If laws aren't transparent and reasonable, you shouldn't necessarily follow them. If I were to sell encryption software that's banned in Kazakhstan, you wouldn't expect me to stop selling to customers there, would you? I see no reason why the United Kingdom should be treated any differently than Kazakhstan in this case.
The British government is certainly not as authoritarian as those in China or Russia, but that doesn’t change the fact that it’s still terrible and restricts people’s rights. For example, you can be detained for as long as they want if you refuse to unlock your encrypted device.
What I don't understand is why Apple is even responding to this absurd demand. Completely banning Apple products in the UK isn't a realistic option for the government, so Apple could simply state openly that it does not cooperate with authoritarian regimes and actively prompt British users via a pop-up to enable ADP to protect themselves from the government.
Because anonymity is the reason I use a VPN in the first place. Without anonymity, I’d have to worry about getting a cease-and-desist letter if I downloaded a torrent, or having the police raid my house if I accidentally called a politician a dick.
It would be cool if there were a way to use it the other way around. A Mullvad server as the entry point and an Obscura server as the exit point. My main problem with Mullvad right now is that its servers are blocked almost everywhere or generate an excessive number of Captchas. With other VPNs, that’s been much less of an issue so far. Alternatively, a residential proxy might be a good option as an optional exit point. One way to achieve this, for example, would be through a partnership with a regular ISP from which you could then borrow IP addresses.
There's the experimental Fairydust Branch which lets you connect a monitor via USB-C. However if you want to use more than one external monitor DisplayLink is currently the only option that works reasonably well. Unless you have a Mac with an HDMI port in which case you can use it.
I think they should instead just introduce a clear system for verifying that a Raspberry Pi is genuine. For example, a code printed directly on the device. If you enter that code on the website, you can see exactly which model it belongs to and how often it has been used. That way, you could determine whether a Raspberry Pi is new or used and whether it has been modified.
I saw that once at a thermal paste manufacturer. They used it to solve the problem of counterfeit thermal paste.You just have to get people to actually use the system and tell anyone else who asks for support but doesn't have an original copy to GTFO.This would allow them to avoid the increased support burden without limiting people's ability to upgrade their Raspberry Pi.
If you're looking for an event where you don't have to use a credit card I can recommend the Gulaschprogrammiernacht in Karlsruhe. It has a similar vibe and is funded entirely by donations and the sale of goulash.
This approach assumes that the smartphone in question is not under the user’s control. That should generally not be the case. When I buy a device, I have the right to install whatever I want on it and to make the camera sensors believe whatever I want. If something cannot be implemented securely under these circumstances, it’s not a good idea, and other solutions are needed. I once tested a video identification system for a company that the manufacturer claimed was absolutely secure. All it took was rooting the smartphone and bypassing the root detection. After that, you could play any pre recorded video, which would then be recognized as camera input. Under those conditions, it was easy to manipulate a video so that a company employee would consider it real enough to verify the test subject.
It’s simply not technically possible to verify the authenticity of the camera input with 100% certainty. Pretending that it is possible only creates problems. Then someone fakes evidence, but all the normies who have no clue about technology assume that it must be real. You see this with AI detectors too they recognize random texts as generated, yet an unbelievable number of people believe them.
The solution would be simply to add a warning as a temporary measure preferably in red text and in a way that would scare the average user. This warning should be accompanied by a call to action urging users to contact the device manufacturer and ask them to release a new driver. Then companies would have no choice but to either create a new driver that runs in user space or be constantly inundated with support requests from customers.
The answer is quite simple. You just don't verify it. The point isn’t to verify the age but to set the age on the device itself. If the parents set the age on the cell phone or computer, that setting is then used as the basis. The operating systems can be configured so that only the device administrator can change the age. Systemd already has a field for storing the age, which programs can read. If the child doesn’t know the root password for the laptop, they can’t change the age. If they do manage to get around that, well, so be it. The solution doesn’t have to be perfect because it would still be an improvement over the current situation without restricting adults in any way.
I'm fundamentally opposed to age verification because it usually leads to mandatory account creation no matter how privacy friendly the age verification process itself may be. It's already extremely annoying that, for example, on YouTube, you can no longer watch many videos without an account. Furthermore, the whole thing also reinforces monopolies. Once you've verified your age on one platform, the barrier to switching to another is even higher than before.
The only acceptable solution would be for apps and websites to simply include a recommended age. Allowing parents to configure their children’s devices to block services that require users to be older than the specified age or that do not provide an age rating. Once this were established, websites targeting all age groups would have a strong incentive to participate. Otherwise, they would suddenly become invisible to a large portion of their underage users.
Mailbox.org is based in Germany, which is why you generally cannot trust its feature that automatically encrypts all incoming emails. Other german mail providers, such as Tuta, have already been forced at the direction of government authorities to store every incoming email from certain accounts separately in unencrypted form. Even though Proton also cooperates with authorities, Swiss data protection laws are significantly stricter in this regard. So far, there is no regulation there that requires them to implement a backdoor. They only disclose metadata, the IP address, and the backup email address. Whereas Mailbox would have to forward the entire emails to the authorities.
I think that instead of trying to prevent web scraping, websites should try to make it easier so that it generates less traffic. As long as any user is allowed to view the website, there will always be a way to scrape it anyway. If there were simply a monthly updated torrent available on a standardized subpage, such as example.com/scrape, scraping would be much less harmful.
