Access to the available font list might be useful for identifying devices likely issued by a particular organization. Unusual fonts that are part of an org's branding usually are installed as part of a standard device image. This allows employees to produce brand-compliant presentations, etc. I was an intern at GE in the mid-90's and we had a custom font with just one character defined - the "meatball" corporate logo.
Is Iran's domestic internet still fully operational (sans access to/from the outside world)? If so, I wouldn't think the cut-off would help much security-wise because a single Starlink terminal would allow the US/Israel domestic access.
How often is the UI spec modified in practice compared to the frequency of UI changes? I wonder if this scheme actually reduces app update frequencies much. I can imagine that UI improvements often would require spec changes. Imagine adding colors to the map POI's, etc.
I've read several articles about this SuperNova trojan, including a couple that included decompilations, but none included what ought to be two key details:
1. Was this GIF-fetching endpoint likely exposed publicly by most customers' SolarWinds deployments?
2. Public or not, was there any auth in front of this endpoint when deployed?
My presumption is that some (most?) customers deployed the SolarWinds admin console publicly (with its own auth in front) and that this particular GIF-fetcher endpoint, being deemed trivial, was not protected by the console's auth scheme. Thus, those who knew about the trojan just had to scan the known IP ranges of SolarWinds customers until they found the exposed admin console, and then remote code execution was easy from there.
If this endpoint was protected by the same auth scheme as the admin console, then this trojan becomes more of a privilege escalation attack. Its existence would increase the value of obtaining the creds of a SolrWinds user, but (presuming SSO integration) those creds would get the attackers lots of other access given the sorts of IT people who use SolarWinds.
If the endpoint was not fronted by any auth scheme but the admin console was not exposed externally, then the benefit would be that attackers who gained access to a SolarWinds customer's employee-facing network (what's the name for the network segments accessible to anyone who plugs in a laptop in a cubicle?) could "ride" this trojan to gain access to a more privileged part of the network.
I'm not an infosec guy. Do these arguments make sense?
So, the user graph will be bifurcated, with US users isolated from those in the rest of the world? If so, I don't see how the US-only TikTok remains popular for much longer.
I'm surprised a manufacturer of such engineering machines hasn't differentiated itself by offering a SLA on driver (and general software) availability for future operating system versions. It would be reasonable to require users to pay a subscription fee for extended support. I'd think the resale value of machines with drivers still available would be much higher than for those without and that this eventually would allow the manufacturer to charge a premium price for the machine at initial sale.
I own a Fujitsu Scansnap s1500. It's out of support, and the existing drivers are incompatible with Catalina. I now must pay a 3rd party $100 for drivers or fiddle around with a Linux scanner server or similar. Never again will I pay $400 for a Fujitsu scanner, that's for sure.
I just watched a Youtube video of the STS-1 landing. He definitely was a happy guy, but it was nearly after landing until he finally exited the shuttle.
I've always been opposed to folks who grumble about suburbs and urban sprawl. I thought that new developments and neighbourhoods meant a growing population and a bigger tax base. I've always lived in the suburbs and love it. I still think there's lots of great things about living in the suburbs, and there will always be demand for it.
I like how the author says that sprawl isn't the problem, the problem is that new developments are large scale, single-purpose, and with no room for improvement or addition.
The graph/map showing how downtown and poorer areas bring in more tax is what did it though. Even just thinking about ploughing in the winter makes it pretty clear that winding suburbian roadscapes are costing the city a lot more than we pay them. That's without mentioning schools, fire halls, garbage collection, etc.
I guess one of the more difficult issues is convincing North Americans that they don't need a private single-family house, large yard, 2+ cars, etc.
For Google, ART seems bigger than just Android. Consider the degree to which their infrastructure depends on the Oracle JVM and the associated strategic risk. As one datapoint, recall the Oracle vs. Google Java lawsuit. How much additional ART development effort is required for correct execution of non-AWT (Abstract Windowing Toolkit) Java applications (essentially, headless server processes)? I know the Java/JVM ecosystem well, but I have not done any Android development. Surely, Google wants control over the destiny of its core software stack.
The article doesn't mention one seemingly huge benefit of JIT compilation: profile-guided optimization:
Perhaps the baby has been thrown out with the bathwater?
Little is mentioned about how ART compares to the JVM. For example, does ART perform escape analysis? Not all object allocations are equally bad. The Sun JVM can figure out which objects may be allocated on TLABs (Thread Local Allocation Buffers) - an optimization which reduces the burden placed on the garbage collector because TLAB-resident objects may be deallocated as the stack is popped. [Please fact-check me as I'm merely a long-time Java developer vs. an expert on JVM internals]
I learned that panhandlers, at least in Chicago, interpret polite negative responses as opportunity and will continue to bother me. So, I have taken to saying flatly, "Not happening." It's not so rude or demeaning that I inadvertently pick a fight, but it's blunt enough to let them know that they're just wasting their time with me.
