HN user

mrcdima

95 karma
Posts6
Comments6
View on HN

Some titles I've recently read or at least have placed on my reading list.

--------------------

Philosohpy

Letters from a Stoic: Epistulae Morales Ad Lucilium - Seneca

Meditations - Marcus Aurelius (must read)

The Republic - Plato

--------------------

History

Five Chimneys - Olga Lengyel

The Gulag Archipelago - Aleksandr Solzhenitsyn (must read)

The Diary of a Young Girl - Anne Frank

--------------------

Fiction

(particularly dystopian) 1984, Brave New World, Animal Farm, Fahrenheit 451

(crime/action) Child 44, The Secret Speech, Agent 6 - Tom Rob Smith

--------------------

Economics

Capital in the Twenty-First Century - Thomas Piketty

Poor Economics: A Radical Rethinking of the Way to Fight Global Poverty - Banerjee, Duflo

Why Nations Fail - Robinson

--------------------

Economics/Decision making/Psychology

Undercover Economist, Freakonomics, Nudge, Thinking Fast and Slow

--------------------

Random titles

The Selfish Gene, Self-Reliance, The Elements of Style (about writing), Slaughterhouse-Five

--------------------

Some links to inspire your reading (though you may want to checkout the websites first to get an idea of the topics they cover)

http://www.gatesnotes.com/Books

http://bookpickings.brainpickings.org/

http://www.farnamstreetblog.com/reading/

http://www.ryanholiday.net/reading-newsletter

I’m just a working-class guy trying to take part in the conversation that all the smart people are having. What books should I read? - http://www.farnamstreetblog.com/2013/03/im-just-a-working-cl...

But can't you implement all three with a temporary password as well? Make the password valid for 24 hours only and when the user logs in with their temporary password perform any kind of extra verification and if that's passed then also force the user to change their password. Seems like the same thing.

The website I noticed on the front page (sunsuper.com.au) was doing precisely this (although their TTL was 90 days which is indeed far too long and it's impossible to tell whether they forced a password reset or simply recommended a password change).

But how does one handle password resets without resorting in one form or another to sending some info in plain text to users?

At least one website on the current front page is there because it sent a temporary password in plain text. I assume this happened because the user forgot his password. This says nothing about how they store passwords and after all how else would you handle a password reset? Send a password reset link? That's the same thing.

Sending passwords in plaintext back to the user after he has set/changed his password is clearly a security risk but when it comes to temporary passwords or password resets how else would that info be sent?

After reading all of Paul Ekman's books, watching all episodes of Lie to Me, and reading various other pop-science books, articles, posts, and so on, all on body language and lie detection, the only honest conclusion I could reach was that if you really want to know if someone's lying you better know the truth beforehand.

Though there is some science to the method, it ultimately relies on very complex combinations of all sorts of hints, clues, behaviors, all very ambiguous and hard to put to together. Applying this method to regular social interactions is even harder because you rarely get any feedback. You might determine that one person is lying but you might never get the chance to truly confirm your assessment. It's really hard to figure out what works and what doesn't.

You might have a chance at improving if you're a detective (maybe lawyer?) and get to often interview people, ask questions and immediately (or at least at some point) get feedback on whether your truthfulness assessment was right or not but if you're just some regular person who has ordinary social interactions it's much harder to become a human lie detector.