Ah, the famous “maybe if I take a step back they’ll appreciate it and not push harder”. Or maybe it’s “if I give the leopard my face maybe it spares my body”.
I’ll let reality speak for itself: look no further than Stingrays and every bit of legal abuse they enabled, where innocent people are spied on in bulk with flimsy excuses. How well did it work out when the protocol was already maximally compatible with laws?
There’s no “minimally compatible”, you either have the privacy technically guaranteed or you don’t. If it’s technically allowed to breach it, it will soon be done as a matter of routine under the guise of “protecting”, “preventing”, and so on.
So in the end we didn’t lose anything, what we did was we gained a short period in which we could all taste that freedom. If we used your proposal nobody would have had even that to begin with.
This logic would have been easier to forgive if it came from youth and inexperience, from someone who never got to know about the endless abuse of surveillance that was inflicted indiscriminately on everyone.
> I promised myself I would never join their ranks.
A wasted opportunity, missed by at least 1 article :).
I do recognize their point that it's been made very hard to catch and prosecute cyber criminals. I think there are ways to improve that that don't destroy the privacy of everyone. But if that's the real goal, why isn't it the big pitch line of the Parent's Decide Act?
The minimally compatible is what existed before. The Snowden leaks showed that the Government, and not just the US government, would abuse the shit out of that for mass surveillance.
So now privacy advocates no longer trust that such a compromise can exist
It’s strange that the author both recognizes that the Government broke the social contract and then says privacy advocates should just keep trusting them in the same article
Every time you step back, the opposing force advances one step and soon you’ll have the same discussion again except from an even weaker position. Do you really think that once the framework is in place everyone will forever be content and not push for the next step?
Like the author, you are advocating for the “small backdoor”. Or like another commenter put it, the prophylactic that only gets you a little pregnant. There’s no such thing.
HN existed 20 years ago...? /s
edit: yes it did, lol
That’s why large tech companies are lobbying in favour of this!
Privacy is being abused by criminals to victimize people at scale. Just because privacy is a moral good doesn't mean you are morally off the hook for enabling criminals.
Governments are so aware of this they're passing sweeping laws against it. This is your new reality -- you can't just bury your head in the sand. The whole point was saying that there could have been a middle ground that protected more of your rights than where you're at now if it weren't for the absolutism.
Turns out that being an absolutist isn't helpful.
It's a mix of what they can do and what they're likely to do. They just have to be able to go back to voters and say they're doing something.
If you think that the fact that they did the wrong thing is an argument for not doing anything, you clearly are blind to politics & history.
And age verification being the wrong solution to the "privacy problem" doesn't remove privacy from lawmakers' crosshairs.
None of these groups will because they profit too much from disrespecting their privacy. The average child would be far safer if they used the Dark Web. I'm not sure why the "richest country on earth" is engaging in zero-sum behavior, but those are the kinds of contradictions such behavior creates.
[1] https://www.pewresearch.org/short-reads/2023/10/18/key-findi...
Parental controls remains the right way to do age gating. It works today and has no privacy impacts.
Then legally require it to be effective and easy-to-use-if-you-take-a-few-minutes-to-read-the-instructions.
See also [0].
There's apparently information that you didn't read contained in the footnote of the comment you replied to.
Based on this layman's reading of the law, [0] California did literally the opposite. They require major OS vendors to require users to enter their birthdate or indicate in some other way their current age, and then require programs and websites to act on that age information. This is entirely different from requiring major OS vendors to allow a "guardian account" to set fairly-fine-grained restrictions on one or more -er- "ward accounts", and then requiring programs and websites to refuse let the "ward account" do the things that those restrictions say that it isn't permitted to do.
"Restrict by age" neither accounts for precocious under-eighteens, nor does it account for vulnerable elderly or otherwise brain/developmentally-damaged adults who need protected. And because "restrict by age" cares very much about your age, and because it's not going to work nearly as well as promised by those pushing it, it will inevitably require scans of both a photo ID and one's face and/or other biometrics.
A "you don't need to know anything about this account other than that these are the things it's not supposed to be able to do" system gives zero shits about the identity of a person, so there's no plausible path for it to gate access behind submission of any identifying documents to any third party.
[0] <https://leginfo.legislature.ca.gov/faces/billTextClient.xhtm...>
[L]egally require[d] ... to be effective and easy-to-use-if-you-take-a-few-minutes-to-read-the-instructions.
Additionally, I expect that -due to kids lying about their ages- within five or ten years, the regs will have "graduated" from self-attestation to ID and biometrics collection. It's likely that other states will require that sort of collection much sooner, causing every US-based company to do that regardless of the existence of less-invasive regs.Like, seriously... if "the kids can lie about their age and there are no consequences for lying" is the bar you want to set, just do the 1990's thing where sites and programs have a "Warning! This might not be suitable for kids!" page/screen that has a checkbox that the kids can check or button that they can press that lets them lie that they're over-seventeen and grants them access.
That being said, age based restrictions isn't a fine grained control over the system as perhaps one would like but that also would be inherently more complicated to think about from a legislative perspective (e.g. how fine grained and how to categorize possible dangers) and user control perspective when it looks like a lot of parents are looking for a blunt generic button that basically goes "this is agreeable with general practices". This seems more or less how real systems are gated.
The other issue is that both present privacy challenges but this just a little more so from a fingerprinting perspective. Presumably you need quite a few bits to completely specify the filter whereas age is only a ~1.58 bit field in the CA model. Not really sure how much this matters when there are so many other signals for fingerprinting and we should probably make fingerprinting from it illegal but just some thought.
> Instead, what we get proposed is a system that cares very much about how old you are, and not one bit about the things that one's guardian understands one needs to be protected from.
Regarding your linked comment, I think it's a bit strange to say that if legislators really did care about child safety they would mandate fine grained controls instead. I'm not sure what additional fine grained factors you may be thinking of precisely, but we already use age as a gate in real life for many things we consider dangerous so it's quite natural for legislators to transpose those. Our laws already very much care about how old you are.
Read [0] and consider the array of specific things that a guardian may wish to protect their ward from. Make sure to make your list cover children of all ages as well as adults with a wide array of cognitive impairment.
> That being said, age based restrictions isn't a fine grained control over the system as perhaps one would like but that also would be inherently more complicated to think about from a legislative perspective...
So? Legislative or regulatory restrictions on human behavior must be as restrictive as required to achieve the stated goal, and not significantly more. The courts are especially concerned about this when it comes to restrictions on speech. If a set of legislators need to sit with something for a quarter or two to understand it well enough to properly regulate it, then that's what they're getting paid to do.
> ...when it looks like a lot of parents are looking for a blunt generic button...
You can have preset lists of categories to block in a system that doesn't care at all what your age is. Surely you know that.
> Presumably, under the law, parents would be the ones to create a child account with a non-editable-by-the-child-account age fields...
The California law has no such requirement. Go read it, it will only take like ten minutes. [1] My summary of it as "the kids can lie about their age and there are no consequences for lying" is not even a little bit unfair.
> Our laws already very much care about how old you are.
