<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>Yarmo - rants</title>
    <subtitle>Blog of an Open Source developer</subtitle>
    <link rel="self" type="application/atom+xml" href="https://yarmo.eu/tags/rants/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://yarmo.eu"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2020-07-31T11:13:30+00:00</updated>
    <id>https://yarmo.eu/tags/rants/atom.xml</id>
    <entry xml:lang="en">
        <title>Flipper Zero and their &quot;Limited&quot; pledges</title>
        <published>2020-07-31T11:13:30+00:00</published>
        <updated>2020-07-31T11:13:30+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yarmo.eu/blog/flipper-zero-limited/"/>
        <id>https://yarmo.eu/blog/flipper-zero-limited/</id>
        
        <content type="html" xml:base="https://yarmo.eu/blog/flipper-zero-limited/">&lt;h2 id=&quot;The_Flipper_Zero_project&quot;&gt;The Flipper Zero project&lt;&#x2F;h2&gt;
&lt;p&gt;I&#x27;m not going to lie, Flipper Zero sounds like a cool project for hackers. Here&#x27;s a &lt;a href=&quot;https:&#x2F;&#x2F;flipperzero.one&#x2F;zero&quot;&gt;link to their website&lt;&#x2F;a&gt; which will lead you to their Kickstarter page.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;What_is_going_on_on_Kickstarter?&quot;&gt;What is going on on Kickstarter?&lt;&#x2F;h2&gt;
&lt;p&gt;Something extremely scummy is going on right now! Have a look:&lt;&#x2F;p&gt;
&lt;p&gt;&lt;img src=&quot;&#x2F;img&#x2F;blog&#x2F;kickstarted_counter__1a.png&quot; alt=&quot;Flipper Zero Kickstarter&quot; &#x2F;&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Looking good, lot&#x27;s of stuff to read, let&#x27;s take our time.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;img src=&quot;&#x2F;img&#x2F;blog&#x2F;kickstarted_counter__1b.png&quot; alt=&quot;Flipper Zero Kickstarter&quot; &#x2F;&gt;&lt;&#x2F;p&gt;
&lt;p&gt;My word, they&#x27;re almost out of Early Birds! Please, for the love of god, if you want to save some money, pledge now, only 9 left and it clearly says &amp;quot;Limited&amp;quot;!&lt;&#x2F;p&gt;
&lt;h3 id=&quot;One_minute_later&quot;&gt;One minute later&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;img src=&quot;&#x2F;img&#x2F;blog&#x2F;kickstarted_counter__2.png&quot; alt=&quot;Flipper Zero Kickstarter&quot; &#x2F;&gt;&lt;&#x2F;p&gt;
&lt;p&gt;A person has just pledged! Where&#x27;s my credit card?&lt;&#x2F;p&gt;
&lt;h3 id=&quot;Another_minute_later&quot;&gt;Another minute later&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;img src=&quot;&#x2F;img&#x2F;blog&#x2F;kickstarted_counter__3.png&quot; alt=&quot;Flipper Zero Kickstarter&quot; &#x2F;&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Wait, 9 left? Someone bailed? Doesn&#x27;t matter, I need this!&lt;&#x2F;p&gt;
&lt;h3 id=&quot;Yet_another_minute_later&quot;&gt;Yet another minute later&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;img src=&quot;&#x2F;img&#x2F;blog&#x2F;kickstarted_counter__4.png&quot; alt=&quot;Flipper Zero Kickstarter&quot; &#x2F;&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Wait, what?&lt;&#x2F;p&gt;
&lt;h3 id=&quot;And_it_goes_on&quot;&gt;And it goes on&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;img src=&quot;&#x2F;img&#x2F;blog&#x2F;kickstarted_counter__5.png&quot; alt=&quot;Flipper Zero Kickstarter&quot; &#x2F;&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;And_on&quot;&gt;And on&lt;&#x2F;h3&gt;
&lt;p&gt;&lt;img src=&quot;&#x2F;img&#x2F;blog&#x2F;kickstarted_counter__6.png&quot; alt=&quot;Flipper Zero Kickstarter&quot; &#x2F;&gt;&lt;&#x2F;p&gt;
&lt;h2 id=&quot;This_needs_to_stop&quot;&gt;This needs to stop&lt;&#x2F;h2&gt;
