For those unaware, if you want to use the latest Office Suite (2024), but don’t want to pay a monthly fee, Microsoft still offers a one time purchase [0] for $149.99 which is now cheaper than the (new) one year subscription (with no cloud storage of course).
This causes some interesting knock on effects on society:
1. more pollen (as mentioned in the article), leading to more more allergies, leading to more allergy med sales
2. no free fruit growing in the streets for kids/others to eat healthy snacks (visitors to some “old world” towns admire this about them). The fruit “littering the landscape” being the stated reason for not planting female trees, means non biodegradable trash from chip bags and other disposable wrappers litter our cities instead
This is an amazing educational experience for students but it is also such a great way to crowd source hyper realistic 3D world replicas - it reminds me of the Minecraft replica of MIT that cropped up at the start of COVID. I really hope they open source and preserve all the work of these students on a combined server anyone can browse.
It would be even more amazing if we ended up in a world where we basically open source public infrastructure projects so that anyone could contribute ideas and/or solicit public comment on new concepts before we invest billions of dollars of public money.
It also immediately comes to mind that Microsoft develops MS flight simulator - could proposed airport innovations be paired with it to test how pilots feel about changes to layouts or e.g. how new runways may affect air traffic and other patterns?
There is a discussion on that thread about the bounty being rather small compared to the damage it could have caused the crypto market and/or Coinbase’s stock/reputation. It’s low relative value is even being cited as a risk to future bugs not being responsibly disclosed.
It is however important to consider the technical complexity, effort, and exploitability when valuing an exploit. This was a very, VERY simple bug to find and with KYC very obvious and unlikely truly monetizable without consequences if exploited (unlike say getting access to the private key of a hot wallet). The biggest damage would have been reputational (though a rational person should consider the fact this kind of missing condition check bug made it to production a major issue already). The market would have recovered from whatever flash crash ensued and the attacker wouldn’t be likely to keep their winnings.
Kudos to tree_of_alpha for being the first to look at the API, spotting this, and reporting responsibly - $250k for what appears to be under an hour of work that was driven by curiosity is not a bad deal at all. I know Brian Armstrong frequents HN so it will indeed be interesting to get his take on this as well if he was involved in it.
You are doing exactly the right thing by reaching out and asking for advice in communities you are a part of that may be able to offer you a job or a connection to one. One piece of advice however would be to include a link to a resume or personal website showing off your independent projects and skills. It’s these projects that will show what technologies you are proficient in and prove to others that you know what you are doing even at a younger age.
I also started coding very early and used my time choose a project and dive very deep into the full stack. Web technology is the easiest thing to “show off” to others since it’s ubiquitous and easy to distribute. Even if you consider yourself a “back end” type of person, learn some web dev to be able to show and tell.
This is a time in your life that you can work on a piece of software that’s just for fun and to learn and do something cool. If you are lucky and commercial, that project might become a job of its own that provides you a passive income. Otherwise, it’s a part of your portfolio to help you secure another opportunity. I routinely look to give part time/internship opportunities to folks in your position precisely because others may overlook your talents and passion to develop them and because I was one of them :)
The email domain where the messages originate is from some sort of federated identity management system that was created in 2010 (here is a proposal deck [0] with technical details). Found this program simply by searching Google for the sending domain.
Based on the guide for using this system [1] (see step 15) looks like this specific email address is the one that sends automated confirmation emails upon registration. Perhaps someone was able to inject a message instead of the regular canned text through some sort of reflection attack? This explains why replies to the message result in a canned response. The system also now appears to be temporarily down. So it’s getting some sort of attention (internally taken down (most likely) or maybe denial of service from the abuse).
The Reddit thread suggests the recipients’ emails are likely ARIN IP range contacts. Those are very available from tools like this [2] so nothing interesting with that, but the real question is WHY someone would do this at all? This was clearly given some thought (on who to send this to who would actually take the time to verify the headers) but given the sloppiness of everything else, is this just a script kiddie flex? Whoever it is pissed off the FBI and gained absolutely nothing.
