Not an idiot :) You make a good point that people don't have their phones on them & alive all the time which is where totp can come in with dongle totp's (like http://www.securemetric.com/secureotp-time.php) agreed it costs you a fair amount but if you want secure when you don't have your phone... it's worth it. And then maybe like google have a few longer random passwords that are to use when you don't have your phone or a TOTP/OTP generator.
HN user
djjaxe
Not everyone has smart phones.
Not everyone that has smart phones keep it on them all the time.
Not everyone that has smart phones that keep it on them all the time have a working (charged) phone all of that time.
What do smart phones have to do with sms?
YubiKeys still can cost you up to $50, where as TOTP using something like google authenticator(doesn't have to be google auth) costs you? Nothing?
This sounds less convenient, harder to implement, and no more secure than OpenID
In what way is it less convenient? A standard user has their phone with them...24/7? At least in the sms realm it's more convenient than trying to come up with a password that has: A capitol letter, a number, a special character, a lower case letter. Also way more secure, a user gets sent a message of a one time code looking like 037.820.374.839 the time it would take to guess that, the one time code would have been timed out and the hacker would have been no closer to getting in compaired to a static password.
On both OSX and many Linux distros, Py 2 comes pre-installed but Py 3 does not.
Because python 3 was not the most stable at the time of distribution of that operating system. Why would I the developer of said operating system release anything but the most stable versions of the language? This would in turn make my operating system at times less stable.
Because Apple usually just goes along for the ride...?
If you clicked on the 86446f74
You would have gotten: https://github.com/expressjs/body-parser/commit/86446f74d5c6...
Which shows parents 0
Basically the cut down to everything is the laziness of how it is developed and how many people are actually looking over the entire code. ATS allows the developers to know that the can be even more lackadaisical about coding as ATS will remove bugs for them...
Wow sorry I can't laugh at something jeez. So, you have never in your life just felt like re-posting a quote off something and just added a little something to it to show the spirit in which it was meant to be. Now you are just being nitpicky and to be honest rude in a sense. I have just joined this community I am trying to fit in and you just come along and see the comment and you "don't like it" because it's short, sweet and too the point. I am laughing at the comment of the programmer of rust for the quote he put on his site and now you have just totally bashed me because you felt it necessary to not like my simplistic comment. Wow.
So rust & ATS & ADA & higher level languages can modify memory space? That I am aware of most higher level languages stray from being able to modify memory space on purpose as it's dangerous but, someone has to do it for the operating system is all I am saying about low level now that we are completely off topic here.
Just because this alternative language would have avoided this bug does not mean a much worse but would not have been created with a higher level language or even ATS.
Ada is a higher language weather or not it has linkage to C or not. The UNIX community cares about performance, performance, performance.
Maybe because most of the code currently out there being use by the biggest companies in the world still use these "unsafe" languages. & tons of the job market still is in these "unsafe" languages.
That's still not my point. At the time of starting openssl I don't believe that ATS was around. In any case my point is that back then C lang was the best choice for performance and still is revered as the "fastest" as `nearly` all other languages are written on top of it either directly or indirectly. In any case I would love to see someone tell all of the openssl community to just drop C and switch to a different language.
LOL "* In theory. Rust is a work-in-progress and may do anything it likes up to and including eating your laundry."
I read the article is does not mention speed, performance once, in which it had nothing to do with what I stated. I was simply stating that higher level languages will cause the library to be slower also less easy to be used by other high level languages like python.
Speed or security?... Age old question.
paypal accepts transactions without accounts just cards...
well this could be fixed by using something like bittorrent sync to allow you to keep your "inbox" wherever you want all you need is the code... and storage space... and well at least 1 of your own computers that already has the inbox to be online at the same time. this also uses a separate dht table to sync and as long as your inbox is only in the megabyte it wouldn't be that hard to read your email from your friends computer or any other computer... but i do agree I would want to limit the ability to spam the network as this would load down a lot of the peers with excess mail that they actually wouldn't need... maybe somehow limit how many messages each node can send out... as this system would be like torrents but you would need a private key to open... you could send mail to multiple people they download the one message and decrypt it you wouldn't really need multiple message sent so if a node is sending many the rest of the network could identify that and ignore that node...
And good point I forget that the web is basically insecure from government intrusion :[
Then I think it's time to look at a mail system that doesn't need servers something built on top of the bit torrent grid or similar system that the government can watch all they want but won't get any information back from it and have it completely open source... this will take out man-in-the-middle and a central server compromised issue and there will be no one to legally strong-arm.
Well it would be nice if google could check the url it was visiting and if there is any sqli in it to not send the request (though this could potentially slow their crawling...)
But the only point in this is to take down a site you won't be able to get into useful information back from this request as the request's response will be heading back to the spoofed address... (though if you are using for ddos it is pointless to get the data back...)
Wouldn't Lavabit be better if all decryption was done on client side, either with javascript or a client side add-on/extension? This way the only thing that is ever on the server is the public key? The only thing left would be if it had been in a man-in-the-middle attack... which is always an issue on the internet unless every part is encrypted which is hard to do... though internally it could potentially be safe as it would not ever be sending out of itself and emails being sent would also be encrypted client side using javascript/add-on/extension... (also have the keys generated on client side) yes this would inevitably be a large client side program but for security it would be worth it.
LOL fair enough, fair enough
or possibly a self checking script that only executed if it was complete... ie: the script is escaped and must run unescape(escaped_script) to be lethal but by then you can confirm that the script is infact whole and as the creator intended to be...
Don't mess up/risk your own computer just your friends... You must have trusting friends. lol
though BTsync is "meant for large files" I wouldn't really advise syncing truecrypt files as it syncs the entire file not just updating lines in the file... (though that would probably be much more efficient) even still using truecrypt would still require entire file syncs the second anything changed. :/ maybe instead encrypt each file separately using AES... might be slightly better as you won't be syncing whole gigs of files if you only changed a small text file...
"Engineer? of software?" I know he is an engineer of software I was not disputing that. If you read my first comment I knew that I was disputing that he had any right to comment on hardware as he did which would put him into the electrical or mechanical engineering. As for getting hired with a CPS as a software engineer, uh yeah it's not identical but that's the same area as I mentioned in my later posts.
I was not objecting to him being an engineer, he can be an engineer of software which does define him as an "engineer" but Microsoft would really hire someone who does not have a degree in the area of the job?