While I generally agree with the sentiment of the article, and I do like the neutral presentation of most of the information, one thing stood out to me. The “it’s not your fault, it’s the food” attitude seems dangerous. I think that mindset will lead to dietary learned helplessness if it becomes prevalent.
It reminds me of the pros and cons of the body positivity movement. On one hand, it’s important not to instill guilt related to food and demonize it. At the same time, being too accepting results in poor mental and physical health outcomes. It’s important to recognize that you hold control over what you do and who you are.
I do know the answer to this - Firefox is not an acceptable alternative to a strong password manager. Local admin can dump any passwords from Firefox, and I think a user can even dump their own passwords from Firefox on windows and Linux.
Great take. Do you have any thoughts on how to improve on CVSS 3.1? I’m wondering if perhaps the optional “additional details” section, where you can contextually upgrade or downgrade scores, should be a mandatory part of the score.
While I disagree with the author’s overarching opinion on ReDoS vulnerabilities, I agree that some CVEs make it through with incorrect severity scores. If you find a CVE like this, MITRE can be contacted to mark it as disputed for investigation.
“Choose to not be poor” is the thesis of your statement, whether you meant for it to be or not. It’s hard for that to be a good faith start to any discussion regarding poverty.
No one making $9/hr with a kid or two is going to be dishing out for a Costco membership and getting a volunteer to drive them around everywhere they need to go. There is no long-term savings and “financial sense”, it’s hand-to-mouth, sometimes shoplifting to survive. Have you executed this plan yourself? If not, I’d suggest appreciating the fact that it isn’t this easy or many people in poverty would have done it.
Your first paragraph seems to be “others are already doing it”. That’s a problem, not a justification for doing more of it. It’s a shame to see embedded analog grain stripped out because it was inconvenient for a dev team. It strikes me as a good example of the bad reputation developers hold for constantly prioritizing their own convenience over the end user’s experience.
To address your second- I think that’s an example of the “slippery slope” fallacy. I’m stating only that film noise and grain is a big part of the atmosphere of many movies and shouldn’t be removed; I’m not suggesting that a viewing experience needs to be done in a world-class theater under perfect conditions to capture artistic intent. Anyone with a basic HD television can see analog noise and grain.
To many film artists, what you’re suggesting seems like the equivalent of hardcoding a custom massive bass boost into commercial headphones because “it makes music better”. It might seem better to you, but you’re modifying someone’s art, which is actively detracting from the film for many.
This is really out of touch. First off, poor people can’t afford Costco memberships. Second, 5 miles is a very long distance in Chicago. How can someone justify spending an hour in traffic each way, and with what car?
The scale of factory farming suffering is much greater than the shark fin industry, even if most of it is a milder form of torture. This just reads as “that’s worse!” fallacy caused by cognitive dissonance. Both can be bad and it strikes me as hypocritical to partake in one and demonize the other.
With all this App Store monopoly talk and pressure to open up, I think Apple will take a hit too. With that said, I think they deserve to be valued higher than most of these companies; Apple seems to have stronger product offerings and customer experience.
Funny you mention this, because we’re already seeing it. In fact, I recall reading that unfiltered marijuana smoke is slightly more harmful to the lungs than unfiltered cigarette smoke.
People get defensive when they feel like they’re being attacked. Many people really enjoy alcohol and don’t like to think about it as a dangerous drug (which, of course, it is).
Is it just me or does this kind of thing reek of a nation state? This feels like the Twilio breach where the suspected goal was access to Signal MFA codes for 15 minutes or whatever that was. Feels like it’s hyper-targeted as some kind of military operation.
Yeah, I was expecting heartbleed and this is “denial of service if you manage to sneak a malformed certificate by a CA and it makes into an attack chain”. Other than the sheer number of devices vulnerable, I don’t see this as being that big a deal.