Readit News logoReadit News
botanical76 commented on White Noise – secure and private messenger   whitenoise.chat/... · Posted by u/onhacker
globalnode · 2 months ago
i admit i havent looked at the app, but i assume is centrally run.

firstly: i think the only way secure p2p messaging can work is if its decentralised. no 3rd parties to communication, how this would be done i have no idea. maybe like email but without the server?

secondly: you'd need to ensure a secure os on each end that you can trust to not take screenshots and send to hq before transmission or after reception.

since its not possible to use the internet without a source ip. its almost provably insecure (in terms of privacy), no matter what protocols are dreamed up. a 3rd party will have to be trusted to distribute packets. and thats the weak point. (unless you force the source IP to be 0.0.0.0 or something before it goes out)

couldnt we just use dns to point to recipients, force zero the source ip and send udp packets directly?

what about pgp through a tor relay?

botanical76 · 2 months ago
As I understand it, it's just a nostr client, so it uses nostr's decentralized network of relays.
botanical76 commented on Show HN: An open source alternative to Wakatime   wakana.io... · Posted by u/jemiluv8
jemiluv8 · 5 months ago
Let me know if anyone has challenges setting up.
botanical76 · 5 months ago
When trying to login via GitHub, I was redirected to "https://wakana.io/login?error=An+unexpected+error+occurred+w...", without an error message being displayed.
botanical76 commented on Ask HN: How should junior programmers use and/or not use AI for programming?    · Posted by u/taatparya
esperent · 5 months ago
> spend hundreds of thousands of tokens just rewriting entire features until there aren't any errors left

If it works, what's wrong with doing this? Obviously, don't turn your brain off. Be critical and work with the AI. But it's not like there's a shortage of tokens. They're only getting cheaper as time goes by. If, by spending enough tokens, you end up with a working feature, then this is a valid method of doing the work.

botanical76 · 5 months ago
Well, rewriting entire features without tact can be a little toxic in collaborative environments. There may be good reasons for the design that does already exist, and those reasons may not be backed by the test suite, and you may only find out about them once you've burned through a month of dev time and further changes on top of the rewrite.

You should consult the code owner or primary set of authors before proposing a large rewrite. But if you do this, you should understand very well the pros/cons of throwing away all of this old code, documentation, and unit tests that have an implicit dependency on the existing structure.

I worry that if you are just vibe coding and letting the AI rewrite everything at will, you could not be further from understanding the details involved.

botanical76 commented on Revealed: How the UK tech secretary uses ChatGPT for policy advice   newscientist.com/article/... · Posted by u/adrianhon
toasteros · 5 months ago
Really? How have policies been made for the past hundred years without it then?

It's completely bonkers that people keep saying stuff like this, virtually implying that we didn't have a functional society before LLMs.

LLMs are tools that generate word salads that sound compelling. They are not research aids and they can't help you understand things better than the plethora of tools we already developed over the centuries can.

So no, the alternative is policy makers doing what policy makers have always done: research, polling, reading, talking, and more research.

Now you'll likely come back and say "but X policy was bad and it was because it was poorly researched". Absolutely! Yes, bad policies exist. Poorly researched policies exist. Poorly implemented policies exist.

Good policies researched well also exist. And the bad ones aren't going away because of the magical word generator.

Seriously. Stop using LLMs to "help" you do stuff you already know how to do.

botanical76 · 5 months ago
> Seriously. Stop using LLMs to "help" you do stuff you already know how to do.

Why?

botanical76 commented on NCSC, GCHQ, UK Gov't expunge advice to “use Apple encryption”   alecmuffett.com/article/1... · Posted by u/jjgreen
kypro · 6 months ago
It surprises me I don't hear more about this in tech circles to be honest because it's something that concerns me greatly.

I like Cloudflare as a product, but it seems to me they've effectively made privacy from state actors online impossible.

Of course, if you cared enough you don't have to use services that use Cloudflare or other reverse proxy services, but most of the web is behind a reverse proxy these days making that difficult.

botanical76 · 6 months ago
It's also understandable why services opt to use a Cloudflare proxy, what with the growing threat that is DDoS attacks from large botnets.

I feel we should build an extension to HTTPS to allow Cloudflare / other reverse proxy services to proxy web requests without circumventing the SSL guarantees between the user and the host. It should be trivially possible.

That said, the cynical side of me worries that it works this way by design.

botanical76 commented on NCSC, GCHQ, UK Gov't expunge advice to “use Apple encryption”   alecmuffett.com/article/1... · Posted by u/jjgreen
verisimi · 6 months ago
The UK government should mandate http (not https) everywhere.
botanical76 · 6 months ago
Why bother? They can just visit Cloudflare HQ, who already proxy 19.3%[1] of the internet. AFAICT, all https traffic proxied by them is accessible to them in plaintext. Of course, Cloudflare are disallowed by law from letting us know if the UK government were surveilling all of their proxied traffic.[2]

[1] according to this particular metric: https://w3techs.com/technologies/details/cn-cloudflare [2] "the IPA makes it illegal for companies to disclose the existence of such government demands." https://www.macrumors.com/2025/02/21/apple-pulls-encrypted-i...

IANAL

botanical76 commented on I'm done with coding   neelc.org/2025/03/01/im-d... · Posted by u/neelc
tinyhouse · 6 months ago
[flagged]
botanical76 · 6 months ago
Isn't it self evident that this person has principles if they have left their job over it?

Does Visa Insights save lives?

botanical76 commented on Hot take: GPT 4.5 is a nothing burger   garymarcus.substack.com/p... · Posted by u/isaacfrond
elif · 6 months ago
Yep I am collecting my debates and one day I want to organize them with AI face and voices and release them as YouTube videos.
botanical76 · 6 months ago
I would implore that you just write a blog post or two (or three) instead, but it is your choice of course.
botanical76 commented on Hyperspace   hypercritical.co/2025/02/... · Posted by u/tobr
DontBreakAlex · 6 months ago
Nice, but I'm not getting a subscription for a filesystem utility. Had it been a one-time $5 license, I would have bought it. At the current price, it's literally cheaper to put files in a S3 bucket or outright buy an SSD.
botanical76 · 6 months ago
I can't even find the price anywhere. Do you have to install the software to see it?
botanical76 commented on Apple pulls data protection tool after UK government security row   bbc.com/news/articles/cgj... · Posted by u/helsinkiandrew
int_19h · 6 months ago
Many people do, unfortunately, so long as it's framed as "only terrorists and pedophiles need encryption that cops can't break".
botanical76 · 6 months ago
How do we actually beat this narrative? I've been proposing a E2EE-based chat application to my friend, and they asked me a similar question: won't it just be rife with pedophiles? How can you make a platform that will be used to that means?

I have strong views about privacy as a fundamental human right, but I don't know how to answer that question. I certainly don't want to make the world worse, but this feels like a lesser of two evils type of deal: either make it even harder to catch bad actors, such as child abusers, or make it plausible that your government take away your freedom forever.

u/botanical76

KarmaCake day133June 12, 2024View Original