<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: dlitz</title><link>https://news.ycombinator.com/user?id=dlitz</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 12 Apr 2026 22:45:48 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=dlitz" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by dlitz in "Richard M. Stallman resigns"]]></title><description><![CDATA[
<p>I don't believe rms is seriously in favor of child sexual exploitation, but that's a red herring.<p>The concern for me is has been the accounts of far more directly-relevant behaviour, such as (iirc):<p><pre><code>  * repeated phone calls to someone from different phone numbers

  * leering

  * breaking the ground rules for an event, and justifying it on the basis that he's personally exempt from any rules

  * singling out a teenage girl attending one of his talks (as in "oh wow, a GIRL")

  * single her out again while telling his questionable 'EMACS virgins' joke

  * saying in an interview that he didn't know any women who have contributed to GCC, when there had been at least 4
</code></pre>
It all adds up to several accounts of people saying they've left the free software movement (or avoided it entirely) because of his behaviour combined with his stature.  As a community leader who supposedly leads by example, he needs to do better, and if he doesn't, the community needs to hold him accountable.  That's happening now.<p>Personally, I think this is a good thing, and I'm glad that he's made the decision to step aside (even if under pressure) rather than fight bitterly and see the community divide along these lines.<p>It also seems like a good opportunity for him to pass the torch and see what happens, or at least take a long hiatus to get some caring advice and to sort himself out, like Linus did last year.  The FSF will <i>eventually</i> need to become an institution that can carry on its mission without him, and this will be a good test of that.  If things go off the rails, he can pen another manifesto and I'm sure a bunch of us will read it.</p>
]]></description><pubDate>Tue, 17 Sep 2019 07:06:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=20992463</link><dc:creator>dlitz</dc:creator><comments>https://news.ycombinator.com/item?id=20992463</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=20992463</guid></item><item><title><![CDATA[New comment by dlitz in "Docker Hub Hacked – 190k accounts, GitHub tokens revoked, builds disabled"]]></title><description><![CDATA[
<p>Well, a compromised google.com main page could return malicious search results for certain queries.  How many Windows sysadmins install PuTTY by googling "putty", and then installing an executable from whatever site shows up in the first couple of results?...</p>
]]></description><pubDate>Sat, 27 Apr 2019 10:26:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=19764842</link><dc:creator>dlitz</dc:creator><comments>https://news.ycombinator.com/item?id=19764842</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=19764842</guid></item><item><title><![CDATA[New comment by dlitz in "Docker Hub Hacked – 190k accounts, GitHub tokens revoked, builds disabled"]]></title><description><![CDATA[
<p>The important thing is that tags are signed and up-to-date, like how git tags work or how Debian signs its entire repository as a unit (via the Release file) rather than having developers just sign individual packages.  Otherwise, even if it's signed, it's subject to downgrade attacks.<p>Installing known-vulnerable old versions of legitimate software can be just as bad as installing custom malware.</p>
]]></description><pubDate>Sat, 27 Apr 2019 10:22:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=19764835</link><dc:creator>dlitz</dc:creator><comments>https://news.ycombinator.com/item?id=19764835</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=19764835</guid></item><item><title><![CDATA[New comment by dlitz in "Docker Hub Hacked – 190k accounts, GitHub tokens revoked, builds disabled"]]></title><description><![CDATA[
<p>I think yall are using the terminology differently from each other in this thread.  "Checksum" historically did not imply resilience against intentional modifications.<p>Nowadays, it's arguably a best-practice when designing a new protocol or storage format to simply make all checksums cryptographically strong unless there's a reason not to.  I think that might be where the confusion is coming from.</p>
]]></description><pubDate>Sat, 27 Apr 2019 10:14:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=19764813</link><dc:creator>dlitz</dc:creator><comments>https://news.ycombinator.com/item?id=19764813</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=19764813</guid></item><item><title><![CDATA[New comment by dlitz in "What I learned from spending 3 months applying to jobs after a coding bootcamp"]]></title><description><![CDATA[
<p>Just fix it in the parser. ;)</p>
]]></description><pubDate>Tue, 22 Nov 2016 02:05:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=13011034</link><dc:creator>dlitz</dc:creator><comments>https://news.ycombinator.com/item?id=13011034</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=13011034</guid></item><item><title><![CDATA[Today Is Burn All GIFs Day (1999)]]></title><description><![CDATA[
