Fingerprints could be stolen from V sign selfies (2017)
eandt.theiet.org
eandt.theiet.org
This guidance isn't unique, though it is certainly accurate. Case in point sourced from 1999 when the differences between identification v. authentication in a biometric context were being hammered out: https://web.archive.org/web/19990508102505/http://biometrics...
I have accounts I haven't logged into for years, but still need access to. Losing access over time is not a good feature. And a 'reset' with antibiotics doesn't make sense for a bunch of reasons.
Also, password diversity is a good thing. I don't want $COMPANY_A's data breach to expose my password to $COMPANY_B
Yes
His name was Lawrence David, but I can't quickly find the writeup that illustrates the point I'm making.
Example: iPhone (and Andorid) both have "secure enclaves" where cryptographic keys are stored. However when you step into the basic PC/Linux realm the concept of a secure-device for key storage (TPM) is pretty non-existent outside of corporate players. We can do better, without totally going pie in the sky.
This is why major organisations don't allow usernames to be name_surname or nsurname. They pick random usernames. I remember when I was a student my username was a random string with characters and numbers.
This makes it more difficult to hack my account (without prior knowledge, shoulder surfing, etc.) since it was highly unlikely you could guess my username and my password.
sounds more like an artifact of early garbagey email systems than any sound security policy. certainly i've seen nothing of the sort from any organization since a VM/CMS system in the early 90's.
> This makes it more difficult to hack my account (without prior knowledge, shoulder surfing, etc.) since it was highly unlikely you could guess my username and my password.
this doesn't make any sense.
if i generate my passwords by a perfectly reasonable, robust procedure, and then prepend them with the string "password", and disclose this fact publicly, they become no less secure.
the username is just like a publicly announced string prepended onto your (hopefully) securely generated password.
Does that make sense? I do not imply that password should not be complex etc. I am merely pointing out the benefits of having a difficult to guess username.
no, it does not. just add more bits of entropy to your password if you want more "unguessability". there's no benefit to putting it into the username.
the username and password fields can be imagined as a single field; whether the entropy is at the start or end of the field makes no difference. we just split them up for database efficiency reasons. (and because the username ends up displayed some places.)
> I do not imply that password should not be complex etc.
I do understand that's not your implication
> I am merely pointing out the benefits of having a difficult to guess username.
i'm saying that if your password is good enough, it doesn't matter what your username is.
the same way that if the last 50% of your password is "good enough", it doesn't matter if you plaster the first 50% of it onto billboards.
https://scifi.stackexchange.com/questions/92738/what-is-the-...
[Ford] slowly drew out from the wallet a single and insanely exciting piece of plastic that was nestling amongst a bunch of receipts.
It wasn’t insanely exciting to look at. It was rather dull in fact. It was smaller and a little thicker than a credit card and semi-transparent. If you held it up to the light you could see a lot of holographically encoded information and images buried pseudo-inches deep beneath its surface.
It was an Ident-i-Eeze, and was a very naughty and silly thing for Harl to have lying around in his wallet, though it was perfectly understandable. There were so many different ways in which you were required to provide absolute proof of your identity these days that life could easily become extremely tiresome just from that factor alone, never mind the deeper existential problems of trying to function as a coherent consciousness in an epistemologically ambiguous physical universe. Just look at cash point machines, for instance. Queues of people standing around waiting to have their fingerprints read, their retinas scanned, bits of skin scraped from the nape of the neck and undergoing instant (or nearly instant - a good six or seven seconds in tedious reality) genetic analysis, then having to answer trick questions about members of their family they didn’t even remember they had, and about their recorded preferences for tablecloth colours. And that was just to get a bit of spare cash for the weekend. If you were trying to raise a loan for a jetcar, sign a missile treaty or pay an entire restaurant bill things could get really trying.
Hence the Ident-i-Eeze. This encoded every single piece of information about you, your body and your life into one all-purpose machine-readable card that you could then carry around in your wallet, and therefore represented technology’s greatest triumph to date over both itself and plain common sense.Personally, I just stick the > in front even though HN doesn't apply special formatting to it. Most people are familiar with that convention, either from Markdown or from stuff like emails.
> like this
knuth:> blah blah blah
wirth:> bläh bläh bläh
Yes, there’s a better way. Please refer to the parent comment in this discussion [1].
The modern convention for such quotations is called "copypasta": you put your quote in the beginning of your message without additional formatting, and attribute it to the author in the end of your message or in the reply to yourself, or ever in the username of account you created to post the quote (such account would be called "novelty account" because THGTTG is in fact a novel).
Attribution after the quote has additional benefit of giving people the pleasure to recognize the source of the quote themself while they read it.
> [Ford] slowly drew out from the wallet a single and insanely exciting piece of plastic that was nestling amongst a bunch of receipts.
> It wasn’t insanely exciting to look at. It was rather dull in fact. It was smaller and a little thicker than a credit card and semi-transparent. If you held it up to the light you could see a lot of holographically encoded information and images buried pseudo-inches deep beneath its surface.
> It was an Ident-i-Eeze, and was a very naughty and silly thing for Harl to have lying around in his wallet, though it was perfectly understandable. There were so many different ways in which you were required to provide absolute proof of your identity these days that life could easily become extremely tiresome just from that factor alone, never mind the deeper existential problems of trying to function as a coherent consciousness in an epistemologically ambiguous physical universe. Just look at cash point machines, for instance. Queues of people standing around waiting to have their fingerprints read, their retinas scanned, bits of skin scraped from the nape of the neck and undergoing instant (or nearly instant - a good six or seven seconds in tedious reality) genetic analysis, then having to answer trick questions about members of their family they didn’t even remember they had, and about their recorded preferences for tablecloth colours. And that was just to get a bit of spare cash for the weekend. If you were trying to raise a loan for a jetcar, sign a missile treaty or pay an entire restaurant bill things could get really trying.
> Hence the Ident-i-Eeze. This encoded every single piece of information about you, your body and your life into one all-purpose machine-readable card that you could then carry around in your wallet, and therefore represented technology’s greatest triumph to date over both itself and plain common sense.
Give as much data as one is comfortable with, when viewing the image in a 1:1 ratio.
It was at that time that I started keeping all of my keys in a sleeve. Do I now need to start wearing gloves?
But recreating through a photo counts as a low-skill attack. Not as low-skill as raking a lock or using bump keys, but it does make low-skill attacks viable on moderately-or-better secure locks.
The same thing was often used as the "peace sign" in the mid/late 1900s, though these days it's not as mainstream as it used to be.
Its roots go back farther than that, and I think your interpretation (with the palm facing one's body) is older than the more modern interpretation.
Sorry but this is not the case at all. Most millenials know it as a peace sign, none of them would think of pokemon.
The hippie counter-culture movement in the 1960s co-opted it as the "peace" sign, but nowadays I'd argue it doesn't have much of a meaning, it's just "something people do for photos" (especially in East Asia).
With the palm facing the viewer it means peace now but it's rare to see it referred to as a V sign in the UK with this meaning.
In WW II Churchill used it to mean Victory not peace but apparently started out used the insulting version and had to have the difference explained to him. Not sure if that is true or just apocryphal.
No doubt the posh school he went to didn't have the grubby little oiks running round the playground flicking the V's everywhere. Or grubby little oiks for that matter. :)