@irenes@mastodon.social avatar

irenes

@irenes@mastodon.social

You are all dreams and we are happy to know you, as you are nice dreams. We are an asexual autistic trans-feminine plural system with a label collection.

We compromise with legibility only so far as to say the following: Technology Director at Internet Safety Labs; ex-Google information privacy expert. 🏳️‍⚧️🍁

This profile is from a federated server and may be incomplete. Browse more on the original instance.

josh, to random
@josh@josh.tel avatar

deleted_by_author

  • Loading...
  • irenes,
    @irenes@mastodon.social avatar

    @josh corporations would always prefer not to have to get involved in large-scale societal issues, even when those issues aren't politicized, for the very simple reason that it's cheaper not to

    irenes, to random
    @irenes@mastodon.social avatar

    sigh so does anyone, like, recognize this extremely sus github org? it has some Go libraries...

    https://github.com/lib

    is this a real part of the Go ecosystem or is it typo-squatting? we're trying to fix some ancient code...

    JenYetAgain, to random
    @JenYetAgain@tooters.org avatar

    Guess what I'm reading?

    irenes,
    @irenes@mastodon.social avatar

    @JenYetAgain we hear he toots as he pleases, too

    mcc, to random
    @mcc@mastodon.social avatar

    So I'm going through a hell upgrade of mysql https://mastodon.social/@mcc/112294139220776280 and the only reason this is a problem is because one of the Wordpress tables got mangled during an upgrade. In fact, the only reason I am running Mysql is to support Wordpress. I don't really want to be running Mysql. Or Wordpress. But I set up this website in 2006, and now I'm stuck maintaining Wordpress, and the Mysql it depends on, and the Ubuntu THAT depends on, for like… the rest of my life. Every new LTS, a jolt of pain

    irenes,
    @irenes@mastodon.social avatar

    @mcc @nfagerlund this is where we usually get into our whole thing about literate programming and how it's a good idea and should be used more, but it's not a complete solution to the larger problem

    irenes,
    @irenes@mastodon.social avatar

    @mcc @nfagerlund if humanity is going to change this dynamic where somebody needs to understand the complexity and that ends up being the limit on our collective abilities, we need to attain a standard of code quality where everyone can forget about it for fifty years, and yet someone can re-learn easily when a changing situation requires it to be changed

    irenes,
    @irenes@mastodon.social avatar

    @nfagerlund @mcc well one criterion is that you need to never, ever lose track of documentation or version control metadata...

    irenes,
    @irenes@mastodon.social avatar

    @nfagerlund @mcc but also.... the connections to lower and higher layers need to be clear, it needs to be possible to re-discover that there even IS a layer there

    mcc, to random
    @mcc@mastodon.social avatar

    There's like an entire class of open source project where you can no longer get support for them because they're old enough that the support channels are IRC rather than Discord or something but nobody's on IRC anymore (or rather hundreds of people are on the libera.chat channel, but no one is talking or reading questions)

    irenes,
    @irenes@mastodon.social avatar

    @mcc oh. well that's upsetting.

    gwynnion, to random
    @gwynnion@mastodon.social avatar

    It's mildly interesting how 80s dystopian sci-fi understood that authoritarians could keep most people under control as long as they maintained a superficial veneer of normal modern life with TV news, gameshows, politics, elections, etc., even if it was all fake propaganda.

    irenes,
    @irenes@mastodon.social avatar

    @gwynnion sigh it was predicting the past, after all. the tech changes every decade but it's happened before, elsewhere. "the future's already here, it's just not evenly distributed."

    irenes,
    @irenes@mastodon.social avatar

    @gwynnion we're always impressed by people who are able to see these things clearly, "beforehand"

    paulrickards, to genart
    @paulrickards@mastodon.social avatar
    irenes,
    @irenes@mastodon.social avatar

