• 106 Posts
  • 24 Comments
Joined 8 months ago
cake
Cake day: July 25th, 2024

help-circle


  • Duels? No clue, honestly. They definitely happened, but their frequency could definitely be overstated. As for meeting at noon? I think it sounds like the most reasonable time and would’ve been common if duels were common. This is pure, complete speculation on my part, so don’t repeat it without doing your own research, but I think the existing facts support my conclusion:

    • Home clocks at the time were only seen among rich folks, often as a status symbol.
    • Even if you did have one of these, they often lost quite a few minutes per day.
    • Towns often had a clock for the church.
    • This clock would’ve been more accurate than a home clock.
    • This clock often rang at noon.
    • Noon is (approximately) pretty easily verifiable by the position of the Sun being the highest in the sky.
    • Noon means that neither party should have an advantage based on where the Sun is facing if you line up east–west.
    • Noon is around a time most people are most likely to be the most awake.




  • I think the description of vulnerability is subjective in this case.

    No, it really isn’t. The Signal protocol enables E2EE, meaning you don’t have to worry about the server infra (that is, even if you don’t buy that they’re using the FOSS server code they say they are, it’s irrelevant). The Signal protocol is open and has been examined forwards and backwards over and over by security researchers around the world. I can’t emphasize how many eyes are on this protocol because of how prolifically used it is, including by government officials worldwide. The app is FOSS, and like the protocol, it has a ton of eyes on it for the same reason. The app is a reproducible build, meaning that if Signal baited you with a fake app, it would be found out immediately.

    It could be that signal is inherently more vulnerable than official channels, as Signal is a private corporation that has no motivation to disclose any failures in their security.

    They’re a corporation, sure, but in the sense that they’re a 501©(3), not a for-profit. Signal would have every incentive to disclose a failure in “their security” (where here that means their app or the protocol; again, what’s happening on the servers literally, provably, mathematically doesn’t matter). For a privacy org like this, it’s in their best interest to immediately report any problems that might compromise privacy.

    I don’t think the article is trying to blame Signal in any way, it’s just not the proper communication channel

    Agreed. But here, I agree it’s not the proper channel 1) because it’s on their personal devices which the person you’re responding to clearly stated and 2) a Signal chat (likely intentionally on their part) bypasses crucial records keeping laws. A known vuln for example is if someone has access to your phone, they can link their own personal device and read your messages as they come up. But again, that requires access to your phone, which becomes problematic if and only if you’re using your own personal device rather than a secure government one.

    and thus utilizing it is an inherent vulnerability no matter how secure their encryption may be.

    No. Again, that’s not an inherent vulnerability. Using it on their personal devices is, but unless you can come up with a vulnerability in the app itself or the protocol itself, then you’re just agreeing with the person you’re replying to.







  • EDIT: To be 1000% clear, they should not be using personal cell phones for this, which they probably did because everyone in this admin is braindead gutter trash. I’m suggesting that self-hosted Signal over government servers is probably fine for security with potentially some tweaks to the app. Something I neglected to think of however is that this sidesteps record keeping, and probably deliberately so. My contention here was solely about security, but this fact makes Signal use unconscionable in my book because it impedes accountability.


    Okay, let’s just be clear here: Signal isn’t just another “private app”; the amount of information they have about your communications is zero (0) with the exception that I believe they can see if you have an account and the last time you connected to the server. Governments absolutely do rely on Signal. The Signal protocol is open and highly robust, the app code is FOSS and has eyes from a shitload of security researchers globally due to its importance, its server code is FOSS (although you don’t have to trust this due to the robust E2EE, and you can even self-host IIRC due to the FOSS server code), and it has reproducible builds.

