Recent comments in /f/technology
adams01pl t1_j85cs2u wrote
Reply to comment by standard_staples in Mozilla plans ground-up UI redesign for Thunderbird email client this July by Hrmbee
Is it running slow on your machine?
xal1124 t1_j85cofy wrote
Reply to comment by R_Meyer1 in Texas Taxpayers Face a $100M Bill to Update Voting Machines with Equipment That Doesn’t Exist Yet by Sorin61
With all the complaining of fake votes, dead people voting, etc., do you think that people would go for voting by phone? People barely know how to construct a password more than 8 characters long. People would have their voting accounts accessed by others, and people would vote for them.
SlowMotionPanic t1_j85cc8d wrote
Reply to comment by ADroopyMango in Millions of passwords stolen from LastPass earlier than company disclosed: Report by BasedSweet
> a piece of paper is much more secure than a database.
Hard disagree. Just require authentication with something like a Yubikey for the best of both worlds. People can take vaults all they want, but they are never getting in it without both the master password and a Yubikey and a biometric component if also enabled.
Unless they kidnap you, in which case you have bigger problems on your hand.
Or one is talking about seed phrases for crypto wallets, in which case they better stamp it into metal and hide it well.
Paper burns and you’ll be locked out for a good long time if not forever. Yubikeys can have a duplicate kept in a safe deposit box. Can’t do that with a paper book in active use.
Discoveryellow t1_j85bhw8 wrote
Reply to comment by standard_staples in Mozilla plans ground-up UI redesign for Thunderbird email client this July by Hrmbee
Because people who didn't use Lotus Notes and Outlook Express don't understand how to use Thunderbird and where to click.
FatedMoody t1_j85bb7t wrote
Reply to comment by Danzzo36 in Millions of passwords stolen from LastPass earlier than company disclosed: Report by BasedSweet
But you could lose it or it could be destroyed
SlowMotionPanic t1_j85b8os wrote
Reply to comment by ADroopyMango in Millions of passwords stolen from LastPass earlier than company disclosed: Report by BasedSweet
The BitWarden example isn’t even comparable. It is 100% user error to use an unknown login portal based off an explicit paid advertisement result in Google.
A paper password book user would fall for the same scam but for whichever targeted sites. They are, in fact, more likely to get scammed because they lack an app like BitWarden which can identify and fill the actual portals thus removing the potential for error.
Password managers with a Yubikey are probably the strongest option for most people honestly.
standard_staples t1_j85alx1 wrote
If they're not going to bring Thunderbird up to modern performance standards, what's the point of putting a shiny new UI on it?
EDIT: Well, the Ars Technica article really seems to miss the big picture here:
> With this year’s release of Thunderbird 115 “Supernova,” we’re doing much more than just another yearly release. It’s a modernized overhaul of the software, both visually and technically. Thunderbird is undergoing a massive rework from the ground up to get rid of all the technical and interface debt accumulated over the past 10 years.
> This is not an easy task, but it’s necessary to guarantee the sustainability of the project for the next 20 years.
> Simply “adding stuff on top” of a crumbling architecture is not sustainable, and we can’t keep ignoring it.
> Throughout the next 3 years, the Thunderbird project is aiming at these primary objectives:
> * Make the code base leaner and more reliable, rewrite ancient code, remove technical debt.
> * Rebuild the interface from scratch to create a consistent design system, as well as developing and maintaining an adaptable and extremely customizable user interface.
> * Switch to a monthly release schedule.
ottoottootto t1_j85ahow wrote
Reply to comment by halfanothersdozen in Mozilla plans ground-up UI redesign for Thunderbird email client this July by Hrmbee
Did you read the article?
halfanothersdozen t1_j859lfk wrote
Why just release a new thing? Why do they need to change Thunderbird?
littleMAS t1_j858ikw wrote
Reply to Texas Taxpayers Face a $100M Bill to Update Voting Machines with Equipment That Doesn’t Exist Yet by Sorin61
"A great first step towards rigging elections," GOP.
Hrmbee OP t1_j856i35 wrote
>The Supernova release will include an overhaul of Thunderbird's user interface. Castellani didn't share screenshots, but he indicated that the new UI would be "simple and clean" and targeted mostly at new users. For "veteran users," the interface will also be "flexible and adaptable" so that people who prefer the way Thunderbird looks now can "maintain that familiarity they love." > >Supernova will also include several other big changes, including a redesigned calendar and support for Firefox Sync. > >Beyond news about the redesign, the blog post is worth a read if you're curious about what the team is doing to battle the software's technical debt or if you want to know why it seems like the app's development moves so slowly (the developers spend a lot of their time simply keeping up with upstream changes from Firefox since the browser still serves as the foundation for Thunderbird's email rendering). The post is also helpful if you need a refresher on the long and complicated relationship between Thunderbird and Mozilla. > >Thunderbird used to be maintained by Mozilla alongside the Firefox browser, but in the modern era, it hasn't always been clear who's responsible for it. Mozilla executives had wanted to spin Thunderbird off as early as 2007, and it moved to a more community-driven development model in 2012.
