Live data from Hacker News

Goodbye, and Thanks for All the Bikesheds

queue.acm.org

211–220 of 285 posts

Re: Goodbye, and Thanks for All the Bikesheds

#211

For those unaware, PHK created (amongst other things) the MD5crypt password hashing algorithm ( $1$… ). It came before bcrypt (1999), scrypt (2009), SHA2crypt (2016), etc , and was committed in 1994: * https://svnweb.freebsd.org/base/head/lib/libcrypt/crypt.c?re... * https://github.com/freebsd/freebsd-src/commit/3b2b7f71deba2a... * https://phk.freebsd.dk/sagas/md5crypt/ * https://en.wikipedia.org/wiki/Poul-Henning_Ka…

Okay. What qualifications does phk have that are relevant to the current subject?

He has a daughter and thus does not want to worry about her online well-being yet (see article).

But I believe that's misplaced, because she will be vulnerable as an adult, and there was never a way to produce encryption which was not easy to turn to non-crackable encryption for those not wanting to play along with national laws.

Re: Goodbye, and Thanks for All the Bikesheds

#212
post #134

Earlier quoted context omitted.

> A sensible regulator would leave some responsibility to the parents (Speaking as a parent of three) why can't we just leave all responsibility to the parents? In our experience in the offline world it seems this applies! I speak as someone who's taken each of my three children - for two of them, multiple times - to the emergency room to be treated for broken bones incurred in the course of Real Life[tm]. Yes, they…

> (Speaking as a parent of three) why can't we just leave all responsibility to the parents? Then I'm sure that you appreciate that there are both legal and informal checks in place ensuring that you can take responsibility for your children in the offline world. For example: I would be surprised if your children were able to play organized sports without your permission. Failing to ask for permission would deny you…

Uhm, I am pretty sure kids do not require signed permission to go on a field with their friends and play basketball or football (either the European or American... or Australian one :). And you are likely to not even find out about it unless someone has broken something.

Signed permissions are needed for "organized sport", where there are other adults or companies that can be held liable in case something relatively usual happens (like broken bones in contact sports, but also pulled or ruptured tendons/muscles in non-contact sports...).

So the challenge is: how do we ensure kids enough freedom to do the things which they need to explore themselves, while ensuring no life altering harm of high chance (death/disability/going to jail...) comes to them or they instill on others — and do not have to have them tracked completely throughout their lives.

Re: Goodbye, and Thanks for All the Bikesheds

#213
post #115

For those unaware, PHK created (amongst other things) the MD5crypt password hashing algorithm ( $1$… ). It came before bcrypt (1999), scrypt (2009), SHA2crypt (2016), etc , and was committed in 1994: * https://svnweb.freebsd.org/base/head/lib/libcrypt/crypt.c?re... * https://github.com/freebsd/freebsd-src/commit/3b2b7f71deba2a... * https://phk.freebsd.dk/sagas/md5crypt/ * https://en.wikipedia.org/wiki/Poul-Henning_Ka…

To clarify: not MD5 itself. It was created in 1991 by Ron Rivest. (It is my experience that knowledge of these things isn't as widely distributed as one might hope.) I first came across it in 1995/1996: Wow, what a magical tool for backend web stuff! I used it for everything.

is the difference between MD5 and MD5crypt the same as between Java and Javascript or are they actually related somehow?

Re: Goodbye, and Thanks for All the Bikesheds

#214

Earlier quoted context omitted.

Like half this list + Meredith are lawyers/policy people. Add in computer security specialists/operators. They use software as a tool to achieve political ends. "tech bros" in context of the article is pretty much referring to builders of software. The tech sisters who have built significant projects are indeed mythically rare. Names like Radia Perlman might be a better choice.

If you refresh yourself on the thread originator comment, you will notice we are talking about "tech sisters advocating for an absolute right to privacy", not "tech sisters who have built significant technical projects". I think Dr. Perlman fits in the latter, not the former category. Also, I think the intended meaning of "tech bros" in the article is more nuanced. Charitably: naive, sophomorically idealistic SV tech…

He already previously qualified tech bros as people who literally built technology and a whole industry in the US that the EU did not build.

The advocating for privacy is the cherry on top. And I never said their work was insignificant. It’s just not foundational — not something I’ve built my own career on the back of — and the primary association that you would have with any of them is going to be advocacy.

Radia is also absolutely a privacy advocate and literally wrote the book (as usual) on the intersection between Network Security and Privacy…

Maybe she would been better served spending all her time building a Twitter following and working on press releases.

Re: Goodbye, and Thanks for All the Bikesheds

#215

Earlier quoted context omitted.

