687 karma · joined February 1, 2016
[1]: https://en.wikipedia.org/wiki/High-bandwidth_Digital_Content...
[2}: https://en.wikipedia.org/wiki/High-bandwidth_Digital_Content...
[3]: https://en.wikipedia.org/wiki/High-bandwidth_Digital_Content...
Until that culture is fixed/adjusted, having a scoring mechanism that is easy enough for manager/executive type people to easily understand risk without any technical knowledge is important. Way easier to argue for an emergency patch/downtime that could cost money when there is a big scary 9 associated with it. And so if the scoring is off and not accurately representing risk, let's work to improve those scores, rather than getting rid of them.
Plus, there is a reason environmental scores exist in the CVSS mechanizm, as it allows for folks to adjust the CVE number to better fit their environment and specifications. I'd personally rather see more CVEs appear and be tracked quickly for easier referencing and discussing, with a slightly adjusted formula to better reflect severity.
The nature of the url being "projectobs" instead of "obsproject" is concerning, and while there appears to be no download links hosted on the site, just redirects to GitHub's downloads, this looks concerningly like one of those SEO spam pages. Further research shows that it likely isn't the case at the moment, just a means to slap ads onto the official wiki docs: https://github.com/obsproject/obs-studio/issues/2565. Still concerning none-the-less.
[1]: https://arstechnica.com/gaming/2021/11/faulty-drm-breaks-doz...
> "The reason this matters so much is that the maximum size of an unsigned UDP packet is typically 512 octets. DNSSEC requires support for at least 1220 octets long messages over UDP, but above that limit, the client may need to upgrade to DNS over TCP. A good practice is to keep enough headroom in order to keep response sizes below fragmentation threshold during zone signing key rollover periods."
This is the reason I don't trust snaps, as I have 0 way of auditing it. I know that there is a "verified" mechanism in snapcraft, but not all apps that are "official" or "trusted" have that tag, such as MusicBrainz Picard, published by the MusicBrainz team, so the only way I know they support it is going back to the official website, which also offers a more conventional PPA that is also easier to audit and trust given the GPG key processes in place there, which _should_ be a bit more trustworthy.
And this theoretical attack on home routers is not out of the question at all. How many unmaintained unpatched IoT devices have been abused with malware/botnets. The clock is ticking on mass exploitation of home routers being attacked and it's firmware replaced with one injecting/stealing information from insecure webpages. If the devices can't be updated, we should make sure there are _safe_ alternatives to accessing the information, rather than hoping that no actor is doing things they should not.
I can list so many scenarios with critical information and attacks that could be made if the webpage was not HTTPS with proper certificates. Including school districts in the United States being force to block inappropriate content in order to receive federal funding, and those firewalls abusing non-http content to decide what to block, and school districts abusing that capability to block anything and everything they want. How about a student trying to understand more about LGBTQ+ individuals and the school district inspecting and censoring the exact content inside the pages to remove words like "lesbian" or "gay" because the school considers them "questionable." Or a school blocking articles pertaining to hacking. I have seen that exact last scenario in fact, where certain articles posted here were blocked in my highschool years ago because they were considered hacking and that was apparently not appropriate to view in school. These are real scenarios and not hypotheticals.
For more info on some other various types of fun attacks, see https://www.troyhunt.com/heres-why-your-static-website-needs...
Isn't that a valid use of the non-profit status? That as long as the funding from donations was going towards that expansion only, it can still be considered a non-profit? Looking at the quick Wikipedia definition, that seems to be the case, if you consider Locast's mission is to provide retransmission of OTA broadcasts to all people in the US.
> "A second misconception is that nonprofit organizations may not make a profit. Although the goal of nonprofits isn't specifically to maximize profits, they still have to operate as a fiscally responsible business. They must manage their income (both grants and donations and income from services) and expenses so as to remain a fiscally viable entity. Nonprofits have the responsibility of focusing on being professional, financially responsible, replacing self-interest and profit motive with mission motive." [1]
PBS is also a non-profit, but PBS does something similar in that certain content is locked behind their "PBS Passport" subscription. If this ruling that requiring donations view without interruption, then PBS is also violating non-profit status based on your statement regarding "Locast chose not to operate like a non-profit." But Locast attempted to resolve that and remove the interruptions entirely, but was still required to completely shutdown and was given 0 chance to adjust... My understanding about hte reasoning for shutting down is that using collected funds, via any means, expansion across the US isn't allowed for some questionable reason under the section of the law Locast was using.
