@beamflash@hachyderm.io avatar

beamflash

@beamflash@hachyderm.io

Consumer of fine internet products. Cognitive spendthrift. Infrastructural pet coddler.

This profile is from a federated server and may be incomplete. Browse more on the original instance.

decryption, to random
@decryption@aus.social avatar

lets say i wanted to use something that isn't a smartphone for TOTP purposes - what's out there? something stand alone, probably not internet connected or reliant on a business providing updates to keep it working, and that I can have multiple copies of

beamflash,
@beamflash@hachyderm.io avatar
beamflash,
@beamflash@hachyderm.io avatar
KathyReid, to random
@KathyReid@aus.social avatar

Hey @ubuntu @ubuntusecurity when will be available for 22.04 LTS?

My university requires FIPS compliance to connect to their VPN- Palo Alto Global protect.

beamflash,
@beamflash@hachyderm.io avatar

@KathyReid @ubuntusecurity @ubuntu Why is an Australian university requiring FIPS (a US certification) in the first place? Not that I'm suggesting it's feasible, but the assertion is surely client-side so something like OpenConnect could spoof it.

Another option - run 20.04 LTS in a VM and route your traffic through it.

beamflash,
@beamflash@hachyderm.io avatar

@KathyReid @ubuntusecurity @ubuntu FIPS certification notoriously takes years so you end up running out of date software if you require it. Perhaps feed that back to the security team that they're forcing the use of older, insecure software (notwithstanding that 20.04 LTS is still under security support, there will still be security improvements that aren't backported) by requiring FIPS. Easy and thoughtless box-ticking security teams don't go hand-in-hand unfortunately

https://keypair.us/2024/02/fips-140-3-validation-times/

luis_in_brief, to random
@luis_in_brief@social.coop avatar

(scrolling the timeline, jaw drops) Welp, going to add "my vision of software freedom leads me to reject two-factor authentication on my source code repository" to examples for a future revision of my old talk on how "software freedom" is often a very selfish, libertarian, anti-liberation, anti-ally framing of software philosophy.

https://lu.is/blog/2016/03/23/free-as-in-my-libreplanet-2016-talk/

beamflash,
@beamflash@hachyderm.io avatar
beamflash,
@beamflash@hachyderm.io avatar

@luis_in_brief Sure, PGP isn't the be-all and end-all these days, but an optional centrally managed signing service doesn't seem that great either. Looking into it more, it's more the developer's fault for blindly trusting code from a CDN (which is a pretty nifty attack vector). Just trying to link it back to the "security is hard, let's not worry" attitude that you are against.

https://www.coinfabrik.com/blog/attack-on-ledger-wallets-what-happened/

simon, to random
@simon@simonwillison.net avatar

I wonder how much people's opinions of LLMs are shaped by the first application of them that they encounter

If your first ever mental model of LLMs is that they're for plagiarism and cheating on homework, I can see how that would cloud your overall opinion compared to if you start out by using them to help debug a weird error message

I'd love to see more research around how people think about and understand these things

beamflash,
@beamflash@hachyderm.io avatar

@simon @shram86 And yet most people are going to blindly use them and accept whatever output they're given

  • All
  • Subscribed
  • Moderated
  • Favorites
  • modclub
  • khanakhh
  • magazineikmin
  • thenastyranch
  • hgfsjryuu7
  • Youngstown
  • rosin
  • InstantRegret
  • slotface
  • mdbf
  • PowerRangers
  • tsrsr
  • kavyap
  • DreamBathrooms
  • Leos
  • vwfavf
  • ngwrru68w68
  • cisconetworking
  • ethstaker
  • GTA5RPClips
  • Durango
  • everett
  • osvaldo12
  • normalnudes
  • tester
  • cubers
  • tacticalgear
  • anitta
  • All magazines