Sarah Jamie Lewis
sarahjamielewis@mastodon.social
<p>Cryptography and Privacy Researcher. President @ Open Privacy Research Society (<span class="h-card" translate="no"><a href="https://hachyderm.io/@openprivacy" class="u-url mention">@<span>openprivacy</span></a></span>).</p><p>Founder @ Blodeuwedd Labs (<span class="h-card" translate="no"><a href="https://mastodon.social/@blodeuweddlabs" class="u-url mention">@<span>blodeuweddlabs</span></a></span>)</p><p>Building free and open source, privacy-enhancing, surveillance-resisting tech like Cwtch (<span class="h-card" translate="no"><a href="https://fosstodon.org/@cwtch" class="u-url mention">@<span>cwtch</span></a></span>)</p>
Posts
-
Post #4304843
RE: https://mastodon.social/@staff/117016446554714236 fwiw, since I was very critical of the first ToS - this updated ToS looks much better. I wish there was an accessible historical diff. Though it seems pretty close in substance to the draft ToS shown back in October (https://github.com/mastodon/mastodon/discussions/36368) One almost insignificant quibble: I think "Content" might be too broadly defined as it relates to the worldwide licence for some features e.g. private profile n...
-
Post #4287207
RE: https://mastodon.social/@sarahjamielewis/117004428207034305 A few updates on the browser project: We've rebased the patches (purge genai/aiwindow/ML engines and purge newtab sponsored widget homepage) onto the latest 153.0 ESR tag with the intention of tracking that for the time being. Thanks to cliffmccarthy, we have a script that allows us to have significantly reduced patch sizes (details https://codeberg.org/basebrowserproject/organization/issues/13) - from 40+Mb of patches to les...
-
Post #4222992
RE: https://mastodon.social/@sarahjamielewis/116994970688711387 A big thank you to everyone who has started discussions / reaching out / testing patches. I've updated the AI removal patch to purge a few more files that I missed the first time around. There is also a new patch, that removes the newtab sponsor heavy/widgety home (808 files , 420419 deletions) There is also a PR open to document testing instructions for the curious. And I've opened some issues for discussions to each...
-
Post #4213022
TIL Deep within the firefox source tree, there is a binary file called adult_set.bin, it's a set of md5 hashes for "adult sites" https://searchfox.org/firefox-main/source/third_party/application-services/components/filter_adult/src/adult_set.bin Most of these were previously stored in the firefox source code as base64'd hashes, and have been reverse engineered (https://gist.github.com/roycewilliams/04ed6eb9509b83ce4d85873861c7f7b4) (thanks for documenting that @tychotithonus@...
-
Post #4175752
Plenty of discussion to be had about what should belong in the core of a browser, and what should be relegated to outside of the main source tree. And I think reasonable people can disagree about certain features. But can we all agree that the world would be a better place if the Firefox source tree did not have a module that cares about when the 2026 World Cup began?
-
Post #4151708
RE: https://mastodon.social/@sarahjamielewis/116967027925557386 To follow up on this, I have pushed an initial, experimental, exploratory patch to https://codeberg.org/basebrowserproject/organization This patch removes (not just disables) many AI features from desktop Firefox including: smart windows, model chat, link previews, smart tab groups, semantic search, on device model integration (translations) etc. 1605 files changed, 98 insertions, 852297 deletions I've tested that Firefox bu...
-
Post #4051441
Thank you everyone for all your interesting thoughts and pointers re: the crisis that is web browsers. A few general followups collected in one place: 1. "Servo is the future, we/you should target effort there" - I'm finding this argument more and more convincing as the line count of the amount of code I'm tallying that I'd like to be removed from FF keeps going up. I am somewhat amazed/shocked by the rapid introduction (and the code size) of recent "features"
-
Post #4023272
RE: https://mastodon.social/@sarahjamielewis/116959309031485270 Many have asked: "Ok, this sounds great, how on earth do we get there?" From the few conversations I have now had: no single project believes they will ever have enough capacity to do browser dev v.s. patch work. And no one will commit to exploration without some assurance that the base will receive long-term active development. Absent some leap of faith, it's likely up to a new project to commit to building that b...
-
Post #3995209
I've been playing around with using "base browser" as a stopgap and it's really all I want in a web browser - no branding, no labs, no telemetry, a few sensible safety defaults, but nothing that degrades general experience (and with the ability to go hyper restrictive if desired) The one downside is that you have to compile this browser from source, and its not a standalone project - its the firefox fork that serves as the pseudo-base of the Tor and Mullvad browser.
-
Post #3992855
If the independent, non-slop web has any future at all, then now must be the time for every firefox fork to commit to working together to maintain a hardfork isolated from Mozilla. It's a project that is too large to be handled by any small project alone (and maybe even all of them combined), but one that is too important to left under the guidance of an organization like Mozilla. Without such bold co-operation I fear we have already lost.
-
Post #3988469
It has always made me uncomfortable when privacy projects align themselves with VPNs. VPNs are, at best, a tool for rerouting traffic. There are a few good reasons for choosing to reroute traffic but none of those reasons are about privacy. And all of those reasons are predicated on an ability to trust the new provider *more* than the default/another. I'm skeptical of that trust in the best cases, I have no idea how it can be justified when/after a provider actively supports authoritarian...
-
Post #3865399
I have a vision in my mind for what I want my next era of computing to look like, and I have been making steady progress towards it for a little while; building the necessary pieces - I'm close to a point where I can be more public about this, which is very exciting. The Linux kernel is/was going to form a stable layer in that stack, but with recent developments in mind, I am more motivated than ever in exploring/contributing to alternatives. Very much time for projects to stand for someth...
