[1]: https://info.arxiv.org/help/withdraw.html#:~:text=Previous%2...
[2]: https://economics.mit.edu/news/assuring-accurate-research-re...
224 karma · joined February 7, 2021
[1]: https://info.arxiv.org/help/withdraw.html#:~:text=Previous%2...
[2]: https://economics.mit.edu/news/assuring-accurate-research-re...
Note that Twitch limits stream quality in certain country. For example, in South Korea, content is transcoded to 720p or lower. [1]
[1] https://www.thegamer.com/twitch-korea-limiting-stream-qualit...
Or: they provide .pkg file to install similar program.
Most of them want sudo. They use root permission for various purpose, but the most impressive one for me was registering their CA certificate on Firefox root store, to support WebSocket over TLS to localhost on Firefox.
The problem came from U.S. cryptography export regulation which makes exportable cryptographic algorithm feasible to crack. Bundled Internet Explorer didn't support good algorithms on SSL.
So, South Korea government wanted to add another security layer. They wanted to state "good to go" algorithm (just like FIPS did), so they built and recommended the encryption algorithm, SEED. And it required ActiveX, because 128 bits cryptography on JavaScript was infeasible then.
The real problem of South Korea is, the slowness of deprecation.
They deprecated ActiveX (and created NPAPI or WebSocket on localhost) in 2014. After Microsoft deprecated Windows XP, they established "Windows XP Task Forse" to respond security issues with Windows XP computers on government agencies. Yeah, this was fairly late, considering MS declared the Windows XP deprecation schedule in 2007.
IE/ActiveX/Java Applet/etc algorithms aren't still completely deprecated in Korea. NEIS, a giantic service used by every K-12 school to record and manage education-related information, still uses the technology based on Internet Explorer by using IE compatibility mode of MS Edge. Repeat, EVERY K-12 school teacher and staff uses this service, with IE compatibility mode.
I want South Korea to adapt new technology and deprecate old one more in due course. I mean, they should accept TLS provides decent end-to-end encrpytion, and they should recognize Triple DES is deemed unsafe algorithm.
A LOT of Korean citizens cared and got angry with this issue. So governments, agencies, and. yeah, "security companies", finally decided/declared to deprecate ActiveX-fu softwares and follow Web Standard.
We didn't expect WebSocket on localhost.
This is not a tradeoff between just privacy and child safety. This is the matter of freedom and democracy.
[1]: I would say Telegram is available option for privacy but Telegram has pretty much possibility to be attacked than Signal...
We teach kids "you should not steal" but not "you should not launch DDoS." I think the latter should be equally educated.
[1]: https://github.com/gchq/CyberChef/commit/c423de545fd0d27aabe...
Remember event-stream[1]? Did we learned something from that? Yes, we might. So was it improved? Never. People are still installing 'new' colors package and wondering why its texts are broken.
What if he uploaded malicious code rather than just just gibberish? What if he uploaded on only npm and not on GitHub? Would we even notice that?
0. This has XSS vulnerability. If attacker writes down this memo: <script>do_the_evil_things()</script> and passes to people, they might be unknowingly attacked(get tracked by attacker their IP/Browser fingerprint, mine cryptocurrencies for attacker, etc...)
1. This basically works under server-side encryption. When user type their text in the website, it is encrypted with the secret key on your config file and saved on the database. This is only effective when attacker only succeeds to crack the database. Also, you can read the text. I know you won't, but you know, cryptographers don't trust anyone. If you want to mitigate this, you might want to learn about end-to-end encryption. In short: the hash of the private link is the secret key. The browser randomly generate the key and encrypt/decrypt the text. The server only receives/saves the ciphertext.
2. AES-256-CBC is unsafe because it provides confidentiallity and not authenticity.[1] This means the attacker who can only crack the database can edit the ciphertext to pseudo-arbitrary plaintext under certain circumstance without knowing of the key. Also under another circumstance, attacker can use 'Padding oracle attack' to recover the ciphertext. it seems your service is not in this case: Laravel's encryption is AES-256-CBC + MAC, which mitigates this problem. So this is safe, but next time, if you write some crypto-related things without Laravel, you'd better use some high-level library such as libsodium or sjcl.
3. This service uses CloudFlare. Using CloudFlare might be safe on small project because they have rock solid WAF to prevent general attacks. But it may be unsafe for a whistleblower from NSA: when it matters with state-sponsered attackers or law enforcements, CloudFlare can be attacked/warranted. Then it becomes another attack vector.
Again, your service and idea are cool. But you should remember that this area is full of land mines, dragons, and dinosaurs with laser guns.
Welcome to privacy/crypto world!
[1]: https://arxumpathsecurity.com/blog/2019/10/16/cbc-mode-is-ma...
[1]: (korean) https://m.hani.co.kr/arti/society/labor/1008768.html#cb
https://scribe.rip/chernobyls-blown-up-reactor-4-just-woke-u...
[1]: https://github.com/apache/spamassassin/blob/trunk/rulesrc/sa...
It's formatted like <first name>.<last name>. I love it.
The reason why the birth rate strangely low, is quite interwoven. TL;DR: People (think they) are not capable enough to raise a child.
First: Real estate prices is skyrocketing. This bizarre phenomenon began in the 2000s. The 17th administration completely reversed the situation, which became another problem, and the 18th administration made real estate prices to soar again. The 19th (present) administration tried to control real estate prices with complicated regulation, but it never worked so far.
Second: An educational craze. 386(1960s) and X(1970s) generations believe that children should go to the prestige university to survive in this harsh world. So they let their children go to 'hagwon'[1], something like cram school but really competitive. E.g. (a) Almost students in SK go to hagwon. (b) Some 6th~9th grade students study 10AM~10PM everyday in hagwon during the vacation, to pass an enterance exam specialized high school(10th~12th grade). (c) Some kindergartens promotes themselves as "English Kindergarten"; where every teacher and student speaks English. The problem is -- because of these craze, a lot of childless family concern that they can't afford expenses for hagwon($300~400/mo in average. In the case of the above-mentioned entrance exam, It goes more than $1000/mo) so their child won't be happy because they'll fall behind when they grow up.
Third: Saving for retirement. Because of these problem, rearing child in Korea costs an arm and a leg. In the past, education was not overheated like this, and Korean-specific mindset forced family to give birth. However, starting with military administration's birth control policy, people changed their mindset, and now a significant number of people are more interested in saving for retirement than give birth.
Quick test: https://s3.us-east-2.wasabisys.com/static.wiki/en.db
https://news.ycombinator.com/item?id=25426662 (Most comments; 11 comments)
https://news.ycombinator.com/item?id=25417067 (3 comments)
https://news.ycombinator.com/item?id=25546867 (Most recent; 89 days ago)
> turf.unkinkPolygon=(x)=>x;
Press F12, click 'Console', copy-paste the above one and press Enter.
Notion advertises itself as 'All-in-one Workspace'... But I don't want to leave everything to unstable 'All-in-one Workspace'.