2,004 karma · joined July 16, 2009
https://popehat.com/2015/10/08/bad-reporting-on-matthew-keys...
[0] https://ja.wikipedia.org/wiki/B%E3%83%BBN%E3%83%BBF
[1] https://ja.wikipedia.org/wiki/Cis_(%E6%8A%95%E8%B3%87%E5%AE%...
[2] https://twitter.com/cissan_9984
[3] http://www.bloomberg.com/news/articles/2015-08-28/while-many...
http://www.bloomberg.com/news/articles/2014-09-25/mystery-ma...
Briefly, once you have say 256 random bits it is trivial to use AES and CTR mode and turn that into 2^71 random bits until you need to rekey. If you cannot get more entropy in the time it takes to use up all of those numbers something is completely broken. The only problem you can have is not having enough entropy to bootstrap (such as VMs or needing to generate a key at poweron on an embedded device), but this paper gives little more than lipservice to it.
The rest of Murray's article is not actually about the actual CoC or any flaws with it.
They did hastly accept the supposed "problems" (that is, it was not a 1:1 copy of the geekfeminism CoC) and tried to fix them. People then complained because they do not believe that things specifically designed for one specific community and are not recommended by most of the experts are appropriate for a general CoC to be used for myriad different communities with far different goals than one specific wiki. TODO then decides that maybe they should actually take some time to think about things instead of circling the wagon around their kneejerk changes.
Garrett then argues that they released something broken and should have consulted the experts and that was one page document is of the same complexity as a 1,000,000 loc kernel. Well, it wasn't broken and it is in line with what most experts suggest, or at least it has not been cogently argued that it was not.
[0] I am using their own definition: http://geekfeminism.wikia.com/wiki/Safe_space
Also, those arguing that governmental assertions of free speech rights only apply to government actions are not familiar with the relevant case law in the US. [2]
Similarly, those claiming that censorship can only be done by state actors are using an incredibly idiosyncratic definition that basically anyone other than a hardcore libertarian would disagree with. [3][4][5] Say it is the 1980s and a college newspaper prints something that upsets someone. They then steal and destroy all copies of that issue once they are printed. How is this action by a non-state actor different enough to be put in another category?
Scott Alexander also has a good read on these issues. [6]
[1] http://www.wired.com/2013/04/aaron-swartz-interview/
[2] https://en.wikipedia.org/wiki/Pruneyard_Shopping_Center_v._R...
[3] https://en.wikipedia.org/wiki/Censorship
[4] https://www.aclu.org/what-censorship
[5] http://rationalwiki.org/wiki/Censorship
[6] http://slatestarcodex.com/2015/07/22/freedom-on-the-centrali...
[0] http://www.huffingtonpost.com/2014/06/16/aaron-paul-xbox-one...
[0] https://web.archive.org/web/20111111114352/http://www.flylog...? it seems to redirect to a generic ioactive blog which is a real shame
These numbers aren't going to be a perfect comparison because of fight length, strategy changes when you overgear content, skill differentials, etc but gear is pretty important.
One could easily argue that having the highest end gear does not really serve a purpose if you aren't doing any actual raiding or PvP though.
edit: I should probably mention that the last expansion (released last November) did a massive stat squish. In the last tier, t16, an LFR geared player would be doing 30k (ilvl 496ish), 100k (ilvl 528-540), and 1.0m+ (mythic/580+). Player power was increasing so much they had to start working around not being able to increase raid boss HP higher than 2^31 - 1. 25 man heroic Thok had ~2b HP for example.
[0] https://www.warcraftlogs.com/rankings/7#bracket=2&difficulty...
[1] https://www.warcraftlogs.com/rankings/7#bracket=7&difficulty...
[1] https://code.google.com/p/chromium/wiki/LinuxPasswordStorage
edit: Apparently there are people that run either incredibly old versions of chrome or don't run a keystore daemon and actually upload all of their dotfiles to github so I guess that part is technically accurate.
[0] https://en.wikipedia.org/wiki/Sony_Computer_Entertainment_Am...
