58 ms·
A Statement on Recent Events Between Signal and the Anti-Censorship Community
- 1una 6y agorelevant: https://news.ycombinator.com/item?id=26031668 https://news.ycombinator.com/item?id=26031668
- Daho0n 6y agoAnd a very different tone in the discussion.
- sneak 6y agoAs I wrote in a comment[1] in their other attention-seeking post[2], they keep talking about "risks" and "vulnerability". There's no exploit or vulnerability here (despite their use of the "PoC" and "responsible disclosure" terms that apply to such things). The fact that you can detect a Signal proxy as a Signal proxy isn't a vulnerability; if it gets censored you're no worse off than you were if that proxy didn't exist: the main Signal servers are censored in Iran already. Indeed, this is the Signal circumvention proxy working precisely as designed. As I understand it, these people got banned from the Signal forum for spreading this FUD there, too. Predictably, they started accusing Signal of some coverup. They managed to get an interview to further publicize their FUD, but eventually reason prevailed and that was pulled by the author, too. Sometimes I really wonder the motives and identities behind the people causing such massive and unnecessary drama and fear in the community surrounding the only mainstream, reliable, end-to-end encrypted messenger out there. iMessage and WhatsApp both got their end-to-end crypto backdoored en masse via plaintext backup/escrow systems, but Signal remains generally safe and secure (provided general endpoint security practices are followed). These sorts of FUD attacks make me wonder about why they're happening, and the motives and incentives of the people causing them. One of the people harassing Moxie about it on Twitter has <50 followers and an account that's only ~2 years old, with only a handful of posts in that time. My money's on sockpupppets. 1: https://github.com/net4people/bbs/issues/60#issuecomment-775179822 https://github.com/net4people/bbs/issues/60#issuecomment-775... 2: https://github.com/net4people/bbs/issues/60 https://github.com/net4people/bbs/issues/60
- rfoo 6y ago> Sometimes I really wonder the motives and identities behind the people causing such massive and unnecessary drama In this case, it's pretty boring. They are just a group of "your average power users" or "wannabe programmers" in their highschool or junior years who happened to be born in China so had some exposure to anti-censorship. Being in their overconfident period of life, they pass by various myth they don't really understand as truth. The community is quite toxic but usually they don't cause trouble outside of their own circle, but when it happens, I don't know how to deal with them either. They also misuses words like "vulnerability" or "responsible disclosure" because some of them have read a lot of news about security research, thought it is extremely cool but have no idea what it actually means.
- sneak 6y agoI've seen a growing number of anti-Signal posts and activism lately, mostly surrounding the (well-documented) design tradeoffs that Signal makes for usability and privacy (such as opting to use phone numbers for usernames, to avoid having to store contact lists/social graphs on Signal servers), or their famous decision not to federate/interoperate. Perhaps it's just criticism growing in lockstep with Signal's overall growth and notoriety, and there aren't any concerted efforts to discredit Signal and sow doubt about using it because it's harder for the intelligence agencies to surveil. I'd like to live in that world. I'm not sure that I do.
- fmajid 6y agoDid you know Signal, like Tor, was financed by an offshoot of the CIA? https://www.opentech.fund/results/supported-projects/open-whisper-systems/ https://www.opentech.fund/results/supported-projects/open-wh... https://pando.com/2015/03/01/internet-privacy-funded-by-spooks-a-brief-history-of-the-bbg/ https://pando.com/2015/03/01/internet-privacy-funded-by-spoo... Now if I were an Iranian dissident, I would be reasonably confident Signal is designed to withstand the Iranian regime’s interception efforts (but not necessarily traffic analysis). If I were someone on the US government’s shitlist like Edward Snowden or Julian Assange, my calculus would be entirely different. (Yes, I know Snowden has endorsed Signal)
- lionkor 6y agoOfftopic, but what's with all the PGP signatures? One message is literally just "this message is signed with my key", followed by a key and a previous key. Is this a meta joke, automated signing (like signed emails), or am I tripping?!
- FDSGSG 6y agoPGP means it's serious!
- sneak 6y agoNo, they're cosplaying security/encryption experts, in an effort to have their attempt at seeking attention seem less like the farce that it is.
