> And before you ask: Yes, I’m laying this one squarely down before (and partly on the toes of) the tech bros: We could have designed our protocols to be minimally compatible with “a nation of laws,” but the tech bros insisted that compromise was treason, and, as a result, we will lose more privacy than necessary.
Ah, the famous “maybe if I take a step back they’ll appreciate it and not push harder”. Or maybe it’s “if I give the leopard my face maybe it spares my body”.
I’ll let reality speak for itself: look no further than Stingrays and every bit of legal abuse they enabled, where innocent people are spied on in bulk with flimsy excuses. How well did it work out when the protocol was already maximally compatible with laws?
There’s no “minimally compatible”, you either have the privacy technically guaranteed or you don’t. If it’s technically allowed to breach it, it will soon be done as a matter of routine under the guise of “protecting”, “preventing”, and so on.
So in the end we didn’t lose anything, what we did was we gained a short period in which we could all taste that freedom. If we used your proposal nobody would have had even that to begin with.
This logic would have been easier to forgive if it came from youth and inexperience, from someone who never got to know about the endless abuse of surveillance that was inflicted indiscriminately on everyone.
> I promised myself I would never join their ranks.
A wasted opportunity, missed by at least 1 article :).
This. Author does talk about a lot of facts but seems very defeatist wrt whether an anonymous, encrypted internet can be preserved.
I do recognize their point that it's been made very hard to catch and prosecute cyber criminals. I think there are ways to improve that that don't destroy the privacy of everyone. But if that's the real goal, why isn't it the big pitch line of the Parent's Decide Act?
I also found the compromise bit of the article strange
The minimally compatible is what existed before. The Snowden leaks showed that the Government, and not just the US government, would abuse the shit out of that for mass surveillance.
So now privacy advocates no longer trust that such a compromise can exist
It’s strange that the author both recognizes that the Government broke the social contract and then says privacy advocates should just keep trusting them in the same article
A working solution can forestall a worse one. Because of the age verification law in California, which is very explicit that you only need a device-wide checkbox, nobody can use the argument that they need a passport scan to comply with the law.
It’s interesting to claim that the ‘tech bros’ oppose hardware attenuation and age verification when this will massively benefit them; everyone will be forced to use their operating system and the government will have exercised its power to protect Microsoft’s god-given right to make money, Peter Thiel’s age verification startup’s ability to collect people’s data and their ability to trace the identity of any critics through identity-based age verification.
That’s why large tech companies are lobbying in favour of this!
Wow, re-read the fine article. He was NOT stating that he wants the outcome you think. He is afraid it is going to happen because the younger generation has no clue or ability to maintain FOSS.
This whole thing can be reduced to "think of the children", see the literal example around paragraph ~30. I'm not sure I've ever seen anyone try so hard to equate being pro-privacy with being pro-crime.
> During the past couple of decades, rampant neoliberalism and “globalism” allowed the U.S. tech industry to capture almost the entire European IT market, including all “social media.” This has recently proved to be a ghastly mistake, and now the EU, along with its member states and companies, are scrambling to claw back their digital sovereignty.
This is not a partisan political statement, it's a factual one. It is simply a statement of fact that neoliberal world markets have permitted hyperscalers to cross national boundaries and provide the same services at scale to governments worldwide, and like, without even going into any U.S. politics at the moment, isn't that... really weird? Like many EU governments had essentially put their ability to function as states in the hands of a foreign actor. That's WILD.
There are some incredibly strange equivalences going on in here that make me think the person in question is indeed quite out of date.
The people pushing for the destruction of privacy and attested software integrity ARE the tech bros. I'm sure there are people here that will vehemently disagree with me, but we see the biggest tech companies pushing for age verification and we see founders and rich folk gleefully giving up their earlier pro-privacy stances in favor of supporting locking down identity. They're building up their moat in real time because not only does it let them kill that pesky FOSS, but also it means they can legally gather even more data from individuals in question.
It also goes hand-in-hand with the increasingly authoritarian bent a lot of those same people have taken and these resources will absolutely be used to crack down on minorities and things they don't like.
I think your head would have to be firmly planted deep underground to somehow not connect the two dots. As another poster here said, they're literally lobbying for these age verification laws because it benefits them.
This is a very strange read. If that was posted on a random blog, I would have dismissed it. I didn’t know that that cell (anti tech bro, anti big tech, pro age verification laws) in the alignment chart is populated by actual people. And by intelligent people even.
Also the fact they call it “age verification” when they clearly build an identity verification and we just accept their language is crazy.
I don't think age restriction will impact FOSS in the long term. If there are some regulations that threaten FOSS now, they are going to be adopted in the long term.
Regulations for age restriction are understandable. A lot of modern technology is harming kids (and I don't mean dirty videos, social media seems to be much more harmful).
A sensible regulator would leave some responsibility to the parents, but require restrictions for consumer devices (smartphones, laptops). Maybe even enable age restrictions by default, block replacing the OS or the firmware, and only allow it once the age was confirmed.
