HN user

mdb31

484 karma
Posts10
Comments92
View on HN

There is no sync to provider servers on any TOTP implementation I use

That's hard to dispute, but will you accept https://guide.duo.com/duo-restore as a counterexample?

Are you perhaps referring to the Google Authenticator or the Microsoft Authenticator apps when you refer to TOTP

No, I'm referring to the actual RFC 6283 TOTP protocol. Which uses a trivially-cloned single private key. Which is, see the example above, in fact trivially cloned 'for convenience' by at least one widely-used 'enterprise' security solution.

What makes you think they don't "securely" make a few duplicates themselves?

Since that literally makes no sense if you know how hardware tokens work.

Since when is TOTP obsolete?

Since about the moment that teams all over the world discovered they could just paste the enrollment QR code (a.k.a. private key) into their wikis, and thereby continue unlimited sharing of their role accounts?

So, I guess 30 seconds after its introduction?

The TOTP "private key" can be easily cloned. Targeted malware, a database compromise at your app provider that you "securely" sync your settings to, or just a few minutes access to your "authentication" device, will do the trick.

Yet, if you go into the "enable 2FA" settings on Github, you only get the option to enable insecure TOTP or SMS.

Apparently, once you do that, you might be able to add proper authentication. But no word on whether that then replaces the obsolete methods you were forced to configure earlier.

But, yes, right on track to enforce 2FA in 2023, I see...

Oh, that's lovely UX... "After you configure 2FA, using a time-based one-time password (TOTP) mobile app, or via text message, you can add a security key"

So, after you enable a broken-by-design 1.5FA method, which you don't want, and which will further expose you to account takeovers, you can, possibly configure actual security.

No wonder these guys are raking in the big bucks...

I'm still confused. So, can you zoom any site on Safari on iOS or not? And if you can't, what definition of 'control' is that, again?

Well, given that Github today doesn't seem to support meaningful 2FA (only TOTP and SMS), wouldn't it be good to fix that issue before starting to talk about requirements like these?

Maybe it's just my account, but I can't currently enroll my hardware token with Github in any way whatsoever.

Sure, they offer some 1.5FA, but why would I bother with that?

I've never experienced any zoom problems (as opposed to Zoom problems...), and I just had a look at all the sites mentioned in TFA.

In all cases, I can zoom all elements (text, images, the works) just fine, up to 500%.

Firefox 100 on Windows. Is this just another one of those "Safari on IOS is broken, so the Web is broken" things, or is there more to it?

@john_cogs: Are there any plans to connect a self-assessment of mental state to the assignment of issues/pings about mentions/incident-response pages in the GitLab app?

So, on "I'm on top of the world" days, I get assigned All The Issues, get a full-screen popup about each mention, and will be asked to be incident lead on just about anything.

Then, if my state is "slightly hungover", I mostly get a list of the most pressing issues still pending, without being overloaded with new stuff.

And finally, the "hugging my teddy bear" state: no additional automated workloads, respectful notifications to anyone pinging me, and a note to my manager if it lasts more than a few days?

Short-and-easy read that contains much truth. Especially item #10, "Lead by example" which encourages managerial review of recurring meetings (which often boil down to "well, here is my Excel sheet, you tell me how you're doing on each line item: I'll let you talk a lot, but I'll only jot down the completion percentage in the end") is worth emphasizing.

Well, the race to attract the outflow of the current Russian 'brain drain' is definitely on.

If the US is able to attract the majority of that (as it most likely will), while keeping out the Putin-aligned plants and/or otherwise mentally deficient factions (which remains to be seen), that will definitely be huge gain for them.

Well, I'm pretty sure you can't even directly sue over ownership of a .com domain? You have to submit to UDNP arbitrage first (https://www.icann.org/resources/pages/help/dndr/udrp-en).

It doesn't seem they even tried this in this case? So this should be a dismissal right away, albeit at great emotional/monetary expense to the original owner. Unfair, but yeah, cryptobros will be cryptobros, and any harm to members of society is just for the good of society, I'm sure...

(Later edit: so, apparently I'm wrong, and there is no binding arbitration clause. Still, lame action, and this seems the exact situation arbitration is designed for, especially since 'local courts' is not exactly well-defined for .com...)

Nope, people communicate like that internally as well, because "that's what's professional"

In some cases, you can fix this by asking the sender to be, like, normal. This works half the time, the other half involves referrals to HR...

Nope, not a caricature. Read, for example https://www.atlassian.com/engineering/post-incident-review-a...

This is held up as a great example of transparent communication. For me, this is true, but only for the meaning of 'transparent' which equates to 'you can see right through it, to the extent there is effectively nothing there'.

But as per the article this comment thread is about, this kind of response apparently the 'professional' state-of-the-art.

Yes, I despair too...

Ah, yes, the same kind of guide that brought us "how to professionally respond to outages"... With classics like "We recognize the incident", "a small subset of customers", "degraded performance" and "the next update (which will be the exact same meaningless drivel as the current 'update') will be in 60 minutes". Don't we just love those? So let's add more of that to the shared vocabulary of IT professionals!

Or... let's just not? In writing, always avoid clichés. Whether it's "do the needful", "by utilizing" or "we did not live up to our customer's expectations", there is one simple rule: if you've seen the exact same sentence or expression before in the exact same context in the last week or so, you should probably avoid it.

And if that makes you unsure what exactly to say, just type what you mean, then get an editor before posting it to your blog or incident report. And if it's time-sensitive, then just ask for forgiveness later, not permission upfront (which is also a cliché but reworded, see what I did there?)

Where do I say that the speedup is surprising?

