The best advertisement for these companies would probably be running a public Polymarket account so everyone else can quickly check how accurate they are.
A monitor cannot install software on your computer by the way. It's Windows installing this software automatically (for some reason), so the blame should be on Microsoft.
Autorun of malware when you plugged in a USB drive was also a Windows issue, I'd classify this as the same security problem.
I actually did not. I know there is some degree of two-way communication over HDMI/DP, and was curious if this was how the software was installed. I think discussing the technical details is a great use of the HN comment section.
(Wifi enabled display device -> HDMI -> Device) would be an incredibly interesting attack vector.
I would think everyone in the HN crowd would be aware of HEAC, the hdmi Ethernet channel, etc.
With full access to the hosts tcp/ip stack, we’d do well not to overlook the potential vectors for a monitor to install software on your computer… especially when the operating system is complicit.
Ok, I don't use Windows and never will, so wasn't aware of this feature, and it would've been nice to have that context. Thought maaybe LG is exploiting a vuln in Windows via USB-C or over one of the niche HDMI features, but gathered it's not that.
> Autorun of malware when you plugged in a USB drive was also a Windows issue, I'd classify this as the same security problem.
Not really. AutoRun ran whatever was on the USB drive, with no oversight. This installs a driver from a company that's supposed to be reputable enough to get their driver signed by MS and pass validation. LG breached that trust here.
Not sure if it was an LLM hallucination, but I was looking for a wifi dongle for linux. Apparently some of them now present as an autorun usb disk until the driver they auto install sends some magic unlock handshake.
that's funny; because my root cause analysis didn't show the user as the person making the decision to show themselves ads? did yours, or was the victim blaming intentional?
Not making the specific decision (showing ads) but making the general decision (giving power to Microsoft). Blaming customers for buying MS products is not really much different than blaming Trump voters for voting for him. In both cases risks were obvious beforehand.
Not everyone is able to accurately predict the future from past patterns. They still deserve dignity and respect. Just because you were able to predict it easily doesn't make it possible for everyone.
The solution I'd like is instead of you making excuses for shitty behavior, instead maybe condemn the shitty behavior? You're allowed to say both, you can said I told you so, (to switching to not windows) while also being bothered when you see SWE at some company mistreat other people. You can complain about LG being abusive with the power they were given, while also offering alternative OS install instructions to that grandma who only wants to VC with her grandkids without being tricked into paying for trash-tier antivirus she doesn't need.
Because it spies on them and nags. But Windows itself already does that. LG could've done the same thing sans the mcafee popups and nobody would care, in fact Dell is probably doing that.
> Yep. Not free-for-all, but silently installed crap collecting metrics is well within their expectations.
I don't expect software engineers to build stuff like this. I expect humans to treat other humans with dignity and respect. In fact, it makes me extremely angry when I see people do it, or advocate that others should tolerate it.
I don't think they should tolerate it, but they do. 0 people are going to leave Windows because of this latest scandal, because the ones who care have already left. At some point I accepted that this doesn't matter to a lot of people, which is their right and choice, and if Linux wants to attract users, it has to do it by being easier to use besides just being more ethical.
Ironically if Microsoft responded by just never signing LG software again, but kept this auto-install thing in, LG monitors would become the best to use with Windows.
The same server that's responsible for sanitizing garbage JS out of user content is also responsible for sending the Content-Security headers. Why would you trust it with one, but not the other? If it's buggy garbage it will also send the wrong headers.
This is a pretty good argument in the case of software written by a small team of experienced engineers. In that scenario, if the engineers don't have the nous to avoid the kinds of HTML injection vulnerabilities that might allow an attacker to inject their own JS code, then, as you say, they are probably also making lots of other mistakes.
A CSP is more valuable in a larger organization, where the codebase is always at risk of being modified by the organization's worst engineer.
But can you run it on their platform? NO, you need to run it on your own machine which takes a bit of work. And we have over 80 courses waaay over whatever codecrafters has
Isn't that the best part of codecrafters? Being able to just use your own text editor instead of a janky web based one which loses everything you typed on page refresh?
You were right, and this comment stuck with me so I have decided to go ahead and implement it.
Every course now has a "work in your own editor" mode: you can download a zip with the starter code for every lesson plus a run_tests.sh that runs the full test suite locally. After that, you can push it to a public GitHub repo, we will judge it based on our grading system and internal tests
gp's argument is that cheapness is a construct, derived from the real, and natural, cost parameter which most people are naturally accustomed to interpreting as increasing from left to right. cheapness would then replace the cost label, and feel natural. alas, this is not what we have here.
reply