Our politicians and legislators lie on camera constantly. But it doesn't really seem to matter much these days. So I'm not sure why this would make a difference.
> Alternatively, you can get an Apple TV and keep the TV off networks or in network jail.
The problem is that a lot of TVs won't even let you use it that way without signing in or downloading an app first. My Vizio wouldn't do anything until I acknowledged a terms of service screen. The only way I could do that was by downloading the Vizio app and connecting it to my network.
The cost of returning the thing to the store can be high.
The packaging can be precarious; what was once stapled cardboard is now taped, what was once a neat and rigid rectangle is now kind of floppy and misshapen and getting worse every time it moves.
Besides, they're big things that can be challenging to move around. Doing it solo is mostly a non-starter.
But sure: Eventually, it gets wheeled back in through the same front door of the store that it came out of just a few hours before.
Now the real fun starts: They don't want it back. They hem and haw. Other associates arrive to reinforce the ultimately firm standpoint of "No."
You point at the return policy on the wall. You read the relevant passages aloud, word by word. You tell them, over and over again, that you're here to return merchandise.
Some smart-sounding person shows up, gives everything an appraisal, and explains "Sir, it even says DO NOT RETURN TO STORE right here on the box!"
It's not clear who got loud first, but it's quite obviously the case that things are definitely loud now.
Finally, the store manager appears. He just needs this fucking circus to end. He asks no questions, issues the refund without hesitation, and everyone walks away pissed off.
---
I mean, I guess that's resolution.
But what often happens instead is this: The TV is unpacked. It's mounted on the wall or arranged just-so on whatever furniture is involved, requiring sometimes-tricky bits of assembly the whole way through. There's excited anticipation in the air about the new widget and how much better it is going to be than the old widget.
Finally, you switch it on and discover that it can't proceed without a network login. This raises a series of red flags that you find impossible to ignore.
So you go out back to cool off for a few minutes, think about life's decisions, and Google ways to get this 2026 build of this TV that nobody online ever mentions the specific model number of to work offline without any connection.
And the missus knows how these things can go. So while that's happening, she signs the thing into the network and gets it set up with an account "just to see how it really works."
Now the TV is connected and it's never going back to the store.
Mounting on the wall is just four screws to the TV, with a standard bolt pattern that fits any modern TV. Whatever accomodations were made will work exactly the same with any TV of approximately the same size.
Since the mounting hardware you already have from your previous TV does follow VESA, you would be returning the new one for that reason.
Unless, you know, it was amazing, like completely dumb with no registration step, and offering great picture quality. That might be worth drilling some new holes in the mounting plate, or whatever it takes to make it work.
When I say returning, of course I mean not buying in the first place! "Does it have a standard bolt pattern compatible with my intended mount" is one of the first things you check for in the technical specs, long before you order something or go pick it up. If your mount is strictly 100x100, you can't have a larger TV on it that has a 200x100 or 200x200.
I've been a consumer of electronic goods for several decades, I have returned many things to stores, I've installed televisions professionally, and I've had one or more missuses.
Is there any merit to pinning me down on this matter?
Do you want me to start asking you the questions, instead?
Penn & Teller have a Bullshit! episode about this (Season 2, Episode 5). Well, it's technically about recycling, but it makes the claim that landfills are not a bad thing, and much better than the current recycling situation, in most cases.
That episode has always stuck with me, and I've always wondered how valid their argument is.
I remember watching that as a young teen with a libertarian bent. As an old man who no longer identifies as libertarian that episode for some reason has stuck with me as the arguments were pretty compelling. I agree and would like to know if the calculations have changed today or if their argument is still valid.
Their argument was NEVER valid, Penn and Teller never addressed how long this trash actually takes to break down (Estimates are as high as 10,000) years. This means for 10,000 years you would need to inspect the landfill every year, and repair it when the landfill breaks.
In actuality what will happen is that all these buried landfills will break, all the bad stuff will leak out and enter the ground water. The groundwater becomes polluted, the plants start dying. And you end up with dead dirt that nothing will grow in.
The people advocating for landfills now, are not going to be around 500 years from now to see the results of their selfish thinking.
