Hacker Newsnew | past | comments | ask | show | jobs | submit | ikiris's commentslogin

You're absolutely right! So does AI most times.

It all was many years ago after the great depression, and similar. Then people kept voting in republicans who's life mission is to gut the SEC and all related regulation keeping them from doing things like this.

The parent didn’t respond to anything their parent said either.

They must have outsourced their security to MSRC

Only if the price is under the competition, which does exist now.

That means you aren't high enough up to deal with the non helpdesk level security people.

True. It is a well-known fact that braincells per capita, and technical competence and understanding rapidly increase the higher you are on the management ladder.

Not if they're touch required in a secure enclave like a yubikey

Malware running on your computer can engineer a situation where you would naturally press that without suspecting anything.

1. Malware logs you out of github.com

2. It waits for you to navigate to the login page

3. It initiates an SSH/signing operation requiring physical touch

4. You hit login on github.com, a 2nd FIDO operation is queued up

5. You press the yubikey button, confirming the SSH operation

6. "Nothing happens", so you press it again to log in

7. You're now logged in, and your SSH credentials have just been hijacked.

Or it could just inject itself into your shell profile, and do this the next time you ssh anywhere. You never really know what you're confirming so Yubikey's threat model implicitly depends on the host device being trustworthy.

This is why hardware wallets for crypto have a physical display to confirm the address and the amount before signing the transaction.


Now I just hear the Voltron intro riff in my head

Those flying diecast lions hurt when they hit you as a kid

Not as much as when the leg broke off and you couldn't fix it, so you glue it in place and stop playing with it rather than ever tell your parents you broke it.

Between transformers, voltron, and borderline evil siblings it’s kinda of a miracle I made it from birth to now. But, hey, here we are and I love my brother… pretty sure he still stands me too.

This is the point this has delved into internet crankery.


No, it's a fairly uncontroversial take. See https://en.wikipedia.org/wiki/Robustness_principle#Criticism and the "See also" section.


This is basically "I should have asked more questions in the interview"

If you aren't willing to fix obvious issues like this it is not somewhere that I want to work.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: