HN user

random5634

1,613 karma
Posts0
Comments338
View on HN
No posts found.

The person responding at a big corporation is often unable to, for practical purposes as a result of policies other than in exceptional circumstances.

When you write in and ask them, please steal a million dollars and give it to me, while they might be able to figure out a way to steal and give it to you, for policy and job performance reasons they are unable to. They say - "I'm unable to do that for you". Who cares if they somehow could - we all understand they have chosen not to.

We are unable to reinstate your account = person responding does not have policy authority to reinstate your account and the exceptional circumstance was not identified.

12 meters would have been "deep" where I was :)

I called them "disco" dives. Dive down a bit, show them some lights and some fish turn around a few times and back up. A play on the discovery label.

But yeah, the grumpy "master" divers will be yelling at you from shore about the whole thing!

Def want 100% contact from start to finish, and if you keep dive to 8-10 meters or less (hard bottom) helps. Just throw some statues / structures down there to look at.

Things to watch for. Folks who can't equalize - just come up or do a super shallow route if you can. And def need to make sure folks can breathe comfortably underwater (shallow water / cow pen). Also doesn't need to be long, it's about the experience. Some idiots take advantage of the depth to extend time which is silly.

Another labor was resort dive, but wasn't sure what differences / similarities were between all these experiences.

Cycles X 5 years ago

Yes - they ship open source and are generally more comfortable with open source licensing because they have much more experience with it.

Expecting an entertainment industry org (which were specially attacked in latest version of GPL around DRM) to be comfortable seems far fetched.

The problem dive locations have is a lot of people a) overstate experience or what they remember, b) are unfamiliar or have not tested equip they will be diving with and c) equip is not familiar to operator if they bring their stuff.

People don't dive enough. So they buy all sorts of new stuff for their big new drift dive vacation. In some cases they've literally not been underwater with it for even 20 minutes. Also makes it harder to do an at a glance x-check for folks if you don't know their gear. And some gear harder to deal with (ie, adding weights underwater) if someone turns out underweighted.

My own feeling - unless someone is current with their equip or has current diving - start with a hard bottom dive at 40'.

Plenty of resorts and other destinations offer resort and discovery diving. You do need be 10 years old, but no prior experience needed, after some basics some places let you do 1-2 open water dives in the same day! All equip is provided. You really DO NOT configure any of your stuff on these dives (you do get comfortable breathing underwater). It's a scuba dive "experience".

Unless you are a diver please don't comment with this type of snark - seriously.

" Discover Scuba Diving is a quick and easy introduction to what it takes to explore the underwater world. To sign up for a PADI Discover Scuba Diving experience, you must be at least 10 years old. No prior experience with scuba diving is necessary, but you need to be in reasonable physical health. Are you ready to try it out? "

Cycles X 5 years ago

Dude - let me make this super simple. These rendering pipelines import the SDKs and APIs they connect with. The pipelines have tons have high value custom code. Under the GPL, they have to be open sourced if they use blender - this is 101 stuff. And under GPL it is viral, if stage 1 is now forced open, the next big set of stuff that integrates with stage 1 is also forced open and so on.

Pixar is not open sourcing their pipeline - period. Do you not understand that these companies build giant and high value software around the various engines?

Listen - I didn't realize how little you understood. This is actually covered in the Blender FAQ's because it can really bite you (even if a small player) if you build an add-on to blender.

"Blender’s Python API is an integral part of the software, used to define the user interface or develop tools for example. The GNU GPL license therefore requires that such scripts (if published) are being shared under a GPL compatible license."

This is cool if you want to use stuff - they make that clear too. "Sharing Blender or Blender add-ons or scripts is always OK and not considered piracy." But for commercial players this is an absolute no go.

This is not FUD, this is hard reality, and no commercial player is going to tie into something like this.

Cycles X 5 years ago

They don’t want to open source the tools and programs they develop as part of their pipelines that tie into GPl or each other - GPl is viral and a library import triggers it.

In terms of the tivoization / drm provisions - the GPL is viral - it only takes one screw up or chain of viral connection to blow their business up. Apple fought the govt to avoid unlocking a terrorists phone, that’s how hard they protect signing keys .

The issue is they don’t know who will use what where, and the viral aspect adds insane risk. Minecraft / roblox and other games may decide to add design pipelines or render chains. Or they may want to run the software on golden image VDI pools that are locked down.

Even Ubuntu was so worried about the chain risk they changed bootloader license away from latest GPl

The work around folks use is to claim just new stuff is agpl and skip contribs sign off. After stuff is mixed gets harder to pull apart. AWS just had to go through that exercise with elastic search

Cycles X 5 years ago

If you import a GPL library into your plugin your plug-in / add on is now GPL. They don’t want that.

GPL has what is called anti-tivoisation / DRM. This license was designed to specifically target the entertainment industry.

Even Ubuntu had to get a different license for boot loader to avoid risks here

Cycles X 5 years ago

Current version of GPL is an absolute no go, especially if you need to import an api / sdk style interface into your extensions and tooling - the GPL is viral. You import a GPL library to interface and your stuff is now GPl.

and latest version requires release of encryption keys etc etc - all major studios WANT content protection to work and the GPL is explicit in its attacks on that

Cycles X 5 years ago

Current version of GPL is an absolute no go for many larger places - even Ubuntu ended up dropping it for parts of stack - risks are way too high

Cycles X 5 years ago

The current version of GPL is 100% toxic at many places I know of - this is not overly conservative lawyers - you have all sorts of rules around releasing your encryption keys - secure boot chains etc - it’s a no go and viral

Except of course the corporate folks who are licensing under AGPL who can and do then take contributors code and make available a commercial version that no one else is allowed to make available.

AGPL is a poison pill license that creates a very distorted open source model - better example is "shared source" - you can look but can't really use it in you own ops.

The whole AGPLv3 / GPLv3 thing was such a mess - a big move towards trying to tell people how to use the code. I think long term GPLv3 and AGPLv3 die out.

Or just grab the phone out of your hand - most people take their phones out of their pocket all the time even on the street. I used to ride a bus and they would grab phones and jump off just as bus would leave a stop. You can actually often get a ton more data this way if you have physical custody of device - no airdrop impersonation needed.

The remote RCE issues Apple has had are critical vulnerabilities. Saudi Arabi doesn't like you, they exploit remotely (maybe not even knowing who you are at all yet) to get your data / your contact lists and social graph etc - and you could be impacted or others could be impacted as a result in a major way.

This exploit requires that they already know who you are and where you live and where you go get coffee. They have to send a physical attacker to stalk your coffee shop. They have to have this equipment to run the impersonation exercise - and then wait until you are picking up coffee and airdropping something.

And after all this they get your email and phone number? So they know all these details about you but can't be bothered to use true people search or ANY of the data brokers or any of the giant data leaks to look this up?

Apple is selling a CONSUMER device. If your threat model is this elaborate, stick your phone in a faraday cage and leave it at home, someone could just grab it out of your hand at the coffee shop and be likely to get a lot more data.

So yes, it's a risk - but on the scale of risks including just being straight mugged and your phone stolen, it seems somewhat lower?

Not that many users expect to sit next to an attacker running this system AND be sharing something.

No question should be fixed - but compared to the rce s Apple has had (which do get fixed quickly) this is relatively lower risk

This only is a risk when you open the share pane close to your attacker.

Your email and phone number may be less secret than these folks claim .

But aside from this overhype interesting work.

How does something like this get through IRB - I always felt IRB was over the top - and then they approve something like this?

UMN looks pretty shoddy - the response from the researcher saying these were automated by a tool looks like a potential lie.