It's good to see that an old stalwart client is getting a much-needed overhaul. Fingers crossed that this goes well, and that they have enough resources to properly execute on their vision.
teh_maxh t1_j855u75 wrote
Reply to comment by ivanoski-007 in Millions of passwords stolen from LastPass earlier than company disclosed: Report by BasedSweet
Its records can only include a single domain, username, and password, and only the password can be changed.
Danzzo36 t1_j852u58 wrote
Reply to Millions of passwords stolen from LastPass earlier than company disclosed: Report by BasedSweet
Can't steal from my notebook
Distracted-Tinkerer t1_j84zxwy wrote
Reply to comment by EntertainerOrk in Millions of passwords stolen from LastPass earlier than company disclosed: Report by BasedSweet
This is why you use a strong master password. Tip: 25+ character passphrase with at least one capital letter, number and special char is S-tier. Also pretty easy to remember.
Car-Altruistic t1_j84xro9 wrote
Reply to comment by strugglz in Texas Taxpayers Face a $100M Bill to Update Voting Machines with Equipment That Doesn’t Exist Yet by Sorin61
Vaporware? The technology has existed for literally all of my career and I’m old, they’re actually mandated for things that are a lot less consequential than voting systems. The fact voting machine manufacturers don’t want to use such technology is a bigger problem.
I could literally make a RPi based device that plugs into existing voting machines today and sell you a solution that anyone can track online in less than 4 hours, secure, cryptographic proof that track records of votes as they come in.
As the article says, they can always go back to paper, which has been proposed on every side (D, R and I) when alleging fraud.
FreeWildbahn t1_j84wf1x wrote
Reply to comment by Dominicus1165 in Millions of passwords stolen from LastPass earlier than company disclosed: Report by BasedSweet
For a rainbow table attack you need a hash like the passwd file on linux systems. But we are talking about cracking a password safe.
Dominicus1165 t1_j84vfnr wrote
Reply to comment by Admetus in Millions of passwords stolen from LastPass earlier than company disclosed: Report by BasedSweet
But again. With 150 services it’s quite hard to remember even with reference. And I look it up again. I have exactly 241 passwords in my manager.
They each need to be secure and not dependent on each other.
emaij t1_j84stgy wrote
Reply to Millions of passwords stolen from LastPass earlier than company disclosed: Report by BasedSweet
Where is Karim Toubba, CEO of last pass? Has not uttered a word about this complete failure. I would place this kind of negligence or recklessness on par with the Catholic church catastrophe. Why is the CEO not taking some responsibility for this?
[deleted] t1_j84lawy wrote
Reply to comment by guatemaleco in Millions of passwords stolen from LastPass earlier than company disclosed: Report by BasedSweet
[deleted]
cryptoderpin t1_j84knmv wrote
Reply to Texas Taxpayers Face a $100M Bill to Update Voting Machines with Equipment That Doesn’t Exist Yet by Sorin61
Cool so the TX gov gets to shovel taxpayer money into their friends “voting tech company” and get a sweet, sweet kick back in the form of political donations, on top of making voting less secure.
We know their games yet we still keep playing the game thus allowing this to continue so in the end it’s really all our fault not the fault of them. The beatings will continue until morale improves.
guatemaleco t1_j84e7xv wrote
Reply to comment by PMs_You_Stuff in Millions of passwords stolen from LastPass earlier than company disclosed: Report by BasedSweet
16 characters seems low unless it’s a randomly generated password. PBKDF2 iterations would also matter a lot here. The most determining factor is probably how likely of a target are you? Are you likely worth the compute time?
[deleted] t1_j84dyw4 wrote
Reply to comment by PMs_You_Stuff in Millions of passwords stolen from LastPass earlier than company disclosed: Report by BasedSweet
[deleted]
Admetus t1_j84dqlk wrote
Reply to comment by Dominicus1165 in Millions of passwords stolen from LastPass earlier than company disclosed: Report by BasedSweet
Nah, a reference to each password completely internal to your head. Even if it's something like 'password 1, password 2, etc.' There's zero correlation between the passwords and what I stated.
Admetus t1_j84dpa7 wrote
Reply to comment by Dominicus1165 in Millions of passwords stolen from LastPass earlier than company disclosed: Report by BasedSweet
Nah, a reference to each password completely internal to your head. Even if it's something like 'password 1, password 2, etc.' There's zero correlation between the passwords and what I stated.
xal1124 t1_j85d8qp wrote
Reply to comment by MPenguinGaming in Texas Taxpayers Face a $100M Bill to Update Voting Machines with Equipment That Doesn’t Exist Yet by Sorin61
Can you cite your source showing that the house is in session during even numbered years instead of odd numbered years?