There was a 10?
HN user
qyi
it's worth it to purchase tools that have long term benefits.
Good luck finding an LCD with any concrete health benefits beyond any other. The industry literally just adds a bunch of gimmicks each year to see if people bite. All I can say for sure is IPS prevents you from needing to fix your head in one angle (especially for low contrast images), and most LCDs are too bright.
This reminds me of another issue: If you have a monitor with overdrive and use a color temperature adjuster like redshift, the overdrive smearing is often super bright while the rest of the screen is mellow.
The essential point is that he's 40 and still doesn't know what he's doing (a common problem in any technical field).
This is true until you realize all general purpose languages are the same and redundant. There is no reason to have more than one on a given system.
Ah yes, we should outlaw the ability for people to send money to each other and have civilization take the burden of incompetent corporations that can't be bothered to follow basic infosec practices (let alone whatever product they are selling in the first place is probably garbage and has no value beyond monopoly).
You sure some ransomware crooks don't provide contracts to their clients?
The standard business solution to solve security issues - for example like having all your database in a public folder - is to get a guy to implement "security" (whatever that means) who is 40 years old and is really confident he knows what he is doing. He will go configure some firewalls and stuff that has absolutely nothing to do with preventing any real risk aside from automated attacks. Every time someone still gets the files from some 90's vuln, everyone is surprised that some sooper dooper hacker wizard was able to own their fortune 500 company.
The least deployed solutions post-attack included web scanning (40%), endpoint detection and response (EDR) and extended detection and response (XDR) technologies (38%), antivirus software (38%), mobile and SMS security solutions (36%), and managed security services provider (MSSP) or managed detection and response (MDR) provider (34%). Only 3% of respondents said they did not make any new security investments after a ransomware attack.
uh huh. uh huh. uh huh. uh huh.
Meanwhile, for example, earlier today: a web search for "cat /etc/passwd" blocks my IP. What even is the point of this article? _Of course_ if you don't patch they will just hack you again. _Of course_ if your company follows terrible 90's practices, it will get owned again.
I was saying that it's a red herring to go "oh people don't used typed languages because Java programs start up slow".
I know you're trying to pin me as being rude, but no. Your answer is bad and ad-hoc. Just because a language is not Java does not make it magically untested and obscure. Just use Go tbh.
Edit: Okay I see the original guy stated Java. It is what it is. The real useful answer is to just use any other typed language, and not use Python.
We live in a world where people unironically put comments on top of every file in their projects (but only the ones they can easily insert a meaningless string into) like "you cannot disclose this file blah blah blah" and call themselves "grown ups". What's this Android nonsense, can't it just run programs like a normal computer? At the very least if it purports to not be a general purpose computer, then there should be no excuse for security vulnerabilities.
After all the snakeoil that depends on facial recognition is bypassed, that will still before it's retrained.
Zope was pretty popular a decade ago, never got into it though.
The idea of an interface is fundamental to computing. No matter what you do, at the end of the day data exchanged between two systems has to be structed _some how_. E.g., machine code submitted to the CPU, register configurations, C ABI, Python structures, JSON. You _could_ be hand wavy about it, maybe even use machine learning, but then it will just be ambiguous and lead to vulns. IMO the constant insistence to try and find ways around this is a huge setback. I used Python heavily in 2008 and always was annoyed when trying to figure out the essence of an API (which is what you get when there is no concrete interface). Whenever I read a Python codebase, unsurprisingly, it's full of handwaving and the resultant bugs (some people know what they're doing, but the problem is there more than in a typed language).
Replace Java with literally anything else (including whatever Java implementation does not have the issue) and the "startup time" red herring is gone.
Python is just for playing with strings, which is a contrived problem brought about by UNIX-style OS. And other confusing non-fundamental, stuff that just leads to months of cognitive dissonance when one inevitably philosophizes over it: objects, classes, exceptions, the ability to modify global variables from other modules, metaclasses, etc.
