<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: goldsteinq</title><link>https://news.ycombinator.com/user?id=goldsteinq</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 23 Apr 2026 12:17:33 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=goldsteinq" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by goldsteinq in "Telemetry helps. you still get to turn it off"]]></title><description><![CDATA[
<p>> Folks who manually enable our "Resist Fingerprinting" preference (which we don't officially support, and I don't generally recommend - but hey, you do you) are very loud on Bugzilla. VERY loud. To the point where I've had a lot of managers and executives come telling me "Everyone is complaining about this breaking stuff, we really need to disable this so people can't accidentally turn it on." Telemetry let me show that despite being SO LOUD they're still a minute portion of the population. Management's question "Should we block it?" became "No." You're welcome.<p>Telemetry shows that users who didn’t opt out of telemetry don’t care about fingerprinting. Who’d have thought.</p>
]]></description><pubDate>Fri, 06 Mar 2026 10:21:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=47273168</link><dc:creator>goldsteinq</dc:creator><comments>https://news.ycombinator.com/item?id=47273168</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47273168</guid></item><item><title><![CDATA[New comment by goldsteinq in "Practical Decentralization"]]></title><description><![CDATA[
<p>It keeps missing the fact that BlueSky, as of today, is not decentralized in any meaningful way. If tomorrow bsky.app (and/or PLC registry) goes dark, the network is dead. There’re no public alternative AppViews. Most users use centralized PLC IDs, which depend on the centralized infra. An extreme minority of users uses external PDSes.<p><a href="https://blue.mackuba.eu/stats/" rel="nofollow">https://blue.mackuba.eu/stats/</a><p><a href="https://arewedecentralizedyet.online/" rel="nofollow">https://arewedecentralizedyet.online/</a><p>> We need to finish moving PLC into an independent org<p>Does not make it decentralized; instead creates a second centralized failure point.<p>> large scale “appviews” — the aggregating backends of apps — are still a bit too expensive and a bit too difficult to write<p>Which is an architectural limitation, because AppViews must store the entire network, and will only get worse.<p>It’s really weird to say that BlueSky is an example of “practical decentralization” when all of its decentralization serves no practical purpose at all.</p>
]]></description><pubDate>Thu, 26 Feb 2026 18:54:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=47170390</link><dc:creator>goldsteinq</dc:creator><comments>https://news.ycombinator.com/item?id=47170390</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47170390</guid></item><item><title><![CDATA[New comment by goldsteinq in "Gpg.fail"]]></title><description><![CDATA[
<p>No “Submit Debug Logs” there, as far as I can see. Do I need to be on matrix.org homeserver for this to work or something?<p><a href="https://photos.goldstein.lol/share/OIgowBN4Wmi4zlm8DmDP0s8jH90Pc96YIopnvrN2NRMSvP0vb0hgFZ3R-5ex67c4SN4" rel="nofollow">https://photos.goldstein.lol/share/OIgowBN4Wmi4zlm8DmDP0s8jH...</a></p>
]]></description><pubDate>Mon, 29 Dec 2025 10:04:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=46419081</link><dc:creator>goldsteinq</dc:creator><comments>https://news.ycombinator.com/item?id=46419081</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46419081</guid></item><item><title><![CDATA[New comment by goldsteinq in "Gpg.fail"]]></title><description><![CDATA[
<p>I’m facing it on Element Desktop, but I’ll try to reproduce it on Element Web. I’ve tried to submit logs from Element Desktop, but it says that `/rageshake` (which I was told to do) is not a command. I’m happy to help with debugging this, but I’m not sure how to submit logs from Desktop.<p>Something like this happens basically every time I try to use Matrix though. Messages are not decrypting, or not being delivered, or devices can’t be authenticated for some cryptic reason. The reason I even tried to use Element Desktop is because my nheko is seemingly now incapable of sending direct messages (the recepient just gets infinite “waiting for message”).</p>
