In this example smart glasses are the equivalent of walking around pointing a gun. Obviously shooting the gun is the real issue but simply pointing it around alarms people and fatigues them to spotting a real threat.
Smart glasses should not be allowed to have a camera always pointed at people. If needed, let them integrate with a phone to use the camera which is much more visually obvious to people when it is being used.
Published CVSS is a base score that gives you a hint of how important the analysis of a vulnerability is to prioritise the patching or mitigation. What you see on websites is only ever the base spiciness so to speak. If you have for example wordpress only running in an isolated environment behind internal firewall rules you‘d downgrade it accordingly. It’s a imperfect metric but so far the best we have to signal priorities. It’s all described in its spec that no one seems to read and websites also communicate it badly.
> These metrics enable the analyst to customize the CVSS score depending on the importance of the affected IT asset to a user’s organization, measured in terms of complementary/alternative security controls in place, Confidentiality, Integrity, and Availability. The metrics are the modified equivalent of base metrics and are assigned metric values based on the component placement in organization infrastructure.
CVSS is impossible to communicate effectively. We don't need a metric; I'm already going to have to read and assess the vulnerability to decide how I actually want to assess the risk given my infrastructure, so the number's not doing me any good.
This isn't just a CVSS issue: there have been a variety of attempts to reduce a risk score down to a single general number and they all end up as somewhere between marketing material, scare tactic, and junk science.
> We don't need a metric; I'm already going to have to read and assess the vulnerability to decide how I actually want to assess the risk given my infrastructure, so the number's not doing me any good.
Would you say that vulnerability with CVSS score that points to low is equally important to verify and take care of than CVSS which points to critical?
Yes. I believe that using CVSS scores as a first pass to decide which vulnerabilities to review is risky.
The most boring reason, even if you take CVSS scores at face value, is that in many cases it is possible to leverage multiple "low" severity vulnerabilities into a massive impact.
But the bigger reason is that CVSS scores are all over the place, and the people operating roulette wheel that generates them do not have any insight into any specific person's systems.
I saw ads for tai chi for a long time and thought of a Chinese hearts and minds campaign. That article reads like it was sponsored as well. Anyone else with the same impression?
Yes, all of the links seem to go through to shopping funnels, even to get a PDF. I’m not seeing any freely downloadable resources. This is basically just an ad.
Many of the true old masters of Tai Chi fled to Taiwan during the Cultural Revolution.
So, if you want the best of both worlds (to learn Tai Chi AND avoid modern China's soft-power influence), sign up to a school that traces its roots back to Taiwan from that era.
I have neither a positive nor negative stance towards that practice. At least the Thai government used Thai restaurants and Muay Thai as a softpower booster. It would not surprise me when China does the same. To (assumingly) spend a lot of money to get Havard of all places to advertise for something that you can also get for free on youtube is a clue in my book.
Tai chi is pushed by a Chinese organisation considered as a dangerous sect by the CCP. Falong something, I can't remember, basically inheritors from a 1980-1990s movement.
Google, Apple and co are free not to do business in the EU. There is no "overreach". It's a 450M pop market with a high median per-capita income. There are many reasons why the EU has a rather small tech industry of its own, high up among them that the EU does comparatively little to protect its market compared to China where most US tech companies don't even bother to enter anymore. In China, if a fine like this hits you, you are not allowed to do business anymore until it's either paid or revoked in court. So yeah, the EU is very lenient on all accounts.
Isn't the median income per capita higher in the US. European companies are likewise free to pay tariffs or not do business.
EU does much more to protect its market compared to US.
EU was never a developing country like China. Most countries in EU benefited from centuries of exploitation of Asia, Africa and the Americas. They don't need protectionism.
reply