Elektrine
EN
Log in Register
Paige Chat Timeline Communities Gallery Videos Email DNS VPN Uptime Kairo
Back to Timeline
Remote

Darrel Miller

@darrel_miller@mastodon.social
mastodon 4.7.0-beta.1
  • Open on mastodon.social

HTTP Advocate, API Architect on Microsoft Graph, Editor of OpenAPI specification, Co-chair of IETF HTTPAPI working group. Architect for Kiota https://aka.ms/kiota

0 Followers
0 Following
11 Posts
Joined April 25, 2022
GitHub:
darrelmiller
Blog:
https://apievolution.tavis.ca

Posts

Open post
darrel_miller
Darrel Miller @darrel_miller@mastodon.social · Apr 26, 2026
Darrel Miller
@darrel_miller@mastodon.social

HTTP Advocate, API Architect on Microsoft Graph, Editor of OpenAPI specification, Co-chair of IETF HTTPAPI working group. Architect for Kiota https://aka.ms/kiota

mastodon.social
Replying to @josepvives@mastodont.cat
@josepvives @nuclearplayer Yeah. I can see that some random anecdote from a Microsoft employee is not any kind of assurance. It is frustrating from my perspective because we have to jump through hoops to get any kind of useful data to be "data driven" in our product work but from the outside world we are perceived to be partying on everyone's private data. More transparency would be good for everyone.
0
0
0
0
Open post
darrel_miller
Darrel Miller @darrel_miller@mastodon.social · Apr 26, 2026
Darrel Miller
@darrel_miller@mastodon.social

HTTP Advocate, API Architect on Microsoft Graph, Editor of OpenAPI specification, Co-chair of IETF HTTPAPI working group. Architect for Kiota https://aka.ms/kiota

mastodon.social
Replying to @dalias@hachyderm.io
@nuclearplayer @dalias the "legitimate interests" GDPR clause for pseudonymous information does seem to make this a grey area, but IANAL and I am not trying to make a judgement on what GitHub did. I'm trying to learn about the objections. I understand the desire for consent but we can see from the "accept cookie" mess that users can just be coerced to consent via fatigue. I wish we had a standardized opt-out mechanism like DNT tried to do.
0
1
0
0
Open post
darrel_miller
Darrel Miller @darrel_miller@mastodon.social · Apr 26, 2026
Darrel Miller
@darrel_miller@mastodon.social

HTTP Advocate, API Architect on Microsoft Graph, Editor of OpenAPI specification, Co-chair of IETF HTTPAPI working group. Architect for Kiota https://aka.ms/kiota

mastodon.social
Replying to @josepvives@mastodont.cat
@josepvives @nuclearplayer Sure it is technically a simple problem. But there are many processes in place that prevent that from happening. Accessing customer content is very tightly controlled. Privacy is something I care about and it is one of the reasons I chose to work at Microsoft rather one of the other big tech companies that do not have the same guardrails in place.
1
2
0
0
Open post
darrel_miller
Darrel Miller @darrel_miller@mastodon.social · Apr 24, 2026
Darrel Miller
@darrel_miller@mastodon.social

HTTP Advocate, API Architect on Microsoft Graph, Editor of OpenAPI specification, Co-chair of IETF HTTPAPI working group. Architect for Kiota https://aka.ms/kiota

mastodon.social
Replying to @w@11n.org
@_aD @w I don't think anyone feels entitled. I think the product owners want to provide the best experience for their users and knowing how the product is used helps. For tools that primarily are clients for a backend service, then the service will know whenever a service call is made. I'm trying to fully understand the objection to capturing some additional usage information that doesn't make a service call. Is it the "slippery slope " problem?
0
1
0
0
Open post
darrel_miller
Darrel Miller @darrel_miller@mastodon.social · Apr 23, 2026
Darrel Miller
@darrel_miller@mastodon.social

HTTP Advocate, API Architect on Microsoft Graph, Editor of OpenAPI specification, Co-chair of IETF HTTPAPI working group. Architect for Kiota https://aka.ms/kiota

mastodon.social
Replying to @darrel_miller@mastodon.social
@nuclearplayer And as a Microsoft employee, my experience has been that we are extremely careful about not logging any information that directly identifies users and any customer created content. It isn't lip service to privacy. I've seen projects delayed while we scrub logs because a developer accidentally logged the name of some artifact that they should not have.
0
4
0
0
Open post
darrel_miller
Darrel Miller @darrel_miller@mastodon.social · Apr 23, 2026
Darrel Miller
@darrel_miller@mastodon.social

