She says "there is no language in nature" which does not seem accurate. Even though she might mean something else or a particular form of language but even then, bees and birds still use sound and something similar to language.
Is it just me?
for e.g. the form of communication used by bees is very well known now, it involves not just spatial movements but also "buzzing" which is totally similar tot he sounds we make, they just lack vocal cords.
What makes you consider it a "discovery" instead of a creation of us humans?
I am more on the side of seeing maths as a precision language we utilize and extend as needed, especially because it can describe physically non-existent things e.g. perfect circles.
What sort of access level / integration would you need to the businesses (repositories, CI systems, mobile app source repositories, Github admin) seeking to use Actory?
Here is a nice talk by Byron Tau who has also written a book titled "Means of Control" detailing some of these flows covering ad tech companies, data brokers and how government contractors use them and serve as a key player to provide services to intelligence agencies.
I think they definitely knew that they are embedding code from US based ad agencies who might either be selling it to the NSA or just doing it in an insecure manner (plaintext protocols).
Mostly in such cases, direct involvement and paying dollars is a clear no-go for the intelligence agencies. They could instead be paying the ad agencies.
Also note that we are talking pre-Let's encrypt and TLS everywhere world, a lot of this traffic was also just plain text making it much easier to harvest.
could someone with legal/data-privacy expertise comment if this would be something they have to disclose under data breach disclosure laws?
Technically it might not be a "data leak", but it very well could result in one if arbitrary content (including js?) can be uploaded to these webpages?
> Norton, Kaspersky, Zscaler, F-secure, NordVPN, Virustotal, Palo Alto: all of them marked these links as safe.
This is sad to see, these tools are forced down so many companies in name of "compliance" while totally not worth the maintenance and cost overhead. Apparently they haven't got any better in the last decade.
I think it is more about finding a "perfect" fit, from the last hiring thread there was a job for which I thought I was a good fit except that I was lacking some prior experience in a specific domain i.e. anti-fraud, and that alone was the basis for not pursuing it further for the company.
Also this time, I see companies hiring "security engineers" with "Strong proficiency in Go or Scala". It is not like they are willing to offer much higher salaries for people who are both security engineers and full-stack software develpers, they just want it for the same market avg. salary ranges.
> Is this for reporting bugs outside of the bug bounty platforms?
Nah, in this case they simply had no official bug bounty program/platform.
I would guess that a big factor is mindset and tech culture across different companies or having a bad head of something who doesn't get the point of bug bounty / promoting responsible disclosure.