Oregon auto atically registers you to vote when you get a license/ID, and has a pretty reliable mail in voting system. Other states interested in their constituents should do the same
This whole project reads like amateur hour. Still using curl pipe to shell install and everything. Plus this lax security disclosure with just an outstandingly foolish security flaw. Gross.
It's a team of 3. It's not like they have a security team, dedicated testers. They were for very long releasing beta software. That in fact already worked.
Oh, so when they advertise “Your Data, Forever and Secure”[1] in big bold letters on their homepage with total disregard for the truth of that statement they are just committing fraud. Got it.
> All social artifacts are stored in Git, and signed using public-key cryptography. Radicle verifies the authenticity and authorship of all data for you.
They're clearly not talking about privacy there.
Is it embarrassing that their private feature was broken? Sure. But it's for the most part a publishing platform. Protecting users against a network adversary who wan't to know what they're publishing isn't exactly core functionality.
Oh indeed, if we just redefine words in the fine print then we can commit fraud with impunity.
Please enlighten me how that blurb supports the common reading of the claim: Your data, … secure. Note that and is a additive conjunction, so the components can be safely examined separately.
A regular person would assume that means your data is secure against tampering and disclosure. If you then say: “lol, jk we do not do anything related to securing your data” in the fine print then in a reasonable society you should be required to remove that more prominent false large print.
You can always go back and reword your large print to be more accurate without making deceptive claims to your benefit. Weird how the deception is always beneficial.
Security is an umbrella term. You can't just assume that secure things are private--you have to make the determination in context with whatever kind of thing it is.
The primary goals of a system like radicle are:
- spread the word
- don't let anybody alter it
If you ask if it's secure, you should assume you'll get an answer related to those purposes.
If you got a sunburn while standing in line for a water slide, you wouldn't say that the slide is unsafe, even though being burned is a hell of a departure from "safety". You'd have to be a little more specific.
all of these start with “unauthorized access” to define this term. can you please explain how open access to private repositories is not unauthorized access and how you can’t expect your data moving to private repositories to be private?
> Information security's primary focus is the balanced protection of data confidentiality, integrity, and availability
..and radicle.dev does nothing to suggest confidentiality is a focus. Words like "private" or "encrypted" don't appear on their front page.
When I saw this, I was surprised because I didn't even know they supported private repos. I just don't understand why you'd want private repositories on a peer to peer protocol. The whole point is to get away from all of the problematic things that stem from having a single point of control/failure and the hierarchies that follow therefrom. Private repositories means that you're re-implementing the very problems that you're presumably using something like Radicle to get away from, now at the application layer instead. If you can tolerate having an admin that may later be unavailable or untrustworthy such that you're locked out, why not just use github?
It's like private blog posts on wordpress. Yeah, if the feature is in there it should work but projects like these encapsulate a certain perspective, and if they're run by a small number of technologists who clearly in it because they care, then I think it's reasonable to evaluate their success based on whether they address the primary problem they're up against, not whether they have a bug in some feature they tacked on as an afterthought.
Anybody can set up encryption on a link. Shame on them for forgetting to do that, but radicle has much more ambitious goals. If they need more help than they're getting for some of the mundane stuff, well I'm not going to judge them too harshly for that.
Neither did I, but the first minute of the video was so sloppy that I stopped to look him up. He's apparently a darling of the right-wing tin-foil-hat-wearing crowd.
As a thought experiment, perhaps someone there thought not fulfilling the Indian group's request would be seen as insensitive.
I suppose the decisionmaker needs to know what societal values one has to uphold, and in which order of importance. As a wild example, if the group had demanded the women walk around in the nude, because of their religion, it'd be obvious to say no because it'd violate so many of the employees' values.
Yes, it boils down to a conflict between two cultures. And when you visit a place, the expectation should be that you will respect local culture. If you cannot do that, stay home.
What if the Hindus had said "we are vegans, please don't serve us meat" - probably reasonable enough, although I seem to recall some rightwingers getting angry about some other occasion where only vegetarian food was to be served.
Yeah, as a host I'd be fine with meeting their dietary restrictions; but would refuse their with staff gender restrictions. Somehow the management company didn't know where this acceptability border lied.
We should allow kids to roam more. But their specific example of a couple letting their 5 year old go to the pond a couple blocks away without supervision is borderline. My spidey senses go off much more when water or pools are involved.
the thing about "borderline" and "spidey sense" is that in no way should that ever lead to someone being arrested or forced to register as a child abuser, but it did. the entire point of the article is that these sorts of nebulous situations are being treated the exact same as undeniable abuse, and that's the problem.
When we were kids we, so most of the kids from the neighborhood, would spend all day down at the beach with no adults around. When it was time for dinner the family that owned the house at the top of the hill would draw the curtains in the living room, which was visible from the beach, to tell all the kids to head back home. No-one ever drowned, died, or got swept out to sea in the inflatable boat we had. And none of the parents batted an eyelid at this, it was normal for kids growing up near the ocean.
This spying is even more prevelant in Korean cars, too. Really sad, because they can be a decent enough product (no worse than any other cheap car) but they are very anti consumer and burning their reputation.
Ugh. certifi the most annoying thing ever. It snuck into numerous python dependencies, never made anything better, and confuses all the junior devs when their venvs/containers etc can't access internal CA signed resources. Probably have explained what to do over 9,000 times. And for what? "To provide updated root CAs". Meh. I don't need daily CA trust store updates. If your CA roots are that new, I want nothing to do with it. Cert issuers (cough sectigo and their amateur hour CA root rotation recently, not even Mozilla had it).
reply