refresh
HN user
rosnd
By paying taxes they’re essentially admitting to a felony to the US government, which makes them trivially easy to raid.
That's not how it works, taxpayers enjoy fifth amendment protections against self incrimination.
IRS can't share this information with other LE without a warrant anyway.
How do you define "politically neutral"?
Remember that last pass has just been caught lying about their security, and you can't trust what they say.
I'm curious, what were they caught lying about?
What proof do you have that last pass uses that encryption scheme? Is there any evidence to suggest that it meets rigorous standards?
LastPass has been extensively reverse engineered. There are, for example, public Defcon talks about it.
Changing passwords in the face of a breach like this is standard practice and is the only logical step forward.
This is not logical at all.
You cannot trust last pass security from this point forward.
Why not? Because they disclosed a breach?
He waived extradition, definitely makes him seem like much less of a flight risk.
How is the LastPass encryption badly implemented?
In your other comment you claimed it was "likely" to be badly implemented, but here you state it as a fact. What's up with that?
Why do you think it is likely? That's a very strong claim.
such as bad RNG
How could that be a problem? The attacker doesn't control your passwords. How would you exploit a known IV as an attacker in this context?
If you don't trust LastPass to encrypt your passwords properly, why would you use it at all?
That exact kind of thing happens constantly
Like when?
And of course, the nature of the concern here involves us not knowing that LastPass was fucking up.
What do you mean? The cryptography used by LastPass is very well understood.
Your encrypted data is compromised, it is in the hands of an attacker who really wants to decrypt it. You're pinning all of your digital security on encryption holding against an active attacker.
Well, yeah. Just like you leak your encrypted password to the internet every single time you log into a website.
What if there is an undiscovered or undisclosed vulnerability in the encryption?
lmao, if aes-256-cbc is broken then LastPass is probably the least of anyone's concerns. This happens to also be one of the more difficult AES modes to screw up.
What if last pass isn't using encryption as secure as they claimed?
Shit, if that was a real concern you would have to be a complete idiot to use LastPass in the first place.
Do we really need robots steelmanning Hitler?
Exactly, the only thing this test reveals is David Rozado's far right biases.
Does that even fit on the spectrum? From Europe things like the "Stanford's guide to political correctness" feel super niche in the same way that some weirdos on the left used to advocate for getting rid of ages of consent.
Only the encrypted randomized passwords were leaked. Unless you knowingly used a bad password for your cloud-based password manager, you're fine.
If you did use a bad password for the cloud based password manager, you're the walnut. The whole sales pitch is that lastpass can't fuck you as long as you have a reasonable password protecting your vault.
Seems like instead of spending Christmas with my family, I will spend it changing passwords for 100s of accounts.
Why didn't you just use decent passwords in the first place? You were using a password manager, what's the fucking point if your password is still "kittens1"?
This is all on you.
"Crazy amounts of data" isn't the main concern, it's latency. It's the people storing giant amounts of data who generally don't worry about that so much.
rather that introducing new remotely accessible attack surface to the kernel in 2022 when we know it's likely unsafe is silly.
This is the worst possible take on this.
Building an SMB server in the kernel because "well, NFS was secure eventually" overlooks the fact that NFS shouldn't be in the kernel either.
The way Linux works, NFS unfortunately has to be in the kernel to achieve reasonable performance.
Yes, but federal drug crimes are not the only kind of drug crimes.
Well, that's a lie which at times has real impact on trial outcomes. I wouldn't really put it in the same category.
That doesn't make any sense, everyone on the receiving end of these threats has a lawyer. Even the shittiest public defender will translate this for you.
These numbers exist solely for the audiences at home.
I mean, various laws covering unauthorized access to computer systems seem like they would be directly applicable here.
https://www.cps.gov.uk/legal-guidance/computer-misuse-act
There must be knowledge that the intended access was unauthorised; and
Check? If not currently, Netflix could trivially ensure that this is the case by just adding a banner on the login page.
There must have been an intention to secure access to any program or data held in a computer.
Check.
What does that look like? Stolen parts will always be cheaper.
The warehouses full of people in Shenzhen tearing down millions and millions of stolen iDevices would still be chugging along, inserting stolen parts into the supply chain.
Apple enforcing DRM on parts is very much a pro-consumer move, steadily taking us towards a world where a stolen iPhone will be worth nothing.
Of course they do. Until third party repair shops created a huge market for stolen iPhone parts, stealing them was significantly less attractive than other phones.
Well, they do. iPhones are still valuable after being parted out, although Apple has been combating this by requiring parts to be registered by them (and shamed for much of the same on HN)
No, only about 1 in 5 mice become addicted to it. The number with humans will be far lower.
It depends, enforcementtracker.com shows that the authorities have been willing to chase after a rather diverse mix of violators.
But indeed, leaving GDPR enforcement to government authorities was a huge mistake. Anyone should be able to sue over GDPR violations impacting them.
Who the fuck are those people overdosing on crack cocaine, and how? This is literally one of the most difficult drugs to dangerously OD on.
You can't snort crack, you can't IV crack. You can only smoke crack, the onset is super fast and doesn't encourage you to rapidly redose. Dosage tends to be limited by your lung capacity.
Maybe with some very impressive lung capacity?
It's easy to overdose on Cocaine HCl using any of the popular RoAs. Insufflated, the onset is very slow, enabling you to take way too much before you actually start to feel the effects. Intravenously, your dosage is not limited by your lung capacity as it would be while smoking crack.
SSNs are not unique for a whole lot of reasons. https://www.nbcnews.com/technolog/odds-someone-else-has-your...
It sounds like banning an Uber account would qualify
In addition, processing can significantly affect an individual if it influences their personal circumstances, their behaviour or their choices (for example an automatic processing may lead to the refusal of an online credit application).
It's definitely much more than 5% of new ICE cars.
This EU commission page suggests that a human review should be conducted before a client is informed of the decision, not only in the case of an appeal.
https://commission.europa.eu/law/law-topic/data-protection/r...