973 karma · joined September 16, 2015
Case in point, I recently wrote a CLI to show which of your AWS infra is not captured in terraform, and you can either print the result as a json to consume by a machine or generate a dashboard with some charts. It took me an embarrassing while to realise that I should have included a damned screenshot in the README, in fact I think I only realised when I wanted to show it to my brother.
Snarky reaction aside, and actually reading the article, it says that the problem is something along the lines of "we incentivized and rewarded business accounts to post large volumes, so now if you switch to chronological order you will see more of these posts which reduces user satisfaction".
Well, that just means that the company will have to adapt before their users start unfollowing spammy accounts and the whole "influencer" business takes a hit. Though tbh, not sure how much of a hit it could take but hey, when instagram says engagement falls, I allow myself to feel optimistic for a brief moment.
People that are elected by the public and hold the power to define every aspect of our lives, should be held to the absolute highest level of scrutiny possible. Every aspect and every single moment of their lives should be transparent and recorded while they hold office, no exceptions whatsoever.
I will concede that having it broadcasted may be a tad hard to do, but there should be a record of what happened during their time - in fact there should be a way to answer the question "what was minister X doing at 2026-08-29 20:13:14 UTC?"
And for the argument that says "oh then nobody would want to do it", I think that's in favour of this approach. Look around at what we're dealing with, and which people want to win elections and the fervour with which they go about it.
We should be trying to make this kind of "job" as unappealing as possible. It should be a chore, not something to go after.
In this case, the companies that make and provide AI models that are increasingly used to interact with me on critical things (banks, public sector services) then yes.
Abso-fucking-lutely they should be regulated like crazy.
In fact I'm really surprised by the amount of people that are not worried by how many parts of their lives are being handed over to be managed by a probabilistic system that is controlled by a private company with next to zero oversight.
There must be a greater liability than "oops, you're right to push back"
The alcohol mentioned in a sibling comment also ticks the box.
For the sugar, I'd say yes, no, no, yes and "not too much, but I'm keeping an eye out".
E.g.
- Is it addictive?
- Does it have the potential to destroy lives?
- Does it have the potential to destroy lives in seconds?
- Does it have a strong lobbying mechanism behind it? (n.b. things that are good and nice rarely need someone to bribe people to accept them)
or simply:
- Would you be worried if your child did it?
I think the number of "yes" that you get draws a very clear line.
Now your app doesn't have direct access to your stripe/github/aws/whatever keys (which is good!) but you still need to have _some_ authentication against your proxy.
If you have a per-app authentication, then if your app's key leaks, then whoever uses it will be able to reach all the external services your app can, i.e. with one key you lose everything. On the other hand, if you have per-endpoint authentication, then you didn't really solve anything, you still have to manage X secrets.
Even worse, from the perspective of the team who owns and runs the proxy, chances are you are going to use per-app AND per-endpoint authentication, because this will allow you to revoke bad keys without breaking everyone else, etc.
What this really solves is subscription management for (big?) organisations. Now that you have a proxy, you only need a single key to talk to <external-service>, no need to have to manage subscriptions, user onboarding and offboarding, etc. You just need to negotiate ratelimits.
I've owned a macbook since 2010, with a short break during the touchbar era when I got myself an XPS with windows which I dual-booted with ubuntu and later a system76 that comes with their own flavour of Ubuntu, called Pop! Os.
The situation in windows (windows 10 at the time) was abysmal. Completely incoherent UI, settings spread across different menus, ads in start menu, slow and broken search, constant nagging to update windows, to update the drivers, to tell me that the drivers have been updated, to install or update my antivirus, etc. These were not things that I installed myself, these were included with Dell's setup of the machine.
On the system76 laptop things were different. Things were calm, I could configure everything as I wanted and things worked. Until at some point I installed a new version of something, which had nothing to do with sound, but it broke sound, just as I was preparing to join a meeting, and just as we were going into the second phase of lockdowns in late 2020 so online meetings were here to stay.
My macbooks are reliable. I've got the M1 as soon as it came out and I never got a single issue with it. I've upgraded twice (I think) across major versions and everything worked. I don't have to worry about it leaving me hanging when I need it.
