This reads more as an article about how the author believes that all men who approach her are potential rapists. Hitting the feminist fallacy of "All men are evil" square out of the park. This turns away most male readers, exclusive of the most valorous of white knights.
(Source: "I will begin to evaluate the possibility you will do me harm. That possibility is never 0%.")
There is also no real "guy's guide" here, there are a few pointers but they're wrapped in a "You're a rapist, Harry" hearsay stories.
Perhaps the author could have either focused more to enlightened male readers on acceptable ways to approach women (top ten lists are still popular on blogs right?), or better yet disclose where she is meeting these guys so other females can avoid encountering such douchebags.
And for those who can't find the points in the article:
* Respect women
* Dress nice
* Take subtle clues
* Don't Rape (you don't say?)
Correct, which may also implicate any "hired guns" lawyers who send DMCA notices for crackpot clients.
In one instance I personally saw, a lawyer sent a false DMCA and they signed it under penalty of perjury for their client. This resulted in a clarification of the perjury that the lawyer may have placed themselves in, and threats to bring it up with the state bar association. Personally I doubted the guy was even accredited in the first place, but the DMCA related harassment stopped promptly.
Most people who are first interacting with the DMCA law are unfamiliar with the fact it has protections against people files false notifications.
Without knowing details about this (and not providing legal advice) this may be how it would work:
If the claim is in fact BS, go lawyer up. File a counter notification, wait 10 days and your content will be put back online (unless they file an injunction to keep it offline), then you file suit against the alleged infringer for the statutory damages of $150,000 per false alleged infringement claim. Likely they'll settle out of court for some number less than their legal costs/time.
Pay your lawyer, use the rest to fund your project.
Go out for a pint, and tell the story to tell on how your project was funded by out witting a scammer.
MFA and Authentication has a much larger scope than what you've brought up here. I should start by I think passwords have atrophied and should be replaced, and MFA is the best option we have to replace passwords at this time. However, MFA has flaws many people are unaware of.
I apologize for starting with a contradiction to something you state, but MFA does not neutralize most hacker threats. It only addresses authentication, it's unable to help against software compromises or user compromises -- Phishing attacks would still be effective, as the user will input a valid temporary token. What is MFA effective at preventing? Brute force password attacks, and users choosing bad passwords.
An attacker who compromises an internal system or is successful in egressing a login database will gain the session tokens for logged in users and be abel to use that to access compromised accounts (subverting the entire logged in process.)
But, you covered this, so I will digress to mentioning MFA's authentication concerns:
The "forgot password" or "lost my token" systems are always a weak link. Frankly, it's improbable (due to overhead costs) that any bulk service provider (twitter, gmail, etc...) enact a strict verification process beyond automated email/phone verification (and this has been compromised before, lookup the attack against cloudflare's google services.)
Second to the "lost password/token" attacks, there is the simple attack against the session ID/token. Remember, once you're logged in, your computer will store a token that it shares with the service to verify you are still authentication. While the token will expire, if the token is active then system will accept the session ID or token to verify you are logged in. The egress of data from the twitter login database included these session IDs. Of course, this requires a compromise of the system and not a MFA login compromise.
Finally, on your discussion of using an MFA token for every login, every time. This is actually not true in all cases. A reasonable approach most implementations use is to require MFA for logins from unknown computers/IPs, once a system is verified via MFA a user would likely have a grace period when they would have to enter only their password until that grace period expires and then they would have to verify via MFA again, this could be 1 week, 1 month or 1 year+
Of course these statements I've made are really up to the environment's configuration, ideally in a very strict environment it's expected you verify via MFA each and every time, session IDs are updated automatically with every action and users are aware of security risks. But we don't live in this security/paranoia utopia (and perhaps that's all for the better.)
Hope I've helped spark some discussions on MFA here. Bam, i'm out!
Yes, this is the by far the most common answer. However, one would need to remember to bring said special cable, which at that point why don't you just remember to bring the wall wort USB adapter instead of carrying around a charge only cable?
Side benefit: wall wort USB adapters can push more amps to your device (e.g.. faster charge) than USB hosts.
Many android phones do this, however not all. This is up to the specific ROM you are running.
iOS devices have put in a phenomenal effort to secure against these attacks, including requiring encryption keys before allowing unknown computers to access the device or data.
Agreed this is an article churn for advertisement.
Recently this attack was back in the news due to NSA referencing it in a mobile device security paper.
BTW if anyone has questions about it, feel free to ask me. I'm the guy (along with friends) who was building these kiosks and deploying them at "hacker" conferences and then gave a presentation on the matter.