The primary issue is that we took elements naturally found in nature and used them to create manmade synthetic material, that nature has no tools to deal with. And these manmade synthetic material will eventually break down small enough to the point where quantum forces take over (nanoscale sized particles) and enter the groundwater. And plants and animals will drink in these manmade synthetic materials the size of nanometers, and the body has nothing that can breakdown or deal with these manmade synthetic materials. Putting a piece of shit into icecream and mixing it is easy. Unmixing a icecream mixed with shit to remove the shit is scientifically impossible.
For billions of years, high-density elements (lead, cadmium, mercury, rare earth elements, arsenic) were locked away in solid mineral ores, buried under hundreds of feet of rock. Surface biology only ever encountered them as faint, background trace elements.
We mined gigatons of these ores, refined them to near-100% purity, combined them with synthetic chemicals, and packed them into hyper-dense landfill cells right above or near freshwater aquifers.
Landfills are fundamentally a temporal transfer mechanism. They take the immediate waste generated by modern high-consumption lifestyles—cheap electronics, disposable packaging, synthetic textiles, convenience goods—and bury it out of sight, converting a present-day logistical crisis into a slow-motion geological problem for future generations.
> > a Google Account that isn't tied to anything else.
> Isn't that pretty much impossible? You need a phone number for verification, which effectively ties it to that phone number.
I just want to follow-up on this because some people claim this is not correct because they have managed to create accounts without phone numbers.
Indeed, I think to this day, under special circumstances (like e.g. on reasonably recent Android devices) you might be able to setup a Google account without phone number.
The trick is, that in the general case, you can not keep this account online indefinitely.
First thing to note: This way of account creation does not seem to work anymore.
Second thing to note: After once logging in from a different country, trying to login again REQUIRES me to provide a phone number after successfully giving username/password/2FA code. No way to use the recovery code instead...
Also, given that this account was never before connected to a phone of any kind, by definition, the addition of a phone number cannot provide additional security confirmation (it's data that simply wasn't present before and any "personal" phone number could potentially do -- of course I haven't tried, because that's the point of not linking a phone number).
I think this way it is finally proven that they only do this to harvest the data/phone numbers and any claim of enhanced security is void.
I write this after having lost the second account to the phone number required screen despite being in possession of all the credentials which were ever assigned to that account...
Even with a burner sim, there is the International Mobile Equipment Identity (IMEI) number, which is tied to the phone, and is known to all apps with the android.permission.READ_PRIVILEGED_PHONE_STATE permission.
As of Android 10, apps cannot obtain permission to access non-resettable hardware identifiers such as the serial number, MAC addresses, IMEIs/MEIDs, SIM card serial numbers and subscriber IDs. Only privileged apps included in the base system with READ_PRIVILEGED_PHONE_STATE whitelisted can access these hardware identifiers. Apps targeting Android 10 will receive a SecurityException and older apps will receive an empty value for compatibility. The currently enabled carrier-based messaging app for SMS/MMS/RCS is a special case that's given access to certain device identifiers including the IMEI. This is normally the GrapheneOS fork of AOSP Messaging but can be changed to another app by the user.
Since these restrictions became standard, GrapheneOS only makes a small change to remove a legacy form of access to the serial number by legacy apps, which was still around for compatibility. It used to need more extensive changes such as disallowing access to the serial number but those restrictions are now standard.
I don't know however if sandboxed google play is such a privileged app.
I couldn't immediately find whether GrapheneOS grants READ_PRIVILEGED_PHONE_STATE to Google Play. It might very well be that the GrapheneOS sandbox spoofs a fake IMEI, and I do hope so.
In any case, my parent comment was meant for stock Pixels, as mentioned by armadyl further up in this thread.
> Google Play receives absolutely no special access or privileges on GrapheneOS as opposed to bypassing the app sandbox and receiving a massive amount of highly privileged access.
It doesn't mention IMEI here, but hopefully READ_PRIVILEGED_PHONE_STATE is included in "privileged access."
That's also incorrect, because the gmscompat app is just a helper app. Play services can and does request additional permissions. Those permissions are handled by the OS under the play services app, not gmscompat. If you want RCS for instance, you must grant play services and google messages phone and ICC auth access, which isn't seen in gmscompat at all.
