HNHacker News
TopNewBestAskShowJobs

ddevault

26,735 karma · joined January 7, 2013

https://drewdevault.com

sir@cmpwn.com

submissionscomments
ddevault··on Sourcehut will blacklist the Go module mirror
Hey Russ, I got your messages that my emails aren't coming through but I'm not sure why. As an alternative, you can reach me on IRC at ddevault on Libera Chat. I'm in CEST, but my bouncer is always online. Cheers!
ddevault··on Amarna Letters
And, of course, most of them are being hoarded by state-sponsored thieves, particularly the British.
ddevault··on Sourcehut will blacklist the Go module mirror
I admitted that my comments about EFAIL -- four years ago now -- were in the wrong, and apologized for them. Unless you're going to argue that this issue should justify consuming 70% of my system's network bandwidth without recourse, move on.

In the interest of not feeding the trolls, I think I can safely stop engaging with you on this thread. Or maybe on any thread -- you and I never seem to have a productive conversation on this website.

ddevault··on Sourcehut will blacklist the Go module mirror
Correct: it was made clear to me in no uncertain terms that the only thing I was allowed to say was "yes" or "no" to this offer.
ddevault··on Sourcehut will blacklist the Go module mirror
What you're thinking about, in my opinion, is best referred to as a spider.
ddevault··on Sourcehut will blacklist the Go module mirror
We can behave like adults, ask why it's not satisfactory, and come to a more agreeable mutual solution, or we can blithely offer an incomplete solution, muzzle the other party, and just continue our DDoS.
ddevault··on Sourcehut will blacklist the Go module mirror
Your comment in this thread is the first time I've seen anyone mention that it was being worked on since... June 2021? This despite repeatedly raising the issue up until I was banned without explanation. I was never told, and still don't know, what disabling the refresh entails, the ban prevents me from discussing the matter further, and I was under the impression that no one was working on it. We have suffered a serious communication failure in this incident. That said, I am looking forward to your follow-up email and seeing this issue resolved in a timely and amicable manner.
ddevault··on Sourcehut will blacklist the Go module mirror
1. We would like to have a more complex discussion than saying "1" or "0" to this specific offer

2. This specific offer is not satisfactory: https://news.ycombinator.com/item?id=34313802

ddevault··on Sourcehut will blacklist the Go module mirror
Hi Russ! Thank you for sharing. I am pleased to hear that there is finally some progress towards a solution for this problem. If you or someone working on the issue can reach out via email (sir@cmpwn.com), I would be happy to discuss the issue further. What you described seems like an incomplete solution, and I would like to discuss some additional details with your team, but it is a good start. I'm also happy to postpone or cancel the planned ban on the Go proxy if there's active motion towards a fix from Google's end. I am, however, a bit uneasy that you mentioned that it's only prioritized for "this year" -- another year of enduring a DoS from Google does not sound great.

I cannot file an issue; as the article explains I was banned from the Go community without explanation or recourse; and the workaround is not satisfying for reasons I outlined in other HN comments and on GitHub. However, I would appreciate receiving a follow-up via email from someone knowledgeable on the matter, and so long as there is an open line of communication I can be much more patient. These things are easily solved when they're treated with mutual respect and collaboration between engineering teams, which has not been my experience so far. That said, I am looking forward to finally putting this issue behind us.

ddevault··on Sourcehut will blacklist the Go module mirror
For a number of reasons. For a start, what does disabling the cache refresh imply? Does it come with a degradation of service for Go users? If not, then why is it there at all? And if so, why should we accept a service degradation when the problem is clearly in the proxy's poor engineering and design?

Furthermore, we try to look past the tip of our own nose when it comes to these kinds of problems. We often reject solutions which are offered to SourceHut and SourceHut alone. This isn't the first time this principle has run into problems with the Go team; to this day pkg.go.dev does not work properly with SourceHut instances hosted elsewhere than git.sr.ht, or even GitLab instances like salsa.debian.org, because they hard-code the list of domains rather than looking for better solutions -- even though they were advised of several.

The proxy has caused problems for many service providers, and agreeing to have SourceHut removed from the refresh would not solve the problem for anyone else, and thus would not solve the problem. Some of these providers have been able to get in touch with the Go team and received this offer, but the process is not easily discovered and is poorly defined, and, again, comes with these implied service considerations. In the spirit of the Debian free software guidelines, we don't accept these kinds of solutions:

> The rights attached to the program must not depend on the program's being part of a Debian system. If the program is extracted from Debian and used or distributed without Debian but otherwise within the terms of the program's license, all parties to whom the program is redistributed should have the same rights as those that are granted in conjunction with the Debian system.

Yes, being excluded from the refresh would reduce the traffic to our servers, likely with less impact for users. But it is clearly the wrong solution and we don't like wrong solutions. You would not be wrong to characterize this as somewhat ideologically motivated, but I think we've been very reasonable and the Go team has not -- at this point our move is, in my view, justified.

ddevault··on Sourcehut will blacklist the Go module mirror
I was indeed in the wrong when I made this comment four years ago. I have since apologized for it. I don't intend to re-litigate anything on HN at this point, but I have good reason to believe that this incident is unrelated to the reason I am presently banned.

