YouTube allows parents to turn off shorts for their kids (if their kids are part of their family account). Unfortunately it doesn't seem possible to turn off shorts for oneself without resorting to browser extensions.
HN user
thomc
email@thomascannon.net
Another thing to look at is the built-in sandboxing and permissions for your agent. Claude Code for example has the /sandbox command which uses Bubblewrap on Linux or Seatbelt on macOS for OS level sandboxing. Combine that with global default deny permissions for read & edit on your SSH, GPG keys and other secrets. You need both otherwise Claude can run bash commands which bypass the permissions.
My one and only experience of dealing with the police in the US was when I was visiting NYC. A tourist was being attacked on the subway because he was taking pictures and since we were still at the platform I jumped out and told 2 officers further down the platform what was going on. I expected them to sprint into action, but they could not have cared less and casually strolled along towards the carriage!
In a similar vain I was the first on the scene of a car crash in the UK, where the driver had exited the vehicle through the window (no seat belt) and was bleeding in the road. When the police turned up they casually and slowly walked up the road towards the scene.
It made me wonder if there was a good reason for this, like to control adrenaline, make better decisions, have time to assess the situation. Or if they were just jaded from seeing it a lot.
Lost an Apple iBook screen this way. Guy in front slammed his chair back while I was working on a presentation and the screen got caught at the perfect angle to flex it and it died.
Didn't blame him, lesson learned, and I move my own seat back very slowly now.
There are at least a couple of banks or credit card companies in the UK now that only offer mobile apps, as well as those now using push MFA with their apps for every large purchase. Recently I needed to install an app from the UK government to prove my identity via camera to renew my driving license, and that doesn't work in GrapheneOS either. I can do it in person (for now) but there is an extra fee.
I have used them for the following:
* Holding a bandage in place
* Temporary clothing fix (broken fly, broken strap)
* Keeping hotel curtains together to block out light
* Popping a SIM tray
* Pinning something inside clothing when travelling in risky areas
It is rare to need one, but they take up no space so I pop one in my bag.*
My M3 was parked for 3 months and went from 80% to 60% which I'm perfectly happy with. Just arrived home, got back in it and drove. It was on WiFi, no sentry, and checked in on it only every 3 weeks or so.
Agree, coffee shops are the modern version. Only 25 years ago as a student in Manchester pubs were everywhere, and we often used to go to the pub at lunch time. Went back there recently and all the pubs we used to frequent were gone, replaced by coffee shops and people with laptops and smart phones :)
I don't know if Google Maps pays much attention to Android users frequenting a particular path. Where I live you need to take a particular route else you end up at closed gates. Despite hundreds of people using this route every day for years Google will still try to take you via a different route that takes you to a closed gate. Other mapping software gets it right but we have to provide specific route instructions in case anyone uses Google and ends up at a dead end. I have noticed this all over actually, with Google trying to take short cuts that don't work vs following well-established routes.
I don't recommend their pegboard for this. When I had some very modest weight (soldering supplies and glues) in one of the compatible trays attached to the top, it bowed out over time and warped the board. This looks far heavier with more leverage.
They said OpenAPI is an open protocol, not OpenAI.
This was attempted with the .trust TLD but did not catch on.
That reminds me of a hack I did. In the fairly early days of Android I realised you could install an app to a device from the Play Store using the website on the PC, and have it auto-run when triggered by an event such as the charger being plugged in. Combined with the API to disable the lock screen (eg when receiving an incoming call so the user can answer) it was a way to remotely disable the lock screen.
I created my first ever Android app in one evening and released it for free. It was the first one of its kind and was quite popular, mainly for parents who let their kids play with their phone and accidently lock it, or for people who wanted access to their loved ones device after they died.
However I received loads of bizarre and abusive support requests from people who demanded I help them, and even call them personally. Eventually I got fed up and started to charge a nominal amount and the support requests suddenly became much more polite and intelligent, filtering out the toxic support requests.
I read a post on HN about how increasing price on something can result in higher sales because people value it more. I decided to increase the price as an experiment, and sure enough the sales went up!
For 3 hours of work one evening creating the app, it made a few £10ks over a few years.
Eventually Google prevented the ability to auto-run newly installed apps due to malware using the same vector, now you have to launch the app manually the first time. While it still worked on older devices I eventually removed it because it failed more than it worked.
One issue I've noticed is in organisations that have staff in regions that don't have title inflation. For example in the UK orgs I've worked the majority of people were not particularly concerned about titles and didn't even put titles in their email sigs. When some offshore temp contractors came onsite and gave themselves grandiose titles in their email sigs that were far above the people they reported to it created a lot of confusion and consternation.
I've also seen issues when UK colleagues who are senior enough to manage teams who manage teams, but are still below the "Director" role, then have to manage an entire team of "Directors" and "VPs" in NA who are the bottom rung and manage nobody. It seems like the job titles in NA can be totally meaningless? I suppose if you are used to how it works, it works fine, but if you are from a region with more conservative (and accurate?) titles it causes friction due to an imbalance in perceived power dynamic.
I've even seen an org chart in a NA firm that has 3 CTOs stretching down the same reporting line, which just seems pointless.
