• 0 Posts
  • 336 Comments
Joined 1 year ago
cake
Cake day: August 18th, 2023

help-circle



  • His fans will say he won and looked powerful. He didn’t, but they won’t care.

    Wish he’d been pressed more about killing the immigration bill. Every time he complained about it, remind him that he killed the immigration bill.

    Wish Orban wasn’t a diplomatic conflict. Trump saying Orban endorsed him should have been a liability but you probably can’t outright call him a wannabe dictator.

    I doubt it changes the mind of too many people who already had a preference, but maybe a few hopefully. Somehow there are undecided people, I hope they saw it plainly. I don’t think there was much that will hurt Harris from it. She performed very well.


  • Hard to know without more context.

    However, one thing people have not mentioned yet is exchange rates and foreign trade. The republican candidates have reportedly been talking about devaluing the dollar in order to increase exports and reduce the trade deficit. A strong dollar makes US exports more expensive for people overseas, and imports cheaper in the US. Devaluation runs a big risk of creating huge inflation domestically even if it props up exports.












  • One thing the article doesn’t make very clear is that for 2FA the PIN requirement comes from the site itself. If the site requires User Verification, the PIN is required. If not, it is not prompted even if set and this attack is possible. The response to the site just says they knew it.

    It is different for Passkeys. They are stored on the device and physically locked behind the PIN, but this is just an attack on 2FA where the username and password are known. (In depth it’s more than that, but for most people walking around with a Yubikey…)

    It also seems limited in scope to the targeted site and not that everything else protected by that specific Yubikey. That limits how useful this is in general, which is another reason it is sort of nation-state level or an extremely targeted attack. It’s not something your local law enforcement are going to use.

    I think the YubiHSM is a much more appealing target, but that isn’t so much a consumer device and has its own authentication methods.