&lt;p&gt;Well, you get the point. Flipper Zero is having some employee continuously adding more &amp;quot;Limited&amp;quot; pledges to perpetually give the impression they are almost out of &amp;quot;Early Bird&amp;quot; kits.&lt;&#x2F;p&gt;
&lt;p&gt;That&#x27;s extremely deceptive and manipulative behavior and should not be tolerated. This needs to stop right now.&lt;&#x2F;p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>State of the Keybase.io website</title>
        <published>2020-07-03T15:23:38+00:00</published>
        <updated>2020-07-03T15:23:38+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yarmo.eu/blog/keybase-website/"/>
        <id>https://yarmo.eu/blog/keybase-website/</id>
        
        <content type="html" xml:base="https://yarmo.eu/blog/keybase-website/">&lt;h2 id=&quot;Disclaimer&quot;&gt;Disclaimer&lt;&#x2F;h2&gt;
&lt;p&gt;Two days ago, I launched &lt;a href=&quot;https:&#x2F;&#x2F;keyoxide.org&quot;&gt;Keyoxide.org&lt;&#x2F;a&gt; which provides a few similar functions as &lt;a href=&quot;https:&#x2F;&#x2F;keybase.io&quot;&gt;Keybase.io&lt;&#x2F;a&gt; but in an Open Source package. I&#x27;ve been wanting to write this post for a while but felt it could be perceived as disingenuous if posted before making my own project public. Therefore, I post this now.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;TLDR&quot;&gt;TLDR&lt;&#x2F;h2&gt;
&lt;p&gt;The Keybase.io website uses non-optimized resources resulting in a slow pageload and 5+ year old versions of libraries with known and public security vulnerabilities.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;The_Keybase.io_website&quot;&gt;The Keybase.io website&lt;&#x2F;h2&gt;
&lt;p&gt;I have opinions about the Keybase service, but this post is not about that. This is about the facts behind their website, &lt;a href=&quot;https:&#x2F;&#x2F;keybase.io&quot;&gt;Keybase.io&lt;&#x2F;a&gt; and more specifically their &lt;a href=&quot;https:&#x2F;&#x2F;keybase.io&#x2F;encrypt&quot;&gt;encrypt&lt;&#x2F;a&gt; page, the one you use to &lt;strong&gt;encrypt private and confidential messages&lt;&#x2F;strong&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;When you load that specific page, make sure to load it in a private session or window to eliminate cached resources. What do you notice?&lt;&#x2F;p&gt;
&lt;p&gt;It is slow. Really slow. I noticed so too and decided to run a &lt;a href=&quot;https:&#x2F;&#x2F;www.webpagetest.org&#x2F;result&#x2F;200627_0Q_044080ef3ab8a678721658c90d2f4706&#x2F;&quot;&gt;Webpagetest (link to result)&lt;&#x2F;a&gt;. Out of three runs, we analyze only the median run (so not the best one, not the worst one).&lt;&#x2F;p&gt;
&lt;p&gt;&lt;img src=&quot;&#x2F;img&#x2F;blog&#x2F;keybase_encrypt__wpt_overview.png&quot; alt=&quot;Keybase encrypt Webpagetest overview&quot; &#x2F;&gt;&lt;br &#x2F;&gt;
&lt;em&gt;keybase.io&#x2F;encrypt&lt;&#x2F;em&gt;&lt;&#x2F;p&gt;
&lt;h2 id=&quot;The_content_loaded&quot;&gt;The content loaded&lt;&#x2F;h2&gt;
&lt;p&gt;It takes &lt;strong&gt;6.25 seconds&lt;&#x2F;strong&gt; to fully load the &lt;strong&gt;2.9 megabytes&lt;&#x2F;strong&gt; that are used on this page. That is hefty for a page that is essentially a single form. I mean, look at it:&lt;&#x2F;p&gt;
&lt;p&gt;&lt;img src=&quot;&#x2F;img&#x2F;blog&#x2F;keybase_encrypt.png&quot; alt=&quot;Keybase encrypt page&quot; &#x2F;&gt;&lt;br &#x2F;&gt;
&lt;em&gt;Why 2.9 megabytes?&lt;&#x2F;em&gt;&lt;&#x2F;p&gt;
&lt;p&gt;That&#x27;s a regular web form. What could possibly be &lt;strong&gt;2.9 megabytes&lt;&#x2F;strong&gt;? The javascript?&lt;&#x2F;p&gt;
