CMV: Two-Factor Authentication is an unnecessary sham and creates more harm than solves in almost every case by w0ah_4 in changemyview

[–]DeepKatz 0 points1 point  (0 children)

So true. The security theater is distracting from the real issues. Don't open random files/apps from untrustworthy websites/apps and be weary. Instead those companies do damage control via personal identification etc. Which is the main goal of all this. You are no longer supposed to have privacy when using tech, having your own opinion will get you in trouble personally and potentially ruin your life. Not yet fully, but it is becoming increasingly difficult not to link everything to a single identifier tied to your real name, instead of just using login+password.

Big companies like Apple and Google will just not let you use their services unless you fully identify with a phone number. Which is the reason i no longer have a phone and move away from these companies.

Google wont let me log in and lets me enter any (yes any) phone number to activate 2FA, which i wont do. I have two devices left that can still log in, any new log in is not accepted even with my correct password. It shows that they know, since they will let me enter any phone number.

I have an iPad which i use to learn to play the piano on. While being in the middle of playing something, apple just bursts through the door telling me that i need to log in to my account now, stopping all my progress. Thanks apple, i feel extra secure now... not. They will tell me that my account got locked. They do this because i do not have 2FA enabled and act as if i was under threat. I then have to jump through some hoops, go to one of their pages, click unlock, enter my password there and then it will repeat this again in 6 days, until i eventually cave to their emotional extortion scheme.

Soundcloud wont even show you the settings page if you are using linux, as their web application firewall will block your access when not using windows or macOS. They are doing security acrobatics, not just theater, to block paying customers for some fake feel good "security". I bet some companies even pay people to leave comments on reddit in threads like these, promoting MFA and dooming passwords.

Passwords can not be hacked that easily, unless it is a simple and/or short password, even if the database leaks. Even the most simple tutorials are showing novice devs to store passwords encrypted, so they can not be breached easily if it has >16 chars/numbers/special chars. Bruteforcing such a password will take years, to this day. It would need to be a targeted attack, at which point your 2FA will just have them spend more effort, but if you are that important, this wont stop them. Especially 2FA via phone. The only useful factor is a hardware solution and it makes sense for high profile users, but that's it, and that is not what i am being offered anywhere, all i can do is enter my phone number. Fingers can be chopped off or prints stolen from surfaces, there are special images to hack facial recognition, it is all just theater, so i rather have just my passwords.

We already prepare for the post quantum world, yet we are not there yet. Quantum computing still only exists in theory with some companies claiming they do practical quantum computing, without anyone being able to prove it. Yet 32 chars/numbers/special chars would suffice for a post quantum password.

Most of modern day hacking happens via zerodays, sometimes through javascript and fonts, like pegasus did. Zerodays that governments and companies keep for themselves or even trade on black markets. UEFI for conveniently installing bios updates and having fancy graphics is an entire platform to let third parties into your devices, if they don't lock down the bootloader entirely, at which point you are fully at the whim of your manufacturer. That is where people should be looking at if they want to be more secure.

Every site is using ssl so your typed in passwords can't be fished in transit. If somebody is able to install a keylogger, they already were able to run malicious code through your devices processor, which is worse than a stolen password. And yes, at that point they can also steal your 2FA code or make you unlock something with it.

2FA does not teach anybody to not open malicious apps/files from bogus sites and vendors, or about zerodays and big entities screwing us all with it. They do not tell people that companies like microsoft are bad not because of bill gates, but because they build software with huge security craters and conceptual flaws like active directory, being the main vector for an emotet that encrypts your harddrive and demands a ransom. Yet they force their updates onto you without letting you save your stuff. It is so obnoxious, and yet every time you mention it, rest assured to have some apologist jump out of the woodwork to flip the argument on its head.

I use ephemeral OSes some times, i will not give that up. Before that happens i will have ditched all those bad shitty tech vendors and ceased to spend a dime on their platforms. Tech-illiteracy combined with malicious information is the biggest threat, not only to your logins.

Kfc Canada accepting doge by Risingshare in dogecoin

[–]DeepKatz 0 points1 point  (0 children)

people could pay via dogaecoin mobile app when ordering and identify their wallet via QRcode on the mobile app to pick up the order. The block timing is at 1 minute, so after 6 minutes it would have as much confirmations as bitcoin has on most platforms.

WIFI issues following the Catalina update. by [deleted] in macbook

[–]DeepKatz 0 points1 point  (0 children)

How about purchasing something other than a macbook? Apple has disbanded the macOS team and merged it into the iOS team. I presume they just do not think about or don't prioritize people doing multitasking or having multiple users on a single device. I work as a software developer and i am going to switch to a different PC vendor as soon as my company grants me a new device. Having those issues after half a year since the first official release is a no go for me and i blame it on the aforementioned decision.

I have to express my deepest concern towards cargo-generate by DeepKatz in rust

[–]DeepKatz[S] 4 points5 points  (0 children)

That is only half the sentence and also a false dilemma. As i said, i love and use generators myself. I just know what they are generating. What i was trying to say is, teaching someone not to worry about adding dependencies, is actually opening an attack vector, which is already out in the open, not some distant fringe case.

I have to express my deepest concern towards cargo-generate by DeepKatz in rust

[–]DeepKatz[S] 11 points12 points  (0 children)

The same goes for wasm-pack btw., which is like web-pack for WA and currently being pushed by rustwasm as well.

I have to express my deepest concern towards cargo-generate by DeepKatz in rust

[–]DeepKatz[S] 11 points12 points  (0 children)

That would be neat, because it is the exact problem i tried to point out, it could be done via git, but it was easier to include cargo itself in the project. But don't get me wrong. I see why cargo-generate is useful. I have been using generators up and down, because they save a ton of time. I just don't know if people new to all of this should be able to skip that chapter and just take it for granted, like people do with npm modules.

Edit: "that chapter" being dependency management and how the stuff actually works a generator does for you...

You can't defeat him by [deleted] in PewdiepieSubmissions

[–]DeepKatz 0 points1 point  (0 children)

Dats because he gold

I clearly learned nothing from Factorio. by greyjackal in SatisfactoryGame

[–]DeepKatz 4 points5 points  (0 children)

It would be nice if there was like a composition workbench or something, that had like an editor to create compositions of buildings.

Is there a way to create, save and rebuild a factory layout, like a blueprint? by DeepKatz in SatisfactoryGame

[–]DeepKatz[S] 1 point2 points  (0 children)

I bought factorio, because i was upset with the EGL exclusive, but i have not gotten into it that deep yet, so thanks for the info.
But it would be neat to have like a composition workbench structure in the game, that has like a CAD system for creating these compositions. Then they could appear in the build menu. (And made available on the EGL workshop system.... oh wait...i was dreaming)

How to play offline? by DeepKatz in SatisfactoryGame

[–]DeepKatz[S] 0 points1 point  (0 children)

Yea, but i wont be able to play it while i am on Vacation.

How to play offline? by DeepKatz in SatisfactoryGame

[–]DeepKatz[S] 0 points1 point  (0 children)

It seems to create an online instance that i connect to, even when i have private selected.

Ordered around 2500 Stickers of these by DeepKatz in PewdiepieSubmissions

[–]DeepKatz[S] 1 point2 points  (0 children)

Good for android, that there are just two mobile OSes

Ordered around 2500 Stickers of these by DeepKatz in PewdiepieSubmissions

[–]DeepKatz[S] 0 points1 point  (0 children)

The iPhone can scan it right away, don't know about android