]]></description><pubDate>Mon, 29 Dec 2025 00:19:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=46415939</link><dc:creator>goldsteinq</dc:creator><comments>https://news.ycombinator.com/item?id=46415939</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46415939</guid></item><item><title><![CDATA[New comment by goldsteinq in "Gpg.fail"]]></title><description><![CDATA[
<p>Okay, sorry, not oss-security mailing list, oss-security _distros_ mailing list.<p><a href="https://oss-security.openwall.org/wiki/mailing-lists/distros" rel="nofollow">https://oss-security.openwall.org/wiki/mailing-lists/distros</a><p>> Only use these lists to report security issues that are not yet public<p>> To report a non-public medium or high severity 2) security issue to one of these lists, send e-mail to distros [at] vs [dot] openwall [dot] org or linux [dash] distros [at] vs [dot] openwall [dot] org (choose one of these lists depending on who you want to inform), preferably PGP-encrypted to the key below.</p>
]]></description><pubDate>Sun, 28 Dec 2025 21:42:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=46414823</link><dc:creator>goldsteinq</dc:creator><comments>https://news.ycombinator.com/item?id=46414823</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46414823</guid></item><item><title><![CDATA[New comment by goldsteinq in "Gpg.fail"]]></title><description><![CDATA[
<p>> Say more. Plenty of people use Signal as a serious communication tool.<p>I did say more already. Maybe you believe in serious communication tools that can’t synchronize searchable history between devices, but I don’t.<p>> They, and other communities that use GPG-encrypted emails are LARPing, and it’s only fine because their emails don’t actually matter enough for anybody to care about compromising them.<p>Are we talking about the same Openwall? Are you aware what Openwall’s oss-security mailing list is? Please, do elaborate how nobody cares about getting access to an unlimited stream of zerodays for basically every Unix-like system.</p>
]]></description><pubDate>Sun, 28 Dec 2025 21:22:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=46414655</link><dc:creator>goldsteinq</dc:creator><comments>https://news.ycombinator.com/item?id=46414655</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46414655</guid></item><item><title><![CDATA[New comment by goldsteinq in "Gpg.fail"]]></title><description><![CDATA[
<p>I’m definitely not “commiting malpractice” on account of not being a security practicioner. I’m talking from a perspective of a user.<p>It’s important to me — as a user — that a communication tool doesn’t lose my data, and Signal already did. Actual practicioners keep recommending Signal and sure, I believe that in a weird scenario where my encryption keys are somehow compromised without also compromising my local message history, Signal’s double-ratchet will do wonders — but it doesn’t actually work as a serious communication tool.<p>It’s also kinda curious that while the “email cannot be made secure” mantra is constantly repeated online, basically every organization that needs secure communication uses email. Openwall are certainly practicioners, and they use PGP-over-email: are they commiting malpractice?</p>
]]></description><pubDate>Sun, 28 Dec 2025 20:56:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=46414417</link><dc:creator>goldsteinq</dc:creator><comments>https://news.ycombinator.com/item?id=46414417</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46414417</guid></item><item><title><![CDATA[New comment by goldsteinq in "Gpg.fail"]]></title><description><![CDATA[
<p>Pros of Matrix: it actually has a consistent history (in theory); no vendor lock-in.
