Dyslexic Privacy & Foss advocate, and Linux user.

Ace 🖤🩶🤍💜

Anti Commercial-AI license (CC BY-NC-SA 4.0)

  • 4 Posts
  • 29 Comments
Joined 1 year ago
cake
Cake day: June 14th, 2023

help-circle














  • The only point I found that falls under “questionable choices” is :

    “If you go looking for compression support in Rust, there’s none in the standard library. But you may notice the flate2-rs repo under the official rust-lang GitHub namespace. If you look at its transitive dependencies: flate2-rs depends on (an individual’s) miniz_oxide which depends on (an individual’s) adler that hasn’t been updated in 4 years. 300 lines of code including tests. Why not vendor this code? It’s the habits a small standard library builds that seem to encourage everyone not to.”
    “Even official packages may end up depending on external party packages, because the commitment to a small standard library meant omitting stuff like compression, checksums, and common OS paths.”

    Which is somewhat valid, but imo it’s really not as big of a deal breaker as they’re trying to make it out to be.




  • Your point is void as the US government is not a single massive entity you can generalize. They’re are a plethora of different, separated branches, departments and offices each operating independently with their own unique functions, values, regulations, practices, etc.

    All you’ve done here is presented a hyper-generalized claim as if all of the government enforces and endorses this practices while providing a single cherry picked counterexample without even knowing the actual reason why they use this practice to begin with or providing evidence of them endorsing the practice despite me asking you to do so.

    The fact of the matter is the vast majority of US government entities do not have any such practice and there’s no evidence of your provided counterexample actually endorsing others to do the same let alone any other branches or departments. If you have evidence, I again ask you to provide it.

    Metaphorically speaking, this is like judging a library’s entire collection based on a single book. Just as a library houses a multitude of books with different themes and purposes, the government comprises diverse entities with unique practices and reasons for their operational procedures. Making sweeping generalizations without considering the individual nuances of each entity is like judging an entire library by a single book on its shelf.




  • No. It’s does make sense, as cases of attacks outside of business hours are harder to deal with because employees are off work. This is further supported by the fact that cybercriminals target websites most especially during off hours and holidays as it buys them more time before they’re discovered. Turning off the servers outside of business hours would effectively prevent this attack vector, at the cost of profit margins.

    Most businesses understand that this is a vulnerable period of time and is why most of them mandate that their IT & cybersecurity professionals must stay on call even if they’re taking time off.