163 karma · joined November 22, 2018
For most monolithic applications I think the whole issue is be a bit moot; if the rest of the application state is in the primary database, then an attacker with database access could presumably accomplish anything without the need to spoof another user at the authentication layer.
Lastly, this scheme doesn't provide any mechanism for rotating the pepper.
Edit: I see that this is primarily intended for federated social networks, but should be reusable for other uses. However for other e2ee systems (e.g. messaging, filesystems) where hiding your social graph is important, wouldn't a key directory be able to infer (part of) your social graph by recording which lookups you make? What's the best way to mitigate that?
> Our open source code has been audited by reputed cryptographers.
I think you probably mean "reputable", as "reputed" inspires a lot less confidence.
> To that, I can only respond that, in a properly configured shell like the one that comes by default with GoboLinux, typing /Programs takes the exact same number of keystrokes as typing /usr: slash, lowercase p, Tab.
Go's module system was specifically designed with this problem in mind: https://go.dev/blog/versioning-proposal
I think Java projects get around this when they have to with shading, but that's a bit clunky.
I don't think hours behind a screen have ever had much of a correlation with productivity for me. Autonomy, stress, being tasked with solutions that actually make long-term sense, etc. must have a much stronger correlation. The enormous erosion of trust that having my hours monitored would have would certainly impact my output.
Surely there are other considerations beyond stability to be had when choosing an operating system?
For example, I would argue that Moxie's desire for unofficial clients to not use the word "Signal" in their project name is a statement of policy, whereas the takedown requests to remove the projects from GitHub and the Play Store are examples of enforcement of that policy.
That said I think I can be convinced that directly informing a violator of your policy of said policy is a type of enforcement in itself.
> I don’t know of another company
He didn't say contemporary company.
Yes, but until computer science is fully formalized we will still need design, and can benefit from science. If/when it is fully formalized and creating software becomes an automate-able optimization problem, we will no longer need system designers. Or software developers, for that matter.
> I never said ignore the field.
Not explicitly, perhaps, but it really does read like that is what you're implying. You said multiple times that anyone labelled as an architect or designer knows nothing and is peddling bullshit. If we can agree that design is amenable to scientific inquiry, then it would make sense that some designers do know things.
Re-reading your original post, I realize now that I chose the wrong quote to respond to. I do agree with you that anything labeled as "design" is necessarily constrained by a lack of knowledge. Any time there are multiple ways to solve the same problem and there is no a priori way to figure out which solution is the best, we are forced to design. My point is that this describes software development, which as noted above has not been fully formalized. Writing software is design, and therefore needs designers.
> Often we have no choice. No one calculate the best work of art. Art is created by design.
Are you implying that when it comes to software, we do have a choice?
> The concept of abstraction, good abstractions and bad abstractions can be separated from design and formalized into exact definitions. That is my argument.
This is where you lose me, I'm not sure I understand what you mean here. Abstraction is a design principle, and developers argue constantly about whether a given abstraction is good or necessary. The motivation behind abstraction as a principle hinges on how you define "too complex", and that sounds very subjective to me—the opposite of formal.
There are branches of science whose theories are more often derived from data and observation than from axioms. Just because you may not be able to break something down into first principles, does not mean that the knowledge is useless.
Design, too, can be data driven. UX and UI design can be analyzed using A/B tests, or by observing patterns of user behaviour.
It might be true that much of systems design is based on anecdotal evidence and intuition, but I don't think that's enough of a reason to ignore the field of design entirely.
For example, the concept of abstraction in software design may be based primarily on the intuition that human beings are bad at holding too much complexity in their minds. But any software developer who has written more than one program will agree that abstraction is crucial to good design.
In Canada I've admitted suicidal plans on multiple occasions to doctors, psychologists, and once even the police. On two of these occasions I was sent to the psychiatric emergency room, but only for as long as it took to assess that I was no longer a harm to myself. The first time that took an afternoon, the second time it took a couple days. After that I went home, no repercussions.