Not sure I've ever seen a company openly take this position. This is a crazy policy.
865 karma · joined July 25, 2011
Not sure I've ever seen a company openly take this position. This is a crazy policy.
https://www.in2013dollars.com/Food/price-inflation/2019-to-2...
https://www.nerdwallet.com/article/finance/price-of-food
It's closer to 28%. I wrote the initial post from my memory of the stat, which is why I approximated it.
But, I also don't think you're lying. I think you honestly believe your grocery bill tripled, and I think a lot of people have a similar internal impression about how bad inflation got. It's not useful for me (or, for politicians) to try and argue it logically. No one can check your receipts from 2019 and 2024 and say, look, things aren't actually that bad. Dems needed to kind of take it at face value and come up with a solution to something that people feel is real, and they just did not do that.
Editing to add: I might as well add the lowest effort source to the ~25% number, which comes from using the search feature of ChatGPT (sorry). https://chatgpt.com/share/672b7e09-4b58-800e-a3df-58f38c33bc...
Despite being about 40% broken I keep the site up because it's still reasonably functional and there are a surprising amount of sites that now depend on having hotlinked the patterns directly from this domain. If it ever degrades to the point of being actively dangerous (and the attribution link rot is pretty close), I'll shut it down. Until then, it's a fun relic from the internet of a decade ago.
Just to answer a question upthread (and I 100% agree this should be on the website), the patterns are all CC-BY-3.0, meaning it just requires attribution and any pattern can be used for free.
Does Apple have access to Patreon creators' gross revenue? I thought they only charged commissions on payments through IAP, which I assumed is only a minority of their overall gross.
Most recently I used it to refresh my memory on a particularly convoluted way to authenticate with a third-party oauth system (it involved using an online oauth debugger and curl commands). I had gone through the process once successfully weeks ago, but by the time I had to do it again I'd forgotten every detail. Rather than have to go through the process of figuring it out again, I went back to my successful attempt, watched it, and basically retraced my steps. Rewind probably saved me an hour or two.
My take on Recall is that, like with almost everything, it's a trade-off of security for convenience. I find it valuable enough that I'm willing to make the trade-off, but others might not.
Article: "This database file has a record of everything you’ve ever viewed on your PC in plain text"
Microsoft: "Snapshots are encrypted by Device Encryption or BitLocker, which are enabled by default on Windows 11."
https://support.microsoft.com/en-us/windows/privacy-and-cont...
The article is a little bit hand-wavy about how exactly the database comes to be decrypted and remotely exfiltrated. The headline says it takes "two lines of code" but unless I'm missing it, I don't see those lines discussed in the article.
This is kind of a blanket argument against all laws, right?
The vouchers were encrypted, and could only be decrypted if there were, I believe, 30 independent matches against their CSAM hash table in the cloud. At that point the vouchers could be decrypted and reviewed by a human as a check against false-positives.
It sounds like with a raw byte hash they might be able to match a photo against a list of CSAM hashes, but they wouldn't be able to do the human review of the photo's contents because of E2E.
"A separate version for the Apple Watch would remain [in the App Store], but then Apple pulled that one as well, telling Eleftheriou that keyboards aren’t allowed on the Apple Watch."
This is wrong, as far as I can tell. The watch app is still in the App Store.
https://apps.apple.com/us/app/flicktype-watch-keyboard/id135...
I just installed it and verified that it works, although the Watch keyboard itself is hidden behind a $10 in-app purchase.
In Apple's implementation, the device never knows if a particular picture is a CSAM match. That determination is made in iCloud when the server attempts to decrypt the safety voucher. Until that point, it's just an encrypted payload that the device can't interpret one way or the other.
In your analogy, where "your home" is the equivalent of "your device", the police never enter the home to determine whether you have anything illegal. Instead, there's some process that boxes up all your stuff into nondescript, anonymous boxes that can only be opened if someone has the key.
To determine illegality, you'd have to voluntarily send them off to the police (police = iCloud), where they only have a handful of keys - they have a "gun" key, a "knife" key, and a few other keys for boxes containing illegal items. But the boxes are nondescript, so the police don't know whether you have anything illegal until they insert the key and turn it. If the "gun" key successfully opens the box, the box contains a gun, and you are reported. If all the police's keys fail on a particular box, then whatever is inside must not be illegal and the police never learn its contents.
