---
[0] https://noyb.eu/en/pay-or-okay-report-how-companies-make-you...
[1] https://noyb.eu/en/project/forced-consent-dpas-austria-belgi...
174 karma · joined May 30, 2019
---
[0] https://noyb.eu/en/pay-or-okay-report-how-companies-make-you...
[1] https://noyb.eu/en/project/forced-consent-dpas-austria-belgi...
How does this work, exactly? Does you cloud password/key manager allow syncing to the YubiKey?
Or do you register a second passkey that you store on the YubiKey whenever you create a passkey?
If it is the latter, do all services that allow passkey authentication also allow registering multiple passkeys? How many?
> could do two backup YubiKeys [...] keep one YubiKey in a safe deposit box
If you register a new passkey on the primary, do you then have to take the backup YubiKey out of the safe deposit box to put it on it as well?
I haven't seen this kind of question answered when sites prompt me to use passkeys instead of passwords.
Those of us who are not comfortable with that and want to keep our credentials offline and sync/backup them ourselves have questions about how the registration/backup/sharing flows work exactly.
I see this as part of a trend together with remote attestation, age verification, CSAM scanning, restricting sideloading, etc that will lead to most interactions over the internet only being allowed if big tech and/or government can verify the participants, the contents, and the hardware and software used.
Even among techies, many support these developments, so it is just a matter of time before we have no choice but to join the former group.
My system would randomly freeze for ~5 seconds, usually while gaming and having a video in the browser running a the same time. Then, it would reliably happen in Titanfall 2 and I noticed there were always AHCI errors in the Windows logs at the same time so I switched to an NVMe drive.
The system would also shut down occasionally (~ once every few hours) in certain games only. Then, I managed to reproduce it 100% of the time by casting lightning magic in Oblivion Remastered. I had to switch out my PSU, the old one probably couldn't handle some transient load spike, even though it was a Seasonic Prime Ultra Titanium.
Put an expiration date on the storefront and make it clear that your software is not guaranteed to continue working after date X
False, it says[0] providing reasonable means to continue functioning of said videogames without the involvement from the side of the publisher
It MUST be possible to continue playing the game using reasonable means. It is not sufficient to declare an EOL date. Have your server source code (stripped down of proprietary stuff) ready for public release at EoL
This would only be sufficient if the proprietary dependencies are reasonable easy to acquire. Allow customers to reverse engineer the binaries and communication protocol after EoL
I don't think this reverse engineering could currently be disallowed in the EU, so it would not be affected by the initiative. Package dedicated server binaries with the game
True, it would meet the requirements of the initiative, but it would be sufficient to provide the server after EOL.----
[0] https://citizens-initiative.europa.eu/initiatives/details/20...
Ensuring that a critical mass of people use remote attestation[0] capable devices.
The next step is a browser API[1] for this so that content owners can exclude devices capable of storing the content, or stripping out ads/tracking, etc.
Sure, there will be a cat-and-mouse game where people will figure out how to fake the attestation for some period of time, but general computation[2] is probably on the way out.
----
[0] https://en.wikipedia.org/w/index.php?title=Trusted_Computing...
It can correctly open my company's Power Point templates and IMO the UI is much better in both aesthetics and discoverability compared to LibreOffice.
> nslookup google.com
Server: fritz.box
Address: fd00::[redacted]
Non-authoritative answer:
Name: google.com
Addresses: 2a00:1450:4001:828::200e
142.250.181.238
Update: the connection does have the DNS suffix, so according to the superuser answer linked in OP (which is the first result when looking up what a DNS suffix is), it should get appended to lookups on windows, but it looks like it isn't in my case. > ipconfig
[...]
Connection-specific DNS Suffix . : fritz.boxPlenty of utility companies are already being forced to provide service. As the EDPB opinion says, a lot of big tech is
> decisive for participation in social life or access to professional networks, even more so in the presence of lock-in or network effects
> Untargeted advertising pays 90+% less than targeted advertising
I don't think that such a large difference is rational. "Untargeted" advertising can still be based on the content being viewed, just not on surveilling the viewer.
> If they lose money by serving a user content because they denied targeted advertising, they should be able to deny them service or have them pay up.
As I understand it the opinion does not categorically rule this out
> Controllers should ensure that the fee is not such as to inhibit data subjects from making a genuine choice
That is why NOYB also focuses[0] on the fact the the fee is disproportionate:
> The current average revenue for programmatic advertising in the EU is € [1.41] per user - across all websites per month [...] visiting the top 100 websites can already cost more than € [1500] per year if you do not consent to tracking
---
[0] https://noyb.eu/en/statement-edpb-pay-or-okay-opinion, https://weis2019.econinfosec.org/wp-content/uploads/sites/6/...
