HNHacker News
TopNewBestAskShowJobs

dannyobrien

5,179 karma · joined October 7, 2010

International Director then Director of Strategy @ EFF, Committee to Protect Journalists, now Filecoin Foundation for the Decentralized Web. Coined "life hacks" (sorry), wrote http://www.ntk.net/ , co-founded https://www.openrightsgroup.org/ .

[ my public key: https://keybase.io/malaclyps; my proof: https://keybase.io/malaclyps/sigs/Te_kJq5oVspmHK7CS9NSFnEgjpWrTgofYGP1M_BCgik ]

Email: danny@spesh.com Web: https://danny.spesh.com/

submissionscomments
dannyobrien··on Show HN: Problee – play-money prediction markets (midterms, AI benchmarks, more)
Interesting! How would you describe the difference between Problee and https://manifold.markets ?
dannyobrien··on AWS says it can't restore some data from mideast facilities struck by Iran
No, I was agreeing with you.
dannyobrien··on AWS says it can't restore some data from mideast facilities struck by Iran
I mean, in those rooms I was arguing over the best policies to prevent access and surveillance and unlawful processing, and what the potential cost-benefit analysis was. And what I was arguing against was an assumption that physically compelling all companies -- or worse, all citizens -- to keep their data within the borders of the host country, would protect you from these problems.

We'd have to explain that if the data was physically in Brazil, but hosted by a U.S. company, that would not stop that company from accessing that data remotely -- unless you specified that. We'd have to also explain that if you were intended to defend against US mass surveillance of non-US persons by the US intelligence services, intelligence services and SIGINT are univerally almost defined by their broad remit to target foreign nations on their own territory in violation of local law. And, finally, if you intended to use the prohibiting the movement of of data as a sanction against companies to punish them for violating data protection standards, as pre-GDPR law in the EU had as an ultimate last resort, and the GDPR often ends up relying on as a last resort, you would find that multinationals are more capable of putting up servers in your home territory and continuing to serve your citizens than they are of substantially changing their practices regarding data processing.

I don't want to sound nihilistic about this -- regulations can exist in these areas. But it's those politics and policies of the institutions with control over the data that are the most important part of this: not where the bits are kept. Especially when those bits are encrypted, and the keys and access controls are elsewhere.

dannyobrien··on AWS says it can't restore some data from mideast facilities struck by Iran
Oh man, I was so close.

No, I'm making no "unconditionality" claim here: there are just risks and benefits. Sometimes you're the person in the room highlighting the potential problems. The risk with doing that is that when those problems don't happen, you look like a fool. But someone should raise the problems anyway, because that's part of the risk assessment!

Of course, if the problems do happen, then you get to indulge in "I told you so". But only if you failed to convince anyone at the time.

dannyobrien··on Antiquated HTML Snippets and Artefacts
Noooooooooooo not XHTML
dannyobrien··on AWS says it can't restore some data from mideast facilities struck by Iran
Yep, exactly. There's a peculiarly unsatisfying kind of vindication that comes from making "slippery slope" arguments, and then watch them play, and now you are now both a) technically correct, and b) fucked. You'll excuse me if I have a brief "I told you so" moment about a scenario about Amazon's UAE datacenters being bombed without bakcups because of a US-instigated Iranian conflict, where -- if I'd ever dared to describe it -- would definitely have got me laughed out of those rooms in 2010.
dannyobrien··on AWS says it can't restore some data from mideast facilities struck by Iran
See my other answers, but briefly: no, they were not thinking about this, which is why we were raising it. I guess the counterintuitive point we were trying to get across is that with most things, the best way to keep it safe from being lost is to put it in a known place, and lock it away. But for data, the strategy -- for that scenario -- is to keep it in a lot of places, with heterogenous defense strategies. This is for data loss, of course, not access or surveillance or unlawful processing. But there is a cost as well as a benefit to deliberately limiting your options.

(I can feel someone saying "but surely having redundancy in one country is good enough, so I'll just say that I know relatively sane people who try to have hemispheric redundancy in their data, and also you never know when two different-in-every-quality-but one locations will suffer from the same disaster. Floods; heat-waves; national protests and strikes. It's surprising how often rare things happen!)

On your second point, it really is crazy. And also amazing that this is a capability that is -- or should be -- available to anyone in the world, not just in the US, and not just devs. Hopefully without also having to think about their data suddenly finding itself in a warzone.

dannyobrien··on AWS says it can't restore some data from mideast facilities struck by Iran
(I like the accidental pun of "Clout Provider" btw, which sadly conveys some of what they try to imply).

We may not be disagreeing that much. My argument was, and is, it's not about where the data is, it's about who has control over it. The counter-argument was "well if it's in another country, then we don't have jurisdiction, so it's going to be much harder". But what you need jurisdiction over is the people. Otherwise, you end up with multi-national corporate end-runs where you have shonky companies offering to store data locally, but who knows what department has control and access.

