I'm glad they're going to have someone verify it. It seemed really strange to me that they rolled their own crowd funding platform for one use. Why didn't they go with a third party like Kickstarter in the first place?
Against Kickstarters TOS. They only allow "creative projects."
Dalton Caldwell: We Did It
31–40 of 59 posts
Re: Dalton Caldwell: We Did It
#32Re: Dalton Caldwell: We Did It
#33Did Svbtle change its font recently? The text looks terrible. It's blurry, poorly aliased and some of the letters have full-out gaps in the strokes. When viewed in Windows, of course.
Many web fonts seem to look bad on Windows, I think in part due to many websites being designed on Macs. This one looks particularly bad on Chrome, but Firefox isn't so bad.
I don't think we have to go whole hog and completely ignore designers' intent, but if usability is being compromised I think it makes sense to take advantage of the fact that we're doing the rendering on the client.
Re: Dalton Caldwell: We Did It
#34Congratulations from me, too! A very impressive result in such a short timeframe. In danger of asking a silly question, I do wonder about this bit though: In the very near future I will ask an impartial 3rd party take a look at our data (while preserving all privacy of our backers) and publicly verify that the join.app.net was operated in an honest manner. I might not be seeing the forest for the trees here, but how…
Re: Dalton Caldwell: We Did It
#35Congratulations from me, too! A very impressive result in such a short timeframe. In danger of asking a silly question, I do wonder about this bit though: In the very near future I will ask an impartial 3rd party take a look at our data (while preserving all privacy of our backers) and publicly verify that the join.app.net was operated in an honest manner. I might not be seeing the forest for the trees here, but how…
What App.net desires is for a trusted third party to say, "Yep, they're legit." So first, you would select an auditor who has a good reputation financially, technically, and ethically. Presumably, you'd line up a couple of secondary sources to publicly reinforce the auditor's reputation and bless the auditor's methodology.
It's been literally decades since I took any accounting classes, but I think you would need to follow the entire chain of some transactions, and this would necessitate showing real investor/customer data at some point. If you can secure that investor's/customer's permission, then sharing the data becomes a non-issue. How you get that permission becomes the issue.
If your auditor's reputation is strong enough, their name alone may be sufficient to secure permission. But you can also take steps to create a "security narrative" designed to put the investor/customer at ease.
You'd need to give the auditor access to your data, while preventing the possibility that they could leak this data. So the auditor would work in your offices, on your machines.
You'd provide laptops so that you can disable all peripheral ports. You'd secure the laptops to the table. The machines would have no optical drives. Those machines would net boot, have wired LAN access but not WAN, and no wireless access at all. They would run the software the auditors required but nothing else.
You'd confiscate phones and cameras from the auditors before they entered your audit environment. You could go a little crazy and record video of the auditors at work, with cameras angled so that you can see what notes the auditors are taking but not what screen they're looking at while they're taking notes. You could go a lot crazy and prove that the auditors are not sitting in front of any windows, thereby exposing data to high powered lenses across the street.
You could sanitize the data your auditors see, so that the auditor initially sees "Backer N" or "Vendor Y" instead of an actual person or company name.
Armed with some variation of the above security narrative, when the auditor says "I'd like to talk to backer N or vendor Y," you can present that narrative to the backer or vendor to secure their permission for auditor access to the information. I wouldn't be surprised if the average backer gets impatient and grants permission well before you're done explaining the security narrative.
Re: Dalton Caldwell: We Did It
#36Re: Dalton Caldwell: We Did It
#37Re: Dalton Caldwell: We Did It
#38This was the somewhat popular but incorrect comment I made previously: http://hackerne.ws/item?id=4278378
Much love. Props.
Re: Dalton Caldwell: We Did It
#39Just completed the sign-up, but still get "We don't recognize that username. This is probably because you haven't been invited to our alpha yet. To request an invitation, please email join@app.net." when I try logging in.
Re: Dalton Caldwell: We Did It
#40I would like to publicly admit my total wrongness and congratulate Dalton on his success with this project. You have won my backing and I'll be there 'apping' with the rest of you guys. This was the somewhat popular but incorrect comment I made previously: http://hackerne.ws/item?id=4278378 Much love. Props.
Let's hope this doesn't become a verb. Tweeting is bad enough, but "apping"?