Or a good way to avoid having party guests trash your house.
HN user
scarhill
Because these objects are moving fast, you would need to look a long way out. Long range radar is hard because the inverse square law applies in both directions, so you need 16x the power to double the range.
You need an outgoing mail server, but ISPs provide those, and typically don't block port 587.
I know that residential ISPs block outgoing port 25 because of the spam issue. Is it common for them to block it incoming as well? You don't really need outgoing port 25 to run your own mail server.
The US has the first amendment. Can you give an example of something the US government wouldn't let Apple publish?
His resume includes:
- FAA ATP AMEL and ASEL certificate with CL-65 SIC rating and Part 121 experience; CE-510S rating (single pilot, Cessna Mustang)
- Helicopter ATP
- single-engine seaplane rating at the commercial level
- FAA Flight Instructor certificate with airplane single-engine, airplane multi-engine, helicopter, instrument airplane, and instrument helicopter ratings
He has also worked as a commercial pilot for Delta/Comair. See https://philip.greenspun.com/flying/resume
WRT to the safety note, it's not as bad as CRT TVs where you had to worry about discharging voltages of 25 kV or so, but point taken.
Does knowing that you're running or contributing to Open Source code count? The AWS Open Source blog posted elsewhere in this topic implies that Elastic is making it hard to tell.
all commits in the github repositories are made by AWS staff.
Given that it was just made public this morning, it would be surprising if it were otherwise. The real question is what the contribution model looks like going forward. The blog post says "Contributions are welcome, as are bug reports and feature requests"[1], but of course the devil is in the details.
1 - https://aws.amazon.com/blogs/aws/new-open-distro-for-elastic...
Copyright law has nothing to do with "reputational harm," assuming Java in fact suffered any.
Making credential stuffing harder is the main reason to do this. Credential stuffing works because users reuse credentials across sites. If someone attempts to use a password from the HIBP database, the two most likely cases are that it's extremely common or the same person is reusing it. Extremely common passwords are bad for all sorts of reasons and the same person reusing a breached password makes the account vulnerable to credential stuffing.
Could you explain? Unless you're using a really weak password or reusing passwords, how would it affect you?
Exactly. I think of the HIBP password list as having three types of passwords (this is an oversimplification, but bear with me):
1) Extremely weak ones that lots of people use (e.g. 'password1') 2) Somewhat unique ones (their pet's name and birthday) 3) Truly strong ones (random, long strings)
I don't want users on my site using type 1 passwords at all. If a password is really type 3, the odds say that no user will ever try to use it again, so there's no collateral damage in blocking it. The person signing up with a type 2 is almost certainly the same user whose credentials are in the breach. I don't want them to reuse that password on my site because it makes their account vulnerable to credential stuffing.
WRT the how could they get it so wrong question, I guess it's time for the obligatory link to Michael Crichton's essay "Why Speculate?" and his discussion of the "Murray Gell-Mann Amnesia Effect" [1]
Money quote: "You open the newspaper to an article on some subject you know well. In Murray's case, physics. In mine, show business. You read the article and see the journalist has absolutely no understanding of either the facts or the issues. Often, the article is so wrong it actually presents the story backward—reversing cause and effect. I call these the "wet streets cause rain" stories. Paper's full of them.
"In any case, you read with exasperation or amusement the multiple errors in a story, and then turn the page to national or international affairs, and read as if the rest of the newspaper was somehow more accurate about Palestine than the baloney you just read. You turn the page, and forget what you know."
I changed the title from "Abandoned Tweet Counter Hijacked With Malicious Script" because the interesting thing to me was the attack vector being the recycling of the S3 bucket name. Of course the same thing could have happened with an abandoned domain name.
I use the RS-HFIQ, a 5 watt 80-10 meter SDR transceiver[1]. If you don't want to mess with sound card configuration you can add the Pi SDR[2] which adds an Orange Pi and sound card to give you an ethernet-connected radio.
[1] https://hobbypcb.com/rs-hfiq [2] - https://www.pi-sdr.net/pi-sdr/index.php/pi-sdr-projects/pi-s...
Except it's not just complex scientific subjects they get wrong. If you start looking for it you'll find it's anything that you know about. I've observed it in articles on pigeon racing.
Here's the source for the Gell-Mann Amnesia Effect quote: https://web.archive.org/web/20061020012137/http://www.cricht...
Lambda containers can run for hours at a time. It doesn't just fork a new process for every request:
https://docs.aws.amazon.com/lambda/latest/dg/running-lambda-...
If the market agreed with you that Intel will suffer greatly in the future due to Meltdown/Spectre the price would have dropped already. Of course you might be correct and the market wrong. You’re short Intel, right?
That works as long as you never need to drive more than 100 miles from home.
Except there is no forum login page, just a SAML redirect to their SSO login.
If people don't know that LastPass has a 2FA app, they might think LastPass Authenticator is the password manager app, and is affected by this bug. As a matter of fact, a number of commenters seem to think exactly that.
As it happens, I switched from Google Authenticator to LastPass Authenticator a few days ago. The app has a feature that allows you to require a PIN or fingerprint in order to use it. That feature is disabled by default. (Note that Google Authenticator has no such feature.) As I understand it, this attack allows someone with access to my unlocked phone to install a activity launcher app and then generate 2FA codes without supplying a PIN or fingerprint. Actually, for my phone they wouldn't need to bother with the launcher app, because I didn't enable the additional fingerprint/PIN feature--it seems to reduce convenience while adding little security.
Still, it's definitely a bug. They should either fix it or remove the feature so people aren't misled into thinking their two-factor codes are secure when they're not.
There's a chapter on this in Mary Roach's book Stiff[1]. The book was published in 2003, so this has been going on for a long time.
1 - https://www.amazon.com/Stiff-Curious-Lives-Human-Cadavers/dp...
According to the notification letters on that site, those three incidents all involve Google employees' information being leaked by third parties, not Google leaking users' data.
Here's a quote from one of them:
"We recently learned that certain hotel reservations made for Google business travel were among the many reservations affected by a security incident impacting a third-party provider’s electronic reservation system that serves thousands of travel agencies and hotels. This did not affect Google’s systems. However, this incident impacted one of the travel providers used by Googlers, Carlson Wagonlit Travel (CWT)."
The problem is adverse selection. If insurance buyers have information that insurance sellers aren't allowed to have or act on, high risk people will buy, while low-risk people won't. As losses go up, so will the price and when the price goes so high that only the highest risk people will buy, the market will collapse.
Canada's consumer price index hasn't exceeded 4% since 1990 and has averaged 1.74% since then. So investors who are buying those bonds could reasonably see things differently than you do.
Not the author, but I think the proposal would be for browsers to not display scary warning pages HTTPS requests using self-signed certificates where the hostname is an RFC1918 IP address.
The argument is that self-signed certificates on internal-only IPs aren't any less secure than plain HTTP.
I also still have my Freerunner in a drawer somewhere. I bought the phone early on and then ended up starting the android-on-freerunner project[1], when Koolu, the company that had begun an Android port, abandoned the project. I used the Cupcake version as a daily driver for quite a while, but it was never anywhere near as stable as a "real" phone.
1 - https://gitlab.com/android-on-freerunner/android-on-freerunn...
The story of why the US has such a bizarre system of paying for healthcare is more complicated and interesting than just union demands and WW II price controls. Here's a great podcast discussing it: http://www.econtalk.org/archives/2017/06/christy_ford_ch.htm...