Fair, and appears I missed the first part "Use of Korean language".
The OCR still tells us more about the target than the actor, but I guess they are suggesting the choice of target itself is the indicator.
HN user
meet.hn/city/gb-St-Albans
Socials: - github.com/jamedjo
Interests: Cybersecurity, Entrepreneurship, Education, Hiking, Mobile Development, Open Source, Outdoor Activities, Programming, Remote Work, Startups, UI/UX Design, Web Development, Adding to lists
---
Fair, and appears I missed the first part "Use of Korean language".
The OCR still tells us more about the target than the actor, but I guess they are suggesting the choice of target itself is the indicator.
Attribution Scenarios: Option A: DPRK Operator Embedded in PRC
Use of Korean language, OCR targeting of Korean documents, and focus on GPKI systems strongly suggest North Korean origin.
I'm don't follow how needing OCR to read Korean documents points to them being North Korean?
Could also point in the opposite direction of them needing to copy the text for translation.
My link isn't a study it's a layman's terms explanation, but there are lots of studies. Your link mentions a meta analysis of 7 studies concluding that up to 90% is genetic.
Yes environmental factors are there too, otherwise it would be 100%, but there's enough evidence pointing to genetics that it is really disappointing when people try to find spurious links to false causes instead.
Twin studies are a classic demonstration of this: comparing identical twins to non-identical twins lets us prove a genetic component.
https://www.open.edu/openlearn/mod/oucontent/view.php?id=669...
Misuse the trademarks licensed to one of their competitors while relying on that competitor to provide them infrastructure for software updates and provide product improvements.
Adjusting their product names sounds like a small change they could have made to avoid antagonising a close partner.
Running their own plug-in mirror infrastructure is something companies often do to reduce the risk from relying on a third party.
Similarly having some stake in the development of WordPress reduces risk of them being shut out if there is a license change that necessitates a fork.
Less about caving in on wishes as more that it's risky to choose both to rely on a third party and wind them up at the same time.
I had a similar experience in 2015: a doctor was trying to prescribe a choice between Venlafaxine (Effexor) and Duloxetine (Cymbalta) as third line ADHD medications. I was astounded that they didn't know that brain zaps were a common side effect and brought up some papers to show them. They apologized and indicated that they would likely stop prescribing them.
I was skeptical when they mentioned that other doctors had been promoting these drugs at gatherings, but what irritated me most was that they didn't have access to the research discussing the known side effects because the journals were behind a paywall. A willingness to pirate / use Google scholar to bypass paywalls shouldn't have been necessary to know about safety issues for a drug.
Today I Relearned: Selective Serotonin Reuptake Inhibitor (SSRI) != Serotonin Norepinephrine Reuptake Inhibitor (SNRI) != Selective Norepinephrine Reuptake inhibitor (sNRI)
So late to the VR headset market they thought they needed to stick googly eyes on it... dunno maybe I'm missing something?
Chrome as a project was still a Google thing even if they used Konqueror's rendering library.
The process model was the novel selling point at the time from my memory [1].
How much of the speedup comes from more efficient memory usage vs faster memory access times and faster CPU?
I wouldn't expect lightweight office use to be primarily limited by the amount of memory available so perhaps that isn't a fair comparison still.
Battery life is significant worse with 32GB ram and laptop reviews often place heavy emphasis on battery life. By offering an 8Gb base model for reviews the manufacturer ensures their laptop will score well in reviews, even if users end up buying a higher spec laptop. It also allows users who want to multitask less to get more out of their laptop.
On desktop the impact of power consumption is lower, so it is better to offer a slightly higher spec base model.
Unlocking the password manager means I need to type a master password in while in a public place. Feels higher risk when it is an unimportant website but potentially gives access to all websites. Still better than the passwords being accessible on disk but having individual passwords would reduce the impact of any password leak.
Our machines always had Cookie Pal [0] installed on them, and it allowed per domain settings for rejecting cookies and control over third party cookies [1].
Cookie Pal includes the following features:
Automatically and transparently accepts or rejects cookies from all or specified servers without user interaction.
Cookies received from unspecified servers can be automatically accepted or rejected without user interaction, or the user can be asked for confirmation.
"On the fly" adding of servers to the accept from and reject from lists, allows you to manually accept or reject a cookie the first time it is received and then have it automatically accepted or rejected every time it is received thereafter.
[0] https://web.archive.org/web/19971012223847/http://www.kburra...
[1] https://web.archive.org/web/20010331050614/http://www.kburra...
One of the founders listed elsewhere on that page was a mentor on an accelerator I took part in. We went over our business in depth, he eventually became a supplier to us, then we became his largest customer. One day he abruptly stopped providing the service, and then relaunched his business trying to copy us instead.
We out executed, but I'd advise caution with mentors. Some were great help, this one was malicious.
It doesn't have to be malicious for it to harm privacy, help them track users for advertising and to be anti-competitive.
The implementation details around cookie recreation don't matter if users are still being tracked. Especially bad if this lets them track you on third party sites that contain Google Plus buttons or advertising iframes.
By ensuring users always remain logged in to the browser they gain a strong advantage over other companies that track users. Users attempting to remove tracking cookies shouldn't find Google ones permanently bundled with the browser.
The intent was likely to aid convenience and avoid users being unexpectedly logged out, but combined with Google automatically logging users into the browser this is a sign that the Chrome team is paying less attention to user privacy than they used to.
