Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
c4mpute
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
1.
▲
by
c4mpute
3y ago
> The German law you cite about getting a password is applicable if you plan to or actually access data they are not authorized to. Which is not the case (assuming they do not). Usually this is the case. The user and Microsoft are not th
2.
▲
by
c4mpute
3y ago
No, they are not. GDPR notices (which this is) must be understandable to the layman. Including all consequences like "this will also allow access to other services secured with the same university/company-wide password". This
3.
▲
by
c4mpute
3y ago
It is even worse. MS doesn't need to do anything. They don't need to pay anyone off. EU bureaucracy is extremely strongly wedded to MS products like Windows, Office, Teams, Outlook etc. As are all EU national bureaucracies and pub
4.
▲
by
c4mpute
3y ago
Because a DNSSEC attestation is usually public, except if you maybe use NSEC 3 and hide the RR behind some random name.
5.
▲
by
c4mpute
3y ago
No. Ambiguous consent is no consent. And continuing to send DNT is ambiguous, because the tracker can not distinguish between intent and accident.
6.
▲
by
c4mpute
3y ago
Would be irrelevant, because the DNT-header will be sent with every request, so for all practical purposes will be later than any other kind of consent.
7.
▲
by
c4mpute
3y ago
GDPR specifies tracking to be necessarily default-off and opt-in anyways. Therefore the browser sending DNT:1 by default would just repeat the legal status quo. A tracker could not successfully argue that this is to be ignored, because the
8.
▲
by
c4mpute
3y ago
Agreed. Torx might not be ideal, but it is widespread and (relatively) cheap. And miles better than anything else that is widespread and cheap.
9.
▲
by
c4mpute
3y ago
If an attacker knows about some exploit involving someservice.com, which you are using. That attacker will try to find out where he can use that exploit of his. E.g. he might use something like shodan, google or DNS to get a list of users o
10.
▲
by
c4mpute
3y ago
Ah, now I get it. Yes, that is a possible problem.
11.
▲
by
c4mpute
3y ago
Even stupid age-old BIND zone files can be version controlled and commented. Anything inferior to that level of documentability should be an instant no-no.
12.
▲
by
c4mpute
3y ago
This kind of thing is pointless against a targeted attack. But it can hide you long enough in case of zero-days/fresh unpatched vulnerabilities because attackers will first target the more easily visible victims.
13.
▲
by
c4mpute
3y ago
You could use your DNSSEC signing key to sign a validation message (offline, because that doesn't work over DNS).
14.
▲
by
c4mpute
3y ago
Domain validation TXT records are poor infosec hygiene. If used at all, those records should never include any hint as to what service they are intended for. E.g. the record should NOT be: example.com IN TXT "someservice.com-validation
15.
▲
by
c4mpute
3y ago
Double or triple that of a car, for a small plane, because of the higher fuel consumption. But this only affects avgas, which is high-octane gasoline for propeller-driven aircraft. Jet-A1, which is light diesel fuel or kerosene-like for jet
16.
▲
by
c4mpute
3y ago
The LibreOffice CSV import is configurable. The Excel one isn't. You can do things in PowerQuery, but that is far from obvious and still buggy. Not to mention all the woes after import, like date/time auto-interpretation and autoc
17.
▲
by
c4mpute
3y ago
Yes, I have. What Excel is still lacking is an easy solution for the input side. You can bind tons of data sources, but all are weird, hard-to-use, manual. There is no easy "grab this from that website, get the current data of what I j
18.
▲
by
c4mpute
3y ago
The problem here is that you usually do not have ~1k users with all the same requirements. You have 200 groups of average 5 users each, all with their own department-specific, country-specific or workflow-specific requirements. Of course a
19.
▲
by
c4mpute
3y ago
To be somewhat constructive: What you rather should have done is not create more elaborate dashboards. What imho the world needs is an easy way to use a spreadsheet tool to generate and publish a dashboard. A "make web dashboard"
20.
▲
by
c4mpute
3y ago
All these cool-looking dashboards are just too inflexible. You cannot add your own aggragates beyond trivialities. You cannot just "color that one value that bugs you". You cannot just generate a readable report plus some explanat
21.
▲
by
c4mpute
3y ago
It would sink into the center of the earth and then oscillate around the center until friction stops it dead center. Materials in the earth's crust and mantle are not strong enough to stop that mass from sinking ever deeper. But that a
22.
▲
by
c4mpute
3y ago
Even better: Each user can have his own locale and charset, and may even change that per program/shell/session. One may save filenames as UTF-8, one as ASCII, one as ISO8859-13, one as EBCDIC. However, the common denominator nowad
23.
▲
by
c4mpute
3y ago
No. Because the API is fragmented into old, not-so-old and new parts, some higher-, some lower-level[0]. You need things from all of them, the new API isn't complete enough and has warts in places where using one of the older ones is b
24.
▲
by
c4mpute
3y ago
It may be a response to specific circumstances like carrying blockade gear, announcements made by the people in question or past crimes: https://www.gesetze-bayern.de/Content/Document/BayPAG-17
25.
▲
by
c4mpute
3y ago
> Die entsprechenden Verfahren enden regelmäßig lediglich mit Geldstrafen. This is plain wrong. Repeat offenders in this matter have been sentenced to jail time, in excess of the two months of possible preventative arrest: https:/&
26.
▲
by
c4mpute
3y ago
Usually that believe stems from the fact that those people explicitly announced they would do it again. And again. After being sentenced. In front of a judge. https://www.merkur.de/deutschland/kleber-aktivisten-letzte-g
27.
▲
by
c4mpute
3y ago
We had technical know-how. Past tense. Then technology became evil incarnate. Nowadays we are scared of everything, ignorant of any kind of science. All policy and all public outrage is purely based on ideology and wishful thinking. If one
28.
▲
by
c4mpute
3y ago
Most reasons in §14PAG for preventative arrest include a crime or misdemeanor that has been committed and will likely be repeated, or the proven announcement or planning of such an offense. So most will be suspects in the literal sense, oth
29.
▲
by
c4mpute
3y ago
> But being imprisoned without having committed a crime is very unlikely to be considered a fault of the employee. I would (without being a lawyer and without having a case to cite) suspect that in those cases it would be considered to b
30.
▲
by
c4mpute
3y ago
Absence is reason to withhold payment in Germany, you can only expect continued payment if you are absent because you are ill (and then only for a certain period). There are some provisions like having to pay out leftover holidays and overt
More ›