aditya's recent activity

  1. Comment on Premier League statement: Manchester City FC in ~sports.football

  2. Comment on Premier League statement: Manchester City FC in ~sports.football

    aditya
    Link

    An independent Commission has found Manchester City FC guilty of all charges related to serious breaches of the Premier League’s financial rules over a nine-season period, and the majority of charges in relation to its failure to co-operate with the League’s investigation.

    The independent Commission found that between Seasons 2009/10 and 2017/18:

    • Manchester City arranged ‘sham’ contracts (which misrepresented the true agreement between the parties) with a number of its commercial partners, as well as relying on ‘sham’ agreements with others, to artificially inflate the club’s revenues and reduce its costs
    • The club filed misstated accounts and concealed the true state of its finances from its auditors and football regulators
    • Manchester City was significantly in breach of both the Premier League’s and UEFA’s spending limits
    • During the Premier League’s investigation, Manchester City committed multiple breaches of its duties of co-operation and utmost good faith towards the League (three of the four alleged breaches were upheld)
    1 vote
  3. Comment on Does anyone have a digg invite code I can get ? in ~tech

    aditya
    Link
    Yet another person looking for an invite :)

    Yet another person looking for an invite :)

  4. Comment on 1940s New York City streetview in ~design

    aditya
    Link
    This is so cool! I learned the lot next to my building wasn't always empty but seemingly an identical 5 floor walk up apartment building. Crazy, because now it's a private parking lot.

    This is so cool! I learned the lot next to my building wasn't always empty but seemingly an identical 5 floor walk up apartment building. Crazy, because now it's a private parking lot.

    5 votes
  5. Comment on Any tips for Barcelona and Lisbon in June/July? in ~travel

    aditya
    Link
    Lots of great suggestions here. wrt Barcelona, I’d also suggest a day trip to Girona and another out to Montserrat!

    Lots of great suggestions here. wrt Barcelona, I’d also suggest a day trip to Girona and another out to Montserrat!

    1 vote
  6. Comment on On the XZ Utils backdoor (CVE-2024-3094): FOSS delivered on its pitfalls and strengths in ~comp

    aditya
    Link Parent
    Honestly, this wouldn't solve the problem. It'd be actively harmful to some who cannot share their identity, would shut out those whose online identities do not match their legal documents for...

    As to what needs to happen to prevent this in the future? I'm torn between privacy and a kyc/kyd (know your developer) process for open source. On one hand I value anonymity for the internet but for critical infrastructure I believe there does either need to be a a way to vet software developers who contribute to a FOSS project that is already in use on 100's of system or an innovation in code reviews:/testing that make spotting issues like this easier.

    Honestly, this wouldn't solve the problem. It'd be actively harmful to some who cannot share their identity, would shut out those whose online identities do not match their legal documents for whatever reason (think transgender people in certain places for example), and also raises the question of who really adjudicates on the validity of "official ID". Would a fake ID such as those used by underaged students to purchase alcohol suffice? What about cases you're dealing with a nation state actor who can trivially issue legitimate IDs for bad actors?

    All of this is without getting into the fact that there are legitimately good reasons a FOSS maintainer may want to remain anonymous. The burden must be on those consuming open source software that they aren't implicitly trusting an upstream maintainer for critical packages. I mostly agree with your points on code review and want to point to efforts like the crev project which try and make the implicit trust explicit based off social code review. This is hard to scale but I remain hopeful organizations will eventually throw their might at it as well...Another thing we ought to be doing is making our tech less complex so things like review are more tractable but I suspect that's basically impossible now...

    10 votes
  7. Comment on I got my IELTS scores back and I need help in ~life

    aditya
    Link
    Aim for starting in the fall. Your internship opportunities are better and you finish your program at a more appropriate time from the perspective of getting a job (if that’s what you want). Also,...

    Aim for starting in the fall. Your internship opportunities are better and you finish your program at a more appropriate time from the perspective of getting a job (if that’s what you want). Also, most US universities prefer TOEFL but IELTS should also be accepted by a bunch.

    4 votes
  8. Comment on What 2023 Black Friday deals are you looking into? in ~talk

    aditya
    Link Parent
    I suspect it’s so you don’t subscribe and immediately unsubscribe to just get the first year. Billed monthly, you can only unsubscribe in the last month, 11 months away? Possibly, some folks will...

    I suspect it’s so you don’t subscribe and immediately unsubscribe to just get the first year. Billed monthly, you can only unsubscribe in the last month, 11 months away? Possibly, some folks will forget and let it renew at full price?

