ALOT of apps are starting to do this. I believe Snapchat initially was the company that began doing it. When a site like Facebook uses your number to identify you, this feature actually makes sense.
I wonder if more fine-grained permissions would make more sense for this sort of feature. Perhaps it would be better if Android had support for "This app may read text messages from 1-800-XXX-XXXX" or something similar instead.
I agree! I found this version to be much easier for some reason. Possibly the brain is quicker to recognize and match the colours than when I'm forcing myself to look for numbers?
I don't totally see the point to these arguments. The inherent nature of the technology we have means that if they can view it once, they can view it as long and as many times as they want. Anything trying to restrict that is just futile -- look at DRM.
Snapchat has never given that particular illusion of privacy. As the most common and basic example, it has absolutely no way of stopping people from simply taking a screenshot of your image. Snapchat is meant to be used to share throwaway photos without the social expectation that comes from putting it on somewhere like Facebook. Anyone who uses the application learns quickly that someone can potentially store the photo they sent -- in a vast variety of ways.
In app purchases are fine, but be HONEST about it.
Not being upfront about the costs of your game directly misleads the customer and, in my opinion, is a terrible and abusive way to earn revenue.
This is great. Proper cryptography is the solution to so many of the problems the modern internet is facing right now, but the key problem with cryptography is that it is never user friendly enough and never distributed enough.
This looks like a great step in the right direction.
I'm not an expert on this, but I believe that at the VM user level they would see wiped data because of the internal mapping. I think physical analysis of the drive would be required.
The term "disc scrub" makes little to no sense in terms of SSDs, which makes this issue even more complicated. People who work in the disc recovery field have been dealing with this since SSDs became popular.
An SSD is limited by its number of writes. To compensate for this, the SSD has very complicated on board logic that abstracts the actual SSD away from what it tells the OS system. This allows it to do certain tricks to save writes. However, when you are "scrubbing" an SSD, internally the SSD might be writing somewhere else entirely. Scrubbing is not considered an effective way of wiping SSDs, from what I believe.
I imagine it assumes a header like X-Requested-By has not been manipulated. You can safely assume that the referrer, or other headers, have not been manipulated. There is no way for malicious Javascript running in the users browser to edit headers.
Of course, anyone can code their own browser to lie about headers. It doesn't make much sense to specifically open yourself to vulnerabilities though.
I think it's important to note that this is a bug that effects older browsers only. Modern IE, Chrome, and Firefox have security measures that do not allow scripts to capture values passed to constructors of a literal. That way, this hack is only needed for older browsers and will hopefully not be needed at all in the future. For more info: http://stackoverflow.com/a/16880162/372767
Also note that this attack, JSON Hijacking, is different than a CSRF (Cross Site Request Forgery) and has little to do with CSRF tokens.
Unfortunately, this is what happens to online communities. Particularly those run by teenagers. I've been a member of a number of communities that have suffered deaths in very similar ways -- choked by the people who own the rights at the expense of the volunteers and the community.
It's unfortunate, because I find that often volunteer teenagers are the ones that truly have a passion for doing what they are doing, but they get held up by corporations or by people who want to monetize. When that doesn't work, the people in charge ignore the community until it dies.
I think it's important to keep this in context, especially for Snapchat. Snapchat is an app. Their website contains almost nothing. I bet a VERY small percentage of people who use Snapchat have ever seen their website, much less google'd the term.
Honestly, most of my HN reading is because I need a mind-break from whatever I'm focusing on. I find it's a great way to take a break, and still learn a few things while I'm at it.
Just finishing going through this in my province. The latest transition is that all gas pumps now suddenly require me to leave the card in. Yay for Chip and Pin!
My point is that the people that get the benefits are not necessarily the people that need them the most. I've seen many families with status that did not need the money, but took advantage of it. I've also seen many families that needed the money, but could not get it because they were not status.
I completely agree with a support system for people who need it, but I do NOT think that system should be based on racial background.
Growing up in a poorer neighbourhood, the native friends I had were able to play football, have school lunches, go on fieldtrips, and go to university when I could not because they were paid for with tax payers' dollars.
My grandparents were not even in this country at the time, it was not my ancestors nor me that hurt anyone.
So I should have less because of what someone with the same skin colour as me did decades ago? Doesn't that seem a little, I don't know, discriminatory?
I wonder if more fine-grained permissions would make more sense for this sort of feature. Perhaps it would be better if Android had support for "This app may read text messages from 1-800-XXX-XXXX" or something similar instead.