Anyone in Wi-Fi range can exploit the device. The sensors of the air purifier can be used for spying, and the device could also serve as a hopping point for exploiting other devices in your home.
HN user
dessant
https://github.com/dessant
The issue is what happens to these toothbrushes in a couple of years when their vulnerabilities will be discovered. Their inevitable exploitation could be prevented by simply allowing to turn off bluetooth. Or even better, only enable bluetooth if the user wants to set up and use these smart features, at least in that case the vulnerable firmware can be updated using the smartphone app.
A warning about Philips electric toothbrushes: you cannot turn off Bluetooth on them, even if you are not using the smart features.
Also be careful with all Philips air purifiers that support Wi-Fi, because the remote control feature cannot be disabled. They create a Wi-Fi hotspot that you need to connect to with a smartphone to finish setting up the device, but if you don't use these features, the air purifier will create a permanent Wi-Fi hotspot, waiting to be exploited.
Of course, but these are thinner and prettier because of the pre-cut shapes.
LightDims solved the problem of bright and blinking status LEDs in our home, they sell sticker sheets in various colors that dim or completely block the light: https://www.lightdims.com/store.htm
Through a series of unfortunate events I ended up briefly owning seven brand new Beoplay Portal PC/PS headphones in the summer of 2022, and keeping the last one that was purchased in exasperation.
The products were all bought from three different authorized dealers across the EU, and despite the serial numbers and manufacturing dates being spread out, mostly all of the headphones had manufacturing deffects:
- The clamping force of the headbands had considerable variation, some of the headphones were very comfortable, one fell off from your head if you looked down, while two of them caused headaches after wearing them for 20 minutes
- The firmness of the foam inside the earpads and of the lambskin also had variations
- Some of the products made a popping sound if you slightly pressed the cushion on the headband
- The painted white L and R letters inside the earcups had various brown spots
- Three headphones made a squeaking sound when you adjusted the length of the arms, one of them was also squeaking during normal use
- The material of the storage bag was half as thick if the product had a later serial number
- One of the products had a broken BLE module and would not connect
I got some casual use out of the headphones I have kept for about 6 months, and despite treating the product like jewelry, the headband cushion material has started separating from a hidden seam. The product was quickly replaced by Bang & Olufsen.
An app is required to adjust the EQ and access other features that are advertised on the sales page, but the app forces you to sign up for a B&O account and share personal information such as your name and email address, then register the product. You couldn't find any information about the requirement for account setup and product registration anywhere, not on the sales page, and not in the user manual. I believe this is at least a GDPR violation.
The headphones sometimes forget the customized settings, and after a couple of months of use, the app now has a hard time connecting to the paired device.
The headphones all sounded great, but from what I've read and experienced, Bang & Olufsen seems to hide shoddy manufacturing tolerances behind bespokeness, even for their most expensive products, and I doubt this is the user experience the rich are craving.
From a quick look on GitHub the projects were not just an initial effort with little time invested in after release, but were actively developed for years. This year alone there are several releases which contain new features.
If I'm not mistaken, they were publishing the exact same version on both app stores, and the apps could be purchased or some of the features were put behind in-app purchases on Google Play. This is a reasonable funding model that has allowed many open source apps to thrive, though in this developer's case maybe it did not meet their needs.
Maybe it's not your intention, but from your comments it comes across like you're putting very little value on other people's work. It was probably a substantial effort that took years to bring these projects to the usability and popularity that they achieved. Again, i'm not sure why did the user above find it problematic to have a paid version of the app on Google Play, and the same version with the same features distributed for free on F-Droid.
I'm not familiar with these projects, so I'm not sure how much time it would take to just keep them afloat, but I've seen they are popular and beloved apps. Looking at the GitHub activity, they have been actively developed for years, and several releases a year also contain new features. This was more than likely a full-time job for the developer.
It's regrettable that the funding model of these projects did not work out, and that the developer sold these apps without informing users about the change of ownership.
Though it feels like at this point we are bargaining for the amount of free work we are expected to get from this person, while sneering at the prospect of there being a paid version of the app published on Google Play as part of the original funding model that was in place long before the sale.
Some of the largest projects on F-Droid are all funded either by having a paid version on Google Play, accepting donations, or a company funding their development by hiring the maintainers. Most of the software you can install from a distro repository are also developed in large part by people that are compensated in some form, if the project requires continued development.
