RIP, Dan. I work with a lot of very smart people. So, I've gotten a bit used to it and don't normally find myself in awe of many people's intelligence. Dan was a person that I was absolutely in awe of. The fist time I met him very long ago (almost 20 years), he showed me code he wrote to share movies through abused DNS slaves... building a p2p network like Napser/Gnutella from the technology. No one had ever thought of such a thing. I don't think anyone else in the world knew DNS well enough to be inspired to think of it. He was so kind and friendly to everyone. It was fun to talk with him about tech/security because he had such enthusiasm and excitement... like a little kid on Christmas or a puppy. :) I learned a lot from him. I have nothing but great memories of him. I remember once when someone hacked him. He even took that in good humor and didn't let it bother him.
Possibly. There is very little to no private funding for true privacy products. I think this is one of the reasons that Proton had to initially rely on crowdfunding. Perhaps, this is because so many tech companies are stuck in the AdRev mindset where sharing customer private data is how they make their real money? If you look at the ecosystem, you see many privacy products are actually government supported either directly or indirectly. For example, the Tor Project has directly taken massive amounts of funding from the US Military and you may recall the story of how Microsoft was forced to buy Skype in order to open it up to surveillance or lose massive amounts US DoD software license contracts. Those are just two examples. But, there are really limitless cases. Trust Google? But, Google receives massive DoD/EU contracts. Apple? Same thing. Role your own? But, nearly all standard encryption and hashing algorithms were either developed by or reviewed by government funded academic researchers in the US or EU.
The way I think of the privacy ecosystem is that it makes dragnet surveillance much harder and it provides some protection if the government has specifically targeted you for data collection. So, companies/products like ProtonMail and ProtonVPN are good things. But, creating something that is 100% safe for the individual is impossible (or at best so impractical to be untenable).
This tactic has been used against companies friends of mine have started. I've only seen it used by large 20+ year old 1970s/1980s publicly traded companies, never someone like Tesla. The way it works is basically that you track where your ex-employees go after they leave. If they go to a competitor/disruptor start-up with out deep pockets, sue that competitor over trade secrets. It's nearly impossible to disprove in court. The competitor start-up exhausts its VC/Angel money on legal fees and goes bankrupt. Potential new customers are wary of using their tech because of the lawsuit. It's a lethal combination that ensures that you don't have to out innovate them. Stealing source code is one thing. I certainly understand suing over that. But, suing over stealing ideas about warehousing from a car company? Really? I don't see any justification for that other than a lack of faith in the ability of your own company to compete and innovate.
Full disclosure: I am shorting TSLA stock. I have worked on autonomous vehicles and do not believe Tesla's claims about their technology. I expect Tesla to go bankrupt sometime in the next few years. I'm even more convinced of this now that I see them using company-killer lawsuits against other competing start-ups.
In case anyone that doesn't follow the development of the library closely missed it, the main improvement in this version is the introduction of ECC support. ECC tends to be able to provide equivalent levels of security as traditional "big prime" cryptography (like RSA) with less computationally intensive operations. This is especially important in a library like OpenPGPjs that is primarily meant for in browser based web usage because it should make things, like sending and receiving mail, faster when ECC is used over older PGP public key encryption systems. For people that use ProtonMail's web based crypto on mobile or tablet devices, a switch to ECC would result not just in similar performance improvements but also in lower battery usage.
Currently, ProtonMail uses RSA keys, but this addition of ECC support to their web encryption library may mean that they are about to start switching users to ECC keys. Because using "larger" (when compared with equivalent theoretical strength RSA keys, for example) ECC keys is less resource intensive than using higher security keys in some other forms of cryptosystems (like RSA) it may also be an indication that ProtonMail is preparing to upgrade users to higher security/stronger keys.
Many cryptographers and organizations, including the US Government, have recommended for a long time that people migrate from older "big prime cryptography" based cryptosystems to ECC based cryptosystems for increased security.
