HN user

ethanplant

107 karma
Posts21
Comments20
View on HN
corrode.dev 5d ago

When Rust Gets Ugly

ethanplant
3pts0
www.alexhyett.com 9d ago

Setting up Webmentions on my Static Site

ethanplant
2pts0
github.com 13d ago

Show HN: Elsewhere – a local POSSE CLI for static-site writers

ethanplant
1pts0
www.cbc.ca 15d ago

B.C. 'preparing legal action' against OpenAI

ethanplant
3pts0
ethanplant.ca 22d ago

Bill C-34 Answers Child Safety with Identity Infrastructure

ethanplant
12pts4
avelino.run 22d ago

The op log was peer-to-peer the whole time

ethanplant
1pts0
douxx.blog 1mo ago

My Nintendo DS Broadcasts Radio (Kinda)

ethanplant
3pts0
ethanplant.ca 1mo ago

Bridger Is Building an Osint Dossier in a Cute Font

ethanplant
2pts0
joshuawold.com 1mo ago

Make Something Wonderful

ethanplant
1pts0
ethanplant.ca 1mo ago

Canada Keeps Sabotaging Its Own Digital Sovereignty

ethanplant
3pts0
idiallo.com 1mo ago

The web is changing, and we are not going back

ethanplant
2pts1
david.alvarezrosa.com 1mo ago

Self-Hosting on the Dark Web

ethanplant
3pts0
ethanplant.ca 1mo ago

Bill C-22 Is a Mess of the Government's Own Making

ethanplant
17pts4
www.theglobeandmail.com 1mo ago

Google warns lawful-access bill could create major cybersecurity risks

ethanplant
5pts2
ethanplant.ca 2mo ago

We Rebuilt the Mainframe

ethanplant
3pts0
www.ctvnews.ca 2mo ago

Major VPN provider says it could leave Canada over lawful access bill

ethanplant
19pts5
nvd.nist.gov 2mo ago

CVE-2026-46333 (SSH-keysign-pwn)

ethanplant
3pts0
aquisthoughts.substack.com 2mo ago

Canada Wants Digital Sovereignty. Bill C-22 Pulls the Other Way

ethanplant
8pts2
angelabenton.substack.com 2mo ago

We Didn't Ask for This Internet

ethanplant
3pts0
aquisthoughts.substack.com 2mo ago

Access Is Not Ownership

ethanplant
2pts0
aquisthoughts.substack.com 2mo ago

Your Computer Doesn't Belong to You Anymore

ethanplant
14pts2
Hi 5 days ago

Hey! This is a really neat project, especially considering your age.

That being said, I’m confused by why what is essentially a beginner learning project is being wrapped in language that makes it sound like a Series B startup.

“This article reached a conclusion from the author’s perspective” is not a criticism of writing. It is a description of writing.

Good writing is almost never neutral. It can be fair, careful, honest, and proportionate. But if it has nothing to say, it isn’t good writing.

I think the idea that it’s a trust issue is broadly correct. “Free vibe-coded anonymous Linux server with root access” immediately causes every infrastructure and security neuron in my body to fire at once.

Broadly I agree that you can’t expect organizations to change their behaviour without changing the incentives. That’s essentially my argument in favour of the platform accountability portions of the bill.

Where I disagree is the framing that it’s a binary between “age verification for all” or “legal liability for parents”. There is a third option: change the incentives for the organizations designing and operating the systems children are using.

Regulate recommender systems, addictive defaults, reporting and appeal mechanisms, non-consensual intimate imagery response, synthetic sexual abuse material, dark patterns, safety plans, transparency, audits, and penalties for platforms that fail to respond properly. Those are all aimed at the organizations creating or amplifying the harm. This is, admittedly, the most difficult approach, but it’s also the approach that actually addresses the root cause.

My concern is that an under-16 account ban turns the enforcement problem into an age-assurance problem for all users. The platform has to determine who is under 16 somehow, which means assessing everyone’s age. That creates privacy and access-control infrastructure while the most vulnerable teenagers are also the ones most likely to route around it.

So yes, change incentives. I just think the incentives should be aimed directly at platform conduct and design, not at making everyone prove they are old enough to participate online.

I’d be cautious about saying OpenBSD itself is directly affected. It really depends on if OpenBSD counts as an “electronic service provider”.

You do raise a pretty good point though, Canada has long benefited from being perceived as a relatively trustworthy jurisdiction. So even if OpenBSD themselves are out of scope, there is a negative reputational hit that will impact Canadian tech.

`human.json` is a neat idea and I’ve been watching it closely. I’m even debating dropping one on my own site.

That being said, the fact that the obvious attack vector goes completely unaddressed gives me pause.

I agree with the principle that the internet has, for lack of a better word, gone to shit.

This isn’t the answer though. It’s not technically feasible and doesn’t actually address the problem.

Your falling into the classic software brain trap of thinking the solution to a social problem is a technical one, when that isn’t necessarily the case.

I don’t feel the need to. If someone says “this is AI” all I hear is, “I don’t want to actually engage with the argument”.

I also have a very specific voice. Blunt. Slightly irritated. Highly opinionated. AI is pretty bad at trying to emulate that well.

Wholeheartedly agree. I feel like we genuinely lost something when seemingly all writing turned from people genuinely sharing their thoughts to “what’s going to get the most engagement on substack”.

I’m genuinely confused as to why the speakers are baffled by the boos.

Everyone, and especially new grads constantly hear that AI is going to replace every job. And absolutely no one seems to be interested in answering the question of “okay, then what?”

Of course people are going to react negatively when they hear, “the machines are going to take your jobs from you. No, we don’t care how you’ll be able to pay your rent or put food on the table”.

I'm not quite sure what being a leftie has to do with the point you're making. This isn't really a political point and more the valid (though not particularly novel) view that "most websites are overcomplicated".

Writing the simplest of websites requires a ton of tooling now.

Meanwhile my website personal website is nothing but markdown files that get rendered into static HTML with a little bit of CSS. You really don't need a massive JS framework for a simple website.

I think the most important issue here, as it often is whenever this idea gets floated, is the technical community and the government are talking past each other.

Perhaps it is entirely true that the government does not intend to create backdoors. But as engineers we increasingly build systems specifically so that even the provider can’t access the data. So when governments describe requirements around lawful access, compelled assistance, or preserving access capabilities, many engineers look at those requirements and conclude: “that is effectively a backdoor.”

The intent may be one thing, but the actual reality is another, and that distinction matters.

Yeah, the privacy aspect is definitely an important aspect of the conversation but I find it’s very easy to brush off.

I think explicitly pointing out the contradiction between the government saying that we need to boost our digital sovereignty while at the same time working to weaken the very foundation digital sovereignty is built in is an aspect we don’t really talk about and is much harder to just brush off under the guise of “we need to stop criminals”.