Money always ends up in the equation when you have to invest years of your life maintaining and supporting a project. And that's perfectly fine and healthy, because it means you can find a path that does not result in either side being exploited.
As for your last point, I was not responding to developers selling out their users, which is unfortunate, but to the expectation to not have a premium/paid version of a software project distributed. I think the developer even shared the pro version for free on F-Droid (OsmAnd does the same), yet the existence of a paid version was regarded as something negative by the user above.
If you're uncomfortable with the taught of you or at least someone else funding the development of the software you use, you're only setting yourself up to be exploited.
Exactly what kind of funding does it need?
I assume your time also has value. Open source software does not have to be shared free of charge, especially not when you need to invest your time and money to package and distribute the software and offer support for the project. The kind of puritan definition of open source that you're alluding to is only playing into the hands of the megacorps that are exploiting their users.
People deserve to be compensated for their work, especially when their work finds an active audience, even if they maintain an open source project.
Oh, no. I liked those tools, but I don't let them update since they started having "premium versions".
Expecting project maintainers to solely fund the development of open source projects used by millions of people is the leopard that keeps eating our faces.
Web preservation projects usually submit their content to the Internet Archive, or at least make it accessible through the Memento protocol. It seems the blog you're looking for already has some archived pages.
https://timetravel.mementoweb.org
The asterisk at the end selects all the archived pages of the host:
https://web.archive.org/web/*/https://comediventareilmiocane.blogspot.com*Yes, and it's people's prerogative to write reviews criticizing the software that is published, regardless of whether it's paid or not.
Do you think that review was respectful, now that you know that the donation prompt was not obtrusive nor randomly shown (see my other comments, it has been explained in detail)? Don't you feel that the way this person expressed themselves was rather demeaning, and perhaps somewhat unjust?
It's definitely a strange proposition, but you could try it yourself.
Install Signal on your phone and start using it, in a couple of months you will be shown a donation popup a single time when you open the app. At this point uninstall the app and contact Signal's development team to send them an invoice for your invested time that has now been ruined when that donation prompt has interrupted your messaging experience.
Also call them beggars and panhandlers, after all that's perfectly reasonable, and even respectable.
You've lost the plot if you think that it is normal or acceptable to call the maintainers of an app or extension beggars and panhandlers if there is a donation prompt shown once a year when you open the app. Most people would in fact find it appalling and demeaning to treat people with such little respect. I think you should also take a second look at your own performance in this thread, and maybe ask a friend for an opinion about your comments, because that behavior is not normal either.
Of course, though the frequency of repeated abuse makes all the difference.
I think empathy is a much more relevant superpower, and the lack of it can be disgusting.
A donation popup is shown once a year, and only when you use the extension, it does not randomly interrupt your browsing experience. Te popup can even be disabled from the extension's options. It is similar to a donation prompt being shown when an app is opened, once a year.
That's what this person was complaining about, that they've seen a donation prompt once when they've initiated an image search with the extension.
There is no winning with some of these people, they want your time and the results of your work, they want it for free, and they want it to be neatly packaged and presented exactly the way that is most convenient for them. If you deviate even a little bit from their unreasonable expectations, you'll be promptly attacked.
Once your projects grow past a certain size, threats of physical violence also become a regular occurrence, here's a milder email I have received last year: https://i.imgur.com/LKJQq1p.png
This kind of harassment is happening every 1-2 weeks on different channels, we keep these private messages because everything has to be documented in case law enforcement needs to be involved.
It also feels awful to be called a beggar and a panhandler just because you're trying to find a balance and build a sustainable project by having a donation popup (that can be disabled) in your software.
This disgusting review was sitting at the top of the review page for Search by Image on the Chrome Web Store: https://i.imgur.com/P1QU176.png
This person has edited their review a couple of times in the past year which pushed it to the top, and also emailed me with a similar demeaning message. I've reported it to Google staff, and they thought that the review did not break their content policy, so they did not remove it.
So yeah, it hurts when you're offering so much of your free time for so little benefits, or none at all, and a couple of entitled jerks still manage to poison the well for everyone.
With each abusive message the thought of no longer offering up your time and the results of your work for free grows stronger and stronger. It's no surprise that people either quit, sell their open source projects, or stop offering it for free.
Personal data is shared with Google and the carrier, that's why they need to ask for consent to enable the feature.
