Live data from Hacker News

The Most Backdoor-Looking Bug I’ve Ever Seen

buttondown.email

211–220 of 222 posts

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#212

Earlier quoted context omitted.

I don’t think your paraphrase is an accurate representation of the article.

From the article: > Anyway, it’s been a while, the world is a different place now, and maybe Hanlon’s razor cuts deeper than I thought. How else would you interpret it?

Paraphrasing Clarke, "Any sufficiently advanced incompetence is indistinguishable from a backdoor."

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#213

> PitM attack I see we've arrived at the point where we're re-naming commonly established acronyms in order to remain politically correct.

"Eschew flamebait. Don't introduce flamewar topics unless you have something genuinely new to say. Avoid unrelated controversies and generic tangents."

https://news.ycombinator.com/newsguidelines.html

Just because an article includes some provocation does make it ok* to swallow the bait and then bring it in here and start a flamewar with it. There's a much better option: don't take the bait in the first place.

* edit: I meant does not make it ok, of course - that was a typo.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#214
post #83
post #69

Earlier quoted context omitted.

If i remember correctly, Telegram pre-dates Signal by several months. It was well-established by the time Signal became usable. This said, the relationship between Telegram and the cryptography community has always been rocky, probably because they touted their E2E support as a differentiator from the start (Whatsapp, Messenger, and whatever-Google-had were not e2e at the time) but quite a few people pointed out thei…

They indeed were one of the first if not the first to come out with a messaging app that can e2e encrypt your chat. This was a time when WhatsApp was found using a plaintext protocol, and right after the Snowden revelations. They did move the needle a bit at the right time. One of the most vocal critics was Moxie, who later founded Signal. It's ironic that 7 years after Snowden and Telegram, Signal the supposed more…

The signal protocol is used in WhatsApp, and will be rolled out as a part of Google's latest RCS effort. Signal maybe didn't catch on, but Moxie's goal of making communications encrypted seems to have worked out all right.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#215

- Clickbait title: Check. - Half-admission that the clickbait title might not apply (at the end of the article by mentioning Hanlon's Razor): Check. - Actual good criticism on "don't roll your own crypto": Check (this is not a sarcasm, I liked that part of the article very much). - Casual mention that the incident is from 7 years ago but implying that today there's a backdoor: Check. - HN going crazy negative when Te…

It’s really messed up that people worried about their privacy are switching from WhatsApp (which has e2e enabled so nobody can read your messages) to Telegram (which generally doesn’t). People whose messages were secure are now going to get exposed when there’s a Telegram breach.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#216
post #97

Earlier quoted context omitted.

The downside is the cost to communication. I didn't know what a PitM was. After a bit I guessed it was Person, i.e. man in the middle, but I wasn't sure that it didn't mean something else. I'm not sure how big the gain is here. Are people really going to read "man in the middle" and assume that no woman could ever do this?

Also: where are the people who were offended by "man-in-the-middle"? Can you point to a single non-man who was offended that the evil-doer in this example was identified as a man? Or can you point to a single man who was offended for the same reason?

There are people who object to all gender-neutral uses of "man", probably more from the belief that it perpetuates bias than from personally taking offense.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#217
post #213

> PitM attack I see we've arrived at the point where we're re-naming commonly established acronyms in order to remain politically correct.

" Eschew flamebait. Don't introduce flamewar topics unless you have something genuinely new to say. Avoid unrelated controversies and generic tangents. " https://news.ycombinator.com/newsguidelines.html Just because an article includes some provocation does make it ok* to swallow the bait and then bring it in here and start a flamewar with it. There's a much better option: don't take the bait in the first place. * ed…

dang, just so we are clear, are you saying my use of a technical term of my own field which I prefer, and which I definitely didn't come up with (it's on the Wikipedia page), in a newsletter I did not submit to HN, was a provocation and bait to start a flamewar (to which I was careful not to participate until now, even if there are some pitiful arguments in this thread)?

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#218
post #108
post #100

Earlier quoted context omitted.

Where can we see this comment? Here at HN or the post itself? I could not see any comments with 'paveldurov'.

Set ‘showdead’ in your profile to yes and scroll down the comments to the end.

Thank you for the explanation!

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#219
post #145
post #97

Earlier quoted context omitted.

The downside is the cost to communication. I didn't know what a PitM was. After a bit I guessed it was Person, i.e. man in the middle, but I wasn't sure that it didn't mean something else. I'm not sure how big the gain is here. Are people really going to read "man in the middle" and assume that no woman could ever do this?

Well, now you know. And I bet the first time you read 'MitM' you didn't know what it was either.

Right, but learning and memorising multiple terms for the same thing has a cost. Maybe that cost is outweighed by the benefits of making terminology less sexist, that is what I'm unsure about.

Re: The Most Backdoor-Looking Bug I’ve Ever Seen

#220
post #213

Earlier quoted context omitted.

" Eschew flamebait. Don't introduce flamewar topics unless you have something genuinely new to say. Avoid unrelated controversies and generic tangents. " https://news.ycombinator.com/newsguidelines.html Just because an article includes some provocation does make it ok* to swallow the bait and then bring it in here and start a flamewar with it. There's a much better option: don't take the bait in the first place. * ed…

dang, just so we are clear, are you saying my use of a technical term of my own field which I prefer, and which I definitely didn't come up with (it's on the Wikipedia page), in a newsletter I did not submit to HN, was a provocation and bait to start a flamewar (to which I was careful not to participate until now, even if there are some pitiful arguments in this thread)?

Certainly not. I phrase comments like that as a way of connecting with the point of view of the commenter, because that makes moderation more persuasive. By no means does it follow that I agree with them. I'm simply acknowledging how they feel [1].

What I'm telling the GP, and HN users generally, is that when something lands with them as a provocation or bait, we need them to pause instead of rushing to HN threads to vent about it, regardless of what the intention of the writer seems to them to be. It's all too easy for readers to get provoked, especially on the internet, even when no one intended to provoke them. Instead of reacting reflexively and making the thread even worse, we need them to handle that reaction and wait until they're able to be a bit more thoughtful [2].

Of course it's also my job to make that case to the commenter without inadvertently provoking anybody else. Obviously I didn't pull that off this time. I can see how my GP comment looked like a claim about your article, and I should have been more careful to disambiguate my own intent [3]. Sorry for fucking that up!

On another note, I wish you wouldn't be "careful not to participate" on topics that you know a lot about! If you participate by sharing some of what you know, there's a chance for people to learn. Of course the arguments here are pitiful—HN is a large internet forum. I don't like it either. But it's all relative, and you (i.e. all of us) shouldn't underestimate the power of adding solid information to a discussion.

[1] I used to tell people "Please don't X, regardless of how right you are"—but that sounds like I'm saying they're right, which I'm not (I say that to everybody). So now I phrase it as regardless of how right you are or feel you are, which seems to preempt that misunderstanding: https://hn.algolia.com/?dateRange=all&page=0&prefix=false&qu...

[2] https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor...

[3] https://hn.algolia.com/?dateRange=all&page=0&prefix=false&so...

Post reply on HN