HNHacker News
TopNewBestAskShowJobs

linuxandrew

459 karma · joined July 22, 2021

submissionscomments
linuxandrew··on Are we doing this again? Yes, we're doing this again
Let's say this passes and the Signal Foundation and Matrix refuse to add surveillance features demanded by the UK. What effect would this have on technology as a whole? Personally I can see it going two ways.

The Matrix.org Foundation operates in the UK would either be shut down, continue in another form elsewhere, or splintered with multiple custodians. I'm not entirely sure about the Signal Foundation, as, on one hand, they are an American org, but on the other hand the US is pushing comparable laws. Regardless I think that "techies" will continue to use and operate Matrix, XMPP, Mastodon, Secure Scuttlebutt and/or other decentralised (P2P/federated) infrastructure outside of the realm of regulation. The form which that takes really depends on whether further repression takes place. Techies are essentially banned from getting compensation or building a business out of providing such platforms and so it may steer towards true P2P and so-called darknets.

Mainstream platforms may find a way around this, like, say, secretly MITM'ing a security number of an encrypted chat. Most of the mainstream platforms are not open source which helps in this regard - the app could even lie about the security verification code to the user. Or perhaps they will be more transparent and simply have all conversations that involve someone that is likely in the UK encrypted for two recipients, one being UK intel. We can only speculate what this might look like, if we would ever even know.

I think this would be a sad outcome for the community and lead to more centralisation towards large, regulated platforms like Facebook, Apple, Google and Microsoft. It would also have a chilling and repressive effect on speech as if that wasn't an issue already. One can only dream of a P2P future but I have some doubts that this would take off without the resources that the big players have.

linuxandrew··on EU Digital Identity Reform: The Good, Bad and Ugly in the EIDAS Regulation
It's also a bit simplistic to say that Snowden is the reason for prevalent HTTPS.

The share of encrypted web traffic rose after Firesheep, HTTPS Everywhere, the Snowden revelations, LetsEncrypt, HSTS and opportunistic encryption. There's been a concerted effort over the past 13 years to make it easier to deploy and use HTTPS for clients and servers.

linuxandrew··on EU data regulator bans personalised advertising on Facebook and Instagram
I don't like companies collecting hundreds or thousands of data points on me.

It's not just advertising, but trashy and addictive suggested content and potential for abuse by actors like Cambridge Analytica.

> I understand hating ads in general

Also this

linuxandrew··on Linux Mint Working on Wayland Support
Have you tried using Zoom in-browser? That worked last time I tried, and you avoid downloading a proprietary non-system package.
linuxandrew··on Irish privacy group files complaint against YouTube adblock detection system
> I've seen many posts on Reddit where people think they should be able to use a service like YouTube for free without ads

I should be able to control my computer and choose what is displayed to me.

> YouTube isn't free to run, and they offer an ad-free service that is reasonably priced for the value provided

YT undercut their rivals and monopolised the market very early on, perhaps illegally, time may tell. I'm sure many users would happily watch their videos elsewhere with different business models and privacy policies but YT largely monopolises the ameteur video market, excluding video shorts like TikTok and it's simply not possible to watch a YT video somewhere else.

If only there was a technology that would solve this problem (cough ActivityPub).

linuxandrew··on Gnome developer proposes removing the X11 session
> If for some reason you want to run an untrusted application, use a container. But building your whole house around the "untrusted" premise sounds ridiculous.

I guess we should do away with memory protection as well. Filesystem permissions? Bah, they can go too, after all, a computer is generally used by a single person right?

The reality is that many users use untrusted applications that don't have access to home, ergo Flatpak. There are plenty of reasons why the free for all security model for X11 isn't suitable. Besides, that ship has well and truly sailed - most of the X11 devs have been working on Wayland for the better part of a decade now.

linuxandrew··on Mullvad Browser
Sorry, late reply. I don't care if my bank knows who I am, but I might care if my bank can learn about my online history/preferences via the many analytics platforms and third party cookies. That shit needs to get shut down.
linuxandrew··on Terraform is dead; Long live Pulumi?
For homelab stuff Terraform/Terrafork will probably be OK for some time. The current TF version will get security updates until the end of the year and I expect others will keep it going after that.

In the medium term I'd expect incompatibilities and fragmentation in the ecosystem to crop up.

