@raccoon@N33R make it secure, he says, as if that's the easiest thing in the goddamned world
i don't like google or github or who the fuck ever either, but they can afford to hire a cybersecurity analyst. with the $0 you pay me to use my service, i cannot.
@AVincentInSpace@furry.engineer@N33R@fops.cloud If you don't check your emails that's on you. Forcing people to use a literal data harvesting company and their garbage TOS because you can't be bothered to make your own database and make it secure is immoral in my opinion.
I stand by my meme and it's message. If I can't make an account I just don't use the website.
@raccoon@N33R and that's fair enough. no outfit is perfect. but when discord gets a data breach, it makes the news. everyone has to care and everyone changes their password because of it. (or they do if they're smart, which most people don't.)
when the smash mouth message boards get hit with a data breach, and you don't happen to see that corporate half-apologetic email, you might not even *know.* it might happen once or twice a MONTH for all you know. the people running the website might not know either. at least when discord got breached they found out and told everyone within 24 hours
@AVincentInSpace@furry.engineer@N33R@fops.cloud I don't know if you are oblivious or of you are playing dumb to turn the things in your favor, but discord is one of the bullshit things websites ask you to login with. Google, github, facebook... They all hava data breach.
@raccoon @sun@shitposter.world @N33R i have a homework assignment for you, type "php password-hash vulnerability" into your search engine of choice and tell me how many results you get back.
I personally believe that responsibility in this regard is best left decentralized.
Naturally, no one expects your forum or whatever to have the same level of security as Google or Facebook, but it's also a less enticing target. The kind of attacks that are visited upon Google's databases are not going to be leveraged against your service because you don't have as much. I don't expect you to be a super de duper security analyst, which is why the password (and maybe even the email/username) that I use on your service is not the one that I use everywhere. If you make a mistake, and my password is compromised somehow, then I just need to change it for your services, because I take some of the responsibility of my security on as well. So you take a chunk of responsibility, and the user takes a chunk, and we don't need to rely on google. Provided you keep your software up to date, and don't make any glaring mistakes, that will be fine for most users. Let's not make the perfect the enemy of the good.
Also, I think it's a mistake to think that "a system is inherently safer because it has more resources". Google is a closed system. You're not taking into account infrastructure sprawl, increased probability for malicious actors, bureaucratic negligence, misappropriation of resources, failure on the account of contractors/data aggregate partners, etc etc. Just because the paychecks are big doesn't mean everyone is incentivized to be perfect. In fact, if pay is regular, and systems are large and complex enough, compensation can become completely decoupled from incentive. Everyone knows a well-paid manager or employee who just skates by because he hasn't gotten caught yet. I think it's more responsible, and safer for everyone, to reduce attack surface and mitigate risk by spreading it around, rather than giving the keys to the city to one guy and hoping he doesn't screw up.