In a hospital setting nobody will be degloving your finger - this is a common situation, and they have pliers that will crack/shatter the tungsten for removal.
I live in a town of <15k people, and it’s the county seat. Our hospital can handle tungsten carbide rings without issue. I checked before getting one for this very reason (though I now wear an Oura as my wedding ring).
Certification takes time and probably overlaped with the phone development. Fairephone is small compared to e.g. samsung and they describe themself more "stable" and long-term support than bleeding edge.
Fairphone 5 and earlier also have end-of-life Linux kernel branches without security support. Fairphone's more recent devices are headed to the same situation. In practice, the same thing happens with other components beyond the Linux kernel.
Fairphones have 1-2 months of delay for partial security backports to older releases from the beginning and much longer delays for full updates. Android 17 is required for full Android security updates. Only a subset of patches are backported to older versions and that subset is decreasing.
Android 17 is also required for the latest and greatest privacy/security protections which are not backported. There have been massive privacy and security improvements in each yearly Android release.
Because a lot of things is public online and can't be copied and sold e.g. due to copyright, patents and trademark. Also if you access a website you are bound to a ToS contract and this is a breach of that contract.
Any person who, with the intention of securing an unlawful gain for themselves or another obtains for themselves or another data that are stored or transmitted electronically or in some similar manner and which are not intended for them and have been specially secured to prevent their access shall be liable to a custodial sentence not exceeding five years or to a monetary penalty.
So this wording is really interesting in the bug bounty sense and I’m curious if you know how it would be handled.
If someone hits an unsecured API, receives information, and notifies the company of this while also requesting a bounty, would that satisfy all of the requirements of prosecution?
The unlawful gain is the sticking point in my mind.
If you publish the bug then it could be unfair competition in my opinion. There was a product test where the mentioned some flaws of a medicine but didnt mention other producers of same drug. They broke the UC rules and paid some money: https://politchronik.swiss/de/prozesse/57953-das-kassensturz...
If you access "private" data it's also unlawful acording to 143. Pentesting is a hot topic but there are comapnys acusing you of hacking if you send them a security report (hacking). If they mention a bug bounty program then you are allowed to test their security as described in this program but not more.
If I would avoid env then i need to put it in some kind of conf file and configure the app to read this file (e.g. mount into container). If I use a fault then i need some kind of credentials to receive the credentials.
So again what do I gain if I avoid env variables in containers?
I just use my home router as VPN to not care if the 100 apps om my phone have a working encryption. I also use it to access my home services so that they are not exposed to the internet. I also use it to limit exposure on my VMs on a cloud hoster.
reply