> That's also incorrect, because the gmscompat app is just a helper app.
Hmm, ok. I was reasoning the helper app was needed to get around the default assumptions from Google Play Services.
> Those permissions are handled by the OS under the play services app
Yes, but I assume you don't mean that as that GOS makes special hard-coded provisions for the play services. GOS claims to run Play Services like any other unprivileged app, and so any additional permission it would want would have to be consented by the user and should be visible to the user. If not, then GOS wording would be quite a bit unfortunate at least.
EDIT: "GmsCompatConfig is the text-based configuration for the GrapheneOS sandboxed Google Play compatibility layer. It provides a large portion of the compatibility shims." [1] This seems to indicate that the permissions requested by Play Services are being honored with the shims from the helper app. That would alleviate the permission problem.
Google Mobile Services apps installed on GrapheneOS including Play services run as regular sandboxed apps. They receive absolutely no special access compared to other apps by installing and running them. There are the standard permission toggles for granting those but none of those are required for typical usage to provide compatibility with many apps from the Play Store depending on their services.
There are additional special permission toggles for RCS and Android Auto. The issue with RCS is mainly that they split the implementation across Google Messages and Play services. Android's standard permission model gives special access to the app selected by the user as the messaging app but Google Messages expects Play services to have special access too.
The shims defined with GmsCompatConfig are a small subset of the overall compatibility layer. It has many shims which need to actually implement the functionality such as remapping the Play Store using privileged installation APIs to the regular ones available to user installed app stores. It has to remap the APIs used by dynamite modules to ones not requiring privileged SELinux policies too. It has a mix of shims which simply stub out the functionality and many which need to handle it as a regular sandboxed app would need to do it.
The only way to install Google Mobile Services apps including the Play Store on GrapheneOS is as regular sandboxed apps. They aren't granted any of the large number of usual privileged permissions, don't run with the usual far more privileged SELinux policies, aren't used by the OS as a backend for anything and aren't otherwise allowed to do special things by the OS in the usual many ways that is granted. They're regular sandboxed apps on GrapheneOS.
That's the application software side. I would assume the IMEI and IMSI are both going out to the cell network though, and I would presume that it's trivial to tie a phone number to those with how the mobile industry generally sells subscriber data to various data brokers. The only question is how permissive those data brokers are (their major constraint is how much most people become aware of this dynamic), but when dealing with a major APT like Google I'd assume they're tuned into the best ones with songs about bona fide purposes.
Yes I am talking with a US perspective. I would hope the GDPR would prevent such things in (most of) Europe. But I also personally wouldn't assume so given that there are still the same dynamics of keeping the info flows private to avoid scrutiny, and claiming plausible "legitimate purposes" and "consent".
The only way to use Play services on GrapheneOS is as a regular sandboxed app. It runs in the standard app sandbox without any of the usual privileged permissions, privileged SELinux policy and many other forms of special access. It also doesn't get used by the OS as a backend for anything. Our sandboxed Google Play compatibility layer implements this by remapping APIs to ones available to sandboxed apps and stubbing out many which aren't needed.
Its possible to set up a phone with a google account without even a sim card in it and use it as a wifi only device, so Im pretty sure what your saying is wrong.
I've had no end of trouble registering an account on our corporate SIMs as the phone numbers (not the actual SIM cards) had been recycled as employees leave.
So many systems cannot handle known pattern of a phone number changing. Who's decided these are imutable values? That I have only one? That it's not shared?
> You can also just get a burner phone number for a few bucks.
But you have to keep paying the monthly cost, if you loose access to a phone number in your Google account it's game over for any account recovery or "let's verify it's you" it might decide to throw your way.
I've been using an app on my Android called KineStop. It definitely works.
I also recently picked up an EmeTerm wristband - it's basically a mini TENS machine for you wrist. I was super skeptical, but my sister recommended it so I tried it and it absolutely helps with (though doesn't always total eliminate) nausea I get from motion sickness. I'm not entirely sure how it works, but it seems like it may have an accelerometer and use that to decide when (and at what strength/duration?) to send a mild shock.
