What you're seeing is the distilled (no pun intended) result of realpolitik at play. China's labs aren't as open as they are out of altruism, but rather to capitalize and undercut the monopoly held by U.S. competitors.
HN user
digdigdag
Depends. Are you a Chinese/Taiwanese national or diplomat who holds a strategic value to the CCP?
We didn't review the entire source code
Then it's not fully investigated. That should put any assessments to rest.
My local GPS + PPS based NTP server finally pays off.
None of my opinions of this manifesto are positive. This is a defeatist position. It dangerously conditions people to be more casual about their privacy and safety.
There are still legitimate reasons to clear cookies, to turn off Bluetooth/NFC beaconing, and to occasionally rotate passwords (vis a vis password managers) as it costs nothing to accomplish, and very little in the way of tradeoffs. So...why not?
The probability of a random individual being the target of a sophisticated state sponsored attack is low, but the probability of being caught up in a larger dragnet and for data to be classified, aggregated and profiled is very high. So why not make it just a bit harder for them all?
If anything, let's chip away at this problem bit by bit. Make their life a bit harder...their datacenters a bit hotter. Add random fud to the cookie values, constantly switch VPN endpoints, randomize your mac address on every WiFi association, constantly delete old comments, accounts, create throwaway accounts, create proxies and intermediaries, rotate your password and 2FA -- use any legal means to frustrate any adversarial entities -- commercial or otherwise. They want information? They want your data? Fine, overwhelm them with it. THAT should be the proper modern privacy-focused manifesto. This is utterly bewildering...
...but then I get to the signatories and this nonsense suddenly made all the sense in the world:
Sincerely, Heather Adkins, VP, Cybersecurity Resilience Officer, Google
Aimee Cardwell, former CISO UnitedHealthGroup
Curt Dukes, former NSA IA Director, and Cybersecurity Executive Tony Sager, former NSA Executive
Ben Adida, VotingWorks
Geoff Belknap, Deputy CISO, Microsoft
The corporate CISO club is behind this.
Why would (should) they? The tarrif is biggest contributor to the would-be price increase, and they want to offload the blame to the policies that enacted it.
Why do you think you get a breakdown of governmental fees in your electric or phone bill, but not the tax subsidies?
- Over 50% of the workers flew in from Taiwan to work on this plant and make these chips.
- The chips still need to fly back to Taiwan to be packaged as there are no facilities here with such a capability.
Made in america is a hard sell. But at least showing the glaring STEM field gap in the U.S. is a start to finally addressing the brain drain.
How about we continue using something more convenient like a standalone dryer and focus our energy usage reduction on the largest target -- which is manufacturing by a whopping 76% of the total electricity consumption in the United States (https://www.eia.gov/energyexplained/use-of-energy/industry.p...) as well as transportation. Nothing else comes close.
Quirky Japanese technology is not the solution.
Before anyone jumps on a new text editor band wagon, just a note on the license they have you agree to in using it:
"Customer Data consisting of User content created while using the Solution is classified as "User Content". User Content is transmitted from Your environment only if You collaborate with other Zed users by electing to share a project in the Editor.
[...]Zed's access to such User Content is limited to debugging and making improvements to the Solution."
No commentary from me. Come to your own conclusions.
You can examine the contents of the shell script yourself -- but how is this any different from running the rest of the application without examining the source?
Do you just draw some arbitrary line to say, "running easily readable shell scripts is bad, but compiling and running code I have never looked at or completely understand is okay."?
Really the only logical answer here is to adopt a zero trust security model and just assume every line of code is compromised. Run it in a VM, in a container, firewall it, jail it, sandbox it, etc.
Otherwise you're whispering sweet nothings to yourself if you believe piping unknown scripts to shell is the most vulnerable thing you can do here.
Why not? There are perfectly legitimate uses for this kind of technology. This would be a godsend for those suffering from paralysis and nervous system disorders, allowing them to communicate with their loved ones.
Yes, the CIA, DARPA, et. al. will be all over this (surprisingly if not already), but this is a sacrifice worth making for this kind of technology.
And expensive...and out of reach of most of the people who need it.
Yep. I have Monaco installed on my Linux and Windows machines as a basic requirement for doing any sort of plain text editing.
Why anyone would continue to use their service after their amateur hour operation was revealed is beyond me. That's not to say their competitors are guaranteed to be better. Really, you shouldn't depend on any offsite service for password management. Use something like Pass (https://www.passwordstore.org/), self-hosted bitwarden or at worst, GPG encrypted text files (which is essentially what Pass does).
If Digg is of any indication, it takes a series of negligent and greed-driven actions to scuttle a social media platform, but it is possible.
Reddit has been more or less re-inventing itself for their asinine IPO aspirations, and in doing so it has moved to closed source code, redesigned their interface, adjusted content policies to court advertisers, and now they're finally going after the crowd of enthusiasts who depend on features that Reddit has failed and/or declined to implement.
