HN user

hsdropout

206 karma
Posts0
Comments44
View on HN
No posts found.

This has been in their guidance since at least 2017.

"Verifiers SHOULD NOT impose other composition rules (e.g., requiring mixtures of different character types or prohibiting consecutively repeated characters) for memorized secrets. Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator"

https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.S...

Also worth pointing out that NIST doesn't set policy, so unfortunately this doesn't directly "forbid" anything, though many other policies reference 800-63.

1. Don’t smoke

2. Try to maintain a healthy weight

3. Reduce your meat intake

4. Avoid ultra-processed foods

5. Drink less alcohol

6. If you notice anything you are worried about, see a doctor

7. Keep up to date with screenings

8. Get physical

9. Wear sunscreen

10. Manage stress

11. Look into genetic risk

12. When faced with a diagnosis, knowledge is power

13. Don’t fear treatment

14. Talk about it

15. Live life to the full

Are you referring to the first amendment? If so, this allows you to speak against the government. It doesn't prevent you from entering optional contracts.

I'm not making any statement about the morality, just that this is not a 1a issue.

Apparently I phrased my response poorly. I was responding to the narrow context of the idea that devs aren't using Azure VMs instead of Macs. I was not disputing the popularity of Azure.

Of the organizations that have Exchange Server on premises, I'd bet the lions share are hybrid, with regular user mailboxes in the cloud, using the server(s) for application relays, etc.

Not sure if I'm missing your intentional irony, but NIST was one of the best places to send folks who think user password rotations are a good idea.

I said "was" because pretty much everyone has now caught up, but NIST updated guidance shortly after big breaches were able to be studied.

Verifiers SHOULD NOT impose other composition rules (e.g., requiring mixtures of different character types or prohibiting consecutively repeated characters) for memorized secrets. Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator

https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.S...

Thanks,I have read this concern before but was not aware it was part of the design specification.

What gives people, especially in the west, the confidence to use it at all, given all of the fusion centers and likelihood of parallel construction? Perhaps this is a rhetorical question...

This implies the browser is pretty sold, but what about the network itself? How do we know all of the traffic isn't deanonymized due to a big company or government having control of a large number of nodes?

Apologies for not bothering to research this question in advance.

In this PDF there is an example of a controversial output in response to an image for job applicants. The "solution" was to decline to answer that category of question. This doesn't feel like a reasonable approach, as it will become a game of whack-a-mole.

This also seems to acknowledge that the model has deep bias-related flaws and instead of treating the causes, they are going after symptoms.

Explored the universe and got to:

~55,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000,000 (55 Quattuordecillion)

but alas, Firefox crashed.