3,936 karma · joined June 23, 2014
Blog at https://adnanissadeen.com/blog
I really appreciate the community here sharing thoughts, similar experiences, and ideas on what to do. First time I've heard of the public suffix list for this.
A quick question to anyone who happens upon this: How does one prevent this issue affecting an entire site in general? Is there a grace period that Google gives a verified (via search console) site with a security issue? If not, then I'm curious how to protect a site which is targeted by malicious groups via comment widgets or if they host content using paths instead of subdomains. Eg: medium.com uses paths to go to user generated content. How would they defend from having their entire domain blocked if someone created a publication that linked out to malware?
Cheers all!
In this case it would be tricky since the link is to google drive and we can’t block those. Also we’ve seen people work around url blocks by either using short links or by using html pages hosted for free to redirect using JS instead of an HTTP redirect. Always another mole to whack :,)
On that note though, I'm perplexed as to how people would manage this kind of thing if using paths instead of subdomains. So instead of <user>.start.page if we used start.page/user. In the latter case, I'm not sure how one would prevent their entire domain from being taken down if malicious users kept linking to malware hosted on file hosting/sharing sites. Is there something similar to the PSL for this?
At its core the issue in my head is user generated content linking out to malicious software being a point of trigger for entire sites being blocked. Does this mean that an entire publication site could be blocked if someone used a comment widget to link out to malware and the site got reported? That seems like an effective DoS mechanism at some point.
I guess what I'm struggling with is why the domain gets blocked instead of the actual url that contains malware (or even the single path that links out to it). Fwiw the google drive link hosting the malware is still active.
Where we, and in this case, I, missed a very important step by the looks of it is in adding ourselves to the public suffix list. I have done research on subomdain content management but for whatever reason, today is the first day I've come across the PSL. Something I definitely take responsibility for and makes me wonder what other stuff I might be missing that is obvious to other folks who've done this at scale.
If there’s a risk that each time that happens the entire domain could be blocked, that’s a lot of risk to try and mitigate. Especially seeing that many of the bigger providers also struggle to mitigate this kind of content despite having technical teams that are larger by an order of magnitude (or more).
Also, this is bound to happen in the future where people are going to link to malware that’s hosted elsewhere.
I’m trying to wrap my head around how to mitigate the risk of the entire site being blocked vs a single subdomain.
Will update here though when it is resolved in case there are any lessons to be shared with folks
In our case, Google's search console shows clearly what subdomain was guilty of the issue and that subdomain has been cleared now. Just really want to expedite the review process since Google's safe browsing has decided to block the entire domain instead of the offending subdomain :-/
I've submitted a review but they do say that reviews related to malware take a few days to process. This is a little hard to be honest given that it's not even our site that is hosting the malware. It was a page linking to google drive which is where the malware actually is hosted.
Hoping we get a response soon. Appreciate the supportive chime in.
Is this a global ban on using HEVC to stream UHD?
What does Netflix use to stream 1080p?
Assuming Netflix turned HEVC off tomorrow how would UHD streams happen on a random smart tv from almost a decade ago?
Feeling very confused because I wasn’t even aware that this was something on the horizon and video codecs isn’t a topic I know anything meaningful about honestly.
I want Apple to tell me when that shop that promises original parts is actually giving me an original which I can track.
I don’t want them stopping me from using it unless it’s genuinely incompatible at a firmware level.
What's the point in asking for the access_token at all for that endpoint otherwise?
Am I misunderstanding the bug? This feels like a foot gun that was happily handed over to a lot of people all this time.
This is definitely outside of the use cases described but I can definitely see myself hooking this up in an IFTTT style to funnel things into my todo systems using the HTTP provider.
Will poke around this soon.
> Startlingly, however, The Economist provides no actual data to support this claim.
Ha! This was a reason I unsubscribed from the economist. A lot of times it makes broad claims and then leaves out the details to support said claim. Almost like it expects the reader to treat the economist like a first hand source and therefore no citation needed.
Good on the author for calling this out and then rebutting with details of their own (not necessarily supporting author’s claims though since I haven’t had time to really think about it just yet).
Ruby starts off by saying you should have a version manager. And windows installation is not straightforward (from a student perspective it’s important to note that something that looks like it isn’t officially supported makes it feels like the entire language is going to be a compatibility slog). This is not dead dead simple. It’s not hard. But it requires more than one concept to be learned to start.
Then the docs. Ruby has so many ways of getting started. Python puts up one main way. Same for the api reference. Python has a single link and they even say “keep this under your pillow”. As a beginner I know what I should do. Ruby? Many links that say arcane stuff (beginner perspective) like rdoc and what not. Python is super clear in their breakdown of reference too. I cannot stress enough how simple this page (https://docs.python.org/3/library/index.html) makes it to find what you want.
