Surely you know/understand that:
1. The minimum standard, even in the West, is not high enough.
2. The resources spent on the vanity projects and luxuries of the ultra wealthy could raise that minimum standard instead.
You say, "you'd be more upset if you have nothing" but that is the actual reality for people actually living here. Our system is extremely fickle and contrary to popular belief, does not directly reward hard work with success. I know many people that work very hard jobs, that make a tiny fraction of what probably the lowest earners on this forum make.
I don't think anyone's seriously suggesting people be held accountable for bugs which are ultimately accidents. But if you knowingly sign off on, oversea, or are otherwise directly responsible for the construction of software that you know has a good chance of killing people, then yes, there should be consequences for that.
You'll see the reporting is totally skewed (huge surprise). He identified certain low ranking military members being effectively thrown under the bus for small things, or things it's dubious they even did. While the Australian gov continues to protect the real psychos: special forces and the top brass.
If you actually listen to an interview with him and not reporting about him, you'll see him explain that he identified some scape goats for prosecution the Australian military we're trying to throw under the bus for minor issues or straight up things they didn't do, while letting the real psychos like special forces off the hook entirely.
There are a lot of us keeping RSS alive. I've been working on a very minimalist RSS reader in Phoenix LiveView for like a year now if anyone is interested in trying out another reader: https://catnip.vip
I absolutely love smooth scrolling in the VTE terminals on Linux, but I can't find anything other than maybe the default terminal app (which I don't like) and iterm2 (which I don't like) that does it on Mac. As the author said, just about every terminal has a GH issue open asking for it with nothing but 'this would require rewriting a lot'
Cause that's not what it's for? It's like the opposite of headless components. It's all head and no component. That's what you're buying. I think that's pretty clear cause that is what Tailwind is. It's CSS, not a component library. That's what this thing is.
Yeah they're not even deprecated really, that's the wrong word. That implies there not actively encouraged to be used. They just moved them to their own repo outside of eslint itself.
> If you can inject javascript, it's game over anyway.
Yeah, but as you pointed out the one thing you can't do is get the cookie. Having the auth token yourself as the attacker is a way different story then just having XSS vulnerabilities. You can still "do" a lot, but you still have to get another user with the token you want to interact with the page with your XSS to "do" what you want.
Self advertisement but I'd appreciate anyone trying out my RSS aggregator which is kinda like HN in terms of design (be warned it's really rough right now though) https://catnip.vip
I don't really think so. In the middle ages, punishments for all sorts of crimes were pretty severe--but partly because the vast majority of crime would go unsolved. If you're a peasant in the middle ages and some valuables go missing, who's going to track that down for you? It's not happening unless you know for sure it was your neighbor or something.
So yeah, when they would catch a thief they would receive some pretty harsh punishment. But it didn't stop much. Theft in the middle ages was rampant.
Humans are pretty bad at making calculations involving a really bad outcome at a 5% chance of happening, or those sorts of things. Theft persists today as it did then, just because it's really hard to investigate and so generally goes unpunished.
That seems to kind of go against the spirit of doing the work to find a vulnerability. It's basically social engineering. Do you get bug bounties for that?