1,828 Matching Annotations
  1. May 2020
    1. Although Mr Abe is known for economic stimulus, his term has involved two large rises in consumption tax, from 5 per cent to 8 per cent in 2014 and then to 10 per cent in October last year. In both cases, the tax increase drove the economy into recession.

      Makes me more sympathetic to Biden plan (no tax raises under 400k income)

    1. Endpoint policies are currently supported by CodeBuild, CodeCommit, ELB API, SQS, SNS, CloudWatch Logs, API Gateway, SageMaker notebooks, SageMaker API, SageMaker Runtime, Cloudwatch Events and Kinesis Firehose.
    1. Using VPC endpoint policies A VPC endpoint policy is an IAM resource policy that you attach to an endpoint when you create or modify the endpoint. If you do not attach a policy when you create an endpoint, we attach a default policy for you that allows full access to the service. If a service does not support endpoint policies, the endpoint allows full access to the service. An endpoint policy does not override or replace IAM user policies or service-specific policies (such as S3 bucket policies). It is a separate policy for controlling access from the endpoint to the specified service.
  2. developer.chrome.com developer.chrome.com
    1. If a user clicks on that button, the onclick script will not execute. This is because the script did not immediately execute and code not interpreted until the click event occurs is not considered part of the content script, so the CSP of the page (not of the extension) restricts its behavior. And since that CSP does not specify unsafe-inline, the inline event handler is blocked.
    1. As we add new features and functionality to our Sites, we may need to update or revise this Privacy Policy. We reserve the right to do so, at any time and without prior notice, by posting the revised version on our Sites. These changes will be effective as of the date we post the revised version on our Sites.
    1. In the US, there is no one national law in regards to returns/refunds for purchases made online as in most cases, this is implemented on a state-by-state basis, however, under several state-laws, if no refund or return notice was made visible to consumers before purchase, consumers are automatically granted extended return/refund rights. In cases where the item purchased is defective, an implied warranty may apply in lieu of a written warranty
    1. Shouldn't I be adding the names of the cookies my site/app is using? The specific names of cookies don't provide users with information they can understand. Regarding cookies installed by third parties: the site owner is not in direct control of these cookies. This results in the naming and future changes to naming conventions also being outside of the owner's control and therefore also duty for disclosure. Due to this, we describe the cookies by their purpose and we give users all the instructions they need in order to understand cookies and manage them in their browsers. Then we link to the privacy/cookie policies of any third parties used by your site and we reference their opt-out pages, when available. This concept is the result from consultations with countless privacy attorneys, feedback from privacy authorities and the interpretation of the law itself.

      This sounds like a reasonable compromise.

      Like they say, listing specific names of cookies isn't helpful or practical/maintainable for perpetuity:

      The specific names of cookies don't provide users with information they can understand. Regarding cookies installed by third parties: the site owner is not in direct control of these cookies. This results in the naming and future changes to naming conventions also being outside of the owner's control and therefore also duty for disclosure.

  3. Apr 2020
    1. Third, the focus should be centered on improving transparency rather than requesting systematic consents. Lack of transparency and clarity doesn’t allow informed and unambiguous consent (in particular, where privacy policies are lengthy, complex, vague and difficult to navigate). This ambiguity creates a risk of invalidating the consent.

      systematic consents

    1. Q. I would like a copy of my data from a breach, can you please send it to me? A. No, I cannot Q. I have a breach I would like to give you in exchange for “your” breach, can you please send it to me? A. No, I cannot Q. I’m a security researcher who wants to do some analysis on the breach, can you please send it to me? A. No, I cannot Q. I’m making a searchable database of breaches; can you please send it to me? A. No, I cannot Q. I have another reason for wanting the data not already covered above, can you please send it to me? A. No, I cannot
    1. more than three-quarters support the stimulus plans that have already passed and “77% of the public thinks it will be necessary for the president and Congress to pass another bill to provide more economic assistance for the country.” That includes 66 percent of Republicans. We are all Keynesians now.
    1. So, on April 9, 2020 the US central government (the president and Congress) and the US central bank (the Fed) announced a massive money and credit creation program that included all the classic MP3 techniques, including helicopter money (direct payments from the government to citizens). It was essentially the same announcement that Roosevelt made on March 5, 1933. 
    1. Will Fithian en Twitter: “The authors said by email that they used a built-in Stata function and aren’t sure themselves how the software used the input weights. I suspect they misapplied that function (too complicated to tweet why) but I don’t know Stata well enough to be sure; it seems neither do they.” / Twitter. (n.d.). Twitter. Retrieved April 27, 2020, from https://twitter.com/wfithian/status/1252692362037362693

