Kissaki

joined 2 years ago
[–] Kissaki@feddit.de 20 points 8 months ago* (last edited 8 months ago)

will cause the visitor's browser to quietly upload a file using the WordPress site's XMLRPC interface

It's absurd that XMLRPC is still not disabled by default.

It's been an unnecessary weak point in the attack surface for many years.

[–] Kissaki@feddit.de 3 points 8 months ago

I'd suspect your VPN is slow before suspecting ISP throttling.

you --> ISP --> target
you --> ISP --> VPN --> target

You're introducing VPN, with different network routing, and a routing middle-man, and suspect ISP before VPN?

[–] Kissaki@feddit.de 5 points 8 months ago

First huzu now suzu. Are we gonna be able to fill the alphabet?

[–] Kissaki@feddit.de 2 points 8 months ago

Yes. I singled out Spotify because they were the driving force on the EU investigation, and are big enough to invest into it. But like you say, it's open to anyone.

[–] Kissaki@feddit.de 2 points 8 months ago

I find their repeated "I'm not outing anyone", "I'm not here to out anyone" irritating, especially for evading sourcing examples. I guess it's a very evasive, non-confrontational approach. But to me, that's not necessarily a good thing. Either way sourcing isn't likely to resolve the overall systematic (Reddit- and Google-sided) issue anyway.

[–] Kissaki@feddit.de 2 points 8 months ago

Of the resulting 122 URLs, 63 have a top comment with a self-promotional affiliate link. Often written months after the original thread was created.

Injecting (posting and manipulating) affiliate links is lucrative for affiliates - Reddit could resolve it by disallowing or automatically clearing affiliate links of links (URL shorteners would be a secondary concern that could be automatically handled too)

Without affiliate spam, it would or could still be lucrative for sellers and product sellers. Which is harder to resolve.

[–] Kissaki@feddit.de 22 points 8 months ago

"where required by local law" - on a global platform? How is that supposed to work? When the addresses or being addressed is in such a locality? After complaints only? After prosecution or court orders?

I guess it's more a disclosure of what can happen than it is a terms of use or moderation guideline.

[–] Kissaki@feddit.de 21 points 8 months ago (1 children)

sued Orange in 2010

14 years. Insane.

[–] Kissaki@feddit.de 71 points 8 months ago (2 children)

Even though the Commission has fined the company concerned, damages may be awarded by national courts without being reduced on account of the Commission fine.

So if/after Apple's appeal is declined, Spotify - the driving force of this EU investigation - can sue Apple for damages with additional cost to Apple.

[–] Kissaki@feddit.de 4 points 8 months ago (2 children)

Under the App Store’s reader rule, Spotify can also include a link in their app to a webpage where users can create or manage an account.

Instead, Spotify wants to bend the rules in their favor by embedding subscription prices in their app without using the App Store’s In-App Purchase system.

I'm confused now. What is a "reader app"?

Spotify wants to make subscriptions an app functionality and Apple restricts that to it's own payment system - and the alternative they provide is external websites?

Why the heck is it called a "reader rule" and "reader app"?

[–] Kissaki@feddit.de 43 points 8 months ago (9 children)

I didn’t know reddit gave out the personal details of their users, but I guess I shouldn’t be surprised.

You make it sound like they have a choice, or do so freely and willingly.

The article is clear on that they don't freely share without assessment though:

Reddit wasn’t willing to go along with the request, at least not in full. The company objected, arguing that handing over the requested information would violate its users’ right to anonymous speech.

Recent legal activity shows that Reddit doesn’t intend to automatically comply with all user information requests.

view more: ‹ prev next ›