Comment by skullone

4 days ago

This whole project reads like amateur hour. Still using curl pipe to shell install and everything. Plus this lax security disclosure with just an outstandingly foolish security flaw. Gross.

It's a team of 3. It's not like they have a security team, dedicated testers. They were for very long releasing beta software. That in fact already worked.

  • If a core feature of your software requires security guarantees you can't just say they don't have a "security team" .

  • Could be a solo person or a team of 5,000. This is amateur hour, and they are not serious about their purported secure and private platform.

  • Oh, so when they advertise “Your Data, Forever and Secure”[1] in big bold letters on their homepage with total disregard for the truth of that statement they are just committing fraud. Got it.

    [1] https://radicle.dev/

    • The rest of that quote is:

      > All social artifacts are stored in Git, and signed using public-key cryptography. Radicle verifies the authenticity and authorship of all data for you.

      They're clearly not talking about privacy there.

      Is it embarrassing that their private feature was broken? Sure. But it's for the most part a publishing platform. Protecting users against a network adversary who wan't to know what they're publishing isn't exactly core functionality.

      4 replies →

To be fair even the largest companies are still using curl piped to sh in their Linux install instructions. And they are all fucking imbeciles.