Wow. Using the same logic as that ruling, donating to politicians is not protected by the 1st Amendment unless you also include a memo making clear your intent...
This feels like more "I'll know it when I see it" but with intent instead of porn.
2,031 karma · joined June 26, 2013
paul at blacksheepwall dot com
Wow. Using the same logic as that ruling, donating to politicians is not protected by the 1st Amendment unless you also include a memo making clear your intent...
This feels like more "I'll know it when I see it" but with intent instead of porn.
> Swedish green-tech firm SaltX Technology demonstrated that it can produce clinker with its Electric Arc Calciner: a proprietary system similar to the plasma torches widely used by automakers and other manufacturers for cutting metal. Plasma torches pass an electric current through a jet of inert gas, typically nitrogen or argon, which ionizes the gas and heats it to temperatures over 20,000 degrees Celsius. In June, SaltX announced a partnership with the Swedish limestone supplier SMA Mineral to accelerate commercialization of its technology.
Article: https://arstechnica.com/science/2022/11/the-road-to-low-carb...
Library + https://en.wiktionary.org/wiki/-arch
The only sane solution I've seen to that is to make everything go through security review, even if the review is a simple "we don't need to review this." If everyone knows everything needs review, it makes it very hard to forget about it and incentivizes people to involve security folks with their projects ASAP in the hopes of getting review done early on / avoiding being blocked by it.
You'll always need exceptions to the rule, so you can have some sufficiently high up VP or similar sign off on releasing things without review (and with the caveat that it's still going to get reviewed, it just won't block release), but that's a lot easier to manage than dealing with random developers deciding it for themselves.
It also helps a lot to have a culture where developers learn about security too, but just like researchers and ethics, they'll have perverse incentives to downplay/ignore risks so you still need other, differently incentivized people, to enforce "checks and balances."
It sounds like IRBs are not designed to review all or even most (animal?) experiments and I think that's unfortunate. It seems like a win for everyone if we get better ethics coverage.
It's not particularly intuitive if you're not used to high level math or functional programming, but it really is a lot simpler (not that it doesn't have downsides/leaks in the abstraction, but that's another discussion).
Apple isn't tunneling everything through a VPN to track it.
I thought I had read a study about talking to people in your car versus drinking, but here's a similar one with talking on a phone versus being drunk: https://www.ncbi.nlm.nih.gov/m/pubmed/16884056/
So while they might lose customers like you, there is clearly ridiculously large piles of money up for grabs if they diversify their products, rather than remain specialized. And, of course, any sufficiently good specialist is at risk of being acquired by one of these behemoth generalists.
> I expect that all add-on developers recognize and respect this concept.
There's a lot of subreddits configured to only allow text posts, one of the subreddits I frequent is configired to delete your post if it is an image post that doesn't have a top level comment by the poster, as the subreddit rules require all image posts to have text descriptions (to guide conversation/mitigate low quality posts).
I don't Tumblr so I don't know the full use case for tags, but from what you've described it sounds like flair: https://mods.reddithelp.com/hc/en-us/articles/360010513191-P...
More or less the same tactic Amazon used for search results: Return useful/functional results for a few years to train you users to trust what is near the top, then start putting promoted products at or near the top and generally ordering the search by what increases your revenue the most, rather than for any user-oriented goal, AKA "sort by relevance".
Also the same thing Amazon did with prices in general, get people used to thinking you're the market with the best price/deal, etc.
HN discussion (2015): https://news.ycombinator.com/item?id=9427856
Hmmmmm, that sounds familiar... https://en.wikipedia.org/wiki/Social_Security_number#/media/...
While it wasn't law, I don't see why legislature wouldn't renege on their promise to not use a unique identifier, already conveniently assigned to all people, for identification purposes.
Edit: Looked at it a bit more, the non-water giving adjacent US soldier is not holding the guy (I think his hands are bound behind his back by cuffs/rope/zip ties/whatever).
I don't know what features U2F tokens support, but if they can be password protected I don't see why U2F being the only auth factor would be bad. You could even have the token itself attest to being password protected so you could require that of users before allowing them to disable non-U2F passwords.
Finding out type definitions is made massively easier with an IDE, but even without one there's an extremely high chance any library you're using is going to at least have autogenerated docs sitting on disk somewhere or mirrored on a crappy website. Maybe you need to clone their repo and build the docs yourself, but even that's pretty unlikely as most language ecosystems have a package manager + docs website or man pages.
I don't really develop anything without at least a third of my screen real estate dedicated to documentation and I don't see "RTFM" as a meaningful or undesirable barrier to programming correctly.
> Now you don't need to know or care about how "uniqBy" works, or the exact details of how you should or shouldn't use it...
I don't follow you. What if "uniqBy" only works properly on sorted lists? You'd never know that based on the type (unless you've got dependent types) and if you're not reading docs on how the function works (the types check/it compiles!) you're going to be in a world of hurt at runtime. Intuitive programming may be easier but it's a heck of a lot more dangerous unless your compiler is intuitive too (i.e. makes the same intuitive assumptions that you do).
> ... and if you try to pass 2 arrays with different items, it will yell at you because that's not right, something that type inference can't determine (at least not with Flow's typesystem)
That's entirely Flow's fault. There's no reason a "proper" type system couldn't deduce that the same type would be needed for both arrays, the `oldItems.concat()` call should have a type definition something like (functional for brevity): concat(Array<T>, Array<T>). Nothing ambiguous about T being the same type.
Additionally, as another commenter pointed out, the majority of assets are in formats that support native compression (textures and audio) and thus won't compress too well a 2nd time.
That seems like a very reasonable ability considering that "Full Security" mode says, "This mode requires a network connection at software installation time."
I'd guess it's a challenge/response deal with the T2 in your Mac issuing a challenge to Apple. The response could be as simple as Apple signing the signature of its software with the challenge, i.e. response = sign(challenge + sign(MacOS))
Presumably it's whatever Apple currently does for iOS, as my understanding is that it has the same downgrade protection feature and that is part of what makes jailbreaking so precious, you need to be on the vulnerable version of iOS in the relatively short window it's still being served by Apple (aka before Apple patches some or all of your exploit chain).
and
> Transparency around every step of the design process — from logic gates to boot code to the applications — gives us confidence in the defenses we're providing for our users. We know what's inside, how it got there, how it works, and who can make changes.
This should be a boon for security researchers! I'm really looking forward to what comes out of fuzzing that whole subsystem. I imagine attacks against the secure enclave would be a lot easier to perform (and ideally, report to Apple) if it was feasible to attack it with pure software.
Users of this product will be able to enter the identity of their perpetrator into the escrow. This data can only be decrypted by the Callisto Options Counselor (a lawyer), when another user enters the identity of the same perpetrator. If the perpetrator identities match, both users will be put in touch independently with the Options Counselor, who will connect them to each other (if appropriate) and help them determine their best path towards justice. The client relationships with the Op- tions Counselors are structured so that any client-counselor communications would be privileged.
edit: from https://www.projectcallisto.org/callisto-cryptographic-appro...
If you're on Android, you can disable update notifications from the app store settings.
I thought China was famous for extremely short turnarounds for industrial engineering edits, so it seems plausible that they could manufacture the boards in a reactionary way and not need to do much in the way of logistics to get them to their targets.
How long are recordings normally kept? I would assume at least a few days for mundane flights (storage is cheap, isn't it?) but any sort of incident similar to this I would assume they keep recordings for much longer, if only for internal purposes.