I wouldn't say no one. There are a number of companies that trust Bitcoin enough to use it in trade for their goods and services. For example, ProtonMail (a secure private e-mail provider) trusts Bitcoin enough to accept it in trade for its services.
So, the same thing that gives the Euro and Gold value (that people will take it trade for goods and services) is one of the components accounting for Bitcoin's valuation. The majority of Bitcoin's value at this point is likely speculation. However some percentage of the value is not derived from currency arbitrage or speculation.
Even if Bitcoin trade participating merchants do not trust the market valuation of Bitcoin enough to be willing to hold Bitcoin for very long after they accept it as part of a transaction (and therefor immediately convert it to USDs) it is still valued by the participating merchant in line with the trade. The same could be said for the value of the electronic ledger recordings created by credit cards. They are generally viewed to have around equivalent value to USDs. But, they are not a currency either.
We will hopefully support ZCash in the future. But, unfortunately, we don't right now. I am a member of the ZCash forum, though. I have been keeping a close watch on the project/coin and am very impressed with it. I don't know anything about Monero. I either hadn't heard of it before or just didn't give it any attention after seeing it because of the flood of coins lately. Thanks for the pointer and endorsement of it - I will take a look at it when I have a chance.
Try to relax a bit. It is good for your health. :) Both of those features are under development. If you would like to see them sooner rather than later, perhaps you know some great programmers that you could recommend to [email protected]? Or, you could share ProtonMail's Careers page: https://protonmail.com/careers
If you're very concerned, you could use a high speed/volume BitCoin Mixer[1]. For example, if it currently has sufficient volume, something on the Darknet like BitBlender[2][3]. There are a number of different mixers out there. You could also, of course, wash the BitCoins by hand yourself.
Something similar happened to my dad. He had a pretty successful company providing security guard services mostly on government contracts. It wasn't very lucrative. He wasn't rich. But, it paid the mortgage and the bills and my siblings and I were well taken care of. Then, when I was around 9 or 10 or so, Wackenhut kind of raised a lot of money and became the Amazon of security guard services. They Amazon'd his company and everything he built just kind of slowly disappeared over the next couple years. He could have done OK getting a job as a security guard himself and working his way up or even changing careers (he was reasonably intelligent). But, something about his company failing broke him and he just kind of never did anything after that. My teen years were absolute chaos until I dropped out of high school and got a job driving a fork lift around 17 and moved out. I remember there being absolutely no food in the house for days and days. It was crazy.
I've had a bunch of friends/acquaintances that killed themselves (hung/shot/jumped off the GG) after their start-ups failed. But, they all did it during the first boom (90's). I haven't personally known anyone that's done it during this boom, yet. I think the difference might be that the bubble hasn't popped yet this time. People who fail can still easily go find work. Back then all the companies were laying people off. So, if your start-up failed there was basically no where to go but back home. Probably the majority of the people I knew in SFBA back when the bubble popped did that. It was crazy how suddenly highways that were packed with traffic could just be cruised down at the speed limit during rush hour with out touching your breaks until you got to your exit. It seemed surreal.
Well, side projects are different. I wouldn't really call them start-ups. I'm talking about a VC funded start-up or a start-up whose goal is to eventually be VC funded. You have to be all-in on that kind of thing or you will not be successful. That is so much the case that it is actually written into the Terms Sheet (funding contract). Usually, it says something like "100% of professional/employment activities".
It's not as important to be in SFBA as it used to be. But, it is still a major factor in success. I consulted for a start-up that had to move there despite not wanting to just because the potential employment pool was so poor in my area (Boston). In SFBA, $40K/yr to $50K/yr is probably not enough to cover just rent, taxes, and utilities. You still need to worry about food, transportation, health insurance, etc. And, you'd have to convince other people to join your "start-up" that was only a part time hobby for you. Attracting the first employees is one of the hardest parts because that is when your ability to cover their paychecks is most uncertain. I imagine it would be very hard to do if they see you're not all-in and absolutely convinced the company was going to be successful. And, who the first employees wind up being is one of the most risky parts... hire the wrong people and you're done.