This all reeks of venture capitalist sabotage and it's the very thing that ultimately killed off Digg.
Instead of warning consumers, why not do what regulators do and, well, regulate? Here, you have entities storing unsecured funds and doing god knows what with it. In the interest of the public good, a just government and a conscientious regulatory body wouldn't busy itself warning anyone. Rather, they would be bringing down the hammer on these entities and making them an example of what happens to companies that try to destabilize the financial system.
Disappointing. Sad to see such a wonderful app likely meet its end. This is to be expected when you pin your existence on the good graces of a for-profit company.
Reddit wants IPO. Badly. They want to show potential investors that they're solvent. To this end, as Google did nearly two decades ago, they will monetize every inch of their user base and application -- that includes access to their data.
But Reddit is on thin ice -- as MySpace, Digg, del.icio.us all found out and as Twitter is finding out.
Why? Reddit doesn't have any asset of intrinsic value. Reddit don't have sought after intellectual property. Reddit doesn't produce any goods. Reddit's value is the community and the data they bring. When they antagonize the community, they are antagonizing what is keeping the lights on for them.
Providing feedback to large corporate machines is akin to screaming into the void at this point. Sometimes the void hears you and responds with a generous canned message. Other times you unsurprisingly get silence. That's why I became completely divested and disinterested in providing general feedback for maps, locations etc.
1. These jobs are situated in Africa for the precise reason that other usual outsourcing countries have become increasingly expensive and prohibitive for this type of work. These workers are exposed to the most vile things the human mind can produce and they do it for starvation wages day in and day out.
2. Their leverage is their sanity and willingness to be able to be exposed to unconscionable content. Many places in the world would categorically block this kind of gig simply for being damaging to the mind, and rightly so. And even in countries where this work is permissible, it would otherwise expose the company to future liability in terms of emotional trauma.
3. This 80% figure is a number fabricated from thin air. These workers don't work in call centers. They are content moderators in some shape or form -- a job that requires not just reading comprehension but being able to weigh certain current events, cultural queues, unspoken and spoken language, and other data that you can't magically feed into a machine.
S
Because it's in reference to "honor killings" that still take place in certain cultures.
Beyond the serious dependability questions Google raises, I feel bad for the millions of units of OnHub, Nest, Stadia, and other hardware that are still perfectly functional, but rendered obsolete because of what amounts to high level, corporate financial decisions.
Any company engaging in mass market IoT sales should be compelled, for the sake of consumer confidence and protection, of an "exit plan" to allow fully localized control of these devices -- independent of an upstream server or system.
Ten years in IT, I've been part of roughly 4 acquisitions across a few jobs. Each time the line delivered to the employees is more or less the same: "don't worry, we don't intend to change anything. It's business as usual".
Then a few months in, the warning signs begin. New HR documents to sign. New benefit schedules. Then there's some turbulence from above -- talks of upper management getting reshuffled. New org charts.
A few months after that, there's new customers to support, new SLA guidelines, new meetings for us to attend. _Then_ it's your organization that starts getting sacked.
It's all just a cynical dog whistling to get people to stay complacent and continue turning the cog while they pull the rug out from under you.
Thankfully I've become adept at the skill of jumping ship when I see the first leaks, if you know what I mean.
Do you have any studies that link microplastics to early onset colorectal cancer or you're just making wild claims?
No, more like X-37B, but perhaps one that can skim the atmosphere, i.e. with scramjet propulsion.
I don't see how China would willfully continue send these balloons without expecting a symmetrical escalation. Sure, they managed to send a few relatively undetected until the past recent weeks, but continued attempts would surely produce a physical response from NATO states, whether that's sending balloons of their own or overflying Chinese territory with other aircraft, or increased signals intelligence operations.
1. The federal interest rate is nearly at 5%. Any business operating depending on lines of credit are going to hurt (Source: https://www.federalreserve.gov/releases/h15/)
2. Consumer spending is down (Source: https://www.bea.gov/data/consumer-spending/main).
So you have the producers spending more to operate, and consumers spending less. This leads to an inevitable contraction in the economic output.
Also known as recession.
It's not just professionalism. It's intentional and codified down to how you pronounce numbers: https://www.faa.gov/air_traffic/publications/atpubs/aim_html...
Does Google still use PageRank anymore? The search results are so bad these days, I'm dubious on how many other websites reference the top results they show.
I think the sense entitlement goes both ways. Sometimes maintainers get the wrong idea that their work is above critique because it's open source.
Such that even when presented with reasonable feedback, they balk and snap at the contributor. "Well if you don't like feature X, why don't you GTFO and fork it". For some reason it's okay for contributions to be critiqued but not the projects. Who gave this poor author this wrong idea?
This is just a symbolic hand-wavy gesture. Nothing Wyoming does in this context is of meaningful consequence to the rest of the nation.
Why you ask? It has < 200 registered EVs in the entire state. Per this data they don't even register in the scale: https://afdc.energy.gov/data/10962
What are they even phasing out?