HN user

tony101

5,492 karma
Posts248
Comments381
View on HN
support.apple.com 5mo ago

Limit precise location from cellular networks

tony101
3pts0
digital-lab.consumerreports.org 3y ago

Permission Slip: App to take back control of your data

tony101
82pts45
ddosecrets.substack.com 3y ago

Cellebrite's phone forensics software and documentation leaked

tony101
8pts0
mjg59.dreamwidth.org 3y ago

Making unphishable 2FA phishable

tony101
194pts54
twitter.com 4y ago

Twitter compiles a list of your interests and won't let you opt out

tony101
14pts3
www.vice.com 5y ago

Plaid paid people $500 for their employer payroll logins

tony101
92pts95
www.ft.com 5y ago

China’s tech giants test way around Apple’s new privacy rules

tony101
9pts1
msrc-blog.microsoft.com 5y ago

One-Click Microsoft Exchange On-Premises Mitigation Tool – March 2021

tony101
2pts0
www.documentcloud.org 5y ago

FBI: Malicious Actors Almost Certainly Will Leverage Synthetic Content

tony101
7pts1
blog.vaccinateca.com 5y ago

VaccinateCA: What We've Learned (So Far)

tony101
1pts0
nakedsecurity.sophos.com 5y ago

Another Chrome zero-day exploit – so get that update done

tony101
5pts0
www.epsilontheory.com 5y ago

The Opposite of 2008

tony101
3pts0
twitter.com 5y ago

PayPal Fires Customer, Refuses to Provide Explanation

tony101
41pts8
www.theguardian.com 5y ago

Why hot new social app Clubhouse spells nothing but trouble

tony101
10pts1
www.techdirt.com 5y ago

The Bizarre Reaction to FB's Decision to Get Out of News Business in Australia

tony101
4pts2
www.infinitus.ai 5y ago

Automating Calls for Good: helping VaccinateCA call 2500 pharmacies every day

tony101
1pts2
www.nature.com 5y ago

Coronavirus is in the air – there’s too much focus on surfaces

tony101
136pts186
www.washingtonpost.com 5y ago

Europe’s growing mask ask: Ditch the cloth ones for medical-grade coverings

tony101
5pts0
www.kqed.org 5y ago

California's Clearest Covid Vaccine Appointment Dashboard Is Run by Volunteers

tony101
21pts3
www.sfchronicle.com 5y ago

Crowdsourced website tracks where you can get vaccinated in California

tony101
2pts0
www.nbcbayarea.com 5y ago

New Website Lists Locations of Covid Vaccination Sites, Tracks Dose Availability

tony101
2pts0
tips.fbi.gov 5y ago

FBI Seeking Information Related to Violent Activity at the U.S. Capitol Building

tony101
125pts125
www.techdirt.com 5y ago

You've Been Referred Here Because You're Wrong About Section 230 of the CDA

tony101
439pts292
www.rollcall.com 5y ago

Capitol Police, a department shrouded in secrecy: not subject to FOIA requests

tony101
54pts24
www.bloomberg.com 5y ago

China Is Making It Harder to Solve the Mystery of How Covid Began

tony101
12pts0
www.cnbc.com 5y ago

Tech was ahead of Covid curve at every stage but couldn’t bring rest of us along

tony101
5pts0
www.washingtonpost.com 5y ago

Prosecutors accuse Zoom exec of working with Chinese government to surveil users

tony101
11pts1
refraction.network 5y ago

Refraction Networking: Internet freedom in the network’s core

tony101
1pts0
www.nytimes.com 5y ago

He’s Sorry for His Bad Reviews. He May Now Avoid Prison

tony101
2pts0
www.abetterinternet.org 5y ago

Memory Safe ‘Curl’ for a More Secure Internet

tony101
2pts0

From their FAQ:

“Permission Slip helps you exercise your right to privacy under the California Consumer Privacy Act (CCPA) by acting as your ‘authorized agent’ and sending data requests to companies for you.”

https://www.permissionslipcr.com/faq.php

The California Attorney General is monitoring companies’ compliance with authorized agent requests:

“The sweep also focuses on businesses that failed to process consumer requests submitted via an authorized agent, as required by the CCPA. Requests submitted by authorized agents include those sent by Permission Slip, a mobile application developed by Consumer Reports that allows consumers to send requests to opt-out and delete their personal information.”

https://oag.ca.gov/news/press-releases/ahead-data-privacy-da...

No. "This warrant authorizes the use of remote access techniques to search the electronic storage media identified in Attachment A and to seize and copy from the electronic storage media identified in Attachment A the web shells, used by actors to communicate with and distribute files to victim computers to infect them with malware, as evidence and/or instrumentalities of the computer fraud and conspiracy in violation of Title 18, United States Code, Sections 1030(a)(2) (theft from a protected computer), 1030(a)(5)(A) (damage to a protected computer) and 371 (conspiracy). This authorization includes the use of remote access techniques to access the web shells and issue commands through the web shells to the software running on the electronic storage media to delete the web shells themselves.