&lt;p&gt;&lt;img src=&quot;&#x2F;img&#x2F;blog&#x2F;keybase_encrypt__wpt_1.png&quot; alt=&quot;Webpagetest run 1 overview&quot; &#x2F;&gt;&lt;br &#x2F;&gt;
&lt;em&gt;How many requests? How many bytes?&lt;&#x2F;em&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Most requests are fonts. That makes sense. Earlier, we saw the page only makes &lt;strong&gt;12 requests&lt;&#x2F;strong&gt;, so I could imagine a few of those being several fonts files. Fortunately, fonts are only &lt;strong&gt;6.5%&lt;&#x2F;strong&gt; of the bytes loaded, so we&#x27;ll forgive them.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;90 percent&lt;&#x2F;strong&gt; of the bytes are due to javascript and images‽ That&#x27;s &lt;strong&gt;2.6 megabytes&lt;&#x2F;strong&gt; for a form! What images?&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Javascript_and_image(s)&quot;&gt;Javascript and image(s)&lt;&#x2F;h2&gt;
&lt;p&gt;Let&#x27;s grab the &lt;a href=&quot;https:&#x2F;&#x2F;www.webpagetest.org&#x2F;result&#x2F;200627_0Q_044080ef3ab8a678721658c90d2f4706&#x2F;1&#x2F;details&#x2F;#waterfall_view_step1&quot;&gt;waterfall&lt;&#x2F;a&gt; and see what is going on:&lt;&#x2F;p&gt;
&lt;p&gt;&lt;img src=&quot;&#x2F;img&#x2F;blog&#x2F;keybase_encrypt__wpt_1_waterfall.png&quot; alt=&quot;Webpagetest run 1 waterfall&quot; &#x2F;&gt;&lt;br &#x2F;&gt;
&lt;em&gt;Run 1 waterfall&lt;&#x2F;em&gt;&lt;&#x2F;p&gt;
&lt;p&gt;At two points in time, the loading of the website stalls. The first stall is &lt;strong&gt;2.6 seconds&lt;&#x2F;strong&gt; for the file &lt;code&gt;sitewide-js.js&lt;&#x2F;code&gt;. The second stall is &lt;strong&gt;2.5 seconds&lt;&#x2F;strong&gt; for the file &lt;code&gt;footprints_transp.png&lt;&#x2F;code&gt;. Let&#x27;s go.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;sitewide-js.js&quot;&gt;sitewide-js.js&lt;&#x2F;h2&gt;
&lt;p&gt;This file is &lt;strong&gt;4.7 megabytes&lt;&#x2F;strong&gt; raw and &lt;strong&gt;1.2 megabytes&lt;&#x2F;strong&gt; gzipped. Let us look at a random excerpt:&lt;&#x2F;p&gt;
&lt;p&gt;&lt;img src=&quot;&#x2F;img&#x2F;blog&#x2F;keybase_encrypt__js_excerpt.png&quot; alt=&quot;Javascript excerpt&quot; &#x2F;&gt;&lt;br &#x2F;&gt;
&lt;em&gt;Javascript excerpt&lt;&#x2F;em&gt;&lt;&#x2F;p&gt;
&lt;p&gt;This is not really optimized for performance: one could choose to minimize the javascript. Allow me to use &lt;code&gt;@node-minify&#x2F;cli&lt;&#x2F;code&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;code&gt;JS_Parse_Error [SyntaxError]: Unexpected token: name «syms», expected: punc «;»&lt;&#x2F;code&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Hmm… Let&#x27;s remove that one line which simply initializes a variable (only fix I could find). I can no longer guarantee it works but let&#x27;s assume it does.&lt;&#x2F;p&gt;
&lt;p&gt;Old version: &lt;strong&gt;4.7 megabytes&lt;&#x2F;strong&gt; raw and &lt;strong&gt;1.2 megabytes&lt;&#x2F;strong&gt; gzipped.&lt;br &#x2F;&gt;
New version: &lt;strong&gt;2.5 megabytes&lt;&#x2F;strong&gt; raw and &lt;strong&gt;0.7 megabytes&lt;&#x2F;strong&gt; gzipped.&lt;&#x2F;p&gt;
&lt;p&gt;First win!&lt;&#x2F;p&gt;
&lt;p&gt;Well, I need to specify one thing: the website loads a gzipped version of the original file at a size of &lt;strong&gt;1.23 megabytes&lt;&#x2F;strong&gt;. When I &lt;code&gt;gzip&lt;&#x2F;code&gt; it on my local machine, the original file even becomes &lt;strong&gt;1 megabytes&lt;&#x2F;strong&gt;. I don&#x27;t know what causes this discrepancy, but while we were able to reduce the raw files by 2.2 megabytes, the reduction could only become 0.3 megabytes once gzipped (on my machine™).&lt;&#x2F;p&gt;
&lt;h2 id=&quot;footprints_transp.png&quot;&gt;footprints_transp.png&lt;&#x2F;h2&gt;
