There a plenty of great self published author on Amazon.
that's just off the top of my head.
There a plenty of great self published author on Amazon.
that's just off the top of my head.
The Placebo Effect is just our poor bodies reaching some limits vs more and more clever scientific studies.
As I understood it, it was self healing abilities only triggered by "someone gives a damn about me" that we don't easily access every day to fix other problems.
So having computer programs just goes more towards the whole "look, it's now on a computer" we've seen in darker scenarios. I'll stay positive on this note.
If you just stick 300 fortune cookies into a computer program, a few of them will strike home and then you get "therapeutic benefit". (I know, because I have a file of over a hundred of them, from asking my Chinese restaurant to give me a bunch each time. A few of them are really pretty good.)
Studies keep trying to go super narrow to carefully limit "complexity" but I am beginning to think the "Scientific Method" is on the verge of missing "Emergent Results" when they risk small details but leave behind controlling micro-scenarios.
Sideways from the Slashdot tradition, I didn't read the article because one look at the summary says it's too narrow, and it's become the Press's job to "expand them". Some journalists try hard, a few are hacks.
Much more broadly, I have smashed together a few projects I know have helped me.
"What sort of moron uses their real name on an internet forum?"
Welcome to Facebook and Google's push!
Reversing 20 years of your type of common sense!
I know, I grew up with too, then it changed about 2007.
Again a guess, but I bet this is about "how much it costs us to upgrade our system".
Underscore I can see, but Space used to be a character that messed up a lot of systems. And I frankly don't have any 20 character passwords, so maybe people lowered it so that users would have any hope of ever remembering their password, however bad it may be.
Quick uninformed guess, sounds like someone's sloppy programming problem.
I'll defer to my betters here but it sounds like when someone slammed out the system they just picked some number like 11 for the password length and then someone else did the best they could by making it require lots of stuff.
Years ago in a weak variant of this whole thread, I designed a system of using some nine passwords for the entire net, and for whatever reasons I am to senile to recall, one email account got a weird password that changed a couple of times until I couldn't get in. (Including one suspicious moment but that's another post.)
But fortunately I made my "security questions" sufficiently strange yet unforgettable that after two hours on hold, I got into Yahoo Customer service and fixed it. (For now.)
But you have a point that, that was a "backup account". If the primary ones ever got hacked, people would have access to tons of stuff.
I'm def of the school of "use your passwords every time so you know them" and haven't looked into password managers that sorta bother me. It's one reason why last quarter's Heartbleed story made me grumpy - is every site in existence gonna make me flip my password system now? I don't have a new one yet.
"True. I should have said major corporate standards when I said government. But because of the way the payment card industry works, if FEELS like government. Complete with not following its own rules and having rules for the sake of rules."
Sorry, but I find this a bit of a big error to make.
I'm really torn on who I dislike more, but to *confuse* corporate policies and govt policies feels like a big step backwards!
(Your choice of which) one punches me in the gut and one holds me by the throat, but to *confuse* them doesn't feel right!
I'm old school here.
What is all this "banking info"!? I only do about five things with my bank, and 3.8 of them I can do on my phone just *dialing the automated number*.
Check my balance, pay something to my credit card, look to see if a check has been cashed that shouldn't have been (I've hired a bit of house help), and a couple other things.
When it gets a little weird I hit 0 or say "Representative" to do a couple of fancy things.
What I spend is in my head, I don't need a huge online report to tell me. My five bills are on my desk (including last month's late one!)
I have resisted BOA's attempt to get me to go all online-automated. I theoretically set up a couple of accounts to be online to save money, but not because I need a fancy account. When you wanna know what you can spend, you make a 1.7 min phone call - what else do you need to do?
"requiring passwords to be at max 5 characters. MY BANK!!!"
I hope not. Even the worst services I have seen want 8 characters. I'll leave it to my betters how fast a cracker program can bust 5!
Okay, off-topic but I can hack a 1 point karma drop.
Bill, what even is that url?
What is even the point of "preview.tinyurl.com"?
It goes to an Evening Sun article by Craig Paskoski here:
I'll reply to you, as you're the closest to the angle I was going for.
Cross-posted from another site, with two more sentences here.
Okay, picking my words a little and hoping I get my tone right...
I get that Google (and Facebook and all kinds of other gangs) are *selling info*. It's sleazy, but to me that's "grey hat". It's "we're psychologically manipulating you to make money, but you knew that but we made the services nice and fun/useful so you don't care". I've been reading a huge Star Trek DS9 Re-Watch overview, and that feels so like a Quark move - he's devious but eventually even he draws his lines.
Secret silent software bugs that only X number of governments even know exist is a whole other level of Black Hat. (Really, somewhere in the combo of Heartbleed and the True-Crypt mess I got grumpier than I have been in a while.)
So Google isn't some poor 12 man op with a lonely tech who was beaten by big guys - behind the sales guys there's a *lot* of tech crunching firepower there. So *maybe* the Agencies have a bit of a lead on them, but I'd bet not as big as those Agencies thought.
It's a fascinating twist - Govt can beat up "little guys" a few at a time in a Divide and Conquer strategy, but what if this story catches on, and then Microsoft and Facebook and Apple and Samsung and your choice of others jump in?
(I put Samsung in there because software bugs know no boundaries, so it's specifically a test of geographic negotiations beyond the US level.)
Short Selling jokes aside, can the US even manage to indict the CEO's of all of US tech? Their dealmaking might just be on the verge of coming to bite them. (There was a TV series about all that, corps, totally owning govt openly and outright.)
