Yeah, one of the last companies I worked for (pretty well known one in SV) enabled SSH on all Macs, and they used a default password...
HN user
0xfffff
This is cool! What about availability on phones/tablets? Can Elektron apps be easily ported?
Yeah, recently Project 0 did a few odd things... first the dramatic iPhone stunt, then more of silence post about Android kernel 0 day still today actively used to exploit Pixel phones...
Now more Windows bashing - I know they try to be independent, but its become pretty obvious who pays the bills. Wish Chris Evans would have a say.
Exactly, welcome back the good old Internet Explorer days!
love it!
Yeah, last 20 years were rapid growth. Places like Pudong didn't really exist just 20 years ago... hard to believe now.
At least we know that Google doesn't get it right either.
Yeah, that's not unusual.
Isn't that exactly what A/B testing is? I'd say lack of consent is the unethical part of it.
Hopefully the EU sues them - this is unacceptable. Facebook should have never been allowed to buy out its core competition.
I uninstalled all Facebook appps but WhatsApp so far - but with recent happenings and announcements around WhatsApp, it needs to go too. Its a bummer, since i always liked it a lot.
did you read the article? thats even addressed
not stupid, just good critical thinking. most people are too naive when using facebook as the past shows.
Its interesting that they can just get away with this so easily and make it the consumers problem. im also wondering how often consumers dont know nor realize they bought something counterfeit.
Wasn't DocumentDB the old name of Azure Cosmos DB? just marketing wise this seems like a bad choice for a name.
Neat idea. That's why u2fa is so important!
Saw this. Also was discussed at 35C3:
Correct, it doesn't. If you grab that cookie and then pass the cookie from somewhere else it will work.
Section 7.2.3 talks about cookie theft.
Microsoft seems to struggle the least at the moment amongst the tech giants.
Imagine that interview...
Google Guy: can you please take off your shirt?
Candidate: aeh... why?
Google Guy: Oh, I just want to give you a backrub.
Candidate: thats a bit strange...
Google Guy: No worries, its just to see if we get along well and so i know we can work together.
Candidate: No, sorry.
Google Guy: come on, I'll get you the job. How about a neck rub?
Candidate: i guess... ok
Google Guy: hehe. ( evil grin and proceeds)
Amazing how this is a common and recurring pattern at Google without much consquences - some of these folks had repeated violations!
I had the same thought - he seems to have indulged in the data quite a bit to come up with such a thourough analysis.
Wow, time flies. I still remember installing version 6.0 like 20 years ago or so for the first time. The client tools, like Enterprise Manager, were much better then, faster, more slick.
That's just called a hash chain, Bitcoin I believe just calls it a chain of hashes. The block data structure incl. salt and POW is what is so unique about Bitcoin.
Just a hash chain, pretty sure one can find much older ones. some old checksums might do that too. When someone says blockchain, in my book (and this might differ from others) - its about the consensus algorithm used to prevent tampering, like POW as introduced by Bitcoin.
Epic Games provided the following comment from CEO Tim Sweeney:
"Epic genuinely appreciated Google's effort to perform an in-depth security audit [...]
However, it was irresponsible of Google to publicly disclose the technical details of the flaw so quickly, while many installations had not yet been updated and were still vulnerable.
An Epic security engineer, at my urging, requested Google delay public disclosure for the typical 90 days to allow time for the update to be more widely installed. Google refused. You can read it all at https://issuetracker.google.com/issues/112630336
Google's security analysis efforts are appreciated and benefit the Android platform, however a company as powerful as Google should practice more responsible disclosure timing than this, and not endanger users in the course of its counter-PR efforts against Epic's distribution of Fortnite outside of Google Play."
Not surprising unfortunatley. That's the result of market dominance, a company can just act as they please. Chrome has become like IE in some ways (and the arguments of defenders are the similarly the same that Microsoft supporters had back then). Google probably hardly tests with other browsers, so it might not even be with malicous intent.
Win back the web was the Firefox motto to challenge IE, and it might be time again.
Surprised not more people mentioned or recalled this, its perfect for phishing. one click, thats it.
Was discussed already. Google is trying to do damage control and entertains that "do no evil" was not a bad idea but thats a thing of the past.
Just because people don't care about privacy, doesn't mean they dont deserve or in fact need it. But in fact most people care, or assume they have privacy. why does Google not show a red icon to users that these messages are not protected for instance. something browsers do? A company like Google should care about their user's privacy, but well thats the entire point of the article.