HN user

dogecoinbase

1,996 karma
Posts57
Comments545
View on HN
www.citationneeded.news 1y ago

Coinbase appears to have violated campaign finance laws with 25M donation

dogecoinbase
43pts3
twitter.com 4y ago

Looks like Python just had a left-pad like incident

dogecoinbase
17pts1
statmodeling.stat.columbia.edu 4y ago

Google’s Problems with Reproducibility

dogecoinbase
4pts0
arxiv.org 4y ago

Retrodictive Quantum Computing

dogecoinbase
2pts0
twitter.com 4y ago

Mozilla to pause crypto donations while they review climate impact

dogecoinbase
13pts0
mta.openssl.org 4y ago

Rich Salz to OpenSSL: Please change your mind

dogecoinbase
85pts23
www.theregister.com 4y ago

HashiCorp runs low on staff, calls a halt to Terraform pull requests

dogecoinbase
24pts4
rbaron.net 5y ago

Reverse Engineering the M6 Smart Fitness Bracelet

dogecoinbase
94pts7
www.cnbc.com 5y ago

Consumer Reports engineers find Teslas can drive with nobody in the driver seat

dogecoinbase
5pts1
9to5google.com 5y ago

Google Voice will soon no longer be able to forward text messages

dogecoinbase
15pts2
www.notion.so 5y ago

In Defense of Mutual TLS

dogecoinbase
12pts22
groups.google.com 5y ago

The Chrome Root Program

dogecoinbase
92pts34
lgtm.com 7y ago

Kernel RCE in iOS/macOS with ICMP

dogecoinbase
163pts64
flaked.sockpuppet.org 8y ago

A unified timeline of Efail disclosure events

dogecoinbase
1pts0
tmate.io 8y ago

Tmate: tmux terminal sharing

dogecoinbase
2pts0
utcc.utoronto.ca 8y ago

You probably don't want to run Firefox Nightly any more

dogecoinbase
3pts0
groups.google.com 8y ago

Firefox Nightly Builds to Send 50% of DNS Requests to Cloudflare

dogecoinbase
4pts0
www.bunniestudios.com 8y ago

An Intuitive Motor: IQ Control’s Serial-To-Position Module

dogecoinbase
3pts0
www.europol.europa.eu 8y ago

Law Enforcement Call for the End of Carrier Grade NAT

dogecoinbase
1pts0
www.coindesk.com 8y ago

Accenture Awarded Patent for 'Editable Blockchain' Tech

dogecoinbase
1pts1
www.w3.org 8y ago

W3C Hearing the Concerns the EME Recommendation Raises

dogecoinbase
2pts0
blog.archive.org 8y ago

HyperCard On The Archive

dogecoinbase
327pts115
tools.ietf.org 8y ago

RFC 8200: Internet Protocol, Version 6

dogecoinbase
1pts0
www.dentacoin.com 9y ago

Dentacoin: The First Blockchain Concept for the Global Dental Industry

dogecoinbase
2pts0
abc7news.com 9y ago

SFO-bound flight diverted due to lithium battery laptop fire

dogecoinbase
1pts0
www.linux.com 9y ago

Welcoming FRRouting to the Linux Foundation

dogecoinbase
3pts0
github.com 9y ago

Systemd eats udev, poettering says breaking not their problem

dogecoinbase
33pts10
mike.tig.as 9y ago

Tor Onion Browser for iOS is now free

dogecoinbase
2pts0
whispersystems.org 9y ago

Open Whisper Systems: caveat re safety numbers if you've published a fingerprint

dogecoinbase
2pts1
rya.nc 9y ago

Ryan Castellucci: Forensic Bitcoin Cracking

dogecoinbase
3pts0

They claim full open source but for several years they did not release the server.

Specifically, they didn't publish the source for their server-side from 20 April 2020 to 6 April 2021 [0] while they secretly added a cryptocurrency payment system to which Moxie was a paid technical advisor [1], which Moxie denied they were doing in January 2021 [2].

0: https://www.androidpolice.com/2021/04/06/it-looks-like-signa... (source was published shortly after the publication of that article)

1: https://news.ycombinator.com/item?id=26715013 (comment from founder of MobileCoin)

2: https://www.theverge.com/22249391/signal-app-abuse-messaging...

Glad to hear Moxie's out. As a reminder, Signal didn't publish the source for their server-side from 20 April 2020 to 6 April 2021 [0] while they secretly added a cryptocurrency payment system to which Moxie was a paid technical advisor [1], which Moxie denied they were doing in January 2021 [2].

0: https://www.androidpolice.com/2021/04/06/it-looks-like-signa... (source was published shortly after the publication of that article)

1: https://news.ycombinator.com/item?id=26715013 (comment from founder of MobileCoin)

2: https://www.theverge.com/22249391/signal-app-abuse-messaging...

Right, the issue is that it's not possible to set file retention for individual channels/conversations, so if you want to have long-term file retention in some places and brief in others, it can't be done (additionally (in my experience, at least), people tend to believe that setting message retention will also apply to files -- it's not called out in the interface/etc).

Bear in mind that at this time, and for many years, data retention policies simply do not apply to uploaded files in a given channel (IIRC it does apply to global retention, but I'm not totally sure of the current behavior). There's a sensitive channel with a short retention period in a Slack for a company I do some consulting for and every few months I remind the admins that images/PDFs/etc that are uploaded to the channel are not purged and they should manually do it... but there's still stuff in there from 2016 if I do a search in:#channel for Files.

after all, you can never protect against someone making an entirely new device that just happens to look like an iPhone.

The specific threat being protected against (leaving aside the increased safety of iPhone users by making the stolen parts market untenable) is your phone, that you recognize and use as your phone and which contains your confidential material and credentials, having internal components swapped out while unattended.

I don't have a specific alternative, but I think that if it's not possible to be effective in a role, one should decline it. It's possible to be an effective SWE while still writing (and hopefully also sometimes fixing) bugs.

Security is not easy, and the entire field is not negligent - the problem is massively asymmetrically stacked against security practitioners, enhanced by poisonous attitudes like the ones expressed here.

Is remaining in a role in which it's not possible to be effective negligent?

This is literally the business model. The owner of an IP address is responsible for the content delivered from that IP address. Cloudflare would like to have it both ways -- they get to multiplex sites behind their network infrastructure and accept money for the service, but not be responsible for the content that they deliver, because it originally came from somewhere else.