425 karma · joined May 28, 2015
The problem is, this is one of those ISPs that have an extra SSID on their CPEs for "free" internet, think Xfinity, but this wasn't Comcast, and this vulnerability stems from an HTTPd misconfiguration, so if you can access the equipment's HTTPd (all you need to do is a single, unauthenticated request, so, really any access will do), you've got full access.
I went through some trouble to contact, via third parties, an insider at this ISP with the power to get things fixed - they did fix the remote part (via the aforementioned firewall whitelisting), but I was told, in no uncertain terms, that they didn't care enough to fix the root of the issue, as long as it wasn't massively exploitable, and it wasn't public.
I like my freedom/money too much to publicize details, and so it's still there, all these years later. I wonder how many vulnerabilities like this are out there, fully known by the vendors/providers, but nothing gets done about them because people are too scared to disclose, until eventually someone comes along and blows the whistle, or the equipment is obsoleted?
If that's the case, and some of his episodes bring this about, he really does need to either recognize this in himself, and exert some self-control, or straight up have someone else check it over.
This is especially dangerous because, since his companies' valuations are so intrinsically tied to his 'cult of personality' (I'm using this term neutrally - I believe 'both sides' will agree that a large percentage of Musk's companies' valuation does come from his bombastic personality and presence), this behaviour can only damage his work, which may put him into a negative feedback spiral, with each subsequent outburst plunging it all further down.
This seems to be quite serious.
There's a stupidly heavy emphasis on group work, with the superficial justification that "it's how the real world works", discounting that, in the real world, if you're in a team but don't actually do the work, you're going to get screwed.
It seems to me, though, that teachers are mostly pushed to do that because it's being done everywhere else, and because IT students have a reputation for being antisocial, so they need to be pushed to work together, in real life, if possible.
It's an entirely wrong approach to the problem.
Besides, France's population is 5 to 10 percent Muslim, which negates the "three to four percent" 'dictating' claim of the article, especially because, last time I visited France, most meats I saw weren't halal.
Even if you can only monitor things, instead of directly issuing commands, it's still information you're leaking.
Information leaks are still a class of vulnerability for a reason. It can give an attacker information on your network topology that he wouldn't usually have.
The less attack surface exposed, the better. Generally, if something is exposed to the Internet that has no (good) reason to be, it's a vulnerability.
Getting the courts/legislators to make the anti-circumvention clause only apply to commercial efforts, instead of absolutely anyone and anything (including researchers, oftentimes), would be a great victory.
The hacking, portrayed as fairly realistic, especially for people used to Hollywood craziness, and the fight (against financial institutions) pulled quite a lot of people.
Then, fairly suddenly, you get hit with a mental illness angle. A lot of people didn't ask for it, and don't really welcome it. It's not just a show about hacking now. It's a show about a very mentally ill man with a particular set of baggage trying to cope with it, while being part/the leader of a very notorious hack team.
So yeah, if you really like the first season, you might not like the second one much. At least so far.
If you're talking about giving legal power to websites' ToS to define what software may parse the data you download from their servers before/after rendering it to you, you're opening a gigantic can of worms, and I don't think most users would be particularly happy with that.
Whether you're willing to go that far for your data or not is up to you, though.
In fact, a driverless car may be capable of estimating its own stopping distance given road conditions and other measurements, account for some margin of error, and then use that to calculate how fast it can go down a road, while still adhering to the posted speed limits.
There is something to be said about a country's foreign policy and how 'arrogant' it is. A country can have a solid foreign policy (read: not be a pushover) and still not act like a giant bully.
Essentially, in any given month, you could get throttled/yelled at for going over an arbitrary data cap, which could (and did) vary every month. Given, it was usually above 1 TB, but it was still there.
ISPs got a book thrown at them by the FCC equivalent, saying that if they advertise their product as unlimited, it must be truly unlimited. Literally the next day that decision came out, all ISPs changed their adverts from unlimited to "at will" data caps, which essentially conveys the same marketing message, but isn't a regulated term.
Welcome to the new world, same as the old world, except where we've replaced a word.
They should attempt to use technical means, though, as it's unlikely that a simple 'Do you use adblock?' prompt is going to work very well.