Live data from Hacker News

Deleting the golang subreddit

groups.google.com

381–389 of 389 posts

Re: Deleting the golang subreddit

#381

Earlier quoted context omitted.

It's a mailing list.. you want it to be a forum, but that's not the point or what it is meant to be. Some of us prefer mailing lists and interacting over email in our preferred client over having to go to various websites and deal with their varying user interfaces.

And for people who don't like mailing lists, /r/golang exists. Not sure why we can't have both.

Isn't the point of the thread that a subset of the (google groups-bound) golang community wants the subreddit removed?

Re: Deleting the golang subreddit

#382

I was the one who proposed deleting /r/golang. It is not some official Go or Google position. As much as I used to love Reddit and was addicted to it, my personal position is that Reddit is no longer a trustworthy platform (if it ever was). Editing user content is beyond offensive. I never even considered such a thing in my years of running LiveJournal. That is a major violation of user trust and trust in the platfor…

>Now I'm brainstorming how one might build a federated Reddit with public, signed mutation log, ala CT or other chains. And then multiple UIs could render the same public & federated data set. The tricky thing is that the admin team is still doing things that you want and need out of a reddit alternative. For example, ensuring that child pornography isn't getting shared. The question is how to set things up so that t…

You "just" need (yeah, easier said than done) to ensure that any intervention from an admin is publicly logged. If admin "foo" removes some content from user "bar", it should just be made visible, something like "user foo removed offensive content from user bar" or "that comment was edited by user foo". The problem here with reddit was not the fact that content was edited, it was that content was edited without anyone knowing it.

Re: Deleting the golang subreddit

#383

Earlier quoted context omitted.

> Reddit SREs You've been working at Google too long. Reddit has on the order of a few dozen employees, not all of them technical. Welcome to how the rest of the Internet works.

I've never worked at any company with more than 50 employees, and have worked on a team with as few as 5 engineers. Even without an explicit SRE role, someone is doing that work -- keeping the servers (reliably) on the internet and performing, mitigating attacks, etc. You should be able to tag the row with a dirty flag on second (or later) write using rules internal to the DB without incurring a large performance pen…

> Even without an explicit SRE role, someone is doing that work -- keeping the servers (reliably) on the internet and performing, mitigating attacks, etc.

To be honest, not in any of the several places I've worked. And I'm a security engineer. Lean startups are desperately trying to prove their product; time is spent on reliability, performance, and security almost entirely reactively and not proactively.

I'm not saying this is a good thing. Bad security (and reliability) posture early on inflicts multiples of the original mitigation cost for years. And yet, it's rational. Time spent securing systems from your own employees when you're tiny is time you're not building your product and finding your market. It's a perverse game of Russian roulette: there are 99 bullets and one empty chamber. The analogy is going to break down here, but spending time and money removing one bullet (1:98 chance of death) is less effective than adding another empty chamber (2:99 chance of death).

Especially when having direct access to the database is insanely useful to fix the problems that moving fast and breaking things inevitably causes, only a tiny fraction of startups are going to enact the kinds of measures you mention.

Re: Deleting the golang subreddit

#384

Earlier quoted context omitted.

I've never worked at any company with more than 50 employees, and have worked on a team with as few as 5 engineers. Even without an explicit SRE role, someone is doing that work -- keeping the servers (reliably) on the internet and performing, mitigating attacks, etc. You should be able to tag the row with a dirty flag on second (or later) write using rules internal to the DB without incurring a large performance pen…

> Even without an explicit SRE role, someone is doing that work -- keeping the servers (reliably) on the internet and performing, mitigating attacks, etc. To be honest, not in any of the several places I've worked. And I'm a security engineer. Lean startups are desperately trying to prove their product; time is spent on reliability, performance, and security almost entirely reactively and not proactively. I'm not say…

I don't disagree with anything you've said, except that I disagree that it's actually a rational choice based on facts, rather than an apparently rational one based on poor information and training -- again, none of the mitigations I pointed out are really expensive.

Let's take prod DB access: Im not saying make it super locked down, Im saying set your DB security group to only be connected to from your API security group, and set an email warning when an instance launches in that group. Doesn't stop your engineers doing it, but it makes it pretty easy to shout across the office "Hey, who is fucking with prod and why?" Takes like 30 seconds to configure on AWS.

There are serious questions about why your CEO can launch that instance though, and that sounds like massive policy failure. Again, restricting the CEO IAM from launching prod instances takes 30 seconds. (And all your non-engineer accounts should be IAM restricted!)

Ignoring that your probabilities don't work out, Id argue that the situation is really remove 5 bullets or add 1 chamber, and people pick the chamber purely because it's constructive, not out of genuine cost-benefit analysis.