The linked comment was indeed out of line, and perhaps you feel justified in thinking that it should be sufficient grounds for a permanent expulsion from the community. I won't argue with that, fair enough. However, I don't think it's reasonable to use it as grounds to suggest that anyone should have their servers DoSed by Google with no recourse, and I think blocking Google is a reasonable move given two years of inaction from the Go team to resolve the issue.

ddevault··on Sourcehut will blacklist the Go module mirror
That's not how the proxy works. The proxy automatically refreshes its cache extremely aggressively and independently of user interactions. The actual traffic volume generated by users running go get is a minute fraction of the total traffic.
ddevault··on Sourcehut will blacklist the Go module mirror
I would share their side as well, but I never heard it. This is a violation of their own code of conduct, which requires them to notify the affected person, explain why, and offer the opportunity to mediate the situation. This is not the first time I was banned from the Go community without notice or explanation, and the first time turned out to be frivolous -- the ban was overturned months later with an admission that it was never justified in the first place. Community management in Go strikes me as very insular and unprofessional.

Regardless, I don't really want to re-litigate it here. The main issue is that Google has been DoS'ing SourceHut's servers for two years, and I think we can all agree that there is no conduct violation for which DoS'ing your servers is a valid recourse.

ddevault··on Sourcehut will blacklist the Go module mirror
Thanks for the tip, will update the post.
ddevault··on Engineers Want to Build Conscious Robots. Others Say It’s a Bad Idea
There's no need. Anyone who believes that general AI is within reach is not smart enough to strive for it anyway.
ddevault··on Ask HN: Help – Locked out of 10 years Gmail account
I'm getting pretty tired of these threads. We've seen them for years and years and years. At this point, anyone still using gmail is a PEBKAC error. Move!
ddevault··on Ask HN: Anyone free to meetup in Tokyo on Xmas?
I hope your meal will take place at KFC :)
ddevault··on I am done. I give up
It's true that luck is a big factor. Every time you try something difficult, you're rolling the dice, and most outcomes are failure. However, there is a strategy you can apply to maximize your odds of success: position yourself so you can keep rolling the dice.
ddevault··on January 1, 2023 is Public Domain Day: Works from 1927 are open to all
I advocate for democratic socialism, which is a mix of socialism and capitalism. Socialism for humanity's basic needs, capitalism for the wants.

Yes, it is possible.

ddevault··on January 1, 2023 is Public Domain Day: Works from 1927 are open to all
Intellectual property is intangible and cannot be stolen. Copying is not stealing; the original does not go away.

https://drewdevault.com/2021/12/23/Sustainable-creativity-po...

ddevault··on January 1, 2023 is Public Domain Day: Works from 1927 are open to all
That's not how rent seeking works. Rent seeking requires exclusive access to a resource, i.e. an apartment in the original metaphor. Nothing prevents the author from monetizing it, too, and they get first-mover advantage and other legs up besides.
ddevault··on January 1, 2023 is Public Domain Day: Works from 1927 are open to all
No, I don't agree with that. In fact I'm a copyright abolitionist.
ddevault··on January 1, 2023 is Public Domain Day: Works from 1927 are open to all
TAOCP is not a single entity; each volume has its own copyright term. The original purpose of copyright is not to enable rent seeking, but to encourage artists to keep making new works. So as old volumes of TAOCP fall out of copyright, it incentivizes Knuth to write new volumes. It would be the system working as designed.
ddevault··on Productivity Blocker
Fun is occasionally permitted on HN. This thread is about a joke add-on in the first place, you know.
ddevault··on Atom was archived today
2.5G is definitely excessive.
ddevault··on LosslessCut: lossless video/audio editing
This project has been my go-to example of the absurdity of Electron since its inception. This is a thin wrapper around ffmpeg, which does all of the real work here and is a much more powerful and versatile tool. Why does this ship an entire web browser? Why does this even exist? The world may never know.
ddevault··on "Doctors fitted a contraceptive coil without my consent"
>In 1948, the United Nations Genocide Convention defined genocide as any of five "acts committed with intent to destroy, in whole or in part, a national, ethnical, racial or religious group." These five acts were: killing members of the group, causing them serious bodily or mental harm, imposing living conditions intended to destroy the group, preventing births, and forcibly transferring children out of the group.
ddevault··on Hackers earn $990k for 63 zero-days exploited at Pwn2Own Toronto
"The market" is highly unethical and anyone who sells exploits there is undoubtedly a black hat.
ddevault··on Amtrak asks fed regulators to investigate Union Pacific handling of Sunset Ltd
These numbers are similarly misleading. Read up on induced demand. Rail passengers in the US are small in number because passenger rail sucks. If it were improved, ridership would go up.
ddevault··on JPEG XL support has officially been removed from Chromium
A closed standard is not a standard. That's it. It's a document of little to no relevance that may as well not exist.
← PreviousPage 3 of 34Next →