Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
snowwolf
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
31.
▲
by
snowwolf
6y ago
> EasyJet said it first became aware of the attack in January. vs > The GDPR introduces a duty on all organisations to report certain types of personal data breach to the relevant supervisory authority. You must do this within 72 hour
32.
▲
by
snowwolf
7y ago
Relevant: https://martinfowler.com/articles/effective-video-calls.html
33.
▲
by
snowwolf
7y ago
It cost me £25 for replacement cushions which they fitted for me in store. https://www.bose.co.uk/en_gb/products/headphones/headphone_a... Which I had to replace after 2 years of weekday daily use of 3-4 hour
34.
▲
by
snowwolf
7y ago
And Apply Pay in London is even better as you don't even need to authenticate the payment. https://www.apple.com/uk/apple-pay/transport/
35.
▲
by
snowwolf
7y ago
What happens when the customer contacts you for support and is using the shielded email service. You don't know the "real" email for the account, and the customer can't email you from the "shield" email. So you
36.
▲
by
snowwolf
7y ago
They aren’t trackers in that respect. Read up on the companies in question. They basically provide analytics to mobile apps so they can better understand their customers to allow them to improve the experience of the app. It’s the equivalen
37.
▲
by
snowwolf
7y ago
The thing is they aren’t actually selling that data. All the services mentioned are paid services that ring are paying to use. And ironically they sprang up to fill a need because Google and Apple made it almost impossible to do app instal
38.
▲
by
snowwolf
7y ago
I wonder why Ring is being specifically called out for this practice. This combination of “trackers” are very common in the app ecosystem as they perform much the same analytics functions used on the web ecosystem (e.g. Branch offers ad cam
39.
▲
by
snowwolf
7y ago
Just thought I should point out that Libreelec is Kodi. It’s just a stripped down OS with just enough on it to run Kodi so it can be fast and stable.
40.
▲
by
snowwolf
7y ago
GDPR has given some good thought to automated decision making and has guidance that I think all companies should follow even if they don’t need to follow the GDPR regulations. “We regularly check our systems for accuracy and bias and feed a
41.
▲
by
snowwolf
7y ago
Is it easier to submit extensions to the Microsoft store? Last time I looked it was very closed off to a selection of hand picked extensions. To be fair this was probably over a year ago.
42.
▲
by
snowwolf
7y ago
Yeah. My guess is 3rd Party provider is AWS S3 and a DB backup was accessed.
43.
▲
by
snowwolf
7y ago
Something like this https://github.com/die-net/http-tarpit
44.
▲
by
snowwolf
7y ago
I have things like Postgres, Redis, Rabbitmq, etc running in docker on my local machine for development. I have a recommended configuration/install prebuilt and kept updated for me, and if I want to test my apps against a new release o
45.
▲
by
snowwolf
7y ago
> Unless the cost equation changes, it is hard to get business users to change their priority With GDPR getting teeth (see recent fines of BA and Marriott) for security breaches, I think this is the beginning of that cost equation changi
46.
▲
by
snowwolf
7y ago
I have a feeling many enterprises are going to be rapidly expanding their security and privacy teams and paying top dollar.
47.
▲
Intention to fine Marriott more than £99M under GDPR for data breach
(ico.org.uk)
230 points
by
snowwolf
7y ago
|
168 comments
48.
▲
by
snowwolf
7y ago
Yeah, the uploading of copyright infringing content is one aspect, but I was also wondering about just uploading rubbish and somehow generating fake listens or tricking real users into listening to your track (game the ranking algorithms to
49.
▲
by
snowwolf
7y ago
I’m not familiar with the process, but could there also have been a fraud aspect (not copyright) to this that wasn’t worth the effort required to prevent? Upload “songs”, generate lots of listens, get paid.
50.
▲
by
snowwolf
7y ago
As long as the ONLY processing of the data is for fraud detection/prevention, then GDPR specifically allows it as a “Legitimate Interest” Recital 47: “The processing of personal data strictly necessary for the purposes of preventing fr
51.
▲
by
snowwolf
7y ago
So there's a few things to unpack here. > with their own malicious version, designed to inject adverts into users’ browsers Your very first example wouldn't be prevented by these changes. > 42% of malicious extensions use th
52.
▲
by
snowwolf
7y ago
So lets take an alternative look at this. The justification is that this improves privacy, security and performance. For who? I use 2 extensions, an Ad Blocker (uBlock Origin) and Password Manager. uBlock Origin has over 10M installs and th
53.
▲
by
snowwolf
7y ago
Just blocking capabilities will be restricted to enterprise. From the manifest V3 design doc ( https://docs.google.com/document/d/1nPu6Wy4LWR66EFLeYInl3Nzz... ) “API Changes WebRequest: Restrict the blocking capabil
54.
▲
by
snowwolf
7y ago
This seems like massive spin. Their primary argument doesn’t wash. As far as I understand it the web request API will still exist and still allow extension developers to view all request data. They just won’t be able to block the request an
55.
▲
by
snowwolf
7y ago
Personal email accounts also tend to leak into having access to employer systems, especially in tech. For example a lot of people use their personal email for Github, so once an attacker has access to your personal email they can move later
56.
▲
by
snowwolf
7y ago
Agreed. But you can hack their replacement programs to extend the life of the newer (post 2015) models. There are a few battery replacement programs on MacBook Pro’s (e.g. https://www.apple.com/support/13inch-macbookpro
57.
▲
by
snowwolf
7y ago
In the EU this is a violation of GDPR if true.
58.
▲
by
snowwolf
7y ago
That doesn’t help stop the attacks using breach lists that are even more prevalent. You could start with email warnings of suspicious activity and fine tune the model parameters based on feedback from false positives. But generally a login
59.
▲
by
snowwolf
7y ago
While the fault lies with the users for not following security best practices, including enabling 2FA there are things gitlab/any site can do to help defend against these sorts of attacks. Some suggestions: Treat logins from datacenter
60.
▲
by
snowwolf
7y ago
In Europe at least it would probably be a violation of GDPR to not actually delete it on request of the user if it is considered personal data.
More ›