From what I understand, connecting to an onion address 'just' involves 6 routers, not the typical 3. (Of course an oversimplification.)
Or am I misunderstanding your threat model here?
562 karma · joined January 31, 2014
From what I understand, connecting to an onion address 'just' involves 6 routers, not the typical 3. (Of course an oversimplification.)
Or am I misunderstanding your threat model here?
Or better yet, build the Edge browser so that it's actually an app using webview2 to help ensure that webview2 has a great API experience and is actually easy to use.
I'd love suggestions for better solutions though, I'm sure there's something I haven't considered.
Poor people are more often in less stable living situations and it's easier to lose track of documentation. Not to mention unhoused people who don't have a safe place to keep track of things either and often don't have up to date identification in the first place. Also, with less access to the internet to do things remotely it's more common to need to take time off work to go to a physical branch which may be very far away, requiring taking multiple busses just to prove their identity.
Of course adding more security is important, but it has tradeoffs like this that harm the poor that need to be considered.
I still think it's BS that you can't scan money though and it very much an overreach. Your home printer isn't gonna make a convincing fake anyway.
Or it was a code change that was able to be validated and rolled out to all regions but then some totally independent interaction caused it to fail afterward in a unique way.
I'm banking on surprising singe point of failure though. I really hope we get a detailed post mortem here.
It's totally possible for a bedroom-made startup to grow to the point where the lack of GDPR enforcement could be directly harmful to customers, for example. True it's unlike they'd get noticed, but I don't think that's a strong argument here.
I want reasonable widespread application of GDPR, ADA, etc with explicitly carved out safeguards for small operations like this teenager.
They shouldn't have to rely on getting lucky
So many "average" users just want consistency and will go with WD again because they don't need to relearn as much (even if the relearning is minimal it's still a mental barrier for anyone who does not feel totally technically competent).
I think of my parents who, despite being very smart people, are frustrated by tech because it doesn't come easy to them. Any extra step isn't beneficial, it's stressful.
If weight loss things were FDA approved, effective, and didn't carry the weight of a society that tells people that being overweight (or even just feeling overweight) makes you less respected as a human being, then I'd totally agree with you that they shouldn't be banned outright. But unfortunately with how we currently look at weight loss it's not as simple.
(I also hate the pervasiveness of identifiable tracking but that's a whole different rant.)
You don't need to perfectly A:B test your two different offerings if that means preventing users from using the product in a way that best suits them. Stop putting shit behind "read more" buttons just because you want to see if people are actually reading your articles. Stop breaking things into multiple screens just so you can track your damn funnels. Better MAU _tracking_ (not even better MAU) does nothing for user experience and pursuing that at the expense of everything else is just plain foolish.
At home I am limited in my skills and in the quality and variety of ingredients. In a restaurant (one where the chef actually makes food, not a place where it's microwaved, cooked from frozen, or just repackaged restaurant supply food), I get a skilled chef using many high quality ingredients which I cant get my hands on for any reasonable price to use at home.
I'll still avoid getting certain things at restaurants that I could make at home (many pasta dishes for example), but there are so many things I'd have a lot of trouble making myself.
All of this hardcoded DNS server BS in iot devices is a pain.
But for example Steam updates on boot, which is a (albeit minor) pain when I want to use it. Similar with Spotify. There aren't really any great alternatives to either of them that have equivalent libraries of content.
Or going right to the core, Windows and it's annoyingly frequent updates. Sure I could use Linux (and I do on a few machines), but that isn't possible on my work machines, and introduces incompatibilities on my personal machines.
A flaw in my browser is extremely high risk and I require it fixed and updated quickly. But a flaw in my SSH server that is only accessible from behind a VPN is lower. And the risk is lower still if it's a flaw in a feature which I do not use.
I don't see an easy solution of course, it's a hard problem. But I wish that I had more granular control over what and when I update, and was given a clearer way to see the impacts of the update so I could weigh risk.
Though setting aside practicality for a bit I wish we would design software to be more backwards compatible so old versions of things could continue to work for longer. I shouldn't have to buy a new phone every three years, for example.
Also for a tool like Audacity, I rarely need to update it. It doesn't depend on a service, so I don't need to worry about an API falling out of support and he security risks are much lower. I wish we could design more of our software to work this way.
Obviously for internet connected things like browsers this isn't possible as the security impacts are significantly higher, but why should I need to update Word every month if I don't plan to use the online components, for example.
But that introduces issues where if Google adds some shitty new feature to Chrome I sorta get forced into it instead of having an opportunity to choose, so there's definitely a tradeoff and also a responsibility on the part of the vendor to make sure they aren't abusing their ability to install things on my computer.
My comment above is more of a rant than a recommendation.
When I open a program, I want to use that program. I don't want to update it, I don't want to see all the new features, I want to USE it. I opened it because I had a task to complete and all this junk is getting in my way.
And same when I close a program, as the author hits on very well.
Basically, the computer/program/etc always wants me to do something for it, but it never asks for those things at an opportune time.
No, I don't want to update my computer right now, and no, updating overnight tonight isn't good either because I need to keep this program running until tomorrow. I understand that your new UX is better for me, and I'm sure I'll love it, but forcing that on me right now is preventing me from doing what I need to do. I see your error dialog describing some odd issue, but I don't have time to triage that right now and decide to take the time to fix it.
I wish software would respect the human element more. My time and attention is valuable, please don't interrupt it carelessly.
There's no assurance that I'll hear about the next invasive feature, which is yet another security risk in my network that I need to be aware of.
And even if Amazon is tunneling all traffic now, that may change or someone may find a way to break out of it.
And even if law enforcement sees that the traffic is from Sidewalk, our legal system is pretty shit regarding the internet and I bet a dedicated prosecutor would try to get you for aiding a criminal because you technically allowed that access to your network. Look at the legal issues around running TOR exit nodes and the uncertainty there, in a lot of ways this is an opt-out version of that. (though I admit this might be a stretch, but I don't trust the legal system enough to handle this well).
But it seems like in this case it's mostly a rate limiting and identification exercise and not a secure protection of user data so the impact of exposure is substantially lower. So it does seem reasonable here.
Though I hope that OP has documented all over the place "do as I say not as I do" so people don't copy this pattern.
Who I am is not.
You don't need to know if I have kids, have a disease, my age, my race, my gender. You don't need to know anything. Sure that information would help you make a better experience for me, I get that. But that's up to me. If I want a better experience, allow me to provide that information in exchange for the benefits that information gains me. But peeking over my shoulder as I walk through your store so that you can overanalyze everything I do isn't okay.
They shouldn't require tracking to succeed in order for me to buy the product. If they want tracking, sure. But be resistant to it erroring out. Don't let errors in 3rd party tools prevent your user from getting their core goals completed.
The same goes for client apps. Don't crash the app if it fails to log to a file. Don't crash the app if it can't sync your cache. Etc, etc. Don't let these unnecessary conveniences get in the users way.
Writing passwords down on paper and leaving that paper in an insecure area isn't.
Your little address book full of passwords is the same as a password manager, and for a lot of people it's easier for them to manage the security of a booklet than it is to handle a password manager properly. And for those people, it's definitely worth using a book for the sake reasons we say using a password manager is a good idea
The contrast issues sometimes make design a bit harder, but it's totally worth it I believe.