doughless

u/doughless@lemmy.world
1 posts · 180 comments

Recent posts

Recent comments

Even if you know how to do them, this one is especially hard, because you only need to focus maybe 5% past the image. Basically, allow the image to split into two as you look farther into the distance, but not too far, or it won't work.

::: spoiler spoiler They look like Romulan Warbirds to me :::

on Let it sink in. · c/lemmyshitpost · 13 pts · 74d

Which comment is wrong about the math? If you include 0, then 0 to 31 is 32 different combinations.

on xkcd #3268: Offside · c/xkcd · 10 pts · 75d

The official rule is that you are offside if you are closer to the goal line than both the ball and second-to-last defender when the ball is passed by your own team. It is only a violation if you then make a play toward the ball after being offside. If the other team makes an intentional play on the ball before you do, then you are no longer offside.

Those examples are perfectly secure if you set the allowed origins to only your domains, or domains you specifically want to allow use of your API.

If someone copied those examples verbatim, they'd end up allowing a website hosted at example.com to call their API. Which I suppose is technically not secure, but I wouldn't call it very insecure unless example.com was taken over by a malicious user.

His reaction is because Waymo isn't returning his luggage unless he pays for it. Two complimentary trips still takes multiple hours of his day for something that wasn't his fault, meaning even that isn't free. It's Waymo's fault, either they fix it, or it's theft.

This has been happening to me the past few weeks, so I tried turning off app notification sign-in, and the attacker switched to entering passwords until it locked my account.

The only way to unlock it is to reset the password, and MS won't let me keep my old one ... why can't I use the old one again, especially if I recently changed it already?! The attackers clearly don't know it, but now they can make me go through the effort of setting a new password every day until I enabled app notification login again.

And then they just switched back to MFA phishing again. The attacker has even stopped bothering making the login request look like it's coming from the same country I live in.

They're typically used in real life situations, for example, when trying to figure out whether their coworkers are like-minded. Once they know they can get away with it, though ... I have a few coworkers that will talk right-wing talking points practically non-stop. Another coworker and I have considered reporting them to HR, but all that would do is put a target on our backs; or at best, get them to silently hold a grudge against us. And it takes a lot more than office drama to get fired where I work.