|
Shitfest the Clown posted:goldmine
|
![]() |
|
![]()
|
# ¿ Apr 2, 2023 05:45 |
|
Subjunctive posted:work places where recruiting has been told that certifications aren’t necessary, instead
|
![]() |
|
fisting by many posted:in a general sense convenience is security, if the alternative is users choosing not to do it at all. i found this post searching for authy alternatives because i have 44 totp generators in my life right now and it's making me hate the internet even more than ever
|
![]() |
|
it does, but it only backs up to their servers i'd rather have a backup of my own (in fact i already do, in a keep rear end xc file, but that took running a random go program i compiled from a random github repo and i'd rather not do that again)
|
![]() |
|
Shaggar posted:microsoft authenticator is the best general purpose authenticator app. it would be nice if they made their push auth a service available to other identity providers cause its so much better than everything else. coincidentally tried it earlier tonight and it doesn’t let you search by name so that’s an automatic fail for me. oh well. I’ll probably stick with authy or google authenticator because searching is absolutely vital for me
|
![]() |
|
see, this is why you keep a gun by the printer ![]()
|
![]() |
|
klosterdev posted:They Gottm
|
![]() |
|
lollllll
|
![]() |
|
the right way to do a poll for this stuff is to give the internet two or maybe three choices and then let them vote only on these choices capitalism is already quite familiar with this strategy when it comes to democratic elections so idk why they keep loving it up with naming products or whatever
|
![]() |
|
lmao surprised it wasn't wrapped in a try catch block that also returned login ok
|
![]() |
|
https://arstechnica.com/gadgets/2021/07/for-years-a-backdoor-in-popular-kiwisdr-product-gave-root-to-project-developer/quote:KiwiSDR is hardware that uses a software-defined radio to monitor transmissions in a local area and stream them over the Internet. A largely hobbyist base of users does all kinds of cool things with the playing-card-sized devices. For instance, a user in Manhattan could connect one to the Internet so that people in Madrid, Spain, or Sydney, Australia, could listen to AM radio broadcasts, CB radio conversations, or even watch lightning storms in Manhattan. ![]() ![]() https://twitter.com/vk5qi/status/1415440183982391298?s=20
|
![]() |
|
MononcQc posted:just playing SIM ant ![]()
|
![]() |
|
too bad, looks like most of these ones have been fixed. but still lmfao
|
![]() |
|
tk posted:Ad intermediaries being taken over/hacked was a big problem back when I was working on anti-malware like 10 years ago. I’m surprised this doesn’t happen more often. i got malware from the nyt this way once. then i installed an ad-blocker and haven't turned it off since and never will. the well is POISONED and if your job depends on ads, well, sorry. if microtransactions ever actually take off i'll happily pay a quarter for every article i read but i'm not subscribing to your goddamn website either.
|
![]() |
|
bad as they are yt ads aren’t even close to the worst offenders
|
![]() |
|
lol but also lol @ using a vpn for anything more than hiding your IP from hbo
|
![]() |
|
ewiley posted:Wait i had it on good authority from mister taviso that browsers are the best way to store passwords once you're running exploited code locally i don't think anything is all that secure for password storage, the second you unlock your vault if it's being targeted it's game over
|
![]() |
|
CRIP EATIN BREAD posted:operating systems have the concept of secure memory and any decrypted passwords should be stored there and not to disk "should" is doing a lot of heavy lifting there. a few years ago i remember reading that all the major pwm vendors did a poo poo job at it, hopefully they've improved. i use a pwm (bitwarden these days) but i still assume if i get tricked into running a compromised executable i'm hosed
|
![]() |
|
https://twitter.com/matthew_d_green/status/1423071186616000513 can't wait to get swatted because a picture of my dog has a hash collision with a bomb schematic or something
|
![]() |
|
cinci zoo sniper posted:on actual thread topics, what is bitwarden’s client coded in electron afaik takes around 120mb on my machine, but i pretty much never run the client anyway vOv
|
![]() |
|
cinci zoo sniper posted:possibly stupid question. am i wrong thinking that using the same app for pw management and totp generation means reducing your 2fa to 1fa? i guess it’s a question of threat model, with physical access like that they could just hit me a few times with a 2x4 and my specific choice of apps would cease to matter at all only if your pwm is breached. it’s still better than only a password, which could be captured/leaked/brute forced some other way.
