<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dw="https://www.dreamwidth.org">
  <id>tag:dreamwidth.org,2009-06-15:406679</id>
  <title>Sumana</title>
  <subtitle>I am not bound to win, but I am bound to be true</subtitle>
  <author>
    <name>brainwane</name>
  </author>
  <link rel="alternate" type="text/html" href="https://brainwane.dreamwidth.org/"/>
  <link rel="self" type="text/xml" href="https://brainwane.dreamwidth.org/data/atom"/>
  <updated>2024-11-12T16:51:25Z</updated>
  <dw:journal username="brainwane" type="personal"/>
  <entry>
    <id>tag:dreamwidth.org,2009-06-15:406679:206094</id>
    <link rel="alternate" type="text/html" href="https://brainwane.dreamwidth.org/206094.html"/>
    <link rel="self" type="text/xml" href="https://brainwane.dreamwidth.org/data/atom/?itemid=206094"/>
    <title>Free digital security checkups for people/organizations concerned about the incoming US government</title>
    <published>2024-11-12T16:51:25Z</published>
    <updated>2024-11-12T16:51:25Z</updated>
    <category term="security"/>
    <dw:security>public</dw:security>
    <dw:reply-count>1</dw:reply-count>
    <content type="html">My friend Jacob is offering:&lt;br /&gt;&lt;br /&gt;&lt;a href="https://jacobian.org/2024/nov/11/digital-security-checkup/"&gt;Free digital security checkups for people/organizations concerned about the incoming US government&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Anyone is eligible for this - whatever your concern. &lt;br /&gt;&lt;div style="margin-left: 40px;"&gt;&amp;nbsp;&lt;/div&gt;&lt;p style="margin-left: 40px;"&gt;Whatever form any sort of resistance takes, it&amp;rsquo;s going to need to  rest on a foundation of security and private communication. I&amp;rsquo;ve spent  nearly twenty years working in the security industry, including actual  experience protecting against nation-state-level adversaries. I&amp;rsquo;d like  to use those skills and that experience to help those most at risk from  the incoming regime (and the vigilante hangers-on that surround it).&lt;/p&gt;&lt;p style="margin-left: 40px;"&gt;&lt;strong&gt;So,  if you &amp;mdash; as an individual or a group &amp;mdash; want to re-assess your digital  security posture, I&amp;rsquo;d like to try to help. I&amp;rsquo;m offering free digital  security check-ups to anyone who feels like they need it now.&lt;/strong&gt;  We&amp;rsquo;ll talk through your current digital security practices and review  the risks that worry you, and I&amp;rsquo;ll give you some suggestions about  practices and tools that might help. If needed (and my availability  permitting), we can schedule follow-up time for some hands-on  walkthroughs and tutorials.&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="https://www.dreamwidth.org/tools/commentcount?user=brainwane&amp;ditemid=206094" width="30" height="12" alt="comment count unavailable" style="vertical-align: middle;"/&gt; comments</content>
  </entry>
  <entry>
    <id>tag:dreamwidth.org,2009-06-15:406679:201768</id>
    <link rel="alternate" type="text/html" href="https://brainwane.dreamwidth.org/201768.html"/>
    <link rel="self" type="text/xml" href="https://brainwane.dreamwidth.org/data/atom/?itemid=201768"/>
    <title>Excised from elsewhere, on trust</title>
    <published>2024-01-08T16:19:33Z</published>
    <updated>2024-01-08T16:20:01Z</updated>
    <category term="security"/>
    <category term="job"/>
    <category term="opensource"/>
    <dw:security>public</dw:security>
    <dw:reply-count>6</dw:reply-count>
