Dan Goodin

@dangoodin@infosec.exