• 0 Posts
  • 37 Comments
Joined 1 year ago
cake
Cake day: June 22nd, 2023

help-circle


  • “Incomplete paper and online applications will not be accepted,” Evans said in the statement. (Parker’s [demonstration] cancellation request would have lacked a driver’s license number.) The Secretary of State’s Office did not respond to individual questions about what testing the portal underwent before launch, the system’s security procedures, what happened to Parker’s cancellation request…

    Yeah, that tells us we just don’t know if this was a problem after all. Evans’s statement basically claims it wasn’t a vulnerability. If that’s correct, then the worst thing might be if someone’s browser tripped on the validation JS and allowed them down a blind alley execution path. If the claim is correct and if the page’s JS never shits the bed, then in that case the only negative outcome would be someone dicking with the in-browser source could lead themselves down the blind alley, in which case who cares. The only terrible outcome seems like it would be if the claim is incorrect–i.e. if an incomplete application submission would be processed, thus allowing exploit.

    Short of an internal audit, there’s no smoking gun here.






  • atx_aquarian@lemmy.worldtoTechnology@lemmy.worldTikTok sues the US government over ban
    link
    fedilink
    English
    arrow-up
    37
    arrow-down
    6
    ·
    edit-2
    6 months ago

    What would give them standing? They’d have to be an entity protected by the constitution to claim that protection was harmed. Is it this (Wikipedia)?

    TikTok Ltd was incorporated in the Cayman Islands and is based in both Singapore and Los Angeles. source

    I guess I’ve never thought about what makes an entity have rights here. Buckingham Palace couldn’t just open shop here and start suing our government, right?













  • Good point in general, but, what they’re specifically talking about here (rolling codes), perhaps what they should have said is that no one can (feasibly) do it, not just that their hardware isn’t capable.

    Edit: Oh, for the blocking signal, that part might be functionality that could be added, I see what I think you’re saying there. Still, that would be a step towards it, but it would still require serious hardware to crack a private key, as I understand.