• 29 Posts
  • 221 Comments
Joined 2 years ago
cake
Cake day: March 2nd, 2023

help-circle





  • Knowledge of the account is an obvious caveat. Yubikey-based MFA is an added layer of protection for accounts, so any kind of attack against MFA assumes the attacker already knows which account to target.

    It’s like saying “our door lock is flawed, but the attacker would need to have knowledge of the door”.

    The cost and complexity is what’s noteworthy and is more relevant. Although attack cost and complexity usuallu goes down with advances in tooling and research. So it may be a good idea to plan a progressive retirement of affected keys.









  • Once the war in Ukraine is over, weaponized drones won’t just vanish. They’re already made by companies with different level of ethics and any country able to pay is or will be able to buy them. Sooner or later, like many weapons, organised crime will get their hands on them, and use them outside of battlefield.

    There’s no way to completely prevent it, but we could at least limit damage by regulating the shit out of drones.