Category: Uncategorized

  • The reputation of United States

    Aral Balkan

    What if I were to tell you that Trump could knock any (or all) of over 20 millionΒΉ European web sites off the Web tomorrow by picking up the phone to one US organisation: Let’s Encrypt.

    We desperately need an independent, not-for-profit ACME provider in the EU paid for by our taxes.

    CC @EUCommission

    ΒΉ This is just based on one firm’s analytics (trends.builtwith.com/websiteli). Others put LE use at 50-60% of all web sites.

    September 2, 2026, 10:11 380 boosts 320 favorites

    The whole idea that famous Let’s encrypt is some risk just because some voters were concerned so much about gas and groceries prices so much they elected a fascist bastard, is so…. “who could expect this 10-20 years ago?” thing.

    I bet Mozilla and Google would lobby the @EU_Commission against this important aspect of EU digital sovereignity.

    Yes, EU would need own certificates authority. But not because it is better than other centralized certificates authority. But because it would be easier and faster to do compared to transition to some decentralized alternative of internet where people exchange contacts like cards with addresses and phones in the past, and sites admins and authors add themselves in some well-respected human-reviewed catalogs of contact cards like “Yellow Pages”, as replacement for current pyramidal DNS & SSL certificates of today.

    I am not sure how is the best way to deal with all that, but it seems it would end need with some kind of that address/phone book for websites described in the Web Numbers article… But even without the central authorities of SSL.

    May be it would be something like that: If you are about to navigate into website, it depends on how it navigated:

    • from contact address book? Trust if same certificate as before.
    • from typing address in address bar or new certificate? Broadcast question for trust across peer to peer networks, something like “who trusts 1234:44444 declaring to be tasty.blog and certificate signature 12AB45DE3WXZ”?
    • Navigating to new website missing in known sites/contacts library from a known site? Ask known site for trust about site you navigate into the first time, or broadcast trust query, or both.

    If site or certificate is new, then it would be an UX quest to solve, to represent results of trust query to a non-techy person.. Of course if there are contacts that are trusting that hypothetical tasty.blog website, they can be shown in the related popup? But would it be some violation of their privacy to show that person, let it be Malory, the fact that Jane and Alex trust this website identity? Even if at UX level, “3 your contacts can confirm identity of this website”?

    Making all websites a sort of invite only, like “Mary gave you link to this tasty.blog website. Add it to your address book?”… Will it ever work?

    I know this would be completely new internet that is basically semi-compatible with standard one, and for today browser it would be similar to visiting first time a site with self-signed (or semi-self-signed with not-trusted root) certificate. Unless some extension would be created that would allow such kind of address-book kind of DNS & SSL functionality. But such extension of course would be incompatible even with old extensions APIs, and with newer more restricted too… And having some local proxy would end up with auto-transform of all links into

    //For site from your local address book
    https://127.0.19.45/from_book/site_name/page_path?a=1
    //for new site that is not in a book - ip address, port, and certificate hash
    https://127.0.19.45/new/1.99.11.15/443/AB444ZYC...3425/page_path?a=1

    I just tried to imagine how it (internet without centralized SSL and DNS but with these address books or Web Numbers) would look like without creating brand new browser, even with Servo rendering engine, using the browsers we already have.

    To some extent it resembles how the GNS (GNU Net domain name system) works?

  • The funny thing about these LLMs and llms.txt

    The https://llmstxt.org site described a technique that offers a way to make websites LLM-friendly. Well, preare it for reading and processing by some automated agent powered by LLM.
    So, one thing got my attention from related recommendations:

    • Use concise, clear language.
    • When linking to resources, include brief, informative descriptions.
    • Avoid ambiguous terms or unexplained jargon.

    So, we, humans, don’t deserve all this, and only LLMs deserve these practices? Does it mean the sites intended to be visited by people should be full of unclear wording, non-concise text? Full of rare jargon? And of course all that as a cherry on cake full of megabytes of javascript, wild and confusing navigation? And of course, hordes of useless and distracting ads, popups and all that crap?

