Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×

Comment Re:Wait, you have to TYPE the password??? (Score 1) 365

Copy/paste cache scrapers exist, and are common for browsers with bugs. Training people not to copy/paste passwords is a good idea.

You're promoting perpetuating a long-standing, widespread and hugely-damaging user security error in order to avoid a relatively obscure problem which can actually be fixed through purely technical means. Not a win.

Comment Re:OpenID Connect scales at O(n^2) (Score 1) 365

What you describe as a problem is actually part of the solution. The problem with classic OpenID was that it was virtually impossible to get, say 1st Bank of MyButt, to use it, because absolutely anyone could be an identity provider. I personally agree with you that classic OpenID was better in that respect, but 1st Bank of MyButt doesn't. They're hemming and hawing about letting Google manage their user's identities, but they will at least consider it.

Comment Re:Wait, you have to TYPE the password??? (Score 1) 365

You're actually very wrong. Long complicated passwords are horrifically impossible to remember causing people to write them down or store them in managers with simpler passwords to open the manager.

Putting them in password managers is the right thing to do.

Length is all that matters for passwords. You're better off with "thatswhatshesaid" (26 ^ 16) than "B4c0nL0v3r!" (72 ^ 11). You're 162 times better off, in fact.

26 ^ 16 = 43,608,742,899,428,874,059,776 72 ^ 11 = 269,561,249,468,963,094,528

https://xkcd.com/936/

You're wrong. Hilariously so.

The entropy of "thatswhatshesaid" is far lower than 43,608,742,899,428,874,059,776. Randall Munroe calculated correctly in the XKCD comic, of course. He didn't assume that each letter was random, he assumed he was choosing four words at random from a dictionary of a specific size (about 2048 entries == ~11 bits of entropy per word). Your password is clearly not a selection of randomly-chosen words, and even if it were, it would likely have been from a much smaller dictionary.

This highlights the danger of asking users to pick passwords... even those who think they know what they're doing are likely to screw it up. Munroe's advice in 936 was good... but I think it has mislead more people than it has enlightened.

No, it's much better to use a password manager and let a computer pick large random passwords for you.

Comment Re:Or let us keep our hard-earned money (Score 1) 574

The tail pound from your mine leaked and now my farm land is useless. I should be able to sue the coal company for the economic value of my land and income it could have generated for my family for the next 10 generations and if the coal company goes bankrupt I should be able to collect from the share holders in proportion to the remaining liability and stock they own.

What about the share holders who sold out before the leak was discovered? What if the owner died and the money was passed on to heirs? What about the ones that moved to another country? Let's say the leaking pond contaminated your drinking water, and coincidentally two of your children have mental development disorders, which of course you can never prove came from that leak? How much cash is worth that?

Comment Re:Or let us keep our hard-earned money (Score 4, Insightful) 574

So we think, now, 30 years after the fact, that the large amount of lead being released into the air from the automotive industry was responsible for the drastic increases in violent crime in the 1960s and 1970s.

Even supposing we hadn't banned leaded gasoline, how exactly do you think the oil and gas industry would take to new efforts to tax their products today? Do you think consumers would enjoy it? Can we ever prove 100% that this was the cause? How many years back would we need to try to retroactively collect these taxes? Can we even legally do so? Just exactly how much do value do you assign to damaging a baby or young child's brain so that you can appropriate tax gasoline for the effect?

Now take everything I just said and apply it to carbon dioxide and global climate change and see how well it's working.

When applied to the commons - primarily the environment - unregulated capitalism is an absolute failure. Attempting to apply more market forces to it only works if your goal is to hasten the revolution that swings things too far in some other direction.

Comment Promises, Promises (Score 5, Funny) 574

She also set a goal of installing half a billion new solar panels within her first term

Come on, even working four years straight there's no way she can install that many solar panels!

On the other hand, if she's doing that there's no way she has time to screw up the country like past presidents... OK, i'm in, as long as she keeps her promise to just install solar panels.

Comment Re:Wait, you have to TYPE the password??? (Score 3, Interesting) 365

If your password is "OPnuo(I&n hKUYNB68IOnih4wOIB*GBi234t73" as it should be,* then yes...

Parent was modded funny, but this is what your passwords should look like -- long and random, and typing them is a PITA. Any web site that disables pasting or prevents your browser or extensions from auto-filling passwords is broken. The sad thing is that most sites that do this (other than those that do it by accident because the devs are clueless) do it because they think they're increasing the security of their users' accounts. They're not.

Solutions like LastPass et al are the best, but honestly just using your browser's password database is better than reusing passwords everywhere. And Chrome and Firefox (at least, perhaps others) offer the option of keeping your passwords synced to all of the devices you use, optionally protected with a master password. Browsers need to offer password generation as well. I think some are working on it.

Of course, the real solution is to get rid of passwords. Web sites should switch to using OpenID authentication. Yes this means that most users will use their Facebook or Google logins, which means that, essentially, the site has outsourced its account security to those other entities. So what? If the developers of random web sites think they can do a better job of account security than Google or Facebook -- they're wrong . I work for Google and previously spent a decade as a security consultant in the financial industry and after seeing how they all work from the inside, I would feel much more secure about my bank account if I could use my Google account (with 2FA, plus all of the analytics and monitoring Google does) to log into it rather than trusting the bank to do a decent job with password-based security. I haven't seen Facebook's infrastructure, but I know people who work there, and they're good. Far better than you'll find at a typical bank, much less J. Random Web Developer.

Comment Re:How much is an AG these days? (Score 1) 256

yet most people somehow attribute to "whore" a worse meaning

Somehow?

Our market-value vigilance over who is zooming whom dates back a good six-million years.

Nowadays we get more upset when someone unworthy buys a home on our street, but the underlying sentiments were once the same.

This modern "whore" make-over as a small proprietor with high integrity is primarily a byproduct of dense urbanization, where there's an infinite number of fish in the sea to whitewash our old instincts—instincts pre-dating fire, language, cities, and agriculture.

"Somehow" you sound like you just fell off the turnip truck, five minutes ago.

Comment Re:Too big to fail (Score 1) 256

That is, the Australian government has $498 billion to spend on whatever, but Walmart gives most of its $468 billion on suppliers.

That's the least comprehension of "whatever" I've ever seen. But you're not first. It's a 100,000-way tie.

The vast majority of government expenditures are written into law, and the benefits go right back to the same people who provided the revenues. A government enjoys great discretion in how it expends, but not much discretion at all concerning what it expends upon.

Certainly in the circular flow, the government's "friends" skim a lot of cream. And why shouldn't they? They're all upstanding businessmen (and businesswomen) engaged in the profit motive, possessed of the oldest, most conservative, barnyard business model:

1) Pick winning horse.
2) Milk cow.

Comment Just mobile? (Score 2) 259

After years of abuse, I just instantly close a website now if it decides an interstitial ad is needed. Regardless of where I am browsing.

No content is worth the suffering, no video can have enough cats to justify the anguish.

I have no idea if my own droopy matters at all, but I like to think window closure after interstitial presentation is a metric tracked and at least I am increasing it.

Slashdot Top Deals

Thus spake the master programmer: "After three days without programming, life becomes meaningless." -- Geoffrey James, "The Tao of Programming"

Working...