Unfortunately I only remember the first half of mine after so many years. In the age of smartphones, at least my brain degenerated to not be able to recall more than a handful of important phone numbers.
894 karma · joined July 6, 2011
Unfortunately I only remember the first half of mine after so many years. In the age of smartphones, at least my brain degenerated to not be able to recall more than a handful of important phone numbers.
https://blogs.microsoft.com/blog/2023/07/18/furthering-our-a...
https://news.ycombinator.com/item?id=36677578
Edit: of course for the next 1-3 years, compliance departments in the EU can declare themselves not guilty and business will continue as usual.
A recent definition of the German authorities clarifies that with „cookies“, they don’t interpret it narrowly as the specific browser technology but any kind of beacon or mechanism for tracking[0]:
> Gemeint ist damit beispielsweise der Einsatz von Cookies und anderen Technologien wie LocalStorage, Web Storage, das Auslesen von Werbe- und Geräte-IDs, Seriennummern, aber auch der Einsatz von ETags oder TLS-Session-IDs zum Zwecke des Trackings, Fingerprinting (z.B. durch das Auslesen von installierten Schriften oder Anwendungen) und vieles mehr. Der Einfachheit halber wird das im Folgenden i.d.R. unter dem verkürzenden Begriff „Cookies“ zusammengefasst.
They name as explicit examples not only cookies but LocalStorage, Web Storage, reading of any kind of serial numbers, ETags, TLS Session IDs (if used for tracking), and any other method for fingerprinting such as font profiling.
[0] https://www.baden-wuerttemberg.datenschutz.de/faq-zu-cookies...
Edit: actually not sure. In Civ 1 you build up your palace, not the throne room per se.
Currently and as far as I know, bioctl does only support user typed in passwords or key disks. You certainly want also encrypted disks on your server but requiring user typed in password is oftentimes a no-go (think of various firewall appliances doing a reboot and not having remote hands). A compensation can be the key disk but I don’t know how widely that is used.
Hardware bound encryption like with a TPM is not supported. Also Linux is still exploring here as far as I can tell (no installer offers that).
In sum: I think disk encryption in the current form is not a tradeoff many installations will take.
https://www.openbsd.org/faq/faq14.html
It’s 3 commands to type in that are explained and that will work as is in most cases.
You can always choose to not install all X* packages. In fact, for a server oftentimes you don’t need more than the base package (you barely need a compiler either or games).
A TPM can attest that some measurements were done with it and it can attest that it comes from vendor X. You can block an entire vendor if they don’t behave but not individual TPMs via remote attestation.
You can use a scheme in which you can set up an „identity“ on first use and then on next use authenticate the same identity. But that identity is kinda per use case.
I am using a Framework with 1.5x scaling using Fedora KDE and it’s amazing. Didn’t find any app yet that doesn’t conform. One difference to years ago is Wayland vs X. With X it was a constant struggle for me while with Wayland and more years invested, scaling became a non-issue on Linux (for me).
Regarding burp suite, iirc this is a JVM based app. I am running Jetbrains products without any issues and no configuration needs. Assuming burp suite uses swing, I would assume no issue. Generally, you can quickly check with a VM. Using Fedora KDE is a great „Just Works“ experience.
Also photos of bomb drops are used to check where bombs might have fallen and not explode.
https://www.spiegel.de/international/business/firm-uses-hist...
https://learn.microsoft.com/en-us/mem/intune/fundamentals/su...
https://learn.microsoft.com/en-us/mem/intune/user-help/enrol...
THIS SOFTWARE IS PROVIDED „AS IS“ AND WITHOUT ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, WITHOUT LIMITATION, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE.
RFC6749 The OAuth 2.0 Authorization _Framework_
If you consider NSA or similar agencies a problem then you are in a world of pain anyway and using an entry level guiding blog post is certainly not appropriate.
For everyone else, this puts already quite a big defense layer to your arsenal even if not unhackable in absolute terms.
For cookies that mean: technical cookies that you need to technical provide your offering (think of authentication session cookie, loadbalancer sticky session cookies, but also cookies to understand if someone opted into tracking) can be set with legitimate interest and do not require a consent.
A consent under GDPR is strictly opt-in. This means, by default you must not track a user (EU citizen) that just landed on your site. After consent, you can load your GA plugin.
Consent is required by GDPR but not for the technical circumstance that you store a cookie but that you use it for profiling. Some lawyers argue that basic web performance is legitimate interest especially in e-commerce, others don’t risk it and ask for consent (which is strictly opt in).
https://fpf.org/wp-content/uploads/2017/06/FPF_Visual-Guide-...