To add to the collection of work-arounds posted here, most hotels seem to have reasonably modern/common printers. Often, they are connected to the untrustworthy hotel PC by a USB cable. It seems faster to unplug the printer from the hotel PC and install drivers on one's own laptop than it is to figure out how to gain access to the hotel's crappy computer. Hotel printers connected to hotel computers via ethernet/WiFi also likely have working USB ports, so one simply could bring his own cable with a "B" plug. I'm sure there are ways a malicious person could install rogue printer firmware, etc., the likelihood of such threats existing in the wild is 1/1000th that of the sum total likelihood of evil existing on hotel PCs.
I suppose the relevance of my entire comment hinges on the presumption that anyone reading HN only uses hotel PCs for printing stuff. Valid?
I was thinking about the sorts of fraud categories AirBnB likely experiences. Most fraudsters want cash or cash equivalents, and the use of lodging on a particular night is nearly as illiquid as stolen fine art. So, those seeking stuff to resell will choose to defraud one of the zillion online marketers who ship stuff to doorsteps. A buyer who actually used the space he reserved could initiate a chargeback later claiming that the service promised via AirBnB wasn't provided -- couldn't access apartment, wasn't as described, etc. However, space providers likely will cooperate with AirBnB and provide evidence in their defense. Better to attempt a chargeback elsewhere if one is short on money. It seems that using AirBnB as a platform for crimes between buyer and space provider is possible, and there certainly has been at least one heavily publicized case, but we would hear a lot more about these events if they were happening much.
So, what's left? Collusion between buyer and space provider -- in all likelihood, they are one in the same, or identities have been stolen. For example, I list my condo on AirBnB for $100/night. Someone books it for the weekend, and then doesn't show up. AirBnB owes me $200 -- after all, I gave up other options to profit from its use. An honest buyer pays up. But, maybe the buyer is dishonest -- he used a stolen credit card, etc. In this case, AirBnB eats the loss and pays me as the space provider. Now, wouldn't it be convenient if I was also the buyer? Cash from stolen credit cards, funneled through AirBnB (much akin to the way online poker sites were used to transfer stolen money via bad heads-up play). This would work until AirBnB noticed that my listing seems to have a suspicious propensity to attract fraudulent buyers. Then, they'll shut me down. So, I'll pop-up elsewhere. After all, no need to actually have a space because no one I accept will ever show up!
I bet the usage patterns of the party/parties involved in this fraud are drastically different than those of legitimate market participants. Someone with a fraudulent listing could out himself by rejecting a bunch of legitimate AirBnB buyers, and this behavior would stand-out as it's the opposite of the behavior expected of an honest seller. So, he must protect against this risk by making his listing unappealing (high price, bad photos/description, unpopular location, etc.). The behavior of users browsing AirBnB when viewing this property could identify its relative undesirability (few clicks, etc.), and price outliers could be identified by comparing similar offerings by date/location/type. The click stream of the "buyer" likely is most revealing. Someone selecting an unappealing property without doing much comparison shopping likely isn't a legit buyer.
What other stuff might predict fraud? Vague descriptions might indicate a fraudulent listing. Most space providers love to tell buyers what's special about their offering. Could some scoring of a listing's prose prove a strong predictor? I've never listed with AirBnB. What do they do to verify listings? As a buyer, they verified my identity. Could this serve multiple purposes? Certainly, I'd feel better listing my guest room if I know that AirBnB will know the identity of the guy who rented the room and then stabbed me at 3AM. But, in addition, does identifying market participants in strong ways help keep fraudsters from repeating their crimes by setting up multiple accounts? Obviously, newer market participants are more risky than established ones, especially those who have interacted with known legit, long-time users. The social graph comes to the rescue here. Even astroturfing ought to show up as a small, disconnected graph unless legit users' identities are stolen.
Of course, this comment is all just conjecture. Obviously, AirBnB can't tell the public about specific fraud methods or how they identify suspicious activity. However, I like the concreteness of considering actual fraud scenarios, so I decided to put forth some ideas for discussion.
Most of the comments here presume that it's unacceptable for a drone ship to break down in the middle of the ocean and be without crew to repair it. What if these ships were designed so that nothing too awful would happen if they floated around in the middle of the ocean for awhile awaiting another ship with a human crew to perform repairs. Or, maybe another drone ship or two to tow a broken one back to land?
