-
• #4252
I'm pretty much pig-ignorant on this, but Bruce Shneier claims that the XKCD long password thing is no longer a good tactic: https://www.schneier.com/crypto-gram-1403.html#13
-
• #4253
He's right. It's nowhere near as good as using some alternative method such as 2 factor auth or something truly random.
Picking anything based on you, (i.e. facts known about you, your favourite lyric, etc, even your language) is a bad idea.
But... presuming you have a line of gibberish, a longer line will always win. Length trumps complexity enough that if you make it reasonable long and only slightly complex, that's better than short and very complex.
It's only a matter of time though. Everything password based is crackable.
-
• #4254
It took me 2 days to notice the ISIS thread, buried away as it was at the time. Come on! I want my lunacy on page 1! It's obvious to me now that Microcosm is all part of the conspiracy to keep the truth hidden and this goes all the way to the top!
-
• #4256
That thread is the den… and should be sinked.
-
• #4257
It's trivial to photoshop an image to show those movements (even the nose picking). It's only marginally more difficult to write an app to apply those transformations on demand. Which is what would happen if such an authentication system were ever put into use.
You simply cannot trust a remote system to be showing you an image of what is genuinely there.
-
• #4258
Speaking of passwords and Persona, anyone trying to log in with Persona on a BlackBerry OS10 phone (in my case Z10)?
It doesn't work on mine (the Persona page keeps spinning). I don't know the details of how it works between LFGSS and Persona, but it looks more like an issue with Mozilla's page than LFGSS. So, I guess, no solutions other than waiting for 10.3? -
• #4259
Hah! You are the single person who uses the Blackberry: https://www.lfgss.com/conversations/131364/?offset=3775#comment11758406
I'm afraid that I have no Blackberry test devices, so even if it is at our end I'm going to be stabbing in the dark even more than usual.
-
• #4260
It's a Blackberry Z10!! With BB10 !! I have all types of Linux-based phones (and no, for me Android is not Linux based :p it just has the kernel), from the Maemo ones up to the Jolla, and, to me, the new BB10 IS an amazing OS and the Z10 an amazing phone (save for the battery a bit)
It's just BlackBerry as a company that is a bit shitty and too much Enterprise oriented.
Thanks anyway. I'll wait for the next update and hope it'll solve it.
-
• #4261
it can't be named :-p as (s)he (:-p) can't login
-
• #4262
Trending ftw
-
• #4263
Heh.
Have you tried enabling third party cookies, or simply signing in directly at https://login.persona.org/
-
• #4264
login.persona.org tells me that my browser is not supported.
Which is real weird as the BB10 has one of the best browsers out there and is actually based on Gecko (which is, you know, but not others, from Mozilla).
-
• #4265
Persona falsely gives that message when third party cookies aren't enabled, or you are in private browsing.
It really means "browser is not supported as currently configured".
But as Persona doesn't know whether you can reconfigure your browser, it just gives a simpler message.
-
• #4266
Cookies are enabled and I rarely use private mode.
I think it really thinks it is not supported.Don't get that message when trying to login from here though. It simply opens the new tab with the Connecting to Persona and the spinner and there it stays until it closes it.
-
• #4267
Maybe try Dolphin:
http://appworld.blackberry.com/webstore/content/95697/?lang=en -
• #4268
Naa, thanks. I'll keep reading it from my PC, tablet or iPhone until the problem solves itself :p
Thanks though -
• #4269
Can the cancel and post reply buttons be separated please? One on the left, the other on the right?
-
• #4270
Can the cancel and post reply buttons be separated please? One on the left, the other on the right?
On which screen.
In the post box I see...
1 Attachment
-
• #4271
Screenshot
1 Attachment
-
• #4272
Ah, mobile view.
Right you are.
-
• #4273
"Jump to first unread post" is still occasionally erratic: I know I read Amey's post below mine.
1 Attachment
-
• #4274
That screenshot doesn't work for me. Clicking on it downloads a file with a funny extension.
EDIT Emyr's one not Scilly's one
-
• #4275
Using stock browser on Cyanogenmod11(A4.4.4), click "upload a file", select "Documents" (gallery not offered :-/) then select a photo or screenshot, that's what I get.
Only to the extent of calculating md5 hashes for the top 100 weak passwords so I could tell some users they were their own worst enemy.
If you know someone's using phrases, have an idea how long it is, and their main language, you can skip the letter-level bruteforcing and skip to the data-mining-based guessing.