• 0 Posts
  • 32 Comments
Joined 1 year ago
cake
Cake day: July 23rd, 2023

help-circle



  • The title is unreasonably generous. The apology is entirely self serving and meaningless.

    • He doesn’t apologize for throwing water for the man - only for posting it on social media.
    • He tries to frame a narrative that the victim deserved it
    • He doesn’t offer any sort of reparations or even an insignificant donation to a group that works with unhoused people generally.

    It’s clearly only to ensure his business is not affected, reduce the threat of prosecution (being considered by law enforcement, presumably for assault), and to encourage leniency from the judge if it gets that far.

    Apology not accepted.











  • Manually keying in the pin is only needed when plugging in the device. Challenges for TOTP, FIDO2, etc. are a configuration option, and are only 3 digits if enabled (press any button if disabled).

    As for “excessive amount of security”, security as an absolute measure isn’t a great way to think about it. Use case and threat model are more apt.

    For use case, I’ll point out it’s also a PGP and SSH device, where there is no third party server applying the first factor (something you know) and needs to apply both factors on device.

    For threat model, I’ll give the example of an activist who is arrested. If their e-mail provider is in the country, they can compel the provider to give them access, allowing them to reset passwords on other more secure services hosted outside the country. The police now have the second factor (something you have), but can’t use it because it’s locked.