&lt;p&gt;Have you found the image yet? It&#x27;s the little image at the bottom of the dog (?) following footprints. Cute :)&lt;&#x2F;p&gt;
&lt;p&gt;&lt;img src=&quot;&#x2F;img&#x2F;blog&#x2F;keybase_encrypt__img.png&quot; alt=&quot;Footprints image&quot; &#x2F;&gt;&lt;br &#x2F;&gt;
&lt;em&gt;Footprints image&lt;&#x2F;em&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Dimensions on page: &lt;strong&gt;330 x 90 pixels&lt;&#x2F;strong&gt;&lt;br &#x2F;&gt;
Dimensions of file: &lt;strong&gt;2836 x 770 pixels&lt;&#x2F;strong&gt;&lt;&#x2F;p&gt;
&lt;p&gt;That&#x27;s only &lt;strong&gt;8.6 times&lt;&#x2F;strong&gt; larger than it needs to be. The bigger crime is the size: &lt;strong&gt;1.4 megabytes&lt;&#x2F;strong&gt;. Which is 50% of the website. You guessed it. This could be better.&lt;&#x2F;p&gt;
&lt;p&gt;Using &lt;a href=&quot;https:&#x2F;&#x2F;imagecompressor.com&#x2F;&quot;&gt;imagecompressor.com&lt;&#x2F;a&gt;, I can compress this full-sized image down to &lt;strong&gt;398 kilobytes&lt;&#x2F;strong&gt; (reduction of &lt;strong&gt;71%&lt;&#x2F;strong&gt;). And I&#x27;m even allowing the full 256 colors. And the dimensions are still &lt;strong&gt;8.6 times&lt;&#x2F;strong&gt; larger than they need to be.&lt;&#x2F;p&gt;
&lt;p&gt;Optimizing the compression and the image dimensions could yield even better results. I&#x27;m not going to bother. The devs didn&#x27;t either.&lt;&#x2F;p&gt;
&lt;p&gt;Still, second win!&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Anything_else_we_can_learn?&quot;&gt;Anything else we can learn?&lt;&#x2F;h2&gt;
&lt;p&gt;The source code contains this:&lt;&#x2F;p&gt;
&lt;pre style=&quot;background-color:#212733;color:#ccc9c2;&quot;&gt;&lt;code&gt;&lt;span&gt;~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
&lt;&#x2F;span&gt;&lt;span&gt;
&lt;&#x2F;span&gt;&lt;span&gt;                              K E Y   B A S E
&lt;&#x2F;span&gt;&lt;span&gt;
&lt;&#x2F;span&gt;&lt;span&gt;                            crypto for everyone
&lt;&#x2F;span&gt;&lt;span&gt;
&lt;&#x2F;span&gt;&lt;span&gt;                        because no one we know ever
&lt;&#x2F;span&gt;&lt;span&gt;                      seems to have a public key. :-(
&lt;&#x2F;span&gt;&lt;span&gt;
&lt;&#x2F;span&gt;&lt;span&gt;     No Google Analytics or other 3rd party hosted script tags on Keybase.
&lt;&#x2F;span&gt;&lt;span&gt;
&lt;&#x2F;span&gt;&lt;span&gt;     And this has the added bonus that we&amp;#39;ll never be able to serve ad code.
&lt;&#x2F;span&gt;&lt;span&gt;
&lt;&#x2F;span&gt;&lt;span&gt;                                    \o&#x2F;  \o&#x2F;
&lt;&#x2F;span&gt;&lt;span&gt;                                  keybase team
&lt;&#x2F;span&gt;&lt;span&gt;
&lt;&#x2F;span&gt;&lt;span&gt;  ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
&lt;&#x2F;span&gt;&lt;&#x2F;code&gt;&lt;&#x2F;pre&gt;
&lt;p&gt;I like it when devs get creative. The third paragraph is a bit alienating, but that&#x27;s my opinion.&lt;&#x2F;p&gt;
&lt;p&gt;Anything else? Given that this is all cryptography related, maybe some security related issues?&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Security&quot;&gt;Security&lt;&#x2F;h2&gt;
&lt;p&gt;&lt;img src=&quot;&#x2F;img&#x2F;blog&#x2F;keybase_encrypt__security.png&quot; alt=&quot;Webpagetest security score&quot; &#x2F;&gt;&lt;br &#x2F;&gt;
&lt;em&gt;Webpagetest security score&lt;&#x2F;em&gt;&lt;&#x2F;p&gt;
&lt;p&gt;I&#x27;ve ran quite a few webpagetests on different website, but a &lt;strong&gt;0&lt;&#x2F;strong&gt; security score is new to me. What does that even mean?&lt;&#x2F;p&gt;
