Earlier quoted context omitted.
If you personally think extensions are too much of a security risk for you, sure, don't use them. But please don't comment "ackshually extensions are insecure and using them is a bad idea" on every post about a browser extension. We already know the risks, it's explained when you install them, we don't need to hear the same lecture every day.
> But please don't comment "ackshually extensions are insecure and using them is a bad idea" I haven't? My first comment on this entire topic is the one you are replying to... And it can be summed up as "risk tolerance and security decisions is personal". Yikes.
Don't fuck with paste
351–360 of 397 posts
Re: Don't fuck with paste
#352Earlier quoted context omitted.
I'll add to that systems that require particular characters to be used, like "must use capital, number and special character". I prefer to generate longer passwords but using only regular characters because I find it easier to type on the occasions I do have to do that. Even worse, there are some that restrict what kind of special character you can use. So even when I've generated one I still have to edit to remove o…
Shout out to forms which error out with "Password too long! Must be at most ten characters. All from this subset of ascii". Which seems especially popular with banks.
They buy someone out, and now there are two systems. Glued together with duct tape. Then they release a new web product, or mobile app, or whatever, and that gets taped on too. Duct tape and spit all the way down, with everything eventually limited by the most broken part (if you're lucky).
Re: Don't fuck with paste
#353Earlier quoted context omitted.
> But please don't comment "ackshually extensions are insecure and using them is a bad idea" I haven't? My first comment on this entire topic is the one you are replying to... And it can be summed up as "risk tolerance and security decisions is personal". Yikes.
I really shouldn't have to explain this, but that statement wasn't directed at you specifically.
How am I supposed to know a direct reply to my comment, saying "if _you personally_" is not actually directed at me personally?
If it wasn't directed at me, I'm not sure why you replied to my comment at all.
Re: Don't fuck with paste
#354Earlier quoted context omitted.
I really shouldn't have to explain this, but that statement wasn't directed at you specifically.
> If you personally think How am I supposed to know a direct reply to my comment, saying "if _you personally_" is not actually directed at me personally? If it wasn't directed at me, I'm not sure why you replied to my comment at all.
Re: Don't fuck with paste
#355Earlier quoted context omitted.
> If you personally think How am I supposed to know a direct reply to my comment, saying "if _you personally_" is not actually directed at me personally? If it wasn't directed at me, I'm not sure why you replied to my comment at all.
Your comment doesn't exist in a vacuum, it's part of a longer reply chain, go read it.
Are you talking to me in this comment, or just generally? I have trouble telling.
Re: Don't fuck with paste
#356Earlier quoted context omitted.
Recently learned that if you Ctrl-F again after the highjacking, it brings up the browser search box. Discovered this thanks to a site (don't remember which) that included a tooltip about this fact in their hijacked search box. I was curious if it would work on Redocly search, which has no such tooltip, and it did. I'm not positive if this works universally, or is just an undocumented feature of Redocly's interface a…
It's a feature built-in to most browsers, same with right-click (if page hijacks right click, right-click twice in rapid succession).
Re: Don't fuck with paste
#357By disabling user input the application security actually gets worse. Users that can’t copy e.g. passwords will use less complex passwords to overcome the trouble of typing in their initially good passwords. But also user experience is degrading when applications enforce complex input and users generate that input like a chad as they should. But now they cannot paste…
I generally agree that you should let the user use the facilities they're used to, but if you have a habit of copying and pasting credentials you'll be more vulnerable to phishing. Firefox and Chrome's built-in password management tools would never accidentally enter your credentials on a lookalike site, but you very well might.
non-sequitur.
getting phished results in the decision to enter the credentials. The mechanism for doing so is irrelevant to that decision.
Re: Don't fuck with paste
#358Earlier quoted context omitted.
> The answer is: we have to, for compliance. Do they? I don’t remember seeing any compliance requirements you can’t reasonably push back. This is just overzealous compliance consultants meeting a team that doesn’t really care about their users. People never really question anything.
> Do they? Probably not. In my experience most standards are pretty broadly defined with hardly any technical requirements. For instance in ISO 27001 it states that you should create awareness in your organisation about information security. A very minimal way is to send a mass email to everyone in the organisation or hang up posters in the office. But I also spoke to someone that was determined that a half day secur…
What tends to happen is that auditors aren't going to tell you not to do something you don't have to, they're going to tell you to do to the things you must. Then the ones going "above and beyond" become convinced they're great at this compliance thing and others who don't do it are mistaken.
A perfect example is that PCI compliances requires firewalls but I know of a CISO that insisted on hardware level separation between networks with no way to bridge between them. The amount of pain and harm he did to that company cannot be overstated but he was convinced it was a requirement of PCI-DSS.
Re: Don't fuck with paste
#359Earlier quoted context omitted.
There's only so much user hand holding you can do.
With how ubiquitous Apple is, introducing a small limitation to prevent user error can make a huge difference in reducing support requests.
Re: Don't fuck with paste
#360Earlier quoted context omitted.
> NSFW language in most workplaces It would have been fine literally everywhere I've worked. I'm not saying there aren't places where this can be an issue. Partly this seems to depend on the region – in the US, in particular, it seems to be a big no-no, which I find odd considering how fucking often fuck is in fucking American media – the fuck is up with that? But outside of that? It seems to be mostly a non-issue.
Probably because the US does have a pretty wide diversity, particularly when it comes to religion. In some areas you'll find a lot of Mormons (who are greatly offended by "fuck"), and in some Christians (where some denonimations don't even like the word "crap" let alone "fuck"), in some Catholics who generally don't seem to care (I've heard some Catholic priests let loose some pretty blue streaks lol), and all kinds…