sylver_dragon

joined 1 year ago
MODERATOR OF
[–] [email protected] 8 points 1 day ago

Aren’t they inherently less secure than a TOTP code?

They can be, depending on the types of threats you expect to face. If physical theft is an expected threat, then a hardware token runs the risk of being stolen and abused. For example, your attackers might just buy off cops to rob you and take your stuff. Having the physical device locked with a PIN/Passcode can mitigate this threat somewhat. But, that just becomes another password the attackers need to figure out.

On the other side of the coin, TOTP applications have started offering Cloud Backup options for accounts. What this demonstrates is that it's possible to move those accounts between devices remotely. A hacked device means those codes may be exfiltrated to an attackers device and you will be none the wiser. Good security hygiene and device hardening can help mitigate these issues. But, it also means you need to a lot of trust in a lot of third parties. Also, you need to be unimportant enough for an attacker to not burn a 0-day on.

Ultimately, security is all about trade-offs. If you worry about physical security and don't expect to face a threat which might compromise your phone, then a TOTP app might be a better option. If you are more worried about a hacked device being used to leak credentials, then a physical token may be a better choice. Each way you go has some ability to mitigate the risks. PIN for a physical token and device hardening for TOTP. But, neither is a silver bullet.

And, if your threat model includes someone willing and able to engage in rubber hose cryptanalysis, then you're probably fucked anyway.

I’ve heard that in the US, the 5th amendment protects you from being forced to divulge a password, but they can physically place your finger on the finger print scanner.

Ya, it's a weird space that you cannot be legally forced to divulge a password, except in cases where the content of the drive is a "foregone conclusion" (as defined by the US Supreme Court). But, they can absolutely collect biometric markers (including forcing a fingerprint scan).

[–] [email protected] 3 points 1 day ago (1 children)

As far as the rest of it, it seems to be happening with every filament I slice in Prusa slicer.

This just reminded me of an issue I was facing recently. I also use Prusa Slicer and was having a hell of a time with my prints. It turned out to be the "Arc Fitting" setting.
In Print Settings - Advanced - Slicing look for the *Arc Fitting setting. When I had it set to "Enabled: G2/3IJ" it just completely borked my prints. Just weird problems all over the place. As soon as I set that to "Disabled", it cleaned up my prints considerably. Not sure exactly what I'm giving up there, but I do know I'm getting much better prints.

[–] [email protected] 7 points 1 day ago

I'm glad to see them trying and I really do want to see competition in the digital game storefront space. However, I have zero trust in EA to not try and fuck me as a customer at some point. So ya, no matter how good of a fee structure they offer devs, they will continue to lack the one thing devs actually care about: customers.

Also, as a Linux gamer, it's really tough to consider a store front which doesn't offer a Linux client. Sure, I might be able to get their app running in Wine. But, at that point, maybe I should just go support the company which is supporting me.

[–] [email protected] 2 points 1 day ago (3 children)

If you haven't yet, try a cold pull and see if that helps. I personally just do a cold pull every time I change filaments. Maybe it helps, maybe it's overkill, but I rarely have issues around clogs.

Other things to think about:

  1. Does this happen with other filaments? Maybe your current filament is wet and needs drying. Maybe you just got a bad batch.
  2. Does slowing down the print speed for infill make a difference? Perhaps this filament is just flowing differently and you need to change the printing temperature, flow rate, or just slow down.
  3. How old is your nozzle? They do wear out and a worn out nozzle can manifest as all kinds of wonky problems.
[–] [email protected] 14 points 1 day ago (1 children)

What Im observing though is more and more indies filling the void with smaller and cheaper games due to easy access to digital distribution. Not exactly a new take as its been hapening for over 15 years now. Interestingly, Epic seems to not take the same stance as Steam does in this space. Where steam gives pretty much any shovelware the same chances, Epic wants to be super picky about these low budget titles. Where is Epic’s Balatro?

This reminds me a lot of the days of the original PlayStation (PS). Nintendo was the large, dominant company. But, they were also really, really picky with the games they let on their platform (still are). Along comes Sony with a better physical format and a willingness to let just about anything on their system. And there were a lot of terrible titles on the PS; but, there were also some real gems from smaller devs and lots more choice for people to find what they wanted to play. That openness and plethora of options drew people to the system. Sure, Nintendo is still around and still a juggernaut, but they gave up a lot of market space to Sony.

Sweeney and many of the big studios seem dead set on trying to replicate lightning. They keep churning out Fortnight clones, live service games and lootbox infested grind fests. None of this is because they want to make a game for players, it's all a bald-faced money grab. And it comes across so clearly in their games. Yes, big budget games cost a lot of money and I don't begrudge studios trying to make money. I'm more than happy to throw money at devs who make a great game (I just pledged ~$250 at the Valheim Board Game project, based mostly on the fact that I fucking love Valheim). I've also bought into way too many Early Access games, because they looked like they had the bones of good games. But, the big budget games seem to get lost trying to pump every last dollar out of your wallet and just quickly become a turn off.

I remember one particular instance in Dragon Age, where an NPC had a "Quest Available" marker floating above his head. When you talked to him, you quickly discovered that you could buy his quest and the game was happy to kick you over to the EA store so that you could buy his quest right there. Fuck that noise. I'm not against DLC, but that sort of "in your face" advertising pisses me right off. Hell, I'm one of those weirdos who likes the Far Cry series. I put tons of hours into Far Cry 5 (seriously, the wing suit was just good fun). Far Cry 6 was ok and I did finish it, though the micro-transaction spam grated on me hard. After that experience, I'm not sure I want a Far Cry 7.