&lt;p&gt;Well, &lt;a href=&quot;https:&#x2F;&#x2F;snyk.io&#x2F;test&#x2F;website-scanner&#x2F;?test=200627_0Q_044080ef3ab8a678721658c90d2f4706&quot;&gt;it turns out&lt;&#x2F;a&gt; that the entire website is built using the following libraries:&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;jquery v1.11.3 (from &lt;a href=&quot;https:&#x2F;&#x2F;blog.jquery.com&#x2F;2015&#x2F;04&#x2F;28&#x2F;jquery-1-11-3-and-2-1-4-released-ios-fail-safe-edition&#x2F;&quot;&gt;april 2015&lt;&#x2F;a&gt;)&lt;&#x2F;li&gt;
&lt;li&gt;bootstrap v3.3.5 (from &lt;a href=&quot;https:&#x2F;&#x2F;blog.getbootstrap.com&#x2F;2015&#x2F;06&#x2F;15&#x2F;bootstrap-3-3-5-released&#x2F;&quot;&gt;june 2015&lt;&#x2F;a&gt;)&lt;&#x2F;li&gt;
&lt;li&gt;moment v2.7.0 (from &lt;a href=&quot;https:&#x2F;&#x2F;github.com&#x2F;moment&#x2F;moment&#x2F;releases&#x2F;tag&#x2F;2.7.0&quot;&gt;june 2014&lt;&#x2F;a&gt;)&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;Besides the obvious aging, these libraries account for a total of six known and public security vulnerabilities, including &lt;a href=&quot;https:&#x2F;&#x2F;snyk.io&#x2F;vuln&#x2F;SNYK-JS-BOOTSTRAP-72890&quot;&gt;cross-site scripting&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;snyk.io&#x2F;vuln&#x2F;SNYK-JS-JQUERY-174006&quot;&gt;prototype pollution&lt;&#x2F;a&gt; and &lt;a href=&quot;https:&#x2F;&#x2F;snyk.io&#x2F;vuln&#x2F;npm:moment:20161019&quot;&gt;regular expression denial of service&lt;&#x2F;a&gt;. All six security vulnerabilities have remediations.&lt;&#x2F;p&gt;
&lt;p&gt;Let the &lt;a href=&quot;https:&#x2F;&#x2F;blog.getbootstrap.com&#x2F;2015&#x2F;06&#x2F;15&#x2F;bootstrap-3-3-5-released&#x2F;&quot;&gt;bootstrap v3.3.5 announcement&lt;&#x2F;a&gt; be a painful reminder: this is &lt;em&gt;pushing it&lt;&#x2F;em&gt;.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Wrapping_up&quot;&gt;Wrapping up&lt;&#x2F;h2&gt;
&lt;p&gt;This should give a nice overview of what could go wrong with a non-optimized and aging website. This could happen to any website. But this is Keybase, the company that promises &lt;strong&gt;&amp;quot;secure messaging and file-sharing&amp;quot;&lt;&#x2F;strong&gt;. The same company that got &lt;a href=&quot;https:&#x2F;&#x2F;www.crunchbase.com&#x2F;organization&#x2F;keybase&quot;&gt;$10.8 million in a Serie A funding&lt;&#x2F;a&gt;. The same company that &lt;a href=&quot;https:&#x2F;&#x2F;github.com&#x2F;keybase&#x2F;client&#x2F;issues&#x2F;24105&quot;&gt;won&#x27;t allow us to see their server code&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;To paint a full and fair picture, there has been an &lt;a href=&quot;https:&#x2F;&#x2F;keybase.io&#x2F;docs-assets&#x2F;blog&#x2F;NCC_Group_Keybase_KB2018_Public_Report_2019-02-27_v1.3.pdf&quot;&gt;audit of the Keybase protocol [PDF]&lt;&#x2F;a&gt; which states that:&lt;&#x2F;p&gt;
&lt;blockquote&gt;
&lt;p&gt;[...] there were weaknesses in the Keybase implementation; these were quickly fixed.&lt;&#x2F;p&gt;
&lt;&#x2F;blockquote&gt;
&lt;p&gt;The audit didn&#x27;t include the website. I&#x27;ll just end with another quote from the same audit:&lt;&#x2F;p&gt;
&lt;blockquote&gt;
&lt;p&gt;Another common theme was the presence of legacy code. [...]&lt;br &#x2F;&gt;
This does not necessarily imply that legacy code is insecure, but complexity and security are intertwined – every new piece of code may contain a security vulnerability, and more code correlates with more risk.&lt;&#x2F;p&gt;
&lt;&#x2F;blockquote&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>No to .io, yes to .xyz!</title>
        <published>2020-06-18T13:09:19+00:00</published>
        <updated>2020-06-18T13:09:19+00:00</updated>
        
        <author>
          <name>
            
              Unknown
            