My understanding of container shipping is that customers make SLA choices much akin to us Americans choosing between UPS Ground/2nd Day Air/Next Day, etc. UPS uses these varied SLAs to smooth out its use of fleet capacity and for price discrimination. Shippers operate transshipment ports as part of distribution networks much like the hub & spoke designs of the major airlines. These ports have a bunch of shipping containers sitting around awaiting capacity.
Consider the needs of companies that must transport low-value, high weight/bulk cargo. These companies likely already choose the "UPS Ground" equivalent for container shipping. Due to low product value, inventory costs are low (in transit goods are inventory), so it's probably less expensive to have buffers of goods in the supply chain than it is to pay for tight shipping SLAs. Why should these companies care if the variance they experience in shipping duration is due to capacity constraints of manned-ships or that it took an extra two weeks to fix the ship upon which their cargo was in transit?
I've always seen local governments as the root cause of "last mile" providers' ability to turn their customers into the product. Why haven't elected officials made more stringent demands upon the companies given monopoly (or at best duopoly) rights to convey bits to and from my home?
I have a condo in Chicago and was delighted to learn that a company was offering our building last mile connectivity via microwave along with SLAs for not only bandwidth but latency as well (to which point I don't recall)! Sadly, the condo board didn't seem so enthralled. Unlike the suburbs, city folk have more options apparently.
What's notable is that no one has yet posted here saying, "Go stunk for me. Perf and reliability were both awful. I went back to blahblah and threw away all my Go code." It's usually easy to find detractors of any technology.
So, even though you hated your previous job, you obviously did well at it -- at least well enough to save-up a nice nest egg. Let's presume that you will progress over time from crappy programmer to a solid one. Anyone like you will get at least that far and likely much farther. The question at hand is simply what you should do to facilitate this progression. Have you considered solving some small but pesky problem which you know is common in your industry? A calculator for compliance with Governmental Rule XYZ? A converter between two 90's era (or worse) file formats still in use within your previous industry? I have no clue what you did before, and I probably wouldn't know what projects to suggest even if I did. My point is only that you can make-up for being a mediocre programmer with deep knowledge of a specific industry. If Patrick can make $30K+ selling bingo card software to teachers, you ought to be able to do similarly in the niche you know well. To avoid having to be a good salesman, maybe you put up a website with the file converter thingy and then sell premium advertising space to vendors in that niche.
I have the same number of feet but one more knee than this guy. From what I understand about above-the-knee prosthetics, walking up stairs with a "normal" gait is an impressive feat. Clearly, the technology is near-miraculous.
With all this said, I'd much rather see advances in bionic attachment techniques. If I could have a metal rod extending from the distal end of my tibia through skin, being without a foot would be much less annoying, and my physical abilities would improve significantly. I could just clamp on a prosthetic in the form of a carbon fiber spring -- the same sort I have now. Presuming the rod required little maintenance, I would require far fewer trips to the prosthetist for construction of new sockets as the shape of my residual limb (the politically correct term for "stump") changes over time. No risk of skin issues preventing me from using my prosthetic leg. No risk of catching my prosthetic foot on something while walking and pulling it off my body. Current socket-based attachment techniques create what effectively is an extra joint with very limited range of motion. Oddly, this is useful for subtle manipulation of a gas pedal (I'm missing my right foot), but it is mechanically inefficient, reduces my perception of stability, and keeps me from feeling like the prosthetic foot is "mine". Because of this extra joint, heavy shoes feel really heavy. Lots of effort has gone into making prosthetic feet light -- a much less valuable attribute if direct body attachment was possible. Reducing the value of making prosthetics lightweight would allow for all sorts of innovation.
My understanding of the current state of affairs is that, while it's quite easy to stick a metal rod into the distal end of a bone, it's quite difficult to allow it to protrude through skin without risking infection. My general take when reading yet another article about some amazing $100K prosthetic device is similar to my thoughts when hearing fuel cell folks talking up the technology in the early 2000's -- They all showed up at tech events talking about how fuel cells were going to change the world, how their own novel technology was going to make them more efficient, lighter, whatever. My question to them was always, "When am I going to be able to replace my laptop battery with a fuel cell so I can take a cross-country flight without worrying about my battery running low?" They always gave some vague answer and then went on talking about the improvements they were making to a technology which was not at all available to me. It's 2013, and I haven't yet owned a fuel cell. However, I'm writing this on a Mac with much better battery life than was available a decade ago even though the fundamental technology used in its battery is unchanged.