I don't see a point of including all kind of OS or software into this regulation. Just the ones that are preinstalled on consumer devices, and commercially distributed to consumers. Once the age of the user was confirmed, the devices should be able to become as open as we know them now.
"LLM-assisted code review won't be a huge disruptor" is quite the prediction. Because it already is in a very big way. The take on LLMs seems incredibly out of date and out of touch with reality. (Which of course, has moved/advanced very fast the past months/year)
> the weights of the model—which you have to sell many million times over before you turn a profit—easily fits on contemporary pocket-sized storage devices.
Which model is this author talking about? Which pocket-sized devices? Where can I get them? No one is using Gemma 4 to find cybersecurity issues.
Edit: there are a lot of sentences that I can't distinguish from sarcasm in this article. I guess I read it too seriously.
I guess tech has grown too large and fractured and maybe most working software engineers are too young to be familiar with phk and his points of view.
He's been a strong privacy and FOSS advocate for decades and has more credibility on both of these topics than nearly anyone on this board.
He also has an account and comments frequently. phkamp. I suggest reading some of his comments before making judgment.
So many kneejerk and nuance-less opinions. Absolutely hilarious that people are thinking the guy who wrote MD5crypt and BSD Jails is anti-privacy.
Also eye opening watching how many people are getting frothing-at-the-mouth mad seeing somebody with that pedigree coming to different conclusions than they do.
> my personal guess is that the opportunities for anonymity on the Internet will shrink until mothers no longer are forced to have “the talk” when their daughters get their first mobile phone. As the parent of a daughter, I am totally on board with that.
depends on the age but.. they've probably discovered all kinds of shit already or heard about it from others
He really seems to think he made some deep insight on the "bubble" that he seems so confident about.
> So, it is not obvious to me who will be training new iterations of these models once the current bubble explodes, in particular if the returns are diminishing the way I have experienced.
It looks like he has no clue on how market equilibriums work. He really seems to think LLM's will just like.. stop existing.
So in their world, people would suddenly realise that AI is actually not that economic and we can't have Opus 4.8 quality models just with updated knowledge cutoff perpetually. So in his future, things won't just stall, they will literally go back.
He's really putting his emotional weight on this particular kind of future.
Either that or he's making nebulous emotional claims - its his blog so he can do it.
For those unaware, PHK created (amongst other things) the MD5crypt password hashing algorithm ($1$…). It came before bcrypt (1999), scrypt (2009), SHA2crypt (2016), etc, and was committed in 1994:
> When Edward Snowden revealed that Somebody Important had been taking an interest after all, the tech bros, who had grown up free of adult supervision, felt betrayed and started a campaign to encrypt everything and anything so that prying eyes could never again look them in the cards.
TIL: Phil Zimmermann was a "tech bro" and had a time machine.
"We could have designed our protocols to be minimally compatible with “a nation of laws,” but the tech bros insisted that compromise was treason, and, as a result, we will lose more privacy than necessary"
Unfortunately, no, you can't have a prophilactic that just makes you a little bit pregnant. We used to know this.
> Right now, there is a LOT of shrill propaganda from the tech bros, who call themselves “privacy advocates,” about how mandatory age checking is the gateway drug to comprehensive identity checks on the entire Internet, and ridiculing the valid civic concerns governments are trying to address as merely “think of the children” strawman arguments.
Oh, it’s not a slippery slope. It’s a single step: age verification IS identity verification, and it abolishes anonymous publishing on the internet, allowing on day one for violent retaliation against political speech.
If you think that authoritarian governments won’t be abusing this instantly, you are sorely ignorant of history.
48 comments
[ 1.6 ms ] story [ 15.5 ms ] threadAh, the famous “maybe if I take a step back they’ll appreciate it and not push harder”. Or maybe it’s “if I give the leopard my face maybe it spares my body”.
I’ll let reality speak for itself: look no further than Stingrays and every bit of legal abuse they enabled, where innocent people are spied on in bulk with flimsy excuses. How well did it work out when the protocol was already maximally compatible with laws?
There’s no “minimally compatible”, you either have the privacy technically guaranteed or you don’t. If it’s technically allowed to breach it, it will soon be done as a matter of routine under the guise of “protecting”, “preventing”, and so on.
So in the end we didn’t lose anything, what we did was we gained a short period in which we could all taste that freedom. If we used your proposal nobody would have had even that to begin with.
This logic would have been easier to forgive if it came from youth and inexperience, from someone who never got to know about the endless abuse of surveillance that was inflicted indiscriminately on everyone.
> I promised myself I would never join their ranks.
A wasted opportunity, missed by at least 1 article :).
I do recognize their point that it's been made very hard to catch and prosecute cyber criminals. I think there are ways to improve that that don't destroy the privacy of everyone. But if that's the real goal, why isn't it the big pitch line of the Parent's Decide Act?
The minimally compatible is what existed before. The Snowden leaks showed that the Government, and not just the US government, would abuse the shit out of that for mass surveillance.