In fact, the Rio's operation is entirely consistent with the Act's main purpose – the facilitation of personal use. As the Senate Report explains, "[t]he purpose of [the Act] is to ensure the right of consumers to make analog or digital audio recordings of copyrighted music for their private, noncommercial use." S. Rep. 102-294, at 86 (emphasis added). The Act does so through its home taping exemption, see 17 U.S.C. S 1008, which "protects all noncommercial copying by consumers of digital and analog musical recordings, " H.R. Rep. 102-873(I), at 59. The Rio merely makes copies in order to render portable, or "space-shift", those files that already reside on a user's hard drive. Cf. Sony Corp. of America v. Universal City Studios, 464 U.S. 417, 455 (1984) (holding that "time-shifting" of copyrighted television shows with VCR's constitutes fair use under the Copyright Act, and thus is not an infringement). Such copying is paradigmatic non-commercial personal use entirely consistent with the purposes of the Act. [1]
[0] 17 U.S. Code § 1008 Prohibition on certain infringement actions
[1] 180 F.3d 1072. 1078-1079. 51 U.S.P.Q.2d (BNA) 1115 (9th Cir. 1999)
So the law does specifically say that making digital copies of music for non-commercial use is ok and it has been reviewed by the judiciary (to some extent).
There is also 17 U.S. Code § 117 which allows backup copies or computer programs "that such new copy or adaptation is for archival purposes only and that all archival copies are destroyed in the event that continued possession of the computer program should cease to be rightful".
You can still get yourself in trouble related to the DMCA depending on what you are doing, but all of your assertions are false.
[0] http://en.wikipedia.org/wiki/Blaster_%28computer_worm%29
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0352
Every language has their own policies, but the English Wikipedia only has it enabled on certain pages.[1]
[0] http://en.wikipedia.org/wiki/Secure_multi-party_computation
[1] https://eprint.iacr.org/2014/075
[2] http://arxiv.org/abs/1502.07469
[3] https://www.iacr.org/cryptodb/data/paper.php?pubkey=2203
On the other hand even major players are constantly having low hanging fruit bugs delivered to them very cheaply due to bug bounty programs (like the two recent Facebook bugs). Paying $5k a bug and having no other costs (such as bad press) could be 'cheaper' than actually giving people security training and having audits. If companies started getting burned by these failures maybe they would work harder to prevent them ahead of time.
[1] http://arstechnica.com/security/2015/03/bogus-ssl-certificat...
The requirements for domain validation are:
11.1.1 Authorization by Domain Name Registrant For each Fully-Qualified Domain Name listed in a Certificate, the CA SHALL confirm that, as of the date the
Certificate was issued, the Applicant (or the Applicant’s Parent Company, Subsidiary Company, or Affiliate, collectively referred to as “Applicant” for the purposes of this section) either is the Domain Name Registrant or has control over the FQDN by:
1. Confirming the Applicant as the Domain Name Registrant directly with the Domain Name Registrar;
2. Communicating directly with the Domain Name Registrant using an address, email, or telephone number provided by the Domain Name Registrar;
3. Communicating directly with the Domain Name Registrant using the contact information listed in the WHOIS record’s “registrant”, “technical”, or “administrative” field;
4. Communicating with the Domain’s administrator using an email address created by pre-pending ‘admin’, ‘administrator’, ‘webmaster’, ‘hostmaster’, or ‘postmaster’ in the local part, followed by the at-sign (“@”), followed by the Domain Name, which may be formed by pruning zero or more components from the requested FQDN;
5. Relying upon a Domain Authorization Document;
6. Having the Applicant demonstrate practical control over the FQDN by making an agreed-upon change to information found on an online Web page identified by a uniform resource identifier containing the FQDN; or
7. Using any other method of confirmation, provided that the CA maintains documented evidence that the method of confirmation establishes that the Applicant is the Domain Name Registrant or has control over the FQDN to at least the same level of assurance as those methods previously described.
Baseline Requirements for the Issuance and Management of Publicly-Trusted Certificates, v.1.2.3 https://cabforum.org/wp-content/uploads/BRv1.2.3.pdf
AOL had to pay a settlement after the search data they released identified people.
That seems like a bit of an over-zealous heuristic for spam. Also, it seems silly to have two different threads just because one URL has https in the first place.