• 171 Posts
  • 508 Comments
Joined 3 years ago
cake
Cake day: June 13th, 2023

help-circle


  • Wow this article is kinda shit. MD5 was on the chopping block for password hashing over 20 years ago. It’s so seriously broken that if someone is using it they deserve to get bludgeoned to death with a Model M keyboard. We have purpose built solutions just for password hashing.

    The only thing the fine bad article sorta got right was two factor. I say kinda because biometrics (something you are) isn’t that great of a second factor. Mainly because you can’t change it. Also, it’s a fuzzy match rather than a hard match. It can be acceptable to use locally and where all the information stays locally AND there is sufficient hardware based security where said biometrics isn’t going to get off the device.

    Finally, there was no mention of any kind of physical token based factor (something you have). Which pairs well with password, passphrase, or any other “something you know” factor.


  • Given the current price of RAM and SSDs, I don’t see how a $200 laptop is even viable to sell. Unless it is barely scraping by on specs or comes loaded with craplets and spyware.

    Just doing a quick search, all I’m seeing is stuff in the $350 range with 4 or 8 GB of RAM. I’m not familiar with the genre of games you play, but I don’t think they would run well on that. Or run at all. Haven’t even looked at the gpu or cpu specs.

    I would try to find something used and compare specs against the min and recommended hardware requirements for the games you play.















  • The right to repair. It’s going to require the ability to make changes to the software on the vehicle. At a minimum the ability to replace the public encryption keys used to communicate with the servers. The bootloader and software is probably locked behind signing keys; so you need to be able to disable or add your own keys. I doubt anyone has access to the full protocols used to communicate with the servers. So, the full technical standard need to be released (which is never going to happen) or reversed engineered through unencrypted traffic analysis and reverse engineering the software.

    A good right to repair law could require some of that be releasable while the company is still active or all if the company goes belly up. IIRC there was a smaller EV company that went bankrupt and there was a concern that once the servers were shutdown the vehicles would be bricked. Not sure what happened in the end. In any case, cars as IOT is the stupidest idea ever created.