|
![]() |
|
i keep mine separate too (bitwarden + ms authenticator) but i've considered moving some totp into bitwarden because i have way too loving many. For now i pushed the frequent/important ones to the top of ms authenticator.
|
![]() |
|
MononcQc posted:I use 1Password and Authy, but I kept forgetting my Authy backup password so I put it in 1Password and that sort of defeats the purpose. if you turn off multi-device authy should be safe anyway, even if you get simjacked (or so i've been told)
|
![]() |
|
this keeps happening and the stance of banks in canada seems to be that chip and pin is "uncrackable" so if fraud happens it must be because you shared your card and pin: https://www.cbc.ca/news/business/pin-fraud-customer-liable-rbc-surveillance-1.5444554 https://www.thestar.com/business/personal_finance/spending_saving/2011/06/18/roseman_man_sues_cibc_for_81276_visa_charge.html
|
![]() |
|
this is why i won't use services like mint either, btw. canadian banks will absolutely tell you to pound sand if you share your pin or credentials
|
![]() |
|
one of my bank accounts only lets me use a 6 digit numeric pin to sign in online ityool 2021 (tangerine.ca for the curious)
|
![]() |
|
ate poo poo on live tv posted:As long as I'm not liable cash-wise for the banks fuckup for verifying identity, I dont' give a gently caress about chip+pin or not. the problem (for me, as a canadian) is there are several cases where that wasn't how it played out at all for people. this is what prompted the discussion in the first place. the only way i can mitigate is i have my phone set to alert me for every single debit and visa transaction made with my accounts/cards so i can call them immediately if fraudulent activity happens.
|
![]() |
|
DoomTrainPhD posted:It's a shame email addresses aren't case sensitive. It would be a train wreck in fast-motion we are all forced to watch every day forever. nah i'm good, i already get a shitload of emails from being one letter off from someone else as it is
|
![]() |
|
i spent a week in maine once. i only saw one black person the entire time i was there and it was the day i went to portland. i saw a few asians but much like my partner they were all tourists.
|
![]() |
|
huh, Stack Overflow had an xss issue for 44 minutes. https://meta.stackoverflow.com/questions/411177/adding-html-tags-or-html-tag-like-to-a-title-breaks-rendering
|
![]() |
|
Fart Sandwiches posted:just chased down a bug where someone editing a csv in Excel caused all the quotation characters to change and broke the processing script. it also changed the date format argh gently caress you Excel now my whipped together script needs to be actually developed on not a suggestion but this is why i have changed code in places to just load from excel files instead ![]() at least the file format is stable enough that decent libraries are available to do this now
|
![]() |
|
abigserve posted:yeah, not sure where else to put this, I just bought a brand new ipad from apple.com, opened the photos app and uh when i was 17 i worked as a line cook. although i wasn't there for this, the owner forgot to order hashbrowns from the supplier one day and they were running out. so he told the busser + cook to salvage any uneaten hashbrowns that were sent back, reheat them, and send them out again. the cook quit on the spot and i quit when i found out too, and told anyone that would listen to never eat there again. so anyway i'm sure every company is now selling returns as new instead of refurbs like they used to and this may or may not be the case here.
|
![]() |
|
mystes posted:You should have just taken the story to Bloomberg. lol ya
|
![]() |
|
infernal machines posted:phishing is easier with outlook. on the subject of the pages long language chat, outlook client falls prey to homoglyph domains and shows the information for contacts from the spoofed domain instead. lol
|
![]() |
|
Shaggar posted:imo a better solution would just be to reject email from any domain shaggar.... was right
|
![]() |
|
haveblue posted:hacker please
|
![]() |
|
Ulf posted:a little sneak peek at the QUIC page that I'm writing up. kick rear end
|
![]() |
|
Shame Boy posted:this just made me realize, there's absolutely going to be people killed (if there haven't been already) when someone murdery uses one of those "where is this IP address located" lookup services and assumes its at all accurate *fires a shitload of missiles into the middle of a lake*
|
![]() |
|
not anymore, they relocated it after that kansas couple kept having scam victims and vigilantes show up on their door
|
![]() |
|
![]()
|
# ¿ Apr 2, 2023 05:45 |
|
Chris Knight posted:good news everyone! it's finally happening? neat
|
![]() |