  9. Comment on Petition launched to save Marvin’s Marvelous Mechanical Museum in Michigan from demolition in ~hobbies

    aditya
    Link Parent
    I only knew the Tally Hall album. Interesting to see there’s more music with this as a reference.

    I only knew the Tally Hall album. Interesting to see there’s more music with this as a reference.

    3 votes
  10. Comment on What programming/technical projects have you been working on? in ~comp

    aditya
    Link
    Continuing to work on gittuf. We’re now in the OpenSSF sandbox! We also had our first alpha release and someone posted the website on Hacker News. Exciting times overall!

    Continuing to work on gittuf. We’re now in the OpenSSF sandbox! We also had our first alpha release and someone posted the website on Hacker News. Exciting times overall!

    3 votes
  11. Comment on Headphone recommends that actually block out voices in ~tech

    aditya
    Link Parent
    You can turn off the talk to pause feature on the XM4.

    You can turn off the talk to pause feature on the XM4.

    3 votes
  12. Comment on <deleted topic> in ~food

  13. Comment on Why is the iOS dialer so terrible? in ~tech

    aditya
    Link Parent
    On Android, I used to use KISS launcher to quickly search for apps / contacts etc instead of navigating to them specifically. So even there I wouldn’t actually go to the dialer app to find a...

    On Android, I used to use KISS launcher to quickly search for apps / contacts etc instead of navigating to them specifically. So even there I wouldn’t actually go to the dialer app to find a contact. It’s an incredibly powerful workflow for me, getting me quickly to what / who I want.

  14. Comment on Why is the iOS dialer so terrible? in ~tech

    aditya
    Link Parent
    You don’t have to do that, though. Spotlight can search contacts and it’s one tap to call from there. Effectively, it’s the same number of taps / swipes.

    You don’t have to do that, though. Spotlight can search contacts and it’s one tap to call from there. Effectively, it’s the same number of taps / swipes.

    12 votes
  15. Comment on What have you been listening to this week? in ~music

  16. Comment on Quantum resistance and the Signal Protocol in ~tech

    aditya
    Link
    Just tried to submit this to ~comp, I always get thrown by ~tech vs ~comp. (Side note: I got a notice that this link was already submitted when in the past I've accidentally submitted duplicate...

    Just tried to submit this to ~comp, I always get thrown by ~tech vs ~comp. (Side note: I got a notice that this link was already submitted when in the past I've accidentally submitted duplicate topics, is that a new tildes feature?)

    Today we are happy to announce the first step in advancing quantum resistance for the Signal Protocol: an upgrade to the X3DH specification which we are calling PQXDH. With this upgrade, we are adding a layer of protection against the threat of a quantum computer being built in the future that is powerful enough to break current encryption standards.

    This post is written to introduce this work to non-experts, and will review what quantum computing is and the challenges it presents for current cryptographic algorithms, before providing a high level overview of how we are adapting our specifications to answer these challenges. If you would like to skip this summary and explore our PQXDH specification in depth, you can read our technical whitepaper here.

    Link to whitepaper: https://signal.org/docs/specifications/pqxdh/

    3 votes
  17. Comment on What programming/technical projects have you been working on? in ~comp

    aditya
    Link Parent
    It depends on the specific application / workflow. gittuf verify-commit and so on are helpers to align with guy’s own workflow but we’re building in some clone and fetch capabilities to verify...

    I guess this all depends on people running 'gittuf verify-commit?' It seems like making that happen automatically as part of 'git clone' would be the next step.

    It depends on the specific application / workflow. gittuf verify-commit and so on are helpers to align with guy’s own workflow but we’re building in some clone and fetch capabilities to verify transparently. The thing is, on one end you may want verification by all users all the time but that’s just hard without building it into git itself. On the other end of the spectrum, I think there’s a lot to be gained from even just the maintainers using gittuf to verify all the time. Related is also Guix’s attempt to embed GPG keys trusted for their repository: https://arxiv.org/pdf/2206.14606.

    That's pretty good, but it assumes GitHub is secure and none of the developers' GitHub accounts got broken into. Maybe that chain of trust could be pushed back earlier in the process, so GitHub is just a cache.

    Absolutely! I think there’s also real scope to allow for signing go releases using the underlying git signatures because that’s the overwhelming majority of go packages anyway.

    IMO there’s a lot of scope to work with GitHub, GitLab etc. for gittuf once we start exploring policy transparency and auditability of historic policy compliance. I’m hoping the OpenSSF is a good venue to sketch all of this out with the right people. :)

    1 vote