• 0 Posts
  • 728 Comments
Joined 1 year ago
cake
Cake day: June 16th, 2023

help-circle





  • Basically, you have:

    • TOTP - no particular investment needed, so very popular, but a bit onerous
    • Various MFA vendors that tie into their cloud services. I hate these since it means I generally have to get additional apps, with uneven platform support
    • Webauthn/Passkey - Cool, integration with my phone, a Fido usb key, windows hello if applicable, no need for external service, uses asymmetric encryption so it’s not shared secret and it’s more convenient… Almost no one bothers to implement it for their service though, despite it being pretty damn easy.

  • Yes, shared secret based, but not a big deal because it is machine generated and unique per account. The ‘server has your credential’ is only a problem if the credential is reused across services. If you have access to read TOTP secrets from the server, you probably don’t need those TOTP secrets to further compromise the service.

    But webauthn/passkey is a better approach. Properly managed SSH keys are good too, but folks aren’t too happy about how ssh keys are commonly pretty lax. Client certificates similarly would have worked, but never took off. Similar story for smartcards.





  • Though the rooftop solar isn’t optimal from an efficacy standpoint, it has other selling points. You have residential solar and a battery? Congratulations, you don’t have to worry so much about power outages. This is particularly a selling point for rural living, where outages happen more often and last longer.

    The abstract “it’s greener” is a less potent sales pitch than “your fridge, heating, and a/c can still work even if the grid is gone”.




  • the stuff you’re asking for doesn’t work that well, but this does

    I didn’t think that this works. The examples where people claim “is just like this” I don’t see as being like this.

    The ones that work are ones that have some relation to their cause. Forcing everyone to really think about an issue Inherent to the act. For example, going about and doing this to parked private jets, which they did.

    Just doing anything to get attention isn’t useful if there’s no Inherent message in the act itself. Especially with climate where everyone already has awareness, just not action.

    Being merely loud is not going to sway hearts and minds in your favor.



  • That’s been my experience so far, that it’s largely useless for knowledge based stuff.

    In programming, you can have it take “pseducode” and have it output actionable code for more tedious languages, but you have to audit it. Ultimately I find traditional autocompletion just as useful.

    I definitely see how it helps cheat on homework, and extends “stock photography” to the point of really limiting the market for me photography or artists for bland business assets though.

    I see how people find it useful for their “professional” communications, but I hate it because people that used to be nice and to the point are staying to explode their communication into a big LLM mess.



  • So much the better, as far as those executives are concerned.

    Let’s say you want to cut costs and you know you have momentum and a long lag where your total incompetence won’t make a difference to business results in the short term, so cut costs by getting rid of the top talent.

    Now if they outright just fire every good person, well that looks obviously stupid, but if those good people just… up and quit… well they are hardly to blame, and don’t have to pay out those massive severances. You get your annual bonus which is big, and your big restricted stock payday might be delayed two years, but they know, realistically, they can probably coast a good 3 or 4 years before the game is up. Or if you have a supremely strong ‘business brand’, you might be able to coast indefinitely as the big shots will never believe that brand isn’t good anymore.