blake,

After seeing how the XZ maintainer's burnout and mental health decline was exploited to the potential detriment of the whole world, we're totally going to be supporting our developers more, right guys? We're totally going to fund critical OSS and pay maintainers enough to hire on other maintainers to take the burden off of them and reduce burnout, right? Right?

blake,

Something that makes this so difficult is that there are so many of these (critical infrastructure projects) just littered everywhere. This kind of thing could happen anywhere, and probably has happened undetected elsewhere for years! Finding all of these would be a day job of its own. Then you have to figure out where all that money is coming from, and what's important enough to get how much money.

Most of this is too complex for me to understand.

apgarcia,
@apgarcia@fosstodon.org avatar

@blake Yes, if I had Jeff Bezos or Elon Musk kind of money, I would totally make that happen.

whitequark,
@whitequark@mastodon.social avatar

@blake more enforced 2FA will surely fix it

stefanie,

@whitequark @blake Still furious that they forced me to abandon my account and now I can't contribute to anything anymore.

Other than somehow sending diffs directly to people.

whitequark,
@whitequark@mastodon.social avatar

@stefanie @blake that sounds like you're choosing not to, to me?

stefanie,

@whitequark @blake I'm choosing not to use 2FA, because I want to know that my password is right when I enter it. I do NOT want a random number that is different every time where I myself have no way of knowing if it is the right one.
Also I am very prone to loosing or breaking stuff. And I don't want my accounts to be just one broken device away from loosing them.
So MS, by enforcing 2FA for no good reason, they forced me to abandon my account.

whitequark,
@whitequark@mastodon.social avatar

@stefanie @blake I'm the same and I chose to put the OTP thing in my KeepassX right next to the password; hope that helps

before that I just stored the TOTP secret as a note and used a CLI tool totp to generate a code

no possibility to lose a device! well, not any more than you have already

whitequark,
@whitequark@mastodon.social avatar

@stefanie @blake btw, don't listen to infosec people telling you that's bad; it protects you from phishing all the same as using an external device

stefanie,

@whitequark @blake I just use strong random passwords. Not a single one of my accounts have been compromised in my life, and I have been on the internet for 30 years now.
I don't need this, and I don't want it. And I don't even believe it. What I believe is, those numbers actually do nothing. The whole thing is just a means to ban accounts without any recourse. They just ban you with the 2FA messasge and you have no way of proving or even knowing that you are entering the right number.

whitequark,
@whitequark@mastodon.social avatar

@stefanie @blake ok, so this is veering into conspiracy theory zone

github can already ban you without any recourse, it's in the ToS and always has been

stefanie,

@whitequark @blake It isn't that I actually strongly believe it.
But how would I know?
The thing is, I can't even know if the password would be right.
And where does it end?

I have online banking disabled on my bank account, I don't store important stuff on online services. My risk is minimal, and I am not a target.

I do not need this security, and i don't want it. Neither do I want a vault door with retina scanner at my house.

Especially since ALL data breaches in a decade were server side

whitequark,
@whitequark@mastodon.social avatar

@stefanie @blake someone I think highly of got phished recently and I talked to her about it

it wasn't that she isn't smart, or competent, or attentive to detail. she was simply sick with some kind of illness, sleep-deprived, and dealing with an unfamiliar situation

(in that particular case her bank didn't ask for an OTP but their anti-fraud caught it anyway)

whitequark,
@whitequark@mastodon.social avatar

@stefanie @blake anyway, no one is forcing you to abandon anything here, you're making an easily avoidable choice and rhetorically presenting it as being forced or compelled to make it

cool story, i don't buy it tho

stefanie,

@whitequark @blake See? That is why my bank doesn't even know my email address.
Whatever is online can never be my bank.
And "easily avoidable" is a stretch. Yeah, go buy a device that you have to keep around at all times. Or install an app on your phone for it, because we know that phones are totally secure and can't be compromised.

I think you have lulled yourself into a false sense of security with those gadgets, and are now justifying it by handwaving away all the problems with it.

whitequark,
@whitequark@mastodon.social avatar

@stefanie @blake you don't need a device or a phone app, as I just told you

whitequark,
@whitequark@mastodon.social avatar

@stefanie @blake save the totp secret anywhere you like. a text file in your ~ for example
apt-get install oathtool
use oathtool to generate OTP codes

annoying? mildly. trivially easy? yep

oblomov,
@oblomov@sociale.network avatar
SenseException,
@SenseException@phpc.social avatar

@blake If there's something that I learned from community, then it's that maintainers can be replaced with the words "So long and thanks for all the fish". Not literally those words, but just to tell them they aren't needed anymore.

xahteiwi,
@xahteiwi@mastodon.social avatar

@blake Right, just like we learned from a global pandemic that gutting public health was a mistake and doctors, nurses and therapists are now in solid, balanced, sustainable work environments.

We're a massively fucked-up society.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • khanakhh
  • DreamBathrooms
  • InstantRegret
  • magazineikmin
  • osvaldo12
  • mdbf
  • Youngstown
  • cisconetworking
  • slotface
  • rosin
  • thenastyranch
  • ngwrru68w68
  • kavyap
  • ethstaker
  • JUstTest
  • tacticalgear
  • modclub
  • cubers
  • Leos
  • everett
  • GTA5RPClips
  • Durango
  • anitta
  • normalnudes
  • provamag3
  • tester
  • megavids
  • lostlight
  • All magazines