FooBarrington

u/FooBarrington@lemmy.world
51 posts · 5.6k comments

Recent posts

Recent comments

Yeah, Chromium's implementation is IMO very elegant and genuinely improves security for most people. That's why I'm a little miffed by comments that paint it as an obviously terrible feature, just like happens with the "read/write to a specific local folder" API.

These days, new browser features often aren't in the users best interest, I understand and share the commonly discussed concerns on those. But compared to the alternatives, these specific APIs genuinely improve safety for most users AND make things more accessible for newbies and pros alike. Blocking them on principle (& without specific technical concerns) will not protect users when their remaining option gives malicious actors far more access without any exploits!

I'm guessing they meant sonar instead. AFAIK active sonar does work really well, but is rarely used since it reveals your location twice as far as you're able to detect others. Not to mention the horrible effects on wildlife - the sound waves carry so much energy that a point-blank hit is somewhere between "lethal & untreatable" and "turned into red mist".

I don't think it's realistically possible to do that totally undetected. Since the earth's magnetic field is so weak and field strength goes down rapidly as distance increases, malicious actors probably couldn't spoof patterns well enough to make the data look real, at least not without coming very close and staying near their target.

I do understand your concerns regarding safety, but not having WebUSB does not guarantee that malicious websites can't access your USB devices. Both Firefox and Chromium already interact with your USB devices to provide features like debugging over USB, so malicious websites that exploit browser bugs are able to talk to your devices either way. And if we don't count browser bugs, you can simply set your browser to block WebUSB by default to arrive at the same outcome.

Of course there is a chance that specific exploits could work in one case and not the other, but that's something the real-life statistics haven't shown to be an issue so far. Browsers are generally pretty safe these days due to multiple layers of sandboxing, so I'd be surprised to see major WebUSB-specific security exploits appearing in the future.


Edited to add:

Sorry, when I said "sky is falling" I meant a general erosion of user security and privacy, when using our "own" devices.

Same here, I hate the direction things are already clearly heading towards on mobile, and I expect desktops to get enshittified as well soon enough. But I see WebUSB as a major positive in that context (since it allows users to take control of their devices in a much easier and safer manner, & mostly guarantees backwards compatibility of such tools for many years to come). And although I've read comments similar to yours many times - this topic gets brought up fairly often - nobody has explained concrete technical issues that are likely to bite us.

I'm afraid of the sky falling (it is).

Somehow, I must've missed all these cases where bad actors abused the WebUSB API. So what did they do? What's the worst damage the victims have suffered?

That's general - in this specific case, by my reckoning, it can never be safe for a website to understand, in any depth, the hardware of the machine requesting it.

You still haven't explained: why? When the options are "website" or "untrusted binary", the website is objectively much safer. Sure, you can sandbox untrusted binaries - but then you can just sandbox the browser.

Yes, there are security concerns, but these fears haven't been confirmed in real life, and they don't disappear if we ban WebUSB! Instead, people have to run untrusted code with access to far more hardware than WebUSB allows.

Honestly, this is such a shortsighted take. Awesome, instead of a simple "Allow?" dialogue to give the sandboxed website access to one specific USB device through an (over time) more and more well-tested implementation, we have to download untrusted binaries that by default get full access to large amounts of user data.

What are you so afraid of? It's already been live in Chromium browsers for a while, and the sky hasn't fallen. And I'm convinced it has largely improved security for users who flash Arduino-like devices, smart home stuff, some phones and a bunch of keyboard/mouse stuff.

I'm not sure I agree. The real world is never going to run perfectly, so some slack must be included (either by adding buffer time to schedules, or using the way you mention). Of course there are examples like Japan that have done a really good job at optimizing these systems, but you won't be able to successfully apply their approach to every country. Some locations require more work to achieve this, others require less.

Generally the closer you get to an "ideal" performance, the more costly every further improvement gets. If 7 min isn't reasonable, what number would be? Say we manage to shave off two minutes, at twice the cost of the current system. Is that really worth it?

The better approach is to include reasonable slack time in people's train schedules, while increasing frequencies so missing a connection doesn't result in hour-long wait times.

Those guys were probably actual magicians, cause I tried their Currywurst ice cream: delicious. Döner: really good. Even fucking Gorgonzola was amazing, and that should not be possible!

One ice cream place had bunch of awesome vegan variants, so I can confirm that they are definitely worth trying!

Unrelated, but a different place once had Gin-Tonic ice. To this day I can't get the flavor out of my head, it was so good. But how tf do you make that :|

on Poor guy · c/comicstrips · 7 pts · 6d

Palpatine secretly controlled the whole trade blockade around Naboo as well as directing Count Dooku, Darth Maul and General Grievous among many other shenanigans.

To compare it to German history: Palpatine didn't just light the metaphorical Reichstag on fire, my Geschwisty. He used an armada of tanks assembled into a Voltron-style robot that shoots Flammenwerfer capable of turning air into fuel.

on ich👴iel · c/ich_iel · 12 pts · 6d

"Zu meiner Zeit hatten wir noch eine Skibidi-Aura gegoont. Das war 1 peak Nicenstein."

Während die Arbeitsproduktivität in den 1980er- und 1990er-Jahren noch um rund zwei Prozent jährlich zunahm, ist sie in den vergangenen sechs Jahren im Schnitt nur noch um 0,3 Prozent jährlich gewachsen. Also kaum. Gemeint ist die Wirtschaftsleistung, die jeder Erwerbstätige im Durchschnitt erbringen kann. Woran liegt es, dass die Produktivität in Deutschland stetig zurückgeht?

Bin ich gerade blöd, oder ergibt der Absatz tatsächlich keinen Sinn?