> Better Auth checked a lot of boxes right out of the gate: high code quality,
Maybe I have high standards, but I absolutely would not describe Better Auth as having "high code quality". It has certainly been improving, but when I first looked at this project it felt really rushed and thrown together, with little automated tests. There's was virtually no logging last I looked, so there's little options to monitor what's happening. I think they've added hooks now so you can "bring your own logging", I guess. And they finally added audit logs but that's only if you use their managed services.
Having said that, I actually use Better Auth, and I'm a huge fan despite those criticisms. I love that it's open source and extendable (there's a free 3rd-party audit logging addon, actually). It's super straight-forward to implement compared with similar products (Ory Kratos, Keycloak, etc). You don't even need a separate DB if you don't want - you can have it create tables in your existing database. And it _is_ improving quickly.
PHL has a verion of this ("Wingmate pass") that I use pretty frequently now! If I have a friend/family flying in/out I usually get one so I can meet them at the gate. It's very nice and convenient. I just wish they would let me use my Precheck, because I have to go through the "regular" security line and sometimes it's just too long and I don't bother.
This SFO version looks a bit nicer, though. You can apply 30 days out vs PHL's 7 days. And PHL makes me choose a specific entry gate when applying. So if you show up and that gate has a long line you can't just go through another gate that has a shorter line (at least that's what they tell you - in practice I've entered through different gates without any problems).
Both PHL and SFO won't notify you whether you are approved until midnight of the day you want to enter, which I find interesting. I guess that's some sort of security feature? I've never been denied, but it could be a hassle if you don't find out until the last minute that you were denied.
Since we're comparing those two in particular... The difference between SFO and PHL could not be more stark.
SFO: Brand new, high ceilings, quiet, clean, soft lighting and overall chill vibe. Variety of healthy (or not) food options, Ritual and Equator coffee. Decent bathrooms.
PHL: Dingey, cramped, loud. Bad food - not even good cheese steaks. Security checkpoints are spread out, PreCheck is far and no Clear. And absolutely FILTHY. I tried to point out to the TSA management that their employees are literally surrounded by dust bunnies the size of my fist, and they said cleaning is not their department. (No duh?!)
It's going from best in the country to worst, IME.
I don't really think this is fair. I haven't been to SFO in years, and I'm sure it's great. But I don't think PHL is nearly as bad as some people like to make it out to be. (To be honest, I think a lot of people just like to trash Philly.)
But it really depends on the terminal, too. I can never keep track of which terminal is which (other than international), but most of them are quite nice, with nice shops, art work, and restaurants (though, at the end of the day, nearly all airport food is mediocre).
As for "Security checkpoints are spread out, PreCheck is far and no Clear". There are 5 terminals and 6 security checkpoints. They are all quite close together, so I'm not sure why you think they are spread out. Especially compared to other major airports. You can easily walk from one to another. And they all sort of get you to the same basically place once you're past security. You can easily access any terminal, regardless of which entry you used.
It's true we don't have Clear, but personally I've never found it that useful. I've used it mostly in Denver (which, to be honest, I think is way less inviting than PHL!), but Clear has never gotten me through security any faster than PreCheck would have. Often times it's been slower! And I can't remember ever waiting longer than maybe 5 or 10 minutes to get through PreCheck at PHL.
There's a lot of things I hate about PHL, but I think your particular characterizations are unfair. Maybe it's been years since you've been through?
When this was DarkSky, the service was solid. I don't ever remember an outage. Ever since Apple bought them it's been extremely unreliable. I regularly get random 5xx errors from them. This is the first time I know of that they've acknowledged an outage. According to their System Status (https://developer.apple.com/system-status/) it's been down for almost 3 hours now.
Oddly, this other system status page: https://www.apple.com/support/systemstatus/ seems to think everything is OK. It's not really clear to me why they have different system status pages.
Android has a "Private Space" feature. As far as I can tell it's only a single extra profile you can create, but I think you can keep it "hidden" (at least in as much as you can't tell if it's been created without unlocking it).
I wish there were an easy way to rotate the image back. I can use the inspector in dev tools and manually change the transform style that's applied, I suppose.
reply