Hacker Newsnew | past | comments | ask | show | jobs | submit | dxdm's commentslogin

Since you mentioned it below several responses to this comment: Why do you think this is okay for software, but not okay in the "physical world"?

Is it about a perceived lack of consequences of the one vs the other? What if the hack caused real damage and suffering? For example, people's medical histories get stolen and exposed? Ransomware encrypts hospital systems, disrupting medical care?

Or, the inverse: while you're away, somebody breaks into your home non-destructively, takes some photos, sleeps on your couch, and leaves. Should that be forbidden? Your fault for allowing it? It is easier to pull something like this in the digital world, is that why it seems different to you?


I don't agree with GP at all, but making hacking illegal indeed gives companies a false sense of security.

Making burglaries illegal is a real way of preventing many burglaries from happening, because it puts people committing them in prison and deters some from doing it in the first place. This only works because the burglar is in the same place as the burglary, and so they can be arrested.

People with little to no computer experience apply the same standard to cybersecurity and treat foreign hackers the same way as burglars. Then they get surprised when the Russians hack them and the FBI does nothing.


You're presenting a false dilemma, there are more options than "all hacking is completely illegal" and "all hacking is a free-for-all".

We're in a thread that starts from the notion that it should not be illegal to "hack a telecom network and take control of it", because "the people running it did not do a good job configuring and securing it." That's essentially the free-for-all position, and defending it by claiming that the opposite extreme is the only other option is a false choice. Nuance and compromise exist, and our world is made of them.

Also, your argument about burglars can be applied to "hackers", too. Police can find and arrest people domestically and beyond. Consequences deter people from all sorts of illegal activity. On the other hand, nation states are not necessarily deterred by laws from kidnapping and killing people inside the territory of other countries. You've probably seen the news.

What's different is the ease of access to digitical, internet-connected systems, and the scale of abuse that affords. That's a reason to think differently about _how_ to shape the rules and laws around "hacking", but not a reason to have no rules or laws at all.


Because it is a battle of the brains, like when you play chess. And I believe the smarter one should win. This is why I have this strongly held belief that if you get hacked, it is on you. The attacker was smarter than you, simple as that. So you have to get smarter and become better. Or you get hacked again and again.

I really don’t understand the urge or need to compare software security with physical security.


> I really don’t understand the urge or need to compare software security with physical security.

Both are about preventing harm in many different forms. Software famously has effects in the physical world, that's the reason why a lot of it exists, and why people get paid that deal with software because it makes their brains feel good.

I also notice that you haven't really answered my questions around that.

> if you get hacked, it is on you. The attacker was smarter than you, simple as that.

From your perspective, what makes "smarter" different from "stronger", or "more resourceful" here? Or do you think that if your door gets bashed in, it's your fault, because your door was too weak? Or your head? What if someone outsmarts your physical security arrangements to wander around in your house? Where's your boundary here?

I think physical and "cyber" security are not so dissimilar in the need to back them up with rules and laws at some point. Still, there are differences, so I don't think the rules and laws need to be the same. You seem to be advocating to have none at all for the software case, and I'm trying to find out about that.


> Both are about preventing harm in many different forms. Software famously has effects in the physical world, that's the reason why a lot of it exists, and why people get paid that deal with software because it makes their brains feel good.

Yes, it would suck if the hospital got hacked while I underwent a surgery for example, and the ventilator stopped working. But if that happens, whoever is doing it is not stronger, just smarter than the people administering the hospital network.

> From your perspective, what makes "smarter" different from "stronger", or "more resourceful" here? Or do you think that if your door gets bashed in, it's your fault, because your door was too weak? Or your head? What if someone outsmarts your physical security arrangements to wander around in your house? Where's your boundary here?

I gave an analogy with chess. You don't have to be strong in the physical sense to win a chess match, just smarter than your opponent. This is how I see the difference.

> You seem to be advocating to have none at all for the software case, and I'm trying to find out about that.

For software, the playing field is level: you use a computer, your opponent uses a computer. But the difference is the other person's capabilities. You can be smarter and you don't get hacked, or your opponent is smarter and hacks you.