The identity-verification systems we're talking about didn't exist twelve months ago. These are new systems being designed in a world in which it's trivial to have a centralized database that contains dossiers of all of everyone's customers everywhere. [2] Nearly all other regs that restrict based only on age were written in a world where that was either impossible, or extremely expensive and time-consuming.
Even if that weren't true, all one needs to do to see how these regs will be actually interpreted by most businesses is to look at all of the companies that are preemptively requiring upload of live video, pictures of one's face, pictures of one's government-issued ID, and/or deep analysis of one's activities with their systems. No US state requires any of that, but it all got slammed in when legislators started talking about doing age-based restriction of Internet services.
Had legislators clearly said "We're going to be designing and enacting laws that require designated guardians to be able to prevent their wards from engaging in guardian-selected categories of activities. We want every guardian to be able to protect their wards, regardless of the age of those wards.", you'd see companies building and deploying very different systems.
[0] <https://news.ycombinator.com/item?id=48911863>
[1] <https://leginfo.legislature.ca.gov/faces/billTextClient.xhtm...>
[2] Am I saying that there exists a centralized database of all of everyone's customers everywhere? Absolutely not.
https://www.pewresearch.org/short-reads/2026/07/01/majority-...
https://x.com/PTBwrites/status/2031529878021923118
https://yougov.com/en-us/daily-results/20250502-1e408-1
https://yougov.com/en-us/daily-results/20250502-1e408-2
> Parental controls remains the right way to do age gating. It works today and has no privacy impacts.
This opinion is not grounded in data and facts. If this was true, we would not be here. But we’re here because parental controls are insufficient, the vast majority of parents are just hanging in there getting their kids to adulthood.
More than 3 million college students are raising kids. Most won’t graduate - https://news.ycombinator.com/item?id=48709130 - June 2026
The real single-parent capital of America - https://news.ycombinator.com/item?id=42867716 - January 2025 ("The places with the most single parents tend to be, to put it bluntly, struggling. The strongest predictors of single parenthood are high poverty rates and high shares of the population receiving government assistance." [There are ~13.6M single parents in the U.S. raising over 21M children. This means single parents head roughly one in three households and approximately 34% of all U.S. children live in a single-parent family.])
Parents Under Pressure: The U.S. Surgeon General's Advisory on the Mental Health & Well-Being of Parents - https://www.hhs.gov/sites/default/files/parents-under-pressu... - 2024
> When stress is severe or prolonged, it can have a deleterious effect; 41% of parents say that most days they are so stressed they cannot function and 48% say that most days their stress is completely overwhelming compared to other adults (20% and 26%, respectively).
> Nearly 70% of parents say parenting is now more difficult than it was 20 years ago, with children’s use of technology and social media as the top two cited reasons.
> Recent data from 2021-2022 indicate that among parents, 23.9% (or 20.3 million) had any mental illness and 5.7% (or 4.8 million) of parents had a serious mental illness.
> Lastly, many other caregivers assume primary caregiving responsibility when parents cannot, thus acting as a critical safety net for children. In recent years, there has been a notable increase in such individuals taking on caregiving responsibilities for children, with approximately 2.4 million children being raised by grandparents, other relatives, or family friends, without their biological parent(s) in the household.
U.S. has world’s highest rate of children living in single-parent households - https://news.ycombinator.com/item?id=37628812 - September 2023 (108 comments)
(fertility rates continue to collapse though, so hopefully this problem continues to decline over time, only time will tell; 40% of annual pregnancies in the US and internationally are unintended, per the Guttmacher Institute and the UN, respectively)
Charted: How American Households Have Changed Over Time (1960-2023) - https://www.visualcapitalist.com/how-american-households-hav... ("A record 58.4% of American households now consist of married or single adults without children. Only 25.3% of American households contain children.")
You know who didn't refuse to get involved? Larry Ellison, Peter Thiel, Mark Zuckerberg. They made suggestions to governments about how to solve this problem, and the best proposed solution was adopted and made the law.
His theory is bunk, there is absolutely no middle ground to be had with the people who want a backdoor. There are no small backdoors.
If we had parental controls that actually worked it would forestall any talk about ID scanning because parents could just enable parental controls.
I don't think it's that encryption was harmful, it's that it wasn't enough, and in a sense I agree with TFA & the Sun Tzu bit: it needed to be complemented by legislation that added decent privacy protections, and it largely wasn't. That was a mistake, I suppose, but the current political situation, esp. in the USA, disfavors privacy regulation getting done, ever. The Democrats are … maybe spiritually for it? … but not terrible effectual at getting it done; Obama's response to Snowden was "meh" at best, and Congresspeople, in particular Feinstein especially, let the DNI walk all over her. The GOP has no interest at all in regulating corporations, at all, ever, so with the House/Senate/POTUS all (R) at the moment, it's going to be until at least Nov before it is possible to even think that these might get addressed, and even that's … generous, and I won't be holding my breath for it to occur.
Stuff like what we saw in another thread today — with LG wantonly installing spyware — and things like Flock would have happened in addition to network intercepts; they are not happening instead of. Corporations and the government will do whatever the People permit them to get away with.
Almost all victimization is being done without end to end encryption. This is not a problem caused by privacy.
Also on Discord and Roblox, they are apparently the biggest platforms for this, but they're not E2EE anyway, they're just hiding it because their executives like what's happening.
It’s only used by them and their buddies and basically only for OTR conversations related to their publicly traded company that would have put them in prison. Totally the “let’s defraud these investors and do industrial espionage” type shit. I also know about a good half dozen other VC-funded E2EE chat apps that are also exactly this.
They do it just to get something they control in app stores that’s also a separate entity. Then they don’t have to answer uncomfortable questions about why such and such is on their phone.
This is some of what regulators are seeing and finding a problem with.
I hope you realize what a poor argument (to lawmakers) that is, especially if your goal is to advocate for privacy.
> In this last Bikeshed in acmqueue, I will ponder the far future of free and open source software (FOSS), hoping to upset so many readers that...
> During the past couple of decades, rampant neoliberalism and “globalism” allowed...
And I’m out. I guess congratulations to the author. Mission accomplished.
But I’m disappointed that the article took a turn towards partisan politics.
Except for shit like Stram Kurs, which nobody really supports or tolerates.
> During the past couple of decades, rampant neoliberalism and “globalism” allowed the U.S. tech industry to capture almost the entire European IT market, including all “social media.” This has recently proved to be a ghastly mistake, and now the EU, along with its member states and companies, are scrambling to claw back their digital sovereignty.
This is not a partisan political statement, it's a factual one. It is simply a statement of fact that neoliberal world markets have permitted hyperscalers to cross national boundaries and provide the same services at scale to governments worldwide, and like, without even going into any U.S. politics at the moment, isn't that... really weird? Like many EU governments had essentially put their ability to function as states in the hands of a foreign actor. That's WILD.
Also, the reason the EU does not have that many tech companies is not global competition; it's that it takes 6 months to hire someone, you cannot fire them ever, and nations tax you based on your unrealized valuation because they don't really believe you should be running things on your own.
