If they arrest someone to gain access to their key, they don’t need this attack to use their key. They can just use their key.
If they arrest someone to gain access to their key, they don’t need this attack to use their key. They can just use their key.
One thing the article doesn’t make very clear is that for 2FA the PIN requirement comes from the site itself. If the site requires User Verification, the PIN is required. If not, it is not prompted even if set and this attack is possible. The response to the site just says they knew it.
It is different for Passkeys. They are stored on the device and physically locked behind the PIN, but this is just an attack on 2FA where the username and password are known. (In depth it’s more than that, but for most people walking around with a Yubikey…)
It also seems limited in scope to the targeted site and not that everything else protected by that specific Yubikey. That limits how useful this is in general, which is another reason it is sort of nation-state level or an extremely targeted attack. It’s not something your local law enforcement are going to use.
I think the YubiHSM is a much more appealing target, but that isn’t so much a consumer device and has its own authentication methods.
I was confused how a resume or application would be largely affected, but the article points out that software is often used to look over social media now as part of hiring (which is awful).
The bias when it determined guilt or considered consequences for a crime is concerning as more law enforcement agencies integrate black box algorithms into investigative work.
Amazon is notorious for combining stock, “the seller” often doesn’t matter.
I think this is the crux of the article. In the past most people have considered photographic evidence to be very convincing. Sure, you could be removed from a photo of Stalin, and later people could do photoshop (with varying realism), now it’s a few words to make changes that many people believe without hesitation. Soon it will happen to video too, very soon.
Most people are not ready for it. Even shitty AI photos on social media get huge reactions with barely a handful calling them out.
Sir, this is a Wendy’s.
I think they gave people time to get over the hype and they saw that what they had was good enough. Especially once inflation hit and they had less extra money.
The game Overlord on the NES had the best intro music of the generation, IMO. It was a port of Supremacy from Amiga and other PCs. The Commodore 64 version had really great intro music too! (I love SID music and warez chip tunes) The Commodore intro melody was later used in a Machinae Supremacy song.
I really enjoyed the game StarTropics too. It had real world tie in stuff with physical media (anti-piracy, but it was neat), and I enjoyed the music and story. The second StarTropics had graphics that blew my mind, everything just looked so smooth.
Amazon sold at a loss, but I don’t imagine the employees or suppliers and their employees feel like being paid was a waste.
Laptops are often taken outside the network.
Do xsnow and xpenguins next!
Really great article, and thanks for posting the text of it.
Facebook is weird for me because it triggers my FOMO, but then if I use it all I see are a ton of random things with the most toxic people in the world living in the comments.
And similarly I just realized why my friends on instagram use stories and not posts, because for the most part stories is the only place I see content from people I know anymore (and again the FOMO).
I really relate to the sentence at the end, “there are people there but they don’t know why and most of what they are seeing is scammy or weird.”
My only real problem is I still use windows more than full screen, barely ever use workspaces, and those are two workflows they really want someone to use.
I really like Fedora, but the release cycle is too fast for my tastes. Also I find Gnome distracting these days.
That’s why after 20+ years I use Mint or LMDE. I don’t have the time or interest to tinker the way I used to unless I’m getting paid for it. Mint was the thing that got me to leave Fedora.
IMO most of the lore is in the physical novels and later games that go more into story. Myst and Riven sort of drop you into an existing universe without explaining much and then you can learn some through bits and pieces as you go.
That combination works in Brave to search the forum (prefixing !ddg or !d) I’m surprised it doesn’t in Searx.
Galaxy Watch, the original Pixel Watch and the Apple Watch have no charging contacts. It’s really the way to go.
The contacts have been an issue forever, like I remember it messing up a Fitbit a decade ago. Really crazy that it’s still a problem.
With that kind of leadership we should be thankful he can’t run for president, or he’d end up voted in.
Before his Twitter addiction it was much easier to think of him as a rich genius like you see in comic books, mostly since nobody knew what he was thinking. He’s also managed a celebrity-like persona that someone like robot Mark Zuckerberg could never pull off. That and money will always get hangers on.
Harder on the corporate side, but this has been an issue in the warehouses.