    Fediverse Reactions
  • It happens often

    What I do at work: something like “teamlead” job in a SaaS project where most often issues are related to “homegrown” billing via stripe or paypal or occasional issues with app-specific data storage.

    What I would like myself: code (not lead but code myself) a desktop local-first project I thinking about.

    What I use for job: complex build flow including webpack, SCSS, react, MUI4, typescript 5, et cetera.

    What I would use for my own project: vite, custom UI framework for custom elements based or tagged templates strings, and something for CSS files with “rules nesting syntax”. And regarding payments I would use the solution to accept payments that has the local bank.

    This strong difference gives me some strong dissatisfaction lately. I even thinking that I should create own local-first software projects as attempt to make some own income, not because I lack money for day to day expenses right now but because I feel I need to do my own things I want to do in my own way to be more satisfied.

  • Back from vacation travel to Estonia

    It was a week-long vacation trip for me and my wife.

    Before anything else I would like to thank community on Reddit who warned about need to fill a travel authorization form (even for transit!). it could be possible that without such hint I would not fill it at all and our vacation could become a sad thing instead.

    One of strongest impressions was is the most developed public transit system we seen in Tallinn.

    Trams are very good. We used them many times.

    Going beyond some “standard” travel landmarks was an improvisation and while we was not able to visit the place we wanted to see, we seen something else, and it was a good experience as whole.

    One of the most cute things seen was the signpost at Kaperi bus stop with directions to various places, from hairdresser to kindergarten. It gives some cute atmosphere that I can’t describe well. most close metaphor coming to mind is it like walking into a quest game about a small medieval village.

    The Elron trains are really good. I can say I dreamed to travel on an European train since last year, and during this travel that dream come true out of the blue, when we decided to travel to Tartu. Train interior design looks quite futuristic to my taste and I like it.

    Intercity buses are quite good, better than I expected. We took a bus from Tartu to Kaperi and than later continued to VΓ΅ru.

    We wanted to visit the very specific place, Urvaste to see Tamme-Lauri oak, the oldest and widest oak of Estonia.

    The main lesson of this attempt was that visiting such places require a careful preparation beforehand. You can’t just sit in tram in Tallinn, travel with Elron train for hours, book a intercity bus to VΓ΅ru direction, and catch a bus from Kaperi to Urvaste in the same day, as an internet search engine suggest. So, if we would be lucky enough to have another trip to Estonia, we would make the next attempt to see the Tamme-Lauri oak the main event to plan whole trip around, not just an impromptu.

    I would say you can not rely on internet regarding routes to and connections between cities and villages smaller than VΓ΅ru and related connections. I feel there is some threshold that if you want to visit some “small” place, you have to not just plan beforehand carefully, but also research in more offline way if want to plan something like that.

    Speaking of trees… I have an impression after this vacation that there are so many trees and forests across Estonia, and this is great! It become one of main impressions from this travel.

    Tallinn also have much more greenery than Tbilisi, and combined with very developed public transit, it gives me some positive solarpunk-friendly feel. Speaking of solarpunk, yes, we seen a large set of solar panels at some place.

    The Viru hotel we stayed in has an own museum about soviet times and KGB. It is very interesting, but may be the narrator of this exhibition tells the story way too fast for my skills in aural English so I missed some moments of the story. Now I know some new details about these harsh and difficult times.

    One moment I was not expected that somehow KiluvΓ΅ileib was not so easy to bump into and we did not got a chance to taste it eventually. May be I “bumped into” wrong 4 places, or may be Gemini is not the best tool to ask questions like that, it seems.

    It was much easier with kama which was available at hotel breakfast and it is very tasty, really.

    We surely will visit Estonia again!