(And that's not taking into account things like build quality, touchpad quality, battery life, silence, etc)
In the end of the day, I do a lot of debugging as part of my work. When I don't work, I want to choose what I will be debugging, not have it forced on me.
And don't get me wrong: I see where Apple is going, I know that they're a greedy company that want to maintain their iron grip and have the final say on what we can and cannot do on our machines.
However, for me for the time being it's the least bad option.
What I _do_ find annoying though and I cannot wrap my head around are lifetimes. Every time I think I understand it, I end up getting it wrong.
For a given project, I have a `./creds` directory which is managed with pass and it contains all the access tokens and api keys that are relevant for that project, one per file, for example, `./creds/cloudflare/api_token`. Pass encrypts all these files via gpg, for which I use a key stored on a Yubikey.
Next to the `./creds` directory, I have an `.envrc` which includes some lines that read the encrypted files and store their values in environment variables, like so: `export CLOUDFLARE_API_TOKEN=$(pass creds/cloudflare/api_token)`.
Every time that I `cd` into that project's directory, direnv reads and executes that file (just once) and all these are stored as environment variables, but only for that terminal/session.
This solves the problem of plain-text files, but of course the values remain in ENV and something malicious could look for some well known variable names to extract from there. Personally I try to install things in a new termux tab every time which is less than ideal.
I'd like to see if and how other people solve this problem
[1]: https://direnv.net/ [2]: https://www.passwordstore.org/
However I don't agree with the repercussions of this, which are the same ones that make all reasonable people, security experts included, oppose EU's ChatControl or the UK's backdoor requests: There is no way to ensure and protect the people that need protection, as there is no way to ensure that only "the good guys" have it.
We tend to bullshit ourselves into believing that because spyware software like Predator are weapons, meaning that only countries would be allowed to buy them and use them (same way that Jeff Bezos cannot buy and use an F-35 for example). We see though, that certain individuals _can_ get their hands on these things and use them however they want.
For example, 3 years ago someone adjacent to the greek government bought and used Predator against MEPs, journalists, army generals, mafia bosses, MPs of opposing parties and even MPs of their own, ruling, party. The greek government of course denied that they did it, and they said that this individual did not act under the instructions of the government (though they then changed the law to prevent anyone for learning details about it, but that's a different story).
So, apart from adopting the same approach as with ChatControl and encryption backdoors, i.e. banning them, I don't know how we could protect ourselves against them.
(I do miss Google Now, it really did feel like the future)
Less essential: Obsidian, Kagi (this one may be bumped to the "essentials" at some point), a few VPS on Hetzner to run some projects, domain names for said projects.
Just because I like them and want to support them: Signal
(The main drive behind this was not to sell it, but to have a UI for when a website changes its layout and I'm on holidays and don't have access to my terminal and/or my yubikeys)
Sure, soon enough a decent non-chromium based desktop browser will come along, be it Zen or something else, but what about the mobile world?
Right now firefox is perfect for me: It makes the web browsable by allowing ublock origin, it syncs my tabs, history and bookmarks, it's great.
Moving to a scenario that we have a different browser on the desktop and a different one on the phone or, worse, the same on the phone but without adblocking sounds like a huge regression.
P.S. Regarding Zen: If you want to be taken seriously, or at least as something more than a toy project, teaching your maintainers how to talk to your (potential) users will go a long way. Telling them off will not gain you any friends. (I'm referring to the github discussion mentioned in a sibling comment: https://github.com/zen-browser/desktop/discussions/5907)
(The other more minor requirement for me is bookmark tags, but I may be able to hijack my way around that)
Maybe something like "This looks good. Would be nice to see it extended to support companies that do not follow the calendar year.".
I'm from Greece and I've always dreamt of living there, but through the various turns of life I ended living for almost a decade in the UK first, so now I'm looking to make the move.
(So if anyone from Switzerland is reading this and is looking for an SRE from an EU country, feel free to reach out at cv@ my username.net)
Lately though I've been thinking about Norway as well, though I feel that transition would be much harder.