What's really stupid about all this is that I give fellow users on this site a little bit of trust because I know that many times, they would like advice or help with their projects, or conversely, they have stumbled on something I can learn.
So I don't worry too much about giving my user name out, or entering it into other HN members' apps. I did it, and I'm not worried about it really. It's not like run4yourlives is my bank id or anything.
What bothers me about the whole thing though is that I've now had it confirmed that HN is too big to trust anymore. Whereas before, there was a sense of kinship with people here - none of whom I've ever met - I now have to worry that some of them are just losers looking to exploit my trust.
That's worse than off topic posts and low quality comments really. It's an attack on the fabric of the community, and the value of the users. It's clear now that I must treat HN as I would treat reddit or digg or any other room full of potential idiots; people who would much rather exploit trust than build it.
I don't feel like any trust was violated by xach in showing us this exploit. He clearly wasn't trying to be malicious, so I frankly don't understand all of these people who are so upset about this. It sounds like a lot of pointless whining.
Frankly, if anybody has violated our trust, it's whoever wrote this exploitable code. When I use a site, especially an open source one claimed to be written by good programmers, I expect it to be protected from well-understood exploits. And pg, as the caretaker of the code (and its likely author), needs to do some talking about how "not cool" running easily exploitable code is and take some responsibility.
1. It most certainly was malicious, if not in outcome, in intent. xach wanted to say "Look, you say you're a coder - look at me I'll show you." There were a multitude of ways he could have presented his case in a manner that would have been - frankly - much more mature.
2. This is pg's personal pet hobby. I don't think holding him responsible for every possible vulnerability is really all that practical, especially when the code is wide open. He's putting it out there with an element of trust that a hacker to be would actually provide a fix instead of being malicious. If xach was such a great positive influence, why didn't he provide a patch?
1. Perhaps we simply have different definitions of malicious. I don't even think it's possible to be malicious with info on HN, unless he were to try to get our passwords or something. I just don't think karma is something to get all upset about.
2. I don't care what this is to pg. If he doesn't want it to be cracked, then he should spend some hobby time doing what every decent web programmer knows to do. There is no "element of trust" on publicly available sites. Further, note that I have not made an argument that xach has been a "great positive influence" - only not a negative one
Honestly, what have you lost? Nothing. The truth is that you shouldn't be trusting a bunch of people you've never met ANYWAY. Nobody's asking you to give them your address or mother's maiden name, but you wouldn't give those out if asked by a fellow member anyway. You should always be wary of sites asking for your information for whatever reason, and just because you trust some of the people on HN doesn't mean there aren't tons more on here that could possibly deceive you.
People seem to react to this like like the record companies reacted to Napster. "OH NO! IT'LL KILL US ALL! Screw changing our ancient business model, we'll just SUE 'EM!"
Instead of updating the way you think about HN (and other sites) you choose to put down the person who enlightened you and cast him out as some sort of heretic.
Hackers INVENT, hackers BREAK STUFF, and hackers BRING OUT THE UGLY! Why is Xach getting martyred for being a real hacker?
Besides, he's giving HN huge publicity. Jeff Atwood twittered about this thread.
I don't know whether you've been paying much attention to some of the threads lately but HN is trying to maintain a particular feel. It's huge publicity that begins to erode HN and turn it into something that many of us would rather avoid.
"Huge publicity"... but it's already publicly advertised in many places, many big names are blogging/twittering about it, did you really expect everyone to ignore it? If it's got such a good feel to it, why can't everyone else get in on that?
So far all I've seen is elitism, both in comments I'm reading and the replies to my own (first) comment.
Hackers aren't supposed to like elitism. We're supposed to promote the sharing of knowledge, information, freely and openly, you know... because that's how the world should be. Or so we say. But I haven't seen that here. I've seen the typical elitist social community, with the people who've been here "longer" running the show aside from the admin.
Decided to end my thought there, it was running a little long...
How did I know you'd pull that card instead of just letting it go? It's so easy to pull that card, isn't it? Long time reader, first time poster. Please don't judge a book by it's hour-old cover.
Well, I think that a room full of idiots is an overstatement. An occasional idiot sure, but even that's beside the point - before this supposed decline of the community, you wouldn't have posted your credit card and social security numbers in the comments, no matter how much trust you placed here.
Comments
What's really stupid about all this is that I give fellow users on this site a little bit of trust because I know that many times, they would like advice or help with their projects, or conversely, they have stumbled on something I can learn.