"If I had 3 hours to chop a tree, Id sharpen my axe" -- I think startups are too hasty to chop, because that's being productive, right?

Re: Deleting the golang subreddit

#385

Earlier quoted context omitted.

This is self righteous, moralising nonsense. You are free to say whatever you want on the internet. Set up a blog or website and go nuts. You aren't free to dictate the behaviour of companies who don't want content on their site that is objectionable or factually baseless. Likewise it is just hypocritical and hilarious to complain about conformity just because your opinions don't correspond with theirs. Those people…

This is self righteous, moralising nonsense. You are free to say whatever you want on the internet. Set up a blog or website and go nuts. I'm not so sure you're understanding where I'm coming from. I used to find online a place where I could freely express an opinion without fear of onerous consequences. Back in the old USENET days, there were trolls and heavy-handed moderation and all manner of unpleasantness, but t…

Unfortunately, your verbosity and rhetorics don't make up for "the truth", "civilization", "anti-corporate revolt" or any other intellectual and ethical monopoly you claim to hold on reality. You automatically assume that your correspondents are fools and boiling frogs. If people have left your lengthy claims of net neutrality being broken by the shutdown of a subreddit with individuals who are accused of doxxing alone, that is because they would rather play tetris than tap hundreds of times on their little devices in order to show your opinions the proverbial door on the subject of this matter. And that is, unfortunately for you, the core value of free speech.

Re: Deleting the golang subreddit

#386

I was the one who proposed deleting /r/golang. It is not some official Go or Google position. As much as I used to love Reddit and was addicted to it, my personal position is that Reddit is no longer a trustworthy platform (if it ever was). Editing user content is beyond offensive. I never even considered such a thing in my years of running LiveJournal. That is a major violation of user trust and trust in the platfor…

Totally agree with distancing from Reddit.

I would contribute to a federated non-repudiable system.

Moderation can be just as auditable. (Perhaps with some emergency actions that then require a follow up consensus to make permanent)

On some occasions the original content must be purged, but the signatures can remain. Communal censorship is vastly different from changing the content.

Re: Deleting the golang subreddit

#387

Earlier quoted context omitted.

Because nobody's even hinted that this has been done before. When someone's comments are edited, that person can see it[1], as can anyone who remembers the comment pre-edit. Add to that the fact that comments that are worth editing (beyond the rather unimportant "fuck u/spez" type of comment) are also presumably highly visible, it would be pretty hard for them to have a history of editing comments without someone hav…

Reddit's website source code is actually open sourced. The backing database is not though.

The anti-spam measures aren't open sourced, which means they could conceivably have other changes that aren't open sourced too.

Re: Deleting the golang subreddit

#388
post #256
post #55

> The sensible amongst us should be above childish drama like this. Are there many sensible among us? Remember, this is an industry in which a CTO would fire an employee for using proper English[0]. It's an industry where a CEO called for employees who voted for a candidate he opposed to resign. We passed the point of insensibility a long time ago. [0] Bryan Cantrill stated in 2013 that Joyent will fire any employee…

Please don't take HN threads on generic ideological tangents. This is like a poster child of that. We detached this subthread from https://news.ycombinator.com/item?id=13037254 and marked it off-topic.

> Please don't take HN threads on generic ideological tangents. This is like a poster child of that.

Dang it[1], I strenuously disagree. I didn't post some 'generic ideological tangent'; I just mentioned the first two things which leapt to mind as indicators that our industry is silly. I could have mentioned Adria Richards, Marco Ament or Jon Gruber, but those didn't come to mind first.

My point — and I think it's a serious one — is that our industry takes itself far too, and undeservedly, seriously. Choosing to shut down a well-operating group over the misbehaviour of the host site's CEO (and it is serious misbehaviour: my opinion is that he should resign or be fired) is, IMHO, among those silly things done from a sense of inflated seriousness.

[1] Couldn't resist the pun; I'm sure it's not original

Re: Deleting the golang subreddit

#389
post #343

Earlier quoted context omitted.

Thanks for this, I have noticed that in the online communities where I hang out, it is nice to have the words of what has been annoying me. Thanks so much.

Well, now that we've identified the problem, what can we do about it? Right now, large swathes of the internet are ruled by bullying stupids. What's more, that old saw about how you shouldn't argue with an idiot, because passerby just see two idiots? -- that's definitely in operation as well.

The one thing that I have done is criticize in a way that makes the person look terrible if they ban you for it. I don't know how well this does for the bigger picture. Sometimes it is quite scary doing this though. My apologies for not replying earlier. I think spreading awareness like you were in your comment is also great, at least for people who have experienced this before, because they say 'oh yeah, that's true'.
Post reply on HN