Habbo Hotel even existed.
What happened? Anime and furry fandom became more socially acceptable across contexts. Why? Probably because of the ridiculous degree to which we are connected online and the way this has eroded our ability to segregate identities. A lot of people you have seen online have always been huge losers, but many of them are more open to flagrantly displaying it now.
Is this good? Dunno. I think making some of these subcultures more mainstream can suck for the subcultures themselves. I've never found it all that off-putting personally, but that could just be a reflection of my own biases as a long-time online loser.
What you call a "flagrantly display", I call a typical, progressive break from meaningless social conventions. People like cute drawings and post them on their websites, so what? And I think it provides good visibility to those communities to demonstrate the skilled and creative people that inhabit it.
I realize now this attitude may seem unnecessarily self-deprecating, though. Oh well.
<footer id="footer">
<img id="footer-image" src="/img/niconiconi.png" width="0%" />
</footer> @media (min-width: 770px)
body {
...
background-image: url(/img/niconiconi.png);
...
}
And on mobile you see that footer @media (min-width: 770px)
#footer-image {
width: 0%;
}What do you mean?
S–Should we tell him?
Nevxnjn Uvzr vf abg n tvey
Edit: apparently it's only on mobile size, near the footer.
#footer, .footer { display: none !important; }
Userstyle to remove the image from this site: @-moz-document domain("niconiconi.neocities.org") {
body {
background-image: none !important;
}
#footer {
display: none !important;
}
}@jstanley discovered that it's only visible when browsing in light mode.
(Insert balloon boy meme of the conspiracy theory guy at his bulletin board)
Of course, the Russians would probably be justified in wondering the same thing about a programming language created in the United States.
Now I want to have a closer look at S/360 and S/370 system tapes… ;-)