Shitposting and its consequences have been a disaster for Intenet discourse.
HN user
ohithereyou
If COVID-19 digs in deep in the US then there is going to be a transformational change in how US citizens think about work, travel, entertainment, security, and the relationship between US citizens and their government. All of these aspects are intertwined:
Work: More people will work more time from home and many firms will switch to virtually full time remote with limited physical gathering. This will decrease the cost of office rents and alter the work/life balance. It will affect wages because people can live outside of city centers and still work so companies will pay less. We may be on the cusp of US government guaranteed sick leave.
Travel: People will, for the short term, do less travel for pleasure, but the big impact, long term, business trips will decrease. More and more business meetings will be replaced with voice and video conferencing. There was no big driver other than some cost reduction here, but now safety and security will be the big drivers here. Global pandemic concerns (prevention, containment) will complicate travel to varying degrees, and in a way that most US citizens aren't used to - it will affect interstate travel, not just trans-national travel.
Entertainment: Many of the sports that have been deferred or canceled will likely be replaced with other forms of entertainment that can be viewed on television or the Internet. Fewer people will go to live performances, both because they can't (cancelled by the government) and reluctant to after COVID clears. This will affect service workers - where most of the lesser skilled jobs have been created in the last three decades.
Security: Security will no longer be seen as just a physical access control concern. Business has been preparing over the last two decades for the eventuality of global pandemic - now they can put those plans into action, and the impacts of them will cascade into personal lives. US citizens will be demanding more from their government in disaster preparedness on pandemics - it will affect travel.
All of these tie into how US citizens see their relationship with their government, and what they demand from it.
Isn't it the aspirational goal for several churches/religious orders to do just this?
Why would they add that when they can just sell you a remaster for the price of a new game?
If you're going to treat investigative reporting and news gathering as a profit making venture then you can only charge what the market is willing to pay, and for the vast majority of people, that's nothing.
Think of the poor buggy whip makers!
Not every desirable activity in life is profitable. If your business plan is "make website -> get money" then perhaps you're in the wrong business.
A site that renders completely blank without JavaScript is a site that I don't enable JavaScript for. They don't want me to view it, and nine times out of ten I can find the information elsewhere.
GOG games are DRM free and typically show up on torrent sites immediately after release, so anybody who wants to pirate the game won't bother to go through the buy->download->refund flow with them.
Terminal middleware already exists - screen and tmux seem to be the most popular here.
Wait, does anybody actually believe any major sport doesn't look the other way when the right team cheats assuming it gets more butts in seats? Major sports aren't about the purity of the game. They're about money - pure and simple.
If MLB could replace all of the players with robots that played a game simulated on a computer, designed to play out a storyline as a drama instead of a legitimate competition, and make more money doing it then they would in a heartbeat and not lose a wink of sleep over it.
What sort of encryption and authentication can I expect if I do that? Can anybody who guesses the port dump code into my running Lisp instance?
Legitimately interested in your explanation as to how this specific research would be a crime absent contact with HackerOne. Please cite statute. I'm not saying you're wrong - simply asking you to back up your claim with evidence.
"Dark web" for things that are not relevant to Five Eyes and NSA when they are relevant. At least in those cases, with good opsec for the "dark web", you can be reasonably sure the company who made the product can't retaliate against you.
That sounds like it's a payout lottery. H1 can't force its customers to pay. It's acting as a go-between on behalf of its customer, the company offering the bounty, not as an neuteal arbiter when there is a dispute.
Perhaps I would take them seriously if there was an escrow account companies paid into and was released to the reporting party when a plurality of multiple, disinterested parties agreed that the report was valid.
not let your anger cause you to do something stupid
Note: I didn't say that I would do this for every company. Just ones that use HackerOne. They have decided to abdicate their responsibility for their security vunerability reporting, and I feel completely justified in dumping info on their vulnerabilities.
