Show newer

It's illegal to enter buildings in the zone as most of them are completely unstable, and due to a new zone administration there's typically no bribing your way out of a situation. Sometimes in the most unsuspecting places you may find street art left behind by a Stalker who risked arrest for something many will never see. Somewhat of a real life Easter egg, or a subtle nod to defiance: "You're not suppose to be here."

Location: Chernobyl Exclusion-zone, Ukraine. 2019.

#theCartographer

@Argus@mastodon.technology Climatological forecasting is a very complex thing there and aiming at different analyses and based on different settings, you get vastly different outcomes. I.e., what should the map exactly show?

Now with some tech savvy, you might want to take a look at Climatological Copernicus services of EU: climate.copernicus.eu/

The website provides access to historical datasets and climatological models and also allows you to create your own analyses using Python/Jupyter notebooks. Have a look here: cds.climate.copernicus.eu/tool

Using this, you can create your own specific forecasts and maps. Just create an account, go to the Data Toolbox and open one of the apps and play.

In my circles, there are now many non-tech friends/acquaintances who newly woke to the reality of privacy issues and are now attempting to flee WhatsApp because the bad big corp can snoop on them.

Now these are the same people who use Gmail as their primary (and often the only) e-mail provider!

Technically speaking, in the case of WhatsApp, if we should believe FB, only the metadata is leaked to the bad corp, as the content is encrypted. Bad enough. The purpose is behavioural profiling and selling advertisement.

Now, in the case of Google, you give them metadata AND the content and the purpose is the same: behavioural profiling and selling adverts.

What an irony.

> For all but the most self-deluded, identifying why we feel a certain way is not an insurmountable challenge.
> -- [Mariella Frostrup/The Guardian](theguardian.com/lifeandstyle/2)

@skells

> Using hardened comms for politically sensitive stuff is a good stopgap but we need to be more ambitious and inclusive to deny "soft surveillance" to would-be social engineers

Absolutely. As engineers, we however need to understand that there's a balance between privacy and convenience. Most people fall for convenience first, privacy later. I.e., we need to make privacy convenient.

@academicalnerd @mathias

@academicalnerd @mathias So I tested this and it works really well.
1. when you chat with somebody who does not use delta chat, they receive a plain e-mail and can respond
2. when you speak to somebody with delta chat, the clients exchange public gpg keys and everything they send will be encrypte with Autocrypt
3. works via IMAP(+push)+SMTP/SSL
4. uses a separate IMAP folder called Deltachat. Stuff inside is encrypted, all comms are there. Including read notifications. I checked the raw data, it's just standard GPG block with extra e-mail headers.
5. I think this is absolutely cool piece of tech.

@academicalnerd @mathias BTW, recently there was this chatter about Delta Chat flying around here. Go and check out delta.chat/en/. I find it so intriguing. Implemented via existing e-mail channels, i.e., SMTP (and IMAP?). No phone numbers, no central servers, no nothing. You can directly speak anybody via their e-mail, even if they never heard about delta chat, it's all encrypted (as e-mails in transport), etc. Since I found out about it, I wonder **"how come nobody came up with this idea before?!"** It's just so obvious... Hidden in plain sight. I am really intrigued... Need to check out.

@academicalnerd @mathias I was thinking today about the fact that encrypted e-mail still leaks metadata. This is an acceptable risk in business where it's typically public with whom you trade, but you need to exchange trade secrets, i.e., content. Leaking metadata is problematic in 2 contexts: against corporates which build your profile and and against state actors. I find it somewhat amusing that plenty (if not most) people who want to protect their privacy and are fleeing WhatsApp still use gmail accounts all the time 😂.

Anyway, I am digressing. What I wanted to say is this: it's probably fair to say that GPG encrypted e-mail is about the same level of privacy as WhatsApp. You don't leak content, but you leak metadata. Now the questions is "to whom?". In the case of e-mail potentially to state actors (filtering traffic and illegal access to servers). In the case of WhatsApp, it's to FB AND US govt et al, i.e., selected state actors (let's not be naive, we need to assume that FB cooperates). If you use Gmail, the same.

To finish off this rant, I have a feeling that using WhatsApp might not be actually too bad in the end. I rather leak my metadata to US govt than to Chinese.

Of course this is all somewhat incoherent late Friday stuff, anyway, I am in a mood to rant a bid :-).

# Earth Harp

![](i.ytimg.com/vi/qrjcOpq_Nw0/mqd)

Earth Harp: It is a musical instrument where free floating strings anchored at long distances on building, or a canyon. It's the world's longest instrument. Ther anchor it on landscapes and architecture to play.

It's so large that the audience is effectively inside the instrument.

William Close is the guy who invented this instrument.

bbc.com/news/av/entertainment-

earthharpsymphony.com/

youtube.com/watch?v=qrjcOpq_Nw

@academicalnerd

Indeed, you are right. But you shall do a proper threat/risk analysis. For instance, there's this problem: with PGP/GPG your e-mail is encrypted in transport, but then you read it on a potentially compromised machine. I find the most annoying thing with encrypted e-mail that I cannot search in it (I do search in my mailbox 20 years back quite often). Finally, often the metadata is more damning than the content: "hey, so you communicated with that and that criminal? Ahaa!" - and I am not going to look up that xkcd comic with the wrench, you saw it, I am sure ;-).

