It seems wild to me that Twitch doesn't sanitize the messages on their backend. I'm sure that they sanitize them on their own UI. But considering how many people also consume messages via their API, they should also sanitize for them, defense in depth and all.
Yeah, I don't like it when languages use too many symbols for things. It's a hard line as I don't like languages where everything is a keyword (e.g. begin end vs { }), but not enough keywords and it's hard to learn and remember the language.
It's crazy to me that there's no screenshots on the blog post. And when you click through to download it there's a bunch of aspirational pictures, but only one short clip showing what it actually looks like. Why? Is it too hard to show a screenshot?
As a non Python dev this seems like very surprising behavior for a system library to be modified by just having a file with a specific name in the same folder.
Except that's a very different threat than with Credit cards. Sure Google could do that, but Europe could even just make their own android fork if they wanted and that would be far easier than replacing the whole credit card system.
And I doubt they would even need to fork Android, they could side load, or just make their own app store and require it to be installed on phones sold in the EU.
I think it really depends on how much control you have over what you're deploying. In one school regularly restarting something with a memory leak that you can't fix is the correct solution.
On the other hand that's just putting a bandaid on the real issue, and if you can you should just fix the memory leak instead of just covering it up. There's also short vs long term solutions to consider. But saying there's a one size fits all solution is kinda silly.
I'd say the problem is that delete usually has a popup. Sure you don't really want to delete without any kind of confirmation, way too many people would click something on accident and if there's not a way to undo it (which has it's own issues), then a popup is a simple solution, but it does result in this unfortunate behavior.
That is only really possible if the window is full screen. By that logic it feels like if the user changes the window size you would want the div to stay in the center even then.
When I tried it, I kept trying to login with some accounts via OAUTH and they all said to only accept logins from their official tool, which makes me think using this with on of my subscriptions will get me banned.