Releasing the details of a vulnerability is not stupid. The users of the software/service deserve to know the data/service they're using is unsafe when a vendor refuses to act on a valid security issue
If you disclose a vulnerability, the company HAS EVERY RIGHT to sue you.
You don't need the right to file a lawsuit to file a lawsuit. You just file the lawsuit. Now, you need an actual, actionable claim to prevail a a plaintiff in a lawsuit. Whether such a thing exists in practice is something we leave to lawyers to argue about and judges/juries to decide.
If your company is in a competitive industry and I release the details of a vunerability in your software and you sue me then that vulnerability and lawsuit becomes marketing item number one for all of your competitors.
this is why these bug bounties and established ways of notifying the company of the vulnerabilities exists
Arguably why they exist. In reality, they tend to exist to give people an incentive to not dump the vuln details on the black market, embargo bugs so customers don't leave, and attempt to maintain a good relationship with security researchers. They do not grant immunity from being sued or somehow grant the legal right for security researchers to do their work as your comment seems to indicate.
Your post reads like propaganda from a bug bounty organization. I'm not saying that you're shilling, just that you're misinformed. In the US it is generally legal to conduct security research. In the US it is legal to communicate the results of that research publicly so long as you have not agreed in some contract to not do so.
Where did you get the idea that legitimate security research is a crime?
Are there other cases where PCI-DSS compliance requirements are selectively enforced?
All the more reason to not submit bugs like this to HackerOne. If you can bypass 2FA by having only one factor then I wouldn't consider that 'stolen credentials' and more a singular stolen credential. Their system is designed to defend against this and it does so ineffectively. That is, by definiton, a security issue.
I wish I could define what is and isn't a bug in my code at work. My defect rate would be incredible.
The market for a freelance security researcher out there is hard, no doubt, but disclosing bugs publically is an addition to your resume, akin to any other professional development you do. It demonstrates you can do the work and it shows the skills you have.
Suing someone for disclosing an actual bug is a long term losing proposition for any company in a competitive industry.
I've seen several stories about how HackerOne doesn't pay out bug bounties when bugs are reported. I, for one, wouldn't submit bugs/PoC to them, and I would actively, publically, and immediately disclose bugs that affect anybody who is a client of HackerOne.
What sort of development do you do on the PowerBook?
Not only that, but it's easy to set up loading games from a hard drive with a broadband adapter and memory card exploit. From there, you can rip your own games or download rips and load to the external hard drive and play that way.
The fed expanded its balance sheet from less than $1 trillion in 2008 to over $4 trillion in 2016, practically dumping $3 trillion into the economy for all intents and purposes. What was the effect of that on crashing the dollar/making it worthless[0]?
[0] https://www.cnbc.com/2017/11/24/the-fed-launched-qe-nine-yea...
Five Eyes sees all
Counterpoint: CALEA and National Security Letters in the US.
That only works if you can assume that everybody using the system you're desiging has access to the underlying technology. Sure, if you're desiging some new system (like an autonomous vehicle on a closed loop, controlled system / system purpose built to perform digit recognition as it is written on it, but why wouldn't you just have the user directly input on a keypad) then you'll get a better result, but in the general, real world, case (autonomous vehicle on city streets with other vehicles / recognizing digits from scanned input without the stroke data) then your special case optimization are impossible and for all general practical purposes do not apply, so appealing to their assistance in increasing accuracy doesn't actually do anything to help the system perform better.
That's great, but I would wager that nearly 100% of all writing ever done in human history was done without capturing the strokes while writing. Therefore, while this added accuracy is great, it is virtually useless for most written work.
My Pro4 has been solid for me. I upgraded about a year ago from an AM3+ FX-8350 build on another Asrock motherboard. That was back when Microcenter was selling the R5 1600 for $79 with $30 off a qualifying motherboard.
On some distros there is an additional software store that connects into Snap[0], so they're technically not distro supplied packages.
Have you tried Trinity Desktop Environment[0], a continuation of KDE 3.5?
But you see, it's "webscale"!