Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
4oh9do
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
4oh9do
4y ago
> Activists also use virtual private networks, which can minimize data collected about browsing, and encourage Polish women to contact them on encrypted channels like Signal. They delete all online conversations after the person has had
2.
▲
by
4oh9do
4y ago
I don't understand the cognitive dissonance seemingly on display by the game collector throughout the article: > He’d had a kind of philanthropic hubris as an owner and collector, someone who never gave a second thought to keeping
3.
▲
by
4oh9do
4y ago
I am not making a claim, I am laying out how the process could hypothetically occur, hence the use of "would" in my post. I'm curious, however, why did you not make a similar post to the parent comment...in that the parent co
4.
▲
by
4oh9do
4y ago
> This is a public blockchain analytics service that has nothing to do with Coinbase's other services. Are you familiar with the concept of parallel construction? It's a tactic LEOs use when they don't want to reveal how t
5.
▲
by
4oh9do
4y ago
Kind of like we find out weekly what happens when Facebook decides it needs to enforce US foreign policy for its worldwide users?
6.
▲
by
4oh9do
4y ago
Yeah, I'm aware of the any number of infinite Evil China (TM) hypotheticals. Let's put the sinophobia on hold for just a second, and answer my question: what are the practical (meaning documented) privacy/security concerns wi
7.
▲
by
4oh9do
4y ago
What are the actual privacy/security issues with TikTok, concretely? Citizen Lab published a report last year - https://citizenlab.ca/2021/03/tiktok-vs-douyin-security-priv... - which found that the app does
8.
▲
by
4oh9do
4y ago
> You're going really hard in the paint to defend Chinese genocide of Muslim Turkic people. Where did I do so? Please either provide a quote of me doing so, or retract your statement as it otherwise amounts to libel. To clarify if s
9.
▲
by
4oh9do
4y ago
> Why is Beihang involved in hosting the W3C? Why is MIT? Do you not have an issue with them also getting funding from the American defense department? Or if you're concerned with the open web, do you not remember when they persecut
10.
▲
by
4oh9do
4y ago
> Government should mandate only allowing SSN for tax identification purposes. CafePress was presumably collecting SSNs precisely for tax identification purposes.
11.
▲
by
4oh9do
4y ago
> Again, 2FA isn't an account recovery process at all; it's a reason you need account recovery. Your reading of the FTC text seems to be that you think the FTC has conflated account recovery with 2FA, but I don't think tha
12.
▲
by
4oh9do
4y ago
As per NIST 800-63B: > To maintain the integrity of the authentication factors, it is essential that it not be possible to leverage an authentication involving one factor to obtain an authenticator of a different factor. For example, a m
13.
▲
by
4oh9do
4y ago
> But requiring 2FA tokens is not a universal practice. It is not universal practice, but it is industry-standard, so I don't particularly understand why it is surprising that the FTC is recommending that CafePress adhere to industr
14.
▲
by
4oh9do
4y ago
What I mean is that executives value their personal livelihoods above money, though the two are often correlated. Therefore the punishment needs to strike at the core, their personal as opposed to financial freedom. "Big" fines fo
15.
▲
by
4oh9do
4y ago
It's all Monopoly money to corporations. If there is no fear of an actual corporal punishment, then there is no personal skin in the game, so to speak. An executive who causes a corporation to be fined may worry about losing their job,
16.
▲
by
4oh9do
4y ago
> But the simpler fix here is just to require password reset emails, not to mandate multi-factor authentication. Password resets lead to iterative passwords, which lead to password reuse, which lead to email compromise, which leads to i
17.
▲
by
4oh9do
4y ago
Bullshit like this will continue happening en masse until there are mandatory prison sentences for C-suite executives for negligence and malice like this.
18.
▲
by
4oh9do
4y ago
What does "inviting" mean? It sounds like it means "Facebook wants free labor instead of paying for formal and expensive security audits".
19.
▲
by
4oh9do
4y ago
Not my list, but I use https://gist.github.com/0XDE57/fbd302cef7693e62c769#privacy-...
20.
▲
by
4oh9do
4y ago
> Firefox security patches are applied to prevent vulnerabilities Sure, but at what rate? If Mozilla releases a critical patch today, and the core maintainer responsible for build maintenance is away on vacation for two weeks, what happe
21.
▲
by
4oh9do
4y ago
My concerns with ostensibly privacy-focused Firefox forks: * Needing to constantly monitor whether the fork is being actively maintained, or if it's a vanity project which abruptly stops/slows down updates when its owner/prin
22.
▲
by
4oh9do
4y ago
Those things aren't particularly news to me. My question is more along the lines of, it seems to me that it's OK (in the sense of being tolerated by the public and legal) when corporations engage in this kind of behavior, but woul
23.
▲
by
4oh9do
4y ago
> the idea that only the data that needs to be collected for a certain purpose should be collected. The US has a similar stature, the Paperwork Reduction Act, a "law governing how federal agencies collect information from the Ameri
24.
▲
by
4oh9do
4y ago
I guess the incongruity is then more along the lines of corporations being allowed to engage in stalking, but not persons, despite the fact that corporations are legally persons.
25.
▲
by
4oh9do
4y ago
One thing I never really understood is the incongruity between online tracking and real-world tracking, the latter of which we would call stalking. If you followed around the owner or employee of a tracking...err "advertising analytics
26.
▲
by
4oh9do
4y ago
Don't shift the goalposts. The conversation is not about legality or illegality of certain actions, but about how this fictional "international organization" does not want any US company to have their personal data. The point
27.
▲
by
4oh9do
4y ago
So? Most of this is negligible, and can be shielded if the donor cares about this level of privacy.
28.
▲
by
4oh9do
4y ago
> The international group of donors does not need to give up any personal data to read a tweet https://developer.twitter.com/en/docs/twitter-for-websites/p... > What information does Twitter collect thr
29.
▲
by
4oh9do
4y ago
> why does the entire thing need to be without a company? Because OP said: > an international group that doesn't trust US based corporations with their personal data That is not realistically possible in today's world, and i
30.
▲
by
4oh9do
4y ago
> Have you ever encountered a project actually fundraising in this way? https://www.eff.org/files/2020/05/27/eff_membership_form_202...
More ›