    This fuck-up was strictly due to the fact that they’re incompetent morons just randomly inviting people to group chats and shit with no guardrails. If I had to guess, they’d probably want to self-host the fork the Signal app and make it so that you can only invite people with some form of clearance, but this last thing is total speculation on my part. I’m sure there’s some way to sanely do this. The part about Signal being secure is just objectively true; it’s audited like absolute crazy, both the FOSS app and the protocol. I would trust it more than whatever the US government could homebrew, even.

    If you, as a citizen, are looking for secure, private messaging, Signal should be at the very top of your list of possible candidates alongside Matrix, SimpleX, and Session (keep in mind that Element and Session do not yet support forward secrecy, although the Matrix protocol does).





  • What you do not appear to be conceding is the trump may have the indirect power to replace the governor.

    Not true, but okay. That’s not the “technically correct” definition; that’s the unambiguously correct definition, and people who have no idea how pardon powers work are coping hard that they upvote whatever they think is true without actually doing any work to verify what they read. As with Reddit, so with Lemmy: it’s a constant on social media, and it’s a constant here that people have no fucking idea what they’re talking about and just vote based on what sounds right to them and what sounds the most authoritative. Evidenced by the fact you can’t go five seconds without reading an upvoted comment by someone who didn’t read past the headline (and then whining that that information should’ve been in the headline when they get called on it or trying to “um ackshually” their way out of it).

    Come back to me if this person gets pardoned. Until then: lol.





  • What role? Clinton works at Columbia now. It’s a matter of fact nonetheless that former officials are often called back to discuss things they have special knowledge of, let alone a Secretary of State of eight years. Would that be used now? No, because Donald Trump is a petulant fucking moron who does whatever braindead, evil, impulsive shit he wants. Would it if we had a competent president? Almost certainly, yes. I’m aware of the principle of least privilege; it does not apply here. It’s especially useful to have in a time of crisis because procedures still need to be followed, and getting clearance takes time. If you need that information right now but their clearance is revoked, you’re screwed.

    Donald Trump being an absolute moron and refusing to ever use her expertise isn’t a valid reason to revoke her clearance.





  • I couldn’t really get into StreetComplete when I tried it, but I think that’s mainly because I’m used to the iD editor’s UI and because it isn’t fully featured. Vespucci solved both of those things for me and gave me a fantastic editing experience. That said, for all I know, recommending Vespucci could leave a newcomer completely overwhelmed with options. So I would say that it’s worth starting with StreetComplete if you want a highly gamified experience for stuff like tag editing for existing objects or starting with Vespucci if you feel like you want something extremely powerful, then trying the other one if your first choice’s UI doesn’t suit you or doesn’t do what you want it to do. (StreetComplete and Vespucci are both available on F-Droid.)


  • OSM has a ways to go to be entirely competitive with GMaps as a navigation tool in most regions (although it gets the upper hand in other areas). OSM’s major advantages are four-fold:

    • It’s open to be used by anyone for any reason for free.
    • It can be contributed to by anyone.
    • (Crucially) It has a way higher ceiling than GMaps could ever hope to have. The level of potential granularity in OSM is absolutely insane. You can mark fire hydrants down to the color, diameter, pressure, and number of couplings. You can mark power lines down to the voltage, shape and material of each individual pole, etc. Individual trees can be marked down to the species. Every street crossing can be marked as having tactile pavings, a type of curb, a material, signals, refuge island, elevated or not, etc. Individual entrances to buildings can be marked as different types and with different door mechanisms. Heights of buildings in meters, whether they have air conditioning, etc., can be marked. This is barely scratching the surface. For navigation, things like this can be superfluous (I would argue that for people with disabilities like blindness, some of these things like the crossing types could be useful), but for research and specific applications, it can in theory crush GMaps rather than just being brought into parity with it.
    • The non-satellite map is just way, way better. If I look at my neighborhood which is reasonably well-mapped on OSM and then compare it to GMaps and Bing Maps, the latter two look like an absolute joke and rely heavily on satellite imagery to fill in the gaps. The problem with that of course is that not everything is visible from space, and it often gets fuzzy with minute details.