Just your normal everyday casual software dev. Nothing to see here.

People can share differing opinions without immediately being on the reverse side. Avoid looking at things as black and white. You can like both waffles and pancakes, just like you can hate both waffles and pancakes.

been trying to lower my social presence on services as of late, may go inactive randomly as a result.

  • 0 Posts
  • 1.9K Comments
Joined 3 years ago
cake
Cake day: August 15th, 2023

help-circle


  • Honestly. I think if tracking is disabled it should do the following:

    • anything screen dimension related including available height/width -> blocked (realistically java-script should never need to disclose this information outside of an internal function anyway)
    • User Agent: generalized (this usually already is the case)
    • Cookie status: kept the same as needed for functionality.
    • addon/plugin info: blocked
    • buildID: blocked
    • hardware concurrently: generalized instead of a set number (low end being < 4 middle being < 12 high anything else)
    • any hardware characteristics(such as gyro, battery state, etc) -> request for permission by default

    Like there are many steps that can be done to help mitigate fingerprinting, its just getting vendors to actually do it.

    being said I had never known about the TLS fingerprinting option, I generally don’t see that shown on the fingerprint detector sites, that’s interesting.



  • it’s nice that someone is responding on it.

    Now that there is a mod team, can restrictions on meta posts and mini modding potentially be added onto the internal discussions?

    The intent is there and I get they’re trying to help, but the amount of negativity and toxicity to something that wasn’t even a rule at that time, I think should be addressed and not allowed.

    Not that I think they were wrong, so to speak. But… I don’t think that orchestrates a healthy environment when there is a mod team for it that can /remove/ the content instead of just spamming the community with protest comments or flaming

    edit: FUTO speech to text is buggy and likes adding text I tried to add later on in parts I’m editing, removed the delayed addon lol




  • Yes, I post a review on every product and restaurant I visit. I wish more sites let you review more than once as there are some places/products that had amazing visits at one point, but then some visits that sucked hardcore, so allowing the average visit would be nice.

    Why? Because I want to share what /my/ expereience with the service was. If they screwed up, others should know. If they did amazing? Others should know. If I was in the other persons shoes, I would rather have known.


  • Whether you respond as a 404 or a 403 would be dependent on whether or not the user who is logged in has the authorization to read the previous directory.

    A site administrator, for example, would have the authority to read the previous directory, which means that the site administrator would know whether or not the resource existed or not(as the previous directory would list it) so in which case a 404 would be proper. However, a user who doesn’t have authority to read the previous directory should not have the ability to know whether or not it exists. so a 404 would not be proper here because the proper one would be a 403 because it’s inherited from the previous directory.

    edit: changed traverse to read, as traversal doesn’t mean you can see what else is there.


  • Generally speaking, unless you’re using OAuth for an authentication, you would check your username and your password at the same time. It’s just you wouldn’t respond if either existed or not. You would just say invalid username and password combination.

    What gets really complicated is the hybrid SSO integrations where they use a username and then if the account has SSO enabled it then redirects you to the sign-in page, Otherwise, it brings you to a password field.

    Realistically what these sites should do to prevent that vulnerability would be to make it so you have to click a dedicated sign in with single sign on button. But not everyone does that type of flow.

    Granted, this also doesn’t include sites that convert your user account into a user ID. And then for your password’s table, only give a user ID. Those would require two queries or a join, regardless, because it’s two separate data places. One to get the user Id and one to get the passwords



  • I don’t respect them because most instances a 403 is more than adequate for your security. The only time I agree with having a 404 over a 403 would be file-specific pathing, but realistically the entire file directory should be a 403 instead of a 404, And then if the user is authorized to access the resource(but it isn’t there), then it gives a 404.




  • I can’t see reddit on my network(I blocked it to avoid using it) so I will take your word for it, I’m assuming its the store freezer/produce doors with ads.

    Being said, there are reasons to technologicalize the process. those type of low level mini pc’s or controllers last generally years at a time, and are a setup once and done type operation. They are also super cheap and can be distributed across the entire chain once instead of needing to get material, print it, and ship it every time a new product or design is done. Sending stuff over the wire is cheap, shipping marketing material is not. It’s generally sent from a different company all-together, and either centralized into a distribution center to be shipped to the stores, or shipped directly to the store from the producer.

    It also allows for video based distribution which allows for more info on the screen (for better or for worse because this also could be ads).

    I think it’s dumb that it’s an individual system it seems for every screen, but I expect that HDMI matrix hardware is more expensive vs just having them separate, but regardless cost wise it’s a no brainer to make it digital over having physical inserts, even if its more wasteful.



  • I had something similar when I was using reddit. Constantly addicted to the site.

    I didn’t know how bad it had actually gotten until when the API changes happened I uninstalled the app I was using.

    For like the next 2 or 3 months, I would consistently catch myself sliding the side bar open and tapping where the app used to be. In some cases I would get in a loop and I would have attempted it like 6 or 7 times before realizing what I was doing.

    The solution like others have said is disengage. The entire point of those platforms are addiction and entertainment. Shorts are even worse than entertainment posts as you can’t use the time waste on an individual level.

    I had to fully block reddit at the DNS level to separate as I kept wanting to go back. I’m starting to notice the same effect when I’m on lemmy so as of late so I’m working on that.


  • I’m not sure location but, if it’s the US my parents had something similar with the no assets thing. Someone stole their car, took it for a joy ride and burned it up the road, they were charged and given a verdict of guilty and had to pay it back, but they claimed no assets. After a few years of no payments whatsoever my mom started complaining, eventually she complained enough they started the legal process of garnishing wages. If he has a job or an income source, they can garnish that either via tax time or via the wages. Being said, the garnish system is super lax for living costs, if they are making bare min wage, you probally won’t get money out of it