I can see why people were tempted to cut corners, especially given past tolerance…
1,125 karma · joined June 15, 2012
I can see why people were tempted to cut corners, especially given past tolerance…
It’s easy to make Apple budge because they have money ties to the Uk.
This works less well for unsavory websites not complying with UK law. See https://prestonbyrne.com/2025/10/16/the-ofcom-files/
The problem is that in practice, if you can't do YouTube, Facebook, Tiktok, INsta, etc... your speech will not be heard by anyone. It's like if a tree falls in the forest and nobody is there to hear it, the fact that it makes sound is irrelevant. So effectively, it amounts to censorship, even though the government potentially had no hand in it.
Now imagine someone in Trump administration pressured Google with a juicy contract, or the prospect of an expensive lawsuit, and the quid pro quo was dumping these videos that annoy "our Israeli friends". This kind of "pay to play" is at minimum corruption. It may also fall of short of constitutional guarantees for free speech. Ironically, it is exactly the same thing a lot of members of the Trump administration have accused Biden of doing (exhibit: the so called "Twitter Files" etc... ), although I don't believe this went anywhere in federal courts (am I wrong?)
I honestly don't know what the answer is. But I would not be surprised if in 50 years time, some of these large companies get regulated as "utilities" and are no longer able to yank "videos" from their platform just because they feel like it. And every time they "abuse" their powers, I feel like we get an inch closer to that onerous regulation.
Genocide in Gaza. It is described as a "genocidal campaign" implying systematic targeting of a national, ethnic, or religious group, prohibited under the 1948 Genocide Convention. This is what the ICC is investigating now.
War Crimes:
- Killing of Palestinian civilians, including children and families.
- Killing of journalist Shireen Abu Akleh, a violation of the Geneva Conventions protecting civilians and journalists in conflict zones.
- Destruction of Palestinian homes in the occupied West Bank, possibly constituting collective punishment or unlawful destruction of property under the Fourth Geneva Convention.
- Intentionally starving civilians by blocking humanitarian aid into Gaza, explicitly prohibited under Article 54 of Additional Protocol I to the Geneva Conventions and cited in ICC arrest warrants for Israeli officials.
- Torture of Palestinian detainees by Israeli forces, a violation of the UN Convention Against Torture.
The article also alleges complicity from the US authorities and corporations (YouTube, Google, MailChimp).
Somehow we expect the digital world to be devoid of risks.
Cryptography that only the good guys can crack is another example of this mindset.
Now I’m not saying ClosedAI look good on this, their safety layer clearly failed and the sycophantic BS did not help.
But I reckon this kind of failure more will always exist in LLMs. Society will have to learn this just like we learned cars are dangerous.
Is it due to MinGw maybe?
I just use ublock Origin with Firefox on Mac/Pc and Orion on iOS.
The annoyance list takes care of the cookie banners.
Is this not a problem? It’s not a good idea to reuse the same key to encrypt very similar files. Similar to ECB. See the famous penguin https://words.filippo.io/the-ecb-penguin/
I’m surprised they don’t use something like XTS commonly used for disk encryption. It derives a unique key for each block/frame and allow you to access each individual blocks/frames non sequentially.
Sure monads are cool and I’d be tempted to use them. They make it impossible for forget to check for errors and if you don’t care you can panic.
But JS is not Rust. And the default is obviously to use exceptions.
You’ll have to rewrap every API under the moon. So for Monads in JS to make sense you need a lot of weird code that’s awkward to write with exceptions to justify the costs.
I’m not sure the example of doing a retry in the API is “enough” to justify the cost. Also in the example, I’m not sure you should retry. Retries can be dangerous especially if you pile them on top of other retries: https://devblogs.microsoft.com/oldnewthing/20051107-20/?p=33...
RIPA notices do indeed assume you’re in possession of the keys of anything encrypted and you must disclose when asked nicely.
You just need an airtight provable way of showing you have a way to destroy that key when you push a button and do that before the notice arrive. I suspect that’s after they seize your stuff.
But I can’t imagine this tool in the hands of someone who does not have a solid understanding of programming.
You need to understand when to push back and why. It’s like doing mini code reviews all the time. LLMs are very convincing and will happily generate garbage with the utmost authority.
Don’t trust and absolutely verify.
They can ask ISPs to do the censorship if they really want to keep us “safe”.
