• 1 Post
  • 21 Comments
Joined 2 年前
cake
Cake day: 2023年6月10日

help-circle


  • The spec has issues due to usual RFC bullshit and corporate greed, but as per usual the viewpoint here is too narrow. I’m running my own open source authentication stack and choose what attestations are acceptable, say only allow the FIPS version of Yubikeys. That feature exists because companies want to be able to control which methods they consider secure enough for their own employees. This tech was built for corporate security, using it externally facing with end-users is a bolted on after the fact idea. Having control is necessary, it does not make the spec evil.

    Now say GitHub enable attestations that only allow Windows Hello passkeys to go through, then yes that’s technically possible. It would also be a support nightmare so they won’t. (It’s already a support nightmare for anyone limiting devices since for example security key vendors regularly forget to publish their fingerprints for new products.)

    The whole biometrics thing? Total red herring. UV can be enabled in many different ways and totally “faked” as well, which is what all the software implementations do such as Bitwarden. Only way to stop it is approvelisting specific devices, see point above.


  • Jinna@lemmy.blahaj.zonetoAutismSo often...
    link
    fedilink
    English
    arrow-up
    12
    ·
    2 个月前

    There’s also the ADHD DLC variant of: I put it down wherever I suddenly completely context swapped to something that needed my hands free and have no idea what I was previously doing, what I had in my hands and where it might now be.


  • I feel like you’re missing the point a bit. Living by values you hold dear is not losing, winning or even necessarily a cause. If your values happen to align with a cause, then supporting it in a way you can is at least somewhat fulfilling.

    Now, there are definitely people who join a cause for tangential reasons. For example because they are a vehicle to what they want, such as someone who wants to build and use explosives can just as easily become a fundamentalist, anarchist or fascist. (And history has examples of these sordid folks.) They barely care about any of the causes and will drift wherever they can live by their own values, even if it’s about blowing shit up.



  • Atuin (by @[email protected]) makes the history storage and management side much easier and portable, but could perhaps use a “smite mode” to make deletion interactively easier. The current interactive implementation prioritizes safety over expediency which is fine, but a “today I clean things” option could perhaps instead prioritize the other way around and enable one key delete w/ undo instead.







  • Picked up a “Electrolux Pure D8.2 Silence PD82-Animal” model last year and it’s been pretty awesome. If you check the tech specs the noise level is really low (and actually delivers on the promise) but still has a much higher suction force than anything I’ve had before. The rotating hair removal accessory is crap though (not powered so just not comparable to a model that is), so no need for the animal version if price for other versions is better. Seems to still be on the market but stock limited as everything these days.




  • Paraphrasing from a recent episode of Behind the Bastards on the Vioxx scandal: There’s a lot of recency bias in humans where it’s difficult to look past the fuckups of the pharma industry. If their “current” MO is to make a shit ton of money at the cost of human lives, then why would someone with lesser critical thinking skills trust them? One needs quite a bit more faculties to separate the capitalism from the good they are doing and tell apart what’s trustworthy and what not.

    So pharma fucked their bed spectacularly and aren’t doing fuck all to restore trust. And that’s very sad considering how important they could be if they wanted to.