To be fair, the context I was having these conversations was countries arguing for data residency to combat the threat of mass surveillance (corporate and governmental) in the US, and the limited protections their users had relative to US nationals. But again, the problem is that it assumes that jurisdiction remains territorial: which is not how this was ever going to play out. The next wave after data residency requirements, beyond the usual extraterritorial intelligence community actions, was laws like the US CLOUD Act, the UK's Investigatory Powers Act, and Australia's TIA law, which effectively attempts to provide regular government departments and law enforcement with the legal ability to access data that would technically be on foreign soil.

My point was not that corporations should not self-police, but the concept of "it's stored here so we can oversee it" is not as clearcut as it seemed, and it risks introducing a new level of complexity to resiliently storing data. Which may be worth the price, but was never considered at the level this was discussed.

dannyobrien··on AWS says it can't restore some data from mideast facilities struck by Iran
I think both of these things are (very) often true, but it is also true that if I'm going to have backups, it is (all other things being equal) better to minimize correlated risk. The assumption in a lot of these conversations is that having the data "in one place" (ie inside a country) was "safer" than having it in "somewhere else". The tougher counterintuitive argument was that it can be safer to have data stored in multiple places, for some risk assessments -- and that for others, having data close by was less important, in the case of seizure or surveillance or illegal use, than who had legal or effective access to that data.
dannyobrien··on AWS says it can't restore some data from mideast facilities struck by Iran
I'm not sure you were disagreeing with (past) me; but if you were, could you expand on your point?
dannyobrien··on AWS says it can't restore some data from mideast facilities struck by Iran
Hi, I'm from the past. When countries in the 2010s -- especially Western countries -- started seeing data residency requirements as an acceptable aspect of national policies, as opposed to a weird authoritarian thing that only China and Russia imposed on their citizens, we[1] spent a bunch of time explaining to their lawmakers that having geographical redundancy was a good thing, actually, and that you should stop insisting on where the data resided for jurisdictional purposes and start talking about where administrative access and encryption keys lived.

[1] OK, "we" here is probably just me -- it was one of those things where the chances of successfully convincing anyone was so small, and the commercial advantages of just nodding along, and then changing your product offering was so great, that really very few people raised it or had reason to. But somebody had to!

dannyobrien··on Why Emacs Consult async searches feel slow and how to speed them up
(I think EDR here means https://en.wikipedia.org/wiki/Endpoint_detection_and_respons... )
dannyobrien··on Antiquated HTML Snippets and Artefacts
I want to know and understand how/when we switched from all-caps tags -- <HTML><HEAD></HEAD> to lowercase. It was early on, but what prompted it?
dannyobrien··on Porting my 1993 Amiga game to Godot, with an LLM reading the 68000 assembly
I just wanted to add how much in awe I am at you creating this game in '93 in assembly. Around the same time I was trying to write a game on the Atari ST, and the dedication to the project -- especially when documentation was so thin on the ground, pre-Internet -- is extraordinary. Do you have any stories from debugging the game? I always found that the most dispiriting part, after the endless hope of handcrafting the code that I was sure would work first time...
dannyobrien··on The death of San Francisco's Market Street
Duelling opinions! (Not really -- downtown SF has had a lot of trouble in the last few years, though as Noah notes, it's been feeling a bit better lately).

However, the trajectory isn't quite that clear, at least over a longer timeline and across the whole city. Back in the 1990s, a lot of downtown was very dodgy feeling, though mostly a block or so away from Market. Market itself varied across its length -- by the time you got to Van Ness it was becoming sketchier. Its status dipped and weaved as the city's fortunes shifted -- not necessarily corresponding exactly to economic success, but by 2011 downtown I think it was fairly "back'.

Other neighborhoods did not do so well during that time, to my memory. The strange thing about 2011 was that San Francisco survived the 2008 crash fairly well economically, so on the surface it was doing well, especially by comparison, but underlying it was a big upswell in the problems that would overtake it in 2015-2022. I'm not sure they were visible everywhere in the city.

I guess what I'm trying to say here is that San Francisco is a heavily boom and bust city, with lots of neighborhood variation in fortunes -- I think plenty of people would argue that Market's upturn has come at the expense of pushing problems out to the periphery. But I wouldn't disagree that it's still digging itself out of the COVID hole, five years on, and despite a lot of potential tax income from the current boom.

dannyobrien··on Google Has Removed MV2 Extensions from the Chrome Web Store, Including UBO
I like Brave, and I know and respect many of the technical team there. I looked into the various stories about the browser that led to it being unpopular in some key communities, and I really couldn't find anything some misunderstandings, common business practices (which you can legitimately disapprove of), and a wish to register opposition to their connection to cryptocurrency/web3.

I think many people would choose not to use Brave because of its association with Brendan Eich (details at Wikipedia here: https://en.wikipedia.org/wiki/Brendan_Eich#Appointment_to_CE... ), which stands as separate from the browser itself, or the actions of the company.

dannyobrien··on Benjamin Franklin’s alter egos gave him the most freedom
So none of these are mandated backdoors, or weakening end-to-end encryption. They're examples of the intelligence services pursuing signals collection. Mandated backdoors would be something like the the United States' (as far as we know) failed attempts to compel companies to insert code to allow third parties to enter and read their communications, or the UK's (as far as we know) long-postponed attempts to add ghost devices to Apple and Meta's e2e communication systems.

