Live data from Hacker News

Skin in the Game

lucumr.pocoo.org

31–40 of 70 posts

Re: Skin in the Game

#31
post #30

This feels like the opposite of my experience. In the early days of the internet nobody ever used their real name anywhere. It was all forums and IRC usernames.

I also have a similar feeling. Though I think OP is talking about open source contributions which might be different from more casual forums and IRC.

Re: Skin in the Game

#32
post #28

Earlier quoted context omitted.

Like I said a limit of one pseudonym on top of the real identity. If everyone knows everyone else is hard limited to a max of 1 pseudonym, then they wouldn’t be afraid any longer.

> hard limited to a max of 1 pseudonym A single combined pseudonym that becomes permanently useless for the rest of your life once it eventually accumulates enough little hints and other metadata across all services to get dox-able to your real identity? Hell no! [0] Even if it can be "killed" in favor of a secret successor pseudonym, that's still terrible, because the limited-life and periodic social death aspect is…

> services to get dox-able to your real identity? Hell no! [0] […] Would you use the same password everywhere on the internet too? Similar risk-management issues arise here.

I'm not sure this follows. It's clear that reusing a password is a bad idea, and more importantly a password is supposed to be secret. Identities _usually_ are not. It's clearly different in the context of Open Source but you would not go into many commercial transactions without verifying the person on the other side.

In quite a few countries (eg: Germany) cannot even voluntarily change your name and your personal information in many ways is required to be public (Impressumspflicht). Sweden maybe goes even further by making tax records public. If that was the same situation as with passwords then life in those countries would not work.

Re: Skin in the Game

#33
post #19

The author seems particularly hung up on the legal implications and consequences of being an open source contributor or project maintainer: "not all legal consequences can be waived", "distance to the legal system", "the real world legal consequences are then stuck with me", etc. It would benefit us all for the author to be specific about these if they are indeed real, as to my knowledge these are mostly FUD. There a…

There are definitely real world consequences of security or licensing issues in Open Source libraries. They are not always that someone will sue you but they are not necessarily any more pleasant.

Perhaps you should speak more about those consequences you’re afraid of?

Take the xz incident from this weekend. No one is crucifying the maintainer who gave Jia Tan commiter rights. No one is prosecuting or persecuting them. Everyone understands that they were under stress. I’m yet to see a single negative thing even been written about them.

The legal consequences you fear feel more imagined than real. As long as you do the best you can with the knowledge you have, no one is taking you to court or putting you in jail over it. I know people online don’t take the No Warranty clause statement seriously when they demand support, but a court definitely will.

At worst someone may come and ask you “is Jia Tan your alter ego?” And leave when they realise its obviously not.

But if you’re arguing that you’re risking reputational harm, where you might get a rep as “the guy who lgtm-d the backdoor PR without reviewing closely”, yeah that’s possible. And it’s a reasonable fear. That’s a risk you’re taking when most of the reward is to society benefiting from your work.

Re: Skin in the Game

#34
post #8
post #4

TIL that untypical is a word that means the same as atypical. It's funny. I think of anonymity as something that has been part of the Internet going back through at least the last three decades of my experience with it. Back in the day you had anonymous retailers, let alone people using pseudonyms. It was very much part of the fabric. If anything, it feels like anonymity on the Internet is harder to achieve these day…

I agree Part of that is getting older. A decade ago I contributed to Python under the name "Demur Rumed" & that's what they put in the 3.6 contributor list. Back then I worked at a company that didn't use GitHub so it was all personal stuff that I'd put under that name Since then I started working in open source companies that are operating on GitHub. An early meeting someone asked "who's this Demur Rumed making rand…

Its still good advice and maybe the best advice.

Look at all of us on hn with our cute little handles, or our throwaways.

You know who doesn't like anonymity? People who want to control you. People who want to harm you for you think, and what you say.

This is internet and it started with a dream and then and bunch of people came on and didn't like that dream but they sure wanted that sweet sweet internet cash and ever since they've been fighting tooth and nail at that dream because its a threat to their very ethos. Fuck them I choose internet.

