@thomasfuchs Yeah, by itself "source?" can be perceived or intended as aggressive ("your post is clearly false"). Additional context is needed if your intent is constructive ("Where did you get this? I want to share it with others")
I should have been collecting the receipts on a rolling basis; chatter at the time for multiple of these was "deploying fast now for highest risk, doing the rest in a more controlled fashion after".
How many stories of "get popped, then do an emergency FIDO2 deployment" does your leadership need to read before you decide to deploy FIDO2 proactively?
Varnish Cache project to change its name to Vinyl Cache with after the next release (after today's 8.0.0, in March), per @bsdphk:
We have tried to negotiate with Varnish Software for many months about this issue, but their IP-Lawyers still insist that Varnish Software owns the Varnish Cache name, and at most we have being offered a strictly limited, subject to their veto, permission for the FOSS project to use the “Varnish Cache” name.
We cannot live with that: We are independent FOSS project with our own name.
So we will change the name of the project.
The new association and the new project will be named “The Vinyl Cache Project”, and this release 8.0.0, will be the last under the “Varnish Cache” name. The next release, in March will be under the new name, and will include compatibility scripts, to make the transition as smooth as possible for everybody.
No disagreement, though we might need to call it 1.5FA. I think it's hard to overstate the insecurity that comes when users have absolutely zero second factor whatsoever -- it turns the entire world into those random store clerks!
But it's also hard to get companies to treat SMS MFA as they should: as an emergency stopgap to cover them while they make better options available, and to allow users to opt into those stronger factors as quickly, and as early, as possible.
Just doing my undue diligence.ISP vet, password cracker (Team Hashcat), security demi-boffin, YubiKey stan, public-interest technologist, AK license plate geek. Husband to a philosopher, father to a llama fanatic. Views his.Day job: Enterprise Security Architect for an Alaskan ISP.Obsessed with security keys:techsolvency.com/mfa/security-keysMy 2017 #BSidesLV talk "Password Cracking 201: Beyond the Basics":youtube.com/watch?v=-uiMQGICeQY&t=20260sFollowed you out of the blue = stole you from someone I respect.Blocked inadvertently? Ask!Am I following a dirtbag? Tell me!Photo: White 50-ish man w/big forehead, short beard, & glasses, grinning in front of a display of Alaskan license plates.Boosts not about security ... usually are.Banner: 5 rows of security keys in a wall case.#NonAIContent#hashcat #Alaska #YubiKeys #LicensePlatesP.S. I hate advance-fee scammers with the heat of 400B suns❤️:⚛👨👩👧🛡🙊🌻🗽💻✏🎥🍦🌶🍫!