I suppose all copies of all pages are theft, if you choose to look at it that way. Me saving a .html file locally, Google caching their search results, archive.org saving copies of pages.
The internet is built around this, and we've all collectively decided that it's OK.
But to your point, their robots.txt does allow this kind of access, so this argument is moot - they explicitly allow bots like archive.org's to crawl & index these pages' content.
According to them[0], Facebook's primary languages are C++, Java, and Python, and they're even embracing Rust now. In general, teams have the freedom to choose what languages and technologies they want to use. (quoting from the linked video)
They might've started with PHP, but even that stopped being a thing once they switched to Hack, their home-grown language, ~10 years ago.
I think you're right. If the vulnerability is there and we know about it, it should be straightforward to write a proof-of-concept that anyone on a vulnerable system can experience for themselves.
e.g. If a JavascriptCore vulnerability allows RCE on a Mac running whatever old version, write something to exploit it and execute the "say" command on that Mac, so anyone running that version can go to that webpage and literally see "wow this is a real exploit that actually works and anyone can abuse".
I'd love to see that. Kind of like the XSS script alert triggers, stuff where you can just paste a bit of code and prove that it -is- exploitable, without it actually doing anything harmful.
> Honestly, this whole ride makes me think I should just get a job at a US startup and use the cost of living difference to pay devs out of my own salary.
I know this was an off-hand remark that you're probably not thinking much about, but you're absolutely right, and it might be worth seriously considering it. Moving to the US is probably the single biggest improvement you can make to your career and opportunity options. You will never have as much opportunity in Europe as you will in the US, not in the tech world. You might be able to eke out some success in Europe, but it'll pale in comparison to what you could've achieved in the US.
The problem is that if you increase the price too much, the bad PR and hit to your reputation will likely offset any extra revenue. If a service like Hulu released a $50/mo ad-free tier people would freak out, even if they still had access to the same free ad-tier experience they do now. I don't know that it'd be beneficial.
I have - I can happily go without it most of the time. The watch has cellular, and notifications cover most of what I need.
Responding to things can wait till I'm back at a computer. If it's urgent, the watch can make calls, and if you're using a bluetooth headset, it's indistinguishable from a phone.
I don't travel without the phone, though, it is great having easy, fast access to everything (maps, browser, tickets, etc). The watch can do most of that but it's clunkier, and for me it's not a hill worth dying on.
So I do think you can achieve what you're looking for - rely less on your smartphone while still being 24/7 reachable. It is definitely worth looking into.
You might be surprised to know that Apple has been doing ads for over a decade. [0] They‘ve had ads for a long time, and still do - App Store search ads[1] and Apple News ads, to my knowledge.
I understand that companies want to avoid getting into legal complications over it, and that's why I think there should be some sort of legislation in place to force companies to explain decisions like this. This is becoming more and more important with time.
Something like: If you end your contract with someone because you think that they were in violation of the terms, you have to clearly list what your reasoning is for it, with no tolerance for black box answers.
DMCA takedown requests include the list of offending URLs. This should be made similar. "We terminated our contract because this, this, and this signal, make us think that you're in violation of its terms". You can then appeal, and obviously if the two parties can't come to an agreement by themselves, you can at least use the legal system.
Otherwise, we're living in a world where contracts between two parties mean nothing. Anyone can pull out of anything at any time for any reason, with no notice.
I remember the hype behind that one! "pure DOM animation in 60fps buttery smooth" or something along those lines, right? They had that periodic table demo.
More than that - apps start off with less features but after enough rounds of updates they grow into full-featured apps again, until some other app with less features (or a less-featured ground-up rewrite) kills it.
It's a really strange (and wholly unnecessary) cycle.
> If they can't understand that stuff they should not be making decisions.
That doesn't seem right. As a developer, if I were the CEO of a company, I would not be able to read progress from the legal team, or finance team, or any other team. What's going on with that lawsuit? No idea. Do I know how long it'll take to wrap that up? Nope. I can't understand any of their jargon. I still gotta make decisions about it.
I don't need legal competence in order to run the company or make decisions about stuff, and I shouldn't need technical competence either.
It's on us, as developers, to communicate clearly and give answers and reasonable estimates, so management can make their plans and adjust priorities if necessary. The process we use to generate those answers (agile, git commits, deployments) is entirely up to us and could not matter less to the business, at the end of the day.
As someone who's been eyeing Kubernetes as a learning experience, that actually is really disheartening to hear. If you're being forced to manage your database outside of Kubernetes, what are you using Kubernetes for? Running your web/worker servers?
I think it might just be that that’s not needed anymore.
The social networks of the past were useful as a way to keep in touch with people. MySpace, early Facebook, and the countless others from back then. Now everyone’s online 24/7, and accessible on multiple services all at the same time, all the time. You don’t need social networks to keep in touch with anyone anymore, their original raison d'être is gone.
What’s sought after now is meeting -other-, new, like-minded people and content. For that we have twitter, Reddit, TikTok, and whatnot. People want their bubbles. We’re all here on HN for that exact purpose.
> "giving in" does not preserve peace—it simply appeases bullies and makes the workplace toxic.
This doesn’t sound right. You are not going to agree with 100% of someone else’s decisions. No matter how much you discuss something, no matter if you understand all the ramifications, everything there could possibly be. Sometimes you’re just not going to agree with the direction someone else is taking, and you’re going to have to accept it.
And that’s okay. It’s not toxic to disagree with someone, or to accept that even though you might disagree, they’re going to do X their way (or that you’re going to have to do X their way because that’s what they want). That’s not office politics, that’s life.
They're just characters from different Unicode blocks, there's no functional difference between them that I'm aware of, other than that characters from some blocks are not allowed here on HN, including all emoji characters.
When I said "standard characters" perhaps I should've been clearer. I meant "they're non-emoji characters". Sorry, I didn't realise it would cause confusion.
The internet is built around this, and we've all collectively decided that it's OK.
But to your point, their robots.txt does allow this kind of access, so this argument is moot - they explicitly allow bots like archive.org's to crawl & index these pages' content.