• 0 Posts
  • 271 Comments
Joined 3 years ago
cake
Cake day: June 19th, 2023

help-circle






    1. Actually text me the one-time passcode, rather than saying you sent it to me while instead texting it to the molten core of the earth.

    Uhhh… how about NO??

    In fact, as a casual security professional (it’s not a core part of my job, but I know a lot more than most ppl), I openly advocate making SMS and eMail illegal for transmitting one-time passcodes.

    Why? Because both are critically insecure, cannot be adequately secured outside of laboratory or highly restrictive environments, and can be trivially hijacked.

    The only one-time passcode that should be used are one-time password generators (TOTP) such as Google Authenticator or any other such method.

    Yes, this requires a little more effort on the part of the site owner, but it’s worlds better than SMS or eMail, and far more user-friendly than forcing the user to open the company’s app just to receive the code (looking at you, Canadian banks and other businesses like Telus).






  • Oh no! Forbidden

    Error: access denied: denied by administrative rule fa68ec4c0b694396d50ce50a8cf4cb6b/81a4d3ff51d16981b7d8

    Why am I seeing this?
    If you have any issues contact the site administrator and provide the following Request ID along with your browser details, specially like the User-Agent: fa68ec4c0b694396d50ce50a8cf4cb6b

    Protected by go-away :: Request Id fa68ec4c0b694396d50ce50a8cf4cb6b

    Just some basic browser protections, and I get this. Is this enshittified Cloudflare v2.0?


  • I am in IT, and personally speaking, with my own machines, I have never had these power settings not be obeyed.

    And the only time when I have seen these settings “not be obeyed” in other systems is because either,

    1. Someone or some other non-Microsoft software had dicked with power settings through the registry/GPO, or
    2. I’ve been able to trace things down to hardware malfunctions or hardware discrepancies.