27 karma · joined May 11, 2022
That's not how it works, taxpayers enjoy fifth amendment protections against self incrimination.
IRS can't share this information with other LE without a warrant anyway.
I'm curious, what were they caught lying about?
>What proof do you have that last pass uses that encryption scheme? Is there any evidence to suggest that it meets rigorous standards?
LastPass has been extensively reverse engineered. There are, for example, public Defcon talks about it.
>Changing passwords in the face of a breach like this is standard practice and is the only logical step forward.
This is not logical at all.
>You cannot trust last pass security from this point forward.
Why not? Because they disclosed a breach?
In your other comment you claimed it was "likely" to be badly implemented, but here you state it as a fact. What's up with that?
> such as bad RNG
How could that be a problem? The attacker doesn't control your passwords. How would you exploit a known IV as an attacker in this context?
>That exact kind of thing happens constantly
Like when?
>And of course, the nature of the concern here involves us not knowing that LastPass was fucking up.
What do you mean? The cryptography used by LastPass is very well understood.
Well, yeah. Just like you leak your encrypted password to the internet every single time you log into a website.
>What if there is an undiscovered or undisclosed vulnerability in the encryption?
lmao, if aes-256-cbc is broken then LastPass is probably the least of anyone's concerns. This happens to also be one of the more difficult AES modes to screw up.
>What if last pass isn't using encryption as secure as they claimed?
Shit, if that was a real concern you would have to be a complete idiot to use LastPass in the first place.
If you did use a bad password for the cloud based password manager, you're the walnut. The whole sales pitch is that lastpass can't fuck you as long as you have a reasonable password protecting your vault.
Why didn't you just use decent passwords in the first place? You were using a password manager, what's the fucking point if your password is still "kittens1"?
This is all on you.
This is the worst possible take on this.
> Building an SMB server in the kernel because "well, NFS was secure eventually" overlooks the fact that NFS shouldn't be in the kernel either.
The way Linux works, NFS unfortunately has to be in the kernel to achieve reasonable performance.
These numbers exist solely for the audiences at home.
https://www.cps.gov.uk/legal-guidance/computer-misuse-act
>There must be knowledge that the intended access was unauthorised; and
Check? If not currently, Netflix could trivially ensure that this is the case by just adding a banner on the login page.
>There must have been an intention to secure access to any program or data held in a computer.
Check.
The warehouses full of people in Shenzhen tearing down millions and millions of stolen iDevices would still be chugging along, inserting stolen parts into the supply chain.
Apple enforcing DRM on parts is very much a pro-consumer move, steadily taking us towards a world where a stolen iPhone will be worth nothing.
But indeed, leaving GDPR enforcement to government authorities was a huge mistake. Anyone should be able to sue over GDPR violations impacting them.
You can't snort crack, you can't IV crack. You can only smoke crack, the onset is super fast and doesn't encourage you to rapidly redose. Dosage tends to be limited by your lung capacity.
Maybe with some very impressive lung capacity?
It's easy to overdose on Cocaine HCl using any of the popular RoAs. Insufflated, the onset is very slow, enabling you to take way too much before you actually start to feel the effects. Intravenously, your dosage is not limited by your lung capacity as it would be while smoking crack.
> In addition, processing can significantly affect an individual if it influences their personal circumstances, their behaviour or their choices (for example an automatic processing may lead to the refusal of an online credit application).
https://commission.europa.eu/law/law-topic/data-protection/r...