> sent from a legitimate government agency email domain,
DMARC-verified-sent from a legitimate [...] domain? -> Someone pwned a mailbox at an agency? I'm sure they would've spun the story into "the government was hacked, not us" in that case.
Or "sent from" a legitimate [...] domain? -> Spoofed envelope sender / FROM? Then Revolut's simply been had by the nose. If the domain is indeed a government domain, and does not publish DMARC records, then a due diligence check on who they're sending such personal info (ie, call that purported government agency up on the phone) would suit them.
After all, they're very pedantic about me running their app on a phone with an unlocked bootloader. I'd then hope that they'd be symmetrically pedantic about verifying whoever they're sending my info to.
RSS is great for informing readers of new content. Sadly only a few actually use it, except (unknowingly, for a large part of the population) for... Podcasts.
So, thinking out loud: you could offer people to subscribe to your website by publishing a RSS feed with dummy audio, using a link in the the episode description to get people to hop through to your website. And then you offer the appropriate "subscribe in iTunes / Spotify / generic podcasting app" buttons on your website page.
And then suddenly the masses can sign up to your updates! And they can easily unsubscribe! And you don't have to deal with email, and can use static file hosting! There'd even be a discovery inroad as presumably the Apples and Spotifies of this world will push it through the personalized recommendations pipe just as they would for any other podcast.
It's a bit subversive but it would work wouldn't it?
Good idea, and unfortunately one of those that would work only while it’s not popular. If it turns out to be good enough to become popular, here comes the enforcement.
It'd be hard to detect from structure. Episode descriptions can and do legitimately have links. And if/when it comes to deep inspection, instead of a dummy audio file one could use a TTS-ed audio version of the post, there's some legitimacy there. You can even flip it around and claim that the blogpost is the "audio transcription" "for those who want it".
But yeah let's not underestimate the power we're giving these platforms. If down the road it doesn't match the monetization strategy? Platform giveth, platform taketh.
Turning shoes into carpet padding is probably "downcycling". I think recycling would mean most of the shoe would be used for new shoes or something of similar complexity, retaining the grade and value of the input materials.
Downcycling is when you reuse something for a less refined purpose. For instance you can use contaminated plastics (im the sense of somewhat mixed types, bits and bobs of labels etc) to make humble park benches, but you won't be then reusing that low grade park bench plastic to make the Hubble space telescope with.
Still, downcycling into carpet is better than dumping the shoes on a coral atoll of course. Yet it's a step below recycling.
If you've installed RealActualBankApp (with the ID of real.actual.bank.app) once (from whatever source!) then there cannot be another app installed with that same id but signed with a different public key (oversimplified version of the story, there is a key rollover scheme).
You can however install an imposter app that's also called RealActualBankApp, with the same icon. It'll need to go by a different ID.
So then we're down to the same problem, or pseudo-problem, of identity confusion, as we have for banking website URLs. Where is the ID/URL shown, and does the user know that it should be mybank.com and not mybank-incorporated.com ?
Android Key Attestations are bound to the app that minted the key, so this does prevent a fully-functional clone from working if they use attestation during auth. But it doesn't prevent a fake app that only exists to phish credentials.
Wear on the chain is greatly increased though on a 1x12 versus a 2x10, because of alignment.
Tolerances on a 1x setup are also much tighter, not ideal for long distance cycletrekking adventures.
Also, with a front derailer, dropping the chain to a smaller cog in the front to get to a lighter gear results in much happier shifting than having to lift the chain to a larger cog on the rear derailer when going uphill.
When MTB racing you can really get some advantage out of shifting combination discipline using a front derailer, when going from a downhill into an uphill.
I'm sad it's hard to find a 2x setup on new bicycles nowadays :-/
> "The victim" of using a certain operating system? Please.
Perhaps "victim" in the sense of not having much choice/agency? Neither in the choice of operating system (due to sparsely restrained anticompetitive behaviour of incumbents over decades) nor in how they're treated (entrapped) by the operating systems. The OSes are really POS (point of sale) terminals for media and cloud services.
