Hacker Newsnew | past | comments | ask | show | jobs | submit | postexitus's commentslogin

For 60% of the world, it doesn't make a difference. Do not project your gendered (read: sexist) language constructs onto us.

Yeah, through multiple layers of approvals. Not shtposting on hacker news.

It is multiple layers of approval, but there is no reason to think they wouldn't approve this. At least not from the limited information I have. The approval is about covering themselves, so if they won't get sued (either because it is legal or they can cover their tracks) they will approve it. There is more than lawsuits they track, but the exact set of things is different for each company and I have no idea what Apple works on.

Thus this could be Apple marketing, or it could be someone independent.


Shit posting looks like natural use of social media so it's actually preferred

https://www.forbes.com/sites/jaymcgregor/2017/02/20/reddit-i...

“I have worked over 100 of these kinds of campaigns and never had it come back on the client. I’ve been doing viral marketing and reputation management since 2005. =In the past year I’ve worked for a major entertainment network to magnify a rumor within sports entertainment, as well as damage control on a rumor that came out of an actor being hired on a film before the production company was ready to announce that casting.”


If apple indeed use shit posting, there has to be several layers of subcontractors in between for plausible deniability. Apple's own comms guidelines strictly prohibits pay-per-review, manipulative, "shit posting" style practices.

This, from a 1 day old throwaway account, tells a lot.

I understand BBC may not have the technical background to critically assess this approach, but whoever using Eudora (I loved it in 2001 btw) for security should get their credentials removed via King's order. Security through "obsolescence" is no different from security through obscurity - therefore, it doesn't work. Somebody not bothering to look for holes in your software doesn't mean they don't exist - in the age of Claude - I am pretty sure I can destroy your legacy software in minutes.


> in the age of Claude - I am pretty sure I can destroy your legacy software in minutes.

Yes but you'd need to a) know that they use that particular software and b) have a reason to bother destroying it in the first place.

That is really the crux of the idea.

The client the guy in the article uses isn't secure because it has no security vulnerabilities - it is secure because nobody bothers to target Eudora users in general.

Of course as others mentioned, if the target switches from "Eudora users in general" to "that guy in particular" then the situation changes (though the attackers would still need to realize he uses Eudora - assuming this article didn't exist to reveal it anyway :-P).

But aside from that, even "in the age of Claude", i doubt anyone is wasting time and/or tokens scanning the open Internet for all sorts of old vulnerabilities in antique software that (relatively) nobody uses in hopes they catch some random passer-by as there is barely any ROI by doing that compared to taking advantage of vulnerabilities on software that people actually use.


True - you avoid widespread attacks, but you become super vulnerable for targeted ones.


> I understand BBC may not have the technical background...

This is BBC Future - the BBC's tech clickbait publisher - not BBC News.

BBC consists of the non-profit news bureau as well as at least a dozen for-profit clickbait and listicle publishers. BBC's ad-free mandate is only for the UK.

> in the age of Claude - I am pretty sure I can destroy your legacy software in minutes

Yep. One of our PortCos has unrestricted access to Anthropic and GPT models. With whitebox testing, it's trivial to identify vulns in legacy environments. With blackbox testing, it takes some effort but it doable with the right steering.


I would be curious to know what kind of vulnerabilities the latest version of Eudora (7.1.0.9 I think) has. With how old it is (2006), surely there are several critical vulnerabilities, but all I could find when looking online is that an IMAP server or SMTP server can execute arbitrary code, which doesn't seem likely to cause a real problem, because I wouldn't expect Google, Yahoo, Microsoft, etc. to use this trick.

The article links to a vulnerability from 1998, which I expect is already fixed in the versions of Eudora people still use.

I agree it would probably be easy for AI to find exploitable bugs though.


> an IMAP server or SMTP server

I hope they are authenticating the server to prevent MITM attacks.


wait until you find out that a large percentage of operating system developers use mutt, alpine or mail.


mutt is still being actively developed. Being on command line doesn't make something legacy. Eudora on the other hand had its latest version out 2 decades ago - it lacks even the most basic security updates (starting from TLS, but many more).


At some point it's going to catch up. Legislation is a very hard process.


Sports betting is centuries if not thousands of years old.


No - it means you are exposed to - electricity / gas / oil prices. Or Wheat maybe?


Everyone is exposed to those so by that definition nobody would ever be gambling. I was trying to be charitable so assumed the bar was higher in the what-if.


You aren't exposed to football game outcomes, nor dice rolls or cards flipping. I, in california, am not exposed to electricity prices in the northeast. My exposure to wheat prices is extremely small - if I go and bet a lot on wheat going down, I'm gambling.

If you are creating risk that didn't exist, you are gambling.


Nice Ramen sold at 14 EUR are those prices. In Japan, you can have a nice hinge quality bowl of Ramen for around 7-8 EUR.


Besides fast food, isn't it always like that though? Of course Japanese food is cheaper in Japan, but I bet Spanish food is more expensive there than in Spain? Or Peruvian food being a lot more expensive in Europe compared to in Peru itself, it kind of makes sense.


yes, that is the case.

But I think the point is that paying 7€ makes it a pretty good deal, at 14€ for "a bowl of soup" it becomes a meh experience.

Similarly, as an Italian abroad, I can get a decent pizza margherita in Budapest, but it costs 12 euros and I get upset every time, you shouldn't spend that much for a bit of dough and mozzarella :)


Cries in London


Comparing price tags across Japan and the west is kind of meaningless now considering how much the yen devalued. I don't think the prices would look that good for a Japanese person paid in yen.


That's why you should try it in Japan.


You are naive. Nothing to do with empathy. Everything is cash - warm little cash. No what's lost is - people stopped voting with their wallets. When someone did something atrocious, people stopped buying it. Now - first of all, half of the consumers don't care if PS5 titles are on disc already. And they will not stop when they stop putting things on discs. So why would Sony stop?


Ok great don't buy them in digital form so Sony learns a lesson?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: