HNHacker News
TopNewBestAskShowJobs

turbinemonkey

358 karma · joined October 9, 2009

submissionscomments
turbinemonkey··on Meta Platforms: Lobbying, dark money, and the App Store Accountability Act
Oh, stop. Tinfoil-hatting like this is how privacy and internet freedom activism gets a bad rap.

QWAC certs are only for "high value" sites: banks, government services, etc. They can only be issued by "Qualified Trust Service Providers" (e.g. digisign, D-TRUST, etc -- not governments), and cost many hundreds of euros. Your blog and mastodon instance and 98% of businesses just aren't affected.

People operating in "high risk" sectors that need access to payment infra (porn, drugs, etc) are, as always, going to have a hard time. That's a worthy conversation, but nothing about QWAC or eIDAS is about "the government not issuing certs to people they don't like".

turbinemonkey··on Meta Platforms: Lobbying, dark money, and the App Store Accountability Act
QWACs exist to provide a more stringent and user-accessible way to assert a website's identity, mostly to foil phishing and other exploits that regular certificate systems don't address well. Where does this cross into censorship at all?
turbinemonkey··on I traced $2B in grants and 45 states' lobbying behind age‑verification bills
Heritage has been laying waste to America my whole life. They basically planned all of Reagan's legislative agenda, too, just like Project 2025 is doing today. In very real ways, they and their vision are America (a system is what it does, not what it says it does).
turbinemonkey··on Meta Platforms: Lobbying, dark money, and the App Store Accountability Act

    Compare this to what the EU built. The EU Digital Identity Wallet under eIDAS 2.0 is open-source, self-hostable, and uses zero-knowledge proofs. You can prove you're over 18 without revealing your birth date, your name, or anything else. No per-check fees, no proprietary SDKs, no data going to a vendor's cloud. The EU's Digital Services Act puts age verification obligations on Very Large Online Platforms (45M+ monthly users), not on operating systems. FOSS projects that don't act as intermediary services are explicitly outside scope. Micro and small enterprises get additional exemptions.

    The US bills assume every operating system is built by a corporation with the infrastructure and revenue to absorb these costs. The EU started from the opposite assumption and built accordingly.
Just another reminder of how we need to protect what we have in the EU (not a guarantee, but at least a chance of fair dealing and a sustained commitment to civic values). Now that the mask has fully fallen, we have to take every step possible to root out American influence.
turbinemonkey··on Storify End-of-Life
Storify was acquired by Livefyre ~4 years ago: https://news.ycombinator.com/item?id=6354835

Livefyre was acquired by Adobe last year.

Whatever the route they've taken, the upshot is a helluva lot of content going poof (per usual).

turbinemonkey··on How I helped destroy Star Wars Galaxies
There's tons of people making more within the Microsoft/Oracle/SAP/Apple/etc ecosystems than employees of those companies, too. This is different insofar as the market was not intentionally created, but it's hard to blame him for "exploiting" the circumstances.
turbinemonkey··on Ask HN: 99designs or crowdspring for large-format illustration work?
I'm well aware of the issues that some designers have with 99designs and such. I have sent briefs to recommended local designers, but they're either unwilling to work within my budget, or ask for unworkable terms (e.g. no revisions).

Given that, I don't see how I have any other recourse. So far, the traditional designer/client relationship certainly hasn't served me well.

turbinemonkey··on Would you (do you?) trust your company's source code to github?
Fundamentally, we don't want any hardware on-premise at all. What we really want is some kind of real statement from the github guys that speaks to all of the issues raised here (encryption, theft, malicious injection, auditing, the "honeypot"/juicy target problem, etc?), as I suggest to PJ below.

I'm guessing that's not going to happen, so I suppose our options are the status quo, host in a less-conspicuous location and manage our own security (as best as one can in a hosted environment), or go with the crowd and seek safety in that quasi-anonymity.

turbinemonkey··on Would you (do you?) trust your company's source code to github?
I have to think so -- you can patch binaries and modify commit logs all you want, but patches are still being applied in sequence, locally, when you pull. If the hashes don't match, boom.

But then, can those hashes be swapped out? We need hashes on the hashes! :-P

turbinemonkey··on Would you (do you?) trust your company's source code to github?
I'd much rather see a public statement on these sorts of issues. The only thing I see on the site that is even remotely relevant is a one-liner on the plans page: "We make every possible attempt to never transmit your data unencrypted."

Presumably, the amount of proprietary code you will manage will only increase over time, perhaps remarkably so. It would be somewhat reassuring if I saw something that indicated that you take this stewardship seriously, rather than tossing off "best effort" one-liners.

turbinemonkey··on Would you (do you?) trust your company's source code to github?
As part-owner of the code in question, this is what one little guy on my shoulders is saying, very loudly.

Taking the other side for a moment: Really, no code in hosted environments (which is what I presume you meant by "the cloud")? In a production environment, user data is way more important than deployed code (compromise that and you may be looking at jail time in some jurisdictions, nevermind ruinous consequences to the business' reputation)...is that encrypted before it hits the disk or something? Or, do you think that any code or data not stored on machines located on premise is tempting fate?

turbinemonkey··on Would you (do you?) trust your company's source code to github?
User management, SCM visualization, and forking is all easier compared to gitosis + gitweb et al....which we live without, but would be nice to have.

Our real aim is to eliminate all in-house hardware. Sysadmin is definitely not our core competency, as they say.

turbinemonkey··on Would you (do you?) trust your company's source code to github?
Nice run-down. I'm pretty relaxed, BTW, but making sure i's are dotted. :-)
turbinemonkey··on Would you (do you?) trust your company's source code to github?
But far, far less likely to be the target of anyone looking to acquire an absolute ass-load of proprietary source code (and github is probably the largest concentration of it today).

(Just trying to continue to run the skeptic's argument, here. I agree with the point quite a bit.)

turbinemonkey··on Would you (do you?) trust your company's source code to github?
Yeah, which is outrageously, painfully expensive:

http://fi.github.com/pricing.html

I'm not trying to have my cake and eat it too -- I recognize that there's a different risk profile to outsourcing hosting of any service compared with doing everything in-house. I just want to make sure I'm not veering too far off the tracks in this case.

turbinemonkey··on Would you (do you?) trust your company's source code to github?
I wouldn't say we have an exceptional need for security, but we do have reservations about dropping the only thing that has any real value in our company right now into what looks like a helluva honey pot.

I'm not sure I can even properly enumerate the risks -- if I could, I'd be able to make a calculation pretty easily. Espionage seems absurd, but who am I to say that that's not a possibility?

That said, we're getting by by cutting back on our extraneous costs, which means exactly the opposite of "hire someone ourselves and keep full control".

turbinemonkey··on Would you (do you?) trust your company's source code to github?
Thanks for clearing things up for me. :-P
turbinemonkey··on Be mindful of Clojure's binding + thread boundaries and lazy sequences
Bah, my first submission and I submitted a broken link. This one's fixed. Sorry, folks. :-(