It's frankly far more derisive of me and any reader really to say that because "free market" has the word "free" in it that the majority of people will cosign it happily with no further thought. Do you also think the DPRK is a democracy because it says so?
The EU has a large menagerie of businesses, successful and otherwise. If hiring friction and tax policy were the whole story, you'd expect the EU to lag in all capital-intensive industries, not just have a specific gap in hyperscale tech, which is the one sector most directly shaped by network effects and first-mover advantage from a market that let a handful of US firms scale first.
Additionally I'd push back on the premise that "doesn't produce hyperscalers" is even a mark against a system in the first place. They're what you get after competition has mostly finished collapsing into a handful of winners who then run the supposedly free market. Funny how the same people who'll lecture you for an hour about the sacred competitive forces of the free market go quiet the second vertical integration and monopoly-adjacent scale start choking those forces out.
Wrong
It is used pejorativly but that does not make it devoid of meaning
It refers to the social policies instituted in the 1980s that (attempted to) inserted competition into every facet of human relationships
It was instituted by liberals
It was new (and a dreadful policy that has lead to the discrediting of liberalism generally)
Hence "neo-liberal
You are welcome
The people pushing for the destruction of privacy and attested software integrity ARE the tech bros. I'm sure there are people here that will vehemently disagree with me, but we see the biggest tech companies pushing for age verification and we see founders and rich folk gleefully giving up their earlier pro-privacy stances in favor of supporting locking down identity. They're building up their moat in real time because not only does it let them kill that pesky FOSS, but also it means they can legally gather even more data from individuals in question.
It also goes hand-in-hand with the increasingly authoritarian bent a lot of those same people have taken and these resources will absolutely be used to crack down on minorities and things they don't like.
I think your head would have to be firmly planted deep underground to somehow not connect the two dots. As another poster here said, they're literally lobbying for these age verification laws because it benefits them.
I vehemently disagree, because this is not what is happening.
The Age verification domino toppled first in Australia, and then other governments found the example was good enough and followed suit.
The issue that HN conversations miss, is that the dominoes were set up over years. People have constantly been trying to deal with the many, many issues thrown up by social media. Issues ranging from the Myanmar genocide, content moderation, fraud, child safety, sextortion, to name just a random grab bag of issues.
Voters, governments, NGOs, victims and even tech firms, have been trying to figure out what to do for a decade+.
Voters, and non-tech-literate society used to complain about the status quo. The political will to change it reached critical mass, and is now in progress.
Also the fact they call it “age verification” when they clearly build an identity verification and we just accept their language is crazy.
There is nothing of substance here. You don't like AI, I get. But it still exists and pretending that no-one finds it useful is utterly foolish.
Edit: I overuse the word utterly. Nice to identify one of my tells.
Regulations for age restriction are understandable. A lot of modern technology is harming kids (and I don't mean dirty videos, social media seems to be much more harmful).
A sensible regulator would leave some responsibility to the parents, but require restrictions for consumer devices (smartphones, laptops). Maybe even enable age restrictions by default, block replacing the OS or the firmware, and only allow it once the age was confirmed.
I don't see a point of including all kind of OS or software into this regulation. Just the ones that are preinstalled on consumer devices, and commercially distributed to consumers. Once the age of the user was confirmed, the devices should be able to become as open as we know them now.
(Speaking as a parent of three) why can't we just leave all responsibility to the parents? In our experience in the offline world it seems this applies!
I speak as someone who's taken each of my three children - for two of them, multiple times - to the emergency room to be treated for broken bones incurred in the course of Real Life[tm].
Yes, they play contact sports.
Yes, we use Family Link with pretty restrictive settings.
Despite the series of broken bones, I'm still in favour of kids playing sports and still dubious about the effect of screen time on young minds...
It would be illegal under the currently proposed /implemented laws and also open up social media to liability, which wouldn’t be true for other products like Alcohol or fire arms that require minimum age to buy but not give to children
Also give it to your kids too often and the state can step in.
Defense in depth
> why can't we just leave all responsibility to the parents? In our experience in the offline world it seems this applies!
They can't be tracked, as long as the devices are in randomly sorted identical boxes. Of course someone can buy a device and give it to a kid, but that's already possible with alcohol (and legal if it's their kid).
I bought a beer yesterday and shared it with our 16 year-old, and I shared some wine with him this evening.
How does that not come under "parental responsibility"?
because we don't live in a 15th century peasant village. The average adult reads at a 7th grade level, 20% of adults are considered functionally illiterate, most adults can't navigate digital spaces, privacy and social media themselves or take on trillion dollar companies.
This also hasn't applied in the offline world since idk, Kant and Hegel, every modern state recognizes that children are persons and citizens in development, not private possessions. If your children have broken bones you can't explain or your parenting is considered to threaten the welfare of your child you can be pretty sure you'll have the authorities at your door quickly, and countries like France have given children the right to sue their parents in case they breach their digital privacy. So called 'sharenting' laws exist because it's not guaranteed that parents are even respecting the privacy of their own children.
I don't mean to be combative about this but
1) do you have children and 2) if yes, how many times have you taken your child to hospital with a broken bone
I have (unfortunately) got a certain amount of experience with this, and I'm not sure it works the way the uninitiated may think it does.
yes one and never but it's not clear to me what our personal life has to do with the legal fact that the welfare of our children is in fact not solely in our hands and is subject to limits we can run foul of
Then I'm sure that you appreciate that there are both legal and informal checks in place ensuring that you can take responsibility for your children in the offline world. For example: I would be surprised if your children were able to play organized sports without your permission. Failing to ask for permission would deny you the responsibility of protecting your child as you see fit.
Signed permissions are needed for "organized sport", where there are other adults or companies that can be held liable in case something relatively usual happens (like broken bones in contact sports, but also pulled or ruptured tendons/muscles in non-contact sports...).
So the challenge is: how do we ensure kids enough freedom to do the things which they need to explore themselves, while ensuring no life altering harm of high chance (death/disability/going to jail...) comes to them or they instill on others — and do not have to have them tracked completely throughout their lives.
The issue isn’t the parents who can’t imagine bad parenting.
How do I propose the government know if I have kids? I'm pretty sure they already know that I don't?
So why should I have to prove I don't have kids when the government can know I'm not on any of those lists?
> A sensible regulator would leave some responsibility to the parents, but require restrictions for consumer devices (smartphones, laptops). Maybe even enable age restrictions by default, block replacing the OS or the firmware, and only allow it once the age was confirmed.
If you think that this statement is too broad for this thread, I don't understand why you only have issue with my direct response to it. It seems like your issue is with the parent comment I replied to for not being on-topic enough.
And this wouldn't affect Linux or FOSS: on a child's device their parent installs either a proprietary OS or a FOSS with parental controls, but again, on your device you install whatever you want.
> Maybe even enable age restrictions by default, block replacing the OS or the firmware, and only allow it once the age was confirmed.
