260 karma · joined January 12, 2017
[1] https://www.theregister.co.uk/2015/08/12/lenovo_firmware_nas...
Actually, what's really interesting is to compare her outlook from earlier this year https://youtu.be/oEyBjYNgaMY
Sorry if my comment implied I had kids, I do not. But in terms of access I see a lot of other comments further below talking about downloading everything locally and serving it through plex, which seems like a solid idea.
[1] https://globalnews.ca/news/4347007/manitoba-has-highest-homi...
IMO, calling the vulnerability the "Firebase vulnerability" makes it seem like it's a problem on Firebase's side. But is it really their problem? At what point do we start blaming the developers instead of the service?
They then handle all communications people want to send to you. More registration authorities should take stances like this.
Now if only they could get DNSSEC support...
So while a design may not make sense right away, there may be other factors at play.
[1] https://www.vice.com/en_ca/article/vv5jkb/the-secret-ways-so...
Of course that doesn't actually scale. That's why most all the big players are providing export features.
You'll probably try to do a bit of research and try to figure out how to opt out of all this and protect yourself. And you should. But you shouldn't just stop there.
Many of the people who are reading this right now are responsible for designing and implementing systems that collect massive amounts of data. I implore you to not just think about your own privacy moving forward, but the privacy of your users. Security and privacy should be two of your top level concerns when designing systems, not just tack-ons.
Simply hating of Google/Facebook/$$$Corp for invading your privacy and not doing anything to rememdy the general poor state of privacy in the modern connected world when you have the power to do so is hypocritical.
Next time you're given a project that has PII and the security user story gets deprioritized, raise it as an issue. Aside from being the right thing to do, many places, such as Canada and California, are looking at GDPR-like regulations. So it makes sense to do it now instead of later.
And if you're going to argue that it's hard, and it's time consuming, and you're a startup just trying to get on their feet so you can't be bothered, then consider that you may be part of the reason we find ourselves in this sorry state.
/rant