Not familiar enough about GCP internal, but AWS prices are way higher than what's quoted in the article. You'll get billed for bandwidth, should you want any logs of your control plane you'll pay them at a premium so high* it will dwarf the cluster price and machine price combined. And for ~$70/month, you get the cluster API, not the EC2 compute required for worker nodes.
It really depends on the market you are targeting and your threat model. If your threat model allows future decryption of the data by a passive listener, then you don't need to rush for PQC. If you are worried about your communications being archived for future decryption, then you need to deploy PQC now even if QCs aren't developed for decades (or ever).
The assumption that you care about this is baked into ANSSI certifications, otherwise you would usually not bother certifying your product. They warned in 2022 that they would do this (See Phase 2: https://messervices.cyber.gouv.fr/guides/en-anssi-views-post...) and will allow PQC-only algorithm no earlier than 2030.
I misunderstood your initial point about logging-in. On PayPal logging in requires my phone, even with hardware 2FA because sometimes it decides my new IP/Browser/luck isn't trusted enough so it needs to send me a SMS/WhatsApp message so it didn't even register with me that you would be talking about taking out your phone as an additional friction. I see that now, in which case: you're completely right. WeRo requires a phone and one that uses either Google Play Store or Apple App Store and worse, depending on your bank that requires strong Play Integrity.
In term of implementation, WeRo looks more like a response to mobile payments like WhatApp, WeChat, Alipay, ... than a response a provider like PayPal. However, I haven't seen anything that'd limit them from expending support if they wished to.
> and also giving numbers out as much as possible
In Person-to-Person, you don't have to share your number. You can use QRCode (Direct SEPA). I'm not entirely sure of the email implementation, but maybe these do not share the phone number either (Edit: seeing https://support.wero-wallet.eu/hc/en-us/articles/25599201237..., it seems you may be able to do an email-only account). In Person-to-Merchant, I'm not sure what information are shared.
> Moreover payment systems that prioritize the needs of merchants usually are horrible for consumers
Supporting merchants flow to pay is different from prioritizing their needs so I'm unsure where you're going from there. It's also completely separated from Person-to-Person payments. PayPal supports Person-To-Merchant and I wouldn't say they are great for merchant.
> Any botanical material of the plant Mitragyna speciosa, also known as kratom, and contains more than 0.050 percentage of 7-hydroxymitragynine on a dry weight basis
Indeed, thanks for catching that. No maximum for an actual kratom leaf but leafs cannot be too potent, right?
Which makes you update hardware and have a window where you are vulnerable. It's terrible but not a blocker and as long as Intel releases new architectures it isn't much different from software issues. As far as I know, Granite Rapids SGX fused keys (FK0, FK1, GWK, FEK) were not yet extracted. Granite Rapids was released around ~2024 meaning an attacker need to hack the provider and perform a new extraction on SGX.
Since there have been multiple 0-day in kernels, we should drop all security boundaries in them because you'd only need execution on the machine and a known vulnerability.
Since there have been with bypass on service X, we should remove auth because all you need is the vulnerability.
Address space layout randomization wouldn't exist with this mindset, and yet it does and helps for many exploits.
SGX is not fully secure. But neither are the other part of the stack. Security (or trust in this case) is done through layers because it's a question of when you'll be vulnerable, not ifs.
As much as I love to discuss how expensive AWS is, I find this comparison quite strange:
- Small instances are used, including a burstable instance for AWS, with no indication on where and how much throttling happened. Saying that the instance is burstable but a price-match isn't even true because later it is discussed that $48 is not a match in price due to services around the instance itself
- It seem Hostim doesn't support large instances, the largest dedicated instance offers 100GB / 4 Cores / 8 GB RAM. At that price point, you either go with AWS for prototyping speed or compliance but definitely not for performance.
- Talking about speed, you got performance, but you'll now spend time developing your own backup and restore processes which are a "coming later" feature. What's the impact of backups compared to disk snapshots on those other network-attached disks?
- It mentions only once the network-attached block storage used by RDS and the Hetzner instance compared. Which is weird because you could go for local storage for cheaper and get more performances, but that introduces some trade-offs.
- Instances are configured with different settings.
Peeker's advantage is not directly related to fog of war. The peeker is moving so before the movement is even sent to the server, the client's camera began moving. As such, the peeker will have at least a tick, usually more before that new position is available to the opponent.
"Fixing" this would make movement sluggish: any movement would need to be validated by the server. Meaning delay between pressing keys and actual movement.
Why stop at tracking license plates? Once you've started you should report on pedestrians, bikes, whether people are at-home, which building people are entering, the way they walk and many more. Those are all "alternative revenue streams" that are as valid from the operator/investor point of view and completely unrelated to whether the way of transportation or activity is meant to be untrackable or unrelated to a way of transportation at all.
There is also a factor of scale: a cop can follow you, but a system where everyone is monitored 24/7 is a very different story.
I've seen VISA cards with several banks in France where there is commission after 1 to 3 monthly ATM so I'd be doubtful about VISA having such as requirement.
Historically, AWS own infrastructure relies on us-east-1. Loosing us-east-1 usually means loosing many other AWS Global services which are required for services in other regions to be healthy.
Not always. RTK strips flags and other information. Sometimes you spend more tokens getting them back later. Sure your saved 70% tokens on that tool call, but nothing in the metrics says whether you ran 3 tool calls instead of 1.
There is also a question of whether that stripped output requires more thinking tokens or not.
I'm not sure how Garmin works, but for instance with Google Wallet-compatible watches, you need a phone where wallet can run. I've had this setup for a year where I loaded the cards from another phone and used a watch to pay.
However Wallet didn't like this setup. Tokens expired at varying delays, sometimes a day, sometimes a week or payment failed without reasons.
Nowadays, I just use my bank's app which work fine on GOS.
Excluding server costs, having that 100Gbps on egress can cost $50k a day. since it's a very high-margin product, AWS support would probably refund or reduce that to hundreds. Not sure how you get to millions either.
The data-sharing surely is for all providers. I think the sentence "When models become available, onboarding details will be shared." hides a lot of things.