• 0 Posts
  • 142 Comments
Joined 1 year ago
cake
Cake day: June 29th, 2023

help-circle
  • It’s a known phenomenon.

    As it happens, people don’t often post their failures on social media, so if you’re comparing your life to someone else’s, you’re at an inherent disadvantage because you only ever see results.

    If you hang out with people in person and involved in their lives, then you get to experience the process leading to the results with all the failure baked in. It’s the difference between porn and sex.





  • I’m not sure I necessarily agree. Your assessment is correct, but I don’t really think this situation is security by obscurity. Like most things in computer security, you have to weight the pros and cons to each approach.

    Yubico used components that all passed Common Criteria certification and built their product in a read-only configuration to prevent any potential shenanigans with vulnerable firmware updates. This approach almost entirely protects them from supply-chain attacks like what happened with ZX a few months back.

    To exploit this vulnerability you need physical access to the device, a ton of expensive equipment, and an incredibly deep knowledge in digital cryptography. This is effectively a non-issue for your average Yubikey user. The people this does affect will be retiring and replacing their Yubikeys with the newest models ASAP.






  • Godort@lemm.eetomemes@lemmy.worldPost-apocalyptic jobs
    link
    fedilink
    arrow-up
    23
    arrow-down
    1
    ·
    22 days ago

    A few competent project managers would probably help things quite a bit, actually.

    Having a single point of contact for several disparate teams of people doing real work so that they can actually do that work, instead of spending extra time in endless meetings arguing over the best way to implement something that requires multiple people’s input is a valuable tool to have.

    Think of them like a tank in an RPG, taking all the meeting hits that would otherwise decimate the effectiveness of people actually putting the real work in.