Cons of Matrix: encryption breaks constantly. Right now I’m stuck in a fun loop of endlessly changing recovery keys: <a href="https://github.com/element-hq/element-web/issues/31392" rel="nofollow">https://github.com/element-hq/element-web/issues/31392</a></p>
]]></description><pubDate>Sun, 28 Dec 2025 20:35:35 +0000</pubDate><link>https://news.ycombinator.com/item?id=46414233</link><dc:creator>goldsteinq</dc:creator><comments>https://news.ycombinator.com/item?id=46414233</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46414233</guid></item><item><title><![CDATA[New comment by goldsteinq in "Gpg.fail"]]></title><description><![CDATA[
<p>Yes, if your only device is a single Android phone you can do that. You can’t, however, use that backup to populate your message history on other platforms.<p>I’ve already lost message history consistency because one of my devices was offline for too long. The messages are there on my other device, but Signal refuses to let me copy my data from one of my devices to another. Signal is, quite literally, worse at syncing message history than IRC — at least with IRC I can set up a bouncer and have a consistent view of history on all of my devices, but there’re no Signal bouncers.</p>
]]></description><pubDate>Sun, 28 Dec 2025 20:28:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=46414182</link><dc:creator>goldsteinq</dc:creator><comments>https://news.ycombinator.com/item?id=46414182</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46414182</guid></item><item><title><![CDATA[New comment by goldsteinq in "Gpg.fail"]]></title><description><![CDATA[
<p>> You don't have to use it like "encrypted SMS"! You're free.<p>Using it as something more than encrypted SMS requires persistent message history between devices.<p>> metric fuckton of messages<p>“More than 45 days” is a metric fuckton? Seriously?<p>> If you want Signal to host the encrypted storage, that costs money. If you don't want to pay Signal money, they provide 45 days of backup for free.<p>I don’t want Signal to store my messages. I want Signal to not lock in my messages on their servers, so I can sync them between my devices and back them up into my own backups.<p>> If you want to self-host your own backups (at your own cost), that's easy to do.<p>Except there’s no way to move it between platforms. I have more than one device.<p>> Are you referring to MobileCoin? That feature isn't in the pipeline for sending messages.<p>I don’t want shady crypto company to hold my data hostage, and there’s no way to store it on my hardware and then move it between platforms. That’s my problem with signal.<p>> A Synchronized Start for Linked Devices<p>It only properly transfers 45 days. You can’t have more than one phone. Phones are special “primary devices” and AFAIK you can’t restore your messages if you lose your phone even if you have logged-in Signal Desktop.</p>
]]></description><pubDate>Sun, 28 Dec 2025 19:51:37 +0000</pubDate><link>https://news.ycombinator.com/item?id=46413880</link><dc:creator>goldsteinq</dc:creator><comments>https://news.ycombinator.com/item?id=46413880</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46413880</guid></item><item><title><![CDATA[New comment by goldsteinq in "Gpg.fail"]]></title><description><![CDATA[
<p>> If you want a suggestion for secure messaging, it's Signal/WhatsApp. If you want to LARP at security with a handful of other folks, GPG is a fine way to do that.<p>I want secure messaging, not encrypted SMS.
I want my messages to sync properly between arbitrary number of devices.
I want my messaging history to not be lost when I lose a device.
I want not losing my messaging history to not be a paid feature.
I want to not depend on a shady crypto company to send a message.</p>
]]></description><pubDate>Sun, 28 Dec 2025 17:02:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=46412463</link><dc:creator>goldsteinq</dc:creator><comments>https://news.ycombinator.com/item?id=46412463</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46412463</guid></item><item><title><![CDATA[New comment by goldsteinq in "The 2025 Matrix Holiday Special"]]></title><description><![CDATA[
<p>According to the official Matrix website (<a href="https://matrix.org/ecosystem/clients/element-x/" rel="nofollow">https://matrix.org/ecosystem/clients/element-x/</a>, <a href="https://matrix.org/ecosystem/clients/element/" rel="nofollow">https://matrix.org/ecosystem/clients/element/</a>): threads, voice calls, spaces, SSO.</p>
]]></description><pubDate>Thu, 25 Dec 2025 12:33:26 +0000</pubDate><link>https://news.ycombinator.com/item?id=46384032</link><dc:creator>goldsteinq</dc:creator><comments>https://news.ycombinator.com/item?id=46384032</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46384032</guid></item><item><title><![CDATA[New comment by goldsteinq in "The 2025 Matrix Holiday Special"]]></title><description><![CDATA[
<p>> some Element users are still stuck on the Classic app, unaware that Element X exists<p>This sounds really arrogant. Element X _still_ lacks a lot of features, saying that the only reason to use classic Element is that you must be unaware of Element X completely ignores that. I wish “Element Creations Ltd” was as aggressive in creating Element X as they are in pushing it.</p>
