16 ms·
RFC 35140: HTTP Do-Not-Stab (2023)
- iddan 2y agoExcellent satire. Really drives the point home. I think it's hard sometimes to understand just how much forces of bad use paper trail to push their agenda. This outlines this really well
- dangsux 2y ago[dead]
- sillysaurusx 2y agoI’ve always wondered, since an RFC is a request for comment, how does one leave a comment? And who?
- vandyswa 2y agoRFC's operate under the IETF. RFC's are developed under some specific group, and you can join that group, the business is generally conducted on email. There are (well, were back when I participated) in-person meetings, but attendance there was not mandatory.
- teddyh 2y agoRFC:s are published by the RFC Editor <https://www.rfc-editor.org/ https://www.rfc-editor.org/>. While it’s true that most RFC:s are written and published through the IETF, this is not an actual rule.
- staplung 2y agoA bit of lore that I learned in my networking class in college was that the RFC name was chosen as tongue in cheek in that by the time a proposal gets to the RFC stage, comments are very much not appreciated. You're supposed to comment well before that point. No idea if that bit of lore is true but it is certainly the case that RFCs are usually the final word on the relevant standard. In fact, once they get their ID, RFCs cannot be modified or rescinded; only superseded by another RFC.
- SilasX 2y agoThen they should be renamed CFCs (closed for comments).
- telgareith 2y agoBut CFCs are banned!
- jaza 2y agoFinally I understand why RFCs are served with the Do-Not-Comment header!
- dogleash 2y agoThat's apocryphal, the name just lasted beyond the original workflow of a now 55 year old publishing system. The idea that a published RFC is a final word is a newer idea too. Yeah, you can't modify an RFC, you have to publish a newer one, but that was a pretty good way of doing distributed change control in 1969.
- riffic 2y ago"request for compliance" is the alternative interpretation.
- jowea 2y ago> The early RFCs were, in fact, requests for comments on ideas and proposals; the goal was to start conversations rather than to create an archival record of a standard or best practice. This goal changed over time, as the formality of the publication process evolved and the community consuming the material grew. Today, over 8500 RFCs have been published, ranging across best practice guidance, experimental protocols, informational material, and, of course, Internet standards. > https://www.rfc-editor.org/rfc/rfc8700.html https://www.rfc-editor.org/rfc/rfc8700.html Nowadays you're supposed to comment before it gets to "Internet standard"
- layer8 2y agoYou can submit errata. Maybe it should be renamed to RFE.
- actionfromafar 2y agoThis is such transparent EU Bureaucracy shilling. No wonder Europe doesn't have any large SaaS companies with their stabbing unfriendly business climate.
- nyanpasu64 2y agoI downvoted before I read the end of the comment and realized this was satire.
- bue7jclotemp 2y agoI think you are factually wrong: Skype, Spotify, Revolut, Zendesk, Transferwise... There are quite many European unicorns too (less though than US and Chinese companies) which are operating as SaaS. Some of them got acquired or re-based to other countries though
- notpushkin 2y agoCan confirm, got stabbed by a spammer on Skype yesterday.
- wkat4242 2y agoSkype is fully American these days though.
- hmottestad 2y agoDidn’t Zendesk stab a pentester recently? https://news.ycombinator.com/item?id=41818459 https://news.ycombinator.com/item?id=41818459
- MBCook 2y agoGood to know HN will be the same in 100 years. /s
- phoronixrly 2y agoYeah, why can't the EU just leave the stabtech industry stab in peace?...
- cuuupid 2y agoFor the low price of $20/1000 clicks, I will provide you with a stabbing consent banner, fully compliant with upcoming EU and CA regulations on web-based stabbing.
- jsheard 2y agoI'm sold, the distinctions between "necessary", "targeting", "performance" and "functional" stabbings are such a minefield. Not to mention how I'm supposed to properly disclose the 846 different stabbing brokers I work with. How's a man supposed to make a living stabbing people with all of this red tape in the way?
- makapuf 2y agoAt least people will be able to differentiate between legitimate interest to stab you and consent to be stabbed for 247 of those 846 partners.
- Macha 2y agoBy the way, studies show users only opt in to stabbing with our competitors banner 95% of the time, but they opt in with ours 98% of the time, thanks to our banner taking 50% longer to properly opt out of, so you should really go with us.
