Live data from Hacker News

Put a Fork in Caddy; It's Done

neflabs.com

71–80 of 90 posts

Re: Put a Fork in Caddy; It's Done

#71

Allow me to spend a few words shooting the messenger: This blog post comes across as petulant whining with a side order of personal attack. The author needs someone to buy them a drink and explain that Caddy is just not that into them and there are plenty of fish in the sea. Having said that, I have no idea why the makers of Caddy think that telemetry is a good idea. None of the examples given on the Caddy site make…

> Who cares about the depth of certificate chains? What value does it bring?

The data will be used to analyze the Internet from the server perspective, similar to e.g Mozilla collecting data from the clients perspective. It can/will be used by e.g researchers to improve the Internet (security, speed etc.)

Re: Put a Fork in Caddy; It's Done

#72

Not surprised at all. And for all the jibes people like to make when comparing things like apache to Caddy etc: guess which sole http/2 server passes all the spec tests? Hint: it’s the one “that looks like a dinosaur” from 1995.

The Go community is working on it :) #upstream

Re: Put a Fork in Caddy; It's Done

#73
post #64
post #60

Earlier quoted context omitted.

I’m surprised it survived the commercial rollout. AFAICT, the commercial rollout required $300/year per instance for any and all commercial usage. It made it sound like you weren’t even allowed to use the open source version for commercial use (is that even possible?).

The commercial licence for the prebuilt binaries is $50 pm for 2 instances. You can build yourself from source with no restrictions.

OK, I see the requirement to pay is only for the binaries. It does seem like grabbing binaries from gocaddy.com is the preferred installation method vs. apt-get, etc for nginx.

$300 is the annual rate for 1 instance.

Re: Put a Fork in Caddy; It's Done

#74
post #71

Allow me to spend a few words shooting the messenger: This blog post comes across as petulant whining with a side order of personal attack. The author needs someone to buy them a drink and explain that Caddy is just not that into them and there are plenty of fish in the sea. Having said that, I have no idea why the makers of Caddy think that telemetry is a good idea. None of the examples given on the Caddy site make…

> Who cares about the depth of certificate chains? What value does it bring? The data will be used to analyze the Internet from the server perspective, similar to e.g Mozilla collecting data from the clients perspective. It can/will be used by e.g researchers to improve the Internet (security, speed etc.)

Who are these researchers? Does Caddy have the kind of market share that would make that information useful?

I could sort of understand it is this was being pitched as a way to improve Caddy by reporting back crashes or misconfigurations. But what I've heard makes no sense to me.

Re: Put a Fork in Caddy; It's Done

#75
post #62

Earlier quoted context omitted.

Then I would suggest changing the wording to just "profile". Whether you realize it or not, the Mormons are a less-than-revered religious minority in many parts of the US, and dropping that fact so early in the article comes across as poisoning the well against him. There's plenty of reason to be upset with Mr. Holt. His own reply elsewhere in this thread reads more like a PR response than a real reply. But keep the…

> His own reply elsewhere in this thread reads more like a PR response than a real reply. What would you like me to say?

Hello, Matt!

To be clear, I am not a Caddy user and have no horse in this race. I tend to sympathize with the privacy-conscious, however, having been a user who turned off telemetry in Firefox after the Mr. Robot scandal. Let me see if I can explain why your response comes across as tone-deaf:

1) Your first response is "I haven't actually watched the video," which immediately suggests that you're not going to actually engage with the claims so much as tackle a strawman version of the claim. Now perhaps the author is repeating an accusation that he has made in the past, and so you actually are familiar with it already, but that's not how this comes across.

2) Your next response--"Several of us in the research community have agreed that telemetry can be a net good for the Web."--is not really doing anything to assuage the privacy concerns. It's not a technical refutation, and it's not a particularly fleshed-out emotional appeal, either. It's basically, "We disagree."

Put another way, let's imagine for a sec that you were a Tobacco CEO and the following exchange was recorded:

Reporter: Sir, we have a multitude of evidence that smoking is conclusively, irreversibly detrimental to human health.

