Re: Lose your device, lose your access
This, of course is the sort of rubbish that's specifically advised against when it comes to good practice.
42420 publicly visible posts • joined 16 Jun 2014
" I assume you use a different long, random password on every site and also different username...."
By and large, yes.
Of course the sites that want an email address as a UID are a bit of a problem. If they're important (i.e. my money's at stake), they get an individual email address - one reason to have a personal domain. Sites which want an email address just for marketing purposes to be annoying (hi, there, booking.com) get an individual email address which will be blocked between my usage or one that's discarded immediately as appropriate.
Sites which issue their own UIDs can be a bit of a problem too in that sometimes they follow a predictable pattern.
It's a curation problem but one largely due to individual services' predilection for annoyance. I can't imagine passkeys being different in that regard. Essentially the combination of UID and password is just a long string of characters as is a passkey with only the protocol differentiating them.
It's the practicality that matters. As things stand I keep passwords on a laptop with a master-password protected password manager. The laptop login is also password protected, of course. Those two passwords are all I need to remember. The laptop is synced to a NextCloud instance.
I only access whatever the passwords protect from my laptop so if I don't have the laptop available I don't need them anyway and the laptop is a big chunk to carry around so I don't accidentally not have it with me.
If what's being proposed is to replace the password manager by a passkey manager on the same laptop then I have to ask what's the difference (I'll come to that in a moment). Or is the passkey to replace the password that's currently protecting the laptop login? If the latter then it means I have to have the laptop and something else to hand. Given that it's already the case that I need the laptop plus a charged, switched on and in-signal mobile to do some things I know from personal experience that that's all too often a complete fail.
But if you're telling me it's "just" replacing my passwords by something with a more secure protocol and that my everyday usage is unchanged then I'm still going to have to take a look at how that protocol's being implemented. I have one end of that in the form of S/W in my laptop and each remote service will have its own implementation. Oh. Just. Great. We all know what happens next, don't we? Some scrote working for either my laptop OS provider or for the S/W used by one or more service is going to spot an opportunity for an improvement, optimisation or tweak (icon: looking for idle hands) and the whole thing gets screwed on a regular basis - shall we say every other Patch Tuesday?
Though the "I lose the device and I lose access" part is already solved - put the passkey in a password manager that's synced (or in case of hardware keys have a second one).
Good theoretical solution. How do you implement it in practice so that you can have one lost or stolen but not both and yet have that second one available wherever you happen to be in an acceptable time-frame and without needing some sort of access which depends on having a passkey available?
I came here to say exactly the same thing. It's not so much that the device becomes a target for cracking.
We have now reached a point where it's expected that a mobile phone will be to hand, switched on, charged and receiving a signal at all times. It may be lost, stolen, have a flat battery, be in the car, a different room, whatever. Without that availability there's no guarantee of being able to make an online purchase, manage a bank account or whatever. (Being retired it doesn't actually have any functionality for employment purposes.)
The smartphone is rapidly becoming a single point of failure for life. Have we learned nothing?
Data is being collected for long enough to be processed. As a general member of the public entering the place I'd have wanted to know what was being done during that time and in particular, could it put be in the way of some sort of harm or disadvantage? What if it made a false identification of me? What would then happen?
If they tried to answer "nothing" I, and, presumably the court, wouldn't believe them because in that case there'd be not point in having the kit installed.
A test restore can be invaluable for refining your backup creation. The first time we tried that in a DR centre we realised that /etc was so late in the backup sequence it took hours of restoration before we had anything we could even log into to check the files which had been restored. A simple change there made a big difference to the success of the second test.
Take the work of any poet - or, come to that, any prose - from a few centuries ago and there will be changes of grammar and vocabulary since it was written. The reader may no instantly grasp this. Unless the LLM has been trained on Shakespearean English it's going to come up with something that requires less thinking about for a modern reader.
Just the first 4 words of Shakespeare's Sonnet are enough to highlight some differences:
"Shall..." Oops. Wouldn't a modern writer be more likely to write - and a modern reader expect - "Should"?
"Shall I compare thee..." What? 2nd person singular pronoun? How is that to be understood? Growing up in rural Yorkshire that was a familiar expression from the older generation and the protocol was internalised (it's the same as the use of "tu" etc. in French) but archaic today. Would a modern reader instinctively grasp the intimacy of the phrase? Would and LLM select it and if so, automatically use "Thou" on the next line?
And that's only the easy bit before the mind-bending nature of the comparison that's being made, the thought that went into working it out than that would then be demanded of the reader even given that, for instance, a summer lease might be a more common concept in his time.
An alternative would be to patch a couple of incoming calls together and let the scammers try to scam each other.
I sometimes used that approach with email scammers:
"That sounds most interesting. I'm too busy to deal with it personally at the moment. Could you please liaise with my colleague at $AnotherScammersAddress"
After all, they're in the same line of business so it's only polite to introduce people with common interests.
"However, given life has occurred here"
Were it not for the counter-example you'd have to consider so unlikely as to be impossible.
Consider the number of different systems integrated to compose life. You have the RNA-protein synthesis system which depends on having not only the RNA template but also the amino-acid specific transfer RNAs and the amino-acid/RNA specific activating enzymes.
I'll concede that the ribosome might not be necessary and could have evolved later and the same applies to DNA. You still need some mechanism to replicate all that RNA.
That's a lot of proteins, all of which have t be coded for in RNA. Given that RNA itself can catalyse peptide bond formation it's still a fearsome boot-strapping problem if you're powering it by thermal energy and an even bigger bootstrapping problem to find some naturally-occurring chemical energy source that can link to it. If you want to see it evolve beyond consuming whatever stocks of organic chemicals that non-life processes can provide you also need some form of photosynthesis to evolve.
You also have to have the planet not only become suitable for life at some stage in its development, it's got to stay that way whilst all this unlikely bootstrap happens. Given that photosynthesis is going to involve photolysis of water that's going to require a means of dealing with the release of something as thoroughly nasty as oxygen.
It's the improbability of all those things being strung together successfully that you have to set against the number of planets.
It's a big ask and, I think, reasonable to discount until a second example is found. It's also possible to understand the thinking behind the "life arrived in a comet" style of thinking about lefe on Earth - it's a throwing the problem over the wall solution.
sentient alien life exists in our vast, nearly infinite universe.
FTFY
Sarcasm aside this is a statement for which we have evidence and, if you want to insist, you can remove the word "sentient" but with the word "alien" is in there there is no supporting evidence and something I find very unlikely.
The one that decided we all needed a course on "Empowering a quality culture: strategies for excellence", springs to mind.
I think you may have misunderstood the motivation. The course wouldn't have cost that much and leaving of your own accord they don't have to pay redundancy money.
"Back in 2012, the government created a legal obligation for energy suppliers to make sure they completed the rollout of smart meters by the end of 2019. Subsequently, it pushed back the deadline three times, first to the end of 2020, then 2024, and then 2025. As of February 2023, the government launched a consultation on plans to have smart meters installed in 80 percent of homes and 73 percent of small businesses by the end of 2025."
They should, by now, realise that there's a substantial customer resistance, that they've got about as far as they're getting, that it was a Bad Idea and they might as well quit while they're behind.
I suppose what stops this from dawning on them is that it looks just like so many other HMG projects - behind schedule and over budget - that they think that with time and budget it will get there in the end if they really want it.
"Here in the UK we outsourced everything and their dog"
And the way things are going we're outsourcing more and more food production in favour of solar farms, data centres etc. I trust it will be ministers, heads of quangos and tech CEOs who will be the first to give up eating.