-
Post #3724687
Many wayland problems can never be "fixed" because they are not "problems", they are fundamental to the very definition of what Wayland is and form the foundational UX philosophy of several compositors - and that's a problem. I've been using some variation of desktop linux has my main OS for decades, I've been building a wayland compositor and thinking about migrating my setup to the future. Some problems I can mitigate through extensions, others are only solva...
-
Post #3141332
Researching the history of &lt;thing&gt;, find a blog post by a standards body ostensibly authoritative about history of &lt;thing&gt; Blog post references &lt;book&gt; published in &lt;year&gt; by &lt;people&gt; - it&#39;s even linked, amazing! Click on link, get taken to library of congress archives, to a page about not &lt;book&gt;...a mislink maybe? Nope, after many minutes of searching, I come to understand such a book never existed, ne...
-
Post #2067986
My goal this morning was to beat my previous 1.5 mile run attempt which stood at 19:00 minutes - with an optimistic target of 18:00. Final 1.5 mile time: 17:46! Slowly getting faster.
-
Post #2067985
Last night was very clear, great seeing. Given the last picture I posted of Jupiter a few days ago, some people were curious about what could actually be seen through the telescope v.s. what came out in image stacking / compositing. So here is a direct capture from the telescope last night showing Jupiter at regular exposure (so you can see the moons), and then I cranked the exposure way down to reveal the atmospheric details - which came through amazingly.
-
Post #2067984
First outside run of the year, first 5km of the year, first time running up hills in 6 months. Ran 40 seconds slower than my end-of-summer PB. Very happy with that as a starting baseline.
-
Post #2040394
Have a first cut of @cwtch working on Tails! The onion grater config needs tightening and a few small code changes are needed to automate away some of the Tor config, but this work should pave the way for Cwtch running on operating systems with similar setups, like Whonix, too.
-
Post #990797
We ( @openprivacy / @cwtch ) are looking for a software dev for a short-term contract to tackle a set of Android-related issues for Cwtch. Specifically we are looking for someone who: - has experience with flutter (both desktop/android) - has experience with android / kotlin dev - is able to work in Canada Our budget for this is 4800-6000 CAD, and we estimate there is ~1 month of work, with the potential for more down the road. Please send recommendations/pitches to jobs@openprivacy.ca.
-
Post #958362
Camera telescope testing last night, wasn&#39;t the best seeing, but I always love a taking a nice photo of Jupiter + moons.
-
Post #949322
Testing out a new telescope camera, chance encountered a bird catching a ride on a thermal.
-
Post #925979
RE: https://mastodon.social/@sarahjamielewis/116217212888293322 Another example of how the slop permeates everything. Today while checking out some new metadata resistance papers, I came across one which talks about a project I originated (@cwtch) and manages to not only cite the wrong year and paper title, but also attributes the work to &quot;Lewis, Angel and others&quot; in the text or &quot;S. Angel&quot; in the references. Just why? What is the point in producing slop tha...
-
Post #744215
&quot;we are cancelling the free open source project tier you&#39;ve been using for years, to be considered for the replacement tier you will need to post the following statement of partnership on your website about that is focused on how great our new AI features are&quot; Oh...we&#39;re in *that* stage of the hype decline.
-
Post #725313
The extent to which core linux projects are laying the groundwork for age verification is very concerning. I understand why some believe they are compelled to do so, and why others feel that it may be better to implement the most minimal conforming implementation in the hopes of fending off something worse. But the line must be drawn such that no threat can obligate an OS to collect/store personal information - without that freedom, we face an uphill fight to protect general purpose computing.
-
Post #714724
The extent to which core linux projects are laying the groundwork for age verification is very concerning. I understand why some believe they are compelled to do so, and why others feel that it may be better to implement the most minimal conforming implementation in the hopes of fending off something worse. But the line must be drawn such that no threat can obligate an OS to collect/store personal information - without that freedom, we face an uphill fight to protect general purpose computing.
-
Post #661802
It&#39;s absurd how good running has been for my mood, the knowledge that I am able to cover significant distances at speed has done wonders for my ability to deal with the constant stream of bullshit.
-
Post #661801
Fun conversations attempting to game out the question &quot;to what extent is [an OS mandating data collection] / [mandating OS data collection] related to age legal in Canada?&quot; - Big difference between the acceptability of applying collection at the point of service of a restricted activity v.s. mandating general collection, even if it stays on device. - Charter FoE rights likely come into play when it comes to mandating the existence of parental controls, optional or otherwise.
-
Post #661800
I like how the internet has got to the point where random sites feature fake quotes by me, occasionally regarding research I never did, sometimes while working in positions I&#39;ve never held.
-
Post #506107
In fun legislative news, BC has finally stopped waiting around for the US to modernize, and has gone ahead and adopted permanent DST starting next week! &quot;Recent actions from the U.S. have shifted how B.C. approaches decisions that merit alignment, including on time zones. Making this change now reflects the current preferences and needs of British Columbians, and helps ensure the province is well-positioned to thrive, even when circumstances across the border evolve.&quot; https:/...
-
Post #425408
With all the discussion around detecting when a code repo contains commits authored by an LLM, I think it is important to note commits like the following in Mozilla Firefox from 2 weeks ago: "Bug 2011195 - When an agent commits, don't add itself as author" https://github.com/mozilla-firefox/firefox/commit/71cc24b6a400dbd434e4df37087960d94b764791 I don't think it's a good thing that Mozilla seem to be explicitly encouraging unattributed LLM code in Firefox.