- lionkor 6y agoMy first reaction was that surely this must be satire, because the last thing I ask myself reading that post is "but how do I know these 2FA GitHub accounts are not hacked?!" ...
- danparsonson 6y agoThis is a community with a strong focus on security - they're proving their identity when they post to add their agreement.
- lionkor 6y agoI don't mean to argue, but I believe github's account system with 2FA should be more than secure enough. If it's not, then why even start a bbs there? Why not just use a signed & encrypted email chain? Seems trivial, especially for what wants to appear to be security professionals.
- smeej 6y agoI work in account security, not for GH, but another platform. Account security with 2FA is a long way from foolproof. Accounts get compromised all the time, especially by phishing or malware. That's why my company's internal emails are all PGP encrypted and signed, even with managed accounts and YubiKey authentication. When it really, really matters, you need more than 2FA.
- nexthash 6y agoIt seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rather than attempting to uphold the greater values of the anti-censorship community. I feel that it doesn't benefit anyone that they behaved this way, choosing to attack the Signal team and the reporter of the article below, rather than resolving the issue productively while allowing the community to continue focusing on their mission. [1] https://www.bleepingcomputer.com/news/security/removal-notice-for-signal-article/ https://www.bleepingcomputer.com/news/security/removal-notic...
- La1n 6y agoWhat could have been the more productive way? If their issues are closed (and Signal does not seem interested in discussing this) and they feel like this is actively putting peoples lives in danger I feel they should call this out.
- FDSGSG 6y ago>If their issues are closed (and Signal does not seem interested in discussing this) Signal merely asked that they post on community.signalusers.org instead of Github. >they feel like this is actively putting peoples lives in danger That's obviously bullshit though, this can't possibly put peoples lives in more danger than using signal without a proxy a week ago would've.
- La1n 6y ago> this can't possibly put peoples lives in more danger than using signal without a proxy a week ago would've. I see one reason it could, it filters out people who do "need" to use it. It could even be people who did not use it before, but think it's undetectable now. Signal implies it can't be detected, at least to non-technical readers. >Unlike a standard HTTP proxy, connections to the Signal TLS Proxy look just like regular encrypted web traffic. There’s no CONNECT method in a plaintext request to reveal to censors that a proxy is being used. https://signal.org/blog/help-iran-reconnect/ https://signal.org/blog/help-iran-reconnect/
- cheph 6y agoSignal's architecture makes it incredibly prone to censorship on multiple levels. Rather focus your energy on something which is not as architecturally prone to censorship such as Matrix or XMPP.
- guytv 6y agoCensorship and privacy are important issues. So is civilised online debate, and communities learning to work together in a nice way. I admire the people that put in time and energy to create a safer future for us all. Hope that this is not going to be taken the wrong way, but whenever I read such threads (and again - I respect all the people involved, their efforts and the importance of this issues) - I can't help but being reminded with this: https://www.youtube.com/watch?v=a0BpfwazhUA https://www.youtube.com/watch?v=a0BpfwazhUA
- henearkr 6y agoYes, indeed, I'm baffled that the people from Signal who dismiss these critics think that the only people possibly "endangered" are the proxy owners. It does not cross their mind that the users are immediately endangered too. They don't understand that it is very easy to identify the proxy users once the Signal proxies themselves are detected? I'm here replying on the top level to this comment, because I think this is very important: https://news.ycombinator.com/item?id=26076113 https://news.ycombinator.com/item?id=26076113 Edit: Actually it is because it is a different problem they are trying to solve. What Signal is solving by these additional proxies is to avoid being blocked. So this is orthogonal to avoiding the detection of users. The real way to avoid detection of users is going through something like Tor. Edit 2: The real problem is that, in countries where Signal is blocked, it is ALSO forbidden and illegal. If it was just blocked and not forbidden, nothing wrong in working around the blocking. But actually permitting users to work around the blocking when it is illegal is not helping them, unless there is also a way to hide them. Else it helps them commit (overtly) the crime for which they risk many troubles.
- La1n 6y agoExactly, according to NGO's people get lashed and jailed for online activities. After Signal has been blocked being detected could actually endanger peoples life. https://freedomhouse.org/country/iran/freedom-net/2019 https://freedomhouse.org/country/iran/freedom-net/2019 https://freedomhouse.org/country/iran/freedom-net/2020 https://freedomhouse.org/country/iran/freedom-net/2020
- ed25519FUUU 6y agoWas the better solution here that signal does nothing?