Some are saying "of course sites are still tracking you in incognito!", but is is unclear to me what they mean by this. I see the following interpretations:
1. Sites can still use local storage so they can track you for the duration of your incognito session, but they cannot connect this tracking to your regular session or other incognito sessions as incognito sessions start with empty local storage and discard it at the end of the session.
2. Sites do not rely on local storage, instead using fingerprinting via a combination of IP, HTTP headers, information they can query via JS, etc., so incognito has no effect on sites' ability to track you.
3. Google has special privileges in Chrome to track you when you are incognito.
In the EU you would have to reduce your welfare state to that level for your own citizens as well. The ECJ says[0]:
> It follows that the level of social security benefits paid to refugees by the Member State which granted that status, whether temporary or permanent, must be the same as that offered to nationals of that Member State
[0] https://curia.europa.eu/juris/document/document.jsf?text=&do...
What I AM sensitive to however, is temporal instability - it just draws my attention and hurts immersion. Here DLSS makes a huge difference, as shown here[0].
Therefore it is sad that Bethesda chose[1] to deliver worse than possible image quality for 80%+ of their PC customers[2].
----
[0] https://youtu.be/ciOFwUBTs5s?feature=shared&t=336
[1] https://news.ycombinator.com/item?id=37452149
[2] https://archive.ph/mqPLK, nvidia has 75% market share here, but you have to look at the higher end parts only and exclude Intel as Starfield does not run at all on their GPUs[3]
[3] https://in.ign.com/starfield/193351/news/starfield-intel-fin...
There are so many powerful interests that stand to gain from preventing e.g. ad-blocking and content capture. Thanks to Windows 11 requiring TPM, it is just a matter of time until hardware support for remote attestation is ubiquitous even on desktop computers.
Meanwhile, our (including myself) attention is (perhaps justifiably to some extent) on the latest news about $EXISTENTIAL_THREAT and how $THE_OTHER_SIDE did $EVIL_THING fed to us by the algorithm. Organizations that used to effectively fight threats to freedom like this (FSF, pirate parties, CCC, EFF, etc) have lost a lot of their support/influence and clarity of purpose over the last decade.
We could fork it and remove the interface or switch to ULID[1] instead.
[0] https://github.com/stephenc/eaio-uuid/blob/master/src/main/j...
This is not true for many applications. Due to the removal of many APIs from the JDK with Java 9, I needed the following dependency artifactIds to be able to move a JEE application with SOAP web services to Java 11: jaxb-api, jaxb-core, jaxb-runtime, istack-commons-runtime, jboss-jaxws-api_2.2_spec, glassfish-corba-omgapi, jboss-annotations-api_1.2_spec, activation, jboss-saaj-api_1.3_spec, saaj-impl, stax-ex, jsr181-api, txw2.
Many of these spec API/implementations are provided by different artifacts that are incompatible with each other. Some I only discovered when something failed at runtime as they perform implementation lookups and you don't get compile errors.
Additionally, many of the Maven plugins we used no longer worked and our application server failed to start.
Can you please expand on what you verify via remote attestation and against which attack vectors this protects you?
Does this protect you against the usual attack vectors of your employees logging in on phishing sites, downloading malware, running office macros etc? Stealing your data usually does not need any root/kernel access.
We hoped it would be fast enough that we can just wait for the confirmation before committing the transaction.
The official documentation says
> This means that under a constant load, latency for basic.ack can reach a few hundred milliseconds
I never did statistics, just looked at the log. IIRC most were acceptable but > 3s occurred frequently enough (and we even had instances of messages never being confirmed, IIRC) that we abandoned that plan.
We considered using Debezium[0], but decided on the current solution as it could be solved entirely with the current services and infrastructure whereas Debezium would have required us to deploy (writing this from memory so this might be inaccurate/incomplete) Kafka, Zookeeper, and a connector service.
We found out the hard way that RMQ does not behave like a transactional DB. Just because publishing worked does not mean the message will be delivered.
Our solution is to also write the message into an outbox table in the DB. We then publish the message using confirms[0]. RMQ asynchronously sends us a confirmation when it has really persisted the message. We then delete the outbox entry. If we do not receive the confirmation in time, a timer will re-publish the message.
Therefore I disagree with the suggestion of using a library wrapping the native RMQ one. We are using spring-amqp and this made it harder to understand what is going on. In the end, for a large project you will have to understand nuances of RMQ (and other infrastructure you are using). Using a leaky abstraction over it means you now have to understand both the underlying product and the abstraction.
[0] https://www.rabbitmq.com/confirms.html#publisher-confirms
Congress could pass laws saying that the EPA can regulate greenhouse gas emissions, that states cannot forbid abortions, etc.
If you think that these rulings are not plausible interpretations of the law, Congress can even define the size of the court[0]. They could pack the court with judges who will interpret the law in their favor.
