That's a great writeup. Is it possible to create a really long passphrase whose hash can't be reversed easily? Perhaps a diceware passphrase with six randomly chosen words?
Yeah and we have better training material for AI now. For example it could be possible to create a program that mimics Hackernews comments. There's more than enough training material on HN to create plausible-looking comments that aren't a bunch of nonsensical gobbledygook and that also pander to people's emotions.
> I can understand what they mean if they use "shill"
You kind of answered your own question. Many people never differentiate between bot and shill, instead preferring to lump those two words together. A bot is programmatic; a shill is a human agent that likes to amplify messages or spread disinformation manually. Although some shills may still use some level of automation, for example, often using several accounts at the same time using some bespoke software arrangement.
All the so called 'neo banks' are still in their infancy which is good reason to avoid them at all costs. I'm waiting until these startups mature (and they are startups).
One thing I never got about premium password managers is the question of: If I stop paying for the subscription, do I still get to access my secrets? I imagine there is still some grace period to backup your stored secrets, but I still think PW managers should offer a free tier so that you can be assured you will still be able to access your secrets, regardless of payment obligations.
I always loved the whimsy present in Unicode. For nostalgia, here's a HN post from 2010 pointing to the `Unicode Snowman for You` site (which is still up!)
It would be cool if MDN had a Stack Overflow question-and-answer style format alongside the main offering. Then Mozilla could take advantage of the gamification model where users earn badges and awards for their efforts.
Jeff Atwood said it once: `If you put a number next to someone's name, then that person will try everything to increase that number`. Also: it would look good on CVs and would be a good heuristic to determine if a person's really fit for a position.
This is poorly chosen language as it doesn't distinguish between freedom versus monetization.
I think most users of free software know it's 'free as in freedom' and they are not being duped.
I think most users of free services are duped into thinking it is actually free and are unaware their data is being sold and monetized and are paying for the service with their data. Lately more people are waking up to that fact though. I don't mean services like MDN, just things like Facebook, Google etc
So what if someone sleuths around in the e-waste dept. of Instagram and steals a few hard-drives with literally Terabytes of potentially very sensitive data? That's why I would hope Instagram are encrypting data at rest with something like LUKS.
Yes, and you could also queue files for deletion at a later stage by throwing away the encryption key for a large batch of files which have been queued for deletion.
I want to know if the photos are securely deleted. It's not enough that the mere reference to a file is gone. I want everything overwritten with zeroes, and the photo made properly irrecoverable.
It gets rid of the programs that obtrusively weigh down the system, as-well as removing a lot of cruft the typical user doesn't need. Disclaimer: it can break some things, but it's a small price to pay for a hardened system.
It's as if the author writes content to /please/ Google. There are other players in town that will spread my message wide, other than Google. Google is a single point of failure too. If most of your traffic relies on a black-box algo developed by Google, at some stage you are going to be butthurt by that algo. Others will celebrate their success at gaming Google's algo and getting good rankings consistently, but these people are mostly blackhat SEOs probably trying to peddle cialis with a cheap discount.
> Security – The operating system installed in a container is usually short-lived, very minimal, and sometimes read-only. It therefore provides a much smaller attack surface than a typical general purpose and long-lived server environment.
Is this true? I always thought things like Docker are massively insecure because they don't respond to the threat landscape that well, since they are kind of 'frozen in time' and kept that way for years at a time without any critical security updates.
I miss OVH's old control panel. It was so nerdy and to-the-point, unlike their newer modern interface that heats up my CPU with boatloads of javascript, and adopts the 'flat' design pattern that has now permeated every site in existence.