- henearkr 6y agoThey could have prioritized the dev (or scheduled the release/deployment): 1/ integrate some Tor-like system, and 2/ the amateur proxies feature Actually they can still do it, by deactivating and putting the amateur proxies feature in standby temporarily while the Tor-like system is being implemented. The very least they can do is not denying that, now they have already deployed 2/, developing 1/ is becoming an emergency.
- edent 6y agoMoxie - and the Signal team - seems to have a real issue taking feedback from outside experts. See the way he has been completely dismissive of the IME vulnerability highlighted by Naomi Wu and others. I remember back when it was TextSecure - I tried to raise some usability and security issues. First I was ignored, then dismissed, then - a few years later - they implemented some of the changes. I still use Signal. But the way the project is run is, dare I say, arrogant and dismissive.
- nexthash 6y agoMaybe, but I think that the way these researchers reacted when their criticism wasn't heard doesn't benefit anybody. By ratcheting up the tension and participating in an internet catfight against the Signal team, a net loss occurs for the anti-censorship community. If the Signal team does indeed have a real problem with taking feedback and criticism, a better approach might've been to gather support and enter into long-term negotiation over Signal's future relationship with the community. This would make its development a lot smoother and prevent anger and bruised egos from building in the future.
- pm90 6y agoThe owners and maintainers of the product get to decide on how to handle issues like this one. But I’m not convinced that an “internet catfight” is a good enough reason for shutting down the conversation completely as it was done. I am aware that it’s totally unfair that signal owners should have to deal with this kind of behavior and not take strong measure like they did... I don’t really know what a good resolution would have been. But it’s also a fact that if a system is broken in some way then that hard truth remains true even if it’s wrapped in layers of shit. The ultimate losers will be the users.
- jrochkind1 6y ago> You were blocked because you know that we don't use GH for discussion, but came here anyway and started opening fake PRs so that you could post and harass other people on GH. > …If you want to discuss anything about circumvention or any other aspects of Signal in a way that is respectful to the rest of the community, please join in on the forums. https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuecomment-774982590 https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... That does not to me seem like "shutting down the conversation completely". (As if there is even a way to do that on the internet if you were to try!)
- ComodoHacker 6y agoWhat interests me more, is Signal's principal stance about censorship. If non-tech people ever come to Signal in numbers, the moderation problem will inevitably arise. Would they censor things that we currently have public consensus about? Like CP, terrorism etc.
- henearkr 6y agoI doubt that this will ever be an issue, because Signal is a messaging application, on which censoring/moderation is thus irrelevant. It's not a social network (contrary to e.g. Telegram which has tons of SNS features). Let's hope it will remain just a messaging/videocall app.
- ComodoHacker 6y agoThey would have no other choice but add group and social features. That's what non-tech people come for.
- henearkr 6y agoGroup feature is already present and is a different thing than Telegram's channels or Facebook's groups. On Signal it is a group of your contacts, so it remains private conversation. There is nothing publicly said, and it is not open for strangers to participate. I don't see any compelling reason for Signal to evolve towards more SNSish groups, to the contrary, by remaining in the current state they avoid the costly conundrum of moderation. > That's what non-tech people come for. I disagree, people come to Signal for what it is. Arguably even more people would come if there was SNS features, but on the business/feasibility aspect (Signal is still an open-source based modest-size project), it would not be worth the cost and endless legal trouble of moderation in all the different countries with all the different laws. Most importantly, introducing SNS would entail moderation which would fail the very purpose of Signal's existence (since the contents of the messages is ciphered and private). In the end, actually less people would maybe come to Signal if it launched SNS features.
- jauer 6y ago
- Gatsky 6y agoSignal seems to get a lot of unfair criticism. I think this is at least partly because they made something a lot of people actually do use. This would otherwise be quite a rarity in cryptography. This ‘statement’ is quite weird. Is it normal to declare oneself an oppressed minority over a github issue? I feel like we should be a bit more charitable to people who make things. Otherwise nobody will make anything anymore...
- alexpetralia 6y agoI agree. If you don't like it, create a fork? It is open source.