- layer8 2y agoI raise you 5000% longer, which gets you to four nines.
- tdeck 2y agoFor those who only skim things, it might be worth scrolling down to read the "Editor Comments" section which is the actual article.
- MathMonkeyMan 2y agoI feel like that section ruins the joke.
- SilasX 2y agoMaybe it’s just me, but I fundamentally disagree with the mentality that we should prioritize the “feeling of being special” among those who already get the joke (and corresponding point) at the expense of those who have yet to appreciate the message. You can still laugh at the joke with the section there, you’ll just have fewer confused people to correct, and be in one less elite club.
- deleted 2y ago[deleted]
- dullcrisp 2y agoSure, but the point of critical thinking club isn’t really its exclusivity. In this case if you don’t know which specific header this is parodying that’s completely understandable. But if you really think this is about computers stabbing people and can’t laugh at yourself about it when you find out that it isn’t then I don’t think we will be able to engage on this topic in a mutually rewarding manner.
- SilasX 2y agoI don’t think it’s about computers stabbing people, but that’s not relevant. The issue is your willingness to keep people in the dark so you can feel good that you got a reference without it being explained.
- 2y ago
- TacticalCoder 2y ago> it’s fucking depressing when even the fucking bare minimum form of regulation is followed to the letter and no more, because every company out there fucking hates you and would sell you out to make a bit more money if they legally could. and even if they couldn’t, who’s going to stop them? Certainly not any government. If you think the EU's regulation are of any help to the consumer you are gravely mistaken. The EU is quickly becoming a fucking nightmare to live in. "The more corrupt the state, the more numerous the laws". The meme that goes around atm is that while Elon Musk created Tesla, SpaceX and Starlink the EU managed to get everybody to now have plastic bottles who do not close properly anymore: due to some regulation that mandates that bottle caps must hold to the bottle, weird only partially-functional mechanism have been created and it's a PITA to either drink from a plastic bottle or, worse, try to lay it horizontally in a fridge. That's what the EU is: probably that some politicians or bureaucrats with enough brain cells to recognize a bottle cap on the ground thought "I've got an idea to make the EU better, let's mandate every bottle to have a cap that cannot be separated from the bottle". As a result you lay horizontally a plastic bottle of sugary drink in your fridge (because you've been used to do that for decades) and now all your fridge is sticky due to the bottle leaking. It's all that is wrong with the EU bureaucrats in one example. Also hailing the EU as the savior vs Microsoft when our lives becames miserable with EU consent cookie popups virtually everywhere is a bit thick.
- WD-42 2y ago[flagged]
- CRConrad 2y agoNo, he needs to learn how to screw on a bottle cap. We keep soda bottles horizontal in our fridge, and they don't leak.
- account42 2y agoDismissing people's real concerns is how you get them to vote for parties you don't like. Fact is that the new caps do make it easier to end up without a good seal.
- nojs 2y agoWouldn’t this header just be another bit of entropy used by companies that are going to stab you anyway?
- sionisrecur 2y agoIf you make misusing the header illegal then only illegals will stab you.
- wkat4242 2y agoWithout legal backing, yes. If it had that it would have been a very different story.
- SilasX 2y agoI couldn’t tell if it was intended to be a note-for-note parody of an RFC about the do-not-track header, but I couldn’t find one that would qualify. The closest would be this[1], but it doesn’t cleanly match up (in part because [1] is more verbose and its points scattered). Another satire RFC in the same spirit is the one about the evil bit[2] (designate one bit in packets to indicate whether it’s intended for evil), with the same subtext as the linked post: no, you can’t trust malicious entities to change their behavior to make it easier to stop. [1] https://www.w3.org/TR/2019/NOTE-tracking-dnt-20190117/ https://www.w3.org/TR/2019/NOTE-tracking-dnt-20190117/ [2] https://datatracker.ietf.org/doc/html/rfc3514 https://datatracker.ietf.org/doc/html/rfc3514
- foundry27 2y agoIt’s great satire, but it really does mirror a larger societal shift where the burden of safeguarding personal autonomy has shifted from institutions/regulators to individual users. Do-Not-Stab, Do-Not-Track, whatever it might be, any sort of “voluntary compliance” is a non-starter in the face of financial pressures IMO we need to start normalizing being militant about this stuff again, to aggressively and adversarially defend the freedom to use your computer the way you choose to use it
- mpalmer 2y agoTo be extremely pedantic, it's great satire precisely because it mirrors that shift. Owes a lot to the OG, A Modest Proposal.
