Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)XY
Posts
17
Comments
344
Joined
2 yr. ago

  • You're absolutely right. Everyone will be very worried and talk about the importance of security in the enterprise and yada yada yada until a cool new AI spreadsheet software comes out and everybody forgets to even check if their firewall is turned on.

    But with that being said, if you have been looking for a good time to ask for cybersecuity funding at your org, see if you can't lock down 5 years worth of budget while everyone is aware of the risk to their businesses.

  • Can, yes.

    Should, maybe.

    Enjoy doing, unlikely.

    And for sure your home isp has all the email ports blocked upstream.

    With all that being said, to call SMTP dead is wildly insane. I do figure it will die someday though. Probably around the same time of universal IPV6 adoption during the year of the linux desktop.

  • You also get additional protection because rather than each website holding onto a hashed (hopefully) copy of the user passwords that can be stolen in bulk, stealing the public keys for a passkey from a site wouldn't compromise the account. Someone would have to get access to your physical device or hack your password manager individually to get access to your passkey.

    And and, the magic for most people is no more passwords and 2 factor stuff to deal with. The standard is still new, and in the cases where you want to use physical keys, its always best to keep 2 in case one gets smushed or goes through the washer. Some sites that have passkeys enabled only let you have 1 passkey. So in that case its kind of risky to make a passkey the only way to sign in.

  • This is just someone siting in the middle and modifying a page not to show the passkey login option anymore and then stealing a password/session token.

    As far as I can tell, this has almost nothing to do with passkeys specifically and would only apply in a situation where a website has a username and password fallback in case a passkey isn't created or isnt working.

  • I agree with you.

    And youre right that the article doesnt focus on the algorithmic hate factory which to me is the main difference between social media and traditional media. For instance, and this is just anecdotal, my grandma who had nothing besides an analog telephone and broadcast tv became just as polarized and angry as someone with social media just by reading and watching Fox news (and eventually OAN and Newsmax) all day. I cant imagine that Facebook would have made it any worse.

    The algorithm is probably accelerating the polarization pipeline, but i guess my point was that social media isnt necessarily doing anything new or distinct. Its doing the same thing Rush Limbaugh was doing on the radio 25 years ago, its just on a new frontier.

    The 24 hour news cycle was already throwing sensational controversial stories up and speculating wildly if not outright lying about to hold on to eyeballs. The longer you watch, the more commercials you see. Etc etc.

    I would love to see a study of social media vs traditional media to see whether the mean time to full polarization changes and if so, how significantly.

    Good Ted talk!