asterius | 8 years ago | on: AV1: A new general-purpose video codec
asterius's comments
asterius | 8 years ago | on: Slack's bait and switch
As to spoofing, we've got to move beyond humans memorizing unicode strings or profile pictures as a means of identity validation. Its shambolic enough that twitter users constanly change their display string, obscuring the twitter handle, but even without that problem, how many people send bitcoin/ethereum to @eloon_musk?
asterius | 8 years ago | on: Slack's bait and switch
How it works Anyone can run a server of Mastodon. Each server hosts individual user accounts, the content they produce, and the content they subscribe to.
Each user account has a globally unique name (e.g. @[email protected]), consisting of the local username (@user), and the domain name of the server it is on (example.com).
Users can follow each other, regardless of where they’re hosted — when a local user follows a user from a different server, the server subscribes to that user’s updates for the first time.
asterius | 8 years ago | on: How Airlines don’t care about privacy: Case Study Emirates.com
I checked firefox and it works correctly too.
asterius | 8 years ago | on: Project Gutenberg blocks access from Germany
asterius | 8 years ago | on: How Airlines don’t care about privacy: Case Study Emirates.com
asterius | 8 years ago | on: How Airlines don’t care about privacy: Case Study Emirates.com
Makes me suspect that a lot of client side validation is happening with mobile apps.
asterius | 8 years ago | on: How Airlines don’t care about privacy: Case Study Emirates.com
I think we can be confident that sites that don't even use CSP won't be implementing Expect-CT any time.
asterius | 8 years ago | on: How Airlines don’t care about privacy: Case Study Emirates.com
The fact that your mail client / embedded browser takes you happily to sites with broken certs, giving them a tracking token (and in this case, total access to your booking) is also quite a problem.
asterius | 8 years ago | on: Hacker News's Undocumented Features and Behaviors
It is notable that HN does not support blocking particular users, or indeed annotating that you like them. Though plenty of fans will upvote well known authors, it is not possible for you to keep a list of people who you think have written well in the past. I'd love it if I could, e.g., mark favourite author names in green.
HN is also notable from my perspective for having some people with good technical sense and clear writing, but very extreme views on other matters, to the extent that they would be pariahs in RL situations.
asterius | 8 years ago | on: Qt or HTML5? A Million Dollar Question
asterius | 8 years ago | on: Qt or HTML5? A Million Dollar Question
asterius | 8 years ago | on: Fired Google Engineer Loses Diversity Memo Challenge
asterius | 8 years ago | on: Fired Google Engineer Loses Diversity Memo Challenge
asterius | 8 years ago | on: E-Stop and Fuel, software that keeps you awake at night
asterius | 8 years ago | on: Escaping Data from Faraday-Caged, Air-Gapped Computers via Magnetic Fields
asterius | 8 years ago | on: Why Paper Jams Persist
asterius | 8 years ago | on: VM escape vulnerabilities patched in VirtualBox
AWS recently started moving from a custom Xen to a custom KVM, but it doesn't seem it was for security reasons. Xen certainly is heavily used by public cloud providers.
asterius | 8 years ago | on: GoPro has discontinued its developer program
They could have made money from their drone product line by diversifying beyond 'toy'. But that would have required integration partners, different sales channels etc, and they didn't have the skills to build that.
asterius | 8 years ago | on: Ask HN: Is big-endian dead?
https://parisvideotech.com/pvt-4-les-formats-et-codecs-du-fu...