72 karma · joined May 14, 2012
"In this cohort, the risk of MS increased 32-fold after infection with EBV but was unchanged after infection with other viruses."
The "Tweets & replies" section of your profile (https://twitter.com/eggsome/with_replies ) has two tweets that seem to match your description:
> we are currently planning to change the rule limit from maximum of 30k rules per extension to a global maximum of 150k rules.
(https://blog.chromium.org/2019/06/web-request-and-declarativ...)
(https://blog.chromium.org/2019/06/web-request-and-declarativ...)
> Hey all, I'm Simeon, the developer advocate for Chrome extensions. This morning I heard from the review team; they've approved the current draft so next publish should go through. Unfortunately it's the weekend, so most folks are out, but I'm planning to follow up with u/gorhill4 with more details once I have them.
https://www.i-dont-care-about-cookies.eu/
It lets you specify a global setting to what extent you want to be tracked, and communicates that to sites that support the extension's "standard".
"KeePass and KeePassX are both good choices. If you really must use an online one, at least LastPass are responsive to researchers and have a competent security team, I would use them."
Asked about the experience he had reporting a 1Password vulnerability, he says:
"Astonishingly bad"
(source: https://twitter.com/taviso/status/1167311357957435392)
"KeePass and KeePassX are both good choices. If you really must use an online one, at least LastPass are responsive to researchers and have a competent security team, I would use them."
He adds about Lastpass:
"I consider them competent, I've reported some pretty complex issues and found they handle them well. Attack surface is definitely massive, I always recommend KeePass or just use a book if that's too complicated"
(source: https://twitter.com/taviso/status/1167311357957435392)
https://newfoodeconomy.org/grubhub-domain-purchases-thousand...
Google Chrome will now detect, if you have sync turned on, if your account is enrolled in Google's Advanced Protection Program (https://landing.google.com/advancedprotection/), and in case you are, give you stronger protection from malicious downloads.
The ZDNet article adds a lot of fluff around this, and weirdly calls the Advanced Protection Program "Gmail Advanced Protection Program".
The result back then was that the reported behavior is in accordance with the CSP spec, so the issue was closed.
Maybe Chrome should change their default CSP for extensions that haven't declared one though to disallow blob: URLs.
"The sole motivation here is correcting major privacy and security deficiencies in the current system. I know, because I set that focus, and the team reports up through me."
https://twitter.com/justinschuh/status/1134092257190064128?s...
"We are planning to raise these values but we won't have updated numbers until we can run performance tests to find a good upper bound that will work across all supported devices."
https://groups.google.com/a/chromium.org/forum/m/#!msg/chrom...
According to the post:
"... Chrome will stop showing all ads on sites that repeatedly display these most disruptive ads after they’ve been flagged.
To determine which ads not to show, we’re relying on the Better Ads Standards from the the Coalition for Better Ads, an industry group dedicated to improving the experience of the ads we see on the web. ..."
They are a bit vage in this post, but as we know from other posts and press briefings, this means:
The site owners will get a notice when Google has found that their site is displaying ads not compliant with the Better Ads Standards. When they don't fix this until after 30 days, all ads on the site are blocked, even those complying with the standards. The site owners can then of course still fix it, and get removed from the block list.
So the "flagging" is actually done by Google, and means the owners of the site get a notice.