Join Nostr
2026-08-23 11:47:28 UTC
in reply to

Leon P Smith on Nostr: As Tad Stoermer explains, in this context, for an external threat, think of an ...

As Tad Stoermer explains, in this context, for an external threat, think of an unpopular foreign invader. The resistance movement is "simple" because the population has no difficulty identifying the abuser as a legitimate threat that needs a response.

Threats that develop internally, such as a politician who grows into a dictator, an abusive family member, abusive boss, or abusive coworker, attempting to point out the facts to other involved parties generally is not going to go well. The resistance is "complex" because it will be difficult to impossible to generate any kind of coordinated action against the abuse, because everybody will be debating whether or not it's really happening or not, or if you are just being overly dramatic.

Personally, my estranged biological brother and Donald Trump remind me a lot of each other. My dad reminds me a lot of the current Democratic leadership: he refuses to recognize that the issue is his problem too. It's easier and more convenient for him to blame me for the way my brother has treated me, than to live in reality.

It's related to "insider threats" in the IT sense: actually, in an act of physical mathematics, I came up with a scheme to tweak the password hashing process to force certain bad actors including internal threats to be slightly more "honest", for some value of "honest".

If mathstodon were to deploy this idea, then all passwords would be automatically suffixed with a phrase akin to "this password is for mathstodon.xyz, please report abuse to ..." or whatever.

Then when the password database is stolen, the password cracker must incorporate that phrase as part of their guess, otherwise their guess is wrong (even if the cracker guessed the correct password)

If on the other hand, the password cracker is guessing the magic incantation acknowledging the source of the password hash, then the cracker has that phrase in its possession, somehow, which is evidence that might lead to a report of the password leak back to the abuse reporting line.

I originally came to this methodology by thinking of it like a transmission medium. Of course this virtual "transmission medium" is purely game theoretic and has no underlying physical mechanism: rather it's attempting to impose a topological constraint on physical messaging networks, a theory of mind viruses if you will.

But of course the culture that IT has around crypto is beyond dysfunctional, so getting anything actually fixed is usually impossible, and difficult in the best of circumstances.