Having an extra hurdle before installing Linux would be an awful secondary effect for this type of regulation independent of whether the check itself is already objectionable (which I always obviously think it is, although obviously plenty of people also don't)
If that's all we want then that's trivial -- just make certain phones that don't have access to social media, or have whatever limitations enforced. And kids only get those phones. I don't think anybody's addicted to desktop social media.
This gets us the privacy and the protection at once.
However society doesn’t have the stomach for that (yet).
Also, as the article correctly identified, society is gearing up to deal with other types of crime online.
The stuff I've seen on this doesn't look terribly convincing. It seems to mostly be along the same lines as saying that since some people get bullied or hang out with a bad crowd, socializing in general is harmful.
Imagine if such an approach was taken to, for example, food safety? Instead of closing down a restaurant that has poor hygiene, you'd be instead horce the restaurant to hire a private security contractor to check people's IDs to verify that they are old enough to consent to getting a foodborne illness. That's an absurd approach.
But it extends to many other common items. Kitchen knifes, cars, lawn mowers, ...
It won't work against a determined teen (too many unlocked devices out there), but it doesn't have to work perfectly to change the culture that most kids have to deal with.
The reason it’s not done “this way” or “that way” even when those are objectively better ways to achieve the stated goal, but rather in an unexplainable way broader way is because the goal is broader that that and age verification is just the tip of the spear. The rest of it is laying the groundwork for a framework to control the freedom on the internet by linking identity to speech and action.
Look at what solution is implemented to decide what problem is it supposed to fix, otherwise you’re just looking at the smoke and mirrors.
Not that every state and country is on board with this, but it’s getting a lot harder to maintain the pressure to keep these initiatives down. Every time they get pushed one step forward it’s that much harder to regain that ground.
There are a lot of different people in different countries pushing for age verification and I imagine they wouldn't all have the same motives.
But the current legislation is stupid. Treating toddlers like hackers, and forcing every website to deanonymize users. It is so backwards, that it's hard to believe it's not done on purpose as the first step to ban anonymity and strictly control all online access. In the UK of course they're already talking about having a VPN ban, because the hacker toddlers are learning how to mask their IP addresses.
Same with GitHub and similar, we have CLAs for a while now for licensing. But I see project maintainers are frustrated with AI generated slop PRs and bad actor contributions. The ecosystem will be closing. You will be able to read code, but forget creating PR without some ID verification (because this is for kids or against terrorism).
This is not connected to age restrictions. It might've been used as an excuse.
His argument is not that they aren't going to find any bugs, but rather that at some point those bugs will be fixed. At which point we will continue on as usual.
This part is the load bearing claim. Why would you continue on as usual? I'm using LLM's everyday on code reviews and they still catch bugs.
I'm treading lightly after you said "did you read it" to OP, I do believe we both understand that argument isn't nearly air-tight. (i.e. it implies either humans get so good at code that bug-introduction-rate falls percipitously, or, LLMs are so awesome they write all of our code bug-free. Neither of which jives with the thesis, that LLM code review is a nothingburger long term)
The best steelman we could say is "he meant 50% of all existing bugs in all currently existing code", which is still incompatible with a time-bound on their usefulness, unless we expect the rate of new code to fall percipitously.
The steelman I'm using, is they're speaking both loosely and strongly and intend us to understand these are strong opinions, held loosely, and they care for us enough to share.
If the argument were instead that it will cease to find new classes of vulnerabilities and bugs, that may very well be true, because that is a question of the limitations of programming and at a lower level computer architecture, but that's not the argument the author made.
> The only real question for me is: Are the LLM-code-review tools economically viable outside the bubble?
Now that's quite a prediction.
Also, from what I recall, Anthropic and OpenAI subsidize their prices by ~40x?
That said, given the prices*quality of recently released open models, I think the cost issue is moot.
Ed Zitron said this?
> Just on that repeated experience, I suspect we have already seen more than half of the “worst software bugs found with LLM-tools” list.
On the other hand, it’s not clear to me how you think that it already is “in a very big way”.
Do yourself a favor and read this, a few times, and take a moment to actually try and see what the author's getting at.
The trouble is, compromise isn't really a tenable option with encryption. Either you make a draconian law that forces all electronic devices to run approved software only, or people will have access to easy encrypted messaging. There's really no middle ground, because where the smallest weakening of encryption affects everyone's privacy, only outlawing encryption completely will get it out of the hands of criminals. The cat's out of the bag.
Author here and in earlier writing seems to make the argument that a little compromise would make the courts less unhappy, but I think that's misattributing motivation. These laws actually are originated by big tech, who think they will be shielded from liability and make more money off of selling your data. https://github.com/upper-up/meta-lobbying-and-other-findings
That would outlaw programming. It's just not feasible at all, anyone with any kind of tech literacy understands that encryption is here to stay. It's also necessary for the web to function at all for the things we use it for, such as banking.
There is no way to prevent people from communicating in secret. Even if they did strictly control digital communication people would just communicate some other way.
I think the author would love to see more enlightened policy, but he doesn’t believe it’s going to happen. Hence the closer: “ Please make my predictions come out wrong.“
Also, these laws don’t simply originate from big tech. That particularly OSINT study was done by someone who wrote their own interpretation of the data points they uncovered, to create a narrative that was comforting to them.
Big tech has been aware that a reckoning was coming, because they and safety advocates have been fighting for years now. The fact that there was no actual teeth or ability to enforce e regulation, and that harms were evolving beyond reason and imagination was general knowledge.
Meta is lobbying to influence the shape of the manacles they know are coming.
This is on purpose.
This is the intent.
Well, mission accomplished, reaction provoked. I'm not going to read this multiple times. I'm going to fire off this comment and remove it from my brain forever.
Talking isn't doing, just like word generation isn't an outcome.
At least, this is what I have come up with because this blog is mostly incoherent blabbering.
Which model is this author talking about? Which pocket-sized devices? Where can I get them? No one is using Gemma 4 to find cybersecurity issues.
Edit: there are a lot of sentences that I can't distinguish from sarcasm in this article. I guess I read it too seriously.
A large model like Kimi 3 should be something like, 1-2TB? That’s a pocket size hard drive
He's been a strong privacy and FOSS advocate for decades and has more credibility on both of these topics than nearly anyone on this board.
He also has an account and comments frequently. phkamp. I suggest reading some of his comments before making judgment.
So many kneejerk and nuance-less opinions. Absolutely hilarious that people are thinking the guy who wrote MD5crypt and BSD Jails is anti-privacy.
Also eye opening watching how many people are getting frothing-at-the-mouth mad seeing somebody with that pedigree coming to different conclusions than they do.
That's the difference he's pointing out in your linked article. There's nothing "anti-E2E" about that piece that he wrote. He says explicitly that people can have whatever standard of encryption they're comfortable with in the post. His piece is entirely about letting all parties to communication decide their limits on privacy. It's a solution that lets people maintain their rights, lets businesses stay compliant with the law and also meets with political reality.
The staunch privacy advocates acting like privacy has to be all or none are right but not in the way they believe. If you continue to build privacy technology where the only option is total privacy then don't be surprised when nation states take all of your privacy away. There's no privacy in prison.
