• 0 Posts
  • 721 Comments
Joined 1 year ago
cake
Cake day: June 16th, 2023

help-circle


  • I was thinking the debate rules actually saved Trump from his worst impulses. Biden was allowed to speak at full length and Trump gets to appear like he can participate in a civilized conversation while Biden would sometimes go off the rails while trying to fill his time. A lot of his embarrassments started in a decent place, but pivoted badly in the middle.

    Trump confidently lied repeatedly without consequences, and so long as someone is unaware that it’s lies, I could imagine them finding Trump’s rhetoric credible that night.


  • I’ll agree, but he was at the same time more bold, like saying everyone wanted to overturn Roe v Wade. Confident and competent lying can get you far, but if you lie about how the people watching would feel, you undermine all your other lying.

    There are few things more maddening than claiming you know how someone feels more than they themselves do. A very credible liar can be undone if they lie that well on a matter the audience personally knows better. Suddenly all the benefit of the doubt purchased by the confidence is erased.








  • Basically, you have:

    • TOTP - no particular investment needed, so very popular, but a bit onerous
    • Various MFA vendors that tie into their cloud services. I hate these since it means I generally have to get additional apps, with uneven platform support
    • Webauthn/Passkey - Cool, integration with my phone, a Fido usb key, windows hello if applicable, no need for external service, uses asymmetric encryption so it’s not shared secret and it’s more convenient… Almost no one bothers to implement it for their service though, despite it being pretty damn easy.

  • Yes, shared secret based, but not a big deal because it is machine generated and unique per account. The ‘server has your credential’ is only a problem if the credential is reused across services. If you have access to read TOTP secrets from the server, you probably don’t need those TOTP secrets to further compromise the service.

    But webauthn/passkey is a better approach. Properly managed SSH keys are good too, but folks aren’t too happy about how ssh keys are commonly pretty lax. Client certificates similarly would have worked, but never took off. Similar story for smartcards.







  • the stuff you’re asking for doesn’t work that well, but this does

    I didn’t think that this works. The examples where people claim “is just like this” I don’t see as being like this.

    The ones that work are ones that have some relation to their cause. Forcing everyone to really think about an issue Inherent to the act. For example, going about and doing this to parked private jets, which they did.

    Just doing anything to get attention isn’t useful if there’s no Inherent message in the act itself. Especially with climate where everyone already has awareness, just not action.

    Being merely loud is not going to sway hearts and minds in your favor.



  • That’s been my experience so far, that it’s largely useless for knowledge based stuff.

    In programming, you can have it take “pseducode” and have it output actionable code for more tedious languages, but you have to audit it. Ultimately I find traditional autocompletion just as useful.

    I definitely see how it helps cheat on homework, and extends “stock photography” to the point of really limiting the market for me photography or artists for bland business assets though.

    I see how people find it useful for their “professional” communications, but I hate it because people that used to be nice and to the point are staying to explode their communication into a big LLM mess.