    <content type="html">I'm writing a blog post over at &lt;a href="https://www.harihareswara.net/"&gt;my name blog&lt;/a&gt; about how open source maintainers can think about trusting new co-maintainers, what that trust entails, how to check for trustworthiness, etc. I was writing this bit, and then a friend reminded me that including something about sex in this piece would mean that she could not share it in her starchy workplace. So I'm saving it here instead, and will replace it with an analogy that won't raise as many eyebrows.&lt;br /&gt;&lt;br /&gt;...&lt;span style="white-space: pre-wrap"&gt;some intake processes concentrate quite a lot on checking for trustworthiness, specifically for the candidate's capacity to be a responsible colleague and take criticism well.....&lt;/span&gt;&lt;div data-draftjs-conductor-fragment="{&amp;quot;blocks&amp;quot;:[{&amp;quot;key&amp;quot;:&amp;quot;1tn6u&amp;quot;,&amp;quot;text&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;type&amp;quot;:&amp;quot;unstyled&amp;quot;,&amp;quot;depth&amp;quot;:0,&amp;quot;inlineStyleRanges&amp;quot;:[],&amp;quot;entityRanges&amp;quot;:[],&amp;quot;data&amp;quot;:{}},{&amp;quot;key&amp;quot;:&amp;quot;869of&amp;quot;,&amp;quot;text&amp;quot;:&amp;quot;In the subculture of people who engage in nonmonogamy or other alternative sexual experiences together, \&amp;quot;vetting\&amp;quot; is sometimes informal, but sometimes groups do require new members to go through a formal process. This Bay Area-based group&amp;#39;s application asks whether any existing group members have endorsed the candidate&amp;#39;s application, and asks questions like&amp;quot;,&amp;quot;type&amp;quot;:&amp;quot;unstyled&amp;quot;,&amp;quot;depth&amp;quot;:0,&amp;quot;inlineStyleRanges&amp;quot;:[],&amp;quot;entityRanges&amp;quot;:[],&amp;quot;data&amp;quot;:{}},{&amp;quot;key&amp;quot;:&amp;quot;4h1i1&amp;quot;,&amp;quot;text&amp;quot;:&amp;quot;How do you know when someone consents to an experience you invite them to share with you? What information do you look for and how do you seek it out?&amp;quot;,&amp;quot;type&amp;quot;:&amp;quot;blockquote&amp;quot;,&amp;quot;depth&amp;quot;:0,&amp;quot;inlineStyleRanges&amp;quot;:[],&amp;quot;entityRanges&amp;quot;:[],&amp;quot;data&amp;quot;:{}},{&amp;quot;key&amp;quot;:&amp;quot;eaqnr&amp;quot;,&amp;quot;text&amp;quot;:&amp;quot;In Bonobo, we understand that people may make mistakes, cross other people&amp;#39;s boundaries, or just impact one another without necessarily realizing it. But we also expect that people will own up to their impacts and mistakes, and take responsibility for them. Tell us about a time you crossed someone&amp;#39;s boundary and took responsibility for it. What happened, how did you respond when you realized you crossed their boundary, and how did you deal with it after that?&amp;quot;,&amp;quot;type&amp;quot;:&amp;quot;blockquote&amp;quot;,&amp;quot;depth&amp;quot;:0,&amp;quot;inlineStyleRanges&amp;quot;:[],&amp;quot;entityRanges&amp;quot;:[],&amp;quot;data&amp;quot;:{}},{&amp;quot;key&amp;quot;:&amp;quot;4alq0&amp;quot;,&amp;quot;text&amp;quot;:&amp;quot;&amp;quot;,&amp;quot;type&amp;quot;:&amp;quot;unstyled&amp;quot;,&amp;quot;depth&amp;quot;:0,&amp;quot;inlineStyleRanges&amp;quot;:[],&amp;quot;entityRanges&amp;quot;:[],&amp;quot;data&amp;quot;:{}},{&amp;quot;key&amp;quot;:&amp;quot;d0p10&amp;quot;,&amp;quot;text&amp;quot;:&amp;quot;TKTK https://www.bonobonetwork.com/apply&amp;quot;,&amp;quot;type&amp;quot;:&amp;quot;unstyled&amp;quot;,&amp;quot;depth&amp;quot;:0,&amp;quot;inlineStyleRanges&amp;quot;:[],&amp;quot;entityRanges&amp;quot;:[],&amp;quot;data&amp;quot;:{}},{&amp;quot;key&amp;quot;:&amp;quot;1cql7&amp;quot;,&amp;quot;text&amp;quot;:&amp;quot;vetting, asking them to think about their values (Oakland play application), asking for references,&amp;quot;,&amp;quot;type&amp;quot;:&amp;quot;unstyled&amp;quot;,&amp;quot;depth&amp;quot;:0,&amp;quot;inlineStyleRanges&amp;quot;:[],&amp;quot;entityRanges&amp;quot;:[],&amp;quot;data&amp;quot;:{}}],&amp;quot;entityMap&amp;quot;:{}}" style="white-space: pre-wrap;"&gt;&lt;div class="Draftail-block--unstyled " data-block="true" data-editor="2u13a" data-offset-key="aquqg-0-0"&gt;&lt;div data-offset-key="aquqg-0-0" class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&lt;span data-offset-key="aquqg-0-0"&gt;&lt;br data-text="true" /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="Draftail-block--unstyled " data-block="true" data-editor="2u13a" data-offset-key="9i5b6-0-0"&gt;&lt;div data-offset-key="9i5b6-0-0" class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&lt;span data-offset-key="9i5b6-0-0"&gt;&lt;span data-text="true"&gt;In the subculture of people who