          </name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://yarmo.eu/blog/no-io-yes-xyz/"/>
        <id>https://yarmo.eu/blog/no-io-yes-xyz/</id>
        
        <content type="html" xml:base="https://yarmo.eu/blog/no-io-yes-xyz/">&lt;blockquote&gt;
&lt;p&gt;TL;DR: I openly urge all FOSS projects and startups to reconsider registering .io ccTLD domains, opting instead for truly generic TLDs like .xyz&lt;&#x2F;p&gt;
&lt;&#x2F;blockquote&gt;
&lt;p&gt;&lt;strong&gt;.io&lt;&#x2F;strong&gt; is dead, long live &lt;strong&gt;.xyz&lt;&#x2F;strong&gt;!&lt;&#x2F;p&gt;
&lt;p&gt;&lt;em&gt;UPDATE: Long live .xyz, .org, and many other gTLDs! Please see &lt;a href=&quot;https:&#x2F;&#x2F;yarmo.eu&#x2F;blog&#x2F;no-io-yes-xyz&#x2F;#update-2&quot;&gt;Update 2&lt;&#x2F;a&gt; below.&lt;&#x2F;em&gt;&lt;&#x2F;p&gt;
&lt;p&gt;Is that an exaggerated statement? Yes, yes it is. But all new projects (and startups?) should reconsider their choice of TLD.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;The_case_in_favor_of_.io&quot;&gt;The case in favor of &lt;strong&gt;.io&lt;&#x2F;strong&gt;&lt;&#x2F;h2&gt;
&lt;p&gt;The &lt;em&gt;de-facto&lt;&#x2F;em&gt; choice is &lt;a href=&quot;https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;.io&quot;&gt;.io&lt;&#x2F;a&gt;. Numerous startups use it as a way to make their offering more legitimate, due to the long history of it being used by businesses, starting in &lt;a href=&quot;https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;.io#History&quot;&gt;1998 with levi.io, registered by Levi Strauss &amp;amp; co&lt;&#x2F;a&gt;. The appeal comes from the shortness of the TLD and, with regards to the high-tech sector, it being the abbreviation for &amp;quot;input&#x2F;output&amp;quot;.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;The_case_against_.io&quot;&gt;The case against &lt;strong&gt;.io&lt;&#x2F;strong&gt;&lt;&#x2F;h2&gt;
&lt;p&gt;But it doesn&#x27;t mean &amp;quot;input&#x2F;output&amp;quot;. It stands for &lt;a href=&quot;https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;British_Indian_Ocean_Territory&quot;&gt;British Indian Ocean Territory&lt;&#x2F;a&gt; as it is indeed a ccTLD (i.e. country-specific) and not a generic gTLD.&lt;&#x2F;p&gt;
&lt;p&gt;Look at the &lt;a href=&quot;https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;.io&quot;&gt;logo on the wikipedia page&lt;&#x2F;a&gt;. Looks techy, right? Everyone knows what the intended use was (&amp;quot;entities connected with British Indian Ocean Territory&amp;quot;), what the actual use is (&amp;quot;startup companies and browser games; little if anything related to the territory itself&amp;quot;) and are happy to play along because $$$.&lt;&#x2F;p&gt;
&lt;p&gt;&lt;strong&gt;.io&lt;&#x2F;strong&gt; is one of the most expensive TLDs out there (overview on &lt;a href=&quot;https:&#x2F;&#x2F;www.domaincompare.io&#x2F;&quot;&gt;domaincompare.io&lt;&#x2F;a&gt; and no, the irony is not lost on me ^_^). Stating the obvious, this is not due to the British Indian Ocean Territory having become such a hot property over the last decade.&lt;&#x2F;p&gt;
&lt;p&gt;The tech industry has appropriated the &lt;strong&gt;.io&lt;&#x2F;strong&gt; ccTLD and everyone is cashing in on it. Everyone?&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Colonial_history_and_.io&quot;&gt;Colonial history and &lt;strong&gt;.io&lt;&#x2F;strong&gt;&lt;&#x2F;h2&gt;