    1. Having visibility to the prevalence means, for example, you might outright block every password that's appeared 100 times or more and force the user to choose another one (there are 1,858,690 of those in the data set), strongly recommend they choose a different password where it's appeared between 20 and 99 times (there's a further 9,985,150 of those), and merely flag the record if it's in the source data less than 20 times.
  4. Mar 2020
    1. In general, the directive does not specifically require that you list and name individual third-party cookies, however, you are required to clearly state their categories and purpose. This decision by the Authority is likely deliberate as to require such would mean that individual website/app owners would bear the burden of constantly watching over every single third-party cookie, looking for changes that are outside of their control; this would be largely unreasonable, inefficient and likely unhelpful to users.
    2. a broader explanation of the way cookies operate and of the categories of cookies used will be helpful. A description of the types of things analytical cookies are used for on the site will be more likely to satisfy the requirements than simply listing all the cookies you use with basic references to their function.
    3. The cookie policy must: indicate the type of the cookies installed (e.g. statistical, advertising etc.);describe in detail the purpose of installation of cookies;indicate all third-parties that install or that could install cookies, with a link to their respective policies, and any opt-out forms (where available);be available in all languages in which the service is provided.
    1. What information is being collected? Who is collecting it? How is it collected? Why is it being collected? How will it be used? Who will it be shared with? What will be the effect of this on the individuals concerned? Is the intended use likely to cause individuals to object or complain?
    1. If your agreement with Google incorporates this policy, or you otherwise use a Google product that incorporates this policy, you must ensure that certain disclosures are given to, and consents obtained from, end users in the European Economic Area along with the UK. If you fail to comply with this policy, we may limit or suspend your use of the Google product and/or terminate your agreement.
    1. Vimeo We use Vimeo for video display. Read more Name Retention Function Statistics __utmt_player 10 minutes Track audience reach vuid 2 years Store the user's usage history Sharing For more information, please read the Vimeo Privacy Policy.

      I like how it groups cookies by the site/service that sets them, and has links to more information and privacy policy for each of those services.

    1. And since any commenter who only wants to drop taunts at others rather than engage on an intellectual level is a waste of everyone's time, I'll tolerate him or her for a while, a short while, hoping for unearthed maturity; but if this fails, that commenter is gone. Thanks for listening. 
    1. I've been meaning to remind readers that I do read the comments. Some time ago, one disappointed commenter mused that others' reflections seemed to go (as I recall) "into a void," because I remained silent to each. Perhaps I was ignoring readers' remarks? I assure you that is not the case. I read them all — although on this site, for some reason, "all" means somewhat sparse — and I find them nearly all remarkable in their perceptiveness. I especially welcome, and enjoy, intelligent disagreement. I choose not to respond, however, only because of my editorial philosophy, which holds that the comment section is, rightfully, for commenters — and commenters alone. I've already had my say, and it seems to me rather rude to take another whack in reply. Whenever I'm so substantively shaky or incoherent as to make my case unpersuasively the first time around, I figure I should live with the consequences. And whenever I find criticism flawed, I figure readers — perceptive as they are — will see the flaw as well, therefore there's no need for me to rub it in. So, I beg you not to take my silence personally.
    1. "I have read and agree to the terms and conditions” may well be the most common lie in the history of civilization. How many times do you scroll and click accept without a second thought? You’re not alone. Not only they go unread, but they also include a self-updating clause requiring you to go back and review those documents for changes. You’re agreeing to any changes, and their consequences, indefinitely. 
    1. And, frankly, we’re abetting this behavior. Most users just click or tap “okay” to clear the pop-up and get where they’re going. They rarely opt to learn more about what they’re agreeing to. Research shows that the vast majority of internet users don’t read terms of service or privacy policies — so they’re probably not reading cookie policies, either. They’re many pages long, and they’re not written in language that’s simple enough for the average person to understand.
  5. Feb 2020
    1. hook and line

      The quintessential fishing method, which uses a hook with a lure or bait attached to entice fish to bite on to the hook. Ensnared fish are then pulled to the surface for capture or release. This targeted fishing method allows scientists to minimize the impact of their research on other non-target fish that could end up as by-catch in nets, cages, and other gear. Also called "pole and line" fishing, this method can be used to make commercial fishing more sustainable, as in the case of tuna-fishing in the maldives, which you can read more about at The Guardian: https://www.theguardian.com/sustainable-business/pole-line-fishing-sustainability-tuna-market