In all honesty I think this is an unfair characterization. I've listened to his podcast for a fair number of years and I think you're exaggerating quite a bit.
Mostly the episodes are specific topics with a guest who's area of research/specialty is the topic and which stay pretty well on-topic.
Most of the AMA episodes are in the area's where Carroll specialize: physics and philosophy of science. It -occasionally- veers off into politics or basketball, but it's nowhere close to 51% politics and basketball. I think the most recent AMA did have more basketball than usual, and admittedly more than I like. And I am not a fan of his politics nor do I consider his political positions especially thoughtful or insightful. But those diversions are more occasional distractions than some majority of the AMA content. And in a 3+ hour Q&A format its not surprising that he's asked about those areas where his regular listeners know that he has a particular interest or position.
Germany also has a crazy Communist party that is more in the pocket of Russia than AfD is -- but somehow that is almost never mentioned, not even in German media. It's quite big and influential.
I think you've got the right idea, though in practice the initial "authentication" question (you are who you say you are) is very closely linked to the initial "authorization" evaluation (can you enter).... because in most systems the only "can you enter" authorization required for access is in fact that you are who you say you are.
But not all systems work this way. There are some systems where you can log in successfully, but then are immediately escorted out because the "can you enter" question has secondary considerations or is decided once identity has been established based on a larger criteria. Expired accounts in some systems work exactly like this.
One problem is that treating authentication as a "can you enter" authorization is predicated on the idea of a session-based system with two states, logged in or logged out. But there are many scenarios where e.g. taking some particular action requires authn and authz, regardless of login status. A simple example is performing some destructive action.
The distinction between authentication and authorization allows modeling of many different kind of systems, including the degenerate case where identification is treated as a proxy for authorization.
Btw, the kind of thinking behind that degenerate case is what leads to IDOR security bugs - "this person is logged in, so they can access whatever the URL says... even if it's another customer's data!" It turns out that thinking clearly about security helps be more secure, and unfortunately, vice versa.
Right. The de facto/apparent case that many users encounter shouldn't be considered the correct mental model or implementation pattern... it just explains why some people see it that way.
Not long ago I designed an authentication system which had to be disconnected from authorization pretty fully. The authentication was global in a multi-tenanted system, but access to any tenant was authorized at the tenant level (as well as all other authorization concerns). To be fair, there was some global authorization concerns, but the vast majority of authorizing actions, including tenant access was governed at the tenant level after authentication.
"Can do" and "can do easily" or "can do with minimal friction" aren't the same.
I use JJ locally and for those that call it a "porcelain" or a "git UI" are missing a lot. Sure you can use it that way, but what I've found is that it facilitates (and perhaps encourages) a pretty different workflow than I'd use with just plain Git. I could pull off what I do in JJ in just plain Git... but it wouldn't at all feel natural and you can really see this when you start using a JJ driven repository with Git tools (including just the Git command line tools).
Personally, and as a mere version control user, I prefer the JJ model of version control much more than Git's. The mechanics of the UI was very easy to get under my fingers (the essentials in about a day), but getting the ideas and really getting an understanding/appreciation for the conceptual differences and their ramifications on workflow took a month or two of regular working and trying things. For me, it was worth the effort.
I very first got into programming by trying to fix a graphic adventure game that somehow was released with a pretty clear syntax error. This was back in the VIC-20 days. Really, for the first while it was about the games ... tweaking them, altering them, and later writing them.
The actual programming was always a means to that gaming end back then and not the end in itself. So in that sense I can completely relate to where you're coming from.
Over a couple years of that, it started to dawn on me that the programming itself had a power and interest all its own worth pursuing.
But I think if it was dropped in front of me as something I ought to do, no matter how dressed up in "fun" it was, it would have set off my non-conformist predispositions a little too much.
What's different is that I found the journey can be just as interesting and engaging as the destination. I read papers, books, and even spend time around here... not because the solutions require it, but because I care about the craft and the process itself.
So yes, the resulting solution is the prime mover, but the process of finding the solutions is no longer just a means to the end, it's part of the motivation of being involved in the profession at all.
I habitually complain about government... so let me help you out with this.
The original issue with the law was never that those poor open source developers were going to have to bear the burden of complying with the law, but that the law itself was a bald-faced invasion of privacy by an overbearing troupe of people in power (i.e., government) so shit-sure of their superiority over the simple common folk they govern (i.e., you and me) that they aren't even embarrassed by their own arrogance.
I would suggest that what "we wanted" is no such law at all. What would be weird, and worthy of comment, is if those of us that complain about government were actually satisfied by an exemption which only applies to pretty damn tiny slice of the market. If anything, that wasn't a victory for privacy or common sense, but rather a concession that they had foolishly created a law that they wouldn't have been able to enforce as broadly as they thought they could get away with... or if they tried to enforce it they'd have to contend with the optics of the big hand of government yet again crushing individuals whose only real crime was their altruism rather than just some giant corporation.
