• 0 Posts
  • 26 Comments
Joined 1 year ago
cake
Cake day: June 11th, 2023

help-circle











  • The short version is that the creators of this API are doing something more secure than what the client wants to do.

    A reasonable analogy would be trying to access a building locked by a biometric scanner vs. a guard looking for a piece of paper with a password on it. In the first case, only people entered into the scanner can get in (this is the cookie scenario). In the second case, anyone with a piece of paper with the right password on it will be let in (this is the Bearer token scenario).

    More technical version: the API is made more secure because the “HttpOnly” cookie - which, basically, means the cookie’s contents can’t be read with JavaScript in the browser - is used to hold the credentials the server is looking for.

    By allowing a third party to access the application, this means you have to allow methods that can be set “client-side” (e.g. via JavaScript in a browser). The most common method is in the “Authorization” HTTP Header - headers are metadata sent along with a request, they include things like the page you’re coming from and cookies associated with the domain. A “Bearer” token is one of the methods specified by the “Authorization” header. It’s usually implemented via passing the authorization credentials prefixed with the word “Bearer” (hence the name) and, often, are static, password-like text.

    Basically, because this header has to be settable by a script, that means an attacker/hacker could possibly inject malicious code to steal the tokens because they must, at some point, be accessible.


  • This misunderstands the premise. You cannot intuit someone’s subjective experience of reality because it is impossible for you to experience their experience of reality. You have only what they’re able to explain to you.

    To come at this from the other direction, if a friend says to you “I’m having a good day” and does not appear obviously distressed, how could you judge the relative goodness of their day or if it was actually good at all?


  • I can kinda understand Autism, to an extent. Certain forms of high-functioning autism - like the one I have - are more akin to mild learning disorders. Deliberate practice and effort can mitigate a great deal of the issues.

    On the other side, I’ve seen people with more extreme forms of the condition and I can’t imagine having to deal with that. I know I can be difficult to deal with and I work really hard to try to mitigate my shortcomings with others - especially people who don’t know me well - but I pale in comparison to the difficulty of people with more extreme forms of Autism.

    In this way, I think ADHD and Autism are probably similar - there’s a spectrum of impact the condition has. The milder forms of the condition may actually feel like a superpower to those that shape themselves to utilize their quirks in their favor. The problem arises when all forms of the condition are considered beneficial when they are demonstrably not.

    Hell, even I have problems that no amount of learning can ever overcome. You can’t exactly teach yourself how to pick up on the subconscious body language queues that most people just know inherently. I’m totally blind to that stuff and it makes intense conversations incredibly difficult and a little terrifying.



  • I won’t lie. I mostly don’t engage with content I see here. I didn’t do that when I was on Reddit either and mostly for the same reason: I don’t really have much to say and, even when I do have an opinion, I don’t usually want to engage in what’s often a protracted debate about something that will probably just end up being frustrating.

    That’s not to say I haven’t had positive experiences on the Fediverse - I’ve had more here than anywhere else - I’m just not particularly motivated most of the time.



  • Israeli settlers have, for years now, been slowly encroaching into territory officially recognized as Palestinian lands. These people absolutely have the choice to move back out of those areas and into lands officially recognized as belonging to Israelis. On the other hand, very few people can “just move, lol” and I wouldn’t be surprised if Israel specifically chose settlers that would be burdened economically if they attempted to leave.

    To be clear, Israel has continuously acted in bad faith against Palestinians and, along with its allies, destroyed the peaceful (or, at least, less militant) groups that sought to unite the Palestinians. This is absolutely a problem of their own making and I would be surprised if there was a peaceful path forward with the current political climate in the region.



  • Parade raining time: https://feddit.de/comment/3373323

    1. I believe flags are sorted alphabetically by how they are internally represented. All flags are a combination of two special letter-symbols. For the UK flag, these two symbols are “GB”, therefore the UK flag should be much earlier.
    2. 🇺🇸 (Flag of the USA [code: US]) ≠ 🇺🇲 (Flag of the US Outlying Islands [code: UM])

    Yes, the first US flag, which most people pick, is actually the flag of the US Outlying Islands. Whenever you see someone use the US flag emoji, check whether they accidentally used the " wrong" one.