Needless to say, this analogy is tortured because it's hard to apply Apple's tech to a physical process, but the point is that whether something is "illegal" isn't able to be determined until you voluntarily ship it off to an entity that has the keys to unlock it.
Apple takes a photo, runs it through some on-device transformations to create an encrypted safety voucher, then it gets "interpreted" once it's uploaded to the cloud and Apple attempts to decrypt it using their secret key.
Google uploads a raw photo, which itself is essentially a meaningless value in the context of identifying CSAM, and Google "interprets" it on the server by hashing it and comparing it against some database.
In both cases, the values that are uploaded by the respective companies' devices don't mean anything, in the context of CSAM identification, until they are interpreted on the server.
Apple released their phone in 2007, the App Store in 2008, and in-app payments in 2009. During that time their marketshare was fairly small, and it didn't start to really grow until they expanded availability to the Verizon network in 2011.
Right at launch of the App Store, Apple announced its sales commission would be 30%. Then they extended that same fee to in-app purchases a year later. At the same time they set the rules that third-party app stores were not allowed, and that third-party payment processors could not be used.
I'm mentioning all of this history to make this point: Apple made these rules when they were not a monopoly by any definition. They released these products, with these rules, into a free market and let the market (both users and developers) decide which products to use and which products to develop for.
Now, obviously, between 2007 and 2021 the iPhone has been a wild success. Its platform has grown in users and developers every year.
So in terms of the framing of "market abuse", at what point between the launch of these rules and now did Apple cross that threshold between free-market competitor who can legally control their own platform to monopolist abusing its power?
I'm asking this question not just to make a point, but because I think it will be instructive for future companies to understand where in the growth curve the rules they started with can potentially cross over into being "abusive".
I'm not clear on what you are suggesting here. Are you saying they should contact people multiple times to make sure they weren't having a bad day the first time around?
2-3 days is common because any longer than that and the survey results will no longer be reflective of a specific point in time.
Also, if you check their crosstabs they have breakdowns for gender and age.
In that situation, maybe the user would have eventually signed up through a different platform, and the company could have been directly paid 100% of the price. But it's also possible that the user would simply never have signed up, in which case Apple's 30% cut would look like a steal compared to the alternative (receiving nothing).
I'm sure Apple is very pleased with the profit margins they get on in-app payments, but I'm equally certain that Apple's desire to keep people using their payment system is just as much about maintaining a great user experience for users.
Obviously the flip side is that some companies - Netflix! - then decide just not to offer payment in-app at all. That's also bad! But I don't know how to compromise on allowing apps to direct users to payment systems outside the app store without opening the floodgates to a million different payment experiences, which I (again, selfishly) would love to avoid.
1. It saves a snapshot of the DOM state before/after each test step. If you have a long acceptance test where it's deeply navigating through your app (i.e. visit "/admin", click on "Login", type "username", click "Submit"), using the GUI test runner will show each individual step in a side-panel. From there, you can hover over a step to see a snapshot of what the page looked like before that step was executed, and a snapshot of what it looked like after.
I had previously only used test runners where, when it would run the acceptance test, you would see a series of really quick flashes of the runner executing a bunch of steps faster than my eye could track, and then a big FAILED message. What failed? How did it fail? Cypress solves this problem by saving the DOM state and allowing me to traverse backwards through the state of the app until I find where things started to go wrong.
2. The cli test runner records a video of its test runs. Super useful in CI where you don't have access to the frontend. Cypress will record its run to an MP4 and you can investigate failures after-the-fact. This has solved a lot of "it works on my machine but not in CI" problems that seem to come up pretty often.
The other positive thing I have to say about Cypress is that I've actually found it more helpful as a development sidekick tool than as a test runner. Particularly when developing features on the front-end that require a lot of user interaction, many times it's easier for me to whip up a quick Cypress test that automates the user interaction (with assertions along the way to make sure the app is working) and then use the GUI Test Runner to do all my debugging.
It's not perfect and I definitely have some frustrations with it, but on the whole it's helped my productivity quite a bit.
Does that mean your video use-case would also be fine? I have no idea. An HN comment from the CEO doesn't seem like it would hold up if Cloudflare suddenly shut down your free account.
I'd love for Cloudfront to officially clarify the limits of the Cloudfront/B2 alliance in terms of external traffic. The confounding issue here is that B2, as a storage service, is not really intended for "serving web pages and websites" — it's for larger files, binaries, etc. — and therefore any traffic from B2 going through Cloudfront is sort of de facto in violation of 2.8.