HN user

jonafato

242 karma

jon AT jonafato DOT com

[ my public key: https://keybase.io/jonafato; my proof: https://keybase.io/jonafato/sigs/0nj0parv3VYKXIAOc86v2t0KJCxmdd-0B-vx1_ogRTc ]

Posts11
Comments128
View on HN

This is a Medium blog on an nytimes.com subdomain, so perhaps you've hit an account or browser specific limit. I'm not getting a paywall in or out of private browsing mode, you may be able to get around it easily.

While I like my Yubikeys, they definitely aren't more convenient or intuitive for people who aren't accustomed to using multifactor authentication already. The webauthn spec [0] includes support for "biometric authenticators" and "platform authenticators" (e.g. the fingerprint readers with secure enclaves increasingly present on phones and laptops), and I think that has a real chance at improving authentication security across the board. Once Apple, Google, and the like start pushing "touch to login" via webauthn, people will come to expect that sort of convenience. And if all of your devices include these authenticators, adding a new device should be as simple as authenticating on one that hasn't been lost or stolen.

[0] https://www.w3.org/TR/2019/REC-webauthn-1-20190304/

It's only a stupid premise if you take the feature for face value and assume that the people behind it expected it to magically solve all of the tracking problems on the web. Alternatively, consider that it's a great opportunity for all those companies that "value your privacy" to put up or shut up. Then tools like Privacy Badger [0] get to call out advertising companies that assert that they only track consumers because that's what consumers want while explicitly ignoring the industry standard opt out mechanism.

[0] https://www.eff.org/privacybadger/faq#How-does-Privacy-Badge...

There's a similar effort in the Python / Django world called Jazzband (https://jazzband.co/). This model will probably become more and more necessary as maintainers need to move on from projects for whatever reason. Having a safe place to transfer a project to with a formal process (announcement of the change, code review before acceptance, etc.) would certainly help combat this issue.

I think plenty of people in the Python community will earnestly say that while acknowledging that there isn't universal agreement on what that one good way is. It's an ideal to strive for, not a statement of fact.

The PyPA team has done a lot over the past five years. The changelog for pip (https://pip.pypa.io/en/stable/news/) contains quite a bit, PyPI was migrated to Warehouse, and there have been several PEPs focused on improving the packaging situation. A lot of these ideas come from various people in the community and get formalized as official recommendations or tools, but these things take time, especially accounting for backward compatibility in an ecosystem as large and mature as Python's.

The short answer to "why isn't this solved?" is "it's hard, and there's a lot to do". Development practices change over time, and the tooling continues to evolve with them. It's easy to see a broad survey like this and think that there's too much going on, but taken at a high level, the space is definitely trending in the right direction.

(Note: I'm not part of the PyPA, but I'm interested in this area and try to follow along from the outside.)

Can anyone comment on their "zero touch is safe" claim (https://krypt.co/faq/)? As far as I understand, tokens like YubiKeys require a touch as an explicit action by the user to prevent authentication without their knowledge. Doesn't a zero touch approach remove a security feature?

I disagree that it's clear. Words have meanings, and

By "unlimited", we really meant "limited".

shouldn't be a valid defense for misleading consumers. The plan would be more accurately described as "15GB 4G LTE Data". If the limits were stated more prominently, the fire departments could have avoided confusion and worked with Verizon or a competitor to get on a plan that wouldn't stop working at the worst possible times. Verizon could have also avoided some bad press by just waiving the fees and sorting things out later instead of demanding extra money during an emergency.

Not OP, but I think they're referring to this story [0] about a survey conducted by the Program for Public Consultation at the University of Maryland. The results showed 83% opposition to repealing the existing net neutrality regulations. A lot of the coverage around this topic makes it out to be a partisan issue, but all of the research shows strong support for net neutrality regulations across the board.

[0] https://www.washingtonpost.com/news/the-switch/wp/2017/12/13...

Why No HTTPS? 8 years ago

HTTPS is for the users' benefit. They should be able to trust that they're getting the content they asked for without modification or snooping.

I don't know that this invalidates mtgx's general point. Right now, data brokers have effectively zero liability, but we don't treat other companies dealing with dangerous or toxic materials the same way. If a company handling money or munitions left their doors wide open, we wouldn't defend their gross negligence, we'd hold them accountable.

It's a bit misleading to post that quote without including the validity section as well. People are not as quick to abandon their ethics as the original results of that experiment suggest.

In 2012, Australian psychologist Gina Perry investigated Milgram's data and writings and concluded that Milgram had manipulated the results, and that there was "troubling mismatch between (published) descriptions of the experiment and evidence of what actually transpired." She wrote that "only half of the people who undertook the experiment fully believed it was real and of those, 66% disobeyed the experimenter". She described her findings as "an unexpected outcome" that "leaves social psychology in a difficult situation." In the journal Jewish Currents, Joseph Dimow, a participant in the 1961 experiment at Yale University, wrote about his early withdrawal as a "teacher", suspicious "that the whole experiment was designed to see if ordinary Americans would obey immoral orders, as many Germans had done during the Nazi period."

The stock launcher that ships with AOSP (and Copperhead OS) [1] is OK but leaves something to be desired. I used Nova Launcher [2] for years before switching to Copperhead and liked it quite a bit, but after forgetting to back up my settings and being to lazy to reconfigure it just the way I liked it, I switched to KISS Launcher [3]. It took a few days to adjust, but I prefer it now, and it has the added benefit of being open source and available through F-Droid.

[1] https://android.googlesource.com/platform/packages/apps/Laun...

[2] http://novalauncher.com/

[3] http://kisslauncher.com/

An update on GnuPG 9 years ago

If I recall correctly, you can choose to let keybase store your password-protected private key for the purposes of decrypting messages through the website, but that's not required, and the advanced features (e.g. chat) don't work without a local install. Everything that can be delegated to the app (GUI or command line) generally is. The keybase team seems to take this quite seriously, and they've had documentation on how to use the platform without giving their servers any information since at least when I joined in early 2014.

Give it a shot, it's quite painless as far as crypto products go. You can always choose not to use it if you decide it's storing too much information. Happy to provide an invite if you (or anyone else) needs one.

I'm by no means a ZFS expert, but much of what I've read from "authoritative" sources [1] suggests that this is a myth. The 1GB of RAM per TB of disk is largely a suggestion from the FreeNAS developers a while back that was specific to FreeNAS (not ZFS in general) and more of a gut feeling than something backed by measurements. ZFS deduplication can be memory-hungry, but it's more "adding memory helps" than "not having lots of memory is catastrophic".

[1] https://linustechtips.com/main/topic/738402-zfs-memory-requi...

I was going to ask "does this need a marketplace?" and link to a list someone was maintaining a few month ago of folks who offered to match donations made to the ACLU, but it looks as though someone turned that into a little web app, anyway: http://matchingdonations.us/. That said, the harder part of this is probably getting people to make that offer to begin with. If this becomes a common thing, I'm sure someone will build a platform around it. If someone told me they'd donate to a charity of my choice in exchange for having dinner or coffee, I'd probably jump at the chance and match their donation, as well.

If you haven't seen it before, zxcvbn [1] seems like a good attempt at automating these things, and there are ports of it in many popular languages. It's been in use in production at Dropbox for several years, now, so I'm hoping the ideas and implementation have been vetted pretty well.

(I have no Dropbox affiliation, I just found the library a while back and thought it was a great way to keep passwords secure while getting rid of arbitrary requirements focused more on SQL injection than password safety.)

[1] https://github.com/dropbox/zxcvbn