HN user

sandblast

55 karma
Posts0
Comments74
View on HN
No posts found.

"Domain-verifications" is an invitation for everyone else that might need it to use the same standard and convention. "Discord-domain-verification" is not, it's what feels like polluting the global namespace with the company name that might cease to exist in a few years.

At the very least, it should be "domain-verification-discord", "-google" and so on. Maybe even "-com.discord", "-com.google"? And the first part clearly standardized and registered, instead of one entity using "domain" and another one "site".

No, in fact I don't. But this post wouldn't be of any help anyway. It feels like it's about nothing, there is no substance, just stating some obvious facts. Without examples that lead to some real recommendations, this whole expertise claimed by the author is of no use.

It looks like the developer was so hooked on the idea of making it minimalistic, he forgot to make it a language-learning app. So it's a blob with a backstory. Design with no substance.

I was just asking to know your thought process, but this discussion probably won't lead to anything anyway — in my view a person's stance on vaccines, gay rights, what have you, doesn't make you any worse developer. If the technology is sound — which I can vibe-check (by a glimpse on how the code is maintained, documented etc.) — I have no reason to peek into one's private views. Your opinion is different, I still don't fully understand it, but we'll just have to agree to disagree.

I am not sure I run a single piece of software where this is done.

And yet you run it. Have you vibe-checked every such software? Did that bring you enough information about individuals creating it? If not, if there are no readily available signs, have you vetted their own, private beliefs otherwise — in order to ensure they don't clash with your own?

What if Linus Torvalds turned out to be secretly a Nazi pedophile for the whole time? Would that make you stop using Linux?

False dychotomy — there are more options than "protecting anonymity" and "revealing identity so that credentials can be vetted". He just writes what he believes under his own name, it doesn't necessarily have anything to do with establishing his authority.

I'll try from another angle:

If I wanted to make a honeypot that undermines users' privacy and anonymity, I would make sure to be as nice to everyone as possible. The "vibe check" is irrelevant, the false positives are far too common.

SimpleX supports measures (managed transparently to the user at the agent level) to mitigate the trust placed in servers. These include rotating the queues in use between users, noise traffic, supporting overlay networks such as Tor, and isolating traffic to different queues to different transport connections (and Tor circuits, if Tor is used).

Also, most often the two parties use different receiving servers, and this aligns us more with the physicals letters analogy from the submitted article, except that each receiving server is more like a central post warehouse in a big city and not a small district branch.

And the appropriate basis of trust in the technology world would be source code audits, not scraping some individual's Twitter posts.

If the users' communications are encrypted — which they are — there is no way for the creator to "reflect his world view", whatever it might be, in the form of undermining the security or privacy for some part of the user base.

Focusing on security and privacy is great, but I expected some downsides. I'm glad you decided to emphasize the dedication of the creator of SimpleX instead.

EncroChat was not open-source, so it was much easier to be infiltrated.

The "police trying to infiltrate it" means nothing unless they can do so successfully. We know that it's vastly easier to undermine users' privacy on WhatsApp than on SimpleX.

So where exactly is that "much more security" you're touting?

Oh, it's very simple: those views mean nothing. Unless you can point to the part of the source code where they are expressed and explain us how this part undermines the project's technological goals.

If you're so eager on encouraging cancel-culture, would you be so kind to elaborate on why exactly you want to cancel this programmer instead of just vaguely pointing in the direction of a closed platform?

I don't know what you're mentioning, but let's not forget that whatever view he might have, it changes nothing in the technology he creates. It's open source, it's auditable, and the code does not have worldviews of its own.

Your comment promotes cancel-culture, and as filthy as it is in general, it's even more so in the technology world. Don't do it. Please.