604 karma · joined December 29, 2024
If one is concerned with this sort of scenario, this talk about corporations and regulations is really short sighted.
You might say it's naive, but is it really naive to buy a TV and expect it to be a device to display audiovisual content and not a spyware/adware machine?
I feel like it's not the user's behavior that should be put into question here, but the borderline criminal behavior of the manufacturer.
Surely it's online? Such magazine still being in issue would be equally surprising to me.
Consolidation alone is insufficient to explain such a gap under the assumption of profitability.
Someone shared the code in the comments, it uses 'copy' and 'cut' event listeners, so disabling this setting would have prevented the exploit regardless of an adblock.
[2] https://ourworldindata.org/grapher/primary-energy-source-bar...
It's good for security, it's more convenient than police doing police work.
Until it's not. Until it's hacked or abused as powerful mechanisms commonly are.
It's simple sandboxing based solely on unix file permissions. Albeit weak, I find the isolation sufficient. Until I'm shown otherwise it seems like a good compromise given how easy it is.
You can also create iptables rules matching on the user, so this technique is useful for applications where you want to restrict network traffic as well, and don't need stronger or more fine-grained isolation mechanisms.
- Strip links, script tags, etc - Apply the same filters used in user comments - Add a warning indicating user-generated content may be present
The post suggests the UX is problematic in that it allows user-generated links to pass as YouTube generated content. I'm not familiar with Creator Studio to know if this is the case, but if so, simple changes can go a long way.
In the real world, reliance on syntax autocomplete and checks was never an issue. The important thing has always been understanding the core concepts of the language and the runtime, e.g. how the event loop works with Node.js and how to write asynchronous and event driven programs.
This problem has long been solved with federated IdPs and MFA - something you own like OTP device/physical token besides something you know like SSN/tax id/password.
Most governments prefer biometrics of course because citizen privacy is the opposite of what they want.