CEO: Actually, a number of scientists and health officials have agreed that smoking is good.

Do you realize how tone-deaf that non-answer comes across?

3) Your final response is the most "PR" part, as it first advertises the product, then pivots away from the contention at hand in favor of praising how wonderful it is that it's open source and has a vast number of contributors. ---

I've already done the transposition analogy once, so I'm hesitant to do it again lest it look like I'm demonizing you, but I want you to read the below and see how you would perceive this response if it came from the CEO of J.Crew about accusations of child labor in its clothing factories:

  "Hey everyone. James here.

  I haven't actually reviewed the accusations yet because I've been at a conference.

  We believe that allowing underage employees to fill a limited number of positions at 
  are factories allows impoverished families to bring in badly needed revenue, and 
  ultimately serves as a net positive for these needy communities.

  A huge thanks to everyone for shopping at J.Crew and making it the World's Best 
  Clothing Line™ five years and counting!"
---

Hopefully that makes sense. It may not have been your intent, but perception is critical when you're the public face of the company. You can gain or lose a ton of goodwill among your users depending on whether you attempt to receive their criticisms with an open ear and work towards a solution, or dismiss them and dodge around the question. And even if you're doing the former, the mere perception of the latter can be damaging.

Good luck.

Re: Put a Fork in Caddy; It's Done

#76
post #16
post #6

Earlier quoted context omitted.

Skimming through that discussion, it seems like the developer is also somewhat naively optimistic and possibly underinformed regarding how much of his own and his customers/users' effort will be required to comply with the GDPR while gathering this data.

Which of "this data" do you see as relevant under GDPR?

Per the sibling thread - User Agent strings.

Re: Put a Fork in Caddy; It's Done

#77

Earlier quoted context omitted.

It's hard to imagine a productive forking discussion taking place on Caddy's forums directly. Certainly not in that announcement. At any rate having read this article I didn't see anything saying that "the whole project was garbage". The video (which Matt Holt removed) is also actually worth watching IMO, although I can see why he doesn't want it posted on the forum given its tone.

The video has a personality calling Matt an 'asshole'. That was unnecessary. Once that statement was made, I do not blame Matt for removing it. Name calling is not the way to go about addressing this important issue. It is indeed unfortunate that it has tainted what was otherwise a useful point of view.

Agree. They also call him a 'dick', repeatedly, and insinuate that he possibly has plans to monetize the gathered data. It escalates quickly and sadly I think all of that speculation and name-calling merely detracts from the strength and importance of the argument.

Re: Put a Fork in Caddy; It's Done

#78

Earlier quoted context omitted.

A server-installation data is not data about a particular user . It’s a information about a piece of running software. GDPR does not regulate information you can store about software components. It merely ensures that companies can only store information about people which the person has given explicit and implicit consent for, and that they can account for this consent. Log-data from a running service disconnected f…

It sounds like it is collecting User Agent strings which depending on who you ask is personal data.

That identifies browser version and operating system combinations in a way which is aggregated and 100% decoupled in a irreversible way from the actual browsing session as conducted by the user(s), given by the browser, automatically, to everyone by default on every request.

You won’t find a single lawyer anywhere who considers this to be privacy sensitive and definitely not covered by the GDPR.

Re: Put a Fork in Caddy; It's Done

#79

What a loveley sidecar ad-hominem. I'm sure his religious beliefs had a major impact on the telemetry issue.

not sure what message I should take from the Mormon.org profile... - Matt is young - Matt is religious Either of those are enough for me to think more seriously about Matt's ability to make judgements about software. (haha, HN you guys are jerks sometimes. I don't know how somebody's evident youth or apparent willingness to believe scientific impossibilities wouldn't warrant questions about their judgement, but y'all…

Religious flamewar will get you banned here. Please don't post like this again.

https://news.ycombinator.com/newsguidelines.html

Re: Put a Fork in Caddy; It's Done

#80
This introduction to this piece, with the utterly pointless link to Holt's profile on a religious social network, is startlingly inappropriate. It says something far more memorable and disturbing about "Nefarious Labs" than the piece does about Caddy.
Post reply on HN