Forgot your password?
typodupeerror

Comment Re: Well "just" vibe code you a new API, then eh? (Score 1) 41

I made the same comment about Googleâ(TM)s SDK. If AI is so awesome, why not just write a single SDK in a single language, and AI build the others on each push? Then devs can use their preferred language and it already has full first party support. Seems so simple⦠and the fact that it isnâ(TM)t being done screams pretty loudly.

Comment Cooperate or Die (Score 2, Insightful) 41

rivals like AMD and Intel offer competitive specs on paper, but their software stacks have struggled with bugs, compatibility issues, and weak adoption. As a result, Nvidia has built an Apple-like moat around AI computing, leaving the industry dependent on its expensive hardware.

Nvidia's competitors need to work together to improve open-source software tooling and to standardize hardware interfaces, or else go the way of Commodore and Tandy.

Comment Re:Rethinking our approach (Score 0) 106

> Throttling is ineffective if you base it on IP address...

I didn't dictate any specific throttling algorithm. You are stabbing a strawman.

> an attacker obtaining the encrypted vault is probably not going to be able to decrypt many passwords,

That may not be how they breach them. It's an extra layer or device that may have an inadvertent security flaw. The more turtles in the stack, there more turtles there are to hack.

Comment Re:Rethinking our approach (Score 1) 106

I'm not understanding why the traditional approach doesn't need throttling. Keep in mind a DOS attack is usually considered a smaller "sin" than a breach(es). If you allow too many retries, then the second sin is more likely. I see no third option*, it's either a DOS freeze or lots of retries.

If hackers find a design weakness in your company's preferred/required password-keeper, they can potentially hack them all. A company can allow multiple keeper brands, but then they either have to vet them all, or accept that some users will select a dodgy brand.

> I read your setup as a global throttle. If that's not what you meant...

* The best throttling and/or DOS defense strategy/algorithm is a more involve topic, but so far not a difference maker in what we are comparing.

Slashdot Top Deals

If you didn't have to work so hard, you'd have more time to be depressed.

Working...