Ever since I realized there will be a persistent log of my browsing history maintained by one or more government agencies, I have mentally-marked http as risky. I cannot wait for something like this to happen, and encourage the wider less-informed community that TLS is critical for both trust (properly implemented, TLS will provide protection against tampering and data leakage) and to provide a minimum level of privacy (I can see you visited site x, but not what sections of it). Bring it on.
Considering the functionality that wasn't reviewed, I don't think it should be advertised as "A".
It might be "A" for the expected permissions, but if there's extra permissions which haven't been investigated, these should be marked down until explained. This would encourage app owners to work with whoever maintains the database to get accurate ratings. If Whatsapp is an A today, there's no incentive for the developers to justify / assist with anything unexplained permissions remaining.
In it's current state, if it's awarding A scores while significant permissions are unexplained, it doesn't help the end user.
This is a wonderful example of NSA meddling. With one hand, Microsoft gives everyone out-of-box encryption, which it can use to demonstrate how well it's protecting consumers. With the other hand, by virtue of a 'feature' to assist consumers, it's providing access to the NSA via SkyDrive copies of encryption keys. Everyone's happy!
Best of all, enterprise customers don't have a reason to complain, because the SkyDrive backup 'feature' shouldn't apply to their deployment scenarios. The only people with a complain are those that use the default option.
We should keep vigilant for these security 'features' that are undermined by implementation. The NSA has years of practice at this, and we're playing catchup.
I've been looking into ocaml, and was wondering what to do once my programs grow beyond a single file. Unfortunately it doesn't have the equivalent of 'lein new' (Clojure tool for creating a new, empty project skeleton), so I'd welcome a repository of best practice examples like skeleton.io.
I'm sick of knowing about things and not jumping in early. So rather than brag that I knew about Ethereum before everyone else did, yet not have any, I figured I'd get some to play with.
Apparently they made the SafeCoin IPO (safecoin being the altcoin/blockchain that powers MaidSafe) available to purchase with both MasterCoin and Bitcoin. Based on exchange rates at the time, it was possible to get more SafeCoins if you purchased with MasterCoin, than if you used Bitcoin (since MasterCoin was so cheap).
Some people thought they could take advantage of the situation, and bought up MasterCoin to purchase SafeCoin. However it sounded like the IPO purchase cap for MasterCoin purchases was filled quickly, meaning a lot of people were left holding near-worthless MasterCoin. Thus began the cries of "Mastercoin pump and dump", which the IPO had (inadvertently?) caused.
MaidSafe sounds intriguing, but the one thing that gives me pause is their licensing page (http://maidsafe.net/developers-licensing), which says that any non-GPL MaidSafe codebases requires 1% revenue fee. I still dont know if that means I can or can't create my own MaidSafe application from MaidSafe compatible libraries that I've written myself, without having to pay them. I also don't know if they have some sort of central enforcement mechanism to prevent such an Application from working on the MaidSafe network. I can only hope they start releasing example code and applications soon to clear up the confusion.