288 karma · joined December 30, 2019
I'm glad the VLC developers never backed down from the Santa hat popping up near Christmas, despite ridiculous criticism from a tiny minority of users.
If you don't like it, fork it.
Australian here. When my house was broken into Police forensics came that afternoon and fingerprint dusted all points of entry and lifted prints. Do they not do this in your jurisdiction? I have just realised DNA is probably poor shorthand for that.
A piece of paper in a locked drawer is potentially accessible to a person breaking into it. It is probably an unsophisticated burglar looking for money. They are probably located in the vicinity of your neighbourhood and have rocked up to your home, and will not evade capture for long. They will likely leave DNA. If they decide to swipe your notebook, it will be immediately apparent you have been compromised, as your drawer is open and your notebook open or missing. Your notebook may be looked at momentarily, perhaps passed to one or two people, more likely, it will be thrown into a gutter as soon as the burglar realises it has no money in it, or just left untouched.
A password in a locked password manager is potentially accessible to a person breaking into it. It is probably a sophisticated cyberattacker looking for credentials. They are probably located overseas and have remotely connected to your home network, and will evade capture. They will leave no trace. If they decide to compromise your vault, it may not be immediately apparent you have been compromised, as your password manager is still there. Your vault will be scrutinised intensely, and your credentials will be sold to many others on a darknet forum.
I know which I'd rather.
The problem is most profound with tech illiterate folk. If you have tried to teach a tech illiterate person how to use a password manager (as I have), you may have encountered the issue that 'autofill' isn't 100% accurate. You will occasionally hit a subdomain or alternative domain which using the same credentials as the saved website (eg amazon.co.uk vs amazon.com). It will appear that no credentials are available for that site. Therefore, you usually have to teach the person how to manually search the vault and either fill manually, or copy and paste credentials. Otherwise, you can expect phone calls for support. And, of course, the original article actually suggests disabling automatic autofill. It suggests filling manually, further opening up the possibility of mistakenly filling onto a dodgy domain. As soon as you teach them a workaround to deal with this case, the phishing vector is basically no different to a post-it.
This problem might also apply to a tired, tech literate person, who mindlessly fills manually or copies credentials without checking the domain.
In either case, we fall back to Google Safe Browsing doing its job properly, and await solid anti-phishing solutions like FIDO2/webauthn.
I am hesitant about recommending a password manager to the tech illiterate simply because one piece of malware could compromise the entire vault. In that respect, a sticky note is arguably more secure than a tech illiterate person using a password manager.
Also, I have my usual criticism of client-side browser encryption. Anyone who has the technical ability to compromise a cloud-based service can likely take it a step further and modify JavaScript files enabling total vault compromise. There is no easy way for a user to mitigate this risk.
Password managers must be a stop-gap measure only until webauthn is more widely deployed. I long for the day when phone-based webauthn keys are the norm, and I can stop fielding questions about password managers from friends and family.
So, this just invites the same perennial arguments frequently made in relation to drug decriminilisation.
On my part, had the drinking age been 21 where I live, I wouldn't have started drinking until I was 21.
I have no doubt war also has neurological effects, but they don't seem to be age specific.
It is challenging, if not impossible, to otherwise defend it. If someone has the possibility to choose (or be forced) to harm themselves and shorten their life in war, then why shouldn't a choice apply to alcohol?
Perhaps you are using an older version of Word and/or the OneDrive client?
Also, in Australia, you'll only recover a portion in accordance with scale limits (party-party costs). Indemnity costs (100% recovery) is rarely awarded. What's the case in the US?
The point is, you look at the substance of what is being done or controlled, not the status of the actor as a private or public entity. That is what the analogy is used to explain.
The substance of what is being done, here, is regulation of communication between individuals over a communication platform. Downplaying it as 'not hosting public content' is inaccurate or at least of no moment. What's public content mean anyway?
If a significant amount of private communication goes through privately owned channels, it is reasonable that the private companies operating those channels respect democratic norms. It's unreasonable to dismiss any criticism as 'they are a private company', as that's beside the point.
There's an argument that private corporations that are involved in dissemination of information (search engines and social media) should respect principles of freedom of speech as a democratic principle, regardless of constitutional mandate.
Suppose the government outsources welfare eligibility decision-making to a private company. Does this mean traditional notions of fairness we would expect from such an decision-maker do not apply, because they are a private company?
It's a minor inconvenience, but I can sleep sound at night knowing my NAS isn't being wiped by a zero day.
It's perhaps a bit premature to demand it at this point, but I'm hoping a full post-mortem will outline precisely how this change was not picked up in pre-prod. Surely all valid customer configurations must be tested prior to rollout.
https://en.wikipedia.org/wiki/Accelerated_Mobile_Pages
* forgive my RAS syndrome
Whether or not it makes business sense to restrict the use of Apple ID elsewhere is a matter properly left to the app developer and not Apple.
I should have added - this is based on my own interpretation of the App Store guidelines. If I'm wrong, I'd like someone to point it out, since I don't want to be spreading misinformation.
Another example is Apple ID. If I use Google or Facebook SSO in my app, I have to offer Apple SSO alongside it. That is okay. However Apple will refuse the app into the App Store if I don't also offer Apple ID login on desktop and Android platforms.
Apple should keep its nose in its own business.
Are these staffers appointed by the community or by other staffers? I would have expected it to be a democratic process. Otherwise it does give off an elitist vibe that ok alludes to.
Edit: delete some things I'm probably not qualified to comment on
The same can't be said of WordPress or MediaWiki. You will not be able to run these at all if they become unsupported and will have to migrate, or risk facing security issues.
Sure, SSGs are not for everyone, but the potential for deprecation isn't a major issue, at least for a personal site.