Also you can be totally justified in working on such tools, but western liberal governments will still imprison you for it. Hell, a guy sat in jail for four years just for ignoring a court order to unlock his phone (United States v. Rawls). He won the appeal but still sat in prison and judges can do that. That's kinda the point of the article.
phk is doing nothing more than telling people the temperature of the room outside of their bubble.
depends on the age but.. they've probably discovered all kinds of shit already or heard about it from others
After all, there is a reason why "some random women will send you unsolicited vag pics just because you're a buy"-talk doesn't need to happen with boys.
There will never be a world populated by humans in which you do not need to have numerous talks with your children about the nature of humans, especially humans they do not know and cannot trust, and about the technology those other humans know how to use. Saying you are forced to do so on account of some particular new technology is like saying you are forced to provision food for yourself on account of this newfangled capitalist system... As if needing to provision food for oneself were not a state of affairs dating back to the dawn of cellular life. And as if the uglier parts of human nature emerge from the smartphone and do not in fact date back to the dawn of humanity as a species.
Demanding everyone on the Internet show their papers to the government so that the author can hand their teenage daughter a free, always-networked pocket computer plus microphone and video camera without having to think about any related risks is an attitude repugnant for its laziness, its entitlement, its delusion, and most of all its contempt for the freedoms of others.
But the problem is, those same forces you're describing are employed to fool people into believing the fictions that support these regressive movements. The real danger we should be focusing on is "won't someone think of the impressionable adults".
When humans come to these deeply flawed conclusions about computers, networks, and governments, it's a new case of an old problem. Maybe the old problem is screaming toward us at a new velocity and intensity. But I think we can improve the existing humane cultural solution with new stories for our children, rather than surrendering to the supposed inevitability of government mandates to lock down and restrict general purpose computing to only well identified citizens in good standing. The restriction to "in good standing" almost inevitablty follows from the "well identified."
That seems undeniable.
After all, look at religions. The major ones have survived, and perpetuated their positions - including many glaringly counterfactual beliefs! - for thousands of years.
If we want to communicate to the majority of humanity, fables seem like the only way.
But the fables will need to be assembled into a coherent ideology, with a motivation for following it.
Whenever I have discussions like this I'm reminded of the L. Ron Hubbard quote: "You don't get rich writing science fiction. If you want to get rich, you start a religion."
It's a bit surprising that more religions haven't started with the motivation of making life better for everyone, instead of getting rich. Another strike against human nature.
I fail do imagine what kind of world is he implying.
> So, it is not obvious to me who will be training new iterations of these models once the current bubble explodes, in particular if the returns are diminishing the way I have experienced.
It looks like he has no clue on how market equilibriums work. He really seems to think LLM's will just like.. stop existing.
So in their world, people would suddenly realise that AI is actually not that economic and we can't have Opus 4.8 quality models just with updated knowledge cutoff perpetually. So in his future, things won't just stall, they will literally go back.
He's really putting his emotional weight on this particular kind of future.
Either that or he's making nebulous emotional claims - its his blog so he can do it.
* https://svnweb.freebsd.org/base/head/lib/libcrypt/crypt.c?re...
* https://github.com/freebsd/freebsd-src/commit/3b2b7f71deba2a...
What qualifications does phk have that are relevant to the current subject?
But I believe that's misplaced, because she will be vulnerable as an adult, and there was never a way to produce encryption which was not easy to turn to non-crackable encryption for those not wanting to play along with national laws.
I first came across it in 1995/1996: Wow, what a magical tool for backend web stuff! I used it for everything.
[0] https://en.wikipedia.org/wiki/Floyd%E2%80%93Rivest_algorithm
TIL: Phil Zimmermann was a "tech bro" and had a time machine.
Unfortunately, no, you can't have a prophilactic that just makes you a little bit pregnant. We used to know this.
Oh, it’s not a slippery slope. It’s a single step: age verification IS identity verification, and it abolishes anonymous publishing on the internet, allowing on day one for violent retaliation against political speech.
If you think that authoritarian governments won’t be abusing this instantly, you are sorely ignorant of history.
> In comparison, tech sisters advocating for an absolute right to privacy seem to be a very rare, and maybe mythical, species.
Ever heard of Meredith Whittaker?
> We could have designed our protocols to be minimally compatible with “a nation of laws,” but the tech bros insisted that compromise was treason, and, as a result, we will lose more privacy than necessary.
This has to be a joke. There's private, and there's not private. There is nothing in between. This is not about tech bros. This is about guiding principles, about personal liberty, and about freedom from tyranny.
> It may not quite be a law of nature, but my personal guess is that the opportunities for anonymity on the Internet will shrink until mothers no longer are forced to have “the talk” when their daughters get their first mobile phone.
In addition to "the talk" guess what else they won't be forced (or allowed) to talk about? Political dissent.
This chunk of the article is both sexist and defeatist. Now to read the rest.
The fact that you name one makes her very rare indeed.
- Eva Galperin, Director of Cybersecurity at the EFF
- Runa Sandvik, formerly of Tor Project
- Yan Zhu, EFF Fellow and CISO at Brave
And many, many more.
It rankled me more than a bit that the author apparently looked around his bubble in Denmark and the FOSS community, saw no "tech sister" privacy advocates, and decided to paint with the widest brush possible and assume there are none anywhere.
"tech bros" in context of the article is pretty much referring to builders of software. The tech sisters who have built significant projects are indeed mythically rare.
Names like Radia Perlman might be a better choice.
Also, I think the intended meaning of "tech bros" in the article is more nuanced. Charitably: naive, sophomorically idealistic SV tech entrepreneurs who rode the "information wants to be free" wave to a world where WhatsApp & FB Messenger are E2EE by default. Uncharitably: anyone not in author's idealogical tribe, particularly ideologically impure programmers who have turned to entrepreneurism. And Americans.
Good to know you don't think Yan or Runa's technical work is significant, though.
The advocating for privacy is the cherry on top. And I never said their work was insignificant. It’s just not foundational — not something I’ve built my own career on the back of — and the primary association that you would have with any of them is going to be advocacy.
Radia is also absolutely a privacy advocate and literally wrote the book (as usual) on the intersection between Network Security and Privacy…
Maybe she would been better served spending all her time building a Twitter following and working on press releases.
Care to amend your statement? I don't see any qualification about building software there.
Face it, the author was just searching for another reason to be mad at men in the software realm.
The point he’s trying to make, as I understand it, is that states adapt. They don’t just throw up their hands and say “guess we can’t do anything about that encrypted traffic.”
The response to distributed kinetic kill capability in the US, for example, is for police to become more militarized and treat every encounter as a potentially lethal one.
> There's private, and there's not private. There is nothing in between
It’s not an argument about privacy per se, it’s highlighting that the stronger the protections against state surveillance and intervention, the stronger the state becomes. By taking an absolutionist stance, we push our institutions to towards the same in response.
I’m not making an argument or against encryption or privacy, just pointing out the systemic effects.
Other people understand that picking a fight with someone will result in a fight.
