

Trump doesn’t appear to care much about the law.


Trump doesn’t appear to care much about the law.


I understand that this is frustrating but it is arguably the right option. If the correct owner can recover the account without TOTP then the TOTP isn’t really protecting the account.
Of course there are various ways to authenticate and it can make sense to have authentication to be (username + password + OTP) OR (email verification) but for a lot of people that email verification is a weaker link. It is more secure to only allow the former.
What I wish is that more sites would document their account recovery procedure. Often times they ask for a phone number for verification or notifications and that silently becomes a backdoor into the account. Even better would be if users can select what authentication combos are supported on a per-account basis (there are a few companies with “lockdown” settings that are a simplified version of this).
Of course it then becomes important to make it clear to the user “if you ever loose you X your account is forever lost”. It shouldn’t be surprise.
This advice feels like “Have you moved to the surface of the sun? Make sure to drink lots of water.” It’s not wrong, but also not particularly helpful. The only solution is to stop buying these things. Ideally take them back and get a refund if it isn’t too late.


Not just the first hit in general but this also sounds likely to be a bait-and-switch. They will roll with that free 1TiB as long as they can for marketing and market capture. They have a few profit streams (ads, whales on bigger plans) to help cover those marketing costs. But most likely they will not be profitable and eventually will reduce/remove the free plan and try to upgrade as many users as possible to the paid plan (reducing costs and increasing revenue in one go).


Generally speaking it will be fine. SSH will also refuse keys with open permissions so you would notice if it was wide-open to other users of the device.
But you know if you are running random code or AI harnesses as that user it can be at risk. Or if you copy around the key all over the place it is more likely to leak. But generally speaking you are secure by default, just don’t do something dumb with the key and you’ll have no problems.


It sounds pretty reasonable. As long as you keep SSH patched and keep the key safe it should be quite locked down. Do double-check that password login isn’t allowed (or that all users have a very strong password).
One non-security note is be careful with rsync backup. Generally rsync isn’t considered a backup as any mistakes made in the source will be propagated to the “backup” on next sync. Although there are ways to use rsync to take good backups (like copying to a new directory for each backup).


Why only streaming services? Why not target the volume of any ads within content that contains audio? While we are at it why not say that the add can’t be significantly more bright?
I built Chibichange to have a way to conveniently deliver changelogs to Dawarich users
Have you considered just posting a changelog to your blog? That would be much more convenient than every app I run pinging me in its own way by phoning home to its server.
Yes, on one hand every commit to nixpkgs needs review (to some degree) on the other hand there are far too many committers to nixpkgs.
There are also gaps such as the bots to auto-merge packages with maintainer approval, so a simple attack looks like this:
So nixpkgs is better than the AUR, but it isn’t great and unlike Arch has no separate official repos.
Because every three letter acronym means more than one thing. There are only 17 576 TLA so they are going to be heavily duplicated.
You should almost always spell out acronyms on the first use.
My wife’s last name was Wang. She was planning on taking her husband’s last name her whole life. Joke’s on her.
It’s not really though. They just used the screen from the pregnancy test and replaced all of the other hardware.


As much as I hate it, I’m 90% sure that they did some analysis (probably 10 years ago now) and found that there are enough people that don’t properly configure their computer that IP location is actually a better indicator than the Accept-Language header.
…which of course perpetuates the problem.


The fact is that it depends and it is a bit confusing for people not familiar. But it isn’t hard to get used to.
+8Q, Paris isn’t specific enough. There are multiple +8Q inside Paris. It can also be a bit risky to make short codes like this especially with larger cities as different maps may put the city in different spots.
What does work is +8Q Eiffel Tower which is useful for something like “Meet me here by the Eiffel Tower” or “I’m right here” when you are texting someone you are meeting and you know you are close but can’t see each other.
So you end up with a few common options:
+8Q Eiffel Tower We are pretty close together but need to get the exact spot.V75V+8Q Paris, France For exact spots around a known area.8FW4V75V+8Q For fully qualified with no reference needed.And a few less useful options:
8FW4V7+ This large part of a city.8FW4+ This part of the country.8F+ This area of the world.If I was designing the system I don’t think I would have done this “trailing zeros assumed” approach. Because IMHO for day-to-day use V75V+ Would be more useful as a shortcut for ????V75V+ rather than the actual V75V????+ showing a rough location on a human scale (in this case the Eiffel Tower park is pretty clearly targeted) rather than an area larger than a city. But that is really the only complaint I have.


While Plus Codes are less memorable they are very easy to share verbally. Especially since you only need city + a few characters to be unambiguous. They are very useful any time you need to share a specific location (GPS-style)
This is Parkinson’s Law.
If you generalize it a bit it is “consumption expands to fit available resources”.
Oof, that is really not a good look. This should have been clearly disclosed and probably with a per-notification for the patch release.
There are a few main benefits.
So I think if you are using unique passwords with an automated password manager the effective benefit is quite small. However for the “average computer user” who likely has less than 5 passwords that they use for everything it forces a pretty high base level of security.


I doubt Gaussian blur is an accurate model of real-world situations.
At the end of the day if you are worried about the codes being painted over print a few out and paint over them. Then scan with a variety of scanners.
If I had to come up with some more digital tests I would guess that a few of these are more representative of real-world situations:
Ideally combine them in a bunch of scenarios then try to scan with a variety of scanner implementations.
Original image credit: https://www.tumblr.com/robotatertot/156736308530/truth