- thrtythreeforty 2y agoI'm registering my elderly relatives for dmachoice.org, to prevent them from getting junk mail. These clowns create the problem and then have the audacity to charge you to be added to the opt out list. I was really skeptical about the GDPR when it was passed and I am now fully on board for an American version.
- shadowgovt 2y agoI'm still extremely skeptical of it because in practice it basically added a cookie banner to every every website I visit infrequently with no particular benefit to me. I'm just going to click "yes," stop asking.
- blooalien 2y ago> ... "it basically added a cookie banner to every every website I visit" ... Yeah, no. Hostile advertising companies added that cookie banner as a form of "malicious compliance" with the law purely to annoy everyone like a buncha spoil't little brats who didn't get their way, so now they're gonna make everyone suffer... If we get a similar law in the USA, you can expect to see annoyances just like it (and probably worse) on sites hosted here, too.
- bagels 2y agoThe authors are [redacted] Google. Are they actually Google? They seem to unironically complain about what Microsoft is doing, but Google is guilty of the same.
- bhaney 2y agoDude come on
- Mathnerd314 2y agoThe actual author is one person, user '5225225'
- averageRoyalty 2y agoApparently they identify as a robot, not a person.
- teractiveodular 2y agoI think the author's entire point is that self-regulation by the big boys is not working very well.
- jaza 2y agoRelax, folks, entities have plenty of other options, there still won't be support for Do-Not-Shoot, Do-Not-Rape, Do-Not-Stone, fun for the whole family.
- grahamj 2y agoDon't forget robots.txt
- PeeMcGee 2y ago> it’s fucking depressing when even the fucking bare minimum form of regulation is followed to the letter and no more For Microsoft this also rings true from the opposite direction. Any specification that Microsoft technically abides is implemented in an egregiously dark way (at least for anything consumable at an enterprise level). They go to great lengths to exercise every bit of leeway permitted by the spec, even when it doesn't make economical sense, because what are you gonna do about it? Vote with your wallet? Against the vendor that runs all your workstations and manages your directories and databases and deployments and authentication and authorization and business intelligence and and and? No, you're gonna accommodate their absurd counter-requirements because what other choice do you have? The decision then becomes: 1. branch your code to shit with `vendor == microsoft` clauses 2. branch your project/architecture to shit and effectively maintain a Microsoft version alongside the "normal" core version 3. use Microsoft's bespoke library that solves the problem they created A project that selects option 3 will face the least resistance integrating with Microsoft products, but will also become beholden to arbitrary rules that complicate integration with every other vendor who benevolently implements the standard.
- jeroenhd 2y agoIt's important to note that the Do-Not-Stab header has been deprecated because one browser engine switched it on by default and requiring users to opt into stabbing hurt the bottom line of the stabbing industry, so it's no longer respected. Luckily someone came up with General Assault Control, a non-standard alternative, which also only has one value, so you can set Sec-GAC to 1 to request websites not to assault you. By design, this header cannot be extended, so it cannot be used to distinguish brutal stabbings from a comedic pie to the face in the future. Because of legal requirements, the General Assault Control header may not be enabled by default, as American states like Colorado require explicit opt-out (rather than explicit opt-in). This protects Colorado's thriving stabbing and shooting industry as most users will never want to opt into being stabbed. Despite the feature being forced to be disabled by default, the organisation behind the spec is pushing hard for customers to download fringe browsers that implement the feature (though you may need about:config to enable it). Because of the small user base, the request not to be assaulted can be used by websites not willing to follow the standard to make their stabbings and shootings more precise. End users can request a JSON file from the web server containing the supposed support for the GAC header, but requesting this URL may be used to kick the user in the teeth by non compliant servers.
- boomlinde 2y agoIt's now customary, in order to comply with European regulations, to present users with a list of possible violent crimes against their person that they can opt out of before using a website. This ensures that non-consent to stabbing is always an active choice, so that users who want to be stabbed or otherwise maimed won't accidentally miss out on the opportunity.
- rakoo 2y agoWe value your body integrity. We and our 1492 partners would like to stab you.