It is my understanding that the Democratic Party that holds the majority in both chambers claims to be in favor of these policies, so why aren't they taking action?
At some point, even ISPs might require remote attestation to allow you to connect your device to the internet. The IETF is already working on standards for the attestation of network devices[0][1].
I speculate that there will temporarily (perhaps similarly to iOS jailbreaking, which is not available at this time for the newest devices/iOS version[2]) be exploits allowing you fool the attestation by e.g. redirecting it to another device as the author suggests, but the end effect will be that vast majority of people will be effectively confined to a walled garden and even determined hobbyists will only be able to use their general computation capable devices to access all content (or even connect them to the internet) some of the time.
[1] https://datatracker.ietf.org/doc/draft-ietf-rats-tpm-based-n...
[2] https://en.wikipedia.org/w/index.php?title=IOS_jailbreaking&...
They've been doing a poor job of communicating. Considering the attention this issue is getting, they should have a prominent notice on their project page[0] about it like the one Logback[1] has telling people that they are not affected.
Furthermore, even their post about the issue[2] still fails to clarify many details like
* are people using newer JDK versions safe, like one commenter in this very thread assumed[3] ?
* does it only affect the format string and not parameters as many [falsely] claimed when the news started making the rounds ?
* what should people trying to block exploitation on a firewall level look for ?
> for a feature we all dislike yet needed to keep due to backward compatibility concerns.
They have not recognized the security risk posed by what is effectively an expression language interacting with user-submitted data. Java projects used in server-side templating like OGNL, JSP and JSF implementations, Spring keep having security vulnerabilities with this even after 20+ years. It is an effectively impossible task to get this 100% secure.
The ridicule Log4j is getting serves a purpose beyond fun: it lets people know that the project's maintainers are not up to the task and another logging library should be used instead, as there might be more issue still undiscovered or added in the future.
[0] https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CEL...
I assume you would be able to get a booster off-label in the Netherlands.
[0] https://gruenerpass.gv.at/geimpft/ "03. Jänner 2022 ist das Impfzertifikat einer einmaligen Janssen Impfung nicht mehr gültig."
> The Spitzenkandidat of the largest party would then have a mandate to assume the Commission Presidency
While this is not de jure, German-speaking media did report on the 2019 election as if the above were consensus. It is my understanding that this was not the case in all EU countries.
those feature are either horrible
I speculate that most users of languages that have these features (Kotlin has all of them) would be unhappy if you took them away. algebraic data types and pattern-matching -- will lead to better development practices, rather than making it easier to work with inferior ones.
I am not arguing against those features, but the ones I asked for seem easier to implement by comparison as they are already in other successful JVM languages.
Furthermore, they are far more frequently useful for my use case of web services storing, transforming and moving data around, often without caring too much about their semantics.
I speculate that a large portion -probably a majority- of JEE/Spring devs are in the same position.I am disturbed by how universally true you seem to consider your positions - as if there were no cases in which mutability is preferable to immutability (even if that is sometimes just due to the way some ORM or serialization library works).
If these features are such bad ideas there should be plenty of stories of Kotlin/C# devs cursing the language for providing them with these footguns.
Having a JDK dev respond like this only strengthens my argument that cageface has no reason to fear that Kotlin will lose steam - Java has different priorities. There is nothing wrong with that, but more developers who want these features should be aware that they will not be getting them from future Java versions.
* null safe navigation operator
* properties
* mutable records
* a way to ignore checked exceptions (or at least having the stream API take functional interfaces that can throw exceptions)
* adding functional methods like .filter()/.map() directly to collections instead of having to .stream().map(..).collect(toList())
Of course, efforts should be made to expand capacity (my government was unfortunately too incompetent train more medical staff for this since the start of the pandemic).
Obviously, these people think that the disease is less dangerous than the vaccine. They should bear the consequences of their choice. Let's not endanger other's lives/prolong their suffering (surgeries are already being delayed again in my country).
I realize this could be a slippery slope, e.g. someone could argue that we should give lower priority to smokers, obese, or addicted people. However, the vaccine does not require any lifestyle changes and at this point it has already been given to billions and has shown a much lower rate of severe side effects than the disease.
Also, MS Teams installed from the Ubuntu software store on Ubuntu 21.04 does not support screen sharing. You have to switch from Wayland to X11 to enable it. Even then it is missing features like selecting a single window to share, allowing others to highlight on your screen. It does not matter whether this is Microsoft's fault - Teams is a must have in many organizations and Canonical promotes the app in their store.
[0] https://wiki.x2go.org/doku.php/doc:de-compat
[1] What I have personally encountered: on KDE drkonqi crashes all the time when remote, on GTK-based DEs I get color management prompts and gnome-keyring breaks on local sessions - even worse, it seems to block for minutes then tell the caller that you don't have credentials instead of exiting with an error.