It seems to me, for really really politically sensitive comms, I would think deeply about the whole transport chain and I would not let the thing even touch my e-mail - like never even touch 1) my domains (ideally not even country TLD which can be associated with me), 2) certainly not any SMTP/IMAP servers associated with me, 3) not even any direct connection with my own computer. And I would care deeply about whether the message is persistent (bad!) or ephemeral (good!). In this sense, maybe Tor+anonymous Protonmail account - if it must be e-mail, or ideally some ephmeral anonymous snapchat stuff could work better than e-mail. Simply: go the Snowden way.

@mathias

@mathias My experience too. Between 2000-2003 almost all my work e-mail were encrypted. Since I left that place, only encrypted e-mails I sent/received were passwords sent around. And since we have encrypted channels in Element/Matrix, not even that is a use case for e-mails anymore.

I however use my GPG keys extensively for 1) signing my e-mails - I find that extremely appealing, especially in business context; and 2) `ssh` keys (I use GPG key on a Yubikey with `ssh-agent` for access). But encrypted e-mails? Not really any more...

A reference to lean start-up way of doing things in another thread reminded me of this.

BTW, rakhim.org guy has some very good comics drawings. Recommended!

@qrsbrwn

> a great deal of resources could be saved by designing decentralised services from the start

I wish it to be that way too. But trying to do that, I recognise that good decentralised (or generally weakly coupled) technical solutions *always* take the structure of the social interactions around them (as in: is monorepo good for your company, or a multi-repo? depends on how your teams communicate! it holds in software, it holds in urban planning, in architecture, in health-care, everywhere). Now that would suggest that we shall simply analyse and understand how people interact and then build a technical solution to fit it. Unfortunately, it's often impossible because how people interact is not always how 1) they think they interact, and/or 2) they wish to interact. So top-down solutions for such systems rarely work. Personally, I prefer here more the lean-startup way of doing things: 1) do something (MVP), don't care that it's bad, 2) discover the problems it creates, 3) fix the problems on both sides (human, as well as tech), goto 1 - until you either badly fail, or you find an equilibrium point. Is it wasteful? Absolutely? Does it have a higher likelihood of success than a waterfall design? Yes.

> We need to realise that we have most of the work ahead of us.

Can't agree more. But that makes life exciting too 😉 .

@jwildeboer

@mathias So when did you receive an encrypted e-mail (for a good reason, not just a joke) the last time? Or in other words, how many did you receive last year?

@mithrandir BS!

> Everybody is good at writing!
> -- me, now

Really, you have probably too high standards on your writing. This kind of a writer's block typically comes from you trying to "write it really well" right away - typically with external audience in mind. Forget it. The best advice I ever got on this topic was: just write it down in plain language as it comes. Then, but only if needed, rewrite, rewrite, rewrite until it's better. But never aspire to write down well on the first attempt. You get only analysis paralysis.

> "Finished is better than ferpect"
> -- some colleague of mine paraphrasing stuff like lifehacker.com/the-done-manife

@jwildeboer @qrsbrwn

I took some time to respond and reread your replies. Really, I think we need to consider the overall dynamics of such initiatives and visions and smart cities. Technology is only one aspect of the vision here. Of course the cost drivers lead to centralised solutions, just because engineers "can". Quickly, however, these visions bump into regulatory and law obstacles, which will lead to redesigns, new experiments, new clashes with law and society at large and so on until the public discourse settles on a mutually acceptable solution. I am personally not disturbed, at least not yet.

You might take me for an optimist, but let's take some recent examples. For instance roll-out of smart-grid and smart-meters in the Netherlands and UK (afaik). 1) Initially a strong thrust towards the roll-out, inducing 2) a strong push-back by the society and 3) leading to slow-down and almost stop of the roll-out, towards finally 4) resolving the privacy issues, opt-out policies, etc. and continuation. Another example are self-driving cars (if that vision comes to fruition in our lifetimes at all - it's reasonable to doubt that), or UAVs. Or for instance consider how whatever privacy intruding tech inevitably clashes with German privacy laws and always loses along the way - just because law does not give a damn about tech and trumps tech in the long run (BTW, a very frustrating observation for me as a hi-tech/R&D oriented person).

The bottom-line is this: while technology is capable of fast advancements towards cheap, but _not-so-good_ centralised solutions, the process of its clashing it with the society at large is good and leads to better long-term outcomes. Certainly better than making tech win - as they do by design in China.

My perception of the worries you two expressed is that in the whole process and societal discourse, we arrived at a point where the clash of tech and societal values is becoming apparent. So we get nervous. But I have trust in a good resolution of it, most (if not all) past precedents indicate we are well equipped to solve it well. And again, whatever visions of smart cities/villages entail, these are just prototypes and experiments at this point, nothing permanent. The Technology Readiness Level of this stuff is still frustratingly low (as I said, somewhere like 3-6, locally we are reaching 6-ish in few selected areas).

You also say, we should have a discussion about privacy 20 years ago and in result nation states and corporations are putting us under mass surveillance. Let's put states aside, we have a strong say in how that plays out in the long run (elections). As for corporations, that is inevitable and it is the role of states to regulate it. Personally, I see it happening: c.f., EU vs. big tech. Is it optimal from inception? No. Do corporations abuse their positions in short-term (e.g., a decade)? Yes. Do they get corrected in the long-run? From my vantage point the answer is yes. Would we like it to work faster? Absolutely. But I accept that that that is the nature societal processes - they take time, like years to settle. They are largely decentralised and emergent, rather than designed.

P.S. Sorry for my lengthy rant. These topics are exciting and interesting, but always lead me off-topic :-).

Show older
CleverLibre Social

CleverLibre Social is an inclusive social instance for open discussion, learning, and community.
All cultures welcome.
Hate speech and harassment strictly forbidden.