The problem here is that the complaint seems to be filed by the copyright owner (or licensee) but the code is accessing piracy sites. There could be a circumvention case if the piracy site is the one filing the copyright complaint, but they have not.
HN user
ehhthing
We have dual-branded debit cards in Canada, too. But these are all debit cards, not credit cards. Visa/MC makes way more money off credit cards than debit cards, which is why they're much more hesitant to allow dual-branding.
Yoon is quite politically toxic at the moment, I don't think he'll be pardoned any time soon. I also think that this would be a good moment for South Korea to reconsider its approach to corruption, especially since Yoon's actions represent a clear escalation in the history of corruption at the highest levels of government.
This would still rely on Visa/MasterCard allowing dual-branded credit cards for overseas transactions, which isn't a very common arrangement. The only market that has this is in Asia where there are UnionPay + Visa/MasterCard dual branded cards and I suspect that the reason they allow this is because the market is huge, especially compared to Canada.
Also Interac does not do online transactions outside of some very specific merchants that take Apple/Google Pay transactions. This is how Interac reduces fraud risk, which is why interchange rates for Interac are so low.
You say this like robots.txt doesn't exist.
This already exists on the previous platform curl was using (HackerOne), it does not prevent the slop.
At my previous employer, I had access to the company’s bug bounty submissions and I can assure you no matter what you try to do, people will submit slop anyway. This is why many companies will pay for “triage services” that do some screening to try to ensure that the exploit actually works.
Unfortunately this means that the first reply to many credible reports are from people who aren’t familiar with the service, meaning that reports often take a long time to be triaged for no reason other than the fact that the reporter assumed that the person reviewing the report would actually understand the product. It’s hard to write good, concise reports if you can’t assume this fact.
Honestly, I don’t know what can be done to fix all of this. It’s a bad situation for everyone involved, and only getting worse.
I think one interesting thing that the article does mention is that Walmart does accept Apple Pay and contactless payments in Canada. I suspect this is because Canadians pretty much expect contactless to be accepted anywhere they shop, compared to in America where there are still many places (restaurants mostly) that have limited support for it.
Walmart does not require you to link a bank account for any of these schemes.
They will also appear to users paying $8/month, not just free.
Modern solar panels last around 30 years, so I wouldn't exactly call it "short-lived".
Economically, I'm sure the locations chosen were optimal. You'd imagine that actual mountainous wilderness would be a much more expensive terrain to blanket with solar panels, compared to flat areas. If there were other choices, economically they'd better options.
Search engines would have been violating copyright for the last 20 years.
I think the point of the post is that he _didn't_ do 7 weeks of work; he did 7 weeks of mostly not work.
OP didn’t put this in the title but the article is from 2016. Turns out a lot has changed in the last decade and I think it’s likely that the article should be updated on what it’s like right now.
I don't think US-made drones would be any different.
Good way to get fired and sued.
Giving third parties access to your business emails can't possibly have negative repercussions right!
With the rise in unfriendly bots on the internet as well as DDoS botnets reaching 15 Tbps, I don’t think many people have much of a choice.
Another thing to keep in mind is that these details can and likely will be clarified in the future as it goes through process.
Why is it always that regulation is the problem, not the company being irresponsible with data.
Can you be irresponsible with childrens' data if you don't know whether your users are children?
It supported using self signed certs, but if the server suddenly switched from a self signed to a trusted CA-signed certificate, no prompt would be given. So the idea that self signed certificates are somehow more secure for this specific purpose is incorrect.
iOS never supported this configuration regardless, a change in SSL certificate does not cause any kind of notification to the user.
Also, you're basically objecting to the entire idea of PKI for use in IMAP which is incredibly hard to justify. Perhaps you wish to use a different model for your own personal reasons but the default being PKI should not be controversial, and if you want to use your own model you should use a different mail client.
The author doesn't go through this in nearly enough detail to make that argument convincing. Rather than spending the entire time trying to find what the "real" ownership amount, the author should've spent the time contextualizing the situation.
The author basically spends the entirety of one sentence dismissing the idea that there could exist a corporate governance model that allows creators to have a meaningful way to direct the company's decision making process and spends the rest of the time on a wild goose hunt to figure out the "actual" ownership percentages.
It was pretty obvious from the beginning given the repeated mentions of complex ownership models that the "real" numbers were not going to mean that creators owned "real" equity in the company. An investigation about what this actually means would've been a much better way to write this kind of essay.
Instead all we got was a long article with a conclusion that was reasonably obvious in hindsight, and no real evidence to support the thesis that "it's all just smoke and mirrors".
I think the last few paragraphs go off the rails. If creators didn't own (at least in some way) some controlling stake in Nebula, why would they publicly say that they do? Moreover, why would creators join Nebula if the terms were not beneficial to them in the first place?
I find it funny that the author writes
It’s equally possible, however, that the system was set up in order to keep any meaningful power away from the creators.
Does the author really think that the chance that all of these creators are lying to their audiences is just as likely as them all telling the truth?
Also, the author even admits
As I mentioned previously, some ownership of Standard has since been offered to other creators through stock options, but it’s unclear how much or what type of stock those options represent.
Owning equity (and thus voting power) in Standard also means that the creator has the ability to vote on how Standard operates Nebula. So the conclusion that the creators have no control over Nebula literally cannot be true. So the statement that "the creators own 0 percent of Nebula" is just misleading, and yet this is somehow the important conclusion that the author wants readers to know...?
It's unlikely that the company itself makes these tablets, they probably buy bulk off Alibaba or something and they all probably fail at the same time because the were all made at the same time.
The real problem is that the quoted replacement price is so high, given that we know the tablets themselves are like $30 each.
The problem with these is that bugdoors require you to target way more valuable stuff compared to backdoors. With a backdoor you can target practically any library or binary that is being run with root privileges, while with a bugdoor you can only really target code that is directly interacting with a network connection.
Direct network facing code is much more likely to have stringent testing and code review for all changes, so as of now it seems a bit easier to target codebases with very little support and maintenance compared to an attack that would target higher value code like OpenSSH or zlib.
Most of these proposals would probably make the internet a worse place rather than a better one.
Complete anonymity on L3 would result in all tracking being on L7 instead. Right now at least most people can use Google/YouTube/most other websites without creating an account. With complete anonymity, it's all but certain that all of these would need to be gated by account creation to prevent abuse.
This would actively increase the ability for websites to track you, or else they'd need to be able to somehow handle abuse with exactly 0 information about where any given connection is coming from.
I don't think these proposals were seriously thought out by the OP.
I've noticed that it's all the chip companies that have CEOs that understand to a deep level the stuff that the company is actually doing.
Compare and contrast the big software / services tech firms...
It feels like companies like Intel, AMD, Nvidia and TSMC are much more about delivering good technical solutions to hard problems than software companies like Google or Microsoft that try to deliver "concepts" or "ideas".
I do sometimes wonder though why decision making at a company like AMD benefits so much from having a highly competent engineer as the CEO compared to let's say Oracle...
The Topics API doesn't seem to have any abuse opportunity since it's entirely enforced by the browser itself. There's nothing the JavaScript API can do that could give Google an advantage here given as far as I know there's only a single function that can be called in the first place.
I think more research would need to be conducted to see whether this change is actually anti-competitive or not.
I don't play Roblox, but I'm aware of their history of exploiting children.
Based on my preliminary research it appears as if these websites actually just ask you for either your Roblox username/password or ask you for your Roblox cookie to authenticate.
I really doubt they would actually be apathetic to removing these, since even though they do get richer off of it... If discovery finds evidence they're trying to cover this up the damages will be endless...
You're delusional if you think the landscape 10 years ago is the same now. Companies are much less likely to simply capitulate to governments now. In fact, the references you make here are why they're less likely to allow these kinds of things.
It looks really bad for them, and it affects their bottom line when these things come out. When public trust in your service is crucial to its existence, you can spend more on lawyers to fight the government about it.
This is your choice obviously, you get to choose how much data you give to them. You can also choose not to give any data at all if you wish.