That reasoning is complete nonsense. If someone scrapes the data, that’s not a big deal, and Reddit has no more claim to the data than anyone else. The data is public and created by users, not by the platform itself. If the traffic is too much for them, they could use rate limiting or simply offer an archive of the data as a torrent once a month. That way, a company training an LLM could access a complete dataset without generating a lot of traffic.
I think the better solution would be to treat every answer as if it were written by a human and then hold the person accountable for any mistakes. I’ve often seen in academic contexts that people have published texts with completely fictitious citations. In such cases one should confront the person as if they had done it on purpose. No one can accidentally invent entire books and authors. The same goes for software projects, where some people submit code that clearly comes from an LLM and hasn't been properly reviewed beforehand. If there are security vulnerabilities in that code, you can accuse the person of having done it on purpose. Anyone who submits AI code without labeling it as such is affirming that they understand the code and have thoroughly reviewed it.
So does that mean my girlfriend is also to blame for the war just because she happened to be born in Russia? She’s against Putin herself, but there’s not much she can do about it because, as a trans woman, she’s persecuted by that shitty state simply for existing. If she protested, they’d kill her. Why should she now be barred from at least pursuing her hobby and submitting patches for software projects?
I think it's immoral to withhold LLMs for “security reasons.” All LLMs are all trained on forum posts from real users, source code from free software, and books written by authors. All of these people should therefore also have access to them. Ideally, the models should all be open weight. But making the model accessible only to certain groups of people is even worse than if it were at least available for purchase as a service for everyone.
Privacy Pass would also be a good option. You can use it with Kagi, where you’ll have cryptographic tokens that you can use for searches without them being linked to your account. Even if you use a non-anonymous payment method, you could still use the service without leaving a trace.
> After about 2010 companies stopped providing the server binary. Games like Modern Warfare 2, Battlefield 2, etc could be played by communities in perpetuity on private servers. If the next game (MW3, BF3) were terrible, you didn't have to buy the sequel, what you had was "good enough" and you could wait for the next version to be released in 2-3 years.
That's not true about Modern Warfare 2. Modern Warfare 2 was the first Call of Duty game where you could no longer host your own servers. In its predecessor, Call of Duty 4: Modern Warfare, however, that was still possible. For MW2, unofficial servers created by players only became available later on. However, Activision has taken legal action against many of these projects.
> Am I responsible for providing a fallback to EOS, or Steam, or playfab in case their services are decommissioned?
In this case, the company offering this service should be responsible for making it possible to host the service independently before discontinuing it. However, games that use such standardized services are actually less problematic in practice. For Steam, for example, there is the Goldberg Steam Emulator, which emulates Steam’s online features. Games that do not have additional DRM or any extra features but simply use the standard Steamworks SDK for multiplayer can be played entirely without the Steam client or server using this emulator.
Even for services that had already been shut down, like Gamespy back then, Openspy quickly emerged as an alternative. Not all games worked right away, but the community fixed most of the issues very quickly. So, in the end, the games that use some kind of custom solution built by the developer themselves are much more important.
> There's also the likelihood of the server architecture requiring many moving pieces. Think if fortnite died tomorrow how many different servers it would take to host. Could an argument be made that an end user couldn't be expected to launch a dozen aws services? More dev time, more costs.
There are already several Fortnite servers available for self-hosting. Fans have created these on their own without access to the official code, and they run on a standard PC or a custom-built server using off-the-shelf hardware. One example of this is Project Reboot, which is publicly available on GitHub. People use it to play older Fortnite seasons or to play the game with friends on unsupported platforms like Linux.
Even though I wouldn't really use something like that myself, I actually think it's a good thing when people share their dotfiles with others. Whether you call it a “distribution” or not is basically irrelevant, and I don't understand all the fuss about it.
However I would still generally advise against using Omarchy because the maintainer does not seem to place any importance on security. For example the default firewall configuration leaves the SSH port open and the number of failed login and sudo attempts before a timeout has been unnecessarily increased. Furthermore Omarchy installs some of the offered programs via a .sh script that is downloaded via curl rather than using a package manager like the one Arch already has. In addition Hannsen still refuses to sign his commits, which means it's only a matter of time before a supply chain attack occurs.
No, thanks. Vivaldi is proprietary software and therefore not trustworthy. Since the source code isn't fully available, there's no way to verify whether an update might secretly add a feature that collects data. Since the source code isn't fully available and you can't compile it yourself, there's no way to prevent a feature that collects data from being secretly added during an update.
The reasoning behind why it isn't open source is also complete nonsense. Just because it's easy to create a fork doesn't change the fact that most users will stick with the original as long as the fork doesn't offer significant improvements. With Firefox, people aren't flocking to the existing forks either.
> I, for one, like streaming apps enough that I don't want to go back to locked-down, expensive DVD players. The alternative to DRM isn't "no DRM", it's "no content".
That statement is simply not true. The demand for streaming services would still be there. There would simply be even more illegal alternatives than there already are, so companies would still be forced to offer movies and TV shows via streaming. They only have the choice between offering DRM-free content and making money, or making no money while people watch it anyway.
But that would only be possible for large companies. If I'm just tinkering with my own Linux distribution for fun, Google won't even bother responding to my request.