mstdn.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A general-purpose Mastodon server with a 500 character limit. All languages are welcome.

Administered by:

Server stats:

12K
active users

@bagder the talk is a tongue in cheek. It makes semi-plausible observations how incessant bikeshedders, defeatist arguments, patches that bolt on ad-hoc features neglecting docs and overall architecture, etc. are close to what NSA could be doing to undermine projects, and have perfect deniability.
It was especially relevant at the time of Snowden leaks and Heartbleed.

@kornel I know. I actually saw his talk live at fosdem. I was only reacting on the notion that it would be easy to do any of it. Because I don't think so.

Hobson Lane

@bagder
And force people to use centralized SSL authentication certs and DNS systems.
And nag people to death about self-signed certs and cookies.
And centralize access to webmail.
And () most popular apps for encrypted communication.
Anticipated all this a decade before Docororow coined the word
@kornel

@hobs @bagder Yeah, these scenarios have happened anyway (although I don't agree with PHK on all of them). OpenSSL has accumulated a mountain of tech debt and a footgunny API, with or without NSAs help.

The custom QUIC impl nobody wants, and the obstruction of other impls may be an organic outcome, but it is what a spy agency would give promotions for.

@kornel
Thank you. Had no idea about QUIC (or any part of SSL) being UDP. After reading through some docs and explanations, I feel for researchers that have to untangle all this to get their job done.
@bagder