- Daho0n 6y agoA fork won't tell people that doesn't use it that the original project they forked is dangerous to use. The proxy shouldn't be there in the first place unless it actually worked. I'm not saying i agree (or disagree) with the current issue's writers but this isn't the first time Signal have put their head in the sand when a problem was pointed out to them. It has become a well-known pattern of Moxie's.
- j-james 6y agoSignal discourages third-party clients. https://community.signalusers.org/t/how-to-get-signal-apks-outside-of-the-google-play-store/808/20 https://community.signalusers.org/t/how-to-get-signal-apks-o...
- toast0 6y agoFork the client and the server then. Yes, I've seen from other comments that the server repo is apparently rarely updated. If that's significant to getting a working client, probably fork the client from earlier; most likely, it you get a significant number of users, you're going to need to get really familiar with the server environment anyway. Running a server environment is probably time consuming ane expensive, but that's kind of why the people running the servers get to set the rules.
- rq1 6y agoElon Musk should tweet about Matrix. Signal team seems completely irresponsible here. Censorship in countries where this app could help puts opponents lives at risk and already led to executions.
- mechnesium 6y ago+1 for Matrix. Signal is a honeypot.
- rq1 6y agoIt looks more and more like it. I even wonder now if they don’t have ulterior motives.
- KingOfCoders 6y ago"Who we are [...] V2Fly maintains V2Ray, a proxy and routing tool that helps people behind China's GFW and Iran's Internet firewall stay connected to the internet."
- superkuh 6y agoYes, that's some of them. I was more impressed that some of the shadowsocks team signed the statement. That's great software I use every day. And it's software other people use in life threatening circumstances.
- ryanlol 6y ago> some of the shadowsocks team signed the statement And hilariously enough also demonstrated that they don’t know how to use PGP.
- ostrophonics 6y agowhy is instant messaging so important? why can't people use eg an encrypted tor bridge to send and receive encrypted emails? or is a mobile phone cheaper/more practical than a laptop in such a situation?
- maqp 6y agoPGP lacks forward secrecy. E.g. the Iranian government can collect every PGP-message you ever send, and if and when they compromise your private key, they can retrospectively a) decrypt your entire message history, even if you've deleted it from your endpoint b) prove that you're the author of every message, because only your private key can be used to craft the digital signatures. Signal solves both problems. For dissidents' communication, PGP is hard to use and incredibly dangerous even when used correctly. It needs to be killed with fire and buried next to nuclear waste in a container made of Beskar or something.
- h_anna_h 6y agoYou do not have to sign anything when you use PGP for encryption.
- upofadown 6y ago>decrypt your entire message history, even if you've deleted it from your endpoint But how many people actually delete their old messages? If they don't then forward secrecy doesn't help. They get your messages when they get you key material. Encrypted instant messaging is inherently less secure than something that can be performed offline like encrypted email because the key information is exposed all the time. So it is much less likely that you will have your key information exposed in the first place with encrypted email. An instant messenger on a phone can normally be defeated simply by grabbing your unlocked phone from your hand and scrolling though your old messages. >prove that you're the author of every message, because only your private key can be used to craft the digital signatures. A private key that in the case of, say, PGP does not have to be associated with any particular identity at all. Also, PGP offers actual deniability by simply not signing the message in the first place while, say, Signal only offers a particularly weak version of forgeability[1] which is problematic in general. [1] https://articles.59.ca/doku.php?id=pgpfan:repudiability#forgeability_light https://articles.59.ca/doku.php?id=pgpfan:repudiability#forg... (see Forgeablity Light)
- motohagiography 6y agoEven if I agree with the principles of the anti-censorship people, to be an activist to apply pressure on Signal for features instead of forking and building solutions is suspicious to me. Signal does a great job of frustrating mass interception, which I think was its original point. Inventing new criteria and re-framing their product as inadequate for this scope change as an activism play seems insincere. We can expect this kind of pressure to be applied to all BDFL-run software projects, as I think there is an emerging organized play to insert new governance over foundational internet software.