&lt;p&gt;In 2014, Gigaom reported in two separate articles (&lt;a href=&quot;https:&#x2F;&#x2F;gigaom.com&#x2F;2014&#x2F;06&#x2F;30&#x2F;the-dark-side-of-io-how-the-u-k-is-making-web-domain-profits-from-a-shady-cold-war-land-deal&#x2F;&quot;&gt;article 1&lt;&#x2F;a&gt;, &lt;a href=&quot;https:&#x2F;&#x2F;gigaom.com&#x2F;2014&#x2F;07&#x2F;11&#x2F;uk-government-denies-receiving-io-domain-profits&#x2F;&quot;&gt;article 2&lt;&#x2F;a&gt;) what shady practices happen behind the scenes of the &lt;strong&gt;.io&lt;&#x2F;strong&gt; TLD management. Afraid of not doing the story any justice with my words, I ask you to read both articles and make up your own opinion on the matter.&lt;&#x2F;p&gt;
&lt;p&gt;The first one describes how the UK gets profits for &lt;strong&gt;.io&lt;&#x2F;strong&gt; while denying any claims from the &lt;a href=&quot;https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Chagossians&quot;&gt;Chagossians, the people native to the Chagos Islands&lt;&#x2F;a&gt; whom they &lt;a href=&quot;https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Expulsion_of_the_Chagossians&quot;&gt;expelled from the islands&lt;&#x2F;a&gt; (a matter which is &lt;a href=&quot;https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Expulsion_of_the_Chagossians#2018_ICJ_hearing&quot;&gt;still actual in 2020!&lt;&#x2F;a&gt;). The second article describes how, in response to the first article, the UK government denied receiving profits and therefore defended that no profits should be shared with the Chagossians.&lt;&#x2F;p&gt;
&lt;p&gt;In january of 2019, &lt;a href=&quot;https:&#x2F;&#x2F;www.theguardian.com&#x2F;world&#x2F;2020&#x2F;jan&#x2F;05&#x2F;uk-forfeit-security-council-chagos-islands-dispute&quot;&gt;The Guardian wrote&lt;&#x2F;a&gt;:&lt;&#x2F;p&gt;
&lt;blockquote&gt;
&lt;p&gt;Last February the &lt;em&gt;&lt;strong&gt;International Court of Justice (ICJ)&lt;&#x2F;strong&gt;&lt;&#x2F;em&gt;, the principal judicial body of the United Nations, issued an advisory opinion that &lt;em&gt;&lt;strong&gt;found the UK was in unlawful occupation of the islands&lt;&#x2F;strong&gt;&lt;&#x2F;em&gt; and demanded that they be returned to Mauritius as quickly as possible.&lt;&#x2F;p&gt;
&lt;p&gt;The &lt;em&gt;&lt;strong&gt;UN general assembly endorsed the opinion&lt;&#x2F;strong&gt;&lt;&#x2F;em&gt; in May and set a deadline for implementation of 22 November 2019, which the &lt;em&gt;&lt;strong&gt;UK ignored&lt;&#x2F;strong&gt;&lt;&#x2F;em&gt;.&lt;&#x2F;p&gt;
&lt;&#x2F;blockquote&gt;
&lt;p&gt;One may not agree with me, but it is my interpretation that, since the Chagossians aren&#x27;t seeing any profits for the ccTLD that corresponds to the land they lived on but were forcibly removed from, &lt;strong&gt;by buying .io domains, one directly supports the still-actual behavior of the UK government defending their colonial history and acts against human rights&lt;&#x2F;strong&gt;.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;FOSS_and_.io&quot;&gt;FOSS and &lt;strong&gt;.io&lt;&#x2F;strong&gt;&lt;&#x2F;h2&gt;
&lt;p&gt;Why do we make FOSS software? Because we believe in openness and equality. It doesn&#x27;t matter who you are, you can use my software, you can modify it, you can redistribute it.&lt;&#x2F;p&gt;
&lt;p&gt;Everything that has happened with the Chagossians and the &lt;strong&gt;.io&lt;&#x2F;strong&gt; TLD is in stark opposition to the core principles of the FOSS community.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;The_case_in_favor_of_.xyz&quot;&gt;The case in favor of .xyz&lt;&#x2F;h2&gt;
&lt;p&gt;The &lt;a href=&quot;https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;.xyz&quot;&gt;.xyz TLD&lt;&#x2F;a&gt; is fun, small, refreshing, funky, a whole lot cheaper and you don&#x27;t support colonialism.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Final_words&quot;&gt;Final words&lt;&#x2F;h2&gt;