engage in nonmonogamy or other alternative sexual experiences together, &amp;quot;vetting&amp;quot; is sometimes informal, but sometimes groups do require new members to go through a formal process. This Bay Area-based group's application asks whether any existing group members have endorsed the candidate's application, and asks questions like&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;blockquote class="Draftail-block--blockquote " data-block="true" data-editor="2u13a" data-offset-key="qgud-0-0"&gt;&lt;div data-offset-key="qgud-0-0" class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&lt;span data-offset-key="qgud-0-0"&gt;&lt;span data-text="true"&gt;How do you know when someone consents to an experience you invite them to share with you? What information do you look for and how do you seek it out?&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;blockquote class="Draftail-block--blockquote " data-block="true" data-editor="2u13a" data-offset-key="9444s-0-0"&gt;&lt;div data-offset-key="9444s-0-0" class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&lt;span data-offset-key="9444s-0-0"&gt;&lt;span data-text="true"&gt;In Bonobo, we understand that people may make mistakes, cross other people's boundaries, or just impact one another without necessarily realizing it. But we also expect that people will own up to their impacts and mistakes, and take responsibility for them. Tell us about a time you crossed someone's boundary and took responsibility for it. What happened, how did you respond when you realized you crossed their boundary, and how did you deal with it after that?&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div class="Draftail-block--unstyled " data-block="true" data-editor="2u13a" data-offset-key="4ppo8-0-0"&gt;&lt;div data-offset-key="4ppo8-0-0" class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&lt;span data-offset-key="4ppo8-0-0"&gt;&lt;br data-text="true" /&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="Draftail-block--unstyled " data-block="true" data-editor="2u13a" data-offset-key="cvk55-0-0"&gt;&lt;div data-offset-key="cvk55-0-0" class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&lt;span data-offset-key="cvk55-0-0"&gt;&lt;span data-text="true"&gt;https://www.bonobonetwork.com/apply&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="Draftail-block--unstyled " data-block="true" data-editor="2u13a" data-offset-key="9eed6-0-0"&gt;&lt;div data-offset-key="9eed6-0-0" class="public-DraftStyleDefault-block public-DraftStyleDefault-ltr"&gt;&lt;span data-offset-key="9eed6-0-0"&gt;&lt;span data-text="true"&gt;vetting, asking them to think about their values (Oakland play application), asking for references,.....&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="https://www.dreamwidth.org/tools/commentcount?user=brainwane&amp;ditemid=201768" width="30" height="12" alt="comment count unavailable" style="vertical-align: middle;"/&gt; comments</content>
  </entry>
  <entry>
    <id>tag:dreamwidth.org,2009-06-15:406679:194261</id>
    <link rel="alternate" type="text/html" href="https://brainwane.dreamwidth.org/194261.html"/>
    <link rel="self" type="text/xml" href="https://brainwane.dreamwidth.org/data/atom/?itemid=194261"/>
    <title>Dreamwidth is working on two-factor auth</title>
    <published>2023-01-02T20:33:16Z</published>
    <updated>2023-01-03T12:20:33Z</updated>
    <category term="security"/>
    <category term="dreamwidth"/>
    <dw:security>public</dw:security>
    <dw:reply-count>5</dw:reply-count>
