HN user

weeks

223 karma
Posts2
Comments33
View on HN

“Buy, receive, or sell the personal information of 50,000 or more California residents”

If a business engages this type of activity, they need to have a scalable process for providing California residents with their data.

Describing a California law passed by a majority of voters as “idiotic hoops” is a miss.

Hardening macOS 8 years ago

"I recommend rolling your own email server"

This is actively harmful advice. Do not roll your own email. Use a well-known provider with a solid security track record.

Thanks for pointing that out. I've escalated internally to have the video restored.

Edit: the video has been restored.

Se­cu­rity Keys 9 years ago

While I absolutely agree with you, it seems far more likely that native implementations by Apple, Google and Microsoft will dominate the market. Windows Hello is a great early example of this.

ARKit 9 years ago

From what I've gathered this totally depends on your market. Creating a paid app or an app targeting US University students? iOS first. Creating an ad supported app or targeting an international market? Android first or use a framework that supports compiling to both platforms.

Where I feel a lot of the animosity from the Wikipedia community stems from is that the people who have "cultivated expertise in governing" are actually Wikipedia volunteers, not WMF employees.

As a Wikipedia administrator (mostly inactive), this sentiment makes complete sense to me. The WMF seemingly spends the majority of its money on non-critical functions such as community outreach, local chapters, yearly conferences and other non-critical costs. Including a parade of highly paid, not very effective executives. One thing to keep in mind is the WMF != the Wikipedia community, it is very possible to truly support the Wikipedia mission without also supporting how the WMF is ran.

While you're right that a lot of FinTech applications do use fingerprinting, it is absolutely against the rules. It's rather annoying from a mobile security perspective but given the rampant abuse of persistent device identifiers on Android, I understand and appreciate Apple's stance here.

The purpose of ascertaining device identity is to prevent someone who can't obtain legitimate Google issued hardware from using stolen user credentials. If you're already a Google employee you can just ask for more trusted hardware, so there would be little point in breaking that part of the security model.

For one, without Google Play Services you have no Play Store. Unless you're going to prevent users from installing apps entirely, there isn't really another safe way to obtain apps. Additionally Verify Apps, SafetyNet, Safe Browsing, etc. are all part of Google Play Services. You _really_ want Verify Apps.

I don't think this could be accurately described as merely a _vulnerability_ disclosure. These web stores are already compromised, therefore anyone that makes a purchase is exposing their payment information. Furthermore there is no "responsible" way to contact thousands of web stores across the globe. The best case for disclosure is Google's Safe Browsing beginning to warn users immediately.