    @paulrickards oh very cool. we don't think we've seen generative plotter art that plays with the CMYK primaries like that before

    irenes,
    @irenes@mastodon.social avatar

    @paulrickards oh how gorgeous! yes, we'll take a look :)

    mcc, to random
    @mcc@mastodon.social avatar

    I have literally implemented SRP at both the client and server side but I am still unable to figure out, if I were to purchase or set up a "Passkey", what exactly I would have, or how it would work, or which computers, web browsers or web sites I should expect it to work with

    irenes,
    @irenes@mastodon.social avatar

    @mcc yes, that is our understanding as well

    irenes,
    @irenes@mastodon.social avatar

    @glyph @mcc (as historical context in case it helps with deciphering the politics, Google is on the "include physical tokens" side of that divide; Microsoft and Apple are on the cloud side)

    irenes,
    @irenes@mastodon.social avatar

    @mcc @glyph yes, we believe the conflict of interest and potential ecosystem-lock-in that you're hinting at is exactly what's going on

    irenes,
    @irenes@mastodon.social avatar

    @mcc @glyph essentially it's a bit of standards judo where the hardware token people built the public awareness and momentum for change, and now in committee the cloud people and OS vendors are redirecting that momentum to their own benefit

    irenes,
    @irenes@mastodon.social avatar

    @glyph @mcc yeah it's

    good faith, yes, everyone believes in what they're doing

    the thing is, our Google experience taught us that even people who want what's best for humanity and practice being self-critical can be substantially influenced by the biases that come with being embedded in a corporate structure. management dictates and profit incentives start to feel like laws of nature, rather than things that people invented...

    irenes,
    @irenes@mastodon.social avatar

    @glyph @mcc we were personally influenced in that way. we wouldn't trust ourselves if we were still in a corporate environment, so we definitely don't trust anyone else :)

    irenes,
    @irenes@mastodon.social avatar

    @glyph @mcc or rather, we trust the intentions and expertise of all the individual contributors on this stuff. the ones we know are good people

    we don't necessarily trust their judgement, not on the larger implications of these decisions

    irenes,
    @irenes@mastodon.social avatar

    @glyph @filippo @mcc yes. fail-closed is pretty harsh, and there are good reasons most people don't do it. there are also good reasons some of us do do it.

    irenes,
    @irenes@mastodon.social avatar

    @mcc no, yeah, we don't think there is either, or else we'd be doing it. besides, the fundamental choices you and we both take issue with aren't the ones made by ICs, they're probably made by SVPs.

    irenes,
    @irenes@mastodon.social avatar

    @glyph @mcc @filippo @djc sigh we have exactly one (it's for accessing a friend's infrastructure). not really our preferred configuration, U2F was better.

    we've been avoiding adding more because we don't want to fill up our smartcards' storage, but the browser tooling is there to do so at this point and the big sites appear to do it by default for new hardware tokens.

    irenes,
    @irenes@mastodon.social avatar

    @filippo @mcc @glyph @djc the existing implementations quite literally do use passkeys rather than U2F when both are available. SOMEbody thinks they are replacements.

    irenes,
    @irenes@mastodon.social avatar

    @filippo @mcc @glyph @djc sigh, sorry, you're new to the discussion (and thanks for answering!) so we should re-state the context in which we mean that

    specifically when adding a new credential, if FIDO2 mode is available it gets used instead of U2F with no opportunity for intervention

    jonny, to random
    @jonny@neuromatch.social avatar

    Do any infosec people ever feel like they have their shit "secure," like I understand this system well enough that for all practical purposes this shit wont be pwned, or is the whole thing that you can only bracket off security as like "if these conditions are true, I wont be pwned in these ways"

    irenes,
    @irenes@mastodon.social avatar

    @jonny one thing we will advise is for irreplaceable stuff like that, don't design a system that's going to fail closed in common situations. we came very close to total device loss in a house fire some years ago... make sure you have some sort of off-site backup, even if it's a flash drive left with a family member. (use a drive meant to be removable, not one that might lose its contents if it goes without power for too long.)

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • thenastyranch
  • magazineikmin
  • osvaldo12
  • GTA5RPClips
  • mdbf
  • Youngstown
  • tacticalgear
  • slotface
  • rosin
  • kavyap
  • ethstaker
  • everett
  • khanakhh
  • JUstTest
  • DreamBathrooms
  • InstantRegret
  • cubers
  • normalnudes
  • Leos
  • ngwrru68w68
  • cisconetworking
  • modclub
  • Durango
  • provamag3
  • anitta
  • tester
  • lostlight
  • All magazines