913 karma · joined April 21, 2019
Why should you entrust them with your private notes and data?
"You agree that the product will send usage data to validate your compliance with the license terms and anonymous feature usage statistics..."
"The information collected under Sections 4.1. and 4.2. may include but is not limited to frameworks, file templates used in the Product, actions invoked, and other interactions with the Product’s features."
"You agree that the product will send usage data to validate your compliance with the license terms and anonymous feature usage statistics..."
"The information collected under Sections 4.1. and 4.2. may include but is not limited to frameworks, file templates used in the Product, actions invoked, and other interactions with the Product’s features."
/s
.COM agreement between registrars and ICANN requires registrars to regularily store all registrant contact infos in IronMountain and set ICANN as escrow, therefore allowing ICANN to contact all registrants should a registrar fold and allow them to transfer to another registrar. Another reason to keep the domain ownership informations up-to-date. [1]
[1]: https://www.icann.org/en/system/files/files/rde-agreement-09...
[1]: https://itp.cdn.icann.org/en/files/registry-agreements/com/c...
Type: Scheduled Production Maintenance
Origin: Registry Donuts Inc.
Planned Start Date: 2023-02-13 22:00:00 UTC
Planned End Date: 2023-02-13 23:30:00 UTC
Implications: Total Outage
Affected Environments: Production Environment
[1] https://developer.apple.com/documentation/sign_in_with_apple...
[2] https://support.apple.com/guide/mail/use-hide-my-email-mlhl4...
They already nearly lost their domain last year [1]
Wouldn't trust to put anything critical/business data in such when I see these kind of choices
I’m the author of the issue on Gitlab (small world, isn’t it ?)
Yes the message is confusing and I agree that .mov isn’t a MIME type but I was merely reporting the error message shown ( plus, they added .mov in their list of file types and had aliased it to .mp4 format, please see: https://gitlab.com/gitlab-org/gitlab/-/blob/master/config/in... )
So wherever the data is, the problem is still the same in my opinion.
Where there is troves of data and schematics about various companies infrastructures
Fortunately they removed Server licenses (you have to pay millions for the Datacenter ones or use Cloud) just in time for these new laws.
And they use dropbear to connect to the router to do changes from remote/customer service/online customer portal, if you're curious (you can see it in logs of the router, Inteno ones)
They say they are audited by NCC ( https://www.notion.so/Security-6c56b4854b624b0d8f36711018647... ) but I don't know how NCC missed this. They disabled TLS 1.0 few days after my message.
My second concern is that their .so domain is the TLD of Somalia (with all the risks it brings in case of malicious takeover), and .so zone doesn't even support DNSSEC, once again this is a big issue for me, especially for an app that hosts "personal data" (I see they also make calls on a .com domain, but the .so main domain issue still stands). Support told me they would change the domain in the future but still didn't happened.
It's only my personal security stance/paranoia, but my 2 cents of what happened with them.
Ok, this story is more about Google Play Store but I feel like there is maybe (in my opinion) some conflict and abuse of dominant position here too.
Felt like it was relevant will all the other Google stories in the last days (Nest for ex.)