Earlier quoted context omitted.
I agree Part of that is getting older. A decade ago I contributed to Python under the name "Demur Rumed" & that's what they put in the 3.6 contributor list. Back then I worked at a company that didn't use GitHub so it was all personal stuff that I'd put under that name Since then I started working in open source companies that are operating on GitHub. An early meeting someone asked "who's this Demur Rumed making rand…
> the advice for teenagers going online is that they should protect themselves by not sharing their identity. To me this is still the basic advice. This is not just for when sommething really bad happens, it's also all the smaller things. Like whether they need their employer to know they had a strong pro-union stance in the past. Or if they really like and promote some artist, that later happens to have an incredibl…
Skin in the Game
21–30 of 70 posts
Re: Skin in the Game
#22> There was a bit of a kerfuffle ( https://www.openwall.com/lists/oss-security/2024/03/29/4 ) about subverting open source projects recently > [...] > A well established identity on the internet creates a form of inner piece Worth noting that the motivating incident (xz backdoor) was a user with legitimate history under what at the time appeared to be a real name. Even mandatory ID verification may not have helped in…
Re: Skin in the Game
#23> There was a bit of a kerfuffle ( https://www.openwall.com/lists/oss-security/2024/03/29/4 ) about subverting open source projects recently > [...] > A well established identity on the internet creates a form of inner piece Worth noting that the motivating incident (xz backdoor) was a user with legitimate history under what at the time appeared to be a real name. Even mandatory ID verification may not have helped in…
But, if they had presented such a passport, we would know they were a state actor. Or at least be able to assume it to a much more reasonable degree.
Re: Skin in the Game
#24I doubt the xz maintainer would have rejected Mr. Jia Tan with verifiable record of employment with a defense contractor and complete Virginia identity, on the basis that their printed application form has no fingerprints and is not showing valid printer tracking dots. That isn't realistic at all, and wouldn't have mattered.
Re: Skin in the Game
#25The author seems particularly hung up on the legal implications and consequences of being an open source contributor or project maintainer: "not all legal consequences can be waived", "distance to the legal system", "the real world legal consequences are then stuck with me", etc. It would benefit us all for the author to be specific about these if they are indeed real, as to my knowledge these are mostly FUD. There a…
Re: Skin in the Game
#26> Maybe verified identities an illusion, but sometimes these illusions is all that's needed to feel more relaxed. Author almost realizes that they're asking for something that is at best a mirage and then bats away that thought[0]. But that's not something that you can casually dismiss near the end of your post, it's a crucial flaw in the whole idea! The comfort that you get from seeing "John Smith" as the contributo…
Re: Skin in the Game
#27Earlier quoted context omitted.
> Since then I started working in open source companies that are operating on GitHub. An early meeting someone asked "who's this Demur Rumed making random pull requests?" sheepishly I declared myself, "Please update your profile with your real name I make a new GitHub account for any new job I start using my company email I never use my personal accounts for anything work related I once got a message from HR telling…
For open- or closed-source work? If I'm doing open source coding, whether professional or not, I'd always want that associated with my personal GH account.
I don't own that code so I don't associate it with personal accounts
But I've never done open source work for an employer either
Re: Skin in the Game
#28Earlier quoted context omitted.
> Pseudonyms are fine, as long as each person has only one What's the problem with real person John Doe also having an account called anon12345? The problem isn't one person having multiple identities, the problem involve mismatches between the quality or qualities of those identities versus particular use cases.
Like I said a limit of one pseudonym on top of the real identity. If everyone knows everyone else is hard limited to a max of 1 pseudonym, then they wouldn’t be afraid any longer.
A single combined pseudonym that becomes permanently useless for the rest of your life once it eventually accumulates enough little hints and other metadata across all services to get dox-able to your real identity? Hell no! [0]
Even if it can be "killed" in favor of a secret successor pseudonym, that's still terrible, because the limited-life and periodic social death aspect is still there, and because humans regularly have different sides in different social contexts. Who wants to screen online dates with the same pseudonym used for asking resume advice?
> then [people afraid of sockpuppets and impersonators] wouldn’t be afraid any longer
If you're that afraid that a pseudonymous account isn't real, you know what? You just ask them to positively authenticate before extending any trust!
Why should everyone else in the world submit to a dystopian panopticon, merely to satisfy your lack of due-diligence and/or anxiety to avoid confrontation?
[0] Would you use the same password everywhere on the internet too? Similar risk-management issues arise here.
Re: Skin in the Game
#29Copyright is from an author but I would like to see authorship revoked not just rights granted. Perhaps some kind of corporate authorship so there is one organisation with the actual legal rights? Theres no reason why contributors have to be anonymous - the project with the license can have named, verified, real people. The legal stuff is beyond me!