I can speak using MIT as an example and I assume Harvard is the same way for the same reasons.
Big research institutions that were present when IP addresses were being allocated got A LOT of IPs by simply asking for them. Apple has the entire 17.0.0.0/8 range. Ford Motor Company has one, the US Gov has a lot [0]. Up until recently MIT had all of 18. (they sold something like half to AWS for a hefty sum not too long ago).
As a student (or visitor), when you joined the network (wired or Wi-Fi) you weren’t allocated some internal IP behind a router but a PUBLIC 18.something that was in the global address space because they had so many IPs available. This meant you could literally host something on the public internet from your dorm room because every device on the network was publicly routable by a unique public IP address.
Not to mention that the "single quote" in the article is hardly from a "unknown" author (Charles Dickens), this BBC article on the same topic [0] has several other quotes from well known literature in the same period.
Yes, they get enough donations to cover their costs, just like Uber has enough VC cash and loans to continue its operations. It's non profit tax status is not strictly relevant to the fact that you typically need at least as much as money as it takes to run your entity rather than less. In my opinion, this doesn't change the spirit of the point that Wikipedia doesn't make money from its free, high-traffic service but rather from favorable financing for its goodwill and assets similar to a not profitable startup.
I've considered this question a number of ways. The fact that capital holders are gatekeepers to innovation is unequivocally worse for federated innovation, but it has created an interesting class of companies which may never need to turn a profit yet still have a positive (and growing) net present value.
Take Wikipedia for example. They lose money running a high traffic service (edit: see below reply for clarification), but it's plain to see they hold a huge asset in terms of goodwill, usage, knowledge base, and their contribution to research and knowledge growth. Despite its operating losses, its capital value (which may be in the form of social capital) is huge and will likely remain well financed into the foreseeable future.
The fact that the service is free is not relevant: a startup offering an invaluable service that is based on years of user research, development and testing has developed an asset which helps other companies and companies pay what they think it is worth (or at the beginning a subsidized rate to take a risk to try it). Operating losses at most start ups are from continued R&D; but if they were to just declare the product as "done" and have a sufficient moat/network, they could rent seek on the asset for years - yet in many cases that's not what is best for anyone (company, clients or shareholders) - we continue to want them to innovate for the good of the product and there will be stakeholders that would rather finance this research in perpetuity to grow the underlying asset and thus the value of the product and company.
Inductively, that's a company with negative NOL but positive NPV. In the physical world this might be the same as an apartment complex that's expanding (forever). They may currently collect $1M in rent, but they are spending $2M on new construction. The new construction may bring in $5M over its 30 year lifespan but it will never be enough to outpace the immediate outlay of continued construction cost. As long as the time value of money is correctly attributed, this isn't a new idea - just one that's been pulled to an extreme.
It's worth comparing Bitcoin's proof of work to other schemes of maintaining currency value to understand this in a relative sense. The Military Industrial Complex which arguably is the mechanism by which the dollar maintains its position as the global reserve currency puts out 152MtCO2/yr [1].
Without making any judgement on if this ratio is reasonable: this is 3-5x more than BTC POW but arguably also contains other negative externalities like loss of life, etc.
A DNS record lookup points to ddos-guard.net which provides both hosting and DDOS protection (like cloudflare) and is based in the Netherlands.
I don't think they care much about Parler or free speech for that matter. They might not care much beyond the likely big hosting bill they are being paid. Free market at work, nothing to see here.
This is fascinating, I didn't realize there was a spec for this for the web.
But this begs the question: Apple Privacy Labels "caught on" because Apple has unilateral control to enforce them in the App Store. If ostensibly the same idea for the WWW did not catch on, is the problem (1) the lack of enforcement/economic incentive mechanisms on the decentralized web or (2) that consumers really didn't care/know enough to create/enforce such free market incentives?
