57 karma · joined August 8, 2019
I don't have to bring a solution to notice that the system we have is not working. (That's not to say I don't wish I had one, I just don't.)
Maybe we'll get lucky and the next vote will fail, or maybe if it passes there will be providers that refuse to comply. I think if it happens, it's far more likely that most will cave, and a few will just pull the plug and stop offering service.
> They've tried to do this for decades and have failed.... Let's see how voters like it.
My "point" is that I thought the same way you did -- look what a mess Clipper Chip was, they always want backdoors but surely a voice of reason will show up, etc -- but something has changed. Couple the vote in the EU with the way the major tech companies reacted to GDPR (you'd be surprised how many sites simply block all of Europe rather than comply) and it's a wakeup call. There is a real chance of the bad guys winning here.
1: https://www.hackerfactor.com/blog/index.php?/archives/929-On...
https://www.patrick-breyer.de/en/posts/message-screening/?la...
ETA: in short, about a month ago they did get the votes, at least in the EU, and it's now "allowed" for providers to scan all content. In a little while, they're going to have a vote to change "allowed" to "required", and we have no reason to think it'll go differently.
That being said, one of two things is true. Either Apple does exactly what they say, in which case they are not able to perform server-side content / fingerprint scanning, or Apple is outright lying about only using their key on behalf of law enforcement. This latter case would open them to all sorts of legal liabilities, like a suit from shareholders for false reports. It would also require the silence of every Apple engineer who has ever been involved in at least their iCloud Photo program, and probably a bunch of server infrastructure as well. Additionally, they'd be legally obligated to report their scan results to the NCMEC but would have to do so in a way that doesn't give away that they're lying about how their systems work.
The only remotely plausible answer I've seen is that Apple wants to keep potentially-violating material out of their general storage, and flagged images are being sent to the review team instead of regular backup, but that's a pretty weak guess.
Perhaps the community could run a crowdsourced "keep them honest" service web service -- upload the latest illegal-in-China Winnie-the-Pooh meme, oh hey look at that, it's in the China-only version of the database, isn't that weird, etc etc. (Obviously you wouldn't want people "testing" images that are in the database for the actual stated purpose...)
> If information and resources referenced in a "security.txt" file are incorrect or not kept up to date, this can result in security reports not being received by the organization or sent to incorrect contacts, thus exposing possible security issues to third parties.
Yes, the information could change after you write the file. No, it is not possible to know, when you write the file, at what future point the information will become incorrect. The document should have a "last reviewed" date, then the consumer can decide for themselves if it has been updated recently enough to be trustworthy.
1: https://tools.ietf.org/html/draft-foudil-securitytxt-11#sect...
With menus, you have to use sub and even sub-sub menus for organization, and the user has to mouse over or use the keyboard to see the sub-options. Every sub(-sub) menu looks the same, maybe with a tiny icon to help find it. With the ribbon, every top level category naturally has major sub-groupings (horizontally), within which more important / commonly-used items can use larger icons, split buttons can be used to show a default action with related actions in a drop-down, and option-groups can be presented as a dropdown or expanded to show them all at once (think "view layout" in a file explorer).
I have to admit I had a negative reaction to the ribbon initially, but especially with the thoughtful integration into Windows Explorer it's really grown on me since. I'm not sure it's appropriate to replace every use of a conventional menu bar but I think it's the best fit in a lot of places.
It would of course be much better to have the previous tweet partially on-screen, possibly under a small gradient.
Let's say the GP's XML library has The GTA Bug, i.e. it uses a quadratic-performance loop when parsing. The bug will go undiscovered until any one consumer of the library a) sees enough performance impact to care, b) has the expertise to profile their application and finds that the library is at fault, and c) reports the problem back to the library owner so that it can be fixed. This combination might be unlikely but since only one consumer has to have all those properties, the probability scales inversely with the number of library users.