I know a lot more people that founded a start-up and did not do well than I know people that did. The stories about the failures are usually not that bad (but some are terrible). A joke among that circle of friends and I is that a start-up is basically a really really expensive job application to a more successful start-up that someone else pays for.
I encourage people to apply to YC. Because, I believe entrepreneurship is good and the people I know that did well did very well. But, be honest with yourself - Do you have wealthy parents/a wealthy spouse/close friend? Will they support you while you get back on your feet? If so, for how long? That's a discussion you can have with them and get a verbal commitment before you just go for it.
I had a good long-time friend, that I was supportive of, start a start-up and fail. He wound up sleeping on my couch for an extended period of time. We're around the same age... I have health insurance, a pretty fat 401K and IRA, a vested pension, an emergency fund, and a lot of seniority at my job. He does not have those things.
As you get older, the choices you make now will look like they were very very different choices. Don't romanticize them- really think them through.
I think there's some truth to the family support part of this. I was just racking my brain trying to think of any founder I knew (and I know a ton of them) that was in the position of "success or potentially homeless". But, I can't. I think there's some variable confounding going on when YC and others talk about people in their early 20's being better positioned to do startups because they're less risk averse due to youth. I think they're less risk averse because it's not such a big deal for them to move back in with their parents if they fail. And, their parents are usually still working and therefor able to handle the strain of that.
Nearly every successful founder I know of had either very wealthy parents, very supportive family and friends, or both.
I don't see any shame in admitting that it's not about some romanticized risk taker ideal alpha geek, but rather about upper class kids lucky enough to have a bunch of built in risk arbitrage supports that they lucked out on being born with.
The most recent information visible in search about this guy's company shows he was making a little over $20,000/year. A recent traffic related arrest of someone with the same name as his in the same area where he is reported to live shows a residence in a cheap beach condo high rise in a low cost part of southern Florida.
All that misery he put out into the world and he probably only made around $20K/yr (probably from mentally vulnerable/disabled populations). Have any of you ever actually purchased a cruise vacation from a robo-caller that spammed you in the middle of the night?
Caller ID is a completely unauthenticated protocol. The system asks you what number you're calling from and you can tell it anything you want. It just believes you.
Contrary to what other people said, you don't need a special line or to involve a specialized company. Almost all opensource VOIP systems allow you to spoof caller ID with a configuration setting or a little scripting/programming.
It's not illegal to spoof caller ID in the US. Many companies spoof a main call-in number from all of their employee's desks. Some morally bankrupt companies like the New York Times have been found to spoof invalid phone numbers when they harass people through their phone system.
These robo-callers call my cellphone at all hours of the day and night. It really reduces my quality of life. I have to have my phone on at night because I'm perpetually on call. There was a span of nearly a month where I was woken up between 1AM and 3AM by someone telling me I won a cruise vacation.
Caller ID spoofing is probably the technology that best shows how poor engineering when thinking through communication protocols can have a massive negative impact on the world.
Caller ID spoofing is also the technology that allows people to "SWAT" celebrities all the time (using just a home PC) with virtually zero chance of ever getting caught.
The kind of odd thing is that these robo-calls have programmed such a gut negative reaction in me to anyone calling me that I will now go to great lengths to not do business with any company that calls me on the phone. Due to getting unrequested phone calls from them, I've dropped a domain registrar, an x86 server manufacturer, and an insurance company. One voice call is all it takes and I am done with the company... even if it is during business hours. I just cannot, and will not, work with a company that calls my personal cell phone with out first being asked to.
Search has been dramatically improved. Difficulties with large mailboxes are often a complex function of many variables with things like client side javascript decryption speeds often playing a large role. While testing is done with large mailboxes as part of the development process, the ultimate solution for people with extremely large boxes will likely be the use of the Bridge program with an IMAP mail client such as Microsoft Outlook. There are unofficial export programs available that call pull all mail out through Proton's API. An official, supported, export (and import) program is planned for the future.
I would drop Signal for that app, even if I had to pay for it.