There are very good reasons for all of this, but it's a lot to try to explain and absorb at once.
The reason is because you're embedding strings into the program, which is just a string. There's no reason languages have to be like this. The ironic part is that developers are just like children and do not understand the significance of this either, which is why string injection vulns still exist today.
No, you were correct. Some people are helping here and there but overall every aspect of the software industry is an absolute mess. Most infosec pros will not point this out, either because they are tunnel visioned on their niche, are trying to sound politically correct, or just trying to not start shit (but nothing will be solved ever if people keep pretending everything's all and well).
Give me access to a machine that isn't blocked from Google, and I will.
It's been happening since before 2010, but sure.
Sorry, I thought hackers do not have nationalism.
They had the death penalty for using the royalty's name in vein until the 90s or so, jailing someone because he was drunk and made a "death threat" (with zero likelihood of it being real) on Facebook, arresting someone for camping alone without a mask, CCTV everywhere, being illegal to raise the middle finger, etc. And yes, then once tech is involved it is accordingly used as stupidly. The UK somehow has a whole different brand of legal stupidity than America.
Heard of him since his DNS vulns. Never read or watched his presentations until recently. It was a breath of fresh air seeing him talk. I thought "this is a true hacker. no corporate BS". Damn.
This is _exactly_ what I'm talking about. You type "directions to adelaide", and you get something about Adele. I don't agree with the sentiment that it seems conspiracyish or "dystopian", though.
On a related note, I find it hilarious that websites - even e-commerece and services that don't seem to have any physical contact - now have a generic COVID-19 popup on top of their cookie popup and privacy police banner.
You can not use Google. The real problem is when you have to do tax or you go to jail and it has to be done with some smartphone garbage (not sure if we're there yet, my country still has paper filing).
Ok, "the justice system".
I've never studied logic and yet I have never agreed with any conspiracy theory (the logical flaws are still obvious even if I can't name them).
If you want people to think logically about topics, the first step is making them not be taboo.
1. Use quotes to force an exact-match search
Almost never works these days. Google now usually just quantizes your search terms into an ad or ultra popular news article written 3 minutes ago. It also ignores all your operators most of the time.
Bonus: If you use something like inurl: You get blocked for a "hacking attempt". Google also has blocked Tor and VPNs since 2006 or so. In fact, they are the one big search engine who has done this the longest. Google search right now is like one of those dinky websites from the early 2000s that follows all kinds of insane practices like blacklists and filters.
What Google Search is trying to be is a thing you can ask questions and get an answer back. For example converting feet to inches, or where is Starbucks. I don't even understand why the niche (really, this is how academic research is done, but i guess you can just discount the entire web as an invalid soruce) of "searching for strings over a set of websites" is not even attempted to be filled. People are crazy.
Just for clarification, are you talking about Vue.js?
Just looked it up and people actually donate thousands of dollars to a JS project?
https://opencollective.com/vuejs
Crazy.
It's infeasible to make sure a server is only accepting "legal" content. I've never heard of a case of someone being jailed because his system involuntarily received some data that happens to be illegal. Normally what happens if there is illegal data that anyone cares about, the hoster is contacted and told to remove it.
it just doesn’t seem worth the risk.
Well, the concern is only yours.
This does raise the point that if police contact you to remove some data you are hosting for someone, you lose money, and they will likely not give you back whatever money you lost (all the more reason it should be fully anonymous like Freenet but IPFS and co are obsessed with trying to solve every use case in the world including legal compliance).
But if the token price rises then the node can just delete your data and make a new deal with someone else and get more profit.
Interesting article. While reading about Filecoin the first time, I had to stop every paragraph and think "but what if the node just doesn't give you your data back when you finally ask for it?". And as pointed out by part 2 of the article, not only can they choose not to give it back, but they are incentivized not to.
edit: Wouldn't erasure codes just completely fix it (as described by the Storj guy)?