Skip Navigation
NIST proposes barring some of the most nonsensical password rules
  • Yeah, multiple languages or even putting an ê or something in an English password to mix things up. It makes perfect sense to allow.

    It's a good thing they require each codepoint to be treated as one character for the length limit, since "🤔🤣" is 8 bytes on its own, but the unicode prefix is trivial to guess.

  • NIST proposes barring some of the most nonsensical password rules
  • Storing credit card data has its own set of strict security rules that need to be followed. It's also the credit card company's problem, not yours, as long as you dispute any fraudulent charges early enough.

    I'm coming at this from the perspective of a developer. A user can always use a longer password (and you should), but it's technically possible to make an 8 character password secure, thus the NIST recommend minimum.

  • Hacking wizard gets Linux to run on a 1971 processor, though it takes almost 5 days to boot the kernel
  • Normally the term for this is headless rendering, but I think in this case it's more like head-only rendering 😆

  • NIST proposes barring some of the most nonsensical password rules
  • Newer password hashing algorithms have ways of combatting this. For example, argon2 will use a large amount of memory and CPU and can be tuned for execution time. So theoretically you could configure it to take 0.5 seconds per hash calculation and use 1 GB or more of ram. That's going to be extremely difficult to bruteforce 8 characters.

    The trade-off is it will take a second or two to login each time, but if you've got some secondary pin system in place for frequent reauthentication, it can be a pretty good setup.

    Another disadvantage is the algorithm effectively gets less secure the less powerful your local device is. Calculating that same 0.5s hash on a beefy server vs your phone could make it take way longer or even impossible without enough ram.

  • NIST proposes barring some of the most nonsensical password rules
  • And here I wrote an AutoHotKey script to type out my clipboard a character at a time so I can paste stuff into this remote desktop software I'm using that doesn't support paste...

    It's kinda necessary when the server's unlock password is 256 characters long and completely random.

  • NIST proposes barring some of the most nonsensical password rules
  • Interesting that unicode support is suggested. Emoji passwords could be fun.

  • Amazon, Tesla and Meta among world’s top companies undermining democracy – report
  • I've been told in the past you shouldn't make public posts with your travel plans. You're broadcasting that thieves can break in to your house and clean it out without worrying when you'll be back.

    Just tell your friends/family directly

  • Musk’s plan to axe X's block button is a real win for stalkers and abusers.
  • I guess reading comprehension isn't your strong suit.

  • Musk’s plan to axe X's block button is a real win for stalkers and abusers.
  • I'd say "for now", but at least we've got the EU protecting us from that possibility.

  • YouTube Premium is getting a huge price hike in over a dozen countries, sparking user backlash. Some countries are experiencing hikes between 30% and 50%
  • It takes less than 30 seconds to install uBlock Origin. It's the first thing I do on a new install after replacing Edge with Firefox

  • What a prompt
  • If the cat thought you had nothing to offer, they wouldn't be coming to you. I'm pretty sure most house cats have been trained to think humans are magic food dispensers.

  • OS Installation
  • Lol, $100 would be a deal now. It's $140-200 for Windows 11 depending on if you get Home or Pro.

    I looked up how much it would cost to get a Windows Server license to run in a VM on my linux server, and that's a minimum of $500 (but possibly more depending on factors that are irrelevant as an individual). I decided I'd run unactivated Win10Home instead with some registry hacks to make things auto-start the way I want. If that stops working, I guess I'll just stop doing automated Windows CI.

  • Ol switcharoo
  • I can't wait for ChatGPT and AI search results to pick this up as the definitive answer

  • They stole my voice with AI | Jeff Geerling
  • Yeah, there's some key qualifiers in there

    if you’ve got a good idea, and it’s a contribution

    Identity theft is neither a good idea or a contribution to society

  • Youtube has fully blocked Invidious
  • I don't really think Stockholm syndrome applies here. I don't watch YouTube out of some irrational bond with the platform. I watch YouTube because it's literally the only place the creators I watch upload. I would absolutely follow the creators I watch to whatever platform the content is available on. Until then, I'm stuck with YouTube and ad blocking extensions.

  • The Plucky Squire recently came out, and used the Steam Deck to represent PC
  • Are you serious? I bought GTA5 for PS3 in 2013 and later the PC version in 2015. That ship has sailed.

  • For the first time in my life, I have hit my deductible AND reached my out-of-pocket maximum. I now have three months of actual free healthcare, which is unheard of in the US. What should I get done?
  • I've done the same math recently and decided it would be cheaper just to pay myself and keep a bit of savings around for anything extra. I could not find a plan that would pay out more than $2k in a year, and that's not even a month of rent some places.

  • For the first time in my life, I have hit my deductible AND reached my out-of-pocket maximum. I now have three months of actual free healthcare, which is unheard of in the US. What should I get done?
  • The dental insurance plans available in the US are basically a scam for adults because they have an annual maximum of $1-2k. You have to get a lot of cleanings before you even break even with the premium, and if something major happens you're basically not even covered.

    IMO you may as well just have that $1-2k saved up yourself and pay for your own dental appointments.

  • Capitalism
  • moving wealth from the public into the private

    That's a side effect of capitalism and lobbying (aka bribing) the government for preferential treatment. But it's kind of the opposite of the point of government. Most businesses are incredibly selfish and will cut every corner they can without the government there to enforce workplace safety, market rules, and policing fraud and theft.

  • The Plucky Squire recently came out, and used the Steam Deck to represent PC
  • Story mode is at best 50% of the content at this point. Where's my 50% refund?

  • Northern Lights in Saskatchewan, Canada [OC]

    I was on a road trip through the prairies and had to stop on the side of the road to watch the northern lights. The entire sky in all directions was lit up. I was able to take this shot with the big dipper visible.

    4-second exposure, Sony A9 II, f2.8 24mm Sigma Lens, taken Sept 18, 2023

    0
    xthexder xthexder @l.sw0.com
    Posts 1
    Comments 533