- avhception 2y agoPlease use this outlandishly convoluted form to opt out of every single one individually. You might also want to read our ToS in order to stay informed about the multiple ways, some of them illegal under EU law, you still will get stabbed. (Approximate reading time: 4h53m, assuming a law degree and multiple years of experience in data protection law practice)
- dare944 2y ago> because every company out there fucking hates you They don't actually hate you. Rather, they love your money and they have a depraved indifference for you.
- khafra 2y agoThey don't hate you, but they're Out To Get You (https://www.lesswrong.com/posts/ENBzEkoyvdakz4w5d/out-to-get-you https://www.lesswrong.com/posts/ENBzEkoyvdakz4w5d/out-to-get...)
- dylan604 2y agoNo, they love the money they can make about you. I don’t know anybody giving their money to these people. It is other shady companies buying the data about for, shady companies that have collected. All of this is offered to you free of charge.
- notpushkin 2y agoMind you, some companies will take your money and still track the shit out of you, show you ads, and sell your data to the highest bidder.
- almostnormal 2y ago> and sell your data to the highest bidder. Do they provide a guaratee to only sell once, instead of selling to everyone?
- forty 2y agolooks like someone just discovered that capitalism is bad for people ^^ who would have thought it...
- maufl 2y agoThat reminds me of the second half of this sketch https://www.youtube.com/watch?v=uQjUh4nWwaM https://www.youtube.com/watch?v=uQjUh4nWwaM
- tsujamin 2y agoA big shoutout to those reading the comments who are the direct subjects of this satire.
- indus 2y agoWhy a header? Do a sidedoor as a /do-not-stab.txt Do-Not-Stab: 1
- m0rissette 2y agoRight. This was just too on point. Thank you for making my night!
- andyzei 2y agoThe Do Not Track header was originally proposed in 2009 by researchers Christopher Soghoian and Sid Stamm.[2] Mozilla Firefox became the first browser to implement the feature. https://en.wikipedia.org/wiki/Do_Not_Track#:~:text=The%20Do%20Not%20Track%20header,browser%20to%20implement%20the%20feature https://en.wikipedia.org/wiki/Do_Not_Track#:~:text=The%20Do%....
- shdon 2y agoI wonder how many web developers actually honour Do Not Track. I do, in all the websites I've made for my employer too, but I think I'm only getting away with it because my employer doesn't know. I've even made it so that browsing with Do-Not-Track enabled also skips the cookie consent banner and just assume the user wants no cookies other than the strictly necessary ones (like their session/login cookie), and doesn't include Google Analytics, instead just upping a single view counter on the page, with no PII in there.
- kelnos 2y agoA better option would be to just make tracking illegal, and heavily fine companies that are found to be doing it. And make it strict liability, so intent doesn't matter. I can dream...
- shadowgovt 2y agoThis sounds like a recipe to reduce the internet to a handful of heavily-financed publishers who can afford legal protection against strict liability.
- psd1 2y agoThat's reasonable. Could also decimate the adtech industry and cut them down to just serving ads based on keyword searches and location, like they did 20 years ago
- 2y ago
- scotty79 2y agoI'd love for Please-Do-Stab header to exist so I can just set it and with it opt out of any stabbing-anti-stabbing wars and politics. I fully understand that it's absence wouldn't meant that people won't get stabbed, but it would save time and mental space of all people like me who really don't care about being stabbed or not. Honestly if anything, I'd like to be stabbed more. By analogy to current situation about tracking ... Ad companies know too much about me? I think they know too little. For example for half a year they still haven't figured out that I know barely any words in German and are serving me German advertisements all the time just because I happen to be living in Germany currently.
- b0rbb 2y agoFor some reason, I'm reminded of a particular comic strip from Achewood - https://achewood.com/2007/01/11/title.html https://achewood.com/2007/01/11/title.html. "Fools! I have invented a usb device which can collect votes from the Internet and drive a knife through your heart!"
- anakaiti 2y ago[flagged]
- Timwi 2y agoThe whole website is a treasure trove. There's a page with two C# puzzles and one with an HTML/JavaScript puzzle that I found very interesting. I'm still stuck on the second C# one!
- tonetegeatinst 2y agoThis is going to wipe out the saas market (Sutures As A Service) which is a additional somewhat often used service once Stabbing As A Service has occurred.