<p>Article URL: <a href="http://www.geek.com/news/today-is-burn-all-gifs-day-566485/">http://www.geek.com/news/today-is-burn-all-gifs-day-566485/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=12879116">https://news.ycombinator.com/item?id=12879116</a></p>
<p>Points: 1</p>
<p># Comments: 0</p>
]]></description><pubDate>Sat, 05 Nov 2016 10:49:22 +0000</pubDate><link>http://www.geek.com/news/today-is-burn-all-gifs-day-566485/</link><dc:creator>dlitz</dc:creator><comments>https://news.ycombinator.com/item?id=12879116</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=12879116</guid></item><item><title><![CDATA[New comment by dlitz in "Proposal to add optional social media account fields to US Customs arrival forms"]]></title><description><![CDATA[
<p>It'll be great precedent for when Iran, China, Russia, etc. want to do the same thing.</p>
]]></description><pubDate>Sun, 28 Aug 2016 08:54:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=12375848</link><dc:creator>dlitz</dc:creator><comments>https://news.ycombinator.com/item?id=12375848</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=12375848</guid></item><item><title><![CDATA[New comment by dlitz in "EpiPen Price Rise Sparks Concern for Allergy Sufferers"]]></title><description><![CDATA[
<p>Yes, apparently Canada has something called the Patented Medicine Prices Review Board:<p><a href="http://pmprb-cepmb.gc.ca/about-us/frequently-asked-questions" rel="nofollow">http://pmprb-cepmb.gc.ca/about-us/frequently-asked-questions</a></p>
]]></description><pubDate>Tue, 23 Aug 2016 08:12:12 +0000</pubDate><link>https://news.ycombinator.com/item?id=12342132</link><dc:creator>dlitz</dc:creator><comments>https://news.ycombinator.com/item?id=12342132</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=12342132</guid></item><item><title><![CDATA[New comment by dlitz in "A x64 OS #1: UEFI"]]></title><description><![CDATA[
<p>Yeah, Matthew Garrett also gave a pretty detailed talk about it Linux.conf.au 2012, which reaches a similar conclusion: <a href="https://www.youtube.com/watch?v=V2aq5M3Q76U" rel="nofollow">https://www.youtube.com/watch?v=V2aq5M3Q76U</a></p>
]]></description><pubDate>Sat, 06 Aug 2016 19:51:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=12239588</link><dc:creator>dlitz</dc:creator><comments>https://news.ycombinator.com/item?id=12239588</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=12239588</guid></item><item><title><![CDATA[New comment by dlitz in "Spy or whistleblower? Should Obama settle with Snowden?"]]></title><description><![CDATA[
<p>Foreign journalists? Glenn Greenwald and Laura Poitras are both American.</p>
]]></description><pubDate>Sun, 17 Jul 2016 06:37:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=12109266</link><dc:creator>dlitz</dc:creator><comments>https://news.ycombinator.com/item?id=12109266</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=12109266</guid></item><item><title><![CDATA[New comment by dlitz in "Misfortune"]]></title><description><![CDATA[
<p>The "auto" in "autopilot" stands for automatic, not autonomous.  Autopilot systems have existed for decades, and they've always referred to systems that automate the most tedious parts of operating a vehicle, while still requiring a human operator to handle new/unexpected situations.</p>
]]></description><pubDate>Sun, 17 Jul 2016 06:31:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=12109252</link><dc:creator>dlitz</dc:creator><comments>https://news.ycombinator.com/item?id=12109252</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=12109252</guid></item><item><title><![CDATA[New comment by dlitz in "Ask HN: How should the CLI be designed today?"]]></title><description><![CDATA[
<p>I'd like to see a good CLI design involving sandboxing-by-default, and handling object-capabilities (e.g. file descriptors) as first-class objects.<p>Right now, "convert a.jpg b.png" passes the strings "a.jpg" and "b.png" to ImageMagick's convert command, but that command is free to open whatever files it wants, since there's no distinction between strings vs resources such as filenames, network sockets, etc.<p>You can do this with pipes in simple cases, and bash has some support for this, but it's very primitive and the syntax is cumbersome.</p>
]]></description><pubDate>Sat, 16 Jul 2016 21:00:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=12107861</link><dc:creator>dlitz</dc:creator><comments>https://news.ycombinator.com/item?id=12107861</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=12107861</guid></item><item><title><![CDATA[New comment by dlitz in "Miranda Warning Equivalents Abroad [pdf]"]]></title><description><![CDATA[
<p>I live in Canada.  AS6939 is Hurricane Electric.</p>
]]></description><pubDate>Tue, 05 Jul 2016 14:44:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=12036752</link><dc:creator>dlitz</dc:creator><comments>https://news.ycombinator.com/item?id=12036752</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=12036752</guid></item><item><title><![CDATA[New comment by dlitz in "Egypt cancelled DST"]]></title><description><![CDATA[
<p>You do when you work at a job that doesn't offer flexible hours.</p>
