HNHacker News
TopNewBestAskShowJobs

kva-gad-fly

16 karma · joined June 26, 2024

submissionscomments
kva-gad-fly··on EV Stupidity Checklist
The presets on my mercedes and my mustang and my honda fit work quite fine, thank you.

And these touch screens are cute until a product manager wants to show their marginally questionable value to the universe by changing the UI, buttons, placement etc. and now you are searching for the crucial functionality that you forgot to set or check, after the last OTA update occurred, before you started moving, and are now careening down the highway at 60 miles an hour...

kva-gad-fly··on EV Stupidity Checklist
Oh my god!!! Physical on/off siwtches for lights.

The number of times I would curse the EV I drove previously, when I saw a person in front with no lights on, or to signal a semi that it was safe for them to switch lanes....flashing the hi-beam sends exactly the wrong message.

Another annoyance: these days, even low end cars have an `AUTO` setting for lights, that ensures that headlamps and rear tail lights come on when dark, or in the rain, when wipers come on, only to have ppl disable them because they belive they extending their battery life....bah!

Shoutout here to my new car (Ford mustang, not the EV version). Lights are a knob; making changes flashes a toast on the front dashboard so I cna see what it gets set to without taking my eyes off the road; and, to boot, regardless of what I set it to when I drive, resets to `AUTO` when I turn off and turn on the car again.

kva-gad-fly··on California sent residents' personal health data to LinkedIn
Not sure I understand this, but "I" (coveredca) pay linkedin to place my ads, for which "I" have to use their libraries? That then scrape "my" clients/customer data to linkedin? for them to make more money selling that data?

Does this also mean that those pious popups about "Do not sell my information" are essentially vacuous?

kva-gad-fly··on Do you need ID to read the REAL-ID rules?
This was intriguing to me:

> One of your staff asked me yesterday how I had traveled to the DC area, whether I had traveled by air, and whether I has shown any ID to do so. As a matter of principle and personal security, I do not wish to discuss my travel history, modes, or plans with you, and I am not required to do so. But the consistent position of your agency in litigation has been that no Federal law or regulation requires airline passengers to have, to carry, or to show ID. The responses by your agency to some of our FOIA requests confirm that, as you know, people fly without ID every day.

How does one go about this process?

kva-gad-fly··on Bypassing airport security via SQL injection
Even if these govt. security audits are checkboxes, dont they require some nominal pentesting and black box testing, which test for things like SQL injection?

That shoudl have caught these types of exposures?

kva-gad-fly··on Bypassing airport security via SQL injection
If this were the case, then it seems quite plausible that the website itself was just a passthrough, and the APIs provided by ARINC would be exposed.

THis then begs the question of how ARINC passed security audit.

kva-gad-fly··on OpenSSH Backdoors
https://www.openwall.com/lists/oss-security/2024/03/29/4

?