- olah_1 6y ago> instead of forking and building solutions What would you fork? The signal server code that hasn’t been updated in almost a year[1]? If that is truly the same code that we use with signal today, would your fork work with this same network? Or would it be it’s own 1-server network all alone? [1]: https://github.com/signalapp/Signal-Server https://github.com/signalapp/Signal-Server
- jayp1418 6y agoI think we should ask this guy how he build it ? https://www.reddit.com/r/signal/comments/l5dug8/signal_server_questions_about_scalability_cds_and/ https://www.reddit.com/r/signal/comments/l5dug8/signal_serve...
- motohagiography 6y agoEither fork the code, or fork a new effort that implements the things you want, and then share it with people who also want it. That these people think it is more viable to co-opt an existing product using organizing pressure for their ends than to build one someone actually wants and share it is indicative of their strategy and attitude. Project leaders need to recognize this tactic coming from afar and then exercise their prerogative to reject meta- and political ploys. Sure, talk to users, get features, but pressure? Treat it like a weed.
- olah_1 6y ago
- hiq 6y agoThe answer from Moxie to these people: https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuecomment-774982590 https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... I think that says it all. I'm also a bit concerned that "security researchers" don't seem to understand the threat model. Signal has never claimed to be able to hide that it was being used. The TLS proxy is only meant to help circumvent censorship, not obfuscate its protocol. And indeed, as a temporary solution, it's not ideal even to circumvent censorship. But they're apparently working on something better, and all this distraction is not helping.
- deleted 6y ago[deleted]
- jrochkind1 6y ago> Signal has never claimed to be able to hide that it was being used. The TLS proxy is only meant to help circumvent censorship, not obfuscate its protocol. I don't understand. How would you circumvent censorship of the protocol without obfuscating the protocol? It seems to me that signal has never claimed to be able to hide that it was being used... until now? But thanks for posting the thing from Moxie, it does sound quite reasonable. What would be useful to me and presumably other HN readers is a clear summary of the tech involved, readable by an audience who is technical but not security/circumention experts. Like, the people complaining could be spending time on that, to educate users and developers, instead of doing... whatever they are doing. That seems to have turned into a much less interesting argument about etiquette or something.
- smokey_circles 6y agoReading the config in the TLS repo, it seems to me that the censorship is at the domain level. So I guess they're trying to pop up as many endpoints as possible to circumvent that. I don't know the details about the network block though, so I might be mistaken. But the nginx config in that repo is purely a TLS proxy. Nothing magical happening there at all, just an entrance node to the main signal network
- lovelearning 6y ago
- say_it_as_it_is 6y agoSignal seems like a magnet for toxic avengers. It's really unfortunate because every negative interaction has a cost. It doesn't matter how valid what "net4people" is claiming because how they're saying it is unacceptable. The Signal team has its reasons for not adopting their recommendations. That's enough.
- smokey_circles 6y agoSorry, where's the vulnerability in _signal_ here? The TLS proxy is not sufficient. Marlinspike addressed this in their incredibly childish PR [0]: >As we said in the blog post, it is nothing more than a simple TLS proxy as an interim solution to help people while we're working on something more scalable and more robust I'm not so sure they made it clear they were working on another solution in that blog post [1], but it's a known problem that proxies can be fingered. I don't see the value add here and I can't read this as anything other than "boo hoo, we weren't listened to" (which is not surprising, given their behavior) [0]: https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuecomment-774982590 https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... [1]: https://signal.org/blog/help-iran-reconnect/ https://signal.org/blog/help-iran-reconnect/
- Jkvngt 6y agoWhy is Signal positioning itself as a solution when Rosenfeld admits it’s not ready?
- kelnos 6y agoThey're not. They released something as a stopgap measure that will help some, but not all, people in Iran get back on the app, because their better, longer-term solution is not ready, and they believed that people there needed at least something in the short term.
- tmpz22 6y agoYes I’m not a disinformation spreader or online troll - I’m just part of the anti-censorship community!
- omginternets 6y agoDoes HN recommend a particular "getting started with Matrix" guide?
- oedmarap 6y agoI think both Moxie and Signal have to be more open to criticism instead of hiding behind either a CoC or a reactive/elitist mindset. They can't eat their cake and have it. If they advise vulnerable groups to use their technology, then they're morally obligated to explore and mitigate any and all issues brought to the table. Signal has lots of funding, so getting "insulted" is not an option — in my view that only applies to FOSS maintainers who work for free.