]]></description><pubDate>Tue, 05 Jul 2016 14:35:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=12036686</link><dc:creator>dlitz</dc:creator><comments>https://news.ycombinator.com/item?id=12036686</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=12036686</guid></item><item><title><![CDATA[New comment by dlitz in "Miranda Warning Equivalents Abroad [pdf]"]]></title><description><![CDATA[
<p>Error 1005 Ray ID: 2bc55074399a2a5b • 2016-07-02 21:50:36 UTC
Access denied
What happened?<p>The owner of this website (www.fas.org) has banned the autonomous system number (ASN) your IP address is in (6939) from accessing this website.</p>
]]></description><pubDate>Sat, 02 Jul 2016 21:51:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=12023909</link><dc:creator>dlitz</dc:creator><comments>https://news.ycombinator.com/item?id=12023909</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=12023909</guid></item><item><title><![CDATA[New comment by dlitz in "Extracting Qualcomm's KeyMaster Keys – Breaking Android Full Disk Encryption"]]></title><description><![CDATA[
<p>You also want the passphrase to be easily changed, separately from the master key (because changing the master key is slow and resource-intensive).<p>Even if you have a strong passphrase, there's some probability of leaking some number of bits of it via side-channels every time it's entered (e.g. surveillance cameras, fingerprints on the screen, shoulder surfing, vulnerable code, TEMPEST, etc).  Plus, people often keep a backup copy of their passphrases (unique, strong passphrases are hard to remember), so there's also a cumulative risk of the backup leaking over time, as well.<p>Long-term confidentiality is just surprisingly hard in the real world.</p>
]]></description><pubDate>Thu, 30 Jun 2016 18:54:34 +0000</pubDate><link>https://news.ycombinator.com/item?id=12010835</link><dc:creator>dlitz</dc:creator><comments>https://news.ycombinator.com/item?id=12010835</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=12010835</guid></item><item><title><![CDATA[New comment by dlitz in "Facebook Offers Tools for Those Who Fear a Friend May Be Suicidal"]]></title><description><![CDATA[
<p>Is there any way to see exactly what this system does, aside from faking a suicidal episode on my timeline and getting friends to report it?<p>I've heard that early versions of this system basically inserted barriers between suicidal people---who are already overwhelmed---and their support networks.<p>Considering Facebook's poor track record when it comes to handling vulnerable populations (nym policy, location support in Messenger, etc.), I'd strongly discourage anyone from using this reporting system without a complete understanding of what it actually does.<p>Heed should also be paid to the effect of having more than one of these systems being triggered at the same time.  The last thing I need when I'm feeling overwhelmed is a dozen apps on my phone suddenly changing their behavior.</p>
]]></description><pubDate>Tue, 14 Jun 2016 21:28:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=11905457</link><dc:creator>dlitz</dc:creator><comments>https://news.ycombinator.com/item?id=11905457</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=11905457</guid></item><item><title><![CDATA[New comment by dlitz in "Why Online Voting Is a Danger to Democracy"]]></title><description><![CDATA[
<p>How does this guarantee a secret ballot, i.e. that voters remain <i>unable</i> to prove to a third party that they voted in a particular way?<p>Low-value elections don't necessarily need secret ballots, but it's important for high-value elections, like selecting the POTUS.</p>
]]></description><pubDate>Tue, 14 Jun 2016 08:32:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=11900618</link><dc:creator>dlitz</dc:creator><comments>https://news.ycombinator.com/item?id=11900618</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=11900618</guid></item><item><title><![CDATA[New comment by dlitz in "Why Online Voting Is a Danger to Democracy"]]></title><description><![CDATA[
<p>The problem is harder than it sounds when you're talking about something as high-value as a national election (especially in the US).<p>Have you read "Reflections on Trusting Trust"?</p>
]]></description><pubDate>Tue, 14 Jun 2016 08:28:10 +0000</pubDate><link>https://news.ycombinator.com/item?id=11900600</link><dc:creator>dlitz</dc:creator><comments>https://news.ycombinator.com/item?id=11900600</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=11900600</guid></item><item><title><![CDATA[New comment by dlitz in "GNOME's plan to discourage portable Gtk apps"]]></title><description><![CDATA[
<p>I don't see the big problem.  Lots of other libraries already work this way.  Perhaps most of them.<p>If you're shipping binary packages, you need to build them in a clean chrooted environment anyway (such as pbuilder/sbuilder/docker or a VM) or you're going to end up with binaries that depend on the latest glibc point release that happens to be installed on your system.</p>
]]></description><pubDate>Tue, 14 Jun 2016 04:33:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=11899794</link><dc:creator>dlitz</dc:creator><comments>https://news.ycombinator.com/item?id=11899794</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=11899794</guid></item></channel></rss>