It's not the end of the world if somebody calls your insecure program a pile of shit and you a nerf herding waste of skin for inflicting said shit upon the world. That's like standard behaviour since the days of Stallman at MIT labs
It's not the end of the world if somebody calls your insecure program a pile of shit and you a nerf herding waste of skin for inflicting said shit upon the world. That's like standard behaviour since the days of Stallman at MIT labs
Wake up. This isn't some social media photo-sharing app. This is the literal definition of mission critical software. Being an asshole is the cost to pay to either a) convince incompetent people to stop wasting everyone else's time or b) convince them to become competent.
You know why I don't write and release crypto software? Because I know I'm not qualified to.
Instead of expecting newbies to know they're going to be met with a storm of putrid shit should they speak a syllable out of line, how about we expect our moderators and leaders have some degree of social skill?
I rewrite it then submit it to somebody else to review before submission, then get a message saying thanks for doing it the proper way, thanks for using the proper channels, and hey you seem OK do you want to come to the invite only hackathon in Germany this year? If I cried about it instead, I'd still be a shitty programmer, and I wouldn't be drinking gigantic beers in Hamburg learning invaluable methods from Henning Brauer how to properly design a program from the ground up with security in mind so you don't have to dispose of everything half way through a major project, wasting everybody else's time because you didn't carefully design. If you think mailing list comments are bad, wait until a room full of developers has to delete six days worth of coding because you screwed up the design with a simple mistake. Wait until your boss finds out you wasted company resources and money for months and had to scrap a project. You will get worse than hurt feelings, you will be fired.
Almost all security/crypto projects are open source. There's no money involved, therefore no corporate sensitivity training or social skills needed. What's needed is secure code to stop governments from rounding up Syrian and Bahraini dissidents and drilling holes into their knees during interrogation because they were duped into trusting cryptocat while planning their democracy protests.
> What's needed is secure code to stop governments from rounding up Syrian and Bahraini dissidents and drilling holes into their knees during interrogation because they were duped into trusting cryptocat while planning their democracy protests.
Oh, get over yourself. We all know the vast majority of online cryptographic transmissions are for child pornography and drug purchases. Don't act like Syrian rebels actually use these technologies when most of them don't even have access to a computer, let alone the knowledge of how to use one.
This is seriously the problem. You sit there and think modern cryptography is something other than a rich white guy's game, as though it's nothing but a Righteous Endeavor, so you get to treat other people like shit. The fact that the paragraph before that one is all about how you're getting drunk at some invite-only German hackathon is proof enough.
Obviously I'm not arguing that Syrians who have access to computers shouldn't get to use crypto, or that there has never been a Syrian who used crypto to aid in protest. But let's not act like crypto's main usage is as righteous as helping a rebellion against an oppressive regime.
You realise that cryptocat isn't marketing itself as a chat client for paedophiles and drug users, but for activists in oppressive regimes, right?
Here's one example from their blog:
> In working with young and middle-aged professionals in the Middle East region, we have discovered that desktop OTR clients suffer from serious usability issues which are sometimes further exacerbated due to language differences and lack of cultural integration (the technology was frequently described as “foreign”). In one case, an activist who was fully trained to use Pidgin-OTR neglected to do so citing usability difficulties, and as a direct consequence encountered a life-threatening situation at the hands of a national military in the Middle East and North Africa region.
That's why people keep talking about the risk from foreign governments - because the cryptocat hype keeps mentioning governments.
> Almost all security/crypto projects are open source. There's no money involved, therefore no corporate sensitivity training or social skills needed. What's needed is secure code to stop governments from rounding up Syrian and Bahraini dissidents and drilling holes into their knees during interrogation because they were duped into trusting cryptocat while planning their democracy protests.
Your unsupported claim that the "majority of cryptographic transmissions are for child pornography and drug purchases" is insanely wrong.
Given the default use of HTTPS by Google, Hotmail (Live.com), Twitter and most recently Facebook, it is almost certain that the legitimate traffic to/from those sites vastly outnumbers, by several orders of magnitude, whatever encrypted data is sent by folks exchanging child pornography images or buying drugs via silk road.
You don't know what you're talking about.
> Be civil. Don't say things you wouldn't say in a face to face conversation.
This was uncivil. I doubt you would say that to his face. Comments like this are likely to get flagged, and if it happens enough, your account will get banned. It doesn't matter how good of a programmer you are, or how impolite RMS and Theo are.
You are exactly the kind of CS professor I'm glad I never had. You failed to read everything and care more about politics than quality of code and safety of users (k now im just trolling, sorry but read the actual replies)
There's a certain level of banter and sarcasm allowed between friends and known colleagues, but strangers don't have that luxury, or shouldn't.