fedi there is so much full force sloperating happening in open source accounting software...
no, NO look at me fedi, I know it's boring but you need to look at the accounting software, it's bad ok, it's really fucking bad out there, and I don't think your financial situation should depend on whatever logic an LLM spat into a bunch of accounting software without review
but the real issue is that microsoft engineers know this, and didn't even so much as try to program a secure backup feature that doesn't expose the keys, or even give a popup in the installer warning people that their drives will be completely unencrypted and insecure by default without an MS account... or any of the 1000s other things they could do to communicate their security stance to users tbh
@GossiTheDog@cyberplace.social Windows charging people for a pro/enterprise license to encrypt more than the OS drive (while still uploading their keys to the cloud) is also just insane to me
For a long time I think you had to pay for a pro license to even encrypt your drives at all, but luckily they stopped doing that, instead you get to encrypt the OS drive for free and everything else is gonna cost you a few hundred extra dollars 💀
@GossiTheDog@cyberplace.social oh also as a note to all the users who installed windows with a local system account instead of linking your microsoft account
none of you have an encrypted OS drive, it just doesn't encrypt your drives by default if you do that because it can't back the keys up to MS cloud
@skinnylatte@hachyderm.io to be fair in many parts of the world where people do this, healthcare and the social aspects aren't too bad to adjust to, getting a permanent work/residence VISA is fairly easy in places that aren't the western world, a lot of people go to Thailand or Vietnam or Singapore for this, access to healthcare and social services isn't so bad in many cases either
I even knew someone who was actively living in Bali for a long time, and arguably that's just kind of a bad place to exist in, but the guy was so comparatively wealthy that he just bypassed all the issues with money and seemed to live a perfectly normal existence with a high quality of life for many years
@prettygood@socially.drinkingatmy.computer@brettm@swarm.coiloptic.org the software explicitly lets me decide to use an arbitrary location, it should just ignore that my desktop isn't following spec in that case... if I had just slammed "save" and not chosen a specific directory the browser can feel free to create the default one from the xdg desktop spec
@whitequark@mastodon.social@risottobias@toot.risottobias.org@ireneista@adhd.irenes.space the quality of your code and project is bad if you're not implementing 2fa in the modern world, users don't like to do security, it ruins UX most of the time, but it's a necessary thing to do otherwise people will just keep getting hacked and that's far worse for everyone (including the individuals) than inconvenience tbh
@david_chisnall@infosec.exchange I’m starting to think that the concerns about LLMs hurting critical thinking ability might have been seriously underrated.yes, absolutely
@SuperDicq@minidisc.tokyo you should go use something with objectively worse encryption and security then, nobody is stopping you from making dumb choices because you don't like the way Signal works
but everyone else will still recommend it because their tech is good, you shouldn't be confused about that LOL
@SuperDicq@minidisc.tokyo yeah, and they still require phone numbers for signs ups which is dumb garbage, but they also literally invented the double ratchet encryption algorithm for instant messaging, they implemented sealed sender for hiding user metadata, and in various ways have done legitimate research on defending against online surveillance
you win some and lose some, Moxie isn't a perfect human being, but signal keeps getting recommended because it's genuinely doing better than 90% of other messaging platforms out there in terms of privacy for their users, even if it does have dumb shit like google play integration still
@SuperDicq@minidisc.tokyo despite the shitty aspects of their technology they're still genuinely a world leader in privacy preserving messaging protocols tbh
@whitequark@mastodon.social I actually don't know of a single electronic component that isn't just a copy of nature on some level, humans are innovative in the sense that we take inspiration from what is around us and jam it into new shit to see if it works, and not much else lol
So... Steam offers this "shader pre-caching" service where the client will detect your hardware and download pre-compiled game shaders to increase your system performance, which is cool and all, but apparently these shaders are taken from other random people's computer when steam detects a matching set of hardware
So now I'm wondering how much validation is actually done on these shaders, and how this works, and if I can actually just use steam to send random code to random people by pretending it's a shader lol
@tek@freeradical.zone@snickerbockers@freeradical.zone sure, AI is useful sometimes or we would just be ignoring it right now, but it's useful in the same way that an IDE helps you write code a little easier... you'd be stupid and insane to think an IDE could produce reasonable code without someone checking over it and running the system themselves
my main issue with AI is that unlike an IDE the quality is so poor that even an intermediate programmer or user will outskill it considerably without much effort... AI is just sort of stupid, and bad at the jobs we use it for, it's like a self driving car that can't actually drive by itself (which makes it seem pretty damn useless)
@dalias@hachyderm.io I actually do think the automated connections to a remote system for updates are bad and should be removed in this case, but it's just wild to me that you genuinely don't believe in mandatory security updates, and further that you actually seem to not understand that the network traffic from a VPN is itself attack surface... this means that even if you trust both ends of the connection you should still install security relevant patches to mitigate issues on the network or in the protocol itself, at the very least, not to mention bugs that can occur when an untrusted application runs locally
most people don't actually completely trust all the applications on their device anyway, even if that application is granted network access to function, this is why defense-in-depth and sandboxing is such a big field of study still
Just here to vibe and share cool computer facts, your friendly neighborhood tech frog. Will often discuss things like distributed systems, programming, society, and computer security. Politics WILL come up sometimes. Video games are cool too :blobowo:Follow for more fun computer adventures!!