Show newer

QT discourse 

@Clackable@tldr.nettime.org
Interesting! I will have to look for someone A that I follow on another instance boosting a reply R by someone B I don't follow on another instance to an original post P also by someone C I don't follow on another instance, and notice that I see R on my Home feed, but don't see P when I click on R. Maybe I am just too young here for that to happen much. :)

ceoln boosted
ceoln boosted

Hi Mastodon! Well I reached 100,000 followers! Thank you so much, I love you all!
As promised, I have brought the mighty Mastodon back from extinction, so watch out! They’re out there stomping around and tooting like crazy! 💨

ceoln boosted

@PeterBronez “Ministry for the Future” came to my to-read list after I read a review by @pluralistic, so I had faith that it was going to be worth it. After I wrote my mini-review, I read a couple of others, and based on those ideas I’d describe the storyline as a kaleidoscope of first-person views. That made it difficult to sort out what was happening, especially in the early chapters. But eventually the threads get pulled together.

ceoln boosted

Many of you have been asking for my thoughts on the #LastPass breach, and I apologize that I'm a couple days late delivering.

Apart from all of the other commentary out there, here's what you need to know from a #password cracker's perspective!

Your vault is encrypted with #AES256 using a key that is derived from your master password, which is hashed using a minimum of 100,100 rounds of PBKDF2-HMAC-SHA256 (can be configured to use more rounds, but most people don't). #PBKDF2 is the minimum acceptable standard in key derivation functions (KDFs); it is compute-hard only and fits entirely within registers, so it is highly amenable to acceleration. However, it is the only #KDF that is FIPS/NIST approved, so it's the best (or only) KDF available to many applications. So while there are LOTS of things wrong with LastPass, key derivation isn't necessarily one of them.

Using #Hashcat with the top-of-the-line RTX 4090, you can crack PBKDF2-HMAC-SHA256 with 100,100 rounds at about 88 KH/s. At this speed an attacker could test ~7.6 billion passwords per day, which may sound like a lot, but it really isn't. By comparison, the same GPU can test Windows NT hashes at a rate of 288.5 GH/s, or ~25 quadrillion passwords per day. So while LastPass's hashing is nearly two orders of magnitude faster than the < 10 KH/s that I recommend, it's still more than 3 million times slower than cracking Windows/Active Directory passwords. In practice, it would take you about 3.25 hours to run through rockyou.txt + best64.rule, and a little under two months to exhaust rockyou.txt + rockyou-30000.rule.

Keep in mind these are the speeds for cracking a single vault; for an attacker to achieve this speed, they would have to single out your vault and dedicate their resources to cracking only your vault. If they're trying 1,000 vaults simultaneously, the speed would drop to just 88 H/s. With 1 million vaults, the speed drops to an abysmal 0.088 H/s, or 11.4 seconds to test just one password. Practically speaking, what this means is the attackers will target four groups of users:

1. users for which they have previously-compromised passwords (password reuse, credential stuffing)
2. users with laughably weak master passwords (think top20k)
3. users they can phish
4. high value targets (celbs, .gov, .mil, fortune 100)

If you are not in this list / you don't get phished, then it is highly unlikely your vault will be targeted. And due to the fairly expensive KDF, even passwords of moderate complexity should be safe.

I've seen several people recommend changing your master password as a mitigation for this breach. While changing your master password will help mitigate future breaches should you continue to use LastPass (you shouldn't), it does literally nothing to mitigate this current breach. The attacker has your vault, which was encrypted using a key derived from your master password. That's done, that's in the past. Changing your password will re-encrypt your vault with the new password, but of course it won't re-encrypt the copy of the vault the attacker has with your new password. That would be impossible unless you somehow had access to the attacker's copy of the vault, which if you do, please let me know?

A proper mitigation would be to migrate to #Bitwarden or #1Password, change the passwords for each of your accounts as you migrate over, and also review the MFA status of each of your accounts as well. The perfect way to spend your holiday vacation! Start the new year fresh with proper password hygiene.

For more password insights like this, give me a follow!

ceoln boosted

@blackenedgreen@mastodon.world
Are they... y'know?

QT discourse 

@Clackable@tldr.nettime.org

Is it, though? I'm still unclear who exactly would be likely to see your reply, but upon clicking on it would not be able to see the original. I don't find that happening to me?

That is, I don't come across replies for which I can't easily see what they are replying to.

Perhaps more likely people who can't see the whole thread won't see your (or any other specific) reply at all? Obviously I'm still somewhere speculating here. :)

QT discourse 

@Clackable@tldr.nettime.org
I don't think anyone's saying that it should be impossible to quote a post; obviously it'll always be possible. The worry is perhaps that if it's made too easy, it will become common, and then ubiquitous, and then part of the culture, and that that could ultimately have significant deleterious effects on that culture. That's how it feels for me, anyway.

@gme
Well, That's a point. I think the two cases are rather different, but then I'm closer to an infosec professional than a journalist myself so... I don't really want to go back and forth forever on it; perhaps I was at least partly just viscerally annoyed by the initial tone.

I don't understand "hot" and "cold".

I mean, matter is like ooh, the average kinetic energy of my molecule has changed somewhat, I'm going to have significantly different physical properties!

What's up with that?

Anyway, it's cold. Like 10° F, in the sun.

@gme
And that's fine! :) You also, I'm pretty sure, don't go around speaking for some group of people and claiming that they will leave the Fediverse if Mastodon doesn't add it post haste. 😉

@futurebird
I said "self-styled elite". :) Rather snarky of me, I admit. I just found the "journalists will leave if this change isn't made" thing annoying. Like, okay? I mean, there are less entitled ways of saying that!

"Metaverse" derision 

Hahaha OMG; do these publications have no one on staff who was around for the Virtual Reality hype in like 2007?

A Virtual Golf Venue, a Space: Rooms You’ll Find in Homes of the Future
Real-estate developers forecast the new additions that homeowners will expect (paywalled, but don't bother lol)

wsj.com/articles/why-homes-of-

@gme

And so far I have no problem with that refusal, myself. :)

I do wish I knew more about the use-cases for non-privileged groups. that might tend to sway my opinion in the other direction.

@kdw @taylorlorenz @futurebird @robertstewart

@gme Yeah! And I like it that way. :) As opposed to what "journalists" are said to want, which seems to be a QT function that is Just Like Twitter available everywhere at all times.

QT discourse again. :) 

@troydarling
That's true! Sadly some people need to be talked about, rather than with, sometimes.

So messy, these humans.

@gme

Sure :) and various servers do offer QTish functions. It's just not so ubiquitous that everyone uses it constantly. And (as a newcomer who likes this new space VERY much) I'm a little reluctant to see that change.

(Especially, frankly, if it's done because some self-styled elite group comes in and says they will leave again if the change isn't made. I mean, sheesh. The arguments from marginalized communities I'm more sympathetic too, but I don't understand them as well.)

@kdw @taylorlorenz @futurebird @robertstewart

@gme
That is true in the current environment, and I like it very much! :) The issue at hand is a proposed change to the environment, though, and one fears it might change that pleasant fact.

That's me in the corner 

@derickflorian
I said Hey! What's goin' on?

(The playlist has advanced.)

Show older
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.