If I bite into what looks like a chocolate chip cookie and get spam, I’m going to kill everyone in the room and then myself.
- 0 Posts
- 15 Comments
What, you don’t want to go to a restaurant where the only things on the menu are fairy bread and cans of VB?
I’m guessing Outback Steakhouse doesn’t really count lol
Still a better drummer than Lars Ulrich
You should cross post this to /c/THE_PACK
Technus@lemmy.zipto
Technology@lemmy.world•I don't like passkeys | Ethan HawksleyEnglish
0·11 days agoThat’s what CSRF mitigations are for.
Do you actually understand how any of the modern web works or does your knowledge stop at W3Schools tutorials from the mid-2000s?
Technus@lemmy.zipto
Technology@lemmy.world•I don't like passkeys | Ethan HawksleyEnglish
0·11 days agoBitwarden lets you store passkeys in its vault, which I think is what you’re asking for? It’s mentioned in the post too.
No. I’m talking about using the password to directly derive the passkey. This would eliminate the need to store them in something like BitWarden.
Technus@lemmy.zipto
Technology@lemmy.world•I don't like passkeys | Ethan HawksleyEnglish
0·11 days agoIn the scheme I’m proposing, the password never gets sent to the server.
The issue of password reuse is the password getting sent to the site, because the prevailing approach is to hash the password server-side. Passwords leak because they get stored in plaintext, or hashed using outdated algorithms, or get logged with request metadata–bottom line, they end up stored somewhere that an attacker can get their grubby little paws on them, or in a way they can reasonably recover them.
Using a master password to derive a passkey client-side isn’t any different than using a master password to unlock a password manager. It just cuts out the middle step.
Technus@lemmy.zipto
Technology@lemmy.world•I don't like passkeys | Ethan HawksleyEnglish
0·11 days agoI feel like there’s some potential in password-derived passkeys, which would get around the storage and hardware lock-in issues. It’d essentially be a master password like for BitWarden, but instead of needing an app to store a bunch of generated passwords, the master password could be all you need to authenticate.
Most of the sources of compromise for regular users would be eliminated because the password never leaves the client.
I’d love to have a backyard someday private enough to try this, not for any new age healing reason, I just wanna know what the warmth of the sun on my taint would feel like
Irish jokes never left
Fire Department Chronicles on YouTube has some really funny skits, but the complete lack of respect for the 180 degree rule or any sort of consistent blocking/sightlines can be really distracting: watching this, I have no idea where each of these characters are standing relative to each other.
Technus@lemmy.zipto
Technology@lemmy.world•Nobody Will Say Why Every Major AI Chatbot Suddenly Went Down YesterdayEnglish
0·29 days agoReally? No one’s posted this yet?
Relevant XKCD: https://xkcd.com/908/



All the messaging about fast charging speed is focused on the wrong thing. EV drivers should be able to do the vast majority of their charging at home or at their destination. The messaging should be about getting chargers in more homes, apartment complexes and workplaces. Speed doesn’t matter as much if you’re going to be parked for half the day or overnight.
Fast charging stations should only be necessary for road trips, where you should be taking a break every so often anyways.