• 0 Posts
  • 86 Comments
Joined 3 years ago
cake
Cake day: June 19th, 2023

help-circle


    1. Actually text me the one-time passcode, rather than saying you sent it to me while instead texting it to the molten core of the earth.

    Uhhh… how about NO??

    In fact, as a casual security professional (it’s not a core part of my job, but I know a lot more than most ppl), I openly advocate making SMS and eMail illegal for transmitting one-time passcodes.

    Why? Because both are critically insecure, cannot be adequately secured outside of laboratory or highly restrictive environments, and can be trivially hijacked.

    The only one-time passcode that should be used are one-time password generators (TOTP) such as Google Authenticator or any other such method.

    Yes, this requires a little more effort on the part of the site owner, but it’s worlds better than SMS or eMail, and far more user-friendly than forcing the user to open the company’s app just to receive the code (looking at you, Canadian banks and other businesses like Telus).


  • Oh no! Forbidden

    Error: access denied: denied by administrative rule fa68ec4c0b694396d50ce50a8cf4cb6b/81a4d3ff51d16981b7d8

    Why am I seeing this?
    If you have any issues contact the site administrator and provide the following Request ID along with your browser details, specially like the User-Agent: fa68ec4c0b694396d50ce50a8cf4cb6b

    Protected by go-away :: Request Id fa68ec4c0b694396d50ce50a8cf4cb6b

    Just some basic browser protections, and I get this. Is this enshittified Cloudflare v2.0?


  • I am in IT, and personally speaking, with my own machines, I have never had these power settings not be obeyed.

    And the only time when I have seen these settings “not be obeyed” in other systems is because either,

    1. Someone or some other non-Microsoft software had dicked with power settings through the registry/GPO, or
    2. I’ve been able to trace things down to hardware malfunctions or hardware discrepancies.







  • rekabis@lemmy.catoPrivacy@lemmy.ml*Permanently Deleted*
    link
    fedilink
    arrow-up
    0
    arrow-down
    1
    ·
    1 month ago

    gmail is the only provider still sending me directly to spam

    Do you have a gMail account? Start a convo with yourself by sending from the gMail account first. Also add your other eMail to the gMail address book.

    It’s been about two decades since I had to do this for myself, but it worked well at the time.






  • Considering that all other alternatives are either

    • extremely difficult if not impossible for non-technical users to leverage, or
    • much, much worse, up to even eagerly giving out your data

    I consider Signal to be the best option out there. It’s not perfect, but nothing is. It simply is the best general option out there, by far, for a general audience.

    Yes, you can be totally secure, untraceable, and ultimately unfindable. But being cut into pieces, with each separate piece entombed in its own barrel of concrete, and each barrel dropped into a different oceanic trench, tends to be a bit beyond what I consider to be reasonable to achieve that.



  • How much do large language models actually hallucinate when answering questions grounded in provided documents?

    Okay, this is looking promising, at least in terms of the most important qualifications being plainly stated in the opening line.

    Because the amount of hallucinations/inaccuracies “in the wild” - depending on the model being tested - runs about 60-80%. But then again, this would be average use on generalized data sets, not questions focusing on specific documentation. So of course the “in the wild” questions will see a higher rate.

    This also helps users, as it shows that hallucinations/inaccuracies can be reduced by as much as ⅔ by simply limiting LLMs to specific documentation that the user is certain contains the desired information, rather than letting them trawl world+dog.

    Very interesting!


  • That may be the case, but the most irritating thing is that thy fill all available spots with the lowest-capacity chips that meet the requested provisioning spec, instead of taking the requested provisioning and using the fewest higher-capacity chips needed to meet the provisioning spec. The latter, at least, would leave spots open for an authorized repair location to manually solder on more approved chips of compatible spec.