• 0 Posts
  • 86 Comments
Joined 1 year ago
cake
Cake day: July 1st, 2023

help-circle
  • If you were alive in 1960s America, you would have seen no seat belts, significantly lower life expectancy, children still dying to smallpox and polio, and if you are ethnically from the Middle East; everyone in America would have hated you. Race riots were a massive thing in the 60s, police brutality was rampant against people of color. Even the FBI was trying to suppress race progress.

    You have presidents for decades trying to create racist drug politics to entrap only non-white non-affluent people into cyclical prison systems.

    You have so much hidden then, that happens today, but it was both hidden and far far greater.

    The ideal doesn’t exist at all and more so for someone like yourself.





  • Notice how I didn’t just use the service name?

    <Disco>

    <Netfucks>

    <MailGoog>

    Whatever nickname you use for your services. There is no requirement you also use the service name in the tagging template.

    The idea that a breach of a service would have someone looking at your individual password is also pretty silly. There would be variations and pattern matching Lagos run against lists of hundreds of thousands to millions of passwords… but the decryption of a complete password to plain text is so reductions at this point, we are talking about the 0.01% case of a then even more silly “let’s look at this guys password in particular” 0.0001% case on top of it…

    It’s not a real problem because if your service is at the point it is leaking not just salted and hashed passwords, but plain text passwords: you are in a big problem up no matter what for most users. Almost everyone reuses passwords. The real risk is the simple reuse. Get just a slightly different variation and you are miles more secure in the case of a breach that results in full decryption.

    The majority still reuse Password1234! Everywhere. This gives you a easier way to be miles better.

    Better still of course is some sort of managed password vault, assuming you trust their implementation. However, this costs zero in the training, or tech literacy upskilling that even the moderate change to a password vault requires. It’s simply an extension of what people already intuitively know. Thus, barrier to entry is easier while giving you several orders more protection.





  • You can take this a step further to segregate passwords as well.

    Reusing passwords across devices is bad. If one gets compromised you don’t want a password being out into a brute force table to be used with all your other accounts elsewhere.

    This method of tagging using HTML markup styles in your passwords lets you keep the same core passphrase but alter the tagging, specific to the service.

    You can do this easily while also giving you artificial password complexity.

    Example:

    Core passpgrase is “yogurt”

    Password for gmail becomes markup with a <mailPassGoog>yogurt</mailPassGoog>

    I only need to remember yogurt.

    Every device just gets a truncated service tag appended to the beginning and end using HTML style tags.

    Suddenly you have a 26+ character password that you don’t forget and doesn’t compromise you across other services because each is different.






  • sudoshakes@reddthat.comtoPolitical Memes@lemmy.worldBig one
    link
    fedilink
    arrow-up
    16
    ·
    edit-2
    7 months ago

    You can simply look at the data for avoidable mortality rates among OECD countries. This tells you the impact of healthcare access to early mortality that could have otherwise been avoided with better access to care. Time to care directly impacts these measures.

    For 2022, the United States is only better than Latvia, Lithuania, Peru, and Mexico in avoidable deaths per 100,000 people. Every other nation in the data set with values is lower. Sometimes by more than half.

    Every other western nation shits all over US stats in infant mortality as well, showing that when you remove obesity from the equation, you still get far worse quality of care from the start of life.

    All this when paying 3X the amount to get the care in the first place.

    The worst part is the US average person pays more than 4 times the amount of administrative care than then EU average. 4X for administrative costs.

    It’s 9 times as much admin cost as countries like Italy who also have some of the shortest wait times to see a physician, or specialist, in the OECD data set!

    Imagine paying 3X more per capita, waiting longer, and getting worse measured outcomes for decades… then still have people asking if they are getting a raw deal?


  • Opinion letter.

    None of the accusations in the title can be substantiated, more than a dozen other apps and technologies are backed by the same organization the article mentions funds part of a signal’s budget.

    Assertions that TOR has a governmental back door, that the CIA wants people to use Signal, are not substantiated, and the article states at the same time that there are fears the anonymity of Signal threatens western governments. Can’t have it both ways.

    The only definitive thing this article can prove or cite is where some OTF funding goes, which was publicly disclosed since it’s inception. It reads like a /r/superstonk GME reeeeeee post equivalent for communication security by a ti foil hat.




  • Sure it does, but that doesn’t make it bad.

    Open source code is not the only solution to secure communication.

    You can be extremely secure on closed source tools as well.

    If they found specific issues with Signal aside from not being allowed to freely inspect their code base, I suspect we would be hearing about it. Instead I don’t see specific security failings just hat it didn’t make the measure for their security software audit.

    As an example of something that is closed source and trusted:

    The software used to load data and debug the F-35 fighter jet.

    Pretty big problem for 16 countries if that isn’t secure… closed source. So much s you can’t even run tests against the device for loading data to the jet live. It’s a problem to sort out, but it’s an example of where highly important communication protocols are not open source and trusted by the governments of many countries.

    If their particular standard here was open source, ok, but they didn’t do anything to assure the version they inspected would be the only version used. In fact every release from that basement pair of programmers could inadvertently have a flaw in it, which this committee would not be reviewing in the code base for its members of parliament.



  • From time immemorial, the purpose of a navy has been to influence, and sometimes decide, issues on land. This was so with the Greeks of antiquity; Romans, who created a navy to defeat Carthage; the Spanish, whose armada tried and failed to conquer England; and, most eminently, in the Atlantic and Pacific during two world wars. The sea has always given man in expensive transport and ease of communication over long distances. It has also provided concealment, because being over the horizon meant being out of sight and effectively beyond reach. The sea has supplied mobility, capability, and support throughout Western history, and those failing in the sea-power test -notably Alexander, Napoleon and Hitler - also failed the longevity one. - Edward L. Beach, in Keepers of the Sea