One of the things they did is they investigated metadata: you know, witnesses who saw what people walked around? Today we have way more of such data, readily available for them, plus ubiquitous CCTV and the like. That's not enough, apparently? Also, the police used to employ informants among the criminals themselves, and even implant the cover agents. Apparently, this nowadays is too expensive/bothersome, compared to running a global search for the keywords in the text messages and the transcripts of all voice messages sent in the country during the last month.
So what the heck are you on about? Content of conversations, letters and phone calls was critical to many investigations - including famous ones like WaterGate and bringing down Al Capone.
Again, if you decide to attack the government's ability to do their work, expect a pushback. This isn't hard.
yeah - once regulators come into play - the private ecosystems take over. discord is already a precursor to this.
the era of mass public social networks will come to the end. next it will be just private networks of individuals. likely the won't interact.
how the dynamics play out - I don't know - but if you study history - you will know what behaviors will happen.
> the era of mass public social networks will come to the end.
its just my unsubstantiated guess, but i feel like this is the end-goal of these age-verification laws...but if that were true, what i don't understand is why don't they just go after the business model itself legal-wise instead of indirectly with age-verification...
I'm sure "child friendly content" is part of their calculations, and I'm sure they'll try to interpret the rules in a way that maximizes their profit.
Of course, I am not sure why anyone trusts the global elite after JE. Telling any system the age of a user could be more harmful to that user than the supposed harm of the software itself.
Decisions that are reversible should just go with the instinctive answer of whoever volunteers to work on it.
I've been in many meeting rooms where, because of the number and caliber of people in the room, we've blown $5000 worth of combined salary arguing about basically nothing. I've been in a few where that number was well over $10k.
If you're going to assign a relatively medium talent engineer to solve a problem, it's cheaper to let them solve it twice, maybe even three times, than it is to try to figure out what the right solution is before touching a keyboard. It helps them grow to give them that autonomy, and more importantly training your team out of reflexively reaching for optimization for every single feature saves gobs of money over time.
The interface for a piece of code matters to everyone. The internal implementation details mostly matter to the bus number on that code. If they're happy with it, that matters a lot. That can be overridden by the consequences of that design, but I've seen a couple cases where the bus number for a module wanted a solution with fewer consequences but the group wisdom wanted something flashier but also more brittle.
Motorola will tell you that they invented Six Sigma and Welch copied it. They also made Digital Six Sigma and that community was a cult.
While we are griping about Amazon, my main complaints are about the fulfillment centers/working conditions, the anti-union activity, building their own versions of products that sell well on their platform, and the penalizing of companies that price higher on-amazon than off-amazon.
I worked at a large, publicly-traded multinational where decades prior and they were still just a 4 man startup they decided the database server and all timestamps should be in the local timezone.
They are still using EST today even when they have global sharding of their customers/databases between US, EU, LATAM, SEA...
--- you're also assuming that the product roadmap will afford your engineers any time to build it the second, third, fourth, etc. time.
The key to reversing a decision is getting over Sunk Cost, to start thinking of some code as scaffolding. Scaffolding allows you to get on to other work and then remove it after, because it's either not needed or the 'real' solution has been installed. People get defensive when you propose to rip out their code. Hey that code made us $250k at a time when we were about to miss payroll. Yes. It did. Thank you for your service. But now it's costing us $30k a month and that shit needs to go.
Getting people to figure out that if a decision is important, making it later is actually the sane thing to do, is a challenge. Because many people's intuition is that we should put energy into this now while it's fresh and we have abundant energy. We can 'solve' it and not have it dangling over our heads. But we don't know the right answer yet. We don't know the strength of our tools or the expertise of our coworkers.
The product roadmap is now and has ever been complete bullshit. Refactoring teaches that you amortize rework across all new stories. That's just how it goes.
(And everything should be in GMT unless you can literally point me to a several hundred page treatise on why another time zone is the correct one. Yeah I've worked west coast places that got bought by NY or Chicago companies and it's a clusterfuck if you both didn't use GMT)
Thank you for the added detail.
> The product roadmap is now and has ever been complete bullshit. Refactoring teaches that you amortize rework across all new stories. That's just how it goes.
Also agree, but teams use sprints and "the roadmap" as a way to say no to fixing bottlenecks they've created for other teams and don't want to take the time and effort to resolve.
(1) We're a small startup/new product team/etc, let's just build the MVP and keep everything simple!
(2) Now we're not small anymore and suddenly have all kinds of nonfunctional requirements we never imagined before! But our simple architecture from before is making everything a pain now!
The natural instinct is then to compromise on the "simpleness" of the first prototype and already try to anticipate all the scaling and nonfunctional requirements that might come later - but that rarely seems to work, as you can't really how (and if) the project will grow.
Seems to me, the real question here is why those teams are still using the "MVP" code even after being well inside the "scale up" phase. Shouldn't this be the point where you gradually migrate to a codebase that is more manageable at scale?
This is a form of Second System Effect Brooks wrote about in 1975.
https://en.wikipedia.org/wiki/Second-system_effect?wprov=sft...
In another reply I already mentioned a flavor of Sunk Cost, which is resistance to any change to the code that 'made us successful' because they consider they have already won and taking it away now is some sort of revisionist history effort instead of just Progress. Hofstadter's Law, which tells you we still have plenty of time, despite three initiatives already having finished long past the point of maximum tolerable pain already.
But more damningly, I have worked with a lot of people who want to skip from Make it Work straight to Make it Fast without Making it Right in the middle. Those are the people who, among other things, reach for caching too early, and then declare the war for cost reductions over before they've even started, because there are no perf analysis tools that can see past and around the caching logic to find the issues that caching either didn't fix or made much much worse.
I'm not advocating for making hot decisions at every point along the way. I'm advocating for people having enough experience and foresight to understand which 20% of the code flow is Architecture from which is just feature factory work and making sure that 20% gets 80% of the design thinking and timely preventative maintenance.
On a couple projects I've just done all that myself. But it is a quick road to being a bottleneck and then to burnout. You have to aggressively recruit people to be bus numbers on all of those things. This is part of why I do so much mentoring.
This is true until you're at a company that is a feature factory and nearly exclusively hires out of universities and struggles to work industry hires into their culture. And these tend to make up a glut of the companies a rung or two below the FAANGs/MANGO.
Because for maintenance there is a different team and budget. Same goes about the meetings. Recent example: it's okay to blow $1000 in man-hours to discuss and reject an increase of the compute capacity of my virtual workstation. I bet the cost associated with request was ~$25 of increase to the monthly bill. But it is from the other budget, so it was refused.
Except for "all of the original team left and we're just here to keep the lights on."
I think it's important to distinguish between situations where the business intentionally made this decision from ones where it was forced upon them. Because the delusion of thinking we can still go on after we scared off all of the people who made this thing leads to a very different dynamic.
This is often because no thought was put into making decisions reversible. Version control, CI/CD, virtualization for example can make it easier to reverse decisions and make it faster and easier to replace bad designs.