This warrant does not authorize the seizure of any tangible property. Except as provided above, this warrant does not authorize the seizure or copying of any content from the electronic storage media identified in Attachment A or the alteration of the functionality of the electronic storage media identified in Attachment A."

https://www.justice.gov/opa/press-release/file/1386631/downl...

Apple App Store Review Guidelines, Section 5.1.1:

"(iv) Access: Apps must respect the user’s permission settings and not attempt to manipulate, trick, or force people to consent to unnecessary data access. For example, apps that include the ability to post photos to a social network must not also require microphone access before allowing the user to upload photos. Where possible, provide alternative solutions for users who don’t grant consent. For example, if a user declines to share Location, offer the ability to manually enter an address."

https://developer.apple.com/app-store/review/guidelines/#pri...

"I'm all for HTTPS everywhere but right now for my products it's either: https with self-signed certificate, which basically makes any modern browser tell its user that they're in a very imminent danger of violent death should they decide to proceed, or just go with good old HTTP but then you hit all sorts of limitations, and obviously zero security."

How about what Plex did for its self-hosted media servers?

"First they solved the problem of servers not having a domain name or a stable IP (they are mostly reached via bare dynamic IPs or even local IPs) by setting up a dynamic DNS space under plex.direct"

"Then they partnered with Digicert to issue a wildcard certificate for *.HASH.plex.direct to each user, where HASH is - I guess - a hash of the user or server name/id."

"This way when a server first starts it asks for its wildcard certificate to be issued (which happened almost instantly for me) and then the client, instead of connecting to http://1.2.3.4:32400, connects to https://1-2-3-4.625d406a00ac415b978ddb368c0d1289.plex.direct... which resolves to the same IP, but with a domain name that matches the certificate that the server (and only that server, because of the hash) holds."

https://blog.filippo.io/how-plex-is-doing-https-for-all-its-...

The press release is specific and limited too:

"The newly-approved regulations ban so-called “dark patterns” that delay or obscure the process for opting out of the sale of personal information. Specifically, it prohibits companies from burdening consumers with confusing language or unnecessary steps such as forcing them to click through multiple screens or listen to reasons why they shouldn’t opt out."

https://oag.ca.gov/news/press-releases/attorney-general-bece...

Bitcoin Is Time 5 years ago

Transfer funds across borders without dealing with multi-business-day bank delays or capital controls in countries like China. Accept donations or other online transactions without relying on Visa/Mastercard.

"A generous friend had a few invitations to extend, and she offered me one. After that, she had an attack of what one can only describe as donor’s remorse, because in order to be able to extend the invitation to me she had to grant Clubhouse access to all her contacts!"

This does not appear to be in compliance with privacy laws such as GDPR.

It's not perfect, but I believe Coinbase uses a combination of cold (offline) storage for most of its coins and insurance for the rest. Also, as you probably already know, people should not hold large sums on exchanges if they can use secure their own keys (and wallets) instead.

"Coinbase prioritizes the security of our customer's digital currency through a combination of online “hot storage” and offline “cold” storage. Coinbase maintains 98% or more of customer digital currency in cold storage, with the remainder in secure hot servers as necessary to serve the liquidity needs of our customers. All digital currency that Coinbase holds in its online hot storage is insured. If Coinbase were to suffer a breach of its online hot storage, the insurance policy would pay out to cover any customer funds lost as a result."

https://help.coinbase.com/en/coinbase/other-topics/legal-pol...

The real problem here is that there is no consequence for incorrect takedowns. If content is taken down and then it turns out to be fair use, no one suffers a penalty.

There are exceptions to this. See Lenz v. Universal Music Corp., 801 F.3d 1126 (9th Cir. 2015).

"Lenz v. Universal Music Corp., 801 F.3d 1126 (9th Cir. 2015), is a decision by the United States Court of Appeals for the Ninth Circuit, affirming the ruling in 2008 of the US District Court for the Northern District of California, holding that copyright holders must consider fair use in good faith before issuing a takedown notice for content posted on the Internet."

https://en.wikipedia.org/wiki/Lenz_v._Universal_Music_Corp.

"In ... Lenz v. Universal Music Corp., decided by the Ninth Circuit on September 14, 2015, a mother's 29-second home video of her two toddlers dancing to Prince's 1984 song "Let's Go Crazy" has made important new law with respect to "takedown notices" under the Digital Millennium Copyright Act ("DMCA"), holding that copyright holders must consider fair use before sending a takedown notification. This decision increases the potential liability for copyright holders seeking to enforce their rights through the DMCA and should serve as a warning to ensure fair use is considered before sending a takedown notice."

https://www.jonesday.com/en/insights/2015/09/ninth-circuit-s...