Sometimes I think Ansible could go down the same path if IBM/Red Hat decided to monetise it. All of these ecosystems run by a single company are fragile. Counter-examples are Linux and Kubernetes which both have many contributing companies with competing interests.

linuxandrew··on Mullvad Browser
I can think of some good uses. Lots of websites block Tor, some websites (like your bank) may lock your account if you start logging in from random countries. Tor can also be a bit slow for some uses.
linuxandrew··on The OpenTF Manifesto
HashiCorp makes its external contributors sign a CLA to basically hand over the copyright.

However the MPL and licensing in general is irrevocable. They have irrevocably licensed Terraform 1.5.5 under the MPL and an enterprise license (dual license). Anyone can use, modify and distribute version 1.5.5 under the terms of the MPL.

Since HashiCorp retains full copyright they can release the next version under the BSL.

Note that many free software projects (like Linux) don't have a CLA which makes relicensing impractical since every contributor would have to agree to it.

linuxandrew··on Desktop Linux has a Firefox problem
As a long-time Firefox user (or rather, LibreWolf and Mull now) the biggest problem as I see it is websites that no longer support it. Compatibility is constantly getting worse as Chrome/Blink monopolises web dev and testing.

I'm considering writing letters to some of the sites that have the biggest issues and raising it as an issue.

Otherwise, Firefox is mostly fine. I have a few gripes with it and Moz are mismanaging their projects, but desktop Linux is hardly their #1 issue.

linuxandrew··on HashiCorp Transitions to BSL
Very disappointing if you ask me.

I'll likely pin versions on Terraform and Vault to the last available MPL release, at least for a while and hold out for a fork or some sort of change.

Edit: dup of https://news.ycombinator.com/item?id=37081306

linuxandrew··on Linux has achieved a 3% desktop market share
I'm not blocked so here you go - info@linuxiac.com
linuxandrew··on Twitter now requires an account to view tweets
> immediate action was necessary due to EXTREME levels of data scraping

It sounds like Elon doesn't "get" the open web

linuxandrew··on Cement's future could be a combination of carbon capture and electrification
Different climate but I lived in two poorly maintained Queenslanders[1] which were a popular style of timber on piles here, both 50 years old and would easily last longer. One even had minor termite damage which was later treated.

Many people here do knock down rebuilds but most would easily last longer than 30 years. Many timber houses get re-stumped after a few decades and concrete piles seem to be a popular choice for replacement.

I see a lot of poorly built homes on slabs as well which seem to have a similar lifespan as the Queenslanders (anecdotally).

1: https://en.m.wikipedia.org/wiki/Queenslander_(architecture)

linuxandrew··on The US government is buying troves of data about Americans
Copyright isn't really ownership and only applies to creative works, software and works that exceed the threshold of originality. It doesn't apply to metadata, location information, secrets and facts about people.

Ownership as a concept doesn't really apply so well to digital things because they are infinitely copy-able. I can have something digital, and you can have it too.

There's certainly a need for better privacy laws which applies to PII but that doesn't really need to be conflated with copyright and ownership.

linuxandrew··on Ask HN: Real-life, ridiculous security incidents?
My story is more of a facepalm since there was no known hack that came of it.

My former employer had a helpdesk website that was written in Perl 4 in the '90s by some interns. The users' passwords were stored in plaintext in /var/www under a subdirectory. Anyone who guessed the URL could have stolen those passwords and accessed a trove of information and data of some of the biggest financial institutions.

My coworker and I patched it up as much as we could (2018-20), upgraded it from RHEL 4 to 7/8, Perl 5, fixed the public password issue, and flagged it with management but it largely fell onto deaf ears at the time.

I am still amazed at how blatantly incompetant and reckless some companies are.

linuxandrew··on TOTP Authentication with Free Software
https://freeotp.github.io/ is yet another TOTP provider by Red Hat. It's the only app that I've used so far. Available from F-Droid plus the usual places. There's also a fork FreeOTP+ by some people who have different ideas about the security model and enabling backup of keys.
linuxandrew··on Layout 2013 and Layout 2020
Google/Blink consistently pushes for bad things like EME, FLoC and Topics API.

They have a very different vision of the web where users live in a corporate playground and complex browser engines which only a few large corps can manage.

