Live data from Hacker News

The Insecurity Industry

edwardsnowden.substack.com

351–360 of 386 posts

Re: The Insecurity Industry

#351

Earlier quoted context omitted.

>the regulation provided by the FAA isn't perfect, so it shouldn't exist This is far from what I'm suggesting. I'm just saying that if it is a gov't regulated anything, those regulations will incur wacky decision making due to the influence of outside money. Nobody likes to be regulated against, and if they are in the position to do so, they will use any mechanism available to them to keep the status quo. I'm also su…

But despite your cynicism about "any gov't regulation body", you would agree that professional associations have by and large been a success in protecting the public in areas like construction trades, engineering, law, and medicine?

Not necessarily. Recently, Miami condo collapes. In the not too distant past London building fire. I'm sure if we were to go looking, we could find more examples. Are these edge cases?

I have less experience with other trades, but you did call out construction separately. My family comes from construction backgrounds at various levels. The 80s in the US saw a boom in the 20 story building construction, and then saw a total collapse (no pun intended) in the construction industry. There are lots and lots of building contracts won by lowest bidder, and the only way to do that is cutting corners somewhere. Usually in quality of material, or reducing the "over-engineered" portions to the point of risking saftey, etc.

It's also widely known in construction that the permitting offices can be gamed. Talk to the right people with the write phrases. NYC is infamous in that people playing by the rules get absolutely nowhere. You have to start spending cash and using influence to get things done. It's all just pointless to being corrupt.

Re: The Insecurity Industry

#352
post #256
post #226

Earlier quoted context omitted.

This makes no sense. Open source doesn't collect my personal information. (Except when it does, which is bad behavior.) Anyway, the law is capable of making reasonable distinctions where necessary.

Nearly every website that collects your personal information is running lots of open-source software. Sometimes, as with PHPSESSID and httpd logs collecting your IP, the collecting of that information is automatically done by that open-source software.

The configuration defaults will evolve but FOSS will continue.

Re: The Insecurity Industry

#353
post #199
post #188

"If you want to see change, you need to incentivize change. For example, if you want to see Microsoft have a heart attack, talk about the idea of defining legal liability for bad code in a commercial product. If you want to give Facebook nightmares, talk about the idea of making it legally liable for any and all leaks of our personal records that a jury can be persuaded were unnecessarily collected. Imagine how quick…

If this happens, it will be the end of open source and the indie web. Only large companies with large legal departments and serious liability insurance, and anonymous underground hackers, will be able to afford to make software public for commercial use or run a website.

Most open-source licenses explicitly say that there's no guarantees.

Re: The Insecurity Industry

#354
post #171

Earlier quoted context omitted.

Which part of Android is written in java? The kernel? The drivers? The JVM ? I somehow doubt anything significant of the OS itself is written in java :)

Which parts? I'm surprised this isn't well known already. Large parts of Android are written in Java. Amongst other things: * All the UI libraries, networking APIs code. * All the system apps and services like the home screen, the keyboard, the system server, the window manager, the telephony subsystem (very important!) and so on. * Many of the system APIs including services like the alarm manager, dropbox manager, s…

I guess it all depends where you make the "OS" stop :)

I'd say the kernel, the drivers and the JVM are already enough to say that Android is not "mostly written in java". And that's not not to talk about whatever shit operating system is running on the modem.

Re: The Insecurity Industry

#355

Earlier quoted context omitted.

But despite your cynicism about "any gov't regulation body", you would agree that professional associations have by and large been a success in protecting the public in areas like construction trades, engineering, law, and medicine?

Not necessarily. Recently, Miami condo collapes. In the not too distant past London building fire. I'm sure if we were to go looking, we could find more examples. Are these edge cases? I have less experience with other trades, but you did call out construction separately. My family comes from construction backgrounds at various levels. The 80s in the US saw a boom in the 20 story building construction, and then saw a…

Interesting. I would see the occasional failure as actually a further indication that the system is working— that it's maintaining a balance wherein most practice is within the bounds of what is safe, but it's not NASA-level lockdown where there's massive waste due to unnecessary redundancy and safety factors.

Re: The Insecurity Industry

#356
post #234

Earlier quoted context omitted.

Do you think Nancy Pelosi is going to ask Richard Stallman, the Debian Project Leader, and the Apache Foundation how the regulation should work? Or is she going to ask SalesForce, Google, Apple, and Microsoft?

Kind of an indictment of the FSF that you think no one would bother talking to them.

Lots of people respect the FSF, Stallman, or both, and put a lot of effort into talking to them, but I have seen no evidence that any US legislator is among them.

Re: The Insecurity Industry

#357
post #352
post #256

Earlier quoted context omitted.

Nearly every website that collects your personal information is running lots of open-source software. Sometimes, as with PHPSESSID and httpd logs collecting your IP, the collecting of that information is automatically done by that open-source software.

The configuration defaults will evolve but FOSS will continue.

Not if publishing FOSS with bad configuration defaults makes you the defendant in a multi-million-dollar class-action privacy-invasion lawsuit.

Re: The Insecurity Industry

#358
post #188

"If you want to see change, you need to incentivize change. For example, if you want to see Microsoft have a heart attack, talk about the idea of defining legal liability for bad code in a commercial product. If you want to give Facebook nightmares, talk about the idea of making it legally liable for any and all leaks of our personal records that a jury can be persuaded were unnecessarily collected. Imagine how quick…

Snowden did an incredible job on this article!

Re: The Insecurity Industry

#359
post #357
post #352

Earlier quoted context omitted.

The configuration defaults will evolve but FOSS will continue.

Not if publishing FOSS with bad configuration defaults makes you the defendant in a multi-million-dollar class-action privacy-invasion lawsuit.

It won't.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

Re: The Insecurity Industry

#360

"For example, if you want to see Microsoft have a heart attack, talk about the idea of defining legal liability for bad code in a commercial product." That sort of discussion is quickly dismissed on HN. And probably elsewhere on the web/over the internet. Instead we frequently see discussion blaming users of the software, i.e., Microsoft's customers, or even suggestions to make the customer liable, or comments from "…

[deleted]
Post reply on HN