• 0 Posts
  • 81 Comments
Joined 1 year ago
cake
Cake day: October 30th, 2023

help-circle

  • That’s how it always starts though.

    People use any device or service they want. It’s a mix of crooks, tinkerers, journalists, etc.

    A company or government makes some moral panic and pushes some privacy or civil rights erosion in the name of “security”. The actual security benefit may or may not exist.

    Then other companies do the same to keep up.

    Then there’s only a handful of companies not doing the thing, so anyone who doesn’t want their privacy or civil rights eroded uses that, including crooks.

    Then politicians and the other companies point to the holdouts as “PROOF!” their changes were good, because look how many crooks use that stuff! (The number of crooks hasn’t changed, they’ve just been concentrated to a single location.) The moral panic deepens.

    The non-criminal population that cares about their privacy or civil rights speak out, but get accused of secretly being criminals, or some other crap that can be used to dismiss their concerns. “If you have nothing to hide, why are you so upset?” and all that.

    Now laws get passed to force all companies to do the same thing, to stop the criminals! But let’s not worry about anyone else. The tinkerers, journalists, privacy-advocates, etc. They don’t matter.

    The law gets passed, and now all toasters are legally required to record your breakfast conversations, for a silly example.




  • You didn’t have to deal with random re-balancing changing your gameplay, spying and tracking embedded in everything, hackers ruining the game or targeting you, invasive DRM (consoles), being forced to update your system for an hour before you can play, being forced to sign up for bullshit accounts in order to play the game you just bought, games that have required updates the day they come out, your games disappearing forever because the publisher changed their mind and removed it from the store, game content being removed to sell as DLC instead, being pressured to link social media accounts, bigger companies buying the game and forcing you to use their services to play it, companies monitoring and recording player interactions, companies going under making it impossible to play the game you already bought…

    Holy shit. I never realized how bad modern gaming has gotten.







  • This isn’t the same thing, but I’m reminded of Minecraft.

    Minecraft is a massively popular game. Notch once said he planned to make it open source when its popularity died down. But now Microsoft owns it.

    Not only that, but Mojang accounts don’t work anymore. You have to have a Microsoft account to play it now. Even trying to download and play an older version of the game offline requires Microsoft to approve it. Microsoft is actively tightening the leash on the game because it makes them money. Open sourcing the game will likely never happen now. The best we can hope for it for versions to fall into public domain after 70-ish years.

    That’s how I see Microsoft. They only care about what its beneficial for them to drive profits. Working on open source projects, and open sourcing a few of their tools to get the benefits of community adoption and code review is great, sure. But they’d sooner try to incorporate Linux into Windows to keep people in their surveillance ecosystem, than to open source Windows.

    Remember when Windows 10 was the last version, until they changed their minds? Remember when they floated the idea of charging a recurring subscription to use Windows, before they silently dropped the idea? Remember when there was credible talk about the next version of Windows being cloud-based where they controlled all your data and you had no privacy? Hell, you have basically no privacy on Windows 10. Trying to reclaim some involves registry edits, special third party tools, and a constant battle with automatic updates reverting your changes.

    I’ll say it again. Microsoft doesn’t care about OSS. It’s just currently beneficial for them to pretend they do.

    Goggle seemed to care a lot about OSS, then started making everything in Android depend on their proprietary ecosystem to function. Now Google is using the dominant position they got by taking advantage of OSS adoption, and have been pushing privacy-invading standards and trying to get rid of ad blockers online, among many other things.

    For these huge companies, OSS is just a tool to get more control and power. The moment it’s no longer useful, they’ll find ways to work around the license and enshitify everything again.

    It keeps happening. I refuse to keep trusting bad actors every time they dangle a shiny trinket over our heads.

    I do appreciate the work this person did in finding the bug. It’s not all doom and gloom.


  • Damn fine work all around.

    I know this is an issue fraught with potential legal and political BS, and it’s impossible to check everything without automation these days, but is there an organization that trains and pays people to work as security researchers or QA for open source projects?

    Basically, a watchdog group that finds exploitable security vulnerabilities, and works with individuals or vendors to patch them? Maybe make it a publicly owned and operated group with mandatory reporting of some kind. An international project funded by multiple governments, where it’s harder for a single point of influence to hide exploits, abuse secrets, or interfere with the researchers? They don’t own or control any code, just find security issues and advise.

    I don’t know.

    Just thinking that modern security is getting pretty complicated, with so many moving parts and all.