]]></description><pubDate>Thu, 25 Dec 2025 10:31:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=46383529</link><dc:creator>goldsteinq</dc:creator><comments>https://news.ycombinator.com/item?id=46383529</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46383529</guid></item><item><title><![CDATA[New comment by goldsteinq in "PowerShell's curl runs JavaScript code with system access"]]></title><description><![CDATA[
<p>I wanted to make a more descriptive title, mentioning that Microsoft uses its own program for `curl` command, but ran out of characters.</p>
]]></description><pubDate>Sat, 20 Dec 2025 23:31:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=46340715</link><dc:creator>goldsteinq</dc:creator><comments>https://news.ycombinator.com/item?id=46340715</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46340715</guid></item><item><title><![CDATA[New comment by goldsteinq in "PowerShell's curl runs JavaScript code with system access"]]></title><description><![CDATA[
<p>> Also, for OP: Do you mean "access to the system it runs on"? Because I'm pretty sure it doesn't run with "SYSTEM" access (as in privileged user).<p>Yeah, I mean “access to the system”. It’s not the same as using headless chrome, because it gives you ActiveX and you can shell out to an arbitrary command.</p>
]]></description><pubDate>Sat, 20 Dec 2025 23:30:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=46340708</link><dc:creator>goldsteinq</dc:creator><comments>https://news.ycombinator.com/item?id=46340708</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46340708</guid></item><item><title><![CDATA[PowerShell's curl runs JavaScript code with system access]]></title><description><![CDATA[
<p>Article URL: <a href="https://support.microsoft.com/en-us/topic/powershell-5-1-preventing-script-execution-from-web-content-7cb95559-655e-43fd-a8bd-ceef2406b705">https://support.microsoft.com/en-us/topic/powershell-5-1-preventing-script-execution-from-web-content-7cb95559-655e-43fd-a8bd-ceef2406b705</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46339551">https://news.ycombinator.com/item?id=46339551</a></p>
<p>Points: 13</p>
<p># Comments: 8</p>
]]></description><pubDate>Sat, 20 Dec 2025 20:52:23 +0000</pubDate><link>https://support.microsoft.com/en-us/topic/powershell-5-1-preventing-script-execution-from-web-content-7cb95559-655e-43fd-a8bd-ceef2406b705</link><dc:creator>goldsteinq</dc:creator><comments>https://news.ycombinator.com/item?id=46339551</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46339551</guid></item><item><title><![CDATA[New comment by goldsteinq in "Is Mozilla trying hard to kill itself?"]]></title><description><![CDATA[
<p>Equivalent of $5-6 monthly</p>
]]></description><pubDate>Sat, 20 Dec 2025 17:21:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=46337751</link><dc:creator>goldsteinq</dc:creator><comments>https://news.ycombinator.com/item?id=46337751</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46337751</guid></item><item><title><![CDATA[Maintaining an open source software during Hacktoberfest]]></title><description><![CDATA[
<p>Article URL: <a href="https://crocidb.com/post/maintaining-an-oss-during-hacktoberfest/">https://crocidb.com/post/maintaining-an-oss-during-hacktoberfest/</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=46302004">https://news.ycombinator.com/item?id=46302004</a></p>
<p>Points: 3</p>
<p># Comments: 0</p>
]]></description><pubDate>Wed, 17 Dec 2025 16:54:10 +0000</pubDate><link>https://crocidb.com/post/maintaining-an-oss-during-hacktoberfest/</link><dc:creator>goldsteinq</dc:creator><comments>https://news.ycombinator.com/item?id=46302004</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46302004</guid></item><item><title><![CDATA[New comment by goldsteinq in "Is Mozilla trying hard to kill itself?"]]></title><description><![CDATA[
<p>I am subscribed to recurrent donations to Thunderbird.<p>I would pay for Firefox if it was focused on privacy and customizabilty, not telemetry and LLMs.</p>
]]></description><pubDate>Wed, 17 Dec 2025 16:50:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=46301943</link><dc:creator>goldsteinq</dc:creator><comments>https://news.ycombinator.com/item?id=46301943</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46301943</guid></item><item><title><![CDATA[New comment by goldsteinq in "Tarmageddon: RCE vulnerability highlights challenges of open source abandonware"]]></title><description><![CDATA[
<p>So the first scenario is also basically “automatic scanner bypass”? That answers my question, yes.<p>> making a tar file that when inspected looks fine<p>Am I correct in understanding that manual inspection would reveal a nested .tar archive (so recursive inspection of nested archives should be enough)?</p>
]]></description><pubDate>Thu, 23 Oct 2025 09:02:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=45679769</link><dc:creator>goldsteinq</dc:creator><comments>https://news.ycombinator.com/item?id=45679769</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45679769</guid></item></channel></rss>