Avatar from Dicebear.

  • 10 Posts
  • 62 Comments
Joined 10 months ago
cake
Cake day: September 14th, 2025

help-circle



  • open source has run for thirty years on a basis the textbook says cannot hold. It looks more like several arrangements overlaid on each other, part gift economy, part shared infrastructure, part public archive, part reputation system, with no single mechanism carrying it.

    If this kind of shit had been scribbled in the margins of my economics textbook, I would’ve paid more attention in class.





  • Turn off the issues tracker and the pull requests or deploy a bare git server for releasing your code. Find a small group of people you really know and trust and work with them on projects, or do it completely alone.

    You don’t need to allow strangers to invade your space. You don’t need a performative Code of Conduct or an LLM policy. Open source doesn’t need to be developed openly for it to be “open source”.

    Write code. Make things you like. Use any tools you want. Do code drops at 2am on Christmas day. Whatever you do, don’t get tricked into running an operation that’s half tech incubator and half daycare for people whose parents gave them a keyboard and no social skills.

    I like this “my workshop has glass walls, but I’m wearing headphones and the doors are locked” model of open source.









  • In a public update, developer Mounir Idrassi reported the account was shut down without warning, explanation, or an apparent appeal process.

    “I have encountered some challenges but the most serious one is that Microsoft terminated the account I have used for years to sign Windows drivers and the bootloader. This termination impacts my work beyond VeraCrypt and has consequences for my daily job. Currently I’m out of options.”

    This is significant because VeraCrypt is a cross-platform encryption application for Windows, macOS, and Linux. On Windows, it supports system encryption features that require signed components, including drivers and the bootloader.

    According to Idrassi, the account termination prevents the project from continuing its standard Windows signing process. Independent reporting indicated that losing signing access could stop VeraCrypt from releasing updated Windows builds before a certificate-related deadline, potentially causing boot issues for some users with system encryption enabled.

    In other words, if you’re a Windows user who uses VeraCrypt, you have reason to be concerned. In the newly surfaced GitHub issue, the reporter says VeraCrypt’s DcsBoot.efi appears to be signed through the Microsoft Corporation UEFI CA 2011 chain and warns that this will stop working on June 27, 2026. The issue also says that on some Windows 11 systems, this could trigger Secure Boot warnings or even cause the boot option to be ignored.

    So, if VeraCrypt cannot restore its Windows signing path or ship updated signed components in time, the project could face a real Secure Boot-related deadline on affected systems.

    Emphasis mine










  • For the same reason I wouldn’t trust a car designed with the help of AI:

    I would be concerned that the internals have the equivalent of a sixth finger. In a picture, that’s fairly harmless, but I’m not giving my personal information to a six-fingered hand if I don’t have to.

    Maybe if the designer has a solid track record independent of AI, and the AI’s contributions were strictly monitored and checked by humans. But then… why would you use AI?