1,711 Matching Annotations
  1. Jun 2020
    1. Ferguson, N., Laydon, D., Nedjati Gilani, G., Imai, N., Ainslie, K., Baguelin, M., Bhatia, S., Boonyasiri, A., Cucunuba Perez, Z., Cuomo-Dannenburg, G., Dighe, A., Dorigatti, I., Fu, H., Gaythorpe, K., Green, W., Hamlet, A., Hinsley, W., Okell, L., Van Elsland, S., … Ghani, A. (2020). Report 9: Impact of non-pharmaceutical interventions (NPIs) to reduce COVID19 mortality and healthcare demand. In 20 [Report]. https://doi.org/10.25561/77482

    1. Hsiang, S., Allen, D., Annan-Phan, S., Bell, K., Bolliger, I., Chong, T., Druckenmiller, H., Huang, L. Y., Hultgren, A., Krasovich, E., Lau, P., Lee, J., Rolf, E., Tseng, J., & Wu, T. (2020). The effect of large-scale anti-contagion policies on the COVID-19 pandemic. Nature, 1–9. https://doi.org/10.1038/s41586-020-2404-8

    1. On April 24, the U.S. National Security Agency published an advisory document on the security of popular messaging and video conferencing platforms. The NSA document “provides a snapshot of best practices,” it says, “coordinated with the Department of Homeland Security.” The NSA goes on to say that it “provides simple, actionable, considerations for individual government users—allowing its workforce to operate remotely using personal devices when deemed to be in the best interests of the health and welfare of its workforce and the nation.” Again somewhat awkwardly, the NSA awarded top marks to WhatsApp, Wickr and Signal, the three platforms that are the strongest advocates of end-to-end message encryption. Just to emphasize the point, the first criteria against which NSA marked the various platforms was, you guessed it, end-to-end encryption.
  2. May 2020
    1. That’s why the escape hatch is so appealing. Self-insured companies can tailor their health benefits to meet the needs of their workers. They don’t have to pay for services their employees neither need nor want. And self-insured plans pay their own medical costs, without having to subsidize the health-care costs of other groups.
    2. The administration and its allies fear that the more people gravitate toward the successful, free-market self-insurance approach, the worse their government-engineered health “reform” will look. We’re already seeing the beginning of this trend.
    1. Although Mr Abe is known for economic stimulus, his term has involved two large rises in consumption tax, from 5 per cent to 8 per cent in 2014 and then to 10 per cent in October last year. In both cases, the tax increase drove the economy into recession.

      Makes me more sympathetic to Biden plan (no tax raises under 400k income)

    1. However, it's possible to enforce both a whitelist and nonces with 'strict-dynamic' by setting two policies:
    1. sadness.js will not load, however, as document.write() produces script elements which are "parser-inserted".
    1. Endpoint policies are currently supported by CodeBuild, CodeCommit, ELB API, SQS, SNS, CloudWatch Logs, API Gateway, SageMaker notebooks, SageMaker API, SageMaker Runtime, Cloudwatch Events and Kinesis Firehose.
    1. Using VPC endpoint policies A VPC endpoint policy is an IAM resource policy that you attach to an endpoint when you create or modify the endpoint. If you do not attach a policy when you create an endpoint, we attach a default policy for you that allows full access to the service. If a service does not support endpoint policies, the endpoint allows full access to the service. An endpoint policy does not override or replace IAM user policies or service-specific policies (such as S3 bucket policies). It is a separate policy for controlling access from the endpoint to the specified service.
  3. developer.chrome.com developer.chrome.com
    1. If a user clicks on that button, the onclick script will not execute. This is because the script did not immediately execute and code not interpreted until the click event occurs is not considered part of the content script, so the CSP of the page (not of the extension) restricts its behavior. And since that CSP does not specify unsafe-inline, the inline event handler is blocked.
    1. As we add new features and functionality to our Sites, we may need to update or revise this Privacy Policy. We reserve the right to do so, at any time and without prior notice, by posting the revised version on our Sites. These changes will be effective as of the date we post the revised version on our Sites.
    1. In the US, there is no one national law in regards to returns/refunds for purchases made online as in most cases, this is implemented on a state-by-state basis, however, under several state-laws, if no refund or return notice was made visible to consumers before purchase, consumers are automatically granted extended return/refund rights. In cases where the item purchased is defective, an implied warranty may apply in lieu of a written warranty
    1. Shouldn't I be adding the names of the cookies my site/app is using? The specific names of cookies don't provide users with information they can understand. Regarding cookies installed by third parties: the site owner is not in direct control of these cookies. This results in the naming and future changes to naming conventions also being outside of the owner's control and therefore also duty for disclosure. Due to this, we describe the cookies by their purpose and we give users all the instructions they need in order to understand cookies and manage them in their browsers. Then we link to the privacy/cookie policies of any third parties used by your site and we reference their opt-out pages, when available. This concept is the result from consultations with countless privacy attorneys, feedback from privacy authorities and the interpretation of the law itself.

