> The end state will be the fully autonomous module with no capability for the driver to exercise command. You will call for it, it will arrive at your location, you'll get in, input your destination and go to the freeway.
Except it won't. You'll go to three Sponsored Locations that offer similar, but not quite the same, services as the destination you selected, while the windows are used as projection screens for advertisements related to your destination and locations you're passing.
- Me: "Take me to Central Park."
- Car: "I'm sorry Tom, I can't let you do that. Going to MOMA, the New Museum, and Battery Park."
- Car: "We'll be passing a Wendy's restaurant momentarily. Did you want to stop to pick up some chicken nuggets or a tasty hamburger? I can offer you a 2 for 1 deal expiring in 5... 4... 3..."
- Me: "We were just planning on pizza, thanks."
- Car: "A $2 non-subsidized convenience fee will be added to your total."
Found the bug! Seems like the new behavior is non-compromisable, but keszybz and pottering both put forward potential solutions that leave everybody happy(?), but that haven't been acted on since July. So, there was some compromise between the requestors and developers, just not in the places I expected to find it in the bug report.
It's great that they're making systemd, but if it doesn't work for you, it won't. (Rephrasing a Github bug I read a while back) systemd seems set on replacing the existing software stack with software that works for its creators, without regard to established historical standards of behavior.
For example (in the GH bug), folks using systemd for networking can't necessarily connect to intranet sites, because systemd doesn't keep historical behavior: it doesn't try all the DNS servers you've provided for each request. Instead, it always connects to whichever DNS server hasn't failed most recently. That's faster, that's good.
If you needed systemd to connect to your local DNS server to resolve intranet names like http://myreports/, and 8.8.8.8 to resolve external names, that would work fine... Until the local server took too long to respond to one request. Then, all future DNS requests would go to 8.8.8.8, effectively blackholing your intranet. That's broken, that's bad.
The resolution supplied in that bug, IIRC, was users shouldn't do it that way. So, the resolution appeared to be that the user should've been hired as the network administrator instead of their current job. Maybe it's been fixed some other way since then? Please correct me if so!
Sure, systemd might be faster, but faster isn't better than working-as-expected.
Those are just the ones off the top of my head, I'm sure we can come up with more. Regardless of the verbage, the EFF deserves a pat on the back (and my recurring donation).
You don't need anything that isn't already publicly available: see every security bug reported on the mailing list, and reliable hop tracing via coordinated parties recording traffic (Tor's version of Bitcoin's 51% problem).
That said, it's still the most reliable limited-anonymity provider I know of.
That's a clever question and the answer has a few parts, mostly due to the slipperiness of "trust" as a concept: I wasn't specific enough in my description of my own threat model (which makes sense, as my aim wasn't to explain the threat model but to cultivate answers from other folks). In short, I currently only have access to systems that are too costly to replace, if the site is under active attack. That's not to say that HN's comment section isn't also a risk, but it seems less of one.
I considered these actors before deciding to ask the question instead of immediately connecting directly: available computer systems, internet pipes, the NYT website, and the bevy of third party ad-services hosted through the website.
I was asking because I'm currently nowhere near a system that I'd trust for this purpose. I'll be near one later and, if you're interested, I'll update the question with my findings.
Not all entry points do the most paranoid thing, and not options are even available on all entry points.
The Tor Browser Bundle (desktop) has different defaults than Orfox (phone), and I think both will connect to non-onion URLs when connecting to an onion site. Same for JS, ad-block, etc.
Does the onion service still serve the same advertisements their website and mobile app do?
If so, they're leaving their users-who-want-to-stay-relatively-anonymous open to attack via the advertisement vector. Members of that group would be considered high-value targets simply due to their anonymity desires.
I can't see the number of daily users being large enough that they'd lose significant profit by closing that attack vector. Hell, if there was a way to pay NYT enough to disable ads on all their services, I'd do it.