The most insidious part of mega bills is the surprises that get snuck into them that I'd like to believe would have been adequately thought about and debated if someone actually had a chance to read them. The article suggests the CARES act itself is to blame and the 14k charges are "fees on these facilities to fund the FDA's regulatory activities". It wasn't meant to attack distillers but that didn't stop them from getting swept up in a provision that didn't belong in this bill in the first place.
How is a logical person supposed to reconcile a bill that was meant to help the country deal with an emergency is actually penalizing the companies that stepped up to help and charging them for the extra red tape?
This appears to be a two part question. Part one is how space efficient the language representation is (words, sounds) and part two is how much mental RAM is needed to extract meaning. In a traditional CS setting this would be an example of a time-space tradeoff (decompression), but given hefty evidence of special structures in the brain that are adapted for language processing, the processing aspect has really been abstracted away by "special hardware" which places a lower bound on how dense the representation can be to take advantage of it in a real-time streaming context. I find it hard to imagine any popular language system evolving to make itself harder by not using the embedded hardware for processing, so I'll turn the rest of my answer to examining the representational efficiency.
If you look at language efficiency from the information theoretic sense (i.e. most meaning conveyed with least amount of "bits" of data), you can approximate the efficiency of a language by looking at the branching factor and probability of words in its language model. The more branches there are, the more meanining a single word can have in a stream of text (especially a low probability word). However, the more words you have in your language, the more "bits"/letters/memory/etc. It takes to represent the word even if you use a probability informed encoding like Huffman.
If you think of a Markov language model as simply bitstream guided state machine, you can approximate the expected length of output for equivalent length inputs and get an information density approximation of the language model itself.
Traditional Chinese which is not phonemic will have a much larger "word" space but a much smaller branching factor. Each symbol conveys more meaning, but highly constrains the space of symbols which can follow. Where it falls on the tradeoff curve relative to say, English is not obvious ex ante, but we can use this framework to test it.
This answer might be a little dense, but is meant to provide some intuition and a thought framework to evaluate your question.
> A user could log in daily, cough into their phone, and instantly get information...
While this model is indeed extremely useful and interesting work, this seemingly casual quote gives new meaning to how unsanitary our phones really are/can be.
Really any cheap VPS provider with cPanel should do what you are asking to provide unlimthed domains, aliases, users, mailboxes, catch alls, forwarding, etc. if you are not looking for anything more complex than IMAP support. Just be sure to set all your DNS/DKIM/SPF up correctly and you should be good to go.
Off topic: the consent dialog on this page was hilarious and simultaneously a great social commentary on the typical dark patterns.
> In order to offer an "ad-filled experience" and maximize our profits, LinuxReviews would very much like you to allow our Google AdSense ad-partner to use tracking and cookies so we can show ads from them on our website.
> Options: Resist, Approve (2x bigger)
As a web developer, this was refreshing, but as a user didn't immediately make me want to accept. I wonder what their opt in rate is like compared to the "best" practice
Interestingly, newer version Fitbit devices also sport an SpO2 sensor, but they have dragged their feet on enabling direct readings or the expected sleep apnea detection features.
The delay seems to have come from the worry of the perception that it was being used for "diagnosis" of sleep apnea as that would put them in a different category with the FDA. You can imagine how direct access to the SpO2 sensor was a hot topic during the height of the pandemic of a repository illness. In short, the hardware is there, but corporate conservarivism kept it from being used or even exposed to the user.
I've bought a Withings Smart Scale (at that point they were briefly owned by Nokia). The scale is simple, clean, durable, featureful; the companion health app is one of the cleanest/effective specimins of UI I've seen in a while and has tons of integrations. I expect great things here and hopefully less fear about exposing the hardware readings of highly useful sensors.
[0] https://www.microsoft.com/en-us/microsoft-365/p/office-home-...