That's factually incorrect. No one in the EU can sue a California company for failing to comply with EU laws so long as the company does not have a physical presence in the EU. They'd have to block their site or something as an EU court has no jurisdiction over a California company and would be unable to take action against them.
An explicit law would need to be made in your jurisdiction forcing you to comply with their laws. I'm not aware of any such thing.
You don't reside there, you're not liable to abide by their laws. I run a small US company, I don't have to comply with GDPR for example. Same applies here.
I don't see why any company would implement this, perhaps appeasing regulators at the federal level.
There've been a few cases where the ransomware was not decryptable - sites like BleepingComputer frequently discuss which ransomware have been cracked by researchers, which are currently actively run and will provide keys and which are undecryptable and you shouldn't pay in any circumstances. Basically it just makes things more complicated, but people are still willing to pay if they can in their specific case and the one they're infected with is reported as regularly providing good keys.
I feel this is actually a decent service for a few reasons:
- Many average users don't want to understand cryptocurrencies, how to safely and securely buy and use it is a challenge in and of itself.
- They're on the hook and the client pays nothing if the ransomer fails to provide a working key.
- They'll also manage the ransom decryption software - if there's problems with it there are 3rd party tools that can often do a better job of decryption than the original decryption tool, again, this is something that's going to be complicated for average users to deal with.
- For some ransomware there are decryption processes available without the need to pay the ransom, figuring out which of these applies can be challenging
- Certain institutions may be unable or unwilling to work with the attacker directly - introducing a middle man to broker can help solve this.
> That sounds like a contradiction --- if you can already execute code, I'd say you're quite privileged.
If you're in a VM, you have no privileges over the host CPU, you can't switch to another VM or to the host itself. That's what's meant by unprivileged here.
I only focused on the JAMA study as I'd seen it before, sorry about that I see it may have looked pretty slanted now, I wanted to have a better look at the positive metaanalysis, however the link on wikipedia was broken, look at where it points on wikipedia, you'll see "Cite error: The named reference Gotink was invoked but never defined (see the help page)."
I'm not disagreeing with you about that depression and anxiety thing, but it seems a bit of a stretch to suggest it to a generally mentally healthy person.
"We found low evidence of no effect or insufficient evidence of any effect of meditation programs on positive mood, attention, substance use, eating habits, sleep, and weight."
As for "destruction of other cultures" - well, people use the same excuses to say that homeopathy is great and crystal healing will cure your cancer. It's a non-sense argument. This has no cultural bearing at all, just a rejection of bullshit. I have no interest in blindly approving things without analysis just because they came from other cultures. Study them. The results here are sketchy at best.
Did you read your own link? One line from it mentions the study that actually brought me to this conclusion:
"A meta-analysis on meditation research published in JAMA in 2014,[167] (that included a combined total of 3515 participants), found insufficient evidence of any effect of meditation programs on positive mood, attention, substance use, eating habits, sleep, and weight."
While there may be other with differing results it's... pretty sketchy in any case. I would hardly say scientific enough to belong in such a class.
I had a look at this when I considered meditation once but found it'd most likely just be a waste of my time. I'd rather not flush my time down the toilet.
> Like - imagine if US was attacked and the attacker killed 60 million Americans. I can almost guarantee that no matter how strongly Americans believe in the 1st amendment, saying that it hasn't happened would be made illegal.
Why would scale change people's values compared to say 9/11? It's important to me that we're the deciders of truth for ourselves. I believe people fighting in those wars have fought for my right to believe what I choose and not what a government tells me.
Think about this in the context China, even today and I think you'll see why I feel this is an incredibly valuable right. Governments can lie too, the American one has many times throughout history and we should and do demand a right to question it.
I'd argue the type of malware described in this article is fairly to completely harmless to the user. Harm to ad networks and a bit of wasted bandwidth is basically the worst case scenario.
The wasted bandwidth would be made clear by the OS to the user too, so it'd be trivial to identify if it was a significant consumer.
> because you can just ask for permission from Android
You cannot ask for permission to bypass sandbox restrictions on Android. You need root access, which means physical access to do things like unlock the bootloader or an exploit.
iOS sandbox seems slightly weaker here due to the use of hidden/private functions to protect certain things, sideloaded apps would likely be a bigger risk on iOS than Android at the moment, but that's not something unresolvable.
In any case, the things you're discussing aren't really so problematic - isolation systems are only getting better, OS level ones are improving every day. We could easily have sandboxes at this level just as secure as the javascript ones.
I'd say that the sandboxing introduced by mobile OSes today solves the vast majority of the problem.
By isolating applications and introducing permissions, malware that can steal or encrypt user data isn't possible even for people installing those pirated APKs.
An explicit law would need to be made in your jurisdiction forcing you to comply with their laws. I'm not aware of any such thing.