Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)B
Posts
6
Comments
234
Joined
2 yr. ago

  • It sounds like she's very upset that Dansup made it explicit that he was fixing this issue, thinking that even exposing it in commit comments (which as we know get way more readership than blog posts) would mean people knew about it, and the less people that knew about it, the safer her partner's information would be since she is continuing to do this apparently. You will not be surprised to discover that I think that type of thinking is also a mistake.

    I agreed with you at first because from your description it sounded like she was saying security through obscurity was a good thing. But that’s not the case.

    What she’s saying in the blog post is that this a 0-day and should be handled according to the best practices for 0-day disclosure.

    You have to decide if you want to

    • publish the findings before the fix -> more people will know and exploit the vulnerability but users might be aware and may or may not be able to mitigate sharing even more
    • publish the findings after the fix -> the opposite

    I don’t pretend to know enough to judge which option is the best. But I can’t fault the blog author for pointing out that Dansup didn’t follow best practices.

  • What’s with this thread and people using the wrong word? First cease/seize and now faze/phase.

  • That’s nice to hear. Usually I need to grow on people.

  • Yeh, there’s not mushroom for interpretation.

  • no phone number to give unlike all their competitors.

    SimpleX would like a word.

  • Deleted

    Permanently Deleted

    Jump
  • So since Apple is probably not just throwing money away… what other reason could they have?

  • Deleted

    Permanently Deleted

    Jump
  • It’s still good marketing. People will associate a good service, with good/great shows/movies and without all the fluff that Netflix has, with a good company.

  • Skepticism rises as to whether the aggressor who could have peace by leaving the invaded country alone actually wants peace. It’s a total mystery.

  • Easy: „If you want to learn more check out our second channel where we explain in depth how we approached this topic, the technology used and what we learned.“

  • Dehydrate!

    (For anyone unfamiliar with it, there’s a similar concept in Cixin Liu‘s Three Body series. Forgot which of the books.)

  • You can just pay for and use single services with proton though so I don’t see this as an „I wish I knew this about Proton before“

  • I was just recently thinking that spray tan on your face is probably considered makeup. And I was wondering if real men (in their eyes) should wear makeup.

  • Solong and thanks for all the dead fish.

  • Oh well, I see that we have no control anymore.

    Bullshit. You can turn off auto download/update in settings.

  • Well if those species can’t pull themselves up by the bootstraps and produce value for shareholders it’s their own fault…

  • Where were you when I was being called a pedant? 😅

  • I'd say it also turns off people who have expertise in other areas and would chime if there wasn’t so many hurdles.

    Say an astrophysicist wants to connect with the community. Do you think they want to take time out of their day to learn the intricacies of a tool that otherwise has no use to them? Do you think they should have to?

    This will inevitably keep this community gated from having a diverse userbase that Reddit has had at its peak.