Skip to content

Brits can get around Discord's age verification thanks to Death Stranding's photo mode, bypassing the measure introduced with the UK's Online Safety Act. We tried it and it works—thanks, Kojima

Technology
65 37 0
  • Women’s ‘red flag’ app Tea is a privacy nightmare

    Technology technology
    126
    1
    313 Stimmen
    126 Beiträge
    1k Aufrufe
    N
    As I mentioned in other comments, I am a noob when it comes to web-sec; please forgive what may be dumb questions. There's nothing to forgive. Asking questions and being curious is how you learn this stuff. Is it really just permission rights "over-exposure" issue? From what I've read, it's more fundamental than that. It's a basic architecture issue. The datastore was publicly accessible, which it should never be. If they had it setup according to best practices, with an API to proxy access and auth, the datastore's permissions would be of minimal consequence, unless their network was compromised (still best practice to secure it and approach with a zero-trust mindset). Or does one need to also encrypt and then decrypt the data itself that must be sent to a database? Generally, cloud datastores handle encryption/decryption transparently, as long as the account accessing data has authorization to use the key. They probably also didn't have encryption setup. Also, if you have time, recommend any links to web/cloud/SaaS security best practices "for dummies"? Here are some more resources: https://cheatsheetseries.owasp.org/cheatsheets/Secure_Cloud_Architecture_Cheat_Sheet.html https://www.oreilly.com/library/view/security-architecture-for/9781098157760/ https://www.oreilly.com/library/view/cloud-computing-security/9780429619649/ Check Humble Bundle
  • 0 Stimmen
    1 Beiträge
    17 Aufrufe
    Niemand hat geantwortet
  • A Deep Dive into All Four Generations of the Honda Acty Truck

    Technology technology
    1
    1
    0 Stimmen
    1 Beiträge
    12 Aufrufe
    Niemand hat geantwortet
  • How LLMs could be insider threats

    Technology technology
    12
    1
    105 Stimmen
    12 Beiträge
    118 Aufrufe
    patatahooligan@lemmy.worldP
    Of course they're not "three laws safe". They're black boxes that spit out text. We don't have enough understanding and control over how they work to force them to comply with the three laws of robotics, and the LLMs themselves do not have the reasoning capability or the consistency to enforce them even if we prompt them to.
  • 77 Stimmen
    21 Beiträge
    121 Aufrufe
    G
    Because the trillions is the point.. Not security.
  • Honda successfully launched and landed its own reusable rocket

    Technology technology
    170
    1
    1k Stimmen
    170 Beiträge
    793 Aufrufe
    gerryflap@feddit.nlG
    Call me an optimist, but I still hold the hope that we can one day do better as humanity than we do now. Humanity has become a "better" species throughout its existence overall. Even a hundred years ago we were much more horrible and brutal than we are now. The current trend is not great, with climate change and far-right grifters taking control. But I hold hope that in the end this is but a blip on the radar. Horrible for us now, but in the grand scheme of things not something that will end humanity. It might in the worst case set us back a few hundred years.
  • 642 Stimmen
    170 Beiträge
    802 Aufrufe
    F
    I actually wouldn't enjoy talking to most people at work, because that would involve going there instead of doing it from the computer where I already am
  • 15 Stimmen
    14 Beiträge
    66 Aufrufe
    S
    Why call it AI? Is it learning and said-modifying? If not then is it not just regular programming but "AI" sounds better for investors?