• 0 Posts
  • 13 Comments
Joined 1 year ago
cake
Cake day: February 13th, 2024

help-circle


  • I do agree that password managers are generally more secure than memorable passwords, however, they also pose he Achilles heel of a system, as one password unlocks all. That is why 2FA tops everything, as even with a weak password, as a hacker would need to crack an OTP to gain access, or convince the one holding the 2nd device to unlock the account for them.

    However I do want to contest the claim that all user-friendly passwords are inherently unsafe. The Electronic Frontier Foundation did a Deep Dive on randomly generated passphrases and shows how secure the system is by entropy alone.


  • Blemgo@lemmy.worldtoTechnology@lemmy.worldX launches E2E encrypted Chat
    link
    fedilink
    English
    arrow-up
    15
    arrow-down
    1
    ·
    17 days ago

    I’m not the one who you asked, but I’d still give some feedback of my own. Musk as a person is a difficult character. I would even go as far as calling him narcissistic.

    • He got thrown out of PayPal for his incessant micromanagement and disruptions to the flow of the company
    • he bought himself into Tesla to replace the CEO with himself
    • he tends to depict himself as one of the greatest tech geniuses out there, yet often the plans he presents to the public are often poorly thought out and serve no other purpose than to show his “talents”
    • when his proposal to build a tiny submarine for the Than Luang cave rescue was shot down and a British diver was chosen instead he resorted to call the diver a “pedo guy”
    • his latest attempts in politics, especially concerning DOGE feel completely half baked and, again, how he presents himself in his position feels more like an ego trip than something more reasonable
    • he publicly had talks with the controversial German political party “Alternative für Deutschland”, which are currently legally considered “assured right-wing extremists” and have had a history of having Nazis and Nazi sympathisers in their ranks

    I generally can’t trust someone who seems to put himself first at everything to handle anything related to security when the role allows him to exploit it for his own gains. And I do not trust someone who supports political groups known for trying to oppress minorities to defend actual rights for free speech.


  • Blemgo@lemmy.worldtoTechnology@lemmy.worldX launches E2E encrypted Chat
    link
    fedilink
    English
    arrow-up
    16
    arrow-down
    1
    ·
    17 days ago

    The question is whether this actually is E2EE, as it’s easy to fake by using a man in the middle attack and hard to prove. The only real way to prove it for sure is to run a third party security audit, like Signal does.

    Taking down the old system doesn’t inspire confidence either, as this downtime could easily been used to interrupt old conversations in order to implement a way to decrypt the messages on the servers before passing it on to the actual recipient, as all keys would have to be re-issued.





  • Is there a benefit from this over the inbuilt Secure Erase functionality in most SSDs/NVMEs? To my knowledge, it instantly dumps the current from all cells, emptying the data on it.

    Furthermore, another issue with SSDs/NVMEs is that it automatically excludes bad blocks, meaning that classic read/write operations can’t even reach those blocks anyways. Theoretically that feature could also be used against you to preserve the data on the disk by marking all blocks as bad, rendering them as inaccessible by the file system.

    Of course there’s also the issue of Secure Erase not being implemented properly in some drives, leading to the bad blocks not being touched by the hardware chip during that procedure.


  • It’s pleasantly surprising to see it getting mentioned it at all. Loved the servers when they were Omegle chatoorms, and it’s a bit sad to see it sort of die out with the death of Omegle. But yeah, the people there are generally nice.

    Also, since I mentioned Omegle: I do not recommend any Omegle clones, as they often have an account system in place, which sort of ruins the whole anonymity stuff and also leaves to some stigma to those who do not want to use the account system. Not to mention that these sites generally attracts horny creeps, and finding a good chat partner is thusly hard.