HN user

mo

1,096 karma
Posts63
Comments37
View on HN
anarc.at 10y ago

Anarcat: The Problems of keybase.io

mo
2pts0
www.engadget.com 10y ago

Edward Snowden's OS of choice gets a major update

mo
16pts12
www.benthamsgaze.org 10y ago

Insecure by design: protocols for encrypted phone calls

mo
61pts2
www.indiegogo.com 10y ago

Skrolli – A Printed Computer Culture Magazine

mo
1pts0
www.kickstarter.com 10y ago

PinMagic: The prototyping and code generation tool (not only) for your RasPi

mo
3pts0
blog.digicert.com 10y ago

Ordering a .Onion Certificate from DigiCert – DigiCert Blog

mo
3pts0
www.cubaconf.org 10y ago

First International Free Software Conference in Cuba

mo
1pts0
ebb.org 10y ago

Badley M. Kuhn: Do you like what I do for a living? SFC fundraiser

mo
1pts0
gnupg.org 10y ago

GnuPG Adds TOFU, DANE and Tor Support

mo
7pts0
dirkriehle.com 10y ago

The Open Source Software Developer Career and Its Benefits

mo
1pts0
drops.wooyun.org 10y ago

Japanese blog publishes POC for Stagefright Android vulnerability

mo
1pts2
www.ibtimes.co.uk 10y ago

Tor Project to use US public libraries to boost network speed

mo
2pts0
blog.lenovo.com 11y ago

ThinkPad Time Machine? Retro Thinkpad: Opinions

mo
37pts3
www.kickstarter.com 11y ago

Last day Help make 20-years of cbase hackerspace book happen

mo
1pts0
gnunet.org 11y ago

GNUnet is a framework for secure decentralized peer-to-peer networking

mo
4pts0
www.wired.com 11y ago

The Dark Web as You Know It Is a Myth

mo
5pts0
en.wikipedia.org 11y ago

Crypto AG: Back-doored machines

mo
3pts0
www.kickstarter.com 11y ago

Cbase Hackerspace turns 20 a book about its history

mo
1pts0
media.ccc.de 11y ago

Video: Telephony voice encryption – projects and therories (1999)

mo
1pts0
www.fairphone.com 11y ago

The architecture of the Fairphone 2

mo
3pts0
threatpost.com 11y ago

US Navy Soliciting Zero Days

mo
82pts53
github.com 11y ago

Rainbow Lollipop: an experimental visual history web browser

mo
30pts18
www.craigmurray.org.uk 11y ago

Reasons the MI6 Story Is a Lie

mo
226pts8
dud.inf.tu-dresden.de 11y ago

A terminology for talking about privacy: Anonymity, Unlinkability, etc.

mo
2pts0
www.indiegogo.com 11y ago

Roundcube Next

mo
1pts0
sfconservancy.org 11y ago

Conservancy Seeks Your Questions on GPL Enforcement

mo
1pts0
www.torservers.net 11y ago

Tor Exit Relay Hosting

mo
6pts0
twitter.com 11y ago

Keybase signups are open for the next 24h. Use invite code: shit-yeah-Facebook

mo
2pts0
fundrazr.com 11y ago

Matt DeHart Legal Defense Fund

mo
1pts0
github.com 11y ago

Xlennart: An XBill modification

mo
3pts0

Anecdotally, I used to be in control of more than half of Tors exit capacity (until I had inspired enough other people to take over), with no association to US TLAs, and I personally know many exit and other relay operators. I have no reason to assume they are affiliated with US TLAs or other TLAs. The majority in terms of numbers may be, but not the majority in terms of bandwidth.

Personally, I doubt the US TLAs have a need to operate any relays themselves. They can simply wiretap, and use control flow data for correlation when necessary. Tor can still be useful for all those who do not try to hide from the few agencies who may have this kind of visibility.

The relay community is pretty good in terms of interacting with each other. There are real-world meetings to get to know others in the space, which may make you also more comfortable seeing their personal reasons for providing bandwidth.

Correct. "Stiftung Erneuerbare Freiheit" acts as LIR in charge of the address space, handing out chunks of that space to exit relay operating non-profits for free, but does not operate any Tor infrastructure themselves and has no visibility into the traffic. The cost for us are the RIPE membership fees (approx 2000€/yr).

Source: I'm its director and founder of torservers.net. Usually using a different nick here.

No. I want to keep them around, sure, but of course they can be styled differently.

I don't know what makes everyone so upset at old listings. They are listed chronologically, there is an RSS feed to follow for fresh things. It's not like it's thousands of mixed jobs where you have to hunt for the recent postings? I definitely don't object to someone adding an archive/expiry functionality that does not completely delete old job listings. If you look at the referenced ticket on github, I created it.