- cmiles74 6y agoSignal should place someone who is somewhat technical between the customers of Signal and the development team. Many companies do this and it ensures that the person handling communication with the public has the time and energy to do so. I don't think this would materially change any outcomes but a couple messages to passionate customers along the lines of "everything you say is super interesting and I am listening, we as a company value your feedback" could go a long way. And, of course, someone who is a bit more diplomatic may have better luck getting some of these issues across to the development team in an impartial manner. Why is the lead Signal developer responding to the public on GitHub and Twitter? It is really helping the project? At this point I'd argue that it's actually hurting the project as we see more of these pointless and public flame wars. Others have pointed out the similarity between this situation and the IME keyboard kerfuffle a couple weeks back.
- baryphonic 6y ago> Our community have been silent for too long. We are the underdogs, doing the real work, and yet unappreciated by many people. Our opinions are underrepresented. That's what makes me believe that we must speak out this time, that we should release a joint statement, to condemn Signal's dismissive and irresponsible attitude to the anti-censorship community, and to call for our unity as a community and their immediate action on the matter. What an entitled, self-serving, narcissistic framing. Even if their technical claims are 100% correct, they have almost no credibility issuing propaganda like this. Yikes.
- dmix 6y agoThat seems to be the new thing today. Everyone trying to frame themselves as an oppressed victim of some higher power. If they think wasted hours programming solutions not getting adopted by OSS makes them some special oppressed group then they must be new to this whole thing. That’s such such a common scenario in OSS and hacker culture in general it’s comical. There used to be a special pride in doing the thankless work, especially in infosec. Or maybe I’m just getting old and the new social media/political culture status quo has brewed up some entitled people where victimhood is the common currency.
- GekkePrutser 6y agoYeah moxie is the #1 reason I don't promote signal to my friends as an alternative to WhatsApp. His attitude to third party clients I find very bad too. They could have added a lot of usability too the signal ecosystem If I move to something else it had to be fully open, not just the source of the app but the network too. Movie is just creating another walled garden. A lot less microphones hanging in the trees than WhatsApp but still a walled garden.
- h_anna_h 6y agoReminds me of the way that signal handled RealSexyCyborg's report of how 3rd party keyboards often leak data.
- proactivesvcs 6y agoBy blocking people that abuse them and by having rational debate drowned out by drum beats? I agree.
- h_anna_h 6y agoNo, do not put words in my mouth please.
- jancsika 6y agoDo I have it correct that the anti-censorship team refused to take the trivial step just to copy/paste their original issue on a forum as suggested by the project?
- voiper1 6y agoIf you see their timeline and screenshots here [0], it says they weren't allowed to post in the forum. [0] https://github.com/net4people/bbs/issues/60 https://github.com/net4people/bbs/issues/60
- jancsika 6y agoAll I see there is the automatic hold which they took a screenshot of, apparently one minute after it was issued! What happened in minute 2 to the present? Did Signal ever approve them to post on the forum? They don't say.
- sudosysgen 6y agoI'm not 100% sure I'm right, but I think that at some point they were denied access to the forum because of spam protections or moderation.
- deleted 6y ago[deleted]
- shame_of_cndev 6y agoA group of security researchers who: * Publish the exploit before vendor know it * Publish the exploit before vendor delivered the patch * Send their own opinion to every media possible (including ycombinator) without mentioning the full event, and using new account to looks more neutral * Disrespect other people * And also have their own "secure" software (v2fly, v2ray, ...) Okay, looks like we need to have a new definition of "security researcher". I think Signal did what they should do when communicate with those "trick or treat" guys: treat me with fame, or I'll trick you with a PoC. Is there a better word to shorten this review...? Oh there is: robber.
- h_anna_h 6y ago> * Publish the exploit before vendor know it > * Publish the exploit before vendor delivered the patch It's called full disclosure and it is the only ethical way to handle it.
- shame_of_cndev 6y ago"Full disclosure is the only ethical way to handle it". haha
- jswizzy 6y agoWilliam Barr would have them all in jail.
- deleted 6y ago[deleted]
- _carbyau_ 6y agoI would have thought that most any "large" complaint regarding "Your Open Source software doesn't do what I want!" could be resolved with "Well, you do it then." Doubly so if the complainants claim to be experts of some kind.