Overall Ruby and it’s documentation feels like it’s made for people who know Ruby or something more than the bare minimum. Python is made for people who’ll be trying out programming itself for the first time.
To me, that’s what made Python win. They just seemed like they thought more about folks starting out for the first time.
I feel like similar things will happen in the forum fediverse (it’s what I call the fediverse alternatives to Reddit). There’s going to be a period of thrashing and churn. And then it’ll settle down with each community having its own vibe and we members get to try it out and settle where we want.
If they really believed in it, the first priority of the company would have been to make it so that every non hardware unit of their physical offices was shut down and people were told to go work from the metaverse within the spaces of their homes, beach houses, coffee shops or wherever they physically were. Every meeting would have been held in the metaverse. Every all-hands, in the metaverse. Every employee in charge of people would have been working with the product and engineering to create experiences for the team to bond and share time in within the Metaverse. Meta should have lived and breathed as a company within the metaverse. Pre layoffs that would have been more than 86,000 concurrent users who would have a daily direct impact on the product.
Instead, Mark wanted people to come back to the office.
The Metaverse by Meta died when their people touted it as the future of work and play but then did absolutely nothing to use it that way themselves.
That said, I’ve watched some comparison videos of his drumming vs more expressive and I can understand where people are coming from :,)
Also, just in case it’s helpful, the zero weight statement was related to the folks I connected with. Not referrals in general.
Basically, as your comment reveals to me, there’s a lot of nuance here and the article generalizes it away into a statement that doesn’t feel accurate.
Imo the article has been referenced well even if the references are mostly second hand; it repeats claims made by other articles which may also be repeating claims made by others.
To me, the key fact that I wanted to check in on was this
> Up to 70% of employees received their current company position through networking.
The reference for this probably comes from a 2017 linkedin survey[1] which polled 15,905 linkedin members in 2016 and received this as one of their answers
> ... 70 percent of people in 2016 were hired at a company where they had a connection
I find that this kind of stands at odds with the words "received their current company position *through* networking." That makes it sound like the networking was the reason they were able to get the job. The linkedin statement makes it seem like that's just how they may have found out about the job. I won't accuse the article of directly saying what I'm assuming it means. But I also think the rewording changes the meaning too much for me.
Wherever I have worked, whenever there's been a job opening I have forwarded it to friends who might be interested. For the ones who got into the job, they had a connection, but that had absolutely zero weight on whether they got hired or not. I was just a more efficient job board promoter.
Not to take away from everything in the article but I definitely would encourage people to break any numbers they find interesting down into what they might actually mean by visiting the sources and trying to read into the claims fully.
[1]: https://news.linkedin.com/2017/6/eighty-percent-of-professio...
That is correct. I mean, some of that is exactly why I write at least 5000 words a day of journal notes while working. Because I want to offload everything from memory to a written form that is indexed.
> and you offer your pupils the appearance of wisdom, not true wisdom, for they will read many things without instruction and will therefore seem to know many things, when they are for the most part ignorant...
This part is where we veer into prediction of how it will alter people and it is both right and wrong. I think the education system has shown us it's possible to have a great memory and to remember many facts and still be ignorant. At the same time, there's so much material that can be consumed and people have surface knowledge of many things and once you dig into a conversation with them on it, the ignorance pops up and it turns out that they don't know much about the topic. I know this. This has been me on many occasions and is still me on some occasion.
>... and hard to get along with, since they are not wise, but only appear wise.
Again, there's some truth to this. I think about the times where I've jumped into a conversation about politics with some half baked knowledge that I read somewhere but failed to understand or recall correctly and I think I must have a looked a fool at those times.
But then again, I've course corrected here and there and I've spent time writing and sharing thoughts with others where I've used previous writings to pull up facts and my own synthesis, and I feel like I've been a better participant at times like that. In that way, writing has helped me steer away from ignorance.
I can't comment further though on the quote because I've never read the rest of the context so I may be missing out on some stuff.
I think Paul is on to something here though. I can't count how many thoughts I've had that I thought were clever but when I started to write the thoughts down and organize it on my own, I discovered for myself that either I didn't have enough evidence to prove myself entirely or that I was just flat out wrong. Writing is a form of thinking in my opinion. And if we don't write, we do lose that side of thinking too. I do appreciate though that Paul doesn't go further into predicting the consequences as Plato's warning does here. But I'll be willing to bet that Paul is right that there will be some negative consequences for sure.