Here's how I understand your position so far:

You think it's okay when actual harm and suffering results from a "battle of the brains" via computers, because one party "outsmarted" the other. Sure, it would "suck", but you think the playing field is pure and level, making it a fair contest and any consequence fair game, and therefore it should not be illegal.

You are unable or unwilling to engage with the question if and why using a computer and "smarts" to cause harm is different from using strength, or any other advantage, to cause such adverse outcomes in other ways; it is not clear to me if you would also regard that as okay and think we should not have the laws that sanction such things; or if and why you think this anarchy should only exist in some sort of "digital computer space", crossing which would serve to make actual, real world consequences not matter that much anymore. It's almost like, by putting a computer between actions and consequences, one passes through a waterfall that washes away responsibility and "sin", in the ethical sense. But that depends on whether you think those were there to begin with, and is only an interesting metaphor for me; please don't get distracted by it.

In any case, that's a very interesting position. I'm curious what you gain from arguing it. Where does that come from? It's possible you're just trolling, but maybe smarts and brains connected via networks are truly special to you. Why?

(Edit: Please disregard "what you gain", it comes across completely wrong and takes it in an unintended direction. "Where does it come from" is what I mean.)


> You think it's okay when actual harm and suffering results from a "battle of the brains" via computers, because one party "outsmarted" the other. Sure, it would "suck", but you think the playing field is pure and level, making it a fair contest and any consequence fair game, and therefore it should not be illegal.

I said the fault lies with the administrators of those systems, not with attackers. I really think I never said it should be legal or illegal. I don’t really care if it is illegal or not, hackers are not dettered by the legality of it. Do you think someone in The Gambia cares that hacking is illegal in Canada?

> You are unable or unwilling to engage with the question if and why using a computer and "smarts" to cause harm is different from using strength

For me being smart and being strong are two wildly different things. It is like asking me why I don’t compare apples to oranges. I can’t.

> In any case, that's a very interesting position. I'm curious what you gain from arguing it. Where does that come from? It's possible you're just trolling, but maybe smarts and brains connected via networks are truly special to you. Why?

I am not trolling. I see this, hacking and securing something against hacking, as an “intellectual fight”.

Let’s say you are a 50 year old security admin that gets owned by a 14 year old with a computer. You were beat because the 14 year old one was smarter than you, not that he had more experience or was physically stronger than you. Just smarter.

Now imagine you’re part of a security team and you still get owned. What does that say about you?

I am at a loss on how to explain that when it comes to computer security the fault, in my book, does not lie with the hacker.

Just like when a flaw is found and exploited I do not blame the one who found it, but whoever made it possible in the first place. And in the case that the flaw was patched and a software update was made available, but it was not installed promptly, then the fault lies with whoever did not update the system.

Regarding arguing: I made a statement expressing my position and got mobbed for it. Now I am defending my position.

We can agree to disagree and keep enjoying what is left of our weekends.


Oh, I don't mind the disagreement, I'm curious to understand why your position is so different from mine, after getting closer to understanding what your position actually is. (I had to do that because there are some implicit premises in my thinking vs what you're saying which seem fundamentally different, and I had to work those out for myself.)

I think I do get it now, and it seems to be pretty much to what I described before. While I think that there is responsibility for the outcomes of one's actions no matter through which ways and means they are accomplished, for you, it seems to depend: making it about smarts or intellect or whatever, and putting a computer in between, causes it to transcend legality and morality. Adverse consequences are not on the actor anymore, and purely on the "defender".

That's not how a lot of people (including myself) see this issue. They would not agree that responsibility and outcomes should get disconnected or redistributed by changing the ways and means in between. (Edit, just to make this extra clear: The idea is that it should not matter if one uses their brain and a computer to effect damage, or some other means. Computers are a different tool, not a different game.) Even more, people find it hard to follow both the ethics and the logic of your argument, because you've not been able to express WHY an exception should be made for "smarts" and "computers" and not in other cases. Whenever I've asked you to explain, you've either misunderstood or evaded the question and responded with re-iterating that "smart" is different from "strong", as if that explains anything. (It boils down to being asked: "Why should the difference between red and blue matter here?" and answering with "Because they are different.")

