nostr users hate sophistry

i had a really serious grumpy outburst at my colleague last night related to the sophistic documentation of the Internet Computer Protocol's authentication systems

there is a file that their blockchain client, used to deploy smart contracts, creates on your disk, that is a .pem.encrypted file

they say "something something under the hood something our purposes something something"

which is complete bullshit, and if the code of this thing is open source then i can go and find out exactly how it gets there

i'm not gonna waste my time reading their code, i'm just gonna impute the logical conclusion: they send a cookie, that they encrypt so the contents cannot be read by you if your dev machine is breached, and that it's a COOKIE

the way the text reads in the documentation, makes it sound like it's authentication

and apparently, it seems that if you do leak that file, someone else can take control of the resource you deployed (the smart contract) and spend all the assets tied to that resource on your behalf

which is AWFUL security and a classic example of the kind of shitcoin sophistry that grinds my gears so bad i yell at my colleague for not getting it that they are LYING and pretending that's ok

it's not ok, this kind of behaviour is disgusting, and it just shows you some of the flaws underlying the psychology of some parts of the dev community, who think they are so clever they can gloss over critical security mechanisms and that everyone is just gonna be like the guard soldier being told "these are not the droids you are looking for" no, these are the droids, and you bitches are trying to trick me

suffice it to say, the entire purpose of my meeting with said colleague was precisely to add code to the smart contract that functions to give total control to the deployer to add administrators and whitelisted users, and block all other access

Reply to this note

Please Login to reply.

Discussion

No replies yet.