When was the last time you saw a completely open residential wifi access point in the wild?
This seems a little like worrying about getting Dodo poisoning.
HN user
When was the last time you saw a completely open residential wifi access point in the wild?
This seems a little like worrying about getting Dodo poisoning.
It's an open poll on a website with no sampling and no detection for bad actors.
For goodness sake, this is literally useless. It tells us nothing.
Even a games website should be embarrassed of it's journalism trying to run this as a story.
"Sony correctly implements GDPR requirements in the EU" is a less exciting headline I guess.
For things like movies, they should have negotiated a contract where sold copies are sold copies and cannot be revoked (even if their right to sell/rent copies lapse).
It's difficult to see how this could ever be possible without significant legislation changes. Nobody (but nobody) offers this, and in the vast majority of the world you literally can't buy out music rights in this way for any licensed music in the titles. That's why literally no online store offers this.
The announcement only seems to have been sent to users in the UK and MoviesAnywhere is a US only service. Also StudioCanal are ultimately the rightsholder who would need to join MoviesAnywhere, and they are not members.
(I am a bit surprised they didn't bung Google and StudioCanal a bit of money to move them to Google Play to avoid the bad publicity though.)
Urgh, that's a huge downgrade. What a shame.
The fact this letter takes aim at something the paper doesn't say is pretty damning. The paper alledges that a series of high entropy identifying metadata about the users system is passed to a very large amount of third parties, including the site being visited, and that has potential to link the real identity of the user to the site they are verifying with.
Yoti's letter then gets angry that "face" data is not passed to third parties. That is not what is alleged.
Not to mention the repeated veiled threats about how they "could" sue academics investigating their systems.
It is absolutely incredibly sus as a letter.
TBH, even LinkedIn seemed to provide me with posts advertising events that happened two weeks ago a bit less pre-acquisition.
Individual self employed photographers successfully use the DMCA to get significant payouts from large publishers and news organisations every single day.
Like literally hundreds of thousands, every day.
No there aren't, because having identical builds of games with Denuvo actually removed and present is vanishingly rare.
If you compare a game that's had significant performance patches over a period of years and had Denuvo removed to the launch version (as so many of these videos are) then no shit you see performance differences, but it doesn't tell you anything.
That report wasn't suppressed. It wasn't published because the methodology had a 44% margin of error, and subsequently it was totally useless.
(https://arstechnica.com/gaming/2017/09/eu-study-finds-piracy...)
It doesn't provide data suggesting that piracy doesn't hurt sales. It literally doesn't provide any data at all.
The evidence for this supposed performance hit is basically zero.
That's worrying, because Apple Mpas is still a borderline useless hot mess.
That only works in the context of when the sender isn't the adversary, which isn't the case in an age verification system - it very much does treat the sender as the enemy and untrusted. And again, the revocation chain on the backend is not zero proof.
The point of this is that you can use the credentials on your phone to prove that you are an adult to a website using zero-knowledge proofs to avoid disclosing your identity to anybody.
No it isn't.
Literally that is not the scope document, and such a solution would not be permitted by the EU as compliant with the legislation.
The app isn't zero knowledge. A prototype workflow has been designed for a one way transfer to sites that is zero knowledge, but it doesn't actually deliver zero knowledge because it you have to verify your age with an external provider to get the credential (which is not zero knowledge), the app has to be secured with either Apple or Google's attestation services (which are not zero knowledge), and the site has to be able to check with the original external provider that the credential hasn't been revoked (which is in no way zero knowledge).
Twitter only supported 2FA using a mobile number for several years, so they quite possibly have that.
People are not always good at infosec for convenience, and Twitter's design for this was incompetent even before Musk's acquisition.
Given how on fire the rest of MacOS currently is I think incompetent management simply not caring about regression testing is more likely.
The EU has zero knowledge proof age verification systems
No, they don't. And they can't.
I hate to break it to you but services have been routinely blocking residential IPs associated with being part of VPN endpoints for the better part of a decade now. Akamai will even sell you (granted they are just reselling another vendors product) a database to do this.
The Pro really looks like it's struggling for a reason to exist given how much cheaper this will be and the difference in feature set.
Yes, 100%.
If they wanted the policial platforms and had offered to buy them from Warner as standalone for a tenth of the cost Warner would have snapped their hand off.
They need the IP for scale. That is what this is about.
You won't pass Google Play hardware attestation that way, and you won't find a bank in Europe or the UK that doesn't require that to log on to their website within five years.
The DSA European digital wallet spec currently requires Google or Apple attestation, so not for much longer.
And that is mandated by the EU.
Given the Times and the Guardian are British they will be archived by the British Library, as it's a legal obligation.
That doesn't mean anything American library that doesn't pay authors Public Lending Right fees gets to.
Just fucking revert the UI at this point. It's a disaster on macOS.
I'll believe it when I see it. Windows many problems are the results of five years of terrible strategy and not caring about if users actually like your platform. It will require sustained effort over a long period to fix.
Presentation of someone else's valid credentials is not fixable by any privacy-preserving mechanism.
And that is precisely why governments will never implement a privacy-preserving mechanism, which is exactly my point.
Compromised tokens would be trivially google-able within a day otherwise.
The EU Digital Identity Wallet isn't zero knowledge. I mean it's just not. It relies on Google Play Integrity Attestation on Android and the iOS equivalent on Apple devices because those give it a revocation mechanism, and those aren't zero knowledge.
https://github.com/eu-digital-identity-wallet/av-doc-technic...
It says that it wants to be zero knowledge, but it has no zero knowledge implementation and no plan of how it even possibly could be zero knowledge, and it never will precisely because that is incompatible with the revocation requirements set down by the EU.
There is no such thing in practice.
Anything with zero knowledge is never going to be considered robust enough by a government. Zero knowledge protocols really have no functional revocation mechanism.
I mean the main reason it exists is because. Nvidia spent a bunch of money designing and fabbing the Tegra for automotive use and nobody bought it so the project was desperate to find a customer rather than out of the goodness of their hearts. That's also why they sold it to Nintendo at a bargain basement price for the Switch.
I strongly suspect the reality is that they had to give Nintendo so much money back due to the complete failure of the bootloader security that they still produce the Shield as Jensen still demands they claw their way back to break even.