I think a lot of sites already do that, although they may not send an email saying 'sorry, we don't have that e-mail on file,' it is pretty common to get a 'if that email exists, we have sent a reset e-mail to it' message when you do a password reset that doesn't expose if the email exists in the system.
Although to the point of this article, they will then happily tell you you can't use an email during signup, so it is a mixed-bag.
I suppose if you allowed multiple usernames per email, you could just email them all the usernames that they have on that email address when they forgot their username, but that seems like a clunky setup. It probably depends a lot on the service though, as someone posted a link to a discussion from 2014 about Amazon's reasoning for allowing multiple emails elsewhere in this thread, which makes a bit of sense for their use-case.
I think you have a good point in that if you are going to use usernames as an identifier, there is an argument that having an email also be an identifier is sort of redundant.
One problem with that is that when users are given the option of an arbitrary username, they tend to be much more likely to forget that username than they are the email address they use daily. So, you need some way of resetting their password and letting the user recover their username. In some cases, you could pair that with other identifiers, like their name, phone, social security number, etc. However, then you are just trading the email as an identifier for something else, which you would also need to check during registration.
For this reason, I've found that moving away from a username and just relying on an email for a login makes managing multi-user sites a great deal easier from an admin side.
Based on the article, it looks like the bricking/disabling occurred after an update to the latest version of the OS.
So, I don't think it is accurate to say that it 'allows remote control by its masters,' as it appears that they just added some sort of check in the latest version of their OS that can tell if the hardware is legit. There isn't any evidence, at least not in the article, that indicates they have some sort of remote control/phone home service running on the phone that allows them to control it arbitrarily.
To be fair, I would be incredibly surprised if creating a built-in Android content blocker is something Google would even consider, let alone implement.
It is disappointing that they aren't making that API public, but just having that be a core feature of their operating system is pretty huge. Hopefully they have plans to make it public or Firefox will just implement their own ad-blocker into IOS firefox.
I don't think this adds the layer of security you think it does, merely a minor bit of obscurity. In context of the specific vector you reference, author={$user_id}, it probably doesn't do anything at all to protect you.
Not that there is anything wrong with adding a bit of obscurity, not using 'admin' as a username and using a non-privileged author for posts can go a long way.
However, if you are worried about someone getting your username from "author={$user_id}," using a user_id of 2,3,4,5, ect, probably isn't going to protect you. I think you are incorrectly assuming that the person that would use this method to get a username is going to stop if they get a 404 at #1(or even after just a single attempt.)
Except, the bandwidth has already been paid for, at least twice.
Once by the consumer by way of a monthly internet bill and once by the content provider(website) in the way of their hosting/bandwidth costs.
It is not clear by the ISP's name(Free) whether or how much they are charging for internet access. negrit seems to suggest that this ISP has a fairly aggressive pricing model.
However, if the cost of people actually using their internet access, especially just to browse websites, is too much for Free, they should look to their pricing model or consider upgrading their networks, as opposed to trying to extort(or at least block) advertisers.
As you mention, this ends up being a much bigger issue in regards to net neutrality. For now, it is just youtube that is using 'too much' bandwidth, but blocking that will only mean other sites will take its place as bandwidth hogs.
Hopefully this will result in discussions to finding a fairer solution, but I believe that should involve upgrading infrastructure and providing better service, rather than blocking sites like youtube or netflix.
That is incorrect, at least for most retail OEM keys anyway.
I noticed that starting with Vista, the distinction between OEM vs Non-OEM key seems to have been reduced. This makes life easier when there is no recovery partition or the hard-drive is hosed. Whereas with XP, you did have to use an OEM version for the key to work.
I have not had any issue validating windows using the above versions of Win 7, as well as a few vista cds that I believe are retail, as long as there is an OEM sticker on the laptop. Every so often I have to call in and do the automated telephone activation, but they are valid CD Keys and I think that is probably tied to how often the key was activated.
Having said that, at least with Vista, the disc the manufacturer gives you is often locked to a specific laptop/bios/board.
Given they state that some accounts were compromised by stolen passwords from "other websites," it would make sense to run some sort of dictionary attack using lists from those sites.
- The SPAM filter in Thunderbird is A.W.F.U.L. Let me repeat that A-W-F-U-L. Despite training it for years it routinely misses the same spam, with the same title, and the same content, while sometimes marking very important emails as junk.
As someone who has also been a heavy Thunderbird user for years, I have not had the same experience. If anything, same content/subject/sender email spam is where Thunderbird's spam filter shines for me.
