sidestep any unpleasantness when they get a subpoena
I'm curious as to how well (legally) this "we could modify the app to do it, but nah" approach actually works, and for how long.
HN user
sidestep any unpleasantness when they get a subpoena
I'm curious as to how well (legally) this "we could modify the app to do it, but nah" approach actually works, and for how long.
Right... it's one thing to for example, use a third-party MEGA client to upload files so that there's no chance of the company ever being able to see your key (unlike random javascript they might inject into the web version).
But when Apple etc. control both ends, their app could always see your data locally because it is the one that encrypts it to upload to the server in the first place. And these companies can receive secret orders from the US government to add backdoors into the local app and there's nothing you can do or say about it, except go out of business (like Lavabit).
In the US at least, companies can and do receive secret demands from the government to add whatever kind of backdoor they want, and you're not allowed to disclose it in any way, they even order you to preserve any warrant canaries you have implemented.
This is for example why Lavabit chose to go out of business instead of giving up their keys.
Most Americans have been ignoring it and doing nothing.
All the protests to date are still quite far away from the https://en.wikipedia.org/wiki/3.5%25_rule
Then in that case I think the previous statement of "end to end encryption means no CSAM scanning" would be false.
Children cannot legally consent to most things in most places, especially until near the end of their teen years.
As sad as this is, end to end encryption means no CSAM scanning.
I think it depends on your definition of e2ee and where the "end"s are.
If the locally running application can decrypt the data, it could always do whatever it wanted. Is that really how you define e2ee?
IMO "end-to-end encryption" simply isn't possible when the application is run by the same company as the servers the data sits on, is closed source, and can at any time, see the decrypted contents of data it downloads from their servers and do whatever they want with it.
Same issue with Proton, MEGA, and any other e2ee app... it's only useful when the company decides not to mess with the data it could always decrypt locally. Also why people are hesitant to use javascript-based e2ee solutions where the site owner can modify the code at will to do what they want.
There are boatloads of gaps.
the Rust is confirmed safe
keep in mind that rust:
- does not prevent logic errors
- does not prevent stack overflows
- does not prevent out of memory errors
- does not prevent bitflips caused by faulty hardware or cosmic rays
- does not prevent memory leaks
- does not prevent unrecoverable errors (panics)
- does not prevent memory safety related issues in an unsafe context
So if reddit just didn't have a frontpage, and you had to navigate to each subreddit manually, that would be enough somehow?
This has got to be hands down the wildest take I've ever seen on this site.
I can honestly say I have never heard of this hobby being a thing in all my long years.
The title of the article is misleading, there will still be booms:
Several U.S. companies are working on a new generation of luxurious supersonic passenger aircraft with much quieter sonic booms and improved fuel efficiency
For me the incentive is being able to own an identity that nobody can take away from me. And the assumption is that services will support this type of identity, so I don't have to make accounts on other systems that people can take away and now I've lost all access to any data I had.
Now if only they could master a name everyone can pronounce.
Port knocking is mostly a bad idea
Hard disagree... there can be other valid perspectives.
If you don't consider it a security control
I think it can be a security control depending on who/what you are trying to secure it from.
Can network operators along the route of your packets see what you're doing? Sure. But if you are only protecting against mass scanning or individual threat actors, they won't have access to that information.
Same, this whole thread is like the twilight zone for me... I can't tell if I'm losing my mind or all the people with this way of thinking are just being completely unreasonable but I've never seen several people at once agree with such a ridiculous (to me) comment.
Reminds me of the time on libera IRC when someone told me "cloud storage does not exist" because they were hung up on some ultra-purist word definition that nobody else shared.
I don't grasp how anyone uses Chrome as their daily driver willingly
The overwhelmingly vast majority of the world population uses Google Chrome with no adblocker, on Windows, and have no desire to change anything. Even if you actively try to persuade them towards other browsers or operating systems.
Why is that difficult to understand? Most people are not technical and do not have the same concerns or gripes as we do... their current software stack is familiar and does what they need it to, and that's all they care about.
What other software have you stopped using because they added an optional feature you didn't use?
By this logic, Linux does not support Wi-Fi, because all the driver modules are "dynamically loaded at run-time."
I'm surprised you were using a proprietary browser in the first place
Musk wrote, “Only by protesting REPEATEDLY and LOUDLY will there be any change!!”
I'm certainly not defending the man, but that comment to me is definitely not plainly seen as "advocating riots"... I'd call that a very disingenuous stretch of the truth.
If we're going to criticize people, I think we need to do it for the right reasons.
It only hallucinates if you use it wrong
Sorry but this is demonstrably false. For starters, see the "R's in strawberry" meme.
no one is seriously calling for the elimination of automobiles.
I think it is because they see cars as much more necessary than guns. IMO The reality is that both could benefit from more regulations and harsher penalties and enforcement.
vibe-coded, and the github repo does not even contain the sources, just a single 'server.js' that is only for the documentation
I'll be that guy I guess then... they stated on their page that credit cards are 0.8mm while the muxcard is 1mm and yet they still claim it is "literally the size of a credit card"... not to mention that they carved out an NFC card, not a credit card.
Yes it's still impressive either way, I'm not debating that.
I misread it as OBFS the proxy protocol
CF uses more than just WebGL to fingerprint users... LibreWolf isn't helping you as much as you think it is.
Because they put up with it.