HTTP Advocate, API Architect on Microsoft Graph, Editor of OpenAPI specification, Co-chair of IETF HTTPAPI working group. Architect for Kiota https://aka.ms/kiota

mastodon.social
Replying to @darrel_miller@mastodon.social
@nuclearplayer I would think the important thing is what data is being collected, not the the fact that any data is being collected. If that remote site is collecting end user identifiable information, that should be as big a problem as if a local tool is doing it. What is good about a "source-open" collecting the telemetry is that you can see and verify what is being collected. You can't with a remote service.
0
5
0
0
Open post
darrel_miller
Darrel Miller @darrel_miller@mastodon.social · Apr 23, 2026
Darrel Miller
@darrel_miller@mastodon.social

HTTP Advocate, API Architect on Microsoft Graph, Editor of OpenAPI specification, Co-chair of IETF HTTPAPI working group. Architect for Kiota https://aka.ms/kiota

mastodon.social
Replying to @darrel_miller@mastodon.social
@nuclearplayer When you call an API or make a git request to some remote repo, there are going to be logs of that activity on that remote site. We acknowledge that site owners need some visibility into what is happening on their service. However, when it comes to code that is downloaded and executed on a local machine there seems to be an expectation that the code owners no longer have any rights to see how that code is executing. Help me understand why the rules are different.
0
13
0
0
Open post
darrel_miller
Darrel Miller @darrel_miller@mastodon.social · Apr 23, 2026
Darrel Miller
@darrel_miller@mastodon.social

HTTP Advocate, API Architect on Microsoft Graph, Editor of OpenAPI specification, Co-chair of IETF HTTPAPI working group. Architect for Kiota https://aka.ms/kiota

mastodon.social
Replying to @nuclearplayer@fosstodon.org
@nuclearplayer I'm going to put on my lead lined suit here and ask a question because I genuinely want to learn. This issue comes up time and time again. The GitHub CLI telemetry provides product owners with information about how their product is used. You can see what it captures here https://cli.github.com/telemetry It is pseudonymous data. There is no user identifying data there. So yes the telemetry is spying on what the app is doing, but not on which user is doing it.
1
20
0
0
Open post
darrel_miller
Darrel Miller @darrel_miller@mastodon.social · Dec 31, 2025
Darrel Miller
@darrel_miller@mastodon.social

HTTP Advocate, API Architect on Microsoft Graph, Editor of OpenAPI specification, Co-chair of IETF HTTPAPI working group. Architect for Kiota https://aka.ms/kiota

mastodon.social

In some ways, typing really was the blocker. It turns out that there are dozens of little "building block" libraries that I have always wanted to write, but just never found the time. Not really complex stuff. Just take a written specification that has done all the hard thinking and turn it into a library that meets my requirements.
Being able to turn specification words into packaged code with tests and docs in a trivially short amount of time, is actually a very handy thing.

0
0
0
0
Open post
darrel_miller
Darrel Miller @darrel_miller@mastodon.social · Nov 21, 2025
Darrel Miller
@darrel_miller@mastodon.social

HTTP Advocate, API Architect on Microsoft Graph, Editor of OpenAPI specification, Co-chair of IETF HTTPAPI working group. Architect for Kiota https://aka.ms/kiota

mastodon.social
Replying to @eythian@teh.entar.net
@timbray@cosocial.ca @eythian@teh.entar.net Technically you can, but technically it has no semantic meaning so you can't do anything useful with it. Any HTTP message can have a body. However only some methods allow the body to have meaning for the request. GET and DELETE don't, POST and QUERY do. It's a layering thing in the design.
0
1
0
0
Open post
darrel_miller
Darrel Miller @darrel_miller@mastodon.social · Nov 09, 2025
Darrel Miller
@darrel_miller@mastodon.social

HTTP Advocate, API Architect on Microsoft Graph, Editor of OpenAPI specification, Co-chair of IETF HTTPAPI working group. Architect for Kiota https://aka.ms/kiota

mastodon.social

The A2A Agent card TypeScript definition has protocolVersion field that is required but has a default value. That is enough to make my head explode. But I need to translate that into proto3. If you have ever explored the saga of field presence in protobuf, you can probably imagine how I feel right now.

3
0
0
0

Remote instance

mastodon.social
Open on original server
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • Communities
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • Lite (no JS)
  • VPN Policy
  • Source code

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 08:04:16 UTC