So I don't worry too much about giving my user name out, or entering it into other HN members' apps. I did it, and I'm not worried about it really. It's not like run4yourlives is my bank id or anything.
What bothers me about the whole thing though is that I've now had it confirmed that HN is too big to trust anymore. Whereas before, there was a sense of kinship with people here - none of whom I've ever met - I now have to worry that some of them are just losers looking to exploit my trust.
That's worse than off topic posts and low quality comments really. It's an attack on the fabric of the community, and the value of the users. It's clear now that I must treat HN as I would treat reddit or digg or any other room full of potential idiots; people who would much rather exploit trust than build it.
Sad but inevitable I suppose.
I don't feel like any trust was violated by xach in showing us this exploit. He clearly wasn't trying to be malicious, so I frankly don't understand all of these people who are so upset about this. It sounds like a lot of pointless whining.
Frankly, if anybody has violated our trust, it's whoever wrote this exploitable code. When I use a site, especially an open source one claimed to be written by good programmers, I expect it to be protected from well-understood exploits. And pg, as the caretaker of the code (and its likely author), needs to do some talking about how "not cool" running easily exploitable code is and take some responsibility.
1. It most certainly was malicious, if not in outcome, in intent. xach wanted to say "Look, you say you're a coder - look at me I'll show you." There were a multitude of ways he could have presented his case in a manner that would have been - frankly - much more mature.
2. This is pg's personal pet hobby. I don't think holding him responsible for every possible vulnerability is really all that practical, especially when the code is wide open. He's putting it out there with an element of trust that a hacker to be would actually provide a fix instead of being malicious. If xach was such a great positive influence, why didn't he provide a patch?
1. Perhaps we simply have different definitions of malicious. I don't even think it's possible to be malicious with info on HN, unless he were to try to get our passwords or something. I just don't think karma is something to get all upset about.
2. I don't care what this is to pg. If he doesn't want it to be cracked, then he should spend some hobby time doing what every decent web programmer knows to do. There is no "element of trust" on publicly available sites. Further, note that I have not made an argument that xach has been a "great positive influence" - only not a negative one
Honestly, what have you lost? Nothing. The truth is that you shouldn't be trusting a bunch of people you've never met ANYWAY. Nobody's asking you to give them your address or mother's maiden name, but you wouldn't give those out if asked by a fellow member anyway. You should always be wary of sites asking for your information for whatever reason, and just because you trust some of the people on HN doesn't mean there aren't tons more on here that could possibly deceive you.
People seem to react to this like like the record companies reacted to Napster. "OH NO! IT'LL KILL US ALL! Screw changing our ancient business model, we'll just SUE 'EM!"
Instead of updating the way you think about HN (and other sites) you choose to put down the person who enlightened you and cast him out as some sort of heretic.
Hackers INVENT, hackers BREAK STUFF, and hackers BRING OUT THE UGLY! Why is Xach getting martyred for being a real hacker?
Besides, he's giving HN huge publicity. Jeff Atwood twittered about this thread.
I don't know whether you've been paying much attention to some of the threads lately but HN is trying to maintain a particular feel. It's huge publicity that begins to erode HN and turn it into something that many of us would rather avoid.
"Huge publicity"... but it's already publicly advertised in many places, many big names are blogging/twittering about it, did you really expect everyone to ignore it? If it's got such a good feel to it, why can't everyone else get in on that? So far all I've seen is elitism, both in comments I'm reading and the replies to my own (first) comment. Hackers aren't supposed to like elitism. We're supposed to promote the sharing of knowledge, information, freely and openly, you know... because that's how the world should be. Or so we say. But I haven't seen that here. I've seen the typical elitist social community, with the people who've been here "longer" running the show aside from the admin.
Decided to end my thought there, it was running a little long...
I wouldn't normally say this, but your case is extreme.
Perhaps you should have an account longer than an hour before you lecture me about the effects of this issue on the community.
How did I know you'd pull that card instead of just letting it go? It's so easy to pull that card, isn't it? Long time reader, first time poster. Please don't judge a book by it's hour-old cover.
Well, I think that a room full of idiots is an overstatement. An occasional idiot sure, but even that's beside the point - before this supposed decline of the community, you wouldn't have posted your credit card and social security numbers in the comments, no matter how much trust you placed here.
Everyone has the potential to be an idiot. Broken windows and all...