• 0 Posts
  • 25 Comments
Joined 1Y ago
cake
Cake day: Jul 09, 2023

help-circle
rss

But DO rotate your passwords if you suspect they’ve been leaked. Or every 5-10 years probably couldn’t hurt either. The thing that has a much bigger effect is using unique passwords for every service. And if you have a password manager, resetting 1 password after a leak is trivial.


I don’t think that matters, since when bruteforcimg a passphrase it’s more like using whole words as the characters (or tokens) in the password. If there’s 7776 possible unique words, it doesn’t matter what characters are in the words at all. Just how many password combinations are used.

Side note, this is assuming words without character replacements. If you consider variations with A->@ or B->8 there ends up being significantly more possible unique “words”


I understand what you mean. Water vapour (i.e. clouds, fog, the visible part of what comes from boiling water which any normal person would call steam) vs Gaseous water (i.e. most of the atmosphere, and the non-visible part of boiling water also called steam).

Vapes work by boiling PG/VG which starts as a liquid (i.e. the juice), and generates both vapourized and gaseous PG/VG. If it was water, any normal person would consider this steam. This isn’t a chemistry or physics class.


I don’t think there’s a need to so pedantic here. Water vapor is the visible part of steam, and for the purposes of this discussion, we’re talking about boiling liquids, so I don’t think there was any miscommunication by using the word “steam”


Our data suggest that the flavorings used in e-juices can trigger an inflammatory response in monocytes, mediated by ROS production, providing insights into potential pulmonary toxicity and tissue damage in e-cigarette users.

Well, I guess that’s a point against flavored vapes. I really wish there were more studies, because presumably not all flavorings would have the same effect. A comparison with unflavored e-juice would have been great.


That’s certainly a problem. It’s one of the big reasons I think THC vapes should be both legal and regulated. In the states were it is legal, there’s strict inventory tracking every step of the way.

Admittedly it’s a lot harder to get people on board with regulating drug-free vapes, but I think it would be a good idea to have guarantees about what you’re consuming just like food.


Well, I’m impressed they actually did test JUST the vape liquid, even though they’re still calling them e-cigs.

Quoting from the journal itself:

There were no significant differences in changes of BAL inflammatory cell counts or cytokines between baseline and follow-up, comparing the control and e-cig groups. However, in the intervention but not the control group, change in urinary PG as a marker of e-cig use and inhalation was significantly correlated with change in cell counts (cell concentrations, macrophages, and lymphocytes) and cytokines (IL8, IL13, and TNFα), although the absolute magnitude of changes was small. There were no significant changes in mRNA or miRNA gene expression. Although limited by study size and duration, this is the first experimental demonstration of an impact of e-cig use on inflammation in the human lung among never-smokers.

The way I read this, it seems like there’s a small correlation with inflammation, but there’s no measurable risk of developing lung cancer from it (they were doing cancer research after all). Personally for an adult, I feel like “inflammation” is kind of a nothingburger, just stop vaping for a while and you’ll be fine. But for kids developing habits, I can understand the concern.


If you’d like to point me at some studies go ahead. The only dangerous cases I’ve heard about were black market vapes that had other contaminants in them. It’s been very hard to find reliable studies because most I’ve seen are self-reported using the entirely generic term “vaping” without any qualifiers on the kind.


I’m getting a lot of downvotes, and maybe I’m wrong about what kinds of vapes kids are using? Obviously if they’re using nicotine vapes, that’s bad and chemically addictive.
But I don’t have a problem with kids vaping the drug-free, flavored juice. It can be habit forming, but so can fidget spinners. As long as it’s not actually dangerous then I don’t see the problem.


Banning fruity flavors sounds like it would inadvertently ban all of the drug-free vapes… Flavor-only vapes get you all the big clouds and cool-factor that’s a big drive for kids, with none of the Nicotine or weed. Just inhaling the vapor on its own can be fairly safe.


Vaping is not the same as smoking and can be done perfectly safely with no drugs involved at all (i.e. flavor only vapes). It’s barely different than inhaling steam.

Edit: I’m willing to admit when I’m wrong, and now think “relatively safely” is a better way of putting this. There’s a few concerns that I’m perfectly happy to live with as an adult, but I get that kids won’t have spent as much time trying to understand the risks.


My Firefox says it now has Total Cookie Protection, and at least the notification about it wasn’t there before. Some other comment I read said that it was part of the Strict privacy setting before (i.e. not the default), but if you want more of a source then that, I lost the comment.

Edit: I was reading about this on a different copy of this post: https://lemmy.world/post/19163486


Really the only difference is that it’s on by default now. It was an optional feature before.


I think you’re missing the point of what I’m asking. In what way are regular salted passwords insecure? Sure you can keep adding extra steps to encryption, but at a certain point you’re just wasting CPU cycles.

I have no doubts about Argon2 being secure, I just think the extra steps are unnecessary for anything I would build (i.e. not touching financial transactions or people’s SSNs). By design argon2 uses a lot of memory and CPU time to make bruteforce attacks much harder, but that’s more of a downside when you’re just doing basic account logins on a low end server.

I’ll happily retract my point about external dependencies. It’s available in most languages, and notably std C++ contains neither argon2 or sha256/512 hashing, so that kind of makes my original point invalid anyway.


If they’re hashing, the column size should be irrelevant. Ideally the database should never see the plaintext password in the first place (though I could understand calculating the hash in the query itself). If they’re not hashing, they should really be rewriting their database anyway.


I’d rather see a paper explaining the flaws with salted passwords rather than “just use this instead”.

My initial reaction is that this overcomplicates things for the majority of use-cases, and has way more to configure correctly compared to something basic like a salted sha256/sha512 hash that you can write in any language’s standard library.

If the database of everyone’s salted password hashes gets leaked, this still gives everyone plenty of time to change passwords before anything has a chance of cracking them. (Unless you’re about to drop some news on me about long time standard practices being fundamentally flawed)


If they’re not already rate-limiting login attempts that’s another huge problem…


Not helpful when something like Consent-o-matic needs to operate on every possible website with a cookie banner.

I have had the same concerns, since watching it click through things faster than I can see is scary. Maybe some day someone sneaks in a cookie banner detector that activates on banking pages to steal your money? uBlock Origin has similar risks, but at least it’s not actively controlling browser inputs.



I personally don’t appreciate jokes about violence either, but whatever. I’m not policing the Internet.


I know you’re making a joke, but this doesn’t really feel like the place to do it given the subject being discussed.


Yep. Ubiquiti sells wifi 7 APs and the latest phones support it as of some time last year I think. The big new feature is 6GHz and the ability to automatically hop between frequencies (You can use 6, 5 and 2.4GHz all at once). Latency has been great, and I easily get 1Gbps+ in the same room as my wifi.


I’d expect in most cars it’s as simple as pulling a fuse for the cellular radio. But depending on how the car is designed that might break other features like the infotainment or keyless entry. It’s hit or miss how any given car will react to things being unplugged.


I’m on a prepaid plan, and got in on a really good deal. They were offering $25/month off indefinitely for signing up for auto-pay (Basically 35% off, lol). It made the plan cheaper and better than most of their monthly plans. I’m happy to know it also saved me from giving out my SSN.


You live near the Department of Motor Vehicles? /s

I have no clue where “the DMV area” is, even after Googling.