So, you're taking an position that people find ethically problematic and logically inconsistent, and that's the reason why you receive this pushback: people feel motivated to counter what they see as an uncontested "ethical divergence", and you gave them an obvious logical chink to pry a lever into.

What I'm taking away is that you truly believe this, which is so foreign to me that I'm completely mystified. It makes me curious, and also uncomfortable, and for both reasons I wonder: How? Why? However, you're simply re-iterating your position, and I've come no closer to finding out, nor do I think I actually will, because I can't find a way to phrase my questions in a way that would bridge a barrier of understanding between us and make you respond to what I'm asking.

I'm still curious. But in any case, please do enjoy the rest of your weekend.


You don’t have to be smarter than your opponent to beat them in chess. You need to be better at chess, that’s it. Sure you need some degree of intelligence to be good at chess but being better at chess is not an indicator that you are smarter than your opponent. Same goes for computer security or any other intellectual field.

For instance, I’m pretty sure I’m better at computer security than Terence Tao but no way would I say I’m smarter than him.


Semantics. If you have a computer, the hacker has a computer, and you get hacked, the hacker is smarter. For whatever values of better/creative/resourceful you want to attribute to “smarter”.

Why, indeed.

We really need to understand why people who study a subject and dedicate their lives to studying and perfecting their understanding would show a clear preference for something...

Yes, I would like to understand why this is their preference. Aren't you curious? I don't think it's enough to say: these people are experts, so in this issue of style and taste their answer is automatically correct, no more info needed, thank you.

Also, I'd be surprised if ALL "people who study [this] subject and dedicate their lives to studying and perfecting their understanding" would share the same preference.


> their answer is automatically correct,

No, but I'll trust their opinion on building design and urban planning over yours the same way I wouldn't trust you to do brain surgery or landing an airliner. I am a skilled pilot in simulators, but I still wouldn't trust myself to land a real plane.


I thought we were talking about how things look, not the skill that goes into making them look like it. These are sufficiently different things.

Fashion. Taste. Informed by functional and economical requirements, materials, surroundings, urban planning, yes, but in the end, there's also an element of taste and subjective preference that can clump together in periods or zeitgeist forms or whatever you like to call it.

As taste and preference go, you are free to delegate yours to others without question, as you seem to be doing here so passionately. I don't find empty appeals to authority very convincing. But maybe I misunderstand what you're saying.

I'm willing to hold two concepts in my head: my own impression of the appearance of different examples of a certain architectural style (which, like all others, has better and worse ones); and the question why some people who know a lot more than me might see it differently than me. Their reasons and my reasons might both be valid, but mine would be far less interesting. Hence, my question.

Finally: You seem to think that I asked you to trust my opinion, or even to change yours. You might want to look into why you think that, because that's not at all what I did. I asked something entirely different.


https://en.wikipedia.org/wiki/Procrustes

> In Greek mythology, Procrustes [...] was a rogue smith and bandit from Attica who attacked people by stretching them or cutting off their legs, so as to force them to fit the size of an iron bed.

> The word Procrustean is thus used by analogy to describe, for example, situations where an arbitrary standard is used to measure success, while completely disregarding obvious harm that results from the effort.


I don't think jujutsu is proprietary (unless you want to redefine that term). Source is freely available, and it uses Apache License 2.0.

While you're right about the disadvantages of git, pretending that it became ubiquitous because it "became a quasi-religion because Linus made it in a day" is selling short its advantages. If you think about it for even just a little bit, it should be obvious what a simplistic statement that it. Also, git was not the stagnation you make it out to be. Even with its warts, it was a breath of fresh air, not unlike jujutsu is now a breath of fresh air vs git.

I remember working with SVN, and all things considered, git was a vast net improvement. Git took a lot of pain away. It made working with a versioned code base faster and simpler, to the point of enabling much better collaborative software development. There's a reason we got GitHub and not SVNhub. And GitHub was what helped git become so dominant.

Would it have been better if Mercurial had beat out git in the propularity contest? Possibly? There's trade-offs between the two, but Mercurial's easier interface counts for a lot. But if it had won, I'm sure we'd be griping about its shortcomings by now.

So yeah, I'm also happy to see some movement around the ergonomics of version control, but I don't understand the need to disparage the tools that got us where we are. It just seems that you're more bitter than happy, and like you're letting that bitterness cloud your judgment.