In the mean time, if I wanted 30 seconds clips of cat videos I’m sure I could use a VPN. Let’s ban it. Teach people censorship is utter BS like every Chinese person knows by now. Sadly my attention span is slightly longer than 30s so I’m not even gonna bother
But honestly I’d stay away from PBDKF2 at this stage. If you look at OWASP they recommend 600k rounds. That number is getting bigger and bigger all the time (10k rounds used to be enough over a decade ago)
https://cheatsheetseries.owasp.org/cheatsheets/Password_Stor...
I would use Argon or scrypt (which is basically PBKDF2 in a loop with some weird mixes) instead.
In this case, the only thing encrypted with TripleDES is the password itself, so the practicality of a crib or other known plaintext attacks is debatable in my opinion.
If you use the same (or similar) password everywhere, then you have bigger worries than Firefox use of TripleDES. Password stuffing based with leaks from poorly hashed password DB (cough facebook cough) is likely the most practical attack vector in this case.
If all your passwords are like q@qrG#Z4ARYm^qjeTEMN2Kh45v^p7L# then crib like attacks are impractical.
There are other weird/debatable choices in the Firefox encryption layer:
- Why bother with CBC? Things like AES-GCM or other authenticated* encryption mode would be nicer. Not sure it's a flaw here (google the cryptographic doom principle of Moxie Marlinspike)
- Why not wrap the encryption keys with some kind of "key wrap" mode instead. There are such things as AES-KV for instance.
- Why do the weird PBDKF2 derivation here? It's not based on a password the player enters, so there's nothing to "strengthen"? Seems oddly unnecessary (or I don't understand and there's a password somewhere).
- If there's a password then PBKDF2 is really really shit compared to scrypt or even better one the variant of argon OWASP said you should use.
If you glance at the code there's a single "key encryption key" in the whole SQLITE file (in the 'metadata' table). That key is decrypted using AES with the PBKDF2 derived secret.
Then each password is in turn encrypted using TripleDES. The "data encryption key" for each these records is in turn encrypted using the aforementioned "key encryption key".
My suspicion is that the TripleDES format must be really old, and when they migrated the crypto layer to use AES they just re-encrypted the top layer (the "key encryption key" later) to use AES. It's much faster (and safer) to just re-encrypt all the TripleDES keys with the new AES than go and mess with "all" the records in the database. It's inelegant and lazy but you effectively get "AES level" of security without having to do all the work, so to speak…
https://github.com/Sohimaster/Firefox-Passwords-Decryptor/bl...
So I get it Etcher for someone who wants to do it on a USB stick is probably as easy if not easier than using cat or dd. I reckon I can probably create the ISO file with Etcher too. But I’ve installed countless distros and never had to download Etcher since I could always point the virtual CD to an ISO file.
Bonus point. I don’t need to learn anything about file systems and partitions and block sizes… it just works. I have no idea how these bootable medias work since I never had to make one.
The same people who do the bare minimum for tests not to explode. But won’t add a new test case for the new branches they just introduced.
The same people who will mangle the code base introducing bizarre dependencies or copy paste the same piece of code rather than refactor.
People who fail to handle errors correctly. My favorite: by wrapping code in a if statement without an else. (else? Get a weird error without logs! Miles away from the call site!)
People who don’t validate inputs.
People who don’t give a monkey about adding context to errors making the thing impossible to debug in prod when they explode.
People who are too lazy or in incompetent to do their job properly and will always jump at the opportunity to save 5 minutes now but waste 5 hours of everybody else’s time later. Because of course these people can’t fix their own bugs!
And of course these are the people who make comments go out of date. I’ve seen them implement a thing literally the line below a TODO or FIXME comment and not delete the line.
Comments going out of date is a shit excuse for not writing comments as far as I’m concerned.
The fact that some people are incompetent should not drive engineering decisions. You should always assume a minimal level of competency.
This would probably be classified as a terrorist attack and frankly it’s just a matter of time until we get one some day. A small dedicated team could pull it off. It’s just so happens that the people with the skills currently either opt for cyber criminality (crypto lockers and such), work for a state actor (think Stuxnet) or play defense in a cyber security firm.
What is it they saved here? Could they not fab this in a less populated area and just follow a few more regulations. We’re not talking about a company with razor thin margins. They spent outrageous amounts of money building the spaceship HQ.
I genuinely want to understand if this is stupidity or if there’s really a profit incentive that makes “fiduciary” sense.