I have two fairly heavily spammed accounts, one of which has a public email address. They consistently catch and remove same or similar content spam every day without issue.
In regards to false positives, it does happen sometimes. Although in most cases the emails that end up in the junk folder legitimately resemble a spam message. Almost any time a legitimate email has been marked as spam, which doesn't really happen all that often, unspamming it is sufficient to ensure the sender doesn't end up there again.
Game and software companies have been doing this for a little while now. I think Sony may have done it first such TOS change to get a bunch of publicity.
As far as being legal or not, I am not sure it has been officially tested yet. However, I think it certainly seems like dirty pool.
Literally having to re-learn the OS is almost certainly an over-statement with pre-win8 versions, as you are correct base functionality in previous versions is in many ways consistent.
However, how I interpret that statement is that it is ill-advised to over-estimate the general computer user's ability to adapt to changes, or the way 'little' changes end up disrupting the way they interact with the OS.
I might be interpreting OP's statement with my own bias, or reading into it too much, and we could probably go back and forth on semantics all day.
Regarding the control panel, I think the search functionality, which again a lot of non-techies may not even realize is an option, is the main redeeming quality and makes it much less aggravating to work with.
I would have to agree that you are looking at this as a power user, rather than a regular user. And, from that perspective, I would agree that the changes are rather minimal and intuitive between recent versions.
However, for older folks, this view is not typically the norm.
I do computer repair and routinely listen to gripes about changes in Vista/7.
For instance, I often hear complaints about things like changing the theme/style settings, searching, modifying network interfaces/settings, or changes to how the control panel works.
These are often, aside from theme/network settings, an improvement, minimal, and intuitive changes IMHO.
But, to someone who is barely computer literate, even "little" things like that can represent a big change and can be very confusing.
And, of course, the change from Win7 et all -> Win8 is massive, even to me...
Wow, when you count 123456 too, it is a big chunk of the office. Not to mention the others that had 12345 as part of their password.
I wonder if this is an IT policy gone bad. Perhaps the guy who set it up used 12345 as the default and, of course, nobody ever changed it.
I learned a long time ago to use a somewhat complex password when setting up new accounts, because otherwise 3 years later, they will be using the insecure temp password you gave them.
"My time is worth money. [...] assuming I work instead"
That is a big assumption. I think the assertion that time is ALWAYS money is incorrect. Often, it is just time. At 3AM, or after you stop working, your time is probably not worth $75/h.
In your example, you only loose money if you stop working early to account for the drive. So, for example, instead of working 8AM-5PM, you work 8:30AM-4:30PM, in order to still get home at 5PM.
With that sort of logic, you could just as easily say that if you work 2 Extra hours each day for a month, the car paid for itself and you still get to live in the country. However, like your example, this assumes your work amount is infinite.
So, while an argument could certainly be made for saving money in gas, spending less time driving, or more time with family, unless you decide to take the drive time out of your work hours, the opposite of how most people determine when they need to be at or leave work, you wouldn't be loosing money, only time.
Hostgator does this too and don't reset, only resend passwords. It has always bugged me. There is no reason to be storing plain-text, especially for their billing system.
At least Dreamhost says the Shell passwords are hashed, which makes sense.
I didn't know that about the plain text dreamhost web-panel passwords though.
Yes, at least in the past, Google has taken into account intent when it comes to cloaking, letting some big sites get away with it and still rank well in serps.
However, I can see how your initial suggestion of showing full content to Google, could be viewed as solely for preserving rankings in an artificial manner.
As an example of cloaking, some News Sites let Google index all their pages, while requiring actual users to login/register to view it.
Typically, if the user has a Google Referrer, they can view the page one time for free and then need to login/register to view anything else.
Visiting the page directly or with a non-google referrer shows a register/login page.
New York Times was one that does(did?) this. I stopped visiting them when they started. I think Washing Post, or one of the posts, was doing it too, as well as a number of other sites.
Experts Exchange used to basically be the same way, although I think they are doing it differently now, and they were slapped by Google a long time ago for cloaking, so changed to a different method of cloaking...
Although to the point of this article, they will then happily tell you you can't use an email during signup, so it is a mixed-bag.
I suppose if you allowed multiple usernames per email, you could just email them all the usernames that they have on that email address when they forgot their username, but that seems like a clunky setup. It probably depends a lot on the service though, as someone posted a link to a discussion from 2014 about Amazon's reasoning for allowing multiple emails elsewhere in this thread, which makes a bit of sense for their use-case.