I almost spit out my coffee from this meme!
I like programming and anime.
I manage the bot /u/mahoro@lemmy.ml
- 1 Post
- 19 Comments
I understand this change by Bitwarden, but I wish they gave us the option to turn this off or at least given us more time before forcing this on us.
There’s a lot of comments talking about how this increases security, which is true. But it also increases the risk of account lockout. This is especially true in two scenarios: traveling and incapacitation.
Traveling - for those of us who travel frequently, we carry all of our belongings with us. This makes us particularly vulnerable to account lockouts. We can’t securely store backup devices or documents in easily accessible locations. We can’t easily rely on trusted friends or family because they are so far away. Also, internet accounts are more likely to lock us out anyway because we are logging in from a different country, which is suspicious behavior.
Incapacitation - god forbid, if there comes a time when we are permanently or temporarily incapacitation, it becomes important for our loved ones to access accounts. When we are in the hospital, it’s important that our loved ones get access to our personal accounts. I personally have advanced directives and have worked with an estate lawyer to make sure that my Bitwarden account becomes available. I also have instructions for immediate trusted family on how to access my vault if I were ever in the hospital. With this short notice, I need to scramble to get all of that updated and provide a way for them to access the account without my 2FA devices.
The above scenarios are based off of my real experience. These are real and likely risks that I have to account for. Security is not just making sure that outside bad actors CANNOT gain access, but it also means that the right people CAN get access at the right time.
What am I going to do? I’m weighing my options.
- I believe the self-hosted version of Bitwarden does not require this. This comes with its own set of risks though.
- Pay for premium, which comes with lockout support - I need to see if this can take care of both use scenarios above.
- Turn on 2FA and memorize the recovery code. While viable, since I will only use the recovery code once, I’m likely to forget it.
- Change the email to a non-2FA email address, only used by Bitwarden, with a strong but easily memorable password. This email must allow access from foreign countries without lockout (gmail is out). I’m actually strongly considering this.
This is being purposefully obtuse. Choosing to force users to memorize a recovery code increases the likelihood of lock outs.
There is a real risk of account lockout, especially for those of us who travel frequently. Lockouts are a significant risk when you need to carry all your belongings and devices.
There are also some of us who also think about what happens to us when we are incapacitated and a loved one needs access to our passwords. In a situation, it’s important to balance security vs expediency to access critical information. This new policy disrupts that.
At the very least, I wish Bitwarden would have given us more time to force this policy. I have to scramble to make changes to my estate planning documents and get in contact with my lawyer to change my advanced healthcare directives.
Jim@programming.devto
Programming@programming.dev•Write code that is easy to delete, not easy to extendEnglish
8·1 年前This is a classic piece, and I love the contradictions in the text. It encapsulates my feelings on good software and code that it almost becomes an art than a science.
Jim@programming.devto
Linux@programming.dev•PSA: You should know that Debian Trixie/Testing does not receive security updates in a timely manner, and is not intended for production useEnglish
7·1 年前PSA for Debian Testing users: read the wiki
https://wiki.debian.org/DebianTesting
Control-F
securityreturns 18 results. This is well known and there’s even instructions on how to get faster updates in testing if you want.
Jim@programming.devto
Programming@programming.dev•Which protocol or open standard do you like or wish was more popular?English
5·1 年前TIL this exists
Jim@programming.devto
Programming@programming.dev•Which protocol or open standard do you like or wish was more popular?English
3·1 年前I also like the POSIX “seconds since 1970” standard, but I feel that should only be used in RAM when performing operations (time differences in timers etc.). It irks me when it’s used for serialising to text/JSON/XML/CSV.
I’ve seen bugs where programmers tried to represent date in epoch time in seconds or milliseconds in json. So something like “pay date” would be presented by a timestamp, and would get off-by-one errors because whatever time library the programmer was using would do time zone conversions on a timestamp then truncate the date portion.
If the programmer used ISO 8601 style formatting, I don’t think they would have included the timepart and the bug could have been avoided.
Use dates when you need dates and timestamps when you need timestamps!
Do you use it? When?
Parquet is really used for big data batch data processing. It’s columnar-based file format and is optimized for large, aggregation queries. It’s non-human readable so you need a library like apache arrow to read/write to it.
I would use parquet in the following circumstances (or combination of circumstances):
- The data is very large
- I’m integrating this into an analytical query engine (Presto, etc.)
- I’m transporting data that needs to land in an analytical data warehouse (Snowflake, BigQuery, etc.)
- Consumed by data scientists, machine learning engineers, or other data engineers
Since the data is columnar-based, doing queries like
select sum(sales) from revenueis much cheaper and faster if the underlying data is in parquet than csv.The big advantage of csv is that it’s more portable. csv as a data file format has been around forever, so it is used in a lot of places where parquet can’t be used.
Wow everyone seems to love P3 but I actually liked P4 better. I mean I really enjoyed both, but P4 was a more immersive experience for me. I should reboot my vita and play it again.
I really felt like P4 had deeper connections and relationships between the characters. It felt more real, and that made the tension in the game more exciting. I love every second of it and am still trying to find a game like it.
Don’t get me wrong, P3 was great also. The gameplay was superb and the characters were all great. But P4 still has a special place in my heart.
Jim@programming.devto
Piracy: ꜱᴀɪʟ ᴛʜᴇ ʜɪɢʜ ꜱᴇᴀꜱ@lemmy.dbzer0.com•*Permanently Deleted*English
10·1 年前They’re asking for TV manufacturers to block a VPN app in the TV. Not to block VPN in general.
Jim@programming.devto
Open Source@lemmy.ml•Ladybird Browser Team Selects Swift as Preferred LanguageEnglish
7·1 年前Dude, if you’re being obtuse on purpose because you have an ax to grind against Rust, try a different approach. You’re not getting anywhere, clearly by the fact that no one agrees with you.
If you don’t like that Rust has a restricted trademark, then call that out instead of trying to label the software and it’s license as non-free. It’s literally called out in my source that name restrictions ipso facto does not violate freedom 3.
But if you genuinely believe that the implementation of the Rust language and it’s trademark is burdensome to create a fork, and you want people to believe you, then you gotta bring receipts. Remember, the benchmark that we both quoted is that it “effectively hampers you from releasing your changes”. It being “not a piece of cake” doesn’t cut it.
Hint: Google Rust forks since their existence also undermines your claim.
Good luck.
Jim@programming.devto
Open Source@lemmy.ml•Ladybird Browser Team Selects Swift as Preferred LanguageEnglish
24·1 年前Please read this and try again.
https://www.gnu.org/philosophy/free-sw.en.html#packaging
Rules about how to package a modified version are acceptable, if they don’t substantively limit your freedom to release modified versions, or your freedom to make and use modified versions privately. Thus, it is acceptable for the license to require that you change the name of the modified version, remove a logo, or identify your modifications as yours. As long as these requirements are not so burdensome that they effectively hamper you from releasing your changes, they are acceptable; you’re already making other changes to the program, so you won’t have trouble making a few more.
Password managers support passkeys.
Jim@programming.devto
Asklemmy@lemmy.ml•What web browser extensions would you highly recommend to others?English
2·1 年前If you are being intentional about its use, then you can get a lot out of it. But for some, maybe even most, YouTube is a distraction.
Jim@programming.devto
Android@lemdro.id•Google Maps for Android now supports Bluetooth beacons for tunnel navigationEnglish
20·2 年前Yes it can be an issue because the GPS doesn’t know where you are and thinks you are on an aboveground street. Freeway tunnels can have multiple exits too.
Jim@programming.devto
Firefox@lemmy.ml•Firefox now supports clean URLs with the new "Copy link without site tracking" optionEnglish
4·2 年前I disagree. I think the default option should be what users expect, and users expect “copy” to do exactly that: copy without modifying the text.
Jim@programming.devto
World News@lemmy.ml•Vivek Ramaswamy Wants to Raise Voting Age to 25 (or have a "competency test" for people 18-25)English
9·2 年前I feel the opposite. We should have mandatory voting for all federal general elections. Treat it like jury duty or taxes - voting is a civic duty. You should be compelled to cast a ballot even if you leave it blank because you have no preference.
Of course, this can only workwith automatic voter registration and 100% mail-in ballots.
Jim@programming.devto
Games@sh.itjust.works•Logan Paul still hasn't refunded victims of his crypto videogame scam | PC GamerEnglish
1·2 年前I don’t want to victim blame here, but both “Logan Paul” and “crypto” together is just screaming scam. That being said, I hope the victims get their money back, though from the article, I doubt it’ll be anytime soon if at all.






I think a few folks haven’t read the article or know who Jeff Geerling is. The title of this article is confusing.
Jeff posted a video on YT about how to self-host your own media in 2024. He recently got a violation from YT that YT considers his video to be harmful and dangerous. He appealed, got denied, but then the update is that YT removed the violation.