I'm pretty sure I could post "standing in the fire is painful and bad for your health" and there would at least be one person in the comments saying "I actually like standing in the fire".
Of course you would! I'm sure you'd see some firefighters or arsonists who would respond in such a manner. It's a very natural thing for some people to find a positive of some kind in things that many people find to be a negative.
In order: no, no, no, and no. I accepted that I can't avoid google spying on me on android, if I could have a phone that works with banking apps without google's crap I would, but thanks to their safetynet racket it's not possible for me.
Most places I worked at cared very little for quality code, there was much more pressure on shipping fast even if it meant incurring technical debt, crap performance for end users, or developers leaving due to legacy code accumulation that nobody understood anymore.
I'm glad there is a tool that let's these companies have even shittier code shipped even faster. The faster they burn down the better.
There should be parental controls that disallows installing apps, so there is no hidden browsers. Google and apple has an entire walled garden infra setup that they are using for control and hoovering up all the user data, the same infra can be uses for this.
This, and more - device makers and those upstream of the parents need to make "child safe" phones .. and probably (uh, oh) make them that way by default so that tech savvy types can disengage restrictions (and have that restrictions lifted state glaringly obvious for non tech savvy parents).
The raison d'etre for my above framed question was to highlight that non tech parents can not be expected to IT-child-safe phones and then monitor risks w/out assistance from vendors.
That's basically what this law is, but it's not saying there has to be a wholly separate phone model, but it's saying every phone (or desktop or laptop or tablet or ...) must have a child safe mode.
The takeaway is that everyone makes security hard. Everyone does this anti-pattern of having these other domains that defeat all their own security recommendations.
GitHub for ages had something like githubnext.com where they would make you do this same OAuth dance (except IIRC it was worse - it explicitly said that it WASNT GitHub). Apple has/had an apple.tv microsite or something they hosted content on.
Your bank will send you “legitimate” surveys or communication from some third party domain like qualtropics.com.
Once upon a time, RuneScape ran a promotion where World of Warcraft players could join a special world with double XP (experience points) or something by clicking this promotion link.
RuneScape has an in-game dungeon designed to teach players about account security. One of the questions is whether you should click on a link that promises double XP...
reply