[1]: https://en.wikipedia.org/wiki/Nonprofit_organization#Managem...
But the big part of the ruling was that it wasn't just how they requested funding, but the why. The ruling argued that collecting funds to expand more throughout the US was not valid for their non-profit status for some reason that made no sense. And as a result, it appears that a replacement will never exist, because the cost of pulling all of these channels with careful and specific antenna placement in a city, the hardware to pull all of those channels in real time, re-encoding the feed from MPEG2 to HLS/MP4 for the web, potentially making different qualities to account for network conditions (can't remember if the M3U8 playlists from Locast did that or not), and the networking costs of transmitting video are expensive.
And the lawsuit was stupid too. US TV channels are crammed to the max with advertisements, so much so that it feels more like an ad delivery mechanism than an entertainment delivery system. Locast could have been advantageous as they would have actual data of who is watching what when and where. Ad companies love that data, and with traditional OTA feeds, they don't have that. Instead, all of these OTA companies actively refuse offering the ability to watch their streams online for free. Other than local news content, everything else is locked behind a paywall of having an active cable subscription. Why should I, as a consumer, pay $100 a month to watch this same OTA content, just so I can watch it online, especially for a medium so jam packed with ads?
I live in the edge of Columbus, Ohio in an apartment. I'm still within 10 miles of the transmitters for the big 6 stations (the local affiliates of ABC, NBC, CBS, FOX, CW, and PBS collectively only use 4 transmitters.). My apartment is luckily facing sort of line of site to most of those transmitters. But even then, I still have bad signal issues with those channels, and in some cases leading to an unwatchable recording. The signal was bad enough that my recording of the 2020 Tokyo Olympic Opening Ceremonies was bared by loss of 2 to 5 seconds of video and audio every 2 minutes. My only alternative was to play $65 to $100 a month to cable or cordcutting subscription to watch that broadcast online. And out of spite for continuing to shutdown any free way to watch their OTA content online, I will _never_ pay. Our laws regarding OTA broadcasts and how people can use and view them need to change ASAP, otherwise what is the point of having them if is not accessible to all.
For a good discussion into why _all_ websites should use HTTPS, and the many different ways that not having the connection secured is actively harmful and why should not be done in the modern era.
https://www.troyhunt.com/heres-why-your-static-website-needs...
Not having your site as HTTPS puts all of your website visitors at risk. Even US ISPs like that of Comcast use these very same practices to inject warnings into insecure web traffic[0], some of which look more like advertisements than warnings. And like mentioned in the article, promises from ISPs not to use it for advertisements are just that, promises, and those can be broken in an instant. And when you have the power to inject anything without notice, you can do anything and everything with the website experience. You can attempt to force a download, present scam pages that look like antivirus warnings or software updates, one of the easiest ways to have users fall for malware.
We should _never_ expect regular non-technical users to have all of their threat models in mind, nor should they be expected to understand all of these differences. Website owners should be expected to protect all of their visitors as best as possible and one of the easiest ways to start is by protecting their website with modern HTTPS encryption. Otherwise, it would be like a chef leaving the bones in a salmon before serving to a customer. You could do leave them in, but a customer might not know they are there and you have left a choking hazard.
[0]: https://gizmodo.com/comcast-to-customer-who-noticed-it-secre...
https://www.troyhunt.com/heres-why-your-static-website-needs...
Not having your site as HTTPS puts all of your readers at risk. Even US ISPs like that of Comcast use this very same practice to inject warnings into insecure web traffic[0]. And like mentioned in the article, promises from ISPs not to use it for advertisements are just that, promises, and those can be broken in an instant.
[0]: https://gizmodo.com/comcast-to-customer-who-noticed-it-secre...
> "[...] and you can't withhold functionality or content or make your app unusable until people allow you to track them."
Per that reading, it would seem like the MLB and NFL apps would be banned from requiring location access before the live streams are playable, which could finally progress some of these insanely stupid TV blackout rules once and for all... Though, unless Apple will also apply this to IP based geofencing, there would still be a long way to go before TV blackout rules are gone from streaming services....
Poll worker validates proper ID, get ballot code for your precinct, walk to voting system, poll worker enters the precinct, voter validates info on screen, voter votes on the touch screen, system prints out choices, walk to scanner system, vote gets scanned, scanner stores those ballots in it's tray in case need for audit.
[0]: https://twitter.com/brockgs/status/1330711644977053696
[1]: https://raw.githubusercontent.com/ESWAT/john-carmack-plan-ar...
https://www.buzzfeednews.com/article/laurenstrapagiel/north-...