4 ms·
Every security engineer I have met so far is to some extent (some of the to quite an extent) paranoid and control-freak. That's good for security engineers, you
by mcepl 10y ago
Every security engineer I have met so far is to some extent (some of the to quite an extent) paranoid and control-freak. That's good for security engineers, you want them to be paranoid and control freaks. Of course, the bad part is that they are paranoid and control-freaks.
So, although I don't question huge amount of work brought to the public for free by Moxie, I cannot notice that he killed all points of federation (even those which were to some extent under his control, http://www.cyanogenmod.org/blog/whisperpush-end-of-life http://www.cyanogenmod.org/blog/whisperpush-end-of-life), that he sabotages non-Google-controlled repositories (https://github.com/WhisperSystems/Signal-Android/issues/127 https://github.com/WhisperSystems/Signal-Android/issues/127) of his so called open software client. I don't care that much because for this and other reasons I won't touch Signal with a ten-feet pole, and federated alternatives (XMPP) work for me just fine, thank you. So, my suspicion is that instead of some theoretical difficulties the issue is that he got how own fiefdom under his control, and now he is not willing to let it go.
All these opponents of federation and open software (I am not talking about just FLOSS here, I mean truly community-drive software), each with their fiefdoms to protect, argue that we are stuck with the open technologies from 1990s (or even earlier), and only their proprietary silo (proprietary meaning with only one implementation and under their control) is able to bring us a shiny new blink. However, they tend to ignore the other part of the story. The biggest problem of storing my life in proprietary silos is not that they are under control, I don’t live a life in delusion of importance, so I don’t expect anybody to mine my communication with my wife about what to do for dinner (and yet, even that communication is encrypted by a pretty good encryption system, which works just fine with a plain XMPP). The biggest problem is that every individual proprietary silos in the moment owner of such silo goes out of business, or for some other reasons looses interest in providing the service. So, the question is not how many technologies from 1990s we use, but how many proprietary technologies from 1990s we don't use. Yes, I have stored on my hard drive all emails since 1997, because old boring mbox files still work as they did. But all those exciting and sometimes tearful conversations I had on Yahoo! IM or ICQ are gone forever. That bigfoot.com and mail.com accounts I had for my life? Yeah.
And to the second lie Moxies lies to himself (I am willing to believe he really means it). It is suddenly easy to move between proprietary silos? Yeah. It is lovely that we have to keep unique identifier (phone number) for all NSAs to trace us in some weird databases somewhere (that livejournal.com account? yes, it is now owned by the Russian Коммерса́нтъ; yes, I know that this newspaper is not that bad). And yes, it is seriously interesting if perhaps phone numbers would serve as the unique personal identifier most Americans were so afraid to introduce. A possibility to have anonymous accounts? Yeah.
However, even this does not seem to make transfer between platforms that easy. If all your friends are on Telegram, then no matter how easy for whole group it would be easy to transfer, you cannot transfer unless whole group does. How many people really and truly love Twitter, and how many of those who hate it with passion are able to move to some better platform? Nobody, because that is where people are.