It was a wake up call. I've since moved most of my digital life onto other services.
996 karma · joined December 27, 2010
m@mdp.im mdp@1984.vc
https://github.com/mdp https://twitter.com/mdp https://1984.vc https://apply.1984.vc
It was a wake up call. I've since moved most of my digital life onto other services.
The fact that they refused to do this and instead bullied her into their own opinion is remarkable. If they'll do this for something so minuscule, imagine what they'll do for bigger issues.
The tapes aren't exposing that Goldman got away without a conflict of interest policy, they're exposing that the Fed is still refusing to let staff stand by their independent opinions.
The immediate reaction was that this might be terror related - "NYPD bomb technicians spent several hours checking the bridge for explosives but found none."
They even subpoenaed a parody Twitter account for claiming it "signal[ed] our complete surrender of the Brooklyn Bridge bicycle path to pedestrians"
Not our proudest moment.
Remember the consequences Putin faced for Georgia in 2008? Neither does he, because there really weren't any.
'In some of the documents, prosecutors allege that HSBC intentionally flouted the law. The bank created an operation that was a "systemically flawed sham paper-product designed solely to make it appear that the Bank has complied" with the Bank Secrecy Act and is able to detect money laundering, wrote William J. Ihlenfeld II, U.S. Attorney for the Northern District of West Virginia, in a draft of a 2010 letter addressed to Justice Department officials.'
'In one email exchange submitted as evidence in that case, employees debated whether the bank should help a Miami client get around U.S. sanctions by moving the client's business to HSBC's Hong Kong office. "I believe that the best outcome would be for the customer to open a relationship with Hong Kong just for leters (sic) of credit purposes. He travels there all the time," private banker Antonio Suarez wrote in a 2008 email. Suarez has since left the bank and couldn't be reached for comment.'
http://mobile.reuters.com/article/idUSBRE8420FX20120503?irpc...
Don't take legal advice from anyone but a lawyer that you are paying.
Seriously, this depends on a variety of factors and is especially dependent on your local laws, the specifics of the contract and most importantly, precedent.
Find a lawyer, give them your contract, detail your side project and get an opinion.
I posted the APKTool output on Github for anyone that wants a quick look - https://github.com/mdp/iMessageChatDecompile
Here's my security disclosure for the day:
You can walk out of most stores without paying for their merchandise if you hide it in your pocket.
Which vendor do I talk to about getting paid for this information?
It was designed to interop with OpenSSL's default command line AES crypto, which has some weak points, mostly around the IV selection.
That being said, the biggest weakness will always be that it's running in the browser and open to injection attacks.
But while I think there's definitely better crypto chat solutions out there, it's nice to see people taking an interest in the subject. And let's not kid ourselves, the vast majority of NSA data collection is probably less about sophisticated encryption attacks, and more about the clever application of political/police powers.
That being said, it's seems to be getting better as more companies embrace SPF.
I get MAYBE 2 spam emails a month that gets through the filter, and my address is pretty easy to harvest.
So is this still a problem?
Struck it from the post.
I wrote up a post with some of my security concerns. http://news.ycombinator.com/item?id=5311010
It lets you use Connect compatible middleware to alter the request or response - (https://github.com/mdp/middlefiddle/blob/master/.middlefiddl...)
There's a bunch of these proxies out there, and they all provide something different, but if you're just looking to inspect the HTTPS request, I'd also recommend the excellent Charles Web Proxy - http://www.charlesproxy.com/ - I bought a copy years ago, and it's been invaluable.
This is not correct. You can't decrypt a key with a one time password.
The OP is requiring a the second factor(the OTP) after the key is sent to the server and authenticated.
My biggest concern is that the Rackspace Cloud product doesn't seem as polished as Slicehost. Slicehost was a great service for newer users, with great documentation and help resources.
It looks like a great app, but I'm still leery of basing something as important as my editor on a closed code base again.
There are also some great alternatives out there, notably Redcar, which is both open and full of Textmate like features.
Wifi might be prevalent in most places but quality and reliability will always be am issue. I've found it to be ubiquitous is SE Asia, however I've had days where slowness could cause even SSH to bog down to a few characters a minute.
Bigger issue, do you mean travel or live in a foreign country? Because yes, you can very easily find a cheap country with good internet, but traveling itself can be a full time job when you're only spending a week at a time in one place.
If it were me, I'd just travel, and do the startup later.