Thus consider most operating system users aren't really users. They're "usees", they're being used. One could surmise that the Microsoft/Apple/Google shareholders are the real users of the operating systems.
If you'd left the commercial OS world in the Win2K/OSX 10.4 era for, say, Gentoo Linux, and would come back now to look over someone's shoulder while they're using (or rather, being used by) their operating systems, you could be forgiven for coming away with the impression that some kind of authority inversion has taken place in the meantime.
Nobody works by choice so I suppose that makes us all "victims" of the system. I'd put using certain software below many worse kinds of suffering however
not true. anybody working as a volunteer works by choice. i work by choice, because i could instead live in germany on unemployment support and welfare, because i am to old to find a job (germany has a big problem with age discrimination) and the government can't force me to work as a selfemployed freelancer. so i choose to work because i want to. not because i have to.
at least in germany i can't think of anyone being forced to work in a job that would cause them suffering. well, except working with windows, and hence from that perspective a worse kind of suffering is quite unlikely.
that aside, almost all suffering comes from how people are treated at work. the days of people suffering in coalmines or other seriously unhealthy work conditions with out any alternative are over. anyone there still suffering at work today is being actively exploited by abusive business owners. yes, the people working there may not have a choice, but we as a society do have the choice to not tolerate such working conditions, and therefore making such demands is not privileged.
Wow. Well it's a very gracious choice of you to not mooch off the welfare system.
> at least in germany i can't think of anyone being forced to work in a job that would cause them suffering. well, except working with windows
You must be actually trolling. You'd honestly choose stocking shelves in a supermarket over being a windows sysadmin? Have you ever heard of RSI? Or actually ever worked a day of physical labor in your life?
we were talking about suffering and dignity. i see nothing undignified about stocking shelves. they don't make me angry, for one. but also suffering, the moment stocking shelves causes any sort of pain you are no longer able to do the job. noone is forced to suffer at work. at least not in germany.
physical labor? not to the point of suffering. the point is, in germany, jobs that make you suffer through physical labor do not exist, because they are illegal. grey areas exist of course, and cases that are not discovered because the victims (and in that case they are victims) don't speak up.
but this is completely besides the point because what i am talking about is what is more difficult to cover by law, and that is mental suffering.
your argument essentially appears to be that because physical suffering exists, we should ignore mental suffering, and anyone complaining about mental suffering should stop whining because others have it worse. 1st world problems or whatever.
so i should also tolerate my boss yelling at me, my coworkers bullying me, being verbally abused, how about discrimination, sexism, etc? surely any of that is more tolerable than the physical pain i'd get from stocking shelves.
just because something worse is possible that does not dismiss the stress and frustration i have to experience when working with windows, or with LLMs.
Maybe one of the reasons why hosted postgres often disallows extensions is due to security concerns from loading arbitrary machine code on a shared host. I wonder if pgrx changes the calculus here.
Since it's a procedural language, you can't do things like create a new index implementation or something else super low level. But there's still a lot you _can_ do. Like implement a custom comparator for a custom type and then use that type in a btree index.
Reads like it’s not copying the parent, it’s manually constructing the env dictionary to be passed to execve explicitly. I do this in one of my tools at work because developers were exfiltrating secrets and hand jamming them into .env files.
Yeah, so, it's not injecting? To inject something into X, X needs to exist. X does not exist yet when execve is set up.
I'm not being pedantic. I just want to read about injection when I'm promised injection :-) because that'd be technically interesting for me. Plainly calling execve isn't so much, I have the manpage here already :-)
DMARC-verified-sent from a legitimate [...] domain? -> Someone pwned a mailbox at an agency? I'm sure they would've spun the story into "the government was hacked, not us" in that case.
Or "sent from" a legitimate [...] domain? -> Spoofed envelope sender / FROM? Then Revolut's simply been had by the nose. If the domain is indeed a government domain, and does not publish DMARC records, then a due diligence check on who they're sending such personal info (ie, call that purported government agency up on the phone) would suit them.
After all, they're very pedantic about me running their app on a phone with an unlocked bootloader. I'd then hope that they'd be symmetrically pedantic about verifying whoever they're sending my info to.
reply