My question is whether Intel investing in AVX-512 is wise, given that: -Most existing code is not aware of AVX anyway; -Developers are especially wary of AVX-512, since they expect it to be discontinued soon.

Consequently, wouldn't Intel be better off by using the silicon dedicated to AVX-512 to speed up instruction patterns that are actually used?

I've hosted my own email since, at least 1993 (that's on the Internet: I was on UUCP at least some years prior to that).

If you have a static IPv4 in a range that is not actively hostile, and you have proper SFF/DMARC records, things should generally work out?

And otherwise, services like https://www.mailchannels.com/ should help? (Still, you will need proper SPF records.)

I've literally had a 95+% delivery rate from users in actual Lagos Nigeria using the strategy outlined above.

This is actually very cool: a dataset of 3900 CVEs, with a matching fixing commit for 1359 of them.

So, lots of opportunity to find a big payout w/r/t the unfixed CVEs. Whether successful or not, those attempts will definitely strengthen the ecosystem.

And possibly even shame Google into providing cross-vendor Android security fixes... (note to the uninitiated: this is heavy sarcasm, will never happen, etc. etc.)

Yeah, this particular myth is common in many EU countries as well. Apart from the minimal amount reportedly saved (30 GBP per annum in real currency is 37 EUR/USD per year, less than 10 cents a day), it does not seem to be particularly true.

I measured this (at the wall socket) over the years, and my findings are below.

For battery-powered devices, disconnecting the charger once the battery is full does nothing, other than to cause the battery to be discharged more rapidly than it would be otherwise. For battery health, it's best (if possible) to set a 'start recharging' threshold at 90% or so, but that's mostly a device-lifetime issue, not a power consumption issue.

For 'mains-powered' devices with a 'soft power-off', like many modern coffee machines, microwaves, etc. etc., the power draw in 'idle' mode is truly insignificant. You may have an atypical (broken?) device, but other than avoiding some transistor whine, you truly don't gain anything by powering these off. For devices like printers, monitors and TVs, I've never seen any 'idle' power consumption that was even noticeable.

Some 'always-on' devices do have significant power requirements. Like: your set-top box (since it needs to records the programs you scheduled), your modem and/or media converter, and your fridge. With these: it's always measure, inquire and replace as needed/possible.

For me, my fridge is as efficient as it gets, the fiber-to-Ethernet box from my ISP draws minimal power anyway and my Mikrotik router and APs are pretty power-efficient as well (like, 4 hours runtime on a tiny UPS). The rest goes mostly to my heat pump (which also powers my boiler), and in the summer months, this always offset by my solar panels, unless cooling requirements get way out of hand.

Most interesting observation here: Short GC pauses do not assure low latency.

Anyway: this paper is mostly about Java, which I rarely use and basically only known from Elasticsearch (where log entries about GC pretty much always seem to indicate 'add more memory'...), but I've never run into any scenarios where .NET CLR GC was a performance issue either (not on the legacy .NET Framework nor in more recent releases, which are a lot better in most performance aspects).

Most GC complaints from the .NET world seem to be from game developers using Unity. Which mostly tells me that there should be a way to have a 'this is the rendering thread, never pause this for GC, unless I really do bad stuff' in Unity...

I guess this is supposed to be some Jabbascript trickery, but for me, a 'paste' action in the second text field just yields... blankness...

Which is a pretty good trick, I have to admit, exposing the nothingness of life. Kudos!

Without drowning in fan noise? This world... Sure, I guess you can get a Mac Studio, or some other 'workstation' class PC, but your switch will still need to be within a few meters of that endpoint, and it's not going to be very green nor silent.

2.5Gb/s can easily be done with a lot of laptops and workstations these days; 10 Gb/s isn't quite there yet (and 25, 40 and 100Gb/s are definitely in the server-only fiber-or-DAC-only realm)

No, it's not like that at all. My original point was that most end-users don't care about the license. Implied was that most end-users determine the state of the market, but whatever.

So, here I am, 4 downvotes to my name for stating the obvious. Despite years of membership, I don't have downvote privileges, so I guess I just have to bow to the galaxy-sized minds that have this ability, and deal with the crumbs that do leave a reply, however utterly misguided?

25Gb/s is just overkill for residential use. It's really cool that's it's available, but I fail to see a use case over my 500Mb/s home connection. Even for the servers that I manage and that are bandwidth-heavy, 10Gb/s is way overprovisioned for now.

WiFi goes up to 1Gb/s, if you're lucky. Sure, some WiFi-6 APs have a 2.5Gb/s connector, but that's not what you want or need, unless you're a high-density enterprise. WiFi-6E will possibly improve that a bit, but it will take WiFi-8 to get anywhere close to saturation.

Wired, you can do 10Gb/s for server systems, which are, amongst other things very loud and not very suitable for placement anywhere near humans. 2.5Gb/s support is spotty, and 1Gb/s still the only thing that works reliably.

So, exactly which residential application requires 25Gb/s is not very clear. Yes, it's cool, but not very useful, and faulting manufacturers (especially in times of crippling supply-chain limitations) for not fully supporting it is questionable.

My take: end-users don't care very much about the license, and even for technical users, the value of an 'open' license is overstated. I simply cannot fix bugs in, say, GCC, and it would also be pretty hard for me to pay someone to do so, despite this project being pretty much the poster child (other than, of course, Linux, but that is not exactly a typical case...) for the GPL.

Corporate users want a way out of an abusive or impossible vendor relationship: source escrow can fix that as well as the GPL can (which is to say: not exactly entirely, but, close, I guess?).

Regular users want... things just to work, and someone to shout at if it doesn't. The license of the underlying source code is pretty much irrelevant for that. There are at least three levels of support/indirection prior to that making any difference.