Bike shedding means no decision is made. That is the worst possible outcome as it provides absolutely zero value. Even a wrong decision provides at least some value even if it fails horribly. Maybe we paint the shed black and it burns down due to excessive heat, but it’s a bike shed so who actually cares if we need to rebuild the entire thing and paint it white this time.
And when it comes to bike shedding, getting it “wrong” is by definition already low stakes. It just doesn’t matter a whole lot.
Even the timezone example isn’t really that material IMO. Sure, it’s an extra annoyance to normalize timestamps to locale in every app/debugging query. But in the end it’s just not that big of a deal.
Worse would have been that early team arguing about it for 6mo without implementing anything. Then no one would be employed currently to curse those early developers to begin with.
Often times the only wrong decision is not making a decision. Very rarely are there decisions to be made that are not overtly obvious which are actually material. These exceedingly rare situations are where the winners from losers get sorted out - but that sort of decision in my experience so far happen a handful of times during an entire career.
As I moved up the ladder in my life I’ve often found my job is to basically flip a coin when a decision choice is presented to me. Very rarely is the topic worth me spending any material amount of mental energy on.
And "bike shedding" is now a term that people hyperbolically apply to any discussion of something the labelling-participant doesn't really care about. A lot of times doing nothing is actually the best business outcome. Waiting until you have more, better information is great.
Lots of stakeholders ask for things that they think matter and then realize two weeks later doesn't and a ton of man hours have already been spent trying to build those skateboards as fast as possible.
> Even the timezone example isn’t really that material IMO. Sure, it’s an extra annoyance to normalize timestamps to locale in every app/debugging query. But in the end it’s just not that big of a deal.
Oh god are you underestimating the long term impact of data not being stored in UTC. For one, it will be a perfectly reasonable thing that your engineers forget this fact and build new systems in UTC, because that's the reasonable thing to do. Also as the years go on your company will make acquisitions of other companies and whatever timezones their data is stored in (hopefully UTC but obviously not always). To properly integrate this data you have to determine for every timestamp whether there was Daylight Savings Time happening at the time on every single object. You also have to figure out all kinds of edge cases around leap seconds.
Otherwise you have a ton of data that's out of chronology. Pity you if that's a thing that matters to you (it almost certainly does).
Also maybe you're lucky enough to be in a position to modify timestamps of all of your objects in all your datastores without significant engineering effort and coordination...but probably not. Obviously the reason the company I mentioned hasn't done it is because they're in that position...
But say you don't want to "fix it" and just want to do this "on every query"...now this process above is something you have to do across maybe thousands of services for potentially every request...
No big deal, he says...
Once you get to the point of bolting on random systems that need to talk in whatever time zones is when you bite the bullet and change it. Yes, that is expensive.
The point I’m making is that if you spend a week dicking around with two junior devs while in your startup phase arguing about EST vs UTC you lose by default. Would much rather have my imaginary employee just choose EST in 14 seconds and move on at that stage. And I have dealt with systems that have done exactly this.
When it becomes a problem I can afford to fix it. Talking about it for more than 5 minutes at the bootstrap company stage is the definition of bike shedding to me. If those are discussions you are having in your weekly dev meetings you have already lost.
This will obviously depend on exactly what you are developing. Payment systems? Probably way more important to get this right vs. some social media app.
The ironic part to me is that this comment thread is basically bike shedding itself! Timestamps are an age old nerd snipe.
No, no, and no.
It causes unforced errors which damage your relationship with customers.
Burnout is a combination of wear and tear and lack of impact. Having giant footguns laying about facilitates the former. And I’ve been in arguments where people disagreed about time zone information and that is not good for interpersonal relationships. It’s not about efficiency it’s about turnover.
It's that important decisions were either not made or got insufficient scrutiny that's the problem. So aggressively shutting down bike shedding that is actually bike shedding by picking a solution and moving on or tabling the discussion to let a team of 2 solve it offline is what you're after.
Sometimes though, bike shedding can be a delay tactic. We have a decision we are not ready to make that someone is forcing a vote on, and there's a silent conspiracy to derail the conversation to avoid the vote for one more meeting.
And then there's people learning not to be responsible for anything, either as a career choice or due to previous trauma at this business. So they are asking for too much input so any consequences are not their fault alone. As you say, being a coin flipper in such situations becomes its own soft power. I've worked at a couple places where a handful of people clearly followed my advice solely because they knew I'd say it was my fault if things went wrong. They just wanted a Decider and I sounded like one so they did things the way I wanted them done. Their motivation was to avoid having to deal with being yelled at. I did my yelling in private, instead of turning it into an opportunity for public humiliation.
Only a couple? This is some peoples entire job, we can refer to them as "enterprise architecture".
Lived experience is a decade ago, and you once saw Kafka solve someone's queuing problem so now everyone's api interface has to run over Kafka. Even synchronous ones.
Often people are smart enough to not ask questions they don't want the answer to. If the three people trusted to handle a problem all are in agreement as to how, then the peanut gallery may just be confounding issues in order to pad resumes or to feel important and involved.
Right now I'm in the process of leaving a company where this happened over and over again. The company's product and design aspects were always neglected in this specific way: whenever a problem was discovered its solution was assigned to whoever would write the code to solve it. That's it. The QA would be notified a week or two before the release and after the solution was "finished". The QA would then not be allowed to even comment on the overall design, only the superficial bug reports were allowed to go through.
Needless to say the product's code-base is a dumpster. The morale is low because it's a daunting task to deal with this dumpster on a daily basis. Now, even if you wanted to, you wouldn't have a budget to fix the previous design mistakes because of the layers of more mistakes that were added on top of them due to the low morale and lack of budget / lack of procedure for making better design decisions. The only thing that keeps the product afloat is its uniqueness in a rather niche field and the backing of a large company that acquired it, but doesn't really depend on it and has no time for a thorough audit.
* A report comes from the field (to the support team) that something is broken (or highly desired by the customer).
* The support team assigns the ticket to the lead engineer.
* The lead engineer writes the code and after a quick battle with CI pushes it all the way to the customer in need.
* Since it's the lead engineer, he has the authority to merge PRs w/o consulting anyone, which is what he does. You just pull the changes and marvel at them, or at the sunrise, whichever you like best. The "urgency" is used as a justification to skip the due process.
Now, when AI came into play, two horrible things were added into the mix:
* AI audit and code review. The audit is a 50/50 chance between finding a real problem vs misunderstanding of the purpose of the code or the context in which it is executed. The AI will also come up with a solution that is either completely wrong, unnecessary or touching too many things for a human to track. Code review acts in a similar way, except, technically it fills the role of a human reviewing the code, so it gives a sense of false security to anyone making changes.
* AI generating code that is hard for humans to follow. First and most obvious problem is the volume. In minutes AI generates changes that will take months of effort to review. But this is only the beginning of the problem. When reading code written by humans, another human builds a model of the author's approach, ability, intention and permissions. When it comes to AI, these... let's call them "dimensions" are all over the place. The generated code you read may seem very plausible for a while until you stumble into a crucial functionality that completely invalidates everything you've learned about the change so far. The change may make unnecessary segues into the territory it was never meant to touch.