Can confirm a 2 day engagement is unusual, and 50% of time writing the report is possible but very much an outlier for standard pen tests. Some interesting exceptions include:
* Some regions have a much shorter average engagement time. North America is usually pretty generous, where markets in other countries will only bear half or a third of the time.
* If you are a junior or less skilled you are perhaps more likely to get the small jobs while you are learning.
* External inf can be short on testing time and long in reporting if you find lots of issues, but automation helps the reporting in that regard.
* Some pentests are very documentation intense for specific reasons, such as M&A due diligence, or clients who want threat models and design reviews incuded. Still isn't 50% though.
And others. But in general what Thomas describes has been my experience over the years.
Disclaimer: I work for NCC, but nothing related to former Matasano and I don't know Thomas. Opinions are my own.
Using HomeAssistant OS here, with the new energy dashboard. I used an ESP32 device running ESPHome to read the flashing LED on my meter and send energy use to HA. It reacts faster than the zigbee monitor that came with the meter to give me good real time usage and long term stats. The energy use over time allowed me to spot some areas where I could reduce consumption.
AndOTP can use your fingerprint as well. Settings->Authentication->Device Credentials
Definitely. As a high school kid in the early 90s a classmate once had a pocket sized TV. The tiny screen and terrible viewing angle didn't stop us from crowding around it during break time!
It is incredible what you've accomplished already with such a small team! A very interesting problem area too. I've been a little involved with maritime from the perspective of digital security, which is an area that needs more attention, and wonder if/how you can improve that side of things with a modern solution. If you need to get in touch with folks who work on maritime cyber security by all means pop me an email.
Very nice pictures. I replaced my old DSLR with a mirrorless Canon M50. I did get a T-Ring adapter to fit it to the scope in the future so I will definitely be giving that a go. As you say, some objects can't really be seen with a standard telescope whereas a camera with long exposure can soak in the light. In fact you don't even need a telescope for many of them, a 200mm quality lens will do fine from the pictures I've seen.
Thanks for the suggestions, I will definitely take them on board!
My wife gave me my Christmas present (a telescope) a little early this year so that I could practice and hopefully be ready for this event. I've had a few sessions already and it feels really special out in the cold night looking up at Mars and other planets whiz by. It does need some preparation though. I've got my site on a hill selected with no obstructions, the telescope has been collimated (calibrated), red dot finder is alligned, I've learnt how to setup the equatorial mount and polar align it, and I have my blue filter for clearer visuals of Saturn and Jupiter. Meanwhile I'm out in the back garden checking for clear skies any chance I get.
One thing to know though, you won't see the planets as they often appear in pictures, those are usually made from hundreds of long exposure shots stacked and processed to bring out the detail. You pretty much just see small bright spots in the sky with a little surface detail if your optics are good enough. There is something about seeing far away planets with your own eyes however which feels magic and photos can't compare to the experience.
I believe they also run a programme of random tests regardless of symptoms. A friend of mine was selected for this and they periodically come to his house and take a sample.
The thing that caught my attention in the email sent to customers today: "Sidewalk uses a small portion of your Internet bandwidth to provide these services to you and your neighbors. This setting will apply to all of your supported Echo and Ring devices"
Even back when I learned COBOL there were stories of programmers who intentionally created Abends so an operator would call them up with an error code, they tell them to hit enter, program resumes and they can claim callout pay.
I converted to Colemak on a TypeMatrix keyboard some years back. Everything was fine and I used to sing its praises until I started having to go to client sites or using other work machines. In one embarrassing incident I was leading a team at a client site and they wanted a demo of what we could do on Linux. No problem, it is my main OS, except I could barely type and looked like I didn't know what I was doing. I went straight back to qwerty on a traditional keyboard after that, it just didn't work for my situation.
It was clear the UK was going this way for a while so I switched to a small cloud host for VPN which exits in another country. $5 a month and it took only a couple of minutes to setup OpenVPN with a simple shell script[0].
Also important is to setup outbound firewall (or other mechanism) so that if the VPN goes down, you don't spew your traffic over the open connection [1].
I don't notice any speed difference from daily usage over the last year. Large file downloads I task my NAS to download outside the VPN.
My purpose is only to prevent the ISP from collecting logs about usage, I don't expect it to have much effect if I'm targeted for surveillance and I'm fine with that. Who knows how ISPs will handle the data (we've seen targeted advertising and content injection in the past) let alone all the agencies with less than stellar security practices.
[0] https://github.com/thomascannon/scripts/tree/master/vpn [1]: https://github.com/thomascannon/scripts/tree/master/vpn/vpn-...
A brave effort. Given your commit history, documented plan and great idea I was happy to back it [1] and hope you succeed. Best of luck :)
[1] https://www.bountysource.com/fundraisers/539-neovim-first-it...
What about the charger, warranty card, manual, etc? There is space at the top of the bottle masked by a silver band which might contain something, but surprised if you could get the charger in there.
I tried it on my account, you get the confirmation that it has changed, but when I logged in it hadn't actually changed the setting. Perhaps one of the URL params is a token, CRC or hash of the email which ensures you need the correct values for the email you are changing.