When we're not busy snarking in the Basement or the Living Room, having a gaping security flaw in software isn't good for any of these companies. So maybe (making up a name) Gennady Li Chandarovskiyij-Maharujshi is the greatest programmer alive at one of the Agencies, but can he really stand up to a world wide team that's now pissed off??
Going all story fiction for a moment, imagine it:
All these companies, led by the big dogs with little guys lending a spare hour;
CEO's around the world getting royally pissed and saying "our products are dominant enough and we have time to put away our micro-jockeying. Let's spend an entire year and 700 billion dollars/whatever to clean this mess up. Grab anyone who has any legit idea whatsoever about software security and let them do whatever they want (jokes aside), no questions asked including extra perks like the 90's like croissant sandwiches in the break room."
US Govt is slowly winning the PR war against "Anonymous", but what if the Big Tech companies with tips from millions of freelancers all unite and say "Thanks for all the fish, yummy, now watch what you made! We have a worldwide "team" of over a *thousand* software people (and four space aliens, only three of which you know about.) Do you *really* wanna keep doing this? Or can we just get back to selling people's info for money?"
At least in my imagination I wanna believe we're on the verge of Tech calling Govt's bluff that they've been going "Divide and Subdue" too long, and the beautiful part is all the bribery is (mostly) illegal - how can they even pretend to shout about 770 companies and 12,345,845 freelancers all spending an entire year on software security?
So that's my message of daydream hope!
You're almost the only one addressing the legal-theory side.
Stepping aside from the technics, what becomes the theory for this?
"Material that is believed to be owned by the recipient but is in fact leased or rented may be removed by the lessor/provider if it causes reputational damage from the sender (and maybe to other parties?)"
Lawyers have a fun job. (Things to do with a 170 IQ). Take can take one word and use it to create billions of client dollars. There was that one other article in Rolling Stone about how Goldman Sachs borrowed one paragraph from their federal government bailout, jammed it into a 15 year old finance bill, and now they get to run oil pipelines while bidding on oil futures and stuff.
Or the one from earlier today where that review board authorized the NSA to keep spying by abusing the words "adequate" and "reasonable".
The report is a bit more clever than that, and *parts* of it are actually good. It's certainly more info than I ever knew before, and than they would have ever released before.
The way these "Devils in Details" landmined reports work is that 95% of it is legit, and builds a legit case towards
Try looking near pages 98-99.
This is the paragraph that echoes this entire thread:
"On the other side of the coin, the acquisition of private communications intrudes on Fourth Amendment interests. Even though U.S. persons and persons located in the United States are subject to having their telephone conversations collected only when they communicate with a targeted foreigner located abroad, the program nevertheless gains access to numerous personal conversations of U.S. persons that were carried on under an expectation of privacy. Email communications to and from U.S. persons, which the FISA court has said are akin to âoepapersâ protected under the Fourth Amendment,426 are also subject to collection in a variety of circumstances."
At this point everyone is clamoring for the followup to be "Unconstitutional so get rid of it." As they say, "always put one concession to your opponent's position in an argument", so here I say, "it is not possible under any form of intelligence work to have *zero* US-US information showing up, such as because any email to that sketchy girlfriend with a CC to your US buddy on it, drags him along along for the ride." Of course that's a minimal data point, but this thread has been about the issue of Non-Zero data collection.
*However*, then they threw their landmine in.
Over on page 99:
"The government has acknowledged that the Fourth Amendment rights of U.S. persons are affected when their communications are acquired under Section 702 incidentally or otherwise, and it has echoed the FISA courtâ(TM)s observation that the implementation of adequate minimization procedures is part of what makes the collection reasonable. (See footnote 433)"
So before everyone jumps on the word "reasonable", *that's* their landmine. You get Schrodinger's Cat scenarios with that email because as soon as they even see whose names are on it, one to Osama Bin Laden's hot neice's Iranian cousin staying in the Netherlands, and one to your radical US buddy, they *already have* metadata! So they decide to open it, whereupon it contains some nice NSFW Rule34/Rule35 pictures, and a PS memo on the bottom of it with a piece of info that actually qualifies as intelligence. Great. Now you have an email that pisses off at least four countries. What do you do with that?! (After you finish grinning lewdly and more to the pictures!)
So the *actual* word to mess with is "Adequate". After you finish laughing at my scenario, is that an *adequate* acquisition of US citizen data? I don't know. So saying "Aha! A right was violated, abolish the entire agency!!" is not the answer. The only one I can think of is a percentage one of some kind, such as "less than X% of US communications were collected, as verified by an auditor that you actually believe." Then we can all start over deciding what that percentage is.
In general I applaud the EU ruling *if* it really gets implemented fairly. But there's all sorts of wiggles to mess around with.
We've been focusing on "that one guy" but look at this note way at the bottom of the article:
"It is only a few days since the ruling has been implemented - and Google tells me that since then it has received a staggering 50,000 requests for articles to be removed from European searches."
And that's 50K requests in a few days.
Google can afford to hire "the army of paralegals", but does the ruling extend to smaller services? You can delist-bomb a small site out of existence when someone manages a "DDOS Distributed De-List of Service" attack on every article in their entire catalog. Then you get games where people try to de-list each other's materials.
Not that I am a fan of Google, but I can bet a senior lawyer at Google is saying "well hell, besides the cost, if we have taken down seventeen million articles on all kinds of topics, there goes our ten year competitive advantage of useful searches."
"More than any other time in history, mankind faces a crossroads. One path leads to despair and utter hopelessness. The other, to total extinction. Let us pray we have the wisdom to choose correctly."
Real Users hate Real Programmers.