Forgot your password?
typodupeerror

Comment Yes, actually (Score 0) 97

The law says children cannot purchase or be sold cigarettes, which is not the same thing as saying children cannot smoke. Likewise, with this law, it is perfectly legal for children to use social media, it is just illegal for the companies to target children and have to provide a means of proving that they do something to try and stop children using their services.

Teenagers still experiment with cigarettes, light drugs and start drinking somewhere around the age of 15 like they should and politicians can keep on making a big fuss out of things which simply are not problems to distract from actual real world problems. Like social media.

Comment They could easily win back market share (Score 1) 60

IMHO, Mozilla should start competing with the rest of the ad blocking browsers, and commit to fully integrating adblock-rust explicitly for that purpose. They should tell the truth they've always been too scared to tell (for fear of losing income) which is that enshittification is unstoppable without going nuclear on the rampant commercialisation of the open Internet, and that people are going to stump up the necessary funds to enable Mozilla to deal with it.

The threat of using DRM to counteract such a move is a complete paper tiger, since it would ruin all the smart device integrations (especially on TVs and older games consoles) which can't be easily updated in the process, as well as break essential enterprise security scanning techniques to the point where it would relegate all but the most banal of entertainment-related services to obscurity.

It's time for management to be brave and grow a pair.

Comment Re: This is the most obvious use for thes glasses (Score 2) 31

Action cams are what people typically go with for that use case. Better quality video and audio with better runtimes for a fraction of the price, enabling folks to add them to helmets, handlebars/chest and more for multiple angles. These Meta glasses are actually worse than Google Glass and have greater cloud dependence. Maybe the only saving grace will be longer support than Google provided.

Comment Re:Good News (Score 1) 46

Britain has a historical defence pact with Ukraine, which unlike Russia, it is actually honouring. An inconvenient truth is that without the very defence pact formed as part of the Budapest Memorandum (which resulted in Ukraine relinquishing its nuclear arsenal and the UK being duty bound to provide aid) every major Russian city would have probably been (very legitimately) nuked in self-defence by now. Thankfully, it's just a bunch of drones sabotaging Russian national infrastructure, and it could all end tomorrow if Russia was willing to actually honour what it too had originally promised instead of trying to play a failed game of conquest.

Likewise, it was Russia's leadership which created the "Ukrainian Nazism problem" that it's complaining about by spearheading a violent uprising in the mid-2010s which turned fringe groups into recognised militia (e.g. Azov) who are now perceived as heroes of the people seen as acting in the best interests of the Ukrainian majority. It isn't just Ukrainians but also Jews, Muslims, Greeks, Crimeans, disgruntled Russians and Belarusians who all ended up uniting under the same banner that was originally considered to be Nazi-adjacent. The irony is that both the problem and the resulting "denazification" all happened in the blink of an eye, and now those so-called "Neo-Nazis" will be forever remembered for protecting Ukraine from an invasion by an evil Russian dictator called Vladimir Putin.

If I was Vlad, I'd be pulling out and claiming the military operation to be a success before integrating all those volunteer North Koreans into Russian society.

Comment Just use client SSL already (Score 1) 87

At this point, webmasters should accept very short lived client TLS keys signed by neutral third parties who take care of the proof of humanity on their behalf. Since security requirements for most websites are low, even places like libraries could issue them if needs be, and webmasters could choose how many or how few authorities they trust. The standard could be used creatively such that Valid To field is used purely as an limiter for initiating trust for the first time, providing convenience to users while making it easy to ban any bots which somehow slip through by banning a trusted entity or even a whole country if they are found to be on the fiddle.

Comment Re:How is the ID accessed? (Score 3, Interesting) 55

Every URL is sent to Microsoft with Optional/Full telemetry enabled when you don't use InPrivate Browsing and that includes your GDID. You can observe this in the Diagnostic Data Viewer, and as it's full URLs (not just domains) Microsoft knows every little search query too. Even if you scale back to security-only telemetry, Microsoft still receives full URLs (not just domains) not via diagnostic telemetry data but instead via Microsoft SmartScreen, and AFAIK that still includes a unique device identifier, with the legitimate reasoning being for their Intelligence Graph to identify malicious endpoints between sessions.

Likewise, all the telemetry related to the running of programs is queued and uploaded with Optional/Full even if no crashes occur, as well as diagnostic logs relating to software installs/updates, so Microsoft can see what devices have been running, when and for how long. All of that can be correlated once law enforcement is involved because they can subpoena third-parties to nab access logs which allow for the use of statistical analysis to reidentify the user.

All of this is legit, but the problem is that Microsoft abused our trust by violating their own Privacy Policy, since they claim not to identify people, but clearly did in this case.