The combination jujutsu/piper is proprietary. As I understand it, sapling as released is also not the entire internal system used at Meta.

Git was an improvement over SVN in some aspects, but a monumental regression in others. There are no two ways around that.

Mercurial is better than git in a bunch of ways. It is much more usable because it has way fewer footguns. But it has some of the same shortcomings as git when compared to SVN. I won't call it perfect.

The reason we didn't get svnhub is that some git fanboy nabbed the domain and essentially said "you shall not have it". Joking aside, there was Sourceforge with working SVN support. But I would say that Sourceforge lost market share for a lot of reasons, not all of them technical. Wrapping Windows downloads in adware installers was only one of those many crazy unforced errors.

Am I bitter? Maybe, because I have to use tools that could be so much better. I've experienced better and every time I am forced back to git, it feels a bit painful because I know what we could have instead. If am bitter, it is because of my experience with a wide range of tools.


Well, then I'm sorry. Your issue seems not so much that tools have shortcomings, but rather, that you seem to focus on these shortcomings so much that everything looks like crap. Maybe not in general, but at least in relation to VCSes, it sure seems like you're wearing some brown-tinted glasses, so to speak.

As a point in case, it's certainly interesting to see you completely disregard jujutsu because it happens to also work (optionally!) with a proprietary backend, when its most useful feature is that it makes working with git night-and-day better, nothing proprietary required. This thing could be a ray of light for you, but for some curious reason, you seem to go out of your way to ignore it.

I mean, it's definitely possible that you think to this day that SVN was the bee's knees and its demise in favor of git or mercurial made us all poorer, but that's certainly a rare perspective. In that context, I'm also finding it hard to reconcile your initial statement around the calcification in VCS land, and now it sounds like you would have preferred to stick with SVN instead.

I'm sure you can give me a rationale for it all, but I wonder how much of it will be just picking rotten (or declared-rotten) cherries out of an otherwise tasty pile. If you stack up the present against a rosy-tinted version of the past and some inexistent pie-in-the-sky, it's no surprise it comes up wanting; but that's just a way to make yourself unhappy, really.


What's wrong with stating my opinion when it's relevant to the topic?

I feel like you are somehow irritated by what I said. Are you personally invested in this discussion somehow?

You have a point in calling me out on jujutsu. I haven't spent enough time looking into it because I have been busy with lots of other things. And I haven't seen any forge-like tooling around it, which further reduced this in my personal priorities. I also got the impression that jujutsu by itself is less scalable than the proprietary jujutsu/piper combo.

The other VCS that I should look into more is Lore. But again, time has been a limiting factor for the past year or so.

You know the really funny thing? I talked to many people with similar skills and experiences as mine and we all essentially have very similar issues with the established open source VCSes.

I had a list of missing features here and it's long and it's boring and I deleted it because it's the kind of stuff that tedious to litigate and what's the point? I'm not here to make anyone switch to something else. I really just hope that we can move past git-as-default into a better era. That's all.


I don't want to stop you from providing your opinion, and looking back, I shouldn't have questioned it the way I did.

I didn't consider, after my own experience switching from the time of CVS and then SVN to git, with the substantial liberation of workflow that it brought, that somebody would not have that experience, but maybe even an opposite one instead. To be honest, I still find that hard to imagine. That's silly of me, but here we are. I apologize.

(Edit: I do want to add that I also reacted to the hyperbole in your previous comments in this thread, which honestly did not help your opinion to come across as particularly well-considered, so that colored my impression of your position and my response to it.)

> I really just hope that we can move past git-as-default into a better era. That's all.

Than I can only recommend to give jujutsu a try, with its git backend, as sacrilegious as it might sound to you. It offers a much saner and more consistent approach to version control, and with with its abstraction over different possible backends, it offers a way out without having to overcome the considerable problem of having to replace git _first_. A better backed can come later.

Depending on what exactly your issues with git are, you might like it, and it could allow you to have a small part in moving past git right now.

I'm usually not one to fall for, or advocate for new-ish tooling, but jj is one of the few that convinced me. I started using it exclusively with existing git repos; colleagues are still using git with the same repos and are none the wiser. I haven't looked back.

