> Who won't adopt enshitification-as-a-business-plan for a few years?
I don't have a crystal ball, but NearlyFreeSpeech was recommended to me in 2010 and I've been using it since 2012. I don't think it's changed at all in that time.
> Even in case (1), isn't it possible that Hide My Email bounces happen differently from regular @icloud.com bounces despite being on the same domain?
I don't think so because when I examine the headers of an HME delivered message to my [email protected] address there's only a single MTA involved.
> We've also been wondering whether Hide My Email was ever responsible for generating the messages with meant-to-be-hidden addresses or whether it was only passing them along and failing to hide them. I don't think we have enough information to tell.
The full headers of the bounce message will tell you.
2. [email protected] -> [email protected] where example.com is not any of icloud.com, me.com, mac.com (such as in your example, gmail.com)
HME can be configured for either of setups.
I really want to establish whether you were able to unmask a real address under (1), since in this case any bounce message should occur too early to disclose the real address.
Under (2), the bounce message can occur after rewriting and I can totally see how it was leaking the real address.
(For the purposes of the exploit, it doesn't matter that you used Mailgun to send the email, but I appreciate that detail.)
And just to clarify: this occurred ever when HME was setup to forward to an icloud.com address? I'd love to see the full headers of a bounced message to understand the MTAs that were involved in disclosing the address.
> Now Apple says it has been fixed, we can add that, in simple terms, it required sending a target Hide My Email user a message that got rejected as spam.
Frustratingly vague. I was unable to reproduce when the original article was posted. I did not test exhaustively, but I was able to get HME to reject messages in various ways (mostly by sending oversize messages) and none disclosed my real address because they were rejected before any rewriting to the final address occurred. And in looking at messages that were delivered, I didn't see any additional SMTP servers in the path that would reject the message.
The most I was able to leak was a DMARC header showing my real domain, but even that only occurred when I replied to an HME email from my real (non-icloud.com) domain. When I updated HME to use my icloud.com address, even that leak went away (but it did make it clear that HME was not sanitizing message headers).
Maybe if you have HME setup to forward to a non-icloud.com domain and that domain's SMTP servers rejected the message as spam, I can see how this could occur. But if forwarding to an icloud.com address, no way this should've been able to happen in the first place.
I wish they'd included a sample message including full headers to see the vulnerability in action. Where in the delivery path was the bounce being generated?
Huh, in my experience audiobooks are more expensive and/or harder to find than ebooks. Out of curiosity, can you give an example of one such audiobook you transcribed?
What an incredible performance. I've seen a sub-4 mile in person. These guys are absolutely flying. All of them. And he beats the pants off that field.
Splits (400m):
400m: 55.3
800m: 1:51.1 (56.8 second lap)
1200m: 2:46.5 (55.4 second lap)
1600m: 3:41.4 (54.9 third lap)
Mile: 3:42.66
Unfortunately you can't link directly to the 1 mile results. Scroll down to the table, select "1 Mile Men", then select "Reports", then "Race Analysis" and/or "Race Analysis Graphical". That leads to these two PDFs (not sure these links are stable):
It's that way so that you can grep multiple files with a single pattern. It would be odd for the pattern to come after the file arguments. It also allows the files to be optional so that it can grep stdin.
Yes, it does, and it's in the submission guidelines too:
> If the title contains a gratuitous number or number + adjective, we'd appreciate it if you'd crop it. E.g. translate "10 Ways To Do X" to "How To Do X," and "14 Amazing Ys" to "Ys." Exception: when the number is meaningful, e.g. "The 5 Platonic Solids."
> notarytool authenticates using a stored keychain profile that you create once, interactively — it prompts for an app-specific password, and there’s no way around the prompt.
You can use `--password <password>` (yeah, yeah, passwords on the command line are bad; I'm just challenging "there's no way around the prompt.")
Later (contradicting itself):
> The one step that stays interactive is notarytool store-credentials, and that’s a choice rather than a limitation: you could pass --password and script it, but that means putting an app-specific password in your shell history.
You can configure your shell to ignore history when needed.
> Her book, Portraits of the Princes and People of India, was published in 1844. It contained 24 lithographs that were drawn from her sketches of important Indian subjects such as Dost Mahomed Khan and Ranjit Singh.
In the U.S., the second dose was added in 1989 so around then. You might've also gotten a booster in the U.S. if you were born earlier but lived in a college dormitory.
If you're not sure, get tested. It's a simple blood draw.
> I still remember having abandoned Siddhartha by Herman Hesse at least three times at the first few pages.
For me it was Catch 22. I think I read the first chapter a half dozen times over a few years. Then one time I just couldn't put it down. Read the whole book, then went back and read it again. I can't even remember what I didn't like about it.
Still for me the issue is this: as a programmer, after spending all day reading or writing words on a screen I just don't energy to put more words into my brain through my eyes. So I'd rather watch a movie.
I listen to a lot of audiobooks because I can do that while I'm doing chores or walking my dog, even though I recognize it's not the same as reading, I seem to retain the information similarly. Mostly fiction though. My two most recent listens: The Diamond Age (the narrator is excellent) and The Vanished Birds. Working on Bel Canto but it's not holding my attention.
I'm not trying to argue with you at all. I feel like you think I made some claim about women being stronger or faster than men, when I very specifically did not.
My only point was that women can sometimes win and/or set records at prestigious endurance events when factors other than strength/speed are relatively more likely to influence the outcome. Such as this record right here: rowing from CA to HI.
Obviously the more elite men in the competition, the less likely this is to occur. But I'm not talking about a small local 10K where a sub-elite woman happens to show up and there's no comparably competitive men and the woman wins overall. I mean events where men and women of comparable competitiveness show up, but a woman just outlasts a man that day due to grit or better preparation or better planning or whatever the factors happen to be. All I'm saying is: the longer events give women more opportunity to win those races, regardless of event size.
I have an acquaintance I've raced with a few times. I've got the better marathon time, but she's got the better 24-hour distance. It's cool that we can both have those wins. That's all.
On the topic of vaccines, if you were vaccinated against measles before it switched to the two-dose schedule (1989 in the US), you might want to have your titers measured.
I was vaccinated in the early 70s when it was a single dose. With measles in the news recently, I asked my doc to add a measles antibodies test to my blood draw. Came back negative. No immunity. I went to the local pharmacy and got an MMR booster the next day.