427 karma · joined March 9, 2017
Just some suggestion on how to report these kind of things, because there is an actual underlying issue here worth fixing. It's good that you didn't mention the reverse proxy. Next, don't say "spoofing an HTTP request" in your first sentence of the report, that's an immediate red flag. If you have access to spoof something on the network, it's already not an issue for 99% of people and an instant low priority. Instead, say "Steam insecurely relies on a redirect response to upgrade the hosted content from HTTP to HTTPS, instead of directly establishing the HTTPS connection". How this can be exploited is now much more general than just being a spoofing issue, with both the problem and solution clearly stated.
Also even at the end of the current quarantine period, companies are not going to pop out and be ready to go just as they were before. The economic landscape will look like after a hurricane has hit, companies that have laid off people are not going to be in a hurry to rehire them in my opinion. Companies are in general unlikely to rehire previously reduced folks (and reduced folks are likewise unlikely to want to return to previous employers), and are instead going to look for new candidates. What we typically see after recessions is massive movements of people between the sectors. The recovery will be a long hard slog. I'd love to share your optimism, but I think the hurricane analogy is apt, even after the sun starts to shine we'll be living in the aftermath of unprecedented economic destruction.
Then explain the same thing to the factoring services, and to then to the guys that are hauling away your laptops and servers. Just cancel your service like a normal person/business, save yourself a lot of grief.
The article's comment section is full of people all saying how they're so much less stressed now, sleeping more etc. Work really is killing you! Mondays are well known to have the highest rate of heart attacks, and Saturdays the least.
Also China today is nothing like China pre-covid. Mandatory mask wearing everywhere, temperature checks every few blocks, in every shop, mobile codes to scan certifying your virus free status before being allowed to buy anything. They're not exactly planning their next Disneyland trips over there.
Zoom uses an .pkg, and have now removed the one-click install script. So every update to Zoom now runs through the same multi-step Next process as well (with one of the steps inactive until you select your disk, as is customary). If you think that isn't a problem for users, you've never walked grandma through the steps while she's trying to show her screen though the phone to you.
Users don't use your software as you would like them to. Zoom now requires ~4 clicks to update when a new version is released as you click through the installer steps. You have to click the single frickin' disk icon (which is the only disk 99.9% of Apple users are going to have... still you have click on it) in one of the steps for the Next button to activate. Result: I fully expect a large percentage of the users to never update their Zoom successfully again. Great win for the users, the software which you downloaded, then clicked to install, no longer executes that scary pre-install script.
The complexity of the infra and deployments are always relative to the size of the company, and no two companies are alike there. Small or big, it's all bespoke. Even if a few pieces are shared as open source projects, there's a veritable iceberg of complexity in the form of inhouse knowledge and tooling in each of the companies, there is nothing even close to a standard deployment system in either green field startups or FAANGs today.
Those emails which ask you to click to continue to receive marketing are a red flag that those companies did not have any legal basis previously, or they're just cargo-culting other companies even though they already have a perfectly valid basis to keep in touch (like you being a an actual customer). Check out your favorite big-company SaaS signup today (like, Jira), you will still typically not see any explicit consent checkboxes, because due to a customer relationship it is not needed.
Except... of course Pointer Events doesn't work in Safari. Safari doesn't even support the regular mouse event "buttons" property which has been in the specs forever, which is a constant source of Safari specific bugs in my experience. Nothing happens when you click? Oh, you must be using Safari!
Why is input handling such a pain in the behind!
- Lastpass or any other password manager on iPhone is a joke, requiring multiple convoluted steps and using the "share" menu in the browser because of the Apple lock-down. Lastpass on Android? Click the password field in any app or the browser, authenticate with your finger. Done.
- All the Google apps on the iPhone are of a much lower quality and behind design and feature wise. The reason I switched last time from the iPhone to Android was because I realized I don't use any of the Apple apps any longer (mail, maps, notes, music, etc.) and I use the Google apps and services exclusively because they're just so much better. And they're way better still on Android!
- Google Photos is amazing. It's hard to overstate just how good it is. And you can still plug in your phone and get your photos of the device, if you like. A recent experience of trying to backup my wife's photos from her iPhone 7 was an incredibly frustrating experience in contrast. The Apple photos desktop app is a piece of crap, somehow even slower and beachball-prone than the Apple Store app, and the backup is very confusing. Using iCloud is not a backup solution, because deleting a photo on any device still deletes it everywhere.
I think following the laws and driving calmly is a great benefit. Never once I have thought, "I'm so happy that Uber driver drove like a maniac weaving between lanes, and got me to my destination all of 4 minutes earlier. Yay".
—Dr. E. E. Peacock, Jr., University of Arizona College of Medicine;
"First 500 GB / month, $1.00". Not bad! <Looks at pricing example>. Oh... $1.00/GB :)
On the other hand, 250GB of only VPC flow logs sounds really high to me, for the "small" environment example.
Actual availability numbers is often secondary to Big Corp customers. The benefit of the CYA/SLA agreement, is that when shit does hit the fan, as the manager you get to shrug and say "well, we bought the improved SLA, not my fault Amazon failed to deliver".