At this point what is making the web a better platform? The web has feature overload, even with features like Server Push which are seldom used. FWIW I think there are some exciting possibilities and new features for the web, especially around the P2P space, but I don't think it's in Google's interests to push for that at all.

linuxandrew··on Layout 2013 and Layout 2020
Mozilla abandoned work on Servo in 2020 (source: https://tildes.net/~tech/ra8/i_am_a_mozilla_employee_amaa) shortly after Layout 2020 came about. Servo was in limbo for some time before recently being handed over to the Linux Foundation, hence the time delay.
linuxandrew··on Layout 2013 and Layout 2020
Servo is now under the Linux Foundation umbrella. It's refreshing to finally see some more players in the browser engine space than the tri-opoly of Google (Blink), Apple (WebKit) and Gecko (Mozilla). LibWeb (Ladybird Browser) is another browser engine, but also in very early days of development.

Gecko is depressingly tied to Firefox and not easily embedded. Blink has somehow become the de facto browser engine thanks to Electron. Even Qt (QtWebEngine) is now based on Blink instead of WebKit. A lot of web apps like Teams only support Blink/Chromium, just like the dark old days of Internet Explorer. Chrome and Edge are basically spyware which people are most drawn to because of being somewhat default and/or well known for their phone/PC.

linuxandrew··on Ask HN: Is HN Dying?
It is official; Netcraft now confirms: Hacker News is dying
linuxandrew··on X12: Requirements for a successor to the X11 protocol (2013)
Network transparency doesn't offer any tangible benefits for a lot of apps and desktop environments because they are drawn with bitmaps and textures rather than vectors.

This topic has been done to death for the past decade. VNC and RDP won. X11 was a razor edge case and nothing more.

linuxandrew··on KDE and GNOME seeks $100k to turn Flathub into a Store for the Linux desktop
> systemd (the attempt to turn Linux into Windows)

systemd was actually inspired by launchd, not Windows. But I guess systemd, Windows and launchd do share one thing in common which is not having a bunch of bandaid shell scripts hanging the system together.

linuxandrew··on I'm done with Google
Exactly this. MSN Music screwed me over when they shut down and made the .m4p DRM music files unplayable. I redownloaded all of the music via BitTorrent and persisted to this day.
linuxandrew··on Btrfs in Linux 6.2 brings performance improvements, better RAID 5/6 reliability
3. Prevent bit-rot w/ software RAID. Running ZFS, btrfs et al. on a single disk can detect bit-rot but not repair it.
linuxandrew··on 'Bin chickens' learned to wash poisonous cane toads
I've heard crows have also learnt to eat cane toads (crows are known to be quite smart) - https://www.australiangeographic.com.au/topics/wildlife/2018...

Apparently other animals are eating them with varying success - https://www.abc.net.au/news/science/2019-11-01/cane-toad-nat...

linuxandrew··on The surprising afterlife of unwanted atom bombs
Whilst weapons of mass destruction have been a deterrant, I would argue that weapons of targeted destruction are just as useful, if not more so, like drones, missiles, anti-missile defense etc. They are also less bad for humanity if they are used. If the US dismantled substantial stockpiles of nuclear warheads it would be unlikely to impact their global standing.
linuxandrew··on NSA, NIST, and post-quantum crypto: my second lawsuit against the US government
I know someone who works in gov (Australia, not US) who told me all about a FOI request that he was stonewalling. From memory, the request was open ended and would have revealed more than it possibly intended it to, and would have revealed some proprietary trade secrets from a third party contractor. That said, it was probably a case that would attract some public interest.

The biggest factors preventing governments from stonewalling every FOI case are generally time and money. Fighting FOI cases is time consuming and expensive and it's simply easier to hand over the information.

linuxandrew··on Why offer an Onion Address rather than just encourage browsing-over-Tor?
I think the avoiding exit nodes part is probably the most important to me. Exit nodes have always been problematic - from memory about 20% of relays have an exit flag but most of the traffic is directed to the most performant relays. Tor actively discourages using the network for file sharing because of the exit node bottleneck.

I think there are probably some uses of the Tor network that aren't fully realised yet - file sharing (something similar to I2P) which avoids the exit node using onion addressing and chat applications (like Briar which uses onion addresses, or Secure Scuttlebutt).

As for web traffic, it is nice to offer an onion address. I wonder if websites could offer an "upgrade" to onion addresses, similar to how IPFS does?

← PreviousPage 3 of 4Next →