Comment Published, irrevocable proof that Windows is spywa (Score 1) 69

Microsoft tied the device ID to the person, then looked up the telemetry associated with the device to work out how the device was used, then sent all that data to the feds, despite their privacy policy stating that device identifiers will not be used to identify people.

We must not forget this. They lied.

Comment Publishing includes a right of access (Score 2) 95

Publish a book, a song, a movie, or even a play, and you are legally required to make copies available to national libraries for archival in the countries you opted to publish them in, along with copies of accompanying scripts, manifests and documentation. Members of the public then have a right to access those copies for education and research purposes. DRM be damned there as well, as the library is freely allowed to use the analog loophole to break it when it gets in the way of legitimate archival.

Software developers and video game publishers should not get any special treatment here, and if scripts and manifests are not off limits, then source code and technical documentation should not be either. Thereâ(TM)s zero reason members of the public should be prevented from independently studying how any published work functions, irrespective of whether they have even purchased a private copy of their own. That is how it has always worked before and that is how it should continue to work in the modern day.

Comment A bug, is a bug, is a bug (Score 1) 17

We are at the point where every bug that can crash an application is treated as at least a DoS CVE of some kind, even if it has an extremely low rating. In that sense, LLMs finding these bugs, even if automating a fix is not possible, is still a good thing from a reliability improvement standpoint.

The sad part is when folks see all these reported bugs and decide to abandon the software altogether as a result, which is something we have been seeing with kernel drivers for old hardware which, quite frankly, could have been marked as post-production, carrying a taint flag of some kind if loaded. A mechanism needs to exist to flag these unloved drivers with known issues for a year or two and to maybe gate them off by default using a one-way sysctl, a kernel command line or something else which does not rely on blacklisting so we can have the best of both worlds..

Comment Suppression makes misinformation worse (Score 1) 134

We saw this stupidity in full action with COVID, and it created problems for people trying to do their bit to educate people. At the time of peak pandemic, if you used a search engine, you would only get NHS or WHO results unless you started adding specific academic keywords which most people would not use. If you used YouTube, the results were further manipulated to always favour specific content by a handful of creators unless you explicitly wanted nutty content. The result was a massive distrust by a public who wanted to find out actually useful information, not vague facts the government thought the public ought to know, as they could see everything was being manipulated by companies at the whims of our government without any transparency over what was deliberately censored and why.

It seems they have not learned their lesson since then and seem hell bent on making the public distrust them further by applying this same flawed principle to presumably every search relating to a trending topic of any national relevance. This is not just a bad look, it is a very bad idea, especially given a string of recent events where fast news cycles resulted in somewhat inaccurate commentary and glaring omissions of facts from reporters and journalists alike.

The true fix for this is to put an end to the attention economy, not to try to divert attention towards likes of Rupert Murdoch and co.

Comment Just refuse to help cloud providers (Score 1) 38

Stick to testing installable software only, that way if the maintainers decide not to pay out, immediately publishing a vuln with or without a PoC is still ethical as it gives sysadmins a chance to mitigate before anyone else finds it. When it comes to cloud hosted crap, you have no recourse, therefore, do not help them in the first place.

Comment Re:Oh dear, oh dear, oh dear (Score 1) 147

You asked for a citation, I gave you a citation which didn't represent one isolated incident but an ongoing chain of them which was considered serious enough for the government to use it as part of their justification to mandate the future scanning of every photo everyone ever takes with their smartphones from now on. Feel free to also gloss over the girls who abused the trust of boys without their consent in order to sell videos if that helps fit your narrative.

Regarding physical store transactions, you don't have to provide ID to buy alcohol in the UK unless you look under 25 (also known as Challenge 25) and nobody is required to record face in order to perform said verification, your purchases usually remain completely anonymous, as they should. Also, in England, we allow drinking alcohol in private from the age of 5 because the concept of underage drinking enforcement came about in response to drunk youths in the street causing trouble. So the sales restrictions aren't even there to stop children from consuming it, they exist to stop troublesome behaviour in public, which is a key differentiation you also seem to be glossing over. Regarding tobacco, the only reason people will now need to supply ID is to prove they were born before a certain year, since Starmer wants to ban smoking outright via raising the legal age by 1 year for every passing year in perpetuity.

If you want to equate how you want the Internet to work and match it up to how physical in-store transactions work, at least educate yourself on how those transactions actually work first, before calling people paranoid for pointing out the flaws, especially when you're conversing on a tech website where the EFF and others have already debunked the claims you're making.

Slashdot Top Deals

Yet magic and hierarchy arise from the same source, and this source has a null pointer.

Working...