- tbrownaw 2y agoI see someone needs to teach their user-agent how to say "no". Maybe they could get advice on the best way to do that from these people?: https://news.ycombinator.com/item?id=42169027 https://news.ycombinator.com/item?id=42169027
- benreesman 2y agoSounds like handlers of the “UPGRADE” verb SHOULD have taken the “WOCK” to Poland.
- zatkin 2y agoWell that's one way to take a stab at this problem.
- ipnon 2y agoAdtech is kind of like the fungal domain of the web, in that it allows life to technically exist where it shouldn’t, because death is actively in progress. It recycles deathly content back to the top of the food chain to Big N, wherein it is reconstituted into cushy salaries for the people that ultimately create the infrastructure that allows endless slop to permeate the web.
- averageRoyalty 2y agoThis website appears to be part of a webring (how delightful!) made up of MtF trans people, furries, self-identified robots (some of which exclusively use third person pronouns) and sometimes a mixture of these. All appear to be some form of sysadmin or programmer. This isn't my tribe, but I'm incredibly pleased to see a beautiful reflection of the old internet within this webring.
- yieldcrv 2y ago> “We and our 756 partners process personal data[…]” wow big polycule this website is in This gets more and more unhinged, I love it
- atoav 2y agoIf Monty Python made an RFC it would look very much like this one, just with more fruit. On a more serious note: yeah wtf. I hope we in the EU draw the conclusion of companies even being unable (unwilling?) to gain informed consent and just start treating these privacy breaches as an outright crime.
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- hamdrew 2y agoI'm personally more worried about being clamped, but this is a step in the right direction.
- dingosity 2y agoThem: What's your LinkedIn Account? Me: Don't have one. Them: Twitter? Me: Nope. Them: InstaGram or TicToc? Me: Nope. Them: Do you use the web at all? Me: Only through Lynx. I see a lot fewer ads. Them: No JavaScript! How do you use YouTube? Me: I don't, really. Them: You have no social media? Me: Well... I *did* order a pizza from Dominos online once... Yeah... I don't use the web much as you would expect for someone who's livelihood depends on it. I just wish USENET was still USEFUL. I have a rant in me about ad-tech and crap-ware on the web. I'm just enjoying my life without the web too much to write it. And clearly, HN is my web-tech achilles heel.
- thih9 2y agoI find it funny that the authors are from Google, of Google Analytics, where the recommended way to opt out of tracking is to install a "do not track" browser plugin (not available on mobile). > Google has also released a browser plug-in that turns off data about a page visit being sent to Google, however, this browser extension is not available for mobile browsers. source: https://en.wikipedia.org/wiki/Google_Analytics#Privacy https://en.wikipedia.org/wiki/Google_Analytics#Privacy
- charles_f 2y agoDon't care too much about do-not-stab since I deployed a pi-bulldog on my network that catches all the back alley NSRs (network stab requests). I was thinking about using SDoH (self-defense over https) or AoT (AR15 over TLS) to be protected outside my network as well, but honestly the little stabbings here and there cause sufficiently little blood to be drew that its not worth the hassle.
- zombot 2y agoThe date in the title is wrong, it should be 2111. Most appropriately, because something as forward-thinking as this proposal cannot be expected to even come up within this century, let alone be accepted.
- vrighter 2y agoWell, given that we need to tell them what they are not allowed to do, vs what they they are allowed, we need some "Do-Not-X" standard convention for headers. For example, I have my browser send all of these with each request: Do-Not-Eat: 1 Do-Not-Insert-Into-Anus: 1 Do-Not-Do-Evil: 1 Do-Not-Chew-Loudly: 1 Do-Not-Forget-To-Bring-A-Towel: 1 Do-Not-Pee-Into-The-Wind: 1 Do-Not-Give-Me-Up: 1 Do-Not-Let-Me-Down: 1 Do-Not-Turn-Around: 1 Do-Not-Desert-Me: 1 Do-Not-Stab: 1 The last one I added just now because this article opened my eyes to this glaring omission.
- narrator 2y agoThis will probably become less funny when everyone has a home robot that can cook for them. A robot that can handle a knife with sufficient dexterity can be a trained assassin if the owner doesn't pay the extortion demand of the malware that has infected their robot.