• 1 Post
  • 38 Comments
Joined 2 years ago
cake
Cake day: June 25th, 2023

help-circle


  • hot take: end users will be more likely to adopt security keys (or device attested passkey which = security key). Physical security, out-of-bounds cryptography to defeat AitM attacks (fake landing pages where six digit codes are stolen and silently used in perpetuity by the bad actor)

    source: my job is to try to get end users to put strong MFA on all the things.



  • I spend way too much time living with this obvious truth-to-come’s future impact on my children. The AI bubble will pop and bring the market down with it, and there will be a net to catch everyone just like the ones that prevent suicides at the FOXCONN factories. I truly hope my children never taste (or become) soylent green but literally everything is on the table after seeing how greedy and cowardly nearly every human is when push comes to shove over the last 5 years.

    The dehumanization frog is being boiled right in front of us, and its way less sophisticated than I ever thought it would be. project2025.observer does a great job at tracking the totality of the christofascist endgame IMO. Dehumanization being normalized will allow them to move on to political opponents heading into midterms.


  • As someone who consults in the IT Security space, It’s bad out there. Contractors and BYOD companies are downright sheepish in asking their outsourced employees to do anything security-related to their devices. The biggest attack vector is allowed unfettered remote access (and therefore the whole company and any bad actors are also granted unfettered remote access)

    I still can’t get over how quickly companies-at-large have abandoned VPN Servers (removing network trust from the list of options as well)

    I’m down to managed browsers via IdP, and I just can’t wait for the objections to that as well. People out here offering their faces to leopards. Certificate-based MFA on all the things IMO - passwords shouldnt matter (but six digit MFA codes aren’t immune to fake landing pages and siphoned MFA tokens that don’t expire)













  • tym@lemmy.worldtoTechnology@lemmy.worldPassword manager by Amazon
    link
    fedilink
    English
    arrow-up
    19
    arrow-down
    4
    ·
    4 months ago

    This isn’t the flex you think it is, OP. 99% of cybercriminals are also cowards. Physical security of ANY kind beats even the best password managers.

    If you don’t know what lattice-based encryption is and how to purchase it through NordVPN, start reading up because encryption as we know it isn’t long for this world. Pretty sure they already dragged their feet too long on Bitcoin’s algorithm but the day cracking common ciphers is within the grasp of quantum clusters is the day we all become Amish. Plan accordingly!



  • tym@lemmy.worldtoTechnology@lemmy.world*Permanently Deleted*
    link
    fedilink
    English
    arrow-up
    1
    ·
    5 months ago

    They DID put that roadblock in place. That’s kinda my point. You have to loosen a VPN’s security to post here (as I’ve had to do to reply). It says “no posting from VPN” in the lower left if one uses more advanced/secure encryption. They also don’t allow account creation from masked email platforms like fastmail.