    <content type="html">&lt;strike&gt;Dreamwidth has now added two-factor authentication, though &lt;/strike&gt;&lt;a href="https://www.dreamwidth.org/support/faq"&gt;&lt;strike&gt;the FAQ doesn't mention it yet&lt;/strike&gt;&lt;/a&gt;&lt;strike&gt;.&lt;/strike&gt; [see January 3rd edit below]&lt;br /&gt;&lt;br /&gt;You can go to &amp;quot;Account Settings&amp;quot; and check under the &amp;quot;Account&amp;quot; tab -- under &amp;quot;Password&amp;quot; is &amp;quot;Two-Factor Authentication&amp;quot;.&lt;br /&gt;&lt;br /&gt;Dreamwidth's 2FA implementation, as with most sites, depends on you having one of those standard apps on your phone or computer that generates one-time 6-digit passcodes, like Google Authenticator or Authy. (The jargon for this is TOTP: Time-based one-time passwords.) Once you do the setup and turn on 2FA in your Dreamwidth account, then your login is more secure, because having your password isn't enough to let someone log in to your account -- they also have to have access to your computer or phone.&lt;br /&gt;&lt;br /&gt;Since it's not in the FAQ and wasn't mentioned in any of the recent &lt;a href="https://dw-dev.dreamwidth.org/232709.html"&gt;code tours&lt;/a&gt; I&amp;nbsp;think this feature might be in beta. I am subscribed to &lt;a href="https://github.com/dreamwidth/dreamwidth/issues/1597"&gt;a GitHub issue&lt;/a&gt; where I might learn more.&lt;br /&gt;&lt;br /&gt;EDITED A FEW HOURS LATER TO ADD: I just tried logging out and in again and the site didn't demand a 2FA code. So I don't know whether this feature actually works right now.&lt;br /&gt;&lt;br /&gt;EDITED 3 JANUARY TO CHANGE TITLE: Changed the title of this post from &amp;quot;Dreamwidth has two-factor auth now (in beta?)&amp;quot; to &amp;quot;Dreamwidth is working on two-factor auth&amp;quot;. Per &lt;a href="https://github.com/dreamwidth/dreamwidth/issues/1597#issuecomment-1369703987"&gt;this GitHub comment&lt;/a&gt;, the 2FA feature is not yet actually functional.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;img src="https://www.dreamwidth.org/tools/commentcount?user=brainwane&amp;ditemid=194261" width="30" height="12" alt="comment count unavailable" style="vertical-align: middle;"/&gt; comments</content>
  </entry>
  <entry>
    <id>tag:dreamwidth.org,2009-06-15:406679:193282</id>
    <link rel="alternate" type="text/html" href="https://brainwane.dreamwidth.org/193282.html"/>
    <link rel="self" type="text/xml" href="https://brainwane.dreamwidth.org/data/atom/?itemid=193282"/>
    <title>Switch from LastPass to another password manager</title>
    <published>2022-12-02T05:31:21Z</published>
    <updated>2022-12-02T12:39:22Z</updated>
    <category term="security"/>
    <dw:security>public</dw:security>
    <dw:reply-count>4</dw:reply-count>
    <content type="html">Bad news about the LastPass password manager: &lt;a href="https://blog.lastpass.com/2022/11/notice-of-recent-security-incident/"&gt;https://blog.lastpass.com/2022/11/notice-of-recent-security-incident/&lt;/a&gt;  &lt;blockquote&gt;&amp;nbsp;We  have determined that an unauthorized party, using information obtained  in the August 2022 incident, was able to gain access to certain elements  of our customers&amp;rsquo; information. Our customers&amp;rsquo; passwords remain safely  encrypted due to LastPass&amp;rsquo;s &lt;a href="https://www.lastpass.com/security/zero-knowledge-security"&gt;Zero Knowledge&lt;/a&gt; architecture.&lt;/blockquote&gt;  My friend Jacob &lt;a href="https://social.jacobian.org/@jacob/109434934940064928"&gt;writes&lt;/a&gt;:  &lt;blockquote&gt;&amp;nbsp;This is your regular reminder that if you're still using LastPass you should, uh, stop that. &lt;br /&gt;&lt;br /&gt; It's  not just this one incident; they've had a series of terrible incidents  &amp;amp; appear to learn nothing. Eg: E2E encryption is littered with bugs  and has been broken/bypassed repeatedly. The master key is accessible by  the sever. Malicious plugins can exfil your master password. The  support forum (phpbb) somehow knows your master password. And more.&lt;br /&gt;&lt;br /&gt;This isn't about scorning; LastPass is actively unsafe and people need to not use it.&lt;/blockquote&gt;  He and others recommend &lt;a href="https://1password.com/"&gt;1Password (paid, USD $34/yr)&lt;/a&gt; -- there are also &lt;a href="https://kith.kitchen/@ehashman/109434934831646545"&gt;other recommended alternatives in that thread&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;img src="https://www.dreamwidth.org/tools/commentcount?user=brainwane&amp;ditemid=193282" width="30" height="12" alt="comment count unavailable" style="vertical-align: middle;"/&gt; comments</content>
  </entry>
</feed>