    Fediverse Reactions
  • EU ID and Age Verification is so strange project

    Why this specification of age verification is so mobile-centric? Like, there are no options like these:

    • OTP via SM flow,
    • FIDO2 webauthn flows with TPM, Yubikey and other USB dongles with keystores and data signing capabilities
    • dedicated device with monochrome display, specialized EUID/Age Verification software preinstalled, and USB, NFC and Bluetooth interfaces, without any touch of Google or Apple

    The whole spec rotates only about just 2 flows:

    1. mobile device of quite specifc kind, with stock Android or iOS onboard, with age verification app installed.
    2. device from (1) used to scan via camera a QR code appearing on screen of the other device.

    I asked a related question to this spec here: https://github.com/eu-digital-identity-wallet/av-doc-technical-specification/discussions/62

    If find this relevant, and have GitHub account – boost that question please.

    (PS: already seen question there from people asking why ever GitHub used to store that spec)

    Fediverse Reactions
  • Would you moved away from Express.JS to something like this?

    Imagine a library for node.js that would have been completely decoupled from raw server request and response?

    It may resemble koa a bit over its general vibe, I suppose.

    Instead of raw request and response, only minimal information for each request is provided, and access to to raw request and response avoided, with special hatches to use them when the above interface is not enough (the feature methods on request and responder objects).

    interface Request<TRouteParameters=Record<string,any>> {
       readonly id: string;
       method: string;
       url: string;
       host: string;
       query: ParsedQueryString;
       params:TRouteParameters;
       headers: RequestHeadersBag;
       cookies: RequestCookiesBag;
       contentLength: number;
       contentType: string;
       body: any;
       feature<T>(featureRef:RequestFeatureRef<T>):T;
       tryGetJson():Promise<any>;
       tryGetText():Promise<string>;
       tryGetBuffer():Promise<Buffer>;
       tryGeBodyStream: Readable;
    }
    
    interface Response {
       readonly statusCode: number;
       readonly headers: IResponseHeadersBag;
       readonly cookies: IResponseCookiesBag;
       readonly hasBody: boolean;
       execute(): Promise<void>;
    }  
    
    interface Responder
       readonly responded: boolean;
       status(status: number): Responder;
       setHeader(name:string, value:string):Responder;
       setCookie(cookie:CookieOptions):Responder;   
       
       next(): Promise<IResponse>;
       done(): IResponse;
       noContent() IResponse;
       redirect(url: string, reasonCode: RedirectReasonCode): IResponse;
       html(markup):IResponse;
       json(value:any):IResponse;
       stream(stream:Readable): Promise<IResponse>;
       feature<T>(featureRef:ResponseFeatureRef<T>):T;
    }   
    
    type RequestHandler = function(req:Request, res: Responder) => (Promise<Response>|Response|void);
    
    export type AfterRequestHandler = (req: Request, res:Response) => (Promise<void>|void);
    
    interface Routes {
       before(...handlers: RequestHandler[]): Routes;
       after(...afterHandler:AfterRequestHandler[]):Routes;
       use(path: RouteTemplateOrString, ...handlers: RequestHandler[]): Routes;   
       get(path: RouteTemplateOrString, ...handlers:RequestHandler): Routes;
       post(path: RouteTemplateOrString, ...handlers:RequestHandler): Routes;
       put(path: RouteTemplateOrString, ...handlers:RequestHandler): Routes;
       patch(path: RouteTemplateOrString, ...handlers:RequestHandler): Routes;
       delete(path: RouteTemplateOrString, ...handlers:RequestHandler): Routes;
       options(path: RouteTemplateOrString, ...handlers:RequestHandler): Routes;
       request(method:KnownHttpMethod, path: RouteTemplateOrString, ...handlers: RequestHandler): Routes;
       tryDispatch(request:Request):Promise<IResponse>;
       useRoutes(routes:Routes, prefix?:string):Routes;
    }
    
