1,098 karma · joined August 8, 2015
You could say that any non-register memory access "blocks" but I feel that's needlessly confusing. Normal async code doesn't "block" in any relevant sense when it accesses the heap.
An error is preferred to silently returning garbage data!
That said, the most important extension usecase is adblocking, and with Manifest v4 and FLoC/Topics and SafetyNet/remote attestation, well...
Presumably they don't use CSV to sync, they're using a saner json/etc. data structure that they're not letting us export ourselves. Seriously, being limited to CSV in this day and age...
At most I imagine the plaintiff is allowed to do discovery, and then has to prove positive discrimination based on that.
> Though manufacturers cannot so easily escape liability, sellers can escape liability by informing the customer before the purchase that a product must be taken "as-is,” which means how the product was found when it was purchased in-store. “As-is” works because the buyer has an opportunity to inspect the product and decide whether to buy it given its condition.
On that analogy, Github and RedHat aren't liable, but the original author of the software still is.
ETA: the first couple of Google results say that no, product liability can't be disclaimed away - particularly when there is no contract or opportunity for bargaining. I am very much not a lawyer but this sounds correct to me (i.e. this is what the law is).
https://www.findlaw.com/injury/product-liability/are-product...
https://www.eltonlaw.com/does-a-disclaimer-mean-you-cannot-f...
https://twitter.com/aionescu/status/1393955460517040129
> * AMD Zen "Summit Ridge" Stepping B1. That is Ryzen's 1xxx series.
> * AMD Zen2 "Matisse", "XT" series only. That is Ryzen's 3xxx series.
Other info at:
https://twitter.com/aionescu/status/1394039410300051456 https://twitter.com/aionescu/status/1394359314102427650 https://twitter.com/aionescu/status/1394359317038452738
Regardless, the vulnerability is in the driver, not the CPU / microcode. Also in the WHQL process that signed such a 'fake' driver. Until the signature is revoked, it might be possible for an attacker to manually install the signed driver on other system configurations too.
> But even better, it has a security descriptor allowing Everyone + Low IL R/W Access, and an IOCTL interface with absolutely no Probes/SEH, which yes, dereferences wild pointers. They don't even bother checking for input size or output sizes.
If that's true of the driver, then it's a sec vuln regardless of what the MSR bit does or doesn't do, no?
(Sarcastic? Who knows?)
It would be less than 3x the length, not 10x. The mountains are a problem; it could go around but would still need to dig a lot. And it doesn't seem feasible politically right now, but it could be a really cool project.
(If it was built, then a side-canal to irrigate the Dead Sea would be a relatively cheap value-add.)
And further confusing the issue, many other parents / families who are forced to stay home do know how to interact with their children productively, and those children have a much better time of it.
Instead we'd see 'ongoing' authorizations on the level of an investigation, a person or team, or a whole sub-organization (modulo clearance / position in that organization). And so you'd have copies of the complete key going around.
Note that banning E2EE implies banning encrypted p2p communications entirely. E2EE is a concept that applies only to centralized comms providers where all messages go through a server.
Practically speaking, it's impossible to ban every encrypted protocol (TLS, SSH, ...). It's also (probably) impossible to ban IP communications that don't have an "approved server" participating.
However, comms providers / social networks to date at least manage, authenticate, and introduce users at the serverside. Fully distributed projects have problems with spam. So governments would have to ban comms providers from "allowing" their clients to talk to each other directly and not via the backend. That's a hefty technological restriction, which would block a wide range of protocols (webrtc/SIP, torrents, probably a bunch of other Very Important things I'm not thinking of right now).
(I disagree with the claim that the choice of which group to vaccinate first won't strongly affect the total number of infections and deaths. But that's a different argument.)
And then, within the Ethics group, they say that the deciding ethical factor in favor of vaccinating essential workers is that they have a higher proportion of minorities and low-income families than the other groups (of high-risk and of old people).
They don't give any reasoning, so it's hard to argue with this. Unlike the Science section, which links a study that models deaths prevented by targeted vaccination. The Ethics section lists some unsupported and unquantified claims (table on slide 31) and at the same time judges which outcomes are better.
Crucially, the first line of this table says that ethically it's equally good to either "Preserve services essential to the COVID-19 response and overall functioning of society", or to "Reduce morbidity and mortality in persons with highest burden of COVID-19 hospitalization and death". Why? Based on what refutable data or model or ethical theory? Who knows.
Of course, this is a summary presentation; there may have been something behind it that they didn't refer or link to.
An upside (green) of vaccinating essential workers (non-healthcare) first: "Racial and ethnic minority groups disproportionately represented in many essential industries. ~1/4 of essential workers live in low-income families."
A downside (red) of vaccinating adults age >65 first: "Racial and ethnic minority groups under-represented among adults >65".
The next page (32) concludes that "mitigating health inequities" (what the paper calls Ethics) is the metric with the biggest difference in outcome, in favor of non-essential workers. A bigger difference in outcome than the one for "maximize benefits and minimize harms" i.e. preventing the largest amount of deaths.
Of course, the presentation doesn't define how these two different things are supposed to be compared. But its recommendation is that "Ethics" outweighs "Science" (their terms, not mine), and therefore populations with larger ethnic minority and low income representation should be vaccinated ahead of those at higher risk from the disease.
And I assume the partners also do some things differently, for at least somewhat legitimate reasons, and no one ARM design can be optimal for everyone.
Once at least one major (political) group calls views held by tens of millions of people hate speech, there is no way to avoid being in someone's black book. This is why many companies are aligning with one party - they can't have both, and it's better than none.
We can tell time inaccurately by timing somewhat regular internal biological events. That pretty much follows from the definition of time as the interval between regular events (which are assumed for physical reasons to be equally spaced). The only question is which underlying events we use and how.
All definitions and measurements of time rely on counting events that are believed to happen at regular intervals. A second was defined for most of history as 1/246060 of a solar day, in other words, measuring changes in lighting.