Show newer
Void Abyss boosted

LASTPASS NEWS ALERT AND COMMENTARY:
LastPass attackers know your name and billing address and all websites you have saved passwords for, and if your master password isn't sufficiently strong may be possible to brute-force open everything on attacker's machines.

PLEASE READ BEFORE PROCEEDING: blog.lastpass.com/2022/12/noti

The fact LastPass doesn't encrypt website URLs is a known flaw it appears they never fixed on purpose, going back almost 6 years:
hackernoon.com/psa-lastpass-do

This eventual possible security breach was planned-for as part of LastPass' design for username and password protection. This doesn't break the core offering.
But it has stripped away multiple layers of protection and will hasten my looking at @bitwarden

It's impossible to be completely secure in a massive offering. However I have always disagreed with their decision to not 100% encrypt all metadata, and this event shows that was a foolish choice when seen against the inevitable of the entropy our complex electronic systems.

In the end, a password manager is still right choice in comparison to alternative. And a cloud-native offering like LastPass strongly hedges against data loss by normal users trying to manage their own vault. That is an undersold primary risk, not hackers. Still, very disappointed.

Current password setup:
- Primary vault is LastPass with 2FA
- Core fallback "key" accounts like email that allow pw reset are only in a KeyPass db file with 20char password, synced via OneDrive+2FA.
- This is then further backed-up with BackBlaze, using 40char encryption key

@darth
The is still at its infancy, some admins want to overprotect and nanny their users other admins want to provide wide reach, free speech and tools for better user experience.
In the end, instances that share the same values of openness, transparency and accountability will naturally keep the federation others that want to be overprotective, imposing block lists upon other instances will remain isolated in their bubble.

@freemo

@darth @freemo I think admins should treat instances like email servers, only blocking the ones that send spam/malware the fine grain blocking is up to the users. From a user perspective you want to be in an instance that have a wider reach in the not the most isolated/restrictive in my opinion.

@aven That's awesome! What TV model did you repair and what learning resources did you use?

Void Abyss boosted
Yesterday I managed to repair a broken television by replacing a busted capacitor on its power supply board. As a novice with electronics and soldering, this felt gratifying and empowering. $10 and a few hours of learning saved needing to get a new TV. :blobcatsmile:

@freemo I see a lot of users complain about the lack of quote toot feature but it's working just fine @ Why didn't this option become standard in other instances?

Cassandrich  
That's what the Mastodon issue tracker item I'm supporting, https://github.com/mastodon/mastodon/issues/20673, is all about: making quoting opt-in,...
Dr. Jack Brown :verified:  
“The clearest way into the Universe is through a forest wilderness.” John Muir #EmotionalIntelligence #Quotes #Nature #Wilderness

@jerry @SpaceLifeForm I find it very hard to miss the reply button but okay some might do 🤷‍♂️

@jerry @SpaceLifeForm

> it appears that some times you respond to a post by essentially starting a new post, rather than replying.

Is this a bug or normal behavior?

> If you want to see an entire thread then you have to go to the original thread on the specific instance.

@Fez how can you find the original thread if you only have a reply?

@SpaceLifeForm The links I mention in the example are direct links to your toot from your instance, can you open them in a private window, so you might then see what I can not see.
The strange thing here is that the toot looks like a reply and technically I should not get your reply toot in my timeline and I get only your reply toot not the whole thread.

Void Abyss boosted

RT from Michael Scaglione (@Scagz89)

With todays #TwitterFiles8 I thought it was pertinent to reshare this video about CIA manipulation of the public.

twitter.com/Snowden/status/158

Void Abyss boosted

One thing I've really been working on this year is binary thinking. When I encounter debates or internet disagreements, in the past I'd find myself believing that if someone disagreed with me on one detail or shade of their argument, they were against or opposed to me, even if other parts of our dialogue were in agreement. I found myself becoming distrusting of those who otherwise were very closely aligned with me, even more so than those who were ideologically very different, probably because I had already written them off or cut myself off from contact with them.

Through the life-saving psychoeducation reading I've been doing the past few years, I've learned that either-or, black and white thinking is exascerbated by trauma. When someone is in fight/flight, the prefrontal cortex is inhibited- that is where higher-order, critical thinking takes place. We are unable to deal with nuance when triggered. Think of fights where you say things to your partner like "you always_____ or, you never _____". In BPD terminology, we call this phenomenon splitting- when you can temporarily think about someone you care about only in terms of them being "all good" or "all bad".

Pair this with the fact that binary thinking is a feature of white supremacy culture. I am an anarchist who was brought up Evangelical (no longer am) where "if you're not with us, you're against us" thinking is rampant.

So interrogating where these phenomena come up in discussing leftist theory and praxis has been eye opening. Just because we are trying to leave certain cultures, doesn't mean those thought processes leave us overnight. They are ingrained in our neurological processes and take time to identify and relearn. We need enough felt safety to be able to access our capability for nuance.

@TheMemeticist@mas.to Damn what might have caused a respiratory illness to become a an autoimmune diseases?

@MOULE @elonjet Hey if there is a website that track your smartphone's bluetooth signal and Public IP address, would you be okay for that data to be shared all over the internet and easily accessible for all the psychopathe out there?

Show older
Qoto Mastodon

QOTO: Question Others to Teach Ourselves
An inclusive, Academic Freedom, instance
All cultures welcome.
Hate speech and harassment strictly forbidden.