Comment Re:Have they heard of a PC? (Score 1) 96
The thing to steal is the secret that is used to generate the code. Then the attacker can generate their own TOTP codes whenever they like.
I don't think any UK banks offer it, but I could be wrong.
The thing to steal is the secret that is used to generate the code. Then the attacker can generate their own TOTP codes whenever they like.
I don't think any UK banks offer it, but I could be wrong.
Yes. We need to stop building software as cheaply as possible and put in actually resilient security. We know how to do that, the industry is just completely incapable of self-regulating. Hence we need liability, qualification requirements and unpleasant punishments for screwing up. Incidentally, that is how all other engineering disciplines made it to maturity. IT will not be different.
That is rather unlikely. Not all Catholics support child-rape, war crimes and serial lying. To be fair, some apparently do. And actual moral conservatives cannot vote for Trump at all.
Yes. And completely forgetting that this is a strategic thing.
Tribalism does not work in the modern world. And yes, they can see what they do to others, so "evil" is clearly not enough, but it also is clearly part of the mix.
Cult-followers are not rational. Even in a small cult, the best the men can hope for is getting some rare attention and the women (and girls) can hope to get raped. In a large cult, things are worse, obviously.
Sure, but banks care far more about your money being stolen than Facebook does about your account being hijacked.
There's an open bug to fix that, but who knows if it will gain any traction.
The problem with TOTP is that if it was allowed there would be a lot of fake TOTP apps appearing, which steal your secrets. Email is bad because people never log out of it, where as your banking app probably times out after a few minutes of inactivity.
The EU is also proposing to allow everyone to opt out of algorithmic feeds, and IIRC for infinite scroll to be opt-in.
There will still be ads, but the feed will otherwise be chronological, or random.
That's not how it works, there is no way it would create a list of places you have verified yourself to, there is nothing to steal.
Android and iOS already have systems like this for apps that require security, such as some banking ones. The app can ask the OS to check that it has not been tampered with. People who root/jailbreak often find that such apps stop working.
Nothing is recorded, it's just an API call that returns a yes/no response to the question "is the system in a secure state?"
Similarly, the EU's app returns a yes/no response to the question "is the user over 13/15/18?" The app calling the API decides which age it requires.
There is no identifier, nothing leaves your device, there is no record of the API call (at least not in the EU app, which is open source), nothing to steal.
I suppose in theory someone could steal the EU's signing keys and make their own fake version of the app with logging, but if you are worried about that you better throw your phone away because the same fear applies to all the other apps, including the web browser, and your SIM card, and the OS updates. Some years ago British "security" service MI5 stole SIM private keys from manufacturers. We also know that US security intercepts hardware during shipping to install backdoors, so unless you got your phone from the factory in China... Who you presumably think already backdoored it anyway.
You are just demonstrating that you do not even have a basic education in Physics.
Ah, no. The problem is primarily no-skill attackers with LLMs going after targets that the high-skill attackers would not have bothered with. Sure, drastically reduced time-to-exploit-available is a serious problem, but doing a competent attack is far more than that.
"High IQ" obviously means being able to pass that dementia test!
Seriously, get therapy. You do not have to be miserable all the time, it is a choice you made.
fortune: cannot execute. Out of cookies.