With any large gathering of people you are certain to find a number of outliers with disrespectful social impositions (being racist, sexism or anti-techism.) Defcon is no exception, so it is a grave presumption to place the blame an event itself for the disrespectful actions of a handful of attendees (unless there is a track of "how to seduce women by licking tattoos" at the event.) Furthermore, the fact it is Defcon is held in Las Vegas which only fuels any such flames of inappropriate behaviour with litres of alcohol and tourists who may just be at the casino bar per-chance.
This said, I am for these cards. Sometimes people simply need to be told in a direct matter to knock it off. However, please do not cast blame on an entire event for the misguided actions of a few people.
I hope this individual has an enjoyable time this year, at the least it appears they plan on returning so whatever misdoings of last year were not enough to dissuade a return visit (even if they plan to now be armed with Defcon funded "creeper cards" it should make the whole experience fare more interesting or enlightening for all involved.)
Under US law you would use the civil court system to recuperate losses/damage (crimes against a person), and criminal court system to place the perpetrator in jail (crimes against society). This really is a bleak abstract of the US court system, you really should talk with a lawyer if you are considering further legal remedies beyond what ICANN policies offer.
1) How the malicious party gained access to your account(s) in order to approve the transfer. This is typically caused by an email address compromise and something you will deal with directly with the email provider (be sure to request logs of recent access to your email account ASAP, this will help later). Also, change your account password on this account immediately and scan your local machine for malware.
2) The more pressing issue for you though is retrieval of your domain. Luckily ICANN has a very specific process on how to handle this, and it's mainly up to your registrar to handle for you. So contacting your registrar is in more cases all you need to do (remember, this isn't a basic support inquiry though, so you may need to wait for the fraud/abuse staff, depending on the registrar.)
You can review the specific process the registrar should be following here: http://www.icann.org/en/help/dndr/tdrp it's the official 'transfer dispute resolution policy'. I have handled these at the registrar level and 95% of the time it goes smoothly as long as the facts are laid out for all parties. Information such as the IP who accessed your email account at the time of the reg. transfer is one of the key pieces of evidence you can provide your registrar to make the transfer dispute go faster, however your registrar is likely (obligated under due diligence) to have their own records of the transferrers IP who approved the request.
I wish you the best of luck, I can't really help out specifically with your case but if you have any questions about the TDRP procedure feel free to ask.
P.S. "Step 3" would be to address any losses, if you want to seek this option out you will need to lawyer up as any damages claimed would have to be recovered in a civil dispute (this is presuming you are presiding under US law/courts)
Excellent article to bring up with recent events. This rant happens time and time again, the record companies double dip and screw over the artists and their customers repeatedly. When is enough going to be enough?
To whomever can revolutionize the music/media industry with stewardship for the arts you deserve these profits for your work.
Dailychanges monitors authoritative name server information, this is unrelated to registrar.
You can have your DNS with GoDaddy but still transfer your domain registration to namecheap/gandi/anyone else. In fact, for people not wanting any downtime this is very likely what they did.
This is actually sadly exactly what the author missed in their article. DNS propagation is directly controlled by the TTL setting on a domain entry.
TTL stands for Time To Live, this is the number (in seconds) that the DNS entry tells people to keep it active in the DNS server cache's (presuming the DNS server will not over-ride this for either a higher or lower number, which is entirely their choice but not common.) This is done so that any request to adomain.com will not have to require a DNS lookup to the main serve for every page request.
It is true that if you have not done a lookup on the domain, then your computer and DNS servers would presumably not have any active DNS records for the domain. So you can make a change and "viola" within 5 minutes (the next time you visit the site) you will have the updated record. However, if you had recently done a DNS inquiry and eceived the record for the old DNS entry, you will need to wait for the old DNS entry to expire before the DNS server you are using will choose to look it up again. This doesn't go into any of the fun of what happens when you have 2 or more DNS servers setup, but ultimately what people are seeing is that the "48 hour" waiting period is substantially less, however most ISPs will stick to this default number to reduce worrisome support from their clients who think otherwise but don't know anything about how DNS works so support will never be able to explain this in laymen terms (or wait, did I just do that?)
namecheap appears to be blurring the line of "stopping sopa" and "boycotting godaddy".
You can choose to boycott a single company based on the lines of disagreeing with their core values, that's great to do! Show them you're pissed for their support of a bill you dislike, but this is not enough to stop SOPA.
Writing your representative helps stop SOPA, being involved helps stop SOPA, bringing yourself up to speed with the bill's progress will help. I hope that no one feels their action to address this matter stops with just transferring domains.
NameCheap has appeared to be "out for blood" since the opportunity arose with goDaddy's PR debacle with SOPA. And it's leaving both company's tarnishing their reputation.
goDaddy supports a draconian censorship bill.
nameCheap jumps in the game and does their best to kick goDaddy while their down for personal gain.
The capitalistic dream in action.
Want to transfer your domains to a registrar with merit and is actually against SOPA instead of trying to gain customers? Find one who was talking about how bad SOPA was before this debacle started last week.