Again: We am not "padding" anything. The site exists since 2012, and we keep old job listings around, as an archive and to help find interesting potential employers that may have jobs apart of what is listed. There's an open ticket about "fading them out" a little to make it even more obvious. There's plenty of recent jobs listed, so your point about "only ever seeing jobs that no longer accept applications" is moot. Also, subscribe to the RSS feed (or Twitter/Facebook), and "all you will ever see will be fresh, open positions".

It's like arguing that a news site should delete yesterday's news instead of keeping an archive, because "you're only interested in today".

As for your "sustainability" and "career building", I disagree there too, but that's for a different conversation.

Well, what about me? I _am_ volunteering, and a couple of others CC @fossjobs.net on Twitter whenever they come across a job offer.

Yes, you are right, this site depends on volunteers. So what? Wikipedia does as well. Why would anyone contribute their knowledge to something that does not help them? Well, maybe it will one day.

We don't have to start a debate about why anyone would volunteer anything, but I find your reasoning pretty self-centered. Also, you're arguing as if this was a mere proposal for a job site that lists FOSS jobs. No, it's not. Is is an actual site that lists FOSS jobs, and it works.

And don't forget about FOSS companies/NGOs who are looking for talent. Some of them actually like to post their job listings at our site, and do so with a very self-centered desire: To fill a position, potentially with less noise than using one of the other platforms. Why would FOSS developers want to look at all the depressing proprietary jobs on other platforms? :)

As I've said, there are no criteria, it is a case-by-case decision. The general guideline is on the website, "We only list jobs that directly improve and involve FOSS or Open Hardware projects."

That being said, I welcome suggestions on how to improve the wording, some examples what fits and what does not, etc. -- Thanks!

No. Of course it makes little sense to apply to old jobs, but one of the goals here is to demonstrate that there _are_ actually paid jobs in FOSS. We keep old job listings around on purpose, also because it helps to find interesting organizations which you can then get in touch with.

If you find a job that looks interesting, it's always a good idea to get in touch and find out the details and how much it is up for negotiations. Quite often there's details in the description, and if not, I would expect full time to mean something around 40 hours per week. It helps to look at the cultural background and where the organization is based. Especially benefits (vacation days, sick days, health insurance) vary quite much between different countries.

(Hi! This is Moritz, who currently maintains the fossjobs site)

It's hard to define clear criteria.

We do want to avoid jobs where people just "use" FOSS. The focus is definitely paid positions where you /contribute/ to FOSS in some way. Besides obvious developer positions, that might be administrative or sysop jobs at FOSS projects/orgs or other non-profit environments, more than sysop jobs at random web startups.

Hi!

A lot of the jobs on fossjobs.net are remote work. In fact, you can directly see the job's location on the job listing. It's definitely worthwhile reaching out to the project to ask.

And of course we would list openings in India, as we would list foss jobs in any place. If you hear of any, please let us know! The easiest way to do that is to cc @fossjobs_net on Twitter.

I did this for half a year, and it was a great opportunity to learn a broad spectrum of Tor-related matters. The rest of the Tor people are very approachable if you need help answering, and there's a lot of material on Tor's StackExchange that you can point to. This is one of the best ways to become part of the Tor team. :-)

You best move a copy of your filesystem or all files encrypted to some online storage, and travel with a barebones installation. Most people I know have a second, travel drive or even travel laptop, and only put a subset of files online (eg. on your private hidden service, HiddenServiceAuthorizeClient is very useful for that).

Happy times.

That is not the case. The disclosures show some rules to match requests to Tor directory authorities (which most clients connect to to bootstrap) and the Tor website, amongst others (like some article at linuxjournal). It is unknown whether these are actual rules in deployment or just example rules from some demo slides, who can add or select rules for collection on what networks, how many rulesets there are and, maybe most importantly, how many rules your traffic has to match before it gets "flagged", and whether that results in full collection of the traffic or for a subset of the (meta)data.

Nice, but the writing suggests that it's secure as in end-to-end encryption, what people expect from HTTPS, while in fact you tunnel everything in plain through a central server. You should make this clear on the site.

I am one of the persons behind https://www.torservers.net/ , a collective of non-profit organizations that run Tor exit relays thanks to your donations. :) I am not aware of any "arrests" anywhere, although some exit relay operators have been raided and their equipment seized in the past. I understand this might scare away some people from running exit relays. You can still contribute to the network by running non-exit relays.

Hidden Services use only the internal network and don't rely on exit relays at all. All communication is end-to-end encrypted, so all relays will only ever see encrypted content.

If you have less than a couple of Mbit/s of upload capacity, you might want to run a bridge. Bridges are especially useful for people in heavily censored regions, and only provide an entry point to the Tor network.