    //and something like this to use all that:
    export function createRoutes(): Routes;
    export function prepareForHttp(...routes: Routes[]): (req:IncomingMessage, res: ServerResponse) => void;
    
    export function prepareForHttp2(...routes: Routes[]): (req:Http2ServerRequest, res: Http2ServerResponse) => void;
    export function prepareMockRequest(options:MockRequestOptions):Request;
    export function enableRequestFeature<TFeature>(factory:(req:Request) => T): RequestFeatureRef<T>;
    export function enableResponseFeature<TFeature>(factory:(req:Request, res: Responder) => T):ResponseFeatureRef;
    
    export const RawHttp2Request = RequestFeatureRef<Http2ServerRequest>;
    
    export const RawHttp2Response = RequestFeatureRef<Http2ServerResponse>;
    
    export const RawHttp1Request = RequestFeatureRef<IncomingMessage>;
    
    export const RawHttp1Response = RequestFeatureRef<ServerResponse>;
    
    

    I defined the interface above while wrote this post.

    The reason for musing about this theoretical library is sort of being tired of not obvious ways to use same code without dirty hacks for http/1.1, http2, and tests.

    Would you use such library? Or there is such library already?

  • A newbie question about French law

    Or multiple questions. Does it mean I now have to check age of people who read my blog if their IP is within France range? Or if their language is French in user agent string? Or law demands browsers to send special digitally signed header of I am adult or I am minor kind? Does it apply to requests coming from Fediverse in behalf of accounts belonging to people this law applies to?

    Generally speaking, to what extent the age verification law like French one applicable to France?

    Fediverse Reactions
  • Nihilism declared a form of extremism by law?

    Here is the headline sparked my question:

    Europol shuts down thousands of websites linked to global nihilist network

    https://www.brusselstimes.com/brussels-2/2244268/europol-shuts-down-thousands-of-websites-linked-to-global-nihilist-network

    The headline actually does not capture what the group actually did, according to article text:

    The groups recruit members through social media platforms and online gaming communities before encouraging them to commit acts including animal torture, violent assaults, self-harm and the production of child sexual abuse material.

    Note also another important detail (at least for me):

    Victims are often blackmailed into remaining in the groups, with perpetrators threatening to share intimate images or videos with family and friends.

    This sounds like how standard mafia or KGB/FSB works.

    Another notable aspect is this:

    Some of the groups also use far-right symbols and terminology to promote their ideology or provoke public outrage.

    I guess the more accurate headline could be like this: “Europol shuts down thousands of websites linked to global misantropic network that included far-right groups”.

    I also suspect that somehow Kremlin involved into this network. At least erosion of ethics worldwide is something Kremlin would find beneficial for their goal of world domination.

    PS: I am not a big fun of nihilism or misanthropy but so far I heard these words only related to philosophy books authors like Nietzsche or in internet whining about unpleasant life and being unlucky. With than being said, I never heard before it can end up with mafia-like behavior or end up becoming a destructive sects.

  • Seen few Typescript compilers out there

    The fact that you can not write a fast compiler for typescript using typescript and have to use go or rust for that does not make typescript bad per se.
    it just marks well its scope of applicability. Business logic, routing rules, small pieces of messages handling glue code on edge devices or cloud functions, and other places where you mostly connect with glue code some other libraries of high-optimized code.

    Well, from code based config to shell scripts, from website backends to in-game scripting. it is not that bad if a language can do all that, even if you can not write its own compiler to be fast on it.

    BTW there are few interesting projects allowing to compile typescript to native executables based on rust. They have 95% coverage or so of Typescript compatibility with Nodejs as Perry.

    I even think to use Perry for next my pet project (local-first blogigng tool).

  • Getting Reddit Banana Master achievement is a sign

    Yesterday I said in a Reddit that it is yet another social media with addictive algorithmic feed (even if often not so endless as at Facebook). And now I got another reminder I am doomscrolling too much. That Banana Master achievement is about “scrolling 100000 banana lengths”.

    I surely need to develop that local-first blogging software I told about recently. Even if it will not become a widely used thing, I will spend on it time I would doomscroll otherwise, and may get some advanced skills in process, as I can try to use some new stuff such as combining nodejs with servo browser engine and make it a desktop app without Electron.

    Fediverse Reactions