God help us all if we have to break out the Emus
Info Sec - Software Engineer - Game Designer - Mod Dev - Digital Artist
God help us all if we have to break out the Emus
Hahaha, I wish.
You would be amazed at how ancient and poorly maintained many web servers are on the modern internet. SQL injection still consistently make the top 3 web app vulnerabilities as of 2021. If that isn’t being sanitized properly I don’t expect emojis would be handled much better.
Only if you call the deep-throating spez is giving him ‘mentoring’. It’s starting to make WSB loss porn look mild in comparison to the ongoing conga line of platform self-destruction.
I opted to switch to NewPipe and YMusic and haven’t looked back since.
Oh it was so much worse than that. Google indirectly banned every 3rd party app on the Play Store from streaming videos in the background to push that feature. Seemingly overnight every app that could do it vanished or cut the feature. Sure you can sideload a fix but your average non-savvy users got screwed into paying up.
As a software engineer who has dealt with so many incidents resulting from the garbage coming out of salesforce. SO. MUCH. THIS.
I swear it’s always in a perpetual state of duct tape no matter where I see it used.
I’m not surprised in the slightest. The politicians and managers in charge of said gov systems are usually of an age that have no idea the basics of how technology works, let alone infosec importance. It’s then contracted out to the lowest bidder on deadlines that wouldn’t permit proper hardening anyways. It’s not even a US specific issue, Australians deal with this dumb fuckery regularly.
Then you get some piss poor public apology, someone gets thrown under a bus, and the cycle repeats ad infinatum.
As someone else who uses Tailscale behind a CGNAT, this indeed works. I use it for accessing my home server from the office for a year now. You can’t quite self host anything public facing but anything on your tailnet can talk to it just fine.
Theoretically a VPS proxy into the server over the VPN could work for devices not capable of running tailscale but your mileage may vary.
They support CCS as the protocol
CCS is is only supported through a PLC translation chip on the vehicle side or a rare Magic Dock adaptor, and only when one side is non-Tesla. Outside of that, CCS is not a factor and the proprietary 11bit CAN bus protocol is used natively. Hence, Tesla controls every side of the equation on their protocol and payment processing without having to communicate with 3rd parties.
Name a charging provider that operates in a country tesla does not?
ABB chargers in India
Tesla you get quick wireless security updates, no waiting for a recall notice and trip back to the dealer.
This isn’t new or innovative. OTA updates for cars have been around years before EVs. But usually those don’t stop the car from starting then still be towed to said dealer because the update wasn’t properly tested or have fallbacks in case of failure.
Point is, shit is going to happen across the board for everyone and Tesla is NOT some golden child. It’ll just be another Apple case where dumb security claims get touted until hackers bring them down a peg or two.
Expecting all network operators to do that is not feasible or reliable. Tesla controls the car, protocol, charger, and payment processing. Everyone else outside the walled garden is openly handling a much bigger market with many more variables in more countries. Forcing customers to use an app for each brand of charger is also an accessibility nightmare. Fear mongering about skimmers is a dumb reason to remove traditional payment methods.
This is all before we get to the lack of screen or keypad means fuck all to security (it’s also an accessibility issue to remove them). If I can break into a Tesla charger wirelessly and fuck with your car, I’m going to do it, walled garden or not. Just look at the state of IoT.
EDIT: This comment aged well https://thedriven.io/2023/07/18/tesla-supercharger-spotted-with-credit-card-reader/
Just pull another Cambridge Analytica with it and watch the world burn. The shady siphoning of data for years until the secret leaks would skyrocket everyone’s anxiety about who had what and questioning everything around them all while conspiracies spiral out of control. If it were searchable at least you’d know, but this way the unknown would be so much worse.
Have fun with that mental image.
I swear if they really wanted to, they could do that and build a database on par with federal government departments.
Not quite what I envisioned by I fucking called it: https://lemmy.world/comment/849710
From the very beginning they were going to make it easy to join. The sinister part is always when you try to leave. If you don’t play by their rules they will take back everything and leave you high and dry. The ActivityPub support was never going to be a two way street. It’s likely a means to siphon fediverse content and drag users back into Meta’s data harvesting.
You say that but I fully believe Meta will tamper with their instance to push external users to sign up in order to engage with anything, while limiting the ability for them to get back out, effectively aiming to become the de-facto ‘center’ of the fediverse.
This is probably cooked up by the same people who conducted massive invasions of privacy during the pandemic by demanding live feeds and 360 scans of student’s private rooms. The worst part about this is the false positives could be intentionally faked to fail or expel ‘undesirable’ students with little or no evidence. It’s utterly fucked from all sides.
That basically sums up everything that comes out of the emerald baby’s fanciful brain farts. A walking joke that has gone on so long that the sad manchild has to do ever more expensive corporate stunts mixed with decade-old cringe humour to stay relevant. After all the shit he’s pulled lately, I’m not even surprised any more.
It’s the new rise of CEOs and millionaires seeking to milk the internet to the last fractional dime. Leave morals and critical thinking at the door. Every major company is doing this now, shutting out everything even remotely capable of being scraped into a LLM and paywalling what used to be free to satisfy post-covid shareholders. Accessibility be damned, line must go up.
Beyond that we have Google crippling the Android and Chromium open source code, Youtube blocking user accounts using adblock, Twitch banning sponsor spots who sidestep their pockets, and of course all of them are doubling down on AI with massive amounts of corporate sponsored IP theft and data laundering on an incompressible scale, suffocating any human content (see the Amazon book crisis).
I’d be interested in something like a lightweight CDN/replication with OAuth2 for logging into other instances. Each instance ‘replicates’ your original account but isn’t itself the master. One can be promoted to master in the event of an outage effectively migrating your account.
Would make for some difficult security considerations given a rogue instance could attempt to hijack authority.
Same with Express/Nord VPN sponsorships. Many people debunked the adverising BS they were spinning about blocking tracking when really it only masked a tiny subset.
As someone who studied infosec, those ads were infuriating. Now I just sponsor block it all because I’m beyond tired of it.