• 54 Posts
  • 1.29K Comments
Joined 3年前
cake
Cake day: 2023年9月1日

help-circle




  • I assume I need to create an account for that and login? Why should I go through the hassle of creating an account to verify claims? These are things that should be verifiable externally without privileged access.

    And reading further, they say that after 12 months you can get the code with a BSL and then AGPL. That’s great, but they say you can’t publish the archive once they give it to you? That’s not very AGPL. And it means that you first have to pay for a year before knowing whether their claims are valid. And that depends on you getting the code for the relevant parts of the search engine.

    It’s possible they are doing what they say, but to start trusting, there has to be proof. Somehow.










  • SerpiApi doesn’t give two shits about the openweb. They are just here to exploit it with their scraping. It’s very convenient to call a search engine the openweb, an action I fully support, but it’s not because they are some grand protectors or something. They just want to make money.

    For Google, it could be “very dangerous” to argue that the knowledge panel is “chock full of copyrighted material,” Rose suggested. Since the search giant doesn’t license all the content in the knowledge box, Google could risk future lawsuits if the act of algorithmically creating the knowledge box without licenses suddenly becomes viewed as infringement, Rose said.

    If Google comes out of this a winner, it’ll be because the judge was paid off or there was some obscure law they used, that made no sense but was somehow applicable here, in a twisted manner.






  • Fruity mobiles have been hacked multiple times. The Israelis routinely do so. Pegasus might right a bell. Jeff Bezos was even a victim.

    Also, the fruit store’s App Store still has malware despite the 30% they steal from developers in the name of “security”.

    The company also sells ads and ad placements BTW. If that isn’t an indication of their goals…

    Regarding bounties, they have regularly snubbed white hats and pentesters. They are one of the most wealthy companies in the world and hate paying bounties. The one I remember clearly is a dude finding exploits in their supply chain, which could’ve led to the attacker sending phones anywhere they wanted and emptying warehouses or adding unnecessary stock. They for nothing, yet the bugs were quietly resolved. Any adversary could thus do what the Israelis did and reroute shipments to modify material before it reaches its destination.

    And let’s not forget the incident where people started seeing photos on their phones from other people’s iCloud, or employees repeatedly snooping on iCloud accounts, especially of celebrities, despite the data being “encrypted”.

    Or that time Macs couldn’t function because some server somewhere was getting DDOSed?

    Finally, it’s a US company. The CLOUD Act and Patriot Act force(d) them to so what was decided in secret courts, without ever being given the right to expose it.

    There’s more, you just have to care to look for it. They are masters of marketing. That’s their entire thing and you are falling for it. Remember that corps aren’t here dlr you. They are here for the money. Especially big companies like that.