HN user

crivabene

692 karma

[ my public key: https://keybase.io/crivabene; my proof: https://keybase.io/crivabene/sigs/rmFFTfXhgBXmkBiak-1t_jIgW_cuHGoqgU1HwQrOUTY ]

Posts124
Comments65
View on HN
www.businesswire.com 7mo ago

Bending Spoons Acquires Eventbrite

crivabene
9pts4
www.brightcove.com 1y ago

Brightcove Acquired by Bending Spoons

crivabene
5pts1
www.wsj.com 2y ago

McDonald's Technology Outage Forces Restaurant Closures

crivabene
19pts17
www.nature.com 2y ago

Potential for rupture before eruption at Campi Flegrei caldera, Southern Italy

crivabene
1pts0
www.theguardian.com 2y ago

My father had a lifelong ticket to fly anywhere. Then they took it away

crivabene
7pts4
www.bellingcat.com 3y ago

Socialite, Widow, Jeweller, Spy: A GRU Agent Charmed Her Way into NATO Circle

crivabene
3pts0
www.theverge.com 4y ago

Okta hack puts thousands of businesses on high alert

crivabene
6pts0
twitter.com 4y ago

The only Antonov An-225 Mriya has been destroyed

crivabene
21pts4
time.com 4y ago

How Open Source Intelligence Became the World's Window into the Ukraine Invasion

crivabene
3pts0
www.euronews.com 4y ago

Meta threatens to shut down Facebook and Instagram in Europe

crivabene
4pts0
www.nytimes.com 5y ago

FDA Approves Alzheimer’s Drug Despite Fierce Debate over Whether It Works

crivabene
1pts0
blog.google 6y ago

Shoploop: An entertaining new way to shop online

crivabene
3pts0
github.com 6y ago

Italian Contact Tracing app source published on GitHub

crivabene
7pts3
www.allthingsdistributed.com 6y ago

Introducing the AWS Europe (Milan) Region

crivabene
1pts0
www.bloomberg.com 6y ago

Hedge Fund Managers Claiming Bailouts as Small Businesses

crivabene
2pts0
www.theverge.com 6y ago

British 5G towers are being set on fire amid coronavirus conspiracy theories

crivabene
14pts0
www.ft.com 6y ago

We face a war against coronavirus and must mobilise accordingly

crivabene
1pts0
theintercept.com 6y ago

Why I’d Rather Be in Italy for the Coronavirus Pandemic

crivabene
3pts0
thehustle.co 6y ago

Inside the wild world of government auctions

crivabene
1pts0
techcrunch.com 6y ago

The U.S. is charging Huawei with racketeering

crivabene
311pts301
theintercept.com 6y ago

After a livestreamed suicide, TikTok waited to call police

crivabene
54pts36
www.cncf.io 6y ago

The Illustrated Children’s Guide to Kubernetes

crivabene
3pts0
medium.com 6y ago

Steve Jobs’ Secret for Eliciting Questions

crivabene
1pts0
www.askthepilot.com 6y ago

Notice to Readers: Website Issues

crivabene
1pts0
investor.symantec.com 6y ago

Symantec Announces Sale of Enterprise Security Assets for $10.7B to Broadcom

crivabene
1pts0
www.cnn.com 7y ago

KLM to fund development of fuel-efficient Flying-V plane

crivabene
4pts2
blogs.windows.com 7y ago

Announcing Project Rome SDK for Android and iOS

crivabene
3pts0
www.cnbc.com 7y ago

Alibaba sets new Singles Day record with more than $30.8B in sales in 24 hours

crivabene
7pts0
fortune.com 7y ago

New Amazon Store Promises 4 Stars or Better for Every Product Sold

crivabene
1pts0
medium.com 7y ago

Making the Adobe Cloud More Resilient – With Chaos

crivabene
2pts0

I love ThinkGeek’s April Fools - they always come up with super creative ideas. And that’s why I love April Fools in general - one day when everyone can be silly and take a breath from the usual routine.

Regarding the downvotes... oh well, I guess you’re right. :(

Not sure about Australia, but the most common reason would be local regulations (i.e. laws forbidding to store certain data outside of the borders of a particular region). But given we're talking about Australia, I would not rule out the latency at all.

Here's an excerpt taken from the EU Internet Handbook [0]:

Cookies clearly exempt from consent according to the EU advisory body on data protection- WP29 [1] include:

- user‑input cookies (session-id) such as first‑party cookies to keep track of the user's input when filling online forms, shopping carts, etc., for the duration of a session or persistent cookies limited to a few hours in some cases

- authentication cookies, to identify the user once he has logged in, for the duration of a session

- user‑centric security cookies, used to detect authentication abuses, for a limited persistent duration

- multimedia content player cookies, used to store technical data to play back video or audio content, for the duration of a session

- load‑balancing cookies, for the duration of session

- user‑interface customisation cookies such as language or font preferences, for the duration of a session (or slightly longer)

- third‑party social plug‑in content‑sharing cookies, for logged‑in members of a social network.

[0] http://ec.europa.eu/ipg/basics/legal/cookies/index_en.htm

[1] http://ec.europa.eu/justice/data-protection/article-29/docum...

As a European who had to make sure the provisions contained in this law were implemented on a few high-traffic sites targeting consumers, I can definitively say that the law is at least a little bit "controversial" and unclear. We had to request the assistance of a law firm to make sure we complied.

Originally it looked like you had to give the users an option to decide if they allow the use of tracking cookies or not, potentially having to deal with NOT pushing such cookies in case the user did not consent. In reality, most of the implementations I've seen are just informing the customers that tracking cookies are used and let them know that usage of the site represents consent of such usage, adding that they can modify the browser preferences if they want to modify their cookie preferences. Additionally, you have to link to a cookie policy that you publish on the site.

As a clarification, this law does not apply to cookies in general: certain cookies, sometime referred as technical cookies (e.g. session) are exempted as long as they're not used for tracking purposes.

In the post they mention the probable cause is a developer account which got compromised. One of the most important rules of most security frameworks (including PCI DSS) is segregating access between development and production: developers are not supposed to be able to access production data. I suppose this rule was not followed here - or an alternative mitigating control (which can be applied instead of the rule above) was not good enough to prevent this.

Does anyone remember WinFS (1)?

Bill Gates described it as his biggest product regret (2).

I remember I thought it was brilliant. Too bad it was probably a little bit too futuristic for its time, as for a few other things they launched when it just was not the right time... the clunky Tablet PCs (3) were for sure another example.

(1) https://en.m.wikipedia.org/wiki/WinFS

(2) http://www.zdnet.com/article/bill-gates-biggest-microsoft-pr...

(3) https://en.m.wikipedia.org/wiki/Microsoft_Tablet_PC

We'll see. They can try to get an appeal court order blocking the original one, or they can just continue to operate and pay the 10k/day fine, which is nothing for them. The problem is that if they do so then I am sure they'll not make their life easy...