Live data from Hacker News

Skin in the Game

lucumr.pocoo.org

21–30 of 70 posts

Re: Skin in the Game

#21
post #8

Earlier quoted context omitted.

I agree Part of that is getting older. A decade ago I contributed to Python under the name "Demur Rumed" & that's what they put in the 3.6 contributor list. Back then I worked at a company that didn't use GitHub so it was all personal stuff that I'd put under that name Since then I started working in open source companies that are operating on GitHub. An early meeting someone asked "who's this Demur Rumed making rand…

> the advice for teenagers going online is that they should protect themselves by not sharing their identity. To me this is still the basic advice. This is not just for when sommething really bad happens, it's also all the smaller things. Like whether they need their employer to know they had a strong pro-union stance in the past. Or if they really like and promote some artist, that later happens to have an incredibl…

It's still good advice for generic online conversations (not necessarily contributions, but that's not what the adults had in mind when they gave that advice), but became effectively impossible the moment Facebook started letting other people tag you even if you didn't have an account.

Re: Skin in the Game

#22
post #7

> There was a bit of a kerfuffle ( https://www.openwall.com/lists/oss-security/2024/03/29/4 ) about subverting open source projects recently > [...] > A well established identity on the internet creates a form of inner piece Worth noting that the motivating incident (xz backdoor) was a user with legitimate history under what at the time appeared to be a real name. Even mandatory ID verification may not have helped in…

But, if they had presented such a passport, we would know they were a state actor. Or at least be able to assume it to a much more reasonable degree.

Re: Skin in the Game

#23
post #22
post #7

> There was a bit of a kerfuffle ( https://www.openwall.com/lists/oss-security/2024/03/29/4 ) about subverting open source projects recently > [...] > A well established identity on the internet creates a form of inner piece Worth noting that the motivating incident (xz backdoor) was a user with legitimate history under what at the time appeared to be a real name. Even mandatory ID verification may not have helped in…

But, if they had presented such a passport, we would know they were a state actor. Or at least be able to assume it to a much more reasonable degree.

And what difference does that make - Really?

Re: Skin in the Game

#24
There was a short entertainment clip on YouTube with ex-CIA person Jonna Mendez - that I can't immediately find - in which she said(as accurate as my heavily quantized memory goes) "The Agency can produce anything, so long it's made of paper, for official purposes". And it struck me, despite aware that spies forge documents all the time: it'll be the real deal when they do it. There is some process legitimacy that backs those.

I doubt the xz maintainer would have rejected Mr. Jia Tan with verifiable record of employment with a defense contractor and complete Virginia identity, on the basis that their printed application form has no fingerprints and is not showing valid printer tracking dots. That isn't realistic at all, and wouldn't have mattered.

Re: Skin in the Game

#25
post #19

The author seems particularly hung up on the legal implications and consequences of being an open source contributor or project maintainer: "not all legal consequences can be waived", "distance to the legal system", "the real world legal consequences are then stuck with me", etc. It would benefit us all for the author to be specific about these if they are indeed real, as to my knowledge these are mostly FUD. There a…

There are definitely real world consequences of security or licensing issues in Open Source libraries. They are not always that someone will sue you but they are not necessarily any more pleasant.

Re: Skin in the Game

#26

> Maybe verified identities an illusion, but sometimes these illusions is all that's needed to feel more relaxed. Author almost realizes that they're asking for something that is at best a mirage and then bats away that thought[0]. But that's not something that you can casually dismiss near the end of your post, it's a crucial flaw in the whole idea! The comfort that you get from seeing "John Smith" as the contributo…

Author here. I’m not asking for anything in particular, I’m primarily writing about a shift in Open Source culture I have observed.

Re: Skin in the Game

#27

Earlier quoted context omitted.

> Since then I started working in open source companies that are operating on GitHub. An early meeting someone asked "who's this Demur Rumed making random pull requests?" sheepishly I declared myself, "Please update your profile with your real name I make a new GitHub account for any new job I start using my company email I never use my personal accounts for anything work related I once got a message from HR telling…

For open- or closed-source work? If I'm doing open source coding, whether professional or not, I'd always want that associated with my personal GH account.

If I'm being paid by an employer to do it, it doesn't go on my personal anything, period

I don't own that code so I don't associate it with personal accounts

But I've never done open source work for an employer either

Re: Skin in the Game

#28
post #14

Earlier quoted context omitted.

> Pseudonyms are fine, as long as each person has only one What's the problem with real person John Doe also having an account called anon12345? The problem isn't one person having multiple identities, the problem involve mismatches between the quality or qualities of those identities versus particular use cases.

Like I said a limit of one pseudonym on top of the real identity. If everyone knows everyone else is hard limited to a max of 1 pseudonym, then they wouldn’t be afraid any longer.

> hard limited to a max of 1 pseudonym

A single combined pseudonym that becomes permanently useless for the rest of your life once it eventually accumulates enough little hints and other metadata across all services to get dox-able to your real identity? Hell no! [0]

Even if it can be "killed" in favor of a secret successor pseudonym, that's still terrible, because the limited-life and periodic social death aspect is still there, and because humans regularly have different sides in different social contexts. Who wants to screen online dates with the same pseudonym used for asking resume advice?

> then [people afraid of sockpuppets and impersonators] wouldn’t be afraid any longer

If you're that afraid that a pseudonymous account isn't real, you know what? You just ask them to positively authenticate before extending any trust!

Why should everyone else in the world submit to a dystopian panopticon, merely to satisfy your lack of due-diligence and/or anxiety to avoid confrontation?

[0] Would you use the same password everywhere on the internet too? Similar risk-management issues arise here.

Re: Skin in the Game

#29
I would like to see the impossible: a AGPL kind of license that disavows attribution. No ego, personalities, decentralised, distributed, copyleft with the power to enforce it. In the early days of Creative Commons there was a no-attribution license option in the license maker they had but it was abandoned.

Copyright is from an author but I would like to see authorship revoked not just rights granted. Perhaps some kind of corporate authorship so there is one organisation with the actual legal rights? Theres no reason why contributors have to be anonymous - the project with the license can have named, verified, real people. The legal stuff is beyond me!

Re: Skin in the Game

#30
This feels like the opposite of my experience. In the early days of the internet nobody ever used their real name anywhere. It was all forums and IRC usernames.
Post reply on HN