It's not anti-privacy to point out the obvious that privacy-advocacy is sometimes at odds with governments and the will of voters at large. Privacy is being abused by criminals to victimize people at scale. Just because privacy is a moral good doesn't mean you are morally off the hook for enabling criminals. Governments are so aware of this they're passing sweeping laws against it. This is your new reality -- you can…

He's very clearly arguing against absolute privacy on the Internet and is saying that the people who advocated for it, which he besmirches as "tech bros", are responsible for the governments going too far now, instead of a happy compromise having been set out at the beginning, which by the way totally mischaracterizes the history of the Internet, where the governments were trying to impose total surveillance from the…

He’s not exactly wrong either. The founders/executives of a tech startup I worked for spun off a completely unrelated E2EE chat app as a separate startup and didn’t market it to anyone.

It’s only used by them and their buddies and basically only for OTR conversations related to their publicly traded company that would have put them in prison. Totally the “let’s defraud these investors and do industrial espionage” type shit. I also know about a good half dozen other VC-funded E2EE chat apps that are also exactly this.

They do it just to get something they control in app stores that’s also a separate entity. Then they don’t have to answer uncomfortable questions about why such and such is on their phone.

This is some of what regulators are seeing and finding a problem with.

Re: Goodbye, and Thanks for All the Bikesheds

#216

A bit of an aside, but after someone introduced me to the notion of Reversible Decisions, it quickly became apparent to me that the solution to the bikeshed problem is to throw money at it before the roosters can start preening about which color the shed should be. Decisions that are reversible should just go with the instinctive answer of whoever volunteers to work on it. I've been in many meeting rooms where, becau…

> but I've seen a couple cases where the bus number for a module wanted a solution with fewer consequences but the group wisdom wanted something flashier but also more brittle.

Only a couple? This is some peoples entire job, we can refer to them as "enterprise architecture".

Lived experience is a decade ago, and you once saw Kafka solve someone's queuing problem so now everyone's api interface has to run over Kafka. Even synchronous ones.

Re: Goodbye, and Thanks for All the Bikesheds

#217
post #83
post #74

Earlier quoted context omitted.

I don't understand what's hard to understand. Regulation that affects people and devices that have no risk of being used for the purported thing that's supposed to be protected against is not well-scoped.

Obviously if the government knew that you had no kids, they wouldn't need to check it. How do you propose they find out, without asking you to prove it?

Backwards. The government knows who has kids because they do things like issue birth certificates and operate state schools. In a lot of places it's legally very difficult not to be listed as a parent on government records.

So why should I have to prove I don't have kids when the government can know I'm not on any of those lists?

Re: Goodbye, and Thanks for All the Bikesheds

#218

Earlier quoted context omitted.

+1! I've fallen in love with many of Amazon's in-group concepts, and maybe I'm just drinking the koolaide, but they have the concept of a "two-way door", which is exactly this -- a decision that can be made, unmade, remade, etc relatively cheaply. If you can identify that a choice isn't very dangerous, you can focus on the things that really are instead.

Amazon's leadership principles are fantastic. They are applicable to anyone doing any job at any level.

... so were "HP Way", "Siebel Principles", "Hyperion Essbase ethics" and many others, collecting dust on library shelves while MBA students getting instant high from Jack Welch's "Winning".

Re: Goodbye, and Thanks for All the Bikesheds

#219

Earlier quoted context omitted.

So is he suggesting that in the future, models of Opus 4.8 tier will no longer be as affordable? Like it would become 3-5x more expensive? Now that's quite a prediction.

I believe the added point was that new tools identify a group of bugs, and then there aren’t more bugs to find. At which point it becomes another tool you use and don’t think about. Also, from what I recall, Anthropic and OpenAI subsidize their prices by ~40x? That said, given the prices*quality of recently released open models, I think the cost issue is moot.

> Also, from what I recall, Anthropic and OpenAI subsidize their prices by ~40x?

Ed Zitron said this?

Re: Goodbye, and Thanks for All the Bikesheds

#220
post #182

Earlier quoted context omitted.

This often massively discounts the cost of reversing decisions. People often work to build things without any thought given to those who have to maintain it afterwards. Especially when it's not them. I worked at a large, publicly-traded multinational where decades prior and they were still just a 4 man startup they decided the database server and all timestamps should be in the local timezone. They are still using ES…

There seems to be some general pattern here that you can find pretty often in "dev war stories" contexts: (1) We're a small startup/new product team/etc, let's just build the MVP and keep everything simple! (2) Now we're not small anymore and suddenly have all kinds of nonfunctional requirements we never imagined before! But our simple architecture from before is making everything a pain now! The natural instinct is…

> The natural instinct is then to compromise on the "simpleness" of the first prototype and already try to anticipate all the scaling and nonfunctional requirements that might come later

This is a form of Second System Effect Brooks wrote about in 1975.

https://en.wikipedia.org/wiki/Second-system_effect?wprov=sft...

Post reply on HN