So now privacy advocates no longer trust that such a compromise can exist
It’s strange that the author both recognizes that the Government broke the social contract and then says privacy advocates should just keep trusting them in the same article
HN existed 20 years ago...? /s
edit: yes it did, lol
That’s why large tech companies are lobbying in favour of this!
> In this last Bikeshed in acmqueue, I will ponder the far future of free and open source software (FOSS), hoping to upset so many readers that...
> During the past couple of decades, rampant neoliberalism and “globalism” allowed...
And I’m out. I guess congratulations to the author. Mission accomplished.
But I’m disappointed that the article took a turn towards partisan politics.
> During the past couple of decades, rampant neoliberalism and “globalism” allowed the U.S. tech industry to capture almost the entire European IT market, including all “social media.” This has recently proved to be a ghastly mistake, and now the EU, along with its member states and companies, are scrambling to claw back their digital sovereignty.
This is not a partisan political statement, it's a factual one. It is simply a statement of fact that neoliberal world markets have permitted hyperscalers to cross national boundaries and provide the same services at scale to governments worldwide, and like, without even going into any U.S. politics at the moment, isn't that... really weird? Like many EU governments had essentially put their ability to function as states in the hands of a foreign actor. That's WILD.
The people pushing for the destruction of privacy and attested software integrity ARE the tech bros. I'm sure there are people here that will vehemently disagree with me, but we see the biggest tech companies pushing for age verification and we see founders and rich folk gleefully giving up their earlier pro-privacy stances in favor of supporting locking down identity. They're building up their moat in real time because not only does it let them kill that pesky FOSS, but also it means they can legally gather even more data from individuals in question.
It also goes hand-in-hand with the increasingly authoritarian bent a lot of those same people have taken and these resources will absolutely be used to crack down on minorities and things they don't like.
I think your head would have to be firmly planted deep underground to somehow not connect the two dots. As another poster here said, they're literally lobbying for these age verification laws because it benefits them.
Also the fact they call it “age verification” when they clearly build an identity verification and we just accept their language is crazy.
There is nothing of substance here. You don't like AI, I get. But it still exists and pretending that no-one finds it useful is utterly foolish.
Edit: I overuse the word utterly. Nice to identify one of my tells.
Regulations for age restriction are understandable. A lot of modern technology is harming kids (and I don't mean dirty videos, social media seems to be much more harmful).
A sensible regulator would leave some responsibility to the parents, but require restrictions for consumer devices (smartphones, laptops). Maybe even enable age restrictions by default, block replacing the OS or the firmware, and only allow it once the age was confirmed.
I don't see a point of including all kind of OS or software into this regulation. Just the ones that are preinstalled on consumer devices, and commercially distributed to consumers. Once the age of the user was confirmed, the devices should be able to become as open as we know them now.
Do yourself a favor and read this, a few times, and take a moment to actually try and see what the author's getting at.
Talking isn't doing, just like word generation isn't an outcome.
Which model is this author talking about? Which pocket-sized devices? Where can I get them? No one is using Gemma 4 to find cybersecurity issues.
Edit: there are a lot of sentences that I can't distinguish from sarcasm in this article. I guess I read it too seriously.
He's been a strong privacy and FOSS advocate for decades and has more credibility on both of these topics than nearly anyone on this board.
He also has an account and comments frequently. phkamp. I suggest reading some of his comments before making judgment.
So many kneejerk and nuance-less opinions. Absolutely hilarious that people are thinking the guy who wrote MD5crypt and BSD Jails is anti-privacy.
Also eye opening watching how many people are getting frothing-at-the-mouth mad seeing somebody with that pedigree coming to different conclusions than they do.
depends on the age but.. they've probably discovered all kinds of shit already or heard about it from others
> So, it is not obvious to me who will be training new iterations of these models once the current bubble explodes, in particular if the returns are diminishing the way I have experienced.
It looks like he has no clue on how market equilibriums work. He really seems to think LLM's will just like.. stop existing.
So in their world, people would suddenly realise that AI is actually not that economic and we can't have Opus 4.8 quality models just with updated knowledge cutoff perpetually. So in his future, things won't just stall, they will literally go back.
He's really putting his emotional weight on this particular kind of future.
Either that or he's making nebulous emotional claims - its his blog so he can do it.
* https://svnweb.freebsd.org/base/head/lib/libcrypt/crypt.c?re...
* https://github.com/freebsd/freebsd-src/commit/3b2b7f71deba2a...
* https://phk.freebsd.dk/sagas/md5crypt/
* https://en.wikipedia.org/wiki/Poul-Henning_Kamp
TIL: Phil Zimmermann was a "tech bro" and had a time machine.
Unfortunately, no, you can't have a prophilactic that just makes you a little bit pregnant. We used to know this.
Oh, it’s not a slippery slope. It’s a single step: age verification IS identity verification, and it abolishes anonymous publishing on the internet, allowing on day one for violent retaliation against political speech.
If you think that authoritarian governments won’t be abusing this instantly, you are sorely ignorant of history.