- 3 Posts
- 46 Comments
theherk@lemmy.worldto
Privacy@lemmy.ml•The Gemini Protocol in 2026: growing, but still not setting the Internet aflame
1·1 month agosourcehut hosts it free and makes publishing dead simple. You just push a tarball, and Bob’s your mother’s brother.
I’m just establishing the baseline that there is some degree of privacy which is not only expected but simply justified with intuition alone. So, there is a line somewhere. Where one draws that line may differ. Your line is no doubt extreme to many; certainly me. But some privacy is critical to a functioning society. I tend to believe that aside from those that hold public office, there is little reason not to have complete privacy.
Do you believe children should be able to use the restroom and dress in private or not? Simple yes or no?
Tell me your views on if children deserve privacy?
theherk@lemmy.worldto
Open Source@lemmy.ml•How does one get into Open Source, generally?
9·5 months agoLots of good advice here. Best method arises but cannot be sought. When you run into something broken or you don’t like, don’t set it aside hoping somebody else will fix it. Fix it.
Even if the maintainer doesn’t want your change. This is the best way to grow the seeds of software freedom you’ve already planted by caring. This is the fundamental ethos in my view of a good steward of the community. When something isn’t ideal, they make it work for themself and then are willing to share if others find it useful.
theherk@lemmy.worldto
World News@lemmy.ml•France's Mélenchon warns: "If I become president we leave NATO"
151·5 months agoA Frexit of sorts.
theherk@lemmy.worldto
Open Source@lemmy.ml•Cal.com goes closed source “because of security”
71·5 months agoThey don’t seem to realize that higher level languages help us understand the code. Language models will be similarly capable of reading the binaries they ship. So what they doing is hiding code from users, not machines.
To clarify, I don’t mean right now. They haven’t been sufficiently trained on machine code and that lacks some semantic help. But the future they fear will have transformers just as capable with lower level code.
The truly terrifying outcome is that it works after changing nothing. Sometimes bugs are the most fun to squash.
Pretty sure it dates back to the dawn of commerce.
theherk@lemmy.worldto
Privacy@lemmy.ml•Sheesh, the US is sure getting scary. Well, it's a good thing it would be impossible to trace Signal to someone via metadata like a phone number, right?
339·6 months agoMore anti-signal propaganda? Who is claiming it can’t be associated to a user. The messages are private, not anonymous.
theherk@lemmy.worldOPto
Open Source@lemmy.ml•We Overhauled Our Terms of Service and Privacy Policy - Another VC funded bait and switch
5·7 months agoIt also matters if you value organizations changing terms after attracting a community and changing to non-transparent solutions while claiming to be “open”. It matters if your values are different.
But you’re right too. If not logging in, your liability is probably not changing.
theherk@lemmy.worldto
World News@lemmy.ml•[Video] 40 Iranian elementary school girls were killed by NATO-Zionist terror attack this morning. More than 45 injured
4·7 months agoThank you, really. Have to be cautious these days.
theherk@lemmy.worldto
World News@lemmy.ml•[Video] 40 Iranian elementary school girls were killed by NATO-Zionist terror attack this morning. More than 45 injured
53·7 months agoAny source for this video? Could be old.
theherk@lemmy.worldto
Open Source@lemmy.ml•About GitHub and how they want to improve PR management with all that GenAI noise
3·7 months agoThis is a really good article and refreshing to see this being recognized as the double edged sword it is (albeit with one edge much sharper than the other). It will be interesting to see how different organizations deal with this. The temporary interaction limitation will be a bandaid in some cases but the deluge will just keep coming.
I’ve been interested in Mitchell Hashimoto’s new trust tooling. I’m not sure it will become a standard, but is a very interesting attempt, and dead simple.
Yes, subpoena was poorly worded. NSL is more likely. But still it is a time-forward threat, which means there is value while the server is or was accepting sealed sender.
And I wasn’t suggesting timing attack is required to defeat sealed sender. I was, on the contrary, pointing out that was a threat even with sealed sender. Though that is non-trivial, especially with CGNAT.
So in summary. You’re right. Sealed sender is not a great solution. But it is a mitigation for the period where those messages are being accepted. A better solution is probably out there. I hope somebody implements it. In the meantime, for somebody who needs that level of metadata privacy, Signal isn’t the solution; maybe cwtch or briar.
Sure. If a state serves a subpoena to gather logs for metadata analysis, sealed sender will prevent associating senders to receivers, making this task very difficult.
On the other hand, what it doesn’t address is if the host itself is compromised where sealed sender can be disabled allowing such analysis (not posthoc though). This is also probably sensitive to strong actors with sufficient resources via a timing attack.
But still, as long as the server is accepting sealed sender messages the mitigation is useful.






Can somebody steel man this for me? I don’t get it.