123 karma · joined December 18, 2017
Referring to the leadership of Heritage as "civil" is a stretch from the point of view of individuals in categories repeatedly demeaned and dehumanized by the members of the organization acting in their official capacities.
"The dose makes the poison" is not something I expect an average Google user to have modeled accurately.
Edit: after reviewing other examples in this thread, my opinion of an average Google user has fallen drastically. Was mostly having a laugh at the fact fluoride salts are generally a thing I avoid, which seems to be the intuition represented by your example.
DHT Sybil attack? Hash ring bloat? Bad peers distributing exclusively irrelevant content?
Wonder if this is a common observation, and if so, what kind of research might elucidate the underlying change.
https://web.archive.org/web/20141226094343/https://developer...
[1] https://linux-sunxi.org/Linux_mainlining_effort
[2] https://www.kickstarter.com/projects/bootlin/allwinner-vpu-s...
[3] https://twitter.com/marcan42/status/1088472549715918848
[4] https://github.com/raspberrypi/firmware/blob/master/boot/LIC...
Here with the rock64 it was just a matter of time till hardware support settled in mainline, and it seems like we're there!
DRM/monetisation - the product as of my comment didn't seem to acknowledge the open source works compiled into the binary, and I didn't think that was a good look for someone with the authority to push out malicious code.
> TabNine makes web requests only for the purposes of downloading updates and validating registration keys.
In this particular case, the use of TLS (good!) makes it relatively challenging to inspect. Assuming the author isn't shipping a cert in his binary (doesn't look like it) - I'd have to spinup a new VM, load a custom root cert, and mess with a TLS terminating proxy / forwarding solution, and hope he's not using a secondary stream cipher on top of TLS. Maybe I get lucky and https://mitmproxy.org/ or something just works out of the box. In any case, lots of effort to know he's not siphoning up all the source code on the local machine and using it to train v2 of his project. And the more robust the DRM solution, the less feasible it is to inspect.
[0] https://github.com/jwise/28c3-doctorow/blob/master/transcrip...
Also, AFAIK most understandings of MIT, BSD, and Apache 2.0 licenses require you to acknowledge the copyright holders of the source code you compile into your binary, even if the licenses permit binary distribution. I can't find your "Copyright (c) 2018 Tokio Contributors" or "Copyright (c) 2014 The Rust Project Developers" that I'd expect based on `strings TabNine | grep github`. Maybe you've got a lawyer that suggests otherwise? Your plea of "trust me, I have good hygiene" carries less weight when I have to `strings` your stuff to know what shoulders of which giants you're standing on.
So, give your proprietary software both network access and access to all my source code?
I have very few complaints about the Jedi autocomplete library, which is neither proprietary nor requires network access.
I welcome innovation in dev tools, but I wish you had found a monetization strategy that didn't require us to trust you so completely.
Please do some research! This is blatantly false. Combustion is not involved in vaping, and boiling is not a chemical reaction!
It's very easy to find peer reviewed medical studies showing vape compounds are considerably healthier than cigarette smoke.
30 sec of googling shows https://doi.org/10.3390/ijerph10105146 amongst the relevant docs.
In any case, hat-tip for empiricism! Very pro composting, wish it was safer, smaller, and easier to do at home.
Don't rule out feathered friends - there's a continuum of intelligence and dependency ranging from finches (simple lil robots, a'la fish) to African Grays (3yo intelligence as discussed) - I've found my 'tiel to be in the sweet spot - intelligent enough to have his favorite people, not so smart as to constantly demand attention.
We've seen several classified documents claiming (pick a three letter USG agency) have minimal operational ability to deanonymize a particular Tor user, and even less-so in real-time.
Fortunately, the FBI has proven it doesn't need to break Tor to interfere with the most egregious of the malactors who call it home. They've hijacked servers hosting objectionable content and used them to deliver Firefox exploits to leak real IP addresses.[1] They've done "good old fashioned police work" and exploited human trust [2] to bring down well coordinated teams of international players.
[1] https://www.eff.org/deeplinks/2016/09/playpen-story-fbis-unp... [2] https://www.wired.com/story/alphabay-takedown-dark-web-chaos...
Good old Yasha! If you've been paying attention to his works, you'll be underwhelmed by this particular post. He repeats his claims, many of which are easily verifiable and simultaneously without significance. Yes, Tor updates fiscal sponsors with regards to project status.
Yes, Tor is USG funded. No, it's not a Honeypot. It's also not a panacea.
As a technical project based in Cambridge, MA, Tor doesn't exist in a political vacuum.
If Tor was more of a pain to the USG than a benefit, it likely would not have been able to grow to the extent it has, but this by no means is indicative of a comprehensive system failure or any significant subterfuge on the part of Tor developers. I do not believe Yasha or anyone else has evidence to the contrary.
To be clear, I dislike Yasha as a self-aggrandizing spinlord shipping a conspiracy theory laden set of tenuous hypothesis, but I've gone out of my way to read the documents he's released to date
Can you provide peer reviewed papers making claims comparable to the sources you provided?
[1] https://www.vox.com/platform/amp/science-and-health/2017/7/2...
He and I discussed them a bit on Twitter: https://twitter.com/itdaniher/status/961307347950940161
I was not impressed by his response.
The "bunch of emails" seemed remarkably banal. I've written similar emails about sponsored open-source work myself.
edit:
email stack 1: https://www.documentcloud.org/documents/4367176-Tor-BBG-corr...
email stack 2: https://www.documentcloud.org/documents/4367193-Tor-BBG-corr...
One of the concepts a related project explored was using live / persistent USB disks to preserve student ownership and facilitate unscheduled explorations.
Multiplexes hardware across students at different times, facilitating students using a consistent environment at home on old P4 desktops and at school on whatever's available.
Even large (32+GB) portable storage devices are available under $50.
Check out "sugar on a stick" and "open1to1" for related trains of thought.
There's mainline kernel support in 4.14, but I'm unclear as to whether it supports USB3, which, behind the price point and the 4GB of RAM, is the main draw.
I only run the device headless, so I can't speak to the behavior or interactions associated with the graphics engine.