HN user

panhandlr

32 karma
Posts0
Comments24
View on HN
No posts found.

How many production servers have you been responsible for in your lifetime?

"There is no difference to running an executable. "

... There are these following differences.

1. That url, assuming no malicious 3rd-party/nation-state is spoofing the response, could return any different version of the installer resource at any given time.

2. That url might not always be available, for any number of reasons, and how is someone who wants to "discover" this software when they are looking through their available package list?

3. Who knows what that url is "suppose to do" ... there is no signing process, peer review process, nothing, you get whatever the apache server on the other side of that HTTP request wants to give you, and your gonna send that right into your root shell...

4. Unlike a package, sitting in my personal safe, self host, audited, self-verified debian package repository mirror ... this URL might not work tomorrow, it might not work at 3:35am when my primary server took a shit and i need to rebuild the whole stack... who knows what this URL will do in between subsequent runs... it could return 2 different things when I am trying to build a cluster of this product.

"Nobody in their sane mine should curl a script into bash to install a product"

This, so much this.

I was actually extremely excited over a similar product "flynn"... but they have also lost their mind when it comes to installation: https://flynn.io/docs/installation

sudo bash < <(curl -fsSL https://dl.flynn.io/install-flynn)

Seriously?

How is that any easier than just providing a package for any given distro?

I mean, for fucks sake, just give me the URL to a tarball with a fucking Makefile in it. I can handle the rest, thank you very much.

The security concerns alone should force any sane system engineer to never pipe curl to sudo'ed bash process.

"Do they not plan on there being an official investigation?"

How do you officially investigate someone stealing your monopoly money?

Where is the FDIC insurance? Exactly what are they suppose to tell the police? The FBI? ... oh thats right, nothing, because they are not a bank, and the only thing "stolen" was some ones and zeroes off a hard-drive.

Seriously though... where is the police report on this? Or any of the other hacked bitcoin exchanges for that matter?

Um... if you don't want anyone to know, why would you EVER send your data to a third party?

All of these "disappearing ink" apps are patently ridiculous, they all have demonstrated security flaws, and they completely ignore the analog gap problem.

What are people thinking when they decide to use this crap?

... "Oh cool, look at me, I am a spy... let me send you something sekret, tee-hee I am sure this other dude running this server is totally cool too so you can send me your sekrets back... tee-hee-hee... nobody will ever know"

So many god damned stupid fucking kids walking all over my fucking lawn these days!

This is no joke brother... We will not rest until this issue is heard in the highest of courts. First they came for our <blink> tags and we laughed... then they came for our options to disable tabbed browser, and they said nothing... then they came for our option to not be tracked by online advertising agencies (javascript) and everyone was too busy sharing kitten photos on facebook to say a damned thing.

The primary problem is that the about:config flag for hiding tabs is ineffective so there is more to the solution than just looking deeper into the config menus.

I agree that these options are for power users, but my fear is that soon after they relegate the ability to disable javascript to the bowels of the application, they will soon remove it entirely. And that this decision is in fact not driven just by the fact that it is seldom used, but driven more-so by the corporate interests they hold with advertising and other online entities that serve not for the browser users, but their own corporate interests. This fundamentally collides with the intent of the Mozilla foundations purpose and this behavior must stop.

The ability to disable javascript has been on the main screen of the options panel because it serves a very important purpose.

Also the ability to not show tabs when browsing a single web page because for that use case, it is more optimal to not show a tab and waste the screen real estate on dead space.

They have fundamentally altered the Firefox browser in a fundamental way that is not configurable and have not provided reasonable alternative.

I refuse to accept any so called "Add-On". These features are not to be pushed off into to the extremities of the community and be forgot about. I firmly believe that any such browser serving only the interests of the user would see these features as being non-optional options and should exist in perpetuity for the life of that software.

Let this day go down in history as the day we declared our independence from the tyrannical Mozilla organization and their corporate-interest driven and oppressive removal of our freedoms and ability to customize our browser. We shall not be stricken down by their restrictive and non-representational releases of firefox... instead we choose to be empowered by the option to disable things such as javascript, and tabbed browsing because we understand these options to be self-evident truths for all browser users.

I am tired of having my freedoms stripped from my browser without any representation into the process. As a user of the browser I was not adequately informed of the upcoming changes nor was I given an opportunity to choose not to upgrade.

THIS MUST END

Contact me for further information, the revolution begins today.