&lt;p&gt;If you choose to make your projects FOSS, you choose to uphold and respect certain principles and human rights, such as the &lt;a href=&quot;https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Free_and_open-source_software#Four_essential_freedoms_of_Free_Software&quot;&gt;Four Essential Freedoms of Free Software&lt;&#x2F;a&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;It is my opinion that buying a &lt;strong&gt;.io&lt;&#x2F;strong&gt; TLD domain directly opposes all a FOSS developer stands for.&lt;&#x2F;p&gt;
&lt;p&gt;I openly urge all FOSS projects and startups to reconsider registering &lt;strong&gt;.io&lt;&#x2F;strong&gt; ccTLD domains, opting instead for truly generic TLDs like &lt;strong&gt;.xyz&lt;&#x2F;strong&gt;.&lt;&#x2F;p&gt;
&lt;h2 id=&quot;Disclaimer&quot;&gt;Disclaimer&lt;&#x2F;h2&gt;
&lt;p&gt;I have bought .io domains in the past. I did not have the knowledge of what was going behind the &lt;strong&gt;.io&lt;&#x2F;strong&gt; TLD. Now that I do, I will let them expire and NOT renew them. I will also never buy a ccTLD again if its use exceeds the intended use, namely to represent the territory it is associated with.&lt;&#x2F;p&gt;
&lt;hr &#x2F;&gt;
&lt;h2 id=&quot;update-1&quot;&gt;Update 1&lt;&#x2F;h2&gt;
&lt;p&gt;There is also the issue of the &lt;strong&gt;.io&lt;&#x2F;strong&gt; TLD&#x27;s &lt;a href=&quot;https:&#x2F;&#x2F;www.prolificlondon.co.uk&#x2F;marketing-tech-news&#x2F;tech-news&#x2F;2019&#x2F;05&#x2F;future-popular-io-domains-question-over-british-empire-row&quot;&gt;future&lt;&#x2F;a&gt;:&lt;&#x2F;p&gt;
&lt;blockquote&gt;
&lt;p&gt;But the UK faces significant international pressure over the Islands, and in the event that they are returned, control over the .io TLD would likely pass to the Mauritian government.&lt;&#x2F;p&gt;
&lt;&#x2F;blockquote&gt;
&lt;p&gt;Who knows what will happen to your domain registration when control is passed to the Mauritian government? Why risk the future of your domain just so you can associate your brand and&#x2F;or product with the words &amp;quot;input&#x2F;output&amp;quot;?&lt;&#x2F;p&gt;
&lt;hr &#x2F;&gt;
&lt;h2 id=&quot;update-2&quot;&gt;Update 2&lt;&#x2F;h2&gt;
&lt;p&gt;It has been pointed out by many that this post focuses too much on the &lt;strong&gt;.xyz&lt;&#x2F;strong&gt; gTLD. This was not my intention. In fact, any gTLD will do just fine, after all they are generic. A non-exhaustive list of gTLDs that could perfectly replace &lt;strong&gt;.io&lt;&#x2F;strong&gt; (assuming &lt;strong&gt;.io&lt;&#x2F;strong&gt; simply stands for &amp;quot;input&#x2F;output&amp;quot;):&lt;&#x2F;p&gt;
&lt;ul&gt;
&lt;li&gt;.net&lt;&#x2F;li&gt;
&lt;li&gt;.org&lt;&#x2F;li&gt;
&lt;li&gt;.tech&lt;&#x2F;li&gt;
&lt;li&gt;.site&lt;&#x2F;li&gt;
&lt;li&gt;.link&lt;&#x2F;li&gt;
&lt;li&gt;.systems&lt;&#x2F;li&gt;
&lt;li&gt;.computer&lt;&#x2F;li&gt;
&lt;&#x2F;ul&gt;
&lt;p&gt;What is important is that you can identify with the TLD, be it &lt;strong&gt;.net&lt;&#x2F;strong&gt; or even &lt;strong&gt;.ooo&lt;&#x2F;strong&gt;.&lt;&#x2F;p&gt;
&lt;p&gt;I would also like to point out &lt;strong&gt;.io&lt;&#x2F;strong&gt; is not the only ccTLD that is often &amp;quot;misused&amp;quot; (IMO) as a gTLD. Think of &lt;strong&gt;.ai&lt;&#x2F;strong&gt;, &lt;strong&gt;.tv&lt;&#x2F;strong&gt;, &lt;strong&gt;.to&lt;&#x2F;strong&gt; and &lt;strong&gt;.ly&lt;&#x2F;strong&gt; to name just a few. The reason I single out &lt;strong&gt;.io&lt;&#x2F;strong&gt; is because this one in particular has a lot of controversy around it that has lasted for forty years and is still active. I haven&#x27;t found the same levels of conflict with the other ccTLDs. If there are, do let me know, I read all links to discussion below.&lt;&#x2F;p&gt;
</content>
        
    </entry>
</feed>