So, even when there are code reviews, they now miss a lot more than they used to when only humans were writing code.
Also, and this is a pathologically bad, but a very common practice: the reviewer's name is missing from the record. You run git-blame and only see the author, not the reviewer. When things go down, the author takes the heat and the reviewer is nowhere to be found. Subsequently, reviewers don't feel like they need to care as much about the outcomes.
Oh, and one more thing. To be effective at reviewing anything you'd want to try things... as in to test them. Perhaps come up with some idea about what things must happen and what things absolutely must not. But where do you find those? Usually... in a design document, s.a. a PRD, but in the case where that design (allegedly) was solely in the head of the person writing the code, how do you even know if the behavior you conjecture the code has (because there are no tests) is the desired one?
On the first project I had with routine code reviews I learned to wait for one or two others to file their reviews and then I would catch everything they missed.
It was an app with too many interactive components on top few pages so perf issues and footguns were both a priority. That generates a lot more comments on CRS. There were two of us doing all of that work and the other had English as a second language so he tended to point out one or two issues and let the rest slide.
This is what usually happens when you confuse the decisions that mattered from the ones that didn't. It's like back before 'just use a linter' was the solution to code formatting. You'd start a project, you'd have the 'code style meeting' and everyone would bash themselves into the rocks of whitespace and bracket placement, and never get to things like code organization, structure, and naming of things.
So then you end up with code that uses the same noun in three places to mean 3 different things and uses it as a verb in a fourth.
You only get so many opportunities to really change the direction the boat is steering and you can wear out your welcome trying to exceed it. If you get some things right they'll let you do a few more.
The thing is, nothing in the suggested procedure addresses the problem of how you are supposed to distinguish the decisions that matter from those that don't. Whoever came up with this idea must've thought that it's trivial to the point it doesn't need solving, but it's the opposite, unfortunately.
Also, FYO, linters aren't responsible for code formatting. It's the formatter's role. Linters advise on style. I.e. the problem of bracket placement is not solved by using linters, an example of problem that is solved by linters is the maximum number of properties a class is allowed to have.
But the meetings about formatting or using / disabling linter rules still happen. Having tools to do that didn't make the problem go away. What did happen, however, is something more like natural selection. The increased volume of newcomers which the field saw up until maybe five or so years ago were mostly steered in a particular "winning" direction. So, today, naturally, you have most people agree on a set of rules to follow because the majority came from the same background. You need a bunch of old-cadgers to work together on a project for there to be a feud over styling rules.
If a decision is hard to make, its often because the differences are small, and therefore it doesn't matter much and you might as well decide by dice-roll.
My life became soo much easier when I had that insight. I used to spend so much mental energy on decisions that most often were inconsequential.
Regarding your question, there's always going to be known and unknown unknowns down the line. My only advice in that case is to get to the unknowns as fast as possible. And from the start take into account that you most likely will have to rebuild a big part when you learn more. That is one of the reasons modularity and decoupling is so important. You want to be able to easily scrap and replace one part without it affecting everything. And keep it simple. Never try to build something that should be capable to handle all imaginable scenarios in the future. You'll be bitten by one of the unimaginable ones, and your complex "can handle everything" architecture will be too rigid to change.
Be sure the work is given to someone who puts some intention into tool selection and you'll probably be okay though. We don't need three different tools doing the same kind of tasks. But sometimes the old old stuff gets moved to the new tool because the old tool couldn't handle that scenario.
What’s even worse is when a lot of talented people spend a lot of time planning a solution on paper which turns out not to be workable in practice, and then they throw good money after bad trying to get the unworkable solution to work, rather than admitting they were wrong.
Remember to * 3 when assessing. Choose wrong, and you do the job, undo it, and do it again.
One of the hardest parts of my job is trying to convince people where the pool of blood on the floor is coming from. We are forever stitching up the wrong wounds and missing others entirely.
Pain sneaks up on people and they often don't realize they're in pain until someone takes it away. This is probably why Refactoring is one of my favorite tech books. It's a set of tools and justifications for chipping away at that pain bit by bit, instead of tolerating more and more while productivity grinds to a halt.
At the end of the day, if only three people really have to care about a thing and they're fine with it, is it their business to run the project the way they prefer/tolerate? It does matter if the opportunity costs and externalities are affecting other projects. If they don't have time to work on other features because of the mistakes they never correct. If other people's flow is constantly interrupted trying to work around their quirky stuff. But if we don't see any of that, or only rarely, then it's more that my internal architect trying to be bossy rather than lift all boats.
> — Day 3-5. OK, there were a couple of solid bugs there, and a fair number of what were technically bugs, but not actually all that bad.
> — Week 2. I guess that was it?
There are a bunch of tools in the developer toolbox that some people never use, and the opposition use religiously. We are especially bad in this industry at turning things into a boolean where they should be a dial or a continuum. Something about that intro to Logic class either rots our brains or works as a filter to keep most of the philosophers out.
In sports there are drills one does a couple times a month instead of every day. You're trying to harden pathways in the brain to make certain reactions be more automatic, to correct subtle errors and suboptimal answers to problems. You don't do them all the time because they're expensive in some way, like time or danger.
I think this is an area where we miss a lot. I don't do TDD all the time. Maybe a week every couple of months. And it's a split between very hard tasks and very simple ones where I practice it. It's easier to work on first principles on a simple problem, but sometimes when you're stuck on a very difficult one, you have to go back to first principles anyway.
"Difficult" can be further broken down into several categories. 1) I don't know how to solve this, 2) the problem is straightforward but arduous and I don't know if I have the stamina for it, 3) I thought I solved it but it's not working.
TDD is a good way to get yourself into bottom up thinking and 'work the problem' by testing your assumptions one at a time. At the very least you have something to show for your work at the next standup even if the answer still eludes.
Similarly, a linter can be good while you're building up muscle memory for writing code the way the current team thinks it should be written. However, it can be a nightmare when you're trying to do exploratory development to fix a bug. I've landed PRs on two different FOSS projects to run the linter after the unit tests for this very reason. I don't fucking care if the code is Clean right now I only care if I've fixed the NPE that is crashing production. The PR is a problem for an hour from now. I need to make it work and then I can make it right.
If anything, he frames that he is concerned about his daughter as a father. The viewpoint of patriarchy.
As in - women in tech who value privacy and rule of law, and are also advocates for child safety and (better versions of) age verification.
In addition, for obvious reasons, you see more (more being the key word) women showing up for issues like NCII.
It is getting mighty tiring to be continuously put in the tech bro libertarian camp just because of my sex, choice of occupation and stance on privacy.
That being said I don't see it as being impossible for a privacy preserving system to be put into place where the central certificate authority (state) offers a way of authenticating the age of the individual without leaking further information, and the client not offering up details about what is being viewed.
For example Meta wants to authenticate a users age and simply receives a boolean response indicating that they are of legal age or not, without anything more.
This could be implemented quite easily in some European countries that already use government issued electronic authentication systems (Auðkenni in Iceland and DigiD in the Netherlands spring to mind).