I'm not surprised to see this come back to bite them if after like 7 years Apple still hasn't adopted the only strong defense.
430 karma · joined June 17, 2015
I'm not surprised to see this come back to bite them if after like 7 years Apple still hasn't adopted the only strong defense.
Doesn't really seem like much of a win for consumers though... it's just trading one personal data hungry megacorp for another.
Maybe immediate disclosure would cause a few users to change their behavior, but no one is tracking security disclosures on all the software they use and changing their behavior based on them.
The caveat here is in case you have evidence of active exploitation, then immediate disclosure makes sense.
The only reason is that the status quo is they have in the past freely supported these use cases, but it doesn't seem that unreasonable for commercial use API access to cost money.
It's a nice idea, but your personal website doesn't matter. Most people go to a Google website at least a few times a day, and they already tell you to switch to Chrome for the best experience. And almost all of the top non-Google websites also have a vested interest in less adblockers, so none are going to riot over this.
I wasn't proposing any specific solution, just stating that eating animals does in fact contribute more CO2 than eating plants. And I have no problem with carbon taxes, in fact I'm in favor. A carbon tax could certainly cover this case if it taxes the CO2 that animals emit.
I don't think it would last a year before it was taken down, regardless of whether or not it did what it was supposed to do or was responsible for any meteorological event.
And if they actually do hurt someone, I imagine they would be criminally liable.
Bytecode is usually a buffer of high level instructions that is compact and fast to read (for the machine). Good for interpreting and holding the semantics of a program in a format that is more efficient than the source code, but it is usually not a good format for running compiler passes.
You can't go to India for a cure that doesn't exist.
If the patches were accepted, the person could have used those fixes to justify the benefits of the static analysis tool they wrote.
In many cases PTC causes tail calls to be slower, and it messes up stack traces. This would happen even if a developer doesn't want/need tail calls. So it was a feature that would degrade performance and debuggability of existing websites to allow new code to use a more recursive style of programming.
The main performance problem comes when you have tail calls that need to grow the stack. The engine will need to do work to adjust the stack frame.
In languages like C++, the compiler chooses to do tail calls when it improves performance, but with tail calls as a language feature, engines have no choice in the matter and had to do it even when they would significantly increase call overhead.
On top of this, there there were a number of implementation issues and corner cases. For example, most engines have some extra code layer for marshalling cross-site function calls that couldn't be removed. I also remember there being issues with Windows x64 ABI/stack frames. Tail calls from interpreter into JIT code were another implementation headache.
All this added up to have JS engines basically boycott the feature.
I would guess it takes at least a couple weeks from exposure to get into critical condition and treated.
But I guess the incubation period is so long that those more mild cases may resolve before they can be tested.
For us, we like that the budget is tangible. There is only so much money we can withdraw from it, which helps us avoid blowing through our budgets. It also works well with the way we split costs. I make more money, so I put more into the pool every month, but other than that we don't need to think about it.