Forgot your password?
typodupeerror

Comment Re:Have they heard of a PC? (Score 1) 44

Does it? I regularly access my accounts on five different UK banks from my Raspberry Pi and I don't use an App to verify on any of them.

Congrats to you and your bank? I regularly access my bank from all sorts of web based devices and I log in with a QR handshake using a mobile app. Just because YOUR bank doesn't use a certain method doesn't mean the method doesn't exist.

My 80 year old mother-in-law lives in the EU and regularly accesses social media from her Windows PC. I don't think that she owns a smart phone either so she is going to be particularly irritated by this new imposition.

I've mixed feelings about your comment. On the one side we're starting to approach a society where access to services is increasingly required to be done via a smartphone / tablet device. Not doing so is an actual burden on users who have limited functionality (e.g. accessing government services here in the country I live gives you the choice between using a login, or catching a bus to a council office and queueing with the other old people who don't own smartphones and therefore can't do an ID verification against your drivers license or passport).

On the other side I think social media would be a much better place if people over the age of 65 were forced to stop using it. Unfortunately my mother does have smartphone so we'll need to find some other ways to stop her posting bullshit on social media.

Comment Re:Goodbye (Score 1) 44

it has now correlated your phone with your proxy-browsed history.

You're making wild assumptions into the implementation. There's no reason the authorisation service needs to have any information about your network condition. But since we're talking about an open source implementation the actual process can be verified, even if the direct application cannot.

To governments, it offers a broad range of brand new vectors to correlate you to an identity if you, say, mention you had an abortion or criticize your local strongman leader, since they control the backend infrastructure that establishes the connection between the token and the identity.

Yes I agree this system won't work well in shitholes like Russia, China, or the USA, but in the meantime we have actual evidence that the vast majority of European nations which do have privacy rules for citizens find themselves repeatedly hamstrung by the fact that attempts to breach them land them in constitutional hot water. I get it Americans (rightfully so) think laws aren't worth anything anymore, but the reality in other western countries is no where near as bad.

Comment Re:Goodbye (Score 1) 44

Can I compile it myself, or install it on my GrapheneOS phone? No to both since each country makes its on version and those versions require device attestation.

The open source tool displays how the protocol functions and allows you to verify the only information sent to the service provider is a token. Given the services are not under the jurisdiction of any one provider you need to be of the belief that either it is just getting the yes/no token, or that they are in cahoots with each individual government separately implementing their secret privacy leaking info. And if you believe that I'm sure you have questions about the FBI's involvement in the trade centre collapse too right?

Comment Re:Not completely safe (Score 1) 44

And yet you still have to trust that this system doesn't get back-doored by three-letter agencies.

Congratulations, you just described electronics. I hope you made this post via telegram and got someone to type it into a burner laptop from an internet cafe, otherwise you may be being watched by the boggieman.

Comment Re:Goodbye (Score 2) 44

"Member states run it through issuers they designate,"

Say goodbye to online anonymity then.

Except not. The member state's issuers only issue the certificate of certification that doesn't leave your device. The rest of the online world gets a yes/no token. Such systems are implemented in many different ways by member states for other purposes already.

But hey you don't even need to trust anyone about this. The app that sits in the middle of it all is open source. Go read the code yourself.

Comment Re:Have they heard of a PC? (Score 3, Insightful) 44

The same way your online banking website runs on your PC but verifies your login via an app. App based digital handshakes are a thing, not just for 2FA, but for all sorts of certifications.

Remember you're using a service, the service is responsible for implementing it. I suspect social media sites being social media sites will simply get users to use the app on their phone once or handshake via a QR code.

Comment Only High I.Q. individuals need apply (Score 3, Funny) 129

To be fair, you only need a room temperature level of IQ to be smarter than literally anyone in the current administration so that isn't a very high bar to clear. I'm sure Trump will promote his Mar-a-Largo janitor to AI Czar if he pledges to give Trump a daily hand job.

Wait... no that poor guy is probably in an ICE detention camp.

Comment Re:Boo hoo (Score 2) 51

This is the way things are supposed to work.

While I agree in general bugs getting patched is a good thing, I don't think this particular method is the way it's supposed to work. The PS5 hypervisor is a bit of the white whale, something that absolute experts have spent years prodding and poking at. Now we are in a time where not one but 2 random people suddenly discovered the bugs within hours of each other? I bet you one or neither even understood how the bug worked.

The PS5 got off light, but the reality is now we're in the days of AI generated bug reports, suddenly a bunch of kids burning tokens are all running the same code on the same targets generating the same bug reports and that is an absolute headache for people who actually do maintain software.

Comment Re:Wait, O365 has been enhanced? (Score 1) 89

It doesn't even support S/MIME extensions by default.

You're ranting a lot about a "failure" and "broken" product that none the less makes the entire world go round. You know what doesn't make the world go round? S/MIME. No one cares. The concept of secure email died in the early 2000s. No need to try to shoehorn security into something that has been universally agreed we'll accept as an insecure medium. Why would anyone support it other than to appeal to a handful of Slashdotters with no business acumen and no idea how the wider world works?

Word, and Excel, both examples of terrible showings in their categories, and I don't think it's out of line to say the worst showing in their categories.

And yet they have collaborative features there are unsurpassed by any other software and hence are adopted globally. For something that is the "worst" it very much seems to me that the entire world's economy uses it just fine. It's like politics isn't it. Everything is "the worst" but it does the job.

Case in point, you can't install O365 on the vast majority of Unix or Linux-based systems, which means, Microsoft knows they are not suitable for any professional.

Professionals don't use Linux. Nerds and coders use Linux. Professionals the world over use Windows, software written for professionals is exclusive to Windows. You are typing this on your Linux machine thanks to professionals who designed your device using Windows.

O365 online, is slow, buggy, glitchy, and crashes so often it's like you're back on early versions of Windows.

Stop the fucking presses! Now there's a statement I agree with.

why use some of the worst products the company has designed to make the point?

Because the world doesn't care about your opinion, it only cares about it's own aggregate opinion, and Microsoft's own balance sheet shows the world disagrees with you, even if you'll find individuals who do agree (I'm sure one of them will have mod points and mod me down shortly)

Slashdot Top Deals

Variables don't; constants aren't.

Working...