HN user

Derek_MK

332 karma
Posts3
Comments63
View on HN

Outside of bots and spam, third party Discord clients also often disable a lot of Electron's options that guard against XSS stuff escaping the sandbox, which is pretty dangerous. I wouldn't be surprised if Discord wanted to minimize the chance of some really big problem stemming from lots of users using these unsafe versions.

Firefox 74 6 years ago

Pretty sure the "new" part is the following:

But when we need an exception, you can now create one by adding custom sites to the Facebook Container.

Yeah, the SEC did. After the contempt hearing, they had to renegotiate what constitutes "material" information as a part of their settlement, and that was essentially Musk/Tesla's wake-up call of "Oh, we only just BARELY got out of that mess". So as a result, they've actually been following what the original spirit of the settlement was meant to enforce.

Of course, we're still seeing issues where Musk is getting sued for threatening workers on Twitter for unionizing, but that's a slightly different issue than lying about production predictions.

Recent highlights sourced from https://www.fcc.gov/news-events/headlines

* FCC Improves Access to 911 and Timely Assistance from First Responders - This is more-or-less explicitly requiring that phones in hotels, campuses, office buildings, etc be able to directly dial 911 without having to do any sort of prefix, that could be unknown or confusing in an emergency.

* FCC Bans Malicious Spoofing of Text Messages & Foreign Robocalls - This makes it easier for the FCC to pursue action against scammers who spoof caller ID (previously there were loopholes so that they couldn't take action if it was a text, or if the call originated from outside the US, or if it's a one-way VOIP call.

* FCC Authorizes $121 Million In Rural Broadband Funding In 16 States - Pretty self-explanatory

* FCC Reaches $550,000 Cramming Settlement with CenturyLink - This was in response to CenturyLink placing "unauthorized third-party charges and fees onto consumers' bills"

* Chairman Pai Recommends Approving T-Mobile/Sprint Merger - This one's more controversial, but you can make a strong case that allowing T-Mobile/Sprint (two relatively small providers) to merge would allow for them to compete at a higher level against Verizon and AT&T, increasing consumer choice and competition for most Americans. It also requires for them to sell off Boost Mobile to address competition concerns at the lower level, and to also invest a lot into pushing 5G technology.

So, in short, the FCC has been focusing on the following to improve the consumer experience with communications in the US:

* Pushing 5G tech

* Fighting back against robocalling and scams

* Increasing access to broadband in rural areas

TLDR/Background:

* Hutchins (MalwareTech on social media) used to be a black hat, and developed/sold a banking trojan that would become Kronos.

* Since then, he's given up black hat activity and began reverse-engineering malware and providing educational material along the same lines.

* He came into the spotlight when he realized that the Wannacry ransomware was attempting to contact a particular web domain that was unregistered. He registered it to see what they were trying to send and why, and found out that it was a global killswitch, fully shutting down the initial strain of the malware.

* After Def Con 2017, he was arrested at the airport when attempting to leave the US. He was being charged with devleoping Kronos, and prosecutors were effectively adding new charges in retaliation every time he refused to plead guilty.

* He eventually caved and plead guilty, and today was sentenced to a year of supervised release, with no jail time (Though he likely won't be able to enter the US again). The judge strongly indicated that the lenient sentence was due to the fact that he stopped breaking the law of his own volition, and started using his skills to better the world.

* This article doesn't mention it, but the judge also suggested that he and his legal counsel seek a pardon, which could potentially allow him to enter the US again. They are planning to go forward with that path.

It was definitely for the banking trojan he created and sold, that would later become Kronos. That said, he also became sort of a public figure in the field due to stopping the initial strain of Wannacry, so news articles were popping up talking about how he was at least tangentially related to Wannacry, and was recently arrested for malware charges. People saw that and started drawing the false conclusion that he created Wannacry.

I mean that's a perfect choice as long as your marketing strategy isn't to hope that people pay extra for the feature thinking that it's FSD. The fact that Tesla still hasn't done something like this is proof that they're kind of relying on people to think that autopilot is something that automatically pilots the vehicle, which it doesn't.

Can someone tell me what I'm missing here? The author is saying that, on hover, it indicates a different URL than what the href actually goes to, which is a much more serious issue than just "HTML element text doesn't match the href", which is also what most people here in the comments are talking about. But then the author calls for a solution of just enforcing that the element text match the href, which wouldn't fix this issue! I'm inclined to think that something's not right in this article.

A sort of ELI5 on this for those that may not be familiar with any of this:

Ray tracing algorithms require checking to see if a ray will intersect with objects in a scene. This takes a LOT of time, and if you want this to be interactive ray tracing (e.g. in a game, where you need a frame drawn in a very short time), you have to find ways to reduce the number of objects you're comparing the ray against.

A lot of the time this includes culling algorithms, which essentially give you very quick ways to say that a number of objects have literally no way of being intersected by a ray, so you can ignore them. There's also things like bounding volume hierarchies (BVHs), which says things like, if a ray doesn't intersect with a given massive invisible cube that contains objects, then it can't possibly intersect things contained in that cube.

This is a bit different of a solution. If I'm understanding it right, this involves simplifying the representation of the objects themselves, so that something that was once a lot of triangles to be checked individually, can now be checked as one object. This means that a) you don't have to check for as many intersections, and b) it uses a lot less memory.

The point is that, if an admin misconfigures the software, then the vulnerability is on them, and the software itself doesn't need to change (minus arguments of usability but that's a whole other can of worms).

I kinda went back and forth on this. The initial comments here made me think that this was basically the reporter saying "person with su can do su things".

Then I looked at the PostgreSQL statement, which said that the report claimed that users with a read-access role could do the su things, and they said that the claim was not true.

And then I looked at the actual report, which stated that you have to have the read-access role, and the execute-access role (or su).

So, what it seems like is that both parties didn't represent the actual situation well, but the root (ha) issue was that it was reported as "IF YOU HAVE READ ACCESS (and execute access) THEN YOU CAN EXECUTE ARBITRARY CODE!!11!!!"

I can totally understand it in cases where the alleged offense is something like uploading copyrighted content to YouTube, where there is clear evidence and an audit trail saying "Here's what you uploaded, here's when you uploaded it, and here's the point where the rights holder registered it in ContentID, etc"

But this is a case where they thought my account was a bot. And I contacted the guy, as a very real person. At that point it's pretty much just sticking one's fingers in one's ears yelling "NANANANANA"

Wow, I've never been able to get a real person at Google to review a case of supposedly breaking ToS. My Google account got suspended for "traffic pumping". I didn't know what "traffic pumping" was at the time but after looking it up, it looks like they thought I was a bot for a phone carrier trying to commit fraud: https://en.wikipedia.org/wiki/Traffic_pumping

For reference, I haven't ever used the Google account for anything like Google Duo, Allo, Hangouts, etc. There was an appeal system linked in the message saying "You broke the terms", but when I filled it out, about 24 hrs later I got a response saying "You can't appeal if you broke the terms", which seems inconsistent at best.

I managed to track down a Google support employee and basically told him "Hey, it should be obvious that I'm a real person and not a bot for a phone carrier". His response at first was "The appeal should work, let me know if it doesn't". I told him that it didn't work, and his response was "Well we're not allowed to help you if the automated system says you broke the terms. You must have broken the terms."

Happy for you getting anything out of them other than a brick wall, at least.

EDIT - To pre-empt some questions that may come up: I was using a unique, randomly generated password for my Google account. Plus, you have to be able to login to the account to see the "You broke the terms" message, so the password was definitely not changed.

A lot of the time, for PC games, someone will have made a plugin that integrates into both the split and the game that removes loading screen times, turning it into an "in-game time" run

Especially in the case of contempt of court. The whole reason why you'd hold someone in contempt is if they are willfully not doing what the court says. The SEC is telling the court "Look, he's literally here talking about how he doesn't respect us. He's willingly doing this."

You can use this argument for literally anything, it means nothing.

Apparently we live in a country where the government can murder thousands upon thousands of innocent Iraqi civilians, deny that it ever happened, and profit off of the destruction.

But god help you if you brutally beat someone to death