      This sounds like a reasonable compromise.

      Like they say, listing specific names of cookies isn't helpful or practical/maintainable for perpetuity:

      The specific names of cookies don't provide users with information they can understand. Regarding cookies installed by third parties: the site owner is not in direct control of these cookies. This results in the naming and future changes to naming conventions also being outside of the owner's control and therefore also duty for disclosure.

  4. Apr 2020
    1. the cost of reading consent formats or privacy notices is still too high.
    2. Finally, from a practical point of view, we suggest the adoption of "privacy label," food-like notices, that provide the required information in an easily understandable manner, making the privacy policies easier to read.
    3. Third, the focus should be centered on improving transparency rather than requesting systematic consents. Lack of transparency and clarity doesn’t allow informed and unambiguous consent (in particular, where privacy policies are lengthy, complex, vague and difficult to navigate). This ambiguity creates a risk of invalidating the consent.

      systematic consents

    4. the authority found that each digital platform’s privacy policies, which include the consent format, were between 2,500 and 4,500 words and would take an average reader between 10 and 20 minutes to read.
    1. Q. I would like a copy of my data from a breach, can you please send it to me? A. No, I cannot Q. I have a breach I would like to give you in exchange for “your” breach, can you please send it to me? A. No, I cannot Q. I’m a security researcher who wants to do some analysis on the breach, can you please send it to me? A. No, I cannot Q. I’m making a searchable database of breaches; can you please send it to me? A. No, I cannot Q. I have another reason for wanting the data not already covered above, can you please send it to me? A. No, I cannot
    1. There is a forum for discussing CommonMark; you should use it instead of github issues for questions and possibly open-ended discussions. Use the github issue tracker only for simple, clear, actionable issues.
    1. more than three-quarters support the stimulus plans that have already passed and “77% of the public thinks it will be necessary for the president and Congress to pass another bill to provide more economic assistance for the country.” That includes 66 percent of Republicans. We are all Keynesians now.
    1. So, on April 9, 2020 the US central government (the president and Congress) and the US central bank (the Fed) announced a massive money and credit creation program that included all the classic MP3 techniques, including helicopter money (direct payments from the government to citizens). It was essentially the same announcement that Roosevelt made on March 5, 1933. 
    1. Will Fithian en Twitter: “The authors said by email that they used a built-in Stata function and aren’t sure themselves how the software used the input weights. I suspect they misapplied that function (too complicated to tweet why) but I don’t know Stata well enough to be sure; it seems neither do they.” / Twitter. (n.d.). Twitter. Retrieved April 27, 2020, from https://twitter.com/wfithian/status/1252692362037362693

    1. Dorison, C., Lerner, J. S., Heller, B. H., Rothman, A., Kawachi, I. I., Wang, K., … Coles, N. A. (2020, April 16). A global test of message framing on behavioural intentions, policy support, information seeking, and experienced anxiety during the COVID-19 pandemic. https://doi.org/10.31234/osf.io/sevkf