some people deserve Extra-Hell

@beyondmachines1

Should be right there next to the guy who wants you to type a long password into a short field where each character turns into an asterisk when you type it.

Because .... dunno ... there's someone in a black hood hanging from a rope above my head??

@number6 @beyondmachines1 I mean it protects you from Recall... which imo is already a breach if it's present.

@Epic_Null @number6 that's a weird risk reduction idea.

Have spyware on my computer, then make my computer less accessible to me so the spyware has a more difficult time.
🤔

@beyondmachines1 @number6 Does that also not technically describe any remote desktop software used for tech support?

But yeah... definitely a weird risk reduction situation.

@Epic_Null Pasting passwords in password fields (masked by default) and displaying passwords are two different things.

Preventing pasting passwords DOESN'T protect you from spywares making screenshots… Copying passwords from a password manager doesn't imply displaying it.

On the contrary, preventing pasting passwords forces users to type it, and mostly likely, to display it from password managers in order to type it. Thus exposing it to M$' screenshot-based malware…

@beyondmachines1 @number6

@devnull @Epic_Null @beyondmachines1

You're saying that it protects people from some hypothetical edge case where malware is recording and sending screenshots off into the internet, but that the developer forgot to capture keystrokes or clipboard contents?

The reality is that hacks occur because people get fatigued having to put in unique, long complicated passwords. Oh, and if they get it wrong 3 times they get locked out of their own data.

Asterisks hinder good security practices.

@number6 @devnull

I think that @Epic_Null was joking about very small password input fields where part of password string would overflow and not be visible on the screen.

@number6

>> You're saying that it protects people from some hypothetical edge case where malware is recording and sending screenshots

No, I'm NOT. I said the exact opposite. That preventing pasting passwords DOESN'T protect from it.

Also, it's not "hypothetical"… I was answering to someone who mentionned "recall" which is micro$oft bullshit "AI that find data you might have accidently deleted" which does EXACTLY that: Screenthots your screen every few seconds…

@Epic_Null @beyondmachines1

@number6 Asterisks prevent anyone next to you to know your password is crao… Not to "hinder good security practices"

I won't answer to the rest of your post about "why hacks happens".
Any "single/unique reasons" that fits an easy narrative il total bullsiht… Security efis complicated

And the rest of your comment has nothing to do with my initial statement anyway. Also, I'm not interested in debating with someone claiming I said the exact opposite of what I said…

@Epic_Null @beyondmachines1

@number6

I'm tired of people acting as if M$ screenshot spyware BS and typical "AI" crap¹ wasn't a problem "cause real malware can capture your keystrokes".

Thanks captain obvious, I know how computers work, it pays my bills… And keystrokes has nothing to do with M$ malware "recall"…

1 To refer to stupid and intrusive continuous screenshots + OCR based spyware, recording everything people do on M$ OSes with builtin malware…

@Epic_Null @beyondmachines1

@number6 People are not supposed to "to put in unique, long complicated passwords" and complain about asterisks, which are not the problem

They're supposed to use local password, not "the claoud", not shitty DIY "encyption" in JS by random joe that you're "supposed to just trust" cause he slapped a megacorporporation logo on his crap code…

What hinders good security practices is stupid web devs preventing pasting in password (and to a lesser extent username) field

@Epic_Null @beyondmachines1

@devnull @number6 @beyondmachines1 Hey Dave? I don't think your client is displaying reply chains correctly. Number6 was responding to my joke about the fields protecting from Recall.

@Epic_Null My client shows his post as an aswer to mine 🤔

@number6 @beyondmachines1

@devnull @Epic_Null @beyondmachines1

I barely do Windows. I thought "Recall" was a virus of some type. Guess I'll have to read up.

My only point is that asterisks don't make us safer.

@number6 @devnull @beyondmachines1 In spirit, you would be correct. It is spyware that takes screenshots of your screen regularly, making any information on the screen vulnerable.

In technicalities, it's a first party tool from Microsoft.

@Epic_Null Yeah it's from M$. And being from M$ is exactly what makes it even worse than third party malware, not less

Because

- It normalises spywares from corporation, "because there's no risk, you can trust Microsoft 🤡" kind of bullshit
- Users don't even need to "makes mistakes or install software from unstrusted sources". They just have a built-in malware and no one even asked them permission. Some marketing moron just decided it's acceptable to dobit

@number6 @beyondmachines1

@devnull @number6 @beyondmachines1 You are talking to someone who ditched Windows years ago on their personal machine.

IMO the only way it becomes not worse than malware is if it finally breaks Window's hold on companies and users, as well as destroying the trust in Microsoft once and for all.

@Epic_Null @devnull @beyondmachines1

Can you opt-out or uninstall? I just installed a duo-boot with Windows 11. I noticed something about AI but ignored it.

@number6 @devnull @beyondmachines1 Currently it requires a copilot + pc and setup, but imo it should be treated as always active, especially with Microsoft's history with consent.

@Epic_Null

"Consent" to micro$oft.
Do you want to be spied on? We won't tell clearly that the default answer is "yes". Here's your choices

- Yes, I want to spied on as much as you'd like
- Yes, I want to spied on as much as you'd like. Just slightly less than response one. Let's call that "Basic telemetry"

On their OS

And
- Yes, I want to spied on as much as you'd like
- Yes, ask me later again later so I assume I'm not being spied on for now

On their web crap

@number6 @beyondmachines1