Little bit of everything!

Avid Swiftie (come join us at [email protected] )

Gaming (Mass Effect, Witcher, and too much Satisfactory)

Sci-fi

I live for 90s TV sitcoms

  • 39 Posts
  • 1.75K Comments
Joined 1 year ago
cake
Cake day: June 2nd, 2023

help-circle
  • They could create a system that picks one person out of the millions that do it, and then still make a random number generator pick a number that they have to choose out of 1000, and it would still mean that “You have a chance” to win. Sure, a chance, like, but at what odds, and that’s only if they were actually checked if it was true.

    We all know there was never a chance.







  • I don’t, specifically because I don’t trust myself to host that. I know what people will say here, but I trust 1pass way more than I could do it myself.

    1pass uses your password plus a secret key to generate your full “password”, meaning you need both to access your vault. The password you memorize, the key you keep safe somewhere (inside the vault is even good, since you probably have it open on another device should you need it). They publish their docs, and show how they encrypt your vaults. To them, your vaults are truly just random bytes they store in blob storage. They don’t store your key, they don’t store your password, they will not help you out if you lock yourself out. That’s the level of security I want for a password vault. If they ever get breached, which hey, it can happen, the most someone will get is a random blob of data, which then I’d go and probably generate a new password and reencrypt everything again anyway.

    Vs me hosting myself, I’m sure the code is good - but I don’t trust myself to host that data. There’s too many points of failure. I could set up encryption wrong, I could expose a bad port, if someone gained access to my network I don’t trust that they wouldn’t find some way to access my vaults. It’s just too likely I have a bad config somewhere that would open everything up. Plus then it’s on me to upgrade immediately if there’s a zero day, something I’m more likely to miss.

    I know, on the selfhosted community this is heresy, but this is the one thing I don’t self host, I leave it to true security researchers.





  • Scrubbles@poptalk.scrubbles.techtoMemes@lemmy.mlMeema said F everybody else!
    link
    fedilink
    English
    arrow-up
    14
    arrow-down
    1
    ·
    edit-2
    4 days ago

    You just hit the nail on the head for things that bother me. People just throwing out ideas that “only partially” work. This isn’t just Monday’s, or climate change, but literally every fucking bit of politics. It drives me up the wall.

    “Yeah but it only makes things 50% better, so I don’t support it”

    So we’ll sit with 100% bad rather than 50% better because Jim in Arizona thinks we need to only have perfect solutions, and that anything that only makes things better aren’t worth investigating. Better transit, electric cars, heat pumps, hydrogen trains, gun control, sex education, free lunches? All horrible things to Jim because “they don’t solve the problem”. No, they just make it much better. Maybe we could use them while we search for the perfect solution, you know slow incremental change? No, okay then fuck you too, Jim

    And while I clearly call out one side, us liberals are very guilty of this too. In fact, there’s already an example of that elsewhere in these comments.