Avatar

ClemaX

ClemaX@lemm.ee
Joined
0 posts • 62 comments

Software developer interested into security and sustainability.

Direct message

I do not have a lot of experience with commerce but you’re supposed to optimize the customer experience. If the customer needs an account to add something to the cart, he might abandon his purchase during the account creation process.

Only some percentage of all potential users will abandon the purchase due to something like this, but your goal is to reduce this percentage as much as possible.

That’s why analytics are used to understand which environment leads to the most purchases and prevent users from abandoning the process.

permalink
report
reply

Then it may be a token stealer.

permalink
report
parent
reply

If your account is linked to your Google, Apple or Facebook account that might be the culprit (I think you can see this in yout account settings). You need to check that because the consequences could be way worse than just having access to your Spotify account. You can use HaveIBeenPwned to look for leaks matching your e-mail address or password.

Another possibility is that your browser/OS or spotify client was infected by a token stealer which can automatically steal your access tokens as you log-in after changing the password.

permalink
report
parent
reply

Due to Secure Boot (if it actually enabled since there are some bogous implementations) this can be prevented. If I understand it correctly, LogoFAIL bypasses this security measure and enables loading unsigned code.

permalink
report
parent
reply

Could you specify what is wrong about Libretube? There is a background playback option and even an audio mode with no video.

permalink
report
reply

Maybe Firefox needs to add a new “Clipboard access” permission that can be granted on a site-per-site basis. When disabled, simple highlight and copy could still be enabled if hidden text cannot be added in between normal text.

The same permission model could be used system wide, but I do not think that such a feature exists on the X server or Wayland. Maybe using a wrapper that runs before the Desktop Environment?

permalink
report
reply

It was already like this in Europe when I began to use Spotify in 2015. I do not hate it because the app’s free tier is already unusable to me due to the adverts.

permalink
report
reply

Isn’t Ventoy used to boot images like ISOs?

permalink
report
parent
reply

I think the shim bootloader as well as the booted software must perform some verifications too.

permalink
report
parent
reply