HN user

dispose13432

480 karma
Posts0
Comments242
View on HN
No posts found.
Class Breaks 10 years ago

The "boringification" of computers will bring us back to the 70s.

If we have to prove _everything_ on your computer, from your calculator or Pokemon, how much do you think a license of windows will cost? $250,000?

Linux/FreeBSD/OpenBSD/Minix will be dead (no one to sponsor certification and then put it in the public).

Crazy "best-practices" (change passwords every couple days, password must include symbols, letters, numbers, upper-case and lower-case in a random order, but be no shorter or longer than eight characters)

Must have a full team of lawyers to prove that everything done fit the letter of the law, and that any hacks are not your responsibility

"Shinyness" is what allows you to have free VSCode and Atom.

Sure, I miss the 70s when you could get a text editor measured in bytes (but, btw, electron is probably more secure than 70s unix) but I definitely like the cost/convenience of modern software.

I have no problems with that guy. I have problems with all those guys who signed the key.

And, again, as you mentioned, those were security experts.

You think that your neighbor won't fall for that?

1. $587 a month in many cities in the US will barely rent a room.

Even in St. Louis (https://www.rentjungle.com/average-rent-in-st-louis-rent-tre... ), average monthly rent for a one bedroom apartment is $1000 a month. In LA, it's over 2000 a month, in NY it's 2700, in Detroit it's at 1000.

SNAP (Food stamps) give about $255 a month. That means that out of UBI, about $300 is left over for rent.

2. If everyone in the US gets $587 a month, that's 1.5 trillion a year.

The current US federal budget is 3.8 trillion.

That's about a quarter of current US federal budget, and we still have to give an actual livable stipend to the truly poor (SNAP, section 8, medicare), some kind of defense, leave some for state/city tax, federal infrastructure programs (freeways/trains).

Entire point of SSL/TLS is to ensure end to end authenticity and confidentiality.

The point is that country A can strongarm a certificate authority under their domain to sign any certificate they want. So if A wants to MITM google or github they can, and there's no way for you to know which certificate is the real one and which is the fake.

1. Key pinning.

2. Certificate transparency

3. Can't do it "accidentally". That's why a lot of people have 2 foot high fences, not that you can't jump over them but to create the atmosphere that this is private, and if you get caught there you can't say "oops".

4. Non-government (malicious router) can't MITM.

access to free lawyers at least for the poor etc is more important than access to the legal databases

That itself is a problem, while we have public defense lawyers, we don't have public preventive lawyers (who I can call and ask if what I'm about to do is altogether legal and what can I do to avoid run-ins with the law).

And the reason people initially used Facebook, Skype, and WhatsApp is not that they were easier to use or better. It's advertising. Notice how all of these are proprietary software made by companies with the means to advertise their software? You can bet people would use GnuPG, Diaspora, and XMPP if they had been advertised by companies like Facebook and Microsoft.

I know quite a few non-techies who use VLC, Firefox, LibreOffice, and other OS advertising-less projects. The difference is:

1. Facebook, Skype and WhatsApp solved problems others didn't and became big. Now it's too late to fight.

Had Diaspora been around before FB, and as easy to work with (put name here, picture here, password here, friend here. You're all set up. Let's go), or XMPP been around before Skype (which is a very old program in internet time), or Kontalk,Signal, etc. been around before WhatsApp (find friends by number, not by username), they probably would have taken off (at least to some degree).

Google came late onto the Desktop scene (Chromebooks) and are not successful while the incumbent (MS) is good.

MS came late onto the mobile scene and failed, while the incumbent (Google) is good.

That's why insurance isn't the end-all/be-all.

They've got enough money out of insurance to build themselves a new satellite, the problem is that they need that satellite yesterday, not today.

On the other hand, SpaceX isn't living off poor blokes who were hoodwinked by a starry-eyed agent. Their customers are professionals with lawyers and accountants taking care of things, so I don't feel that SpaceX is particularly unethical.

So let's go through a hypothetical situation:

A has friend 1 and 2. He vets them, checks their ID, goes to a key-signing party, trusts that they are 1 and 2 with his life.

Now he gets an email from "5000" who claims that he's from the IRS and needs to know information from you.

You look up this "5000"s signature.

Now, none of A's friends work in the IRS, but "5000" was signed by "500","302","201" and another 500 people.

"302" was signed by "23", "23" was signed by "2".

Should "A" send him the info?

Theoretically, he can call "2", ask him how "2" knows "23", then call "23" on behalf of "2", and so on.

But he doesn't know if "23" is honest, and all the more so "302".

And what if "302" says that he knows who he is because he self-identified as "5000 from the IRS" at a bar?

Too much thinking.

Now imagine A is the kind of person who downloads EXEs to view cat pictures?

Web of Trust seems to be an inherently broken paradigm.

Think about this. Let's say I trust my friends (so when my friends sign John Doe is John Doe, it's really him). It's a big deal (not every friend is so security conscious, maybe he met this guy on facebook and looks so real), but would I trust someone because of a friends-friend's recommendation?

I know which friends are naive. But which friend's-friend's-friend is naive?

And those are the only web-of-trust connection I have with him? Can I trust him? Can I not? How do I tell?

Some of us have a different opinion based on our own genuinely-held beliefs

Such as?

Browsing a website with an adblocker in a public place may literally give me a virus.

That's what HTTPS everywhere protects against.

It seems to require much less effort for folks, which is perhaps why they do this

It's also much easier to find readers.

Compare:

Facebook: become friends with your co-workers, now they see your picture

Blog: Please go to jupiter90000 (that's how many zeros?).blogspot.com to see my once a week pic updates!!

Is he paying $50 more for not participating, or getting a $50 discount for participating?

On the other hand, think about it like this:

What if insurance costs $10,000 a month, with a $9900 discount for "healthy behavior", so your average person pays $100 a month.

It's a great deal.

Now what happens if someone gets sick and can't upkeep his healthy behavior?

He loses his insurance.

This defeats the purpose of health insurance, but most people tend not to think of long-term repercussions.

They could have just as easily wrote their own fast and secure implementations of flash and Java instead of disabling them. Especially for Java given Google's deep experience with it and that they already have their own runtime.

Yup, Google should:

1. Reverse Engineer a proprietary language/API (Flash).

2. Write a secure VM for it (Flash and Java), trying to hit a moving target.

or

Get everyone to use an open, standardized tech (HTML5/js).

Can you give me one reason Google should prop up Flash?

He forgot to mention that since it's closed source and Adobe isn't releasing a SFW converter, even the Internet Archive can't backup a copy of the sfw file and have it useful.

OpenOffice, OOTH, can be converted to HTML or PDF, and even if OO and LO go down, the engine will still be available.

The failure modes of software are not as well understood, but are rarely life threatening.

Well, it's not life threatening, but what do you think will happen if every month your credit-card stops working for a few days because of a Windows/Linux regression?