spicy security take, 2FA
The common understanding of "two-factor authentication" (something you know and something you have) is terrible, because it relies on classification that is really hard to do. Do you *have* a 2FA app or do you *know the key* to a 2FA app?
A much better model is "a factor is a separate environment that would need to be compromised independently", because it can be reasoned about and directly reflects the actual thing that needs to happen to bypass it.
This means that a 2FA app on a phone and a password manager on a PC are two factors; two devices that need to be separately compromised. A 2FA utility *in* the password manager is *not* two factors, because compromising the computer is enough to bypass both. Biometric+password *is* two factors, because compromising the computer does not get you biometric data, unless it's actively stored on there.
And yes, this is something that non-security-specialized folks can understand too, if you use slightly different wording ("hack two different devices instead of one" for example).
(They also said something to the effect of "we welcome the presence of new providers, as long as they have a sound business plan", which suggests that they are very well aware of what shit this company was trying to pull)
The time when VRN was really pissed at DB Vertrieb and it *showed* in the press release...
https://www.vrn.de/verbund/presse/pressemeldungen/pm/022653/index.html
> Leider müssen wir aktuell feststellen, dass die Deutsche Bahn sich nicht an die im VRN beschlossenen kundenfreundlichen Regelungen gebunden fühlt.
> DB Vertrieb [...] möchte gezielt die Kunden auf das Medium Smartphone zwingen.
> Der VRN bedauert dieses Vorgehen des DB-Konzerns und möchte sich bei allen VRN-Kunden, die ihre Abos bei der DB abgeschlossen haben, für die damit verbundenen Probleme entschuldigen.
> Wie auch in anderen Bereichen des täglichen Lebens gibt es auch im ÖPNV offenbar gute Gründe, nicht bei überregional agierenden Großkonzernen zu kaufen, sondern bei Anbietern vor Ort.
will ferrell was not the apparent trans ally I was expecting in 2024 https://youtu.be/PRZ1ELeGepo?si=GZK7zC4-l8ozRKib
Friend shared a chonky landing page for a Major Cloud Vendor's offerings...and y'all, I don't think anyone has internalised how high on their own supply the contemporary JS community is.
It takes some cirrostratus levels of disconnectedness to believe your `chatbot.js` is fine when it clocks in at ~750K (wire, 3MB unzipped) INCLUDING ITS OWN COPY OF REACT, lodash, every polyfill you've ever heard of, and 269 embedded `data:image/...` URLs.
Hoe herkennen we ecofascisme? Vaak wordt beweerd dat de klimaat- en ecologische crisis door overbevolking komt, maar dit klopt niet. Volgens Oxfam is de rijkste 10% van de bevolking verantwoordelijk voor meer dan de helft van de wereldwijde broeikasgasuitstoot. [3/5]
#sysadmin pro tip!
If you generate a lot of fresh Let's Encrypt certificates today, and don't enable auto-renewal, they will expire on December 25th, giving you a good excuse to leave your family dinner early.
It's now too late for Marcellus Williams, but it's not too late for Robert Roberson. On Oct 17, Texas will execute him for a crime he absolutely did not commit. Make it a big deal. https://youtu.be/ifpEfj1_hzQ
Technical debt collector and general hype-hater. Early 30s, non-binary, ND, poly, relationship anarchist, generally queer.
- No alt text (request) = no boost.
- Boosts OK for all boostable posts.
- DMs are open.
- Flirting welcome, but be explicit if you want something out of it!
- The devil doesn't need an advocate; no combative arguing in my mentions.
Sometimes horny on main (behind CW), very much into kink (bondage, freeuse, CNC, and other stuff), and believe it or not, very much a submissive bottom :p
My spoons are limited, so I may not always have the energy to respond to messages.
Strong views about abolishing oppression, hierarchy, agency, and self-governance - but I also trust people by default and give them room to grow, unless they give me reason not to. That all also applies to technology and how it's built.