So it isn't weird at all that "we're" silent. This isn't a win. Pointing out that the law had unintended consequences, including with Linux, et al., wasn't a statement of objective but rather a simple show that the law was rife with thoughtless unintended, or perhaps simply unspoken, consequences. The legislature's act here didn't restore privacy nor did it remove bad outcomes: if anything it now just raises questions about equal protection under law, at least on some practical level. It raises the question why some users of computers need such protections as age verification and others don't, and why the licensing terms of the OS are a valid proxy for that need... taking for granted that the stated purposes of the law are the real ones, of course.
Yes and the burden of proof standard is typically lower in a civil case than it is in a criminal proceeding. So a prosecutor may very legitimately not bring a criminal case if they feel they can't meet the "beyond a reasonable doubt" standard, but the same evidence brought in civil court could very well win the day. So the civil suit path could still be a deterrent to bad behavior if not so severely throttled.
> Cops can still be prosecuted for behavior that is a constitutional violation and outside the scope of what a normal cop would consider reasonable.
[edit: I didn't correctly read the comment I was replying to, which was talking about prosecutions, not civil suits. But I do believe that qualified immunity is still largely an issue with Flock, so I'm not retracting the comment entirely.]
So long as there is already an established legal precedent for the rather specific circumstances at stake, then yes, that's true. But that has to be demonstrated in pre-trial motions because the default is qualified immunity is grounds for dismissal of the case prior to any judgement on the facts absent such a clear cut applicability of precedence. Sure, you could appeal the dismissals... but that's quite a barrier and burden just to get to having a case heard let alone then having to try the case in question.
Consider this quote from the 9th District Court of Appeals' opinion on a qualified immunity appeal:
"The panel held that at the time of the incident, there was
no clearly established law holding that officers violate the
Fourth or Fourteenth Amendment when they steal property
seized pursuant to a warrant. For that reason, the City
Officers were entitled to qualified immunity. The panel
reasoned that although the decision in Brewster v. Beck,
859 F.3d 1194 (9th Cir. 2017) was instructive on the
question of whether the theft of property covered by the
terms of a search warrant, and seized pursuant to the warrant,
violates the Fourth Amendment, Brewster’s facts varied in
legally significant ways from those in this case. Moreover,
the panel noted that the City Officers seized Appellants’
property in 2013, prior to the Brewster decision in 2017. The
panel held that although the City Officers ought to have
recognized that the alleged theft was morally wrong, they did
not have clear notice that it violated the Fourth Amendment.
The panel further held that the Fourth Circuit’s unpublished
decision in Mom’s Inc. v. Willman, 109 F. App’x 629, 636–
37 (4th Cir. 2004)—the only case law that the time of the
incident holding that the theft of property pursuant to a
warrant violates the Fourth Amendment—did not put the
“constitutional question beyond debate.”"
> I know it's unpopular but I went from not supporting these sorts of systems to embracing them after seeing the positive effects in China.
Any police state can absolutely achieve a low rate of crime: both those crimes that even those of us that embrace individual rights want to see stopped but also those crimes that us liberal types would consider exercise of rights.... but are definitely crimes in China.
The problem is, you can't stop the real, mutually agreed crime with tools like this without endangering the elimination of legitimate individual rights.
In more liberal societies, this means we have real barriers for evidence collection and usage which absolutely let some universally recognized bad guys get away... because those barriers help ensure that the law doesn't become a tool against the merely politically inconvenient opposition members who properly should be able to speak out against the powerful.
If you had a perfectly objective government filled with dispassionate people dedicated to their legitimate role of protecting the rights of the citizenry... perhaps there wouldn't be any issue. But when you have people that decide to turn their opponents into criminals only because of their opposition or questionable loyalty.... No thank you... you can stay in China if that's the kind of society you're willing to accept.
From what I've seen... I think if I were writing business applications, I'd reach for Elixir... if I were writing something lower level like communication software, I'd reach for Erlang.
I have written a fair amount of Elixir (and targeting business applications) and I think Elixir's expressiveness lends itself well to making more abstract models of the business processes and data seen in solving business problems. However, writing Elixir I find you end up reading a lot of Erlang and in certain problem spaces I could imagine the appeal over Elixir. I could absolutely see where if I were writing more technically oriented programs.... programs closer to the hardware in some ways or programs designed to communicate with other programs (protocols, etc.) I could see Erlang as being a more clear and direct language in these circumstances.
All of this is very hand-wavy, but it's my impression.
Mostly the episodes are specific topics with a guest who's area of research/specialty is the topic and which stay pretty well on-topic.
Most of the AMA episodes are in the area's where Carroll specialize: physics and philosophy of science. It -occasionally- veers off into politics or basketball, but it's nowhere close to 51% politics and basketball. I think the most recent AMA did have more basketball than usual, and admittedly more than I like. And I am not a fan of his politics nor do I consider his political positions especially thoughtful or insightful. But those diversions are more occasional distractions than some majority of the AMA content. And in a 3+ hour Q&A format its not surprising that he's asked about those areas where his regular listeners know that he has a particular interest or position.
reply