I'm not so much asking as a gotcha, as modern examples of this kind of backdoor (or published encryption weaknesses) would be a big deal. I realise that there are many other tactics that states, especially the US, pursue that undermine privacy online. These just seemed weirdly specific to projects that the US has, in fact, failed to pull off for years: compelled insertion of code, and deliberately weakened encryption.

(ObContext: I worked at EFF during the Snowden revelations, and worked on understanding the impact of PRISM, and Bullrun specifically.)

dannyobrien··on Benjamin Franklin’s alter egos gave him the most freedom
Could you give examples of the US adding backdoors and weakening end-to-end encryption? I'll give you the almost-certain weakening of proposed crypto standards, and Clinton-era export controls, but I don't think I've seen any movement in that direction recently. The most successful attempts statutorily seem to be in the UK and the US.

Also: the European Court of Human Rights, as a non-EU institution, doesn't have an enforcement mechanism, so I'm not sure it's a good example to give in defending against such proposals. For instance, Russia declined to respect that decision, and I don't think it's had much effect on the UK's backdoor regime.

dannyobrien··on Markdown Database Pattern
A somewhat similar pattern has been suggested with the Open Knowledge Format: https://github.com/GoogleCloudPlatform/knowledge-catalog/blo...
dannyobrien··on Scrap (2006)
well that and the claustrophobia and the sugars
dannyobrien··on Aaron Swartz was prosecuted for scraping, while Meta does it without consequence
The best state of affairs is that neither Aaron nor Meta nor anyone else should be targeted for scraping. It shouldn't be a crime. I understand the ire about the injustice, but I don't think the right situation is that because Aaron's case was wrongly pursued, we should somehow enforce that error in the name of consistency.
dannyobrien··on Extensible Software in the age of LLMs
There's also Spritely's[0] work on Ocapn[1], and Hoot[2], their Guile Scheme implementation in Wasm.

[0] - https://spritely.institute/

[1] - https://github.com/ocapn/ocapn

[2] - https://spritely.institute/hoot/

dannyobrien··on Confessions of a Long-Distance Sailor
Also in this genre: Moxie Marlinspike (yes, that[1] Moxie Marlinspike)'s documentary about anarchist yacht-squatting, "Hold Fast" (2007) https://vimeo.com/15351476

[1] https://en.wikipedia.org/wiki/Moxie_Marlinspike

dannyobrien··on Twenty Years of Pandoc
My most used pandoc snippet:

tidyhtml () { pandoc -f html-native_divs-native_spans -t markdown-raw_html-raw_attribute | pandoc -f markdown -t html }

which strips out styling, wrapper divs, spans, inline attributes, etc from (for instance) HTML copied from a google or word doc. Just the semantic goodness!

dannyobrien··on How Google helped destroy adoption of RSS feeds (2023)
At the time, I was working at the Committee to Protect Journalists with dissident bloggers working in Syria, Egypt, UAE, Turkey, etc. We had a group of them come to the US to talk to the big tech companies about the issues they were struggling with: fake takedowns, language support, local censorship, and so on. I remember distinctly as we worked on the agenda for the meeting with Google that Google Reader being shut down was the first complaint any of us mentioned. We laughed, but it was serious.
dannyobrien··on Show HN: Bento - An entire PowerPoint in one HTML file (edit+view+data+collab)
Hey, I just wanted to say thank you for writing this -- I couldn't find a way of contacting you directly in the repo, so I'll just have to bury this here! I really appreciate the work that went into this, and the design.
dannyobrien··on GPT-5.6
I eagerly await the models replying with that: "I'd be happy to create a pelican riding a bicycle, but just a note that this might already be in my training data. Simon."
dannyobrien··on Show HN: Rowboat – Open-source, local-first alternative to Claude Desktop
What I'm looking for right now is a tool like this that lets more than one person participate in the conversation: right now Claude Code and similar tools are great for working alone, but I'd like to effectively pair-prompt with a partner who can see what's happening, and take turns steering the conversation.

Can Rowboat do this? If not, does anybody know a harness that can?

dannyobrien··on What Emily Bender meant by "stochastic parrots"
So I'm not sure if it's the first version of this doc, but I ran the first version of it that's on Wayback Machine[1] with the current version to see what the differences are.

Most of the changes seem to be because Masley found one counter-example (Newton County, Georgia) where AI datacenters do seem to be increasing water costs; the only deletions AFAICS is toning down language where Masley used to say "there are no examples" to "there is one counter-example". I don't see any other major corrections that have been removed.

Here's an annotated diff of the two texts: https://bafybeie7b3zs2gqifpvn7ee7y7326wcexwnsbhnur5coymu3m6w...

dannyobrien··on How We Made IPFS Content Publishing 10x Faster
Actually, this works now! https://inbrowser.link/ https://github.com/ipfs/service-worker-gateway -- getting p2p working in browsers is still surprisingly hard: even the official routes like webrtc have lots of hard edge cases.
Page 1 of 20Next →