Gestrid

joined 1 year ago
[–] [email protected] 7 points 4 months ago

Now where's that comic...

Ah, found it!

[–] [email protected] 9 points 4 months ago

I just call them communities. That's what I've seen others use.

[–] [email protected] 31 points 4 months ago* (last edited 4 months ago) (2 children)

FYI, there was no "conversation so far". That was the first thing I've ever asked "Rufus".

[–] [email protected] 4 points 4 months ago* (last edited 4 months ago) (1 children)

then i found you can't export your data from Authy

Exporting data from a 2FA app sounds like the opposite of secure. Not to mention you don't want your 2FA codes on Authy (or any other 2FA app) to remain valid if you're not using it.

When I switched from Google Authenticator to Authy years ago, I went through each 2FA-enabled account one by one to disable 2FA and then re-enable it using Authy. It's a long process depending on how many accounts you have 2FA enabled on, but it's worth it.

Reading the OP, looks like it's time to generate new keys for all my 2FA accounts.

[–] [email protected] 1 points 4 months ago

The way I read it, they already (in the third paragraph of the blog post) had companies auditing their backend technology and (in the fourth paragraph) were starting to have companies audit their apps, too.

[–] [email protected] 2 points 4 months ago* (last edited 4 months ago) (7 children)

I admittedly should've done more research before my first comment, but it does actually turn out that everything I said is true. Proton's technology was previously audited by Mozilla and is currently audited by SEC Consult and other companies regularly, and the audits are available for everyone to view. Additionally, they do have a bug bounty program. Also (and this is something I didn't mention), the ProtonVPN and Proton Mail apps are all open source.

[–] [email protected] 3 points 4 months ago (9 children)

That's where the second and third paragraphs come in. Because other companies likely test it themselves, too.

They'll typically report security bugs privately and then, after X amount of months, publicly announce the bug. Doing it this way will, ideally, force the other company to patch the bug prior to the announcement. If not, they'll end up with a publicly known security bug that bad actors can now exploit. The announcement will also let the public (including companies) know to update their software.

[–] [email protected] 11 points 4 months ago (14 children)

I imagine it probably is inspected, just not by the public. They probably do it themselves.

And they may have contracts with certain companies specializing in this sort of security that also inspect it.

And there's also the cybersecurity companies that test it whether they're contracted or not. At some companies, their entire job revolves around finding bugs (especially security bugs) in other companies' software.

Just because it's not on GitHub doesn't mean it's not a good product that hasn't been thoroughly tested.

[–] [email protected] 1 points 4 months ago

People can usually unlock the carrier on their own. Many phones (or at least every phone I've ever gotten from T-Mobile) even come pre-installed with a carrier unlocking app. It's just not automatic, and certain conditions need to be met.

People may also sometimes be able to buy phones already unlocked directly from the manufacturer if they want to. (Whether or not they're able to do this depends on the manufacturer.)

[–] [email protected] 1 points 4 months ago

You're right about the forums. While they're useful as smaller chat rooms separate from the "main ones" (for example, someone in a Discord server I know started a forum for fanart and discussion about a specific upcoming video game), they're completely useless as a replacement for traditional forums.

Also, like you said, the search feature simply isn't good enough to be able to efficiently search through all those forums. While Reddit's (and probably Lemmy's) search engine isn't great either, it at least has the benefit of being indexed by other search engines.

[–] [email protected] 6 points 4 months ago (3 children)

its completely unbearable

How so?

view more: ‹ prev next ›