Hacker Newsnew | past | comments | ask | show | jobs | submit | Hizonner's commentslogin

Sure, Jan.

Having lived many years prior to social media, I'm gonna say that "fundamentally warps people" is pretty damned overwrought language.

You don't know what this group is, but you confidently spew statistics about it?

This was a stupid waste of time the first time it was posted here.

Invading Ukraine was idiotic on its own, and that happened.

It's not irrational to notice that irrational actors do irrational things.


How rational is killing others when someone tell you? You need strong propaganda of fear to makes other to kill each other. Something like those articles.

Yet again: we're making the Russians do it?

Whats the point of using methods that you fight against?

Why would the Iranian government put such a constraint in its own root certificate?

I guess now would be a great time for browsers/OSes to ship a "trust this CA, but only for this TLD/list of domains" feature.

One possible alternative might be to add the ability for user configuration to substitute one certificate for another one (both will need the same public key and subject name, but the substitute will not be self-signed (since you do not have the private key)), and to use the data in the substitute certificate instead of the original. If the name constraints extension is implemented, then it would make this and other things possible. Since the substitute certificate will be considered trusted, it is not necessary for the substitute certificate to have a signature (if it does (e.g. because you got it from somewhere else instead of making it yourself), then the signature can be ignored), nor is it necessary for the substitute certificate to be issued by anyone (this applies even if it is the end certificate being substituted).

I think some servers do not send a copy of the root certificate to the client. In this case, what I described above might already be possible even if that feature has not already been added to existing implementations, as long as it does not require the installed certificate to be self-signed.


It would be simple today to abolish the use of CAs but it just a big cargo biz that makes money on nothing as usual based on peoples incompetence. For 99% of all sites today security would be handled better without CAs. People simply don't understand how it works.

All that was true until fairly recently. Today, you can get certificates for free and there’s more transparency than ever thanks to CT.

What would you suggest as an alternative? TOFU?

I could see that for local applications (e.g. making mDNS/.local and private IP certs TOFU capable by default would be amazing, and maybe even for some explicit hobbyist public TLDs?), but I don’t think I’d love it for my bank or email provider.


> It would be simple today to abolish the use of CAs […]

The main technical way I know of doing this would be by putting TLS public keys in DNS (DANE, RFC 6698), but then you have to make sure that DNS packets are not fiddled with, so you need to bring in DNSSEC.


Exactly, and in some ways, DNS is even more centralized. At least there’s a choice of CAs independent of TLDs.

That's a false concern, because the names the CAs are certifying are still DNS names. If your TLD reasssigns your DNS name out from under you, or even if your TLD starts returning false data on only selected queries, the CAs will be happy to issue a cert to the new holder.

It would be great to have a widely-recognizable pseudodomain out there where the names were key hashes. It would actually graft really easily into DNSSEC. The zone format doesn't have to change at all; you just declare that if the KSK hash matches the domain label under this specific TLD, you don't need to check upstream of that. Then you add a P2P protocol for getting the actual data, and start slowly pushing that protocol down the resolver tree to incrementally decentralize everything.


This exists in Firefox at least, but I don’t think it’s easily exposed in the UI

20 years ago would have been a great time for that one.

> If Anthropic has all this data that Claude was being used by the Houthis to develop a missile guidance system, why the fuck did they allow it?

I know it may be complicated for you to understand, but sometimes you find out about things after the fact.

> Linux follows international sanctions in not allowing citizens of certain countries to be involved in any way, why isn't Anthropic following the law?

I know it may be complicated for you to understand, but people will try to circumvent any measures you might use to exclude "citizens of certain countries"... and will often succeed. That also applies to the measures Linux uses, by the way.

> Also, why will Anthropic end a session when you use colourful language to admonish it

Because a very significant fraction of "AI safety" is stupid. That particular kind of stupid "safety" tends to show up downstream of external pressures. Mostly from people who open with "Why doesn't Anthropic just...". Not to say that they don't also have internal sources of stupidity.

> yet apparently just knowingly allows terrorists to develop weapons?

Because, and do try to keep up on this one, rocket guidance is not necessarily "weapons", it's not always obvious that what you're working on is rocket guidance, and on the Internet nobody knows you're a terrorist.


> on the Internet nobody knows you’re a terrorist.

How does Anthropic know that they are terrorists then? They went off the Internet and confirmed in person?


Filming them at work, or following them to the next job so you can film them at work, is not in any way, shape, or form "harassment".

Yes, they should be different. In almost all cases, they should be less.

But what I really wanted to mention is that flock is not the government, and flock's services are not exclusively available to governments.

Same goes for their competitors.


The government represents the public will of the people and has democratic legitimacy. The notion that it should be more constrained than private actors seems absurd. I'm okay with taxation, pulling people over for speeding, automated speeding enforcement, fining parents who don't send their kids to school, garnishing wages, etc. that would be unacceptable from a private actor who is not imbued with the public's will.

>The notion that it should be more constrained than private actors seems absurd.

That is precisely the notion of the US constitution. If some random person chose to take down a flier criticizing the president, that is fair game (legally, or at least it defers to private policy). If a government agent did that, it verges on breaking the first amendment because we know that is a form of government suppression of speech. The first 10 amendments to the constitution pretty much all work to some extent of this logic.

> I'm okay with taxation, pulling people over for speeding, automated speeding enforcement, fining parents who don't send their kids to school, garnishing wages, etc. that would be unacceptable from a private actor who is not imbued with the public's will.

Those are all pretty much state laws outside of taxation, not part of the Constitution. We could setup campaigns to restrict those powers anytime we want to, or to grant them to private citizens in some cases.

Speech and surveillance fall under the constitution. Restricting/granting such power requires a much higher standard of process.


Due to the monopoly on violence, governments need additional more constraints in some areas. If your government dislikes you and they can track every step you take out in public, it becomes much easier for them to violate your rights without anyone stopping them. And because the government could fetch the same data from any company collecting it, companies too must be banned from doing so.

People who know what both of them are (hello) still won't know which one the headline is talking about.

The circuit one is definitely older, probably has more users, and is just as relevant in this forum.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: