The membership has another impact on the balance sheet. It not only adds revenue, it also cuts loss from shoplifting
HN user
jackweirdy
¯\_(ツ)_/¯
Thunk
Same. I have found it impossible to explain to the uninitiated so I delight in finding others who’ve found it!
It’s a nice property of elections that you can measure votes needing more intervention against the margin of victory before you decide your next step
Does it have to be one photo? If you reproduced a spinning drive but with the camera positioned to see half of the spinning disc, I wonder if it could capture the "stream" of pixels in one arc of the spinning disc
He didn’t work there. He was a Neo-Nazi and member of Neo-Nazi organisations, divulging secrets.
By keeping him out of jail, Mi5 stood to gain more intelligence
Canadian citizens are exempt but this is the program that allows non-visa travel to nationals of certain countries https://esta.cbp.dhs.gov/
What a delightful little question!
In a previous job I worked for a site doing natural language parsing on recipes.
We noticed one of our partner websites had an unusual number of unique ingredients. It turned out every ingredient was a link to another recipe to make that ingredient, along the lines of your idea.
However for some reason (presumably SEO) they took this to the extreme and everything was a recipe. Including apples.
The recipe for “apple” is
1. Take 1 Apple
2. Eat and enjoy
But since Apple is a prerequisite for this recipe, infinite looping is a risk in the kitchen now
This couldn’t have been better timed for me.
I sit with a pile of raspberry Pis I throw into different rooms about the house and want to stick assorted tasks on them. My open question was how can I just image them, plug them in and centrally configure what runs on them with no more sd card or Mac detection shenanigans when I change their job.
I’ll be giving this a try!
I think it’s not a nation state actor thing. In 2018 British airways checkout got popped by a JavaScript being library being changed to eavesdrop credit cards. The same thing could easily happen with password forms
Granted they didn’t break the session in flight, but there is a low bar to achieve the same thing
- Eavesdropping on you, doesn't happen because you use the password manager's autofill.
I rate this more likely and it’s one reason I still use TOTP stored in the same place as the password for other services.
A lot of sites are susceptible to cdn JavaScript compromises, and at least with TOTP stored in the same place as the password, a password replay attack has a very tight window of usability
If I am not misunderstanding (sorry if I am) it sounds like you use the http challenge where your cert provider tries to GET your challenge file — if so, could the DNS challenge be better suited? There, you put the challenge in a TXT record value
Not clear if it was message interception or (maybe more likely) Snapchat have their own moderation that can refer outward. The text is not e2e encrypted
The telegram group has a bunch of people (including myself) willing to mail pre-made ones, or the unsoldered PCBs for self solder.
It has become quite a community around the software and breakout hardware in itself
I had a problem with Zen recently-ish too. Ultimately was an Openreach thing at the local exchange apparently. The good Zen support was still ultimately there, but it took a little time for things to fall into place. Standard L1 checklist inflation. Thankfully though Zen are one of the few ISPs where I felt like it was worth it to send packet traces because a decent chunk of folks there would know what they are.
On the other hand, I think any ISP at the mercy of openreach is doomed to have limited support.
I have fibre to the property, and was having periods of 1hr-2hr day of my gigabit speeds dropping to 4-5MB. openreach themselves were blindly sending engineers to look for an issue that couldn’t physically be at my house.
Not much you can do there either as an ISP or as a customer besides wait for openreach to figure out they’re wasting their own time
Fertilizer itself isn’t carbon. Are you referring to the fertilizer production line or fertilizer itself
What % of the carbon of the plant is fertilizer production?
The CO2 in plants is 100% from the air, and then goes back into the air when burned
The recipe for government PR
- we don’t comment on individuals
- we don’t comment on hypotheticals
- we don’t comment on anonymous sources
- we don’t comment on politics.
TL;DR we don’t comment on anything, ask someone else!
Definitely should be checking certs, though I always worry about the flip side of these device security decisions. if there is no way to update the trusted root certs, your TV becomes terminally ill with software ewaste disease when the manufacturer updates stop coming.
I really don’t like hardware becoming waste because we don’t have a better iot cert pool update story
I trust YouTube to know how to bake their own cert and trustworthy tls libraries into their apps but I’m not sure if that’s common in other apps
In the meantime I maintain an unofficial apt source that autogenerates packages via GitHub actions - https://github.com/notbobthebuilder/podman
If a property is a string in your typescript interface but a number in your external service (api, DB, whatever) the typescript compiler would not know
If you want to use podman some of the more recent podman versions on Ubuntu or Debian, I have a kind of hacky PPA up here - https://github.com/notbobthebuilder/podman
GitHub actions auto build new version releases for me so major versions become available as soon as they are released and I click the button
This is one of my favourite essays and I find myself going back to read it every couple of years. Something about the mix of DFW seeming almost purely anthropologically interested in the passengers but paternally fond of the junior ranks of the crew
(Edit - the question is now different so my comment is stale)
My understanding is power is expended when current flows through a metal with resistance, and that loss is in the form of heat. The lower the resistance, the lower the loss and therefore lower the heat
Just to be clear I mean if the browser bar says accounts.google.com, you get the internet "level" validation. Regardless if the IP resolved by malicious dns is 10.0.1.1
This would be an extension of the recent HSTS preload list trend of associating a particular TLD (e.g. .dev) with a particular mechanism, and would not affect other tlds than (say) .lan or ip ranges
I don't see why a browser would "just trust" that because it is a private IP - the TLD is what matters. When you hit an internet TLD you should play by internet rules, when you hit a LAN TLD (or IP range) you could play by LAN rules. The judgement being decided by where the domain in the http request, not the final destination of any DNS lookups
If you directly went to 10.254.127.1, or some-domain.lan, that should validate differently to going to accounts.google.com
I like the "trust on first use" commenter's suggestion, akin to how typical SSH works
The argument I have in favour of not requiring encryption is best summarised by what you have outlined. It would require a massive industry shift towards no obvious solution with no backwards compatibility that doesn't solve anything
Until I hear a convincing story of how I will do the usual lan tasks of
- connect to my router to fiddle with settings
- see the management interface on my printer
- join my parents network and do things for them without having to explicitly trust a CA
- And most importantly, see consumers who don't understand any of those things be able to do these things all out of the box
I can't see how it is a viable expectation
I totally love encryption. It's great. But seriously: what domain will I visit to fix my pppoe settings. Who's going to control that domain, and who's going to renew the certs for it. Because if the answer we will expect consumers and SMEs to trust a certificate authority created by a factory with its own crappy security practices, I'm not sure how that's an improvement
Otherwise we are breaking things to "fix" something that doesn't "fix" anything. if someone is MITMing my lan, it doesn't matter whether my router is TLS or not. it's compromised
Do LAN sites need HTTPS? IE wifi router, printer, fax control panel?
I am pro-HTTP for these use cases for as long as browsers have more serious warnings against self signed certs, old SSL/TLS versions and weak algo choices than the warnings for HTTP.
Hardware deserves to be supported as long as it physically works rather than as long as its embedded TLS stays supported