And I think that points to the elephant in the room. Big publishers, like EA are so focused on making profits, they have lost sight of making a good game. Give me a solid, complete experience. Give me good controls, enough story to hold the action together and just a general sense of fun. Once that is in place, then maybe throw hats for sale on top of that. But, when lootboxes and micro-transactions are core to the gameplay and the game is balanced to force you in the direction of buying that crap, fuck your game. If the core gameplay is designed to suck so much that I want to buy cheats to bypass that core gameplay, I'll save myself a bunch of money and just skip the game entirely. There are way too many options available out there, which don't suck, for me to waste my time and money shoveling your shit.

[–] [email protected] 4 points 2 days ago

weirdos who bought a bunch of bud light only to shoot it after

In fairness, a bud light can being ripped apart by a .22 hollow point is a pretty awesome sight. And what else is canned horse piss good for?

[–] [email protected] 7 points 2 days ago (1 children)

writes Nestler. “We want to hear from you when you think Reddit is making decisions that are not in your communities’ best interests. But if a protest crosses the line into harming redditors and Reddit, we’ll step in.”

Translation: We don't really give a shit what you think. Now shut up and generate that content for us to sell to AI companies.

[–] [email protected] 3 points 2 days ago

According to T-Mobile's 2023 Annual Report they had $8.3 Billion in Net Income in 2023. A $31.5 Million dollar settlement isn't even a rounding error. Unless and until these fines start actually cutting into profits, in a significant way, businesses aren't going to care about cybersecurity.

We really need to take a page from the EU's GDPR and start assessing these fines as a percentage of global annual revenue. Quit dicking around and make the fines high enough that companies make the secure choice, rather than the cheap choice, because the ROI for the cheap choice includes a high risk of "fuck you" level fines.

[–] [email protected] 4 points 2 days ago (1 children)

While I don't agree with the criminalization of marijuana, it's really rough when it comes to a prosecutor and a law they may not like. Step back and ask the question, "should an Attorney General (AG) be allowed to not prosecute laws they don't agree with?" You might be willing to say, "yes" for laws you also don't agree with; but, what happens when it starts to cover laws you want to see enforced? Should "prosecutorial discretion" effectively allow an AG a complete veto power over the laws as passed by the State and Federal legislatures?

As much as it may suck for the person in that position, it would be really bad for democracy to allow that sort of power. We empower an AG to enforce the law as written. But, we also expect that they will enforce the law as written. So ya, I would expect that Harris (or her office), as AG, prosecuted marijuana cases. That's really what the whole "rule of law" thing means. It means the laws, as written, being enforced on all people. And it's up to us, the people, through our representatives to get that law changed.

And hopefully, this will work out to be more than an empty campaign promise. Though, I don't plan to hold my breath.

[–] [email protected] 14 points 3 days ago (1 children)

Some employees have accused Dell of trying to shrink its workforce with this policy

There's the real goal. Cut headcount without directly cutting headcount. Of course, the headcount which bails first will be the highest performers with the greatest ability to find other employment. But, that won't show up on the bottom line for a few years.

[–] [email protected] 3 points 3 days ago

Necessity is the mother of invention. Laziness is the father.

[–] [email protected] 2 points 4 days ago

Although thinking about it I could clip the PEI to the glass giving it a flat bed…

Having had a similar issue, actual bed more warped than a TV preacher, and a dead, impossible to replace leveling sensor. I moved to a glass bed. But, now that you mention it, this seems like a great way to get then PEI adhesion and have the bed actually level. Just ordered some larger clips and I'm gonna try this out.

 

I recently used Firefox Nightly on my Android device, in a private tab, to login to gmail. After I closed the browser, both via the "quit" menu icon and via swiping the Firefox away in the Overview, I had expected the session information to be deleted and the next time I came back to gmail via a private tab, to be required to login again. However, this was not the case. Despite closing out the browser, something seems to have survived and the I was immediately logged back into the gmail session.

Is this some sort of expected behavior? Shouldn't closing out the browser delete all session information from a private tab? Is there something I missed that maybe I'm not actually "closing" the browser?

 

My daughter wanted a "Gorilla Tag" birthday. And my wife wanted me to print some party favors for the guest kids. Not my model, but they are churning out ok-ish.

 

I'm currently purchasing a new GPU and specifically settled on the MSI 4070 Super. I'm all set for everything except connecting the display to the card.

Currently, the display I have (which isn't being upgraded for now) only has two input options: DVI and VGA. The new GPU only provides HDMI or Display Port. This isn't really a problem as adapters/cables exist to go from Display Port/HDMI to DVI-D.

But, the question I have is, which is the better option, or does it make any difference? And, are there any "gotchas" I should watch out for when buying the cable?

I realize that I am likely over-thinking this, but I would rather ask a stupid question than make a stupid mistake.

 

Just got started with this game (PC - Steam version). It's fun so far. I had really wanted to use my controller. But, the aiming movement is so sluggish. I've tried pushing the "Aim Sensitivity" up to 10, but still felt like I was turning through molasses. Is there anything which can be done to speed that up, or is the controller just fundamentally slow on PC?

Using an Xbox controller via Bluetooth. And the issue isn't lag, it's the rotation speed in game.

 

The politically divided Virginia General Assembly approved long-overdue budget legislation Wednesday, voting in an unusually fast-paced special session to both reduce taxes and boost spending on public education and mental health as part of the package.

 

The free Friday ride program seems to be having the impact the Virginia Railway Express wanted when the commuter rail system decided to offer it earlier this year.

The program started on June 2 and will run through Sept. 1. The aim is to draw new and non-traditional riders to take train trips north and back home.

So far, the program has increased average daily rider trips for those Fridays by around 40%, from about 3,500 to 5,000

 

As a way to kick off migration from Reddit to Lemmy, let's start with a classic thread. So, what have you done with PowerShell this month?

For bonus imaginary points, have you done anything in regards to the Great Reddit Migration?

view more: next ›