Ken Thompson's Unix Password
541–550 of 665 posts
Re: Ken Thompson's Unix Password
#542Earlier quoted context omitted.
> Would you still feel safe if a burglar broke into your house and left a note saying they didn't take anything? That doesn't make it okay, but it certainly should result in a much lesser sentence than if the perpetrator had damaged or stolen property.
No. The serious crime is breaking in. Usually when someone's house is broken into they don't care about the stuff at all. They care that their personal space and sense of security has been violated. Also the criminal doesn't know what they'll find when they get in in but they are setting up a situation that can escalate quickly. Kids home alone? Someone with a shotgun? The very act of breaking in means they are ready…
Re: Ken Thompson's Unix Password
#543Earlier quoted context omitted.
This is exactly why some versions of Windows required you to press ctrl-alt-delete to open the login form. Programs aren't allowed to block Windows from receiving ctrl-alt-delete, so a fake login program would not be able to stay on the screen after the user pressed ctrl-alt-delete. (Of course this only works if the user knows to always hit ctrl-alt-delete when they go to login. If the user sees an already-open (fake…
The new Windows 10 login screen doesn't seem to support anything running on it, all I've seen is a duo security prompt that A. Only showed up after a login and B. Doesn't work on Windows 10 in a non-rdp session on a Microsoft account[0]. Sadly this also means you can't run something like Wallpaper Engine on the lock screen[1]. 0: https://duo.com/docs/rdp-faq#can-i-use-duo-with-a-microsoft-... ? 1: https://steamcommun…
Its utility's limited these days since consumer configurations of Windows have users trained not to expect to have to press ctrl-alt-del to log in. I'm not sure that it's even enabled by default on domain-joined machines any more as of Windows 10 (still available via Group Policy, though).
Re: Ken Thompson's Unix Password
#544Earlier quoted context omitted.
He has not presented any facts that are under contention, only normative estimations that rely on facts that are deliberately unspecified. The politically and economically safe option in the workplace is always to discard people who fall under scrutiny that exposes an employer to liability. This raises the reasonable standard of complaint for these types of issues beyond "his password, which I cracked despite design…
> The politically and economically safe option in the workplace is always to discard people who fall under scrutiny that exposes an employer to liability. What leads you to believe this? You are aware, I assume, of the existence of "wrongful termination" lawsuits, many of which have cost companies millions of dollars? > Can you think of a crackable-length passphrase that would make a normal, level-headed person suspi…
1. The courts are profoundly unfair. Are you comfortable forcing harassment victims to go through the courts for what are literally criminal allegations?
2. This example seems too contrived and implausible, as is anything else I could think of. The whole story just seems too magical. Maybe I'm just being hard-headed and arguing with a hero.
3. I will concede that is a more unpleasant series of events without care for semantics.
Re: Ken Thompson's Unix Password
#545Earlier quoted context omitted.
And they would almost certainly know the password rules, because anyone making an account would have to be told the rules in order to understand what was happening.
Unless the rules were unique and hidden for each user! User1: 1,3,7,10,12,15 User2: 2,3,5,8,10,13 I think we’re on to something big.
Re: Ken Thompson's Unix Password
#546Earlier quoted context omitted.
My password says "FUCK [a woman whom I no longer have an intimate relationship with]". This doesn't concern you? Does it concern 'jedberg?
Well it's none of my business and after the story you've shared I can't say I am very concerned. But in the story about HR, they looked into it and there was "other stuff", I guess they concluded something else about that situation. We don't know what that "other stuff" is and if it's right or wrong, but it's also likely not the exact same situation as your very detailed and specific story, is my point.
Re: Ken Thompson's Unix Password
#547Earlier quoted context omitted.
The new Windows 10 login screen doesn't seem to support anything running on it, all I've seen is a duo security prompt that A. Only showed up after a login and B. Doesn't work on Windows 10 in a non-rdp session on a Microsoft account[0]. Sadly this also means you can't run something like Wallpaper Engine on the lock screen[1]. 0: https://duo.com/docs/rdp-faq#can-i-use-duo-with-a-microsoft-... ? 1: https://steamcommun…
The specific threat that ctrl-alt-delete's supposed to mitigate is where a user's already logged in, but a program's running that mimics the login prompt. Since applications can't handle ctrl-alt-del in Windows, if you pressed it at a fake login prompt, you'd get the Windows Security dialog/screen rather than a login prompt and it would be obvious that something's wrong. Its utility's limited these days since consume…
Re: Ken Thompson's Unix Password
#548Earlier quoted context omitted.
Offtopic. Many teams use mailing lists. That UX always scared me. Is anybody know good tutorials on how to getting started to use this kind of interfaces?
This is a common refrain, mailing lists do need a lot of instructions at the bottom to make sense — email wasn't made for groups. It's like 'group' SMS, your phone might provide you with a single chat window with all your friends, but what it really is doing is just sending a separate SMS to every one of the recipients. So you need the 'the manual' attached to every message to make sure people get it right. Looks dow…
Most modern phones use MMS Group messaging for groups larger than two. It's more efficient and flexible than SMS.
Re: Ken Thompson's Unix Password
#549Earlier quoted context omitted.
>I never once used it for evil: never read anyone's email, never viewed anyone's private files, never poked around the academic file shares for test solutions, never tried to steal credit card numbers or social security numbers from the finance office's file share. I don't understand this justification. The system owners can't know that to be true and have to proceed as if the systems are compromised. Would you still…
> Would you still feel safe if a burglar broke into your house and left a note saying they didn't take anything? You might feel safe if he didn’t, but you wouldn’t actually be safe, would you?