Re: Skin in the Game

#35
post #22
post #7

> There was a bit of a kerfuffle ( https://www.openwall.com/lists/oss-security/2024/03/29/4 ) about subverting open source projects recently > [...] > A well established identity on the internet creates a form of inner piece Worth noting that the motivating incident (xz backdoor) was a user with legitimate history under what at the time appeared to be a real name. Even mandatory ID verification may not have helped in…

But, if they had presented such a passport, we would know they were a state actor. Or at least be able to assume it to a much more reasonable degree.

Really? Organized crime also produces fake documents, and they are sold/smuggled to independent actors constantly.

Plus, identity theft is not an uncommon crime.

Re: Skin in the Game

#36
post #23
post #22

Earlier quoted context omitted.

But, if they had presented such a passport, we would know they were a state actor. Or at least be able to assume it to a much more reasonable degree.

And what difference does that make - Really?

it increases the cost for the attacker, forging ID is expensive and against the law. It also leaves behind additional evidence that might be useful to investigators

Re: Skin in the Game

#37
post #33

Earlier quoted context omitted.

There are definitely real world consequences of security or licensing issues in Open Source libraries. They are not always that someone will sue you but they are not necessarily any more pleasant.

Perhaps you should speak more about those consequences you’re afraid of? Take the xz incident from this weekend. No one is crucifying the maintainer who gave Jia Tan commiter rights. No one is prosecuting or persecuting them. Everyone understands that they were under stress. I’m yet to see a single negative thing even been written about them. The legal consequences you fear feel more imagined than real. As long as yo…

> Perhaps you should speak more about those consequences you’re afraid of?

I'm not particular fearful of anything. It's an observation of a cultural change that I perceive. I'm facing many more interactions with throwaway accounts, individuals that have no desire to establish a reputation etc. It changes the way you communicate in subtle ways, there is less of a believe that you will run into some of those folks at conferences or they would not disclose themselves.

The legal elements of that are largely hypothetical since most folks will statistically not be involved with a lawsuit. However the legal underpinnings are largely what enables Open Source, so we cannot completely be blind to this. At the same time it's also clear that we care less about this as a whole. While it was once much more commonplace to verify authors, to vet licenses and contributors, that's clearly something that even established projects do less of. I have no idea what this means, but it seems like it's a shift nonetheless.

The practical implications are much more obvious. The creator of xz also suffered inconveniences despite not being the perpetrator when GitHub restricted their account.

> I know people online don’t take the No Warranty clause statement seriously when they demand support, but a court definitely will.

That's not entirely clear. At some point even writing code can become a legal matter and plenty of software engineers who were charged and convicted under wire-fraud charges are there to tell a story. Mind you, many of those things were outright obvious malice, but we don't know for sure where such lines are drawn for sure.

Re: Skin in the Game

#38

I would like to see the impossible: a AGPL kind of license that disavows attribution. No ego, personalities, decentralised, distributed, copyleft with the power to enforce it. In the early days of Creative Commons there was a no-attribution license option in the license maker they had but it was abandoned. Copyright is from an author but I would like to see authorship revoked not just rights granted. Perhaps some kin…

Train an LLM with it and then let it write the code.

At least Microsoft believes that works.

Re: Skin in the Game

#39

Earlier quoted context omitted.

the cost of pseudonym is the amount of work you invest to build a reputation, I don't think there's really a problem here

A bonafide genius might be able to build a similar reputation for 3 pseudonyms in as much time and effort as it takes for a more average person to build 1. Obviously most people are not bonafide geniuses and they know it, so there’s always a lingering fear of being taken in somehow.

[deleted]

Re: Skin in the Game

#40

Earlier quoted context omitted.

the cost of pseudonym is the amount of work you invest to build a reputation, I don't think there's really a problem here

A bonafide genius might be able to build a similar reputation for 3 pseudonyms in as much time and effort as it takes for a more average person to build 1. Obviously most people are not bonafide geniuses and they know it, so there’s always a lingering fear of being taken in somehow.

Throw the resources of an APT at the problem, how many reputationally high pseudonyms could be generated?
Post reply on HN