I've been told by multiple people that the recovery method of passkeys is to enter your username/password. If passwords are eliminated, your final recourse is fucked.
Which is a laudible goal, but something that makes "oh just fall back to the standard insecure recovery process" not a very good response to the concerns about users being able to actually hold on to their passkeys easily and reliably.
> We are working with outside cybersecurity forensic specialists to investigate the issue and review our security policies and procedures. Finally, we have also reported this incident to law enforcement agencies.
Do we expect Nvidia acquisition of HF to have changed the vibe? Note that also the OP is from July, before the acquisition.
> Note that even OS kernels can have this issue - imagine what happens in virtualized environments with overcommitted physical CPU's scheduled by a hypervisor as virtual CPU's? Yeah - exactly. Don't do that. Or at least be aware of it, and have some virtualization-aware paravirtualized spinlock so that you can tell the hypervisor that "hey, don't do that to me right now, I'm in a critical region".
I can't be the only one who learned this the hard way by cramming too many vCPUs onto too few physical cores and initially wondering where the high load and latencies came from.
From a business perspective, Amazon was/is a legit business threat to ~every physical bookstore (and, arguably, many publishers). It doesn't follow that they could take Amazon to court for that.
That update was made 9/6: 5 days prior to archival and on the same day xcancel.com previously also "returned". I can find no public updates regarding Nitter project after the 9/11 archival.
The repo being archived happened after that UPDATE post that you mention. So the project has gone from suspended, to un-suspended, and now it's suspended again (and the repo got archived this time).
Edit: I see I'm being downvoted for just providing facts, so here's some evidence: you can see on the main project page that the repo was archived on 11 Sep[0]. Looking in the commits, the "UPDATE" message was commited on 6 Sep[1].
It's impossible to know what this "legal advice" was, but the software project itself is probably fine. The legal risk is always going to be with the person that hosts it with the intention of facilitating the unauthorized access of Twitter's website. Seems like that could run afoul of the Computer Fraud and Abuse Act.
In cases like these, companies often try to go after the upstream project, not just operators. The law gives them lots of tools for this: the CFAA has a conspiracy provision; The DMCA has a provision against making software for circumventing copyright; Trademark law might make the name nitter or xcancel illegal; and finally even if the claims are weak the litigation itself is an enormous burden
reply