But that depends on your list of missing features, I suppose. If they don't match, I'd be curious what they are and why they might not have been picked up.


There's -i for interactive, lets you add, patch and reset (unstage).


Where would you draw the line for a sufficiently simple implementation of sufficiently simple requirements? A door knocker? A door?


I don't think there should be a line.

But it should be considered fair to say that some things are over-engineered in relation to others.

It should also be considered ok to call things over-engineered. OP himself did.


Of course you can call things over engineered, but seem to want to include questioning the requirements, specifically also those of the example we're talking about.

Once you start that, you also need to stop somewhere. For example, we could even question the need for a door in the first place. Not saying that we should, but if you want to take over defining other people's requirements, you're putting this on yourself.

So if you don't want somebody else to call you out for over engineering somebody else's requirements, where do you stop?

It's not an enviable position to be in. :)


I am just saying over and over that the over-engineering part itself can come from a "requirement", which seems to be the contentious position here.

Some other people mentioned the doorbell project was over-engineering and I just agreed with them.


I agree that requirements need to be kept in check to avoid over engineering. However, I think it's hard to decide for other people far away what their requirements ought to be.

So I don't agree that you can call mrb's basic wireless doorbell "overengineered" for requirements reasons alone without opening yourself up to the same scrutiny that you're applying to him.


> I agree that requirements need to be kept in check to avoid over engineering

Then we are in agreement!

The person who originally called it "overengineered" wasn't me, it was another user.

I did joke that an electric doorbel "does a similar job" but that was to demonstrate that "similar" is also a judgement call.

I am just saying that lukeify or anyone can call it overengineered from their point of view, similar to how GP called commercial products overengineered.


Gotta keep up with pitch inflation!

https://en.wikipedia.org/wiki/Concert_pitch


Love the pedantry here. I'm currently at: no op code does anything, it's all fancy effects in the hardware that can be described in arbitrary detail, which somehow allows me to cause these letters to appear on your screen.


Insightful and compelling. Tell me another one.


With pleasure.

There was a boy A very strange, enchanted boy They say he wandered very far Very far, over land and sea A little shy and sad of eye But very wise was he.

And then one day A magic day he passed my way And while we spoke of many things Fools and kings This he said to me: "The greatest thing you'll ever learn Is just to love and be loved in return."


But Wikipedia tells you in the first paragraph what it's all about.

A "Pareto front represents the set of solutions where no solution outperforms any other solution in the set at every objective, and every solution not in the set is outperformed by at least one solution in the Pareto front in every objective"


Knowing a definition is not the same as understanding. I know this first hand from interviewing people who at the beginning of the interview can confidently tell me the definition of certain principles in statistics that I ask them about, and then later on in the very same interview when I present to them a real world scenario to analyze, they are completely oblivious that the very concept they explained to me so articulately when we started the interview is the very same concept needed to solve the real world scenario being presented to them.

In general Wikipedia isn't a great way to learn new concepts; it's a good reference when you're already familiar with something and need to brush up on it.


I agree. What I meant to say is that the Wikipedia article tells you upfront where it is going. In TFA, you need to push many little paragraph cards across the screen before you get an idea what you are going to learn.


True, but remember that everyone learns differently. I read the bit you quoted four times, and while I can parse it, the actual understanding doesn't sink in for me. The Mario Kart article (even if much longer to read) helped me actually feel what it means.


Is there a version I can just read as text without having to push every paragraph out of the way with my fingers across an unevenly colored background that shines through?

I get that this form of presentation may be great for many people, but for my brain, it makes it extremely hard to engage with the content.


I'm sorry, this is by design colorful and interactive. If you still want to read about this topic in a less "juicy" way, you can can take a look at this other article: https://hinnefe2.github.io/python/tools/2015/09/21/mario-kar...


Thanks a lot for the link!

I appreciate your work to make this topic accessible in an interactive format. Somehow, in this case, it's too much for me.

I think the ratio of information to interactivity is too low. It's like I have to push around a tiny keyhole to slowly access information. The graphs look fun, but their fancifulness is distracting me.

I don't usually mind interactivity, but I think usually it is embedded in the text, instead of gating it, if that makes sense.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: