HN user

MattSteelblade

851 karma
Posts2
Comments152
View on HN

Not at all; standard IR procedure is scope -> containment -> eradication -> recovery. There is a fog right now; we don't know all the details. It seems to me that it's just as likely they weren't fully kicked out before or that the initial vulnerability wasn't remediated. You can't recover until the threat actor has been removed.

There is a lot of love in my group from years of MtG for drafting games, so 7 Wonders and Dune Imperium are consistent favorites. When we have the time, we'll do Twilight Imperium. We've enjoyed all three Nemesis games. We are currently also really enjoying Spirit Island. We've completed Gloomhaven: Jaws of the Lion and put in some serious time with regular Gloomhave as well. As LotR fans, we've also enjoyed the LotR LCG and War of the Ring.

Per the article, the issue is with recalled batteries that are going to take 18-24 months to be replaced that won't allow the bus to charge pas 75% or below 41 degrees and because of the risk of fire and lack of suitable fire mitigation equipment, can no longer be charged in garages. Not seeing any mention of an issue with the underlying technology.

It sounds like you're describing Google's proposal, which I believe is at least feasible (though likely uneconomic) unlike, say, Starcloud's. I don't think you are correct about the orbit, though; Google's proposal lists the satellites at 650 km, which would give them approximately 20 years in orbit without boosts. They list estimated life at 5 years given radiation concerns, so they almost certainly would purposely deorbit them earlier.

I never said Google wasn't serious; I said they are hardly betting on it relative to their other capital expenditures. Google rightfully describes this as a "moonshot." To date, the only public hardware commitment is two prototype satellites in 2027 for a feasibility study. Compared to the billions pouring into Waymo, DeepMind, and terrestrial data centers, this doesn't yet qualify as an "enormous" financial bet, even if the engineering intent is serious.

Not even a little; doesn’t pass napkin math. It doesn’t solve any problems while adding a litany of new ones: massive radiators for heat rejection, radiation hardening, and enormous launch + repair costs (assuming repairs are even possible). The idea exists to separate investors from their money; the product is the funding round.

Based on the comments in the thread, I sense I will be in the minority, but for most consumers this is a reasonable default. Broadly speaking, the threat model most users are concerned with doesn't account for their government. The previous default is no encryption at rest, which doesn't protect from the most common threats, like theft or tampering. With BitLocker on, a new risk for users is created: loss of access to their data because they don't have their recovery key. You are never forced to keep your recovery keys in Microsoft's servers and it's not a default for corporate users.

For password hashing, only short-output or broken hash functions have practical collision concerns. The odds of any random collision with a 256-bit hash, and not with a specific hash, is 50% at 2^128 inputs. Salting is a defense against precomputation attacks like rainbow tables and masking password reuse. Attackers crack password dumps by trying known password combinations, previously compromised passwords, brute force up to a certain length, etc. and using the hashing algorithm to compare the output.

Bitwarden is also a zero knowledge architecture built on E2EE; I would presume that is the standard in the industry.

Starcloud 1 year ago

This doesn't pass the sniff test. Please, show me the napkin math where this remotely adds up.

My dad was obsessed with this game while I was growing up and I was so proud to learn how to use DOSBox so that he could play it again. A very formative game for me and I get a nostalgic itch to revisit it every few years. Just seeing the title, I can hear the music playing.

The author posted a link to an article[1] showing that Mississippi's retention policies were not responsible for the increase in scores.

But I've gotten some plausible pushback from researchers who say that Mississippi has always held back lots of kids. In practice, the 2013 law didn't change anything.

...

In 2017, the average age of a fourth grade class is a minuscule 0.01 higher than the 1998-2013 average. That's no difference at all. This proxy is strong evidence that Mississippi's retention policies never changed in practice, which means it's entirely kosher to just compare their scores normally before and after reform.

[1] https://jabberwocking.com/mississippi-revisited-the-mississi...

Being able to disable it on the fly is the number one thing I miss the most. Additionally, it would be nice to interface through the app instead of the website, but that's definitely under nice-to-have; the website is functional on a mobile device.

This is, almost verbatim, my exact same experience. Used pi-hole as an excuse to get a Raspberry Pi. Used it for a long time but got tired of troubleshooting. Discovered NextDNS (from this site), and have been a happy customer since. NextDNS has not been perfect (it looks like they abandoned their app(s)), but it has the added benefit of working outside of my home network.

Unisys will pay a $4 million civil penalty;

Avaya. will pay a $1 million civil penalty;

Check Point will pay a $995,000 civil penalty; and

Mimecast will pay a $990,000 civil penalty.

With the exception of Mimecast, these are companies that are bringing in billions of dollars in revenue annually. How is this supposed to deter them?

To be clear, this wasn't an example of Amazon explicitly not having it in stock and she went to third parties looking for it or her shopping for better prices. In both of those workflows it is very obvious you are buying from a third party. Instead, she went to the product page, went to the color she was looking for and just hit add to cart. I will note that it does show a different seller, but you can't argue it is prominent; it's the smallest font on the entire page. Here is a link to an Amazon page with the product[1]. If you click on the different colors on that page, you'll see that most of them are shipped and sold by Amazon; this product was shipped by Amazon, but not sold by them. Here is a screenshot of the product page[2]. You'll see that "Pure luxury" is the actual seller, even though it is shipped by Amazon. As mentioned before, while it is directly below the Add to Cart and Buy Now buttons, it is the smallest font. I hope this explains how even though you are on the official store page, you can purchase from a third-party without realizing it. Amazon has been doing this more and more recently, but this was the first time it ever bit us.

[1] https://www.amazon.com/Stanlely-Quencher-FlowStateTM-Tumbler... [2] https://imgur.com/a/BBHf3N6