https://blog.dantup.com/2016/06/dachip8js-my-csharp-chip8-in...
738 karma · joined August 8, 2011
https://blog.dantup.com/2016/06/dachip8js-my-csharp-chip8-in...
https://en.wikipedia.org/wiki/DNS_hijacking
The new Google "did you mean to go to ?" nonsense is something else to add to that link!
My ISP (TalkTalk) claims to have an opt-out page but the forums suggest it's been broken for years, and today it is a 404. I have an open issue with the CEOs office to opt me out manually but they've been pretty useless so far.
I did see someone from Google ask if it'd be useful if after the first time, when Google knows it's a valid domain, it should just go there directly (even without the slash). Everyone said yes, but it doesn't seem like it was ever implemented!
Eg. if I type "cheese", it shows "Did you mean to go to http://cheese/"? If I click that link I get TalkTalk's "Error Replacement Service" full of ads (or at least I did, till I switched to Google DNS because TalkTalk's "opt-out" system has been conveniently broken for years)!
They could have that £1.50 back if they could give me an explanation! =)
(In the UK, all prices shown in the menus are inclusive of VAT and then the total on the bill shows how much of the total is the VAT, so both the amount you can add up yourself from the menu and the line items shown on the bill should match the total you're paying perfectly).
The bill was totally itemised, the total just wasn't the sum of all the numbers above it. I really wish I'd taken a picture of it now (I didn't really expect them to take it off me, I really expected them to explain that I was being a doofus) :(
I totalled the numbers up again and the total was exactly £1.50 less than the total shown on the bill! My wife (having no faith in my basic adding skills) pulled out her phone telling me "don't be silly" and added them up to get the same result as I had.
We asked the waiter about it, who disappeared off to get his own calculator.. He added things up, looked confused and then took it off to the manager. She then repeated the process on the calculator and also looked confused, unable to explain what had happened. They gave us £1.50 in cash, apologised and then kept the receipt (I guess they didn't want us posting that on twitter!).
To this day I've no idea what happened. You could suggest that some programmer somewhere is getting rich off this, but it seems rather unlikely to me. I'd really love to know what the cause was (and whether the manager ever reported it further up the chain; because this seems like a rather serious error to me.. how often does it happen? is it always £1.50? did the issue get found/fixed?).
There is a big difference between a multi-billion dollar company that has a reputation, shareholders etc. and a completely random person (who could literally be anyone with any motives). You can't go to Facebook and give them an envelope of cash for keys to access other peoples Facebook accounts whereas some random guy is much more likely to be open to this.
Security online is already shit and people freely handing out access to their online accounts is not making things better. There's need to breach servers anymore, you just create a "fun" browser extension with god permissions that auto-updates and then after a few weeks just start harvesting usernames, passwords, card details, instant messages and emails... :/
Why would you trust your Facebook account (or any other account) to a random stranger on the internet you've never met, heard of, or even seen? Whose real name you probably don't even know?
So, even if you're not connecting logged-out users, it seems to me that you might be connecting different logged-in users accounts.
I don't mind; I'd rather have targeted ads than not; though it does seem a bit creepy and often it's useless - I'm sick of seeing ads for stuff I already bought; you're losing cash there!
That said, with OAuth so common and used by Google a lot (and such a risk to get wrong) I'm surprised there isn't a Dart Team-owned package for this. I'd be much more confident using something from a company with a reputation to protect and a good dev/QA process.
I feel like I spend half of my life at work investigating or working around bugs in dependencies added by past developers, patching abandoned libraries, fixing conflicting dependencies dependencies version constraints or just working around incompatibilities between their goals and ours (both of which may have changed since the dependencies were added).
I also think we generally don't think hard enough before taking dependencies on from complete strangers. With Dart this isn't quite so bad because the source is all there and you can scan through it but in C# people just pull binary dependencies and assume they're safe. I don't think this is good practice and I think it's only a matter of time before some relatively popular package ends up with obfuscated malware in the binary in the package (but not the repo) and everyone will get upset :-(
--
I just actually took a look at the Dart twitter pub package. It has a bunch of TODOs on the homepage and the pubspec shows a dependency on a Git repo by the same author for OAuth using the "random-secure" branch. Not only is this repo full of stuff I don't need (like Shelf extensions to do OAuth flow I don't want) but the Git dependency means I have no control over the version of that that gets pulled (and the name of the branch doesn't fill me with confidence). Sure, if I used it it would probably work; but for the little code it took I'd rather eliminate a huge set of possible future complications of that author starts making changes in that Git repo.
I know some will refer to this as NIH and I'm ok with that. I'd rather spend a little more time now and save time later, and in my experience taking random deps (esp. from small unknown devs) always results in pain down the line. I don't claim this is the best/correct way, it's just what feels best to me based on my experiences :-)
https://blog.dantup.com/2017/01/visiting-a-site-that-uses-di...
For some things, this is true. However you can be sure an entity like Microsoft or Google isn't going to accept a few thousand quid to inject ads or affiliate links into customers websites. A one-man-band that's struggling to turn a profit though, it's less certain. There are a lot of people trying to make a quick buck online and most people have a price.
There are definitely some great things out there being built by small teams that I might miss out on, but that's how it is unless we can tightly control what third party scripts can do on our pages. Sometimes a service will be "so good" that I'll do it anyway, but it's always a trade-off. I don't think most people are as anal about this as me though!
I don't mind included scripts on my page from huge orgs that have a lot to lose by doing bad things but there aren't that many companies that fall into this (Disqus did, but possible shouldn't ;))
That's a bit harsh - wanting to know whether you get 0 visitors to your blog post or 2,000 yesterday isn't just about ego; it helps you understand the value of your posts (and whether you should bother). Knowing how many people visited isn't the same as bragging about it.
Given the option, I would probably also just parse logs - I don't think Analytics is adding much on top of that; I just don't have that option using GH Pages. The reason I moved from AppEngine to GitHub was to stop messing with the code for my blog in an attempt to make me write more posts instead! =D
2. Yeah, it's not ideal. In this case, it looks like Disqus are gonna fix stuff though (they've commented on my post; there's a link right at the top of the article now).
3. I don't have access to the server logs as I'm running on GitHub Pages, so something like Analytics is all I have. I do find it useful (given no server logs), it's nice to see the traffic to my blog; there's no point posting if nobody is reading! :-)