Here's the consent popup: https://imgur.com/a/PIqcDgR
The design of such consent popups has been deemed illegal in the EU, Google was also previously fined [1] for a similar consent popup. The "REJECT" button needs to be just as accessible and needs to have about the same visual weight as the "ACCEPT" button, dark patterns like the ones you see in the RCS consent popup above are illegal.
[1] https://www.theverge.com/2022/1/7/22871719/france-fines-goog...
The constant nagging when you tell Google "no" shows how little respect they have for their users. Messages by Google, which is primarily an SMS app, is asking me every 1-2 weeks to enable RCS chats. The link for declining the request is small and easy to miss, while the AGREE button below it takes up 25% of the area of the popup.
Dear Google UX designers, the way you present your little "decline" links is illegal in the EU. I'm sure you've got these design directives from a product manager, but you can still say "no" to breaking the law.
Maybe they were referring to my extension :), as of now you can still access the old search results.
The classic reverse image search results from Google will not be around for much longer, I've been getting reports about my browser extension no longer working with Google Images in some regions.
Yandex Images also possibly going away or becoming heavily censored is also an issue for journalists and researchers, since it is the best performing publicly available reverse image search engine.
An important limitation of Web Speech API is that it only accepts audio from a microphone, you can't transcribe an audio file or a WebRTC call.
Access to a smartphone with NFC can indeed be an issue for some people, but it is still better than having to record videos of yourself holding your ID next to your face, then a couple of years later finding out that your personal data is freely circulating on the web because one of those sleezy identity verification services has been hacked.
The issue is not compatibility with Chrome. Projects that were otherwise ready for the Manifest V3 migration and have worked towards that goal in the last few months can no longer proceed with the migration, their work has been made obsolete. The code we wrote no longer works, and we don't even know how or if the issue will be addressed before the next major Firefox ESR release. If a solution is not released in the next few months, this issue will prevent some projects from migrating until the end of 2024, or they will have to contend with dropping support for Firefox ESR.
I hope reading the linked pull request thread and the comments here will make it easier to see what went wrong, and why listening to the people that work with these extension APIs is important.
It will affect cross-platform extensions that need to migrate to Manifest V3 this year. Some projects will be forced to stay on Manifest V2 just for Firefox, substantially increasing development cost because of the need to maintain both MV2 and MV3 versions across platforms, or abandon a substantial part of Firefox users and only support the most recent browser version, assuming that a fix is even implemented in the browser.
Regarding your edit, I have not demanded anything, but asked if it would be possible to delay the release, for all the discussed reasons. For which I have received a non-answer, "it has already been merged" is not a valid reason for not correcting a mistake, and asking people to invest even more of their time in this and repeat what has already been discussed in a new bug report was just the last drop that made the lack of respect for other people's time obvious.
I have taken the time to comment on the pull request before it was merged. I have mentioned several use cases, and offered an explanation for why the feature is important. If that is not enough for you and for Mozilla engineers, then perhaps the correct response is to simply abandon their platform. I've done my part, and I'm not going to further sacrifice my free time because some people have no concern about how their actions affect other people's lives.
It's certain that 2 years from now extension developers will still be getting support requests and receive negative reviews because of that commit, even if an alternative API is released in the next few months. But who cares, it's not you who has to find a solution and deal with users.
All of this could have been averted by simply offering an alternative API in the same browser version in which the new restriction was implemented. There was no pressing need to immediately restrict the API.
Disallowing the modification of Access-Control-Allow-* response headers will impact extensions that need to download page content.
Search by Image sets CORS headers for some images in order to download them from the content script before uploading to a search engine. In many cases an asset will only be served if the request contains the correct origin, referrer and cookies. Reproducing such a fetch request was impossible from a background page last time I tested, and even if configuring all aspects of a request becomes possible, it could still open up extensions to security issues, because it's difficult to figure out if certain data types would be sent by the browser if the request would be made from the page context, such as the referrer. We would also need to request additional permissions, such as access to HTTP cookies.
Extensions used for archiving pages would no longer be able to create faithful representations of the tab content. Advanced ad blockers such as uBlock Origin would be impacted as well. There is a general issue of extensions not being able to access certain parts of the page, such as a tainted canvas in Chrome, or a closed shadow DOM in Safari, and this restriction would make the problem worse.
You think it's fine to invite developers to begin porting extensions to Manifest V3, and then kneecap their work a couple of months later as they port their extensions, while also telling them to open new bug reports in which they need to spend time defending general-purpose computing? This is not a missing feature, but a limitation that has been added only to Firefox.