Perhaps users who regularly clear all cookies will start using guest accounts instead. Myself I'm more concerned about the general trend of unexpected behavior.
Chrome lost all my browser history, bookmarks, settings and extensions when I let someone else log into chrome and log out again. I now try to use Firefox for non Google services but still use multiple gmail/docs accounts in chrome for performance.
Even if I hadn't already had a terrible experience with their login feature, it is a privacy violation. I haven't agreed to have my browser history and other private data uploaded to an advertising company. The argument that most users want this is flawed: many would object to giving Google access to this without permission. Maybe the EU will step in?
Is there a way to do this for existing repos?
You can add a webhook on GitHub and have it point to our Pull Mirroring API [1], followed by manually setting up the integration to send status updates back [2].
We're looking to make this process easier, and have explored ways we might implement this in https://gitlab.com/gitlab-org/gitlab-ee/issues/5220.
[1] https://docs.gitlab.com/ee/api/projects.html#start-the-pull-...
[2] https://docs.gitlab.com/ee/user/project/integrations/github....
This comment reminded me to create issues for reducing clutter on the MR page [0], and expanding multiple resolved discussions [1]
First thought was that people would protest this by flooding the relevant department with product updates, maybe triggered on each commit. Then I noticed the caveats:
- Updates don't count: only significantly large changes need disclosing.
- Can't be forced on companies with fewer than 10,000 users. Maybe commercially led open source products could claim that users are spread across many forks each with fewer users.
- New product disclosures only applies to communications companies already forced to backdoor existing products. Maybe we'll see companies akin to Alphabet evading the need to backdoor new products by forming separate companies.
Overall I'm more worried by the requirement to backdoor communications than having to disclose new services. Security shouldn't be sacrificed. Additionally the gagging order would prevent companies from being honest with their users as well as making it harder for them to fight against it.
The Xkcd would go "We thought we sanitised our input but we still lost this years student records. Did you really name your son Little Bobby Drop [DOS/STONED]{16 byte malware Signature}?"
Yes, very easy. In a mac you just plug in a Firewire/thunderbolt device[1]. More extreme measures involve freezing the RAM. Both require physical access to the machine, but a bit more scary that plugging your laptop into a public display/TV gives an attacker control of your computer and passwords.
Full disk encryption TrueCrypt/BitLocker/FileVault can act as countermeasures[2] and modern versions of OSX don't allow DMA from the login screen anymore.
[1] http://www.breaknenter.org/2012/02/adventures-with-daisy-in-...
[2] http://www.researchgate.net/publication/49277520_Cold_Boot_M...
TA = Army Reserves, not town council / home association!
The article might make it appear they jokingly talked/thought about a bomb, but others make it clear there plans were concrete. It mentions them going to "meet the brothers" at a training camp where duties would include "helping them making the bombs". I think it becomes a crime when it goes from curious learning to definitive plans. They weren't just thinking something socially unacceptable, they were planning to cause harm.
It sounds like they only charged him for this after he gave up the keys he was previously withholding. While I disagree with the power this law gives, its less extreme if its only used when they can prove the password was both covering up a crime and not forgotten. More of a deterrent, and slightly less of a thoughtcrime.
Is it the number of applicants or the quality which is the issue?
Would it help if you targeted CS students by running web dev workshops? That way you could attract developers who haven't considered applying to a startup and might not otherwise teach themselves web development. Student salaries are also lower.
Maybe you could look further geographically too. We had an ItMegaMeet in Bristol yesterday which sponsor companies used for recruiting.
I too would be surprised at how little some CS students know about web development and testing-- if I hadn't sat through a web tech unit so outdated that those of us with some experience could easily have done a better job. I helped the lecturer improve the course for the next year, but think these kinds of things need a different and more collaborative teaching model.
Thing is though- some things are easier to train on the job than others. So while I would hire my peers, I'd personally see it as a bonus if they used TDD not a prerequisite.
Find a company interested in your tech, make them a customer/client and sell them a minority stake?
If its a talent acquisition it might be hard to find someone passionate enough to run your startup, and near impossible to do in your spare time.
(My experience: none)
Does this work for streaming videos? The `open request in new tab`->`save`->`close original tab`->`stop new tab` process works, but is a bit long. Would be nice to just be able to cURL/save.
Is it a code problem or a productivity problem?
Code productivity: Using issue tracking like FogBugz or Github really helps you make sure you work on the important bits first to get a minimum viable product.
I try to think 'Lean Startup' on my projects. Only create the features you really need. Get the bare minimum thing working properly and get feedback/testing from someone who would actually use your product/service. Iterate. Be agile.
More generally: The basic productivity techniques can be a distracting read http://www.43folders.com/howto.
Breaking things down to much can create overhead. I've been trying to improve the way I stay on task. Not just working on the project, but working on the most critical parts without getting distracted. Its too easy go on a tangent, and research something which wasn't critical.
I'm currently refining a method I call ReasearchLock: keeping track of the current task so I don't deviate from it. Things which appear critical often turned out not to be if I tried to get by without them and just left them for later.
I outlined my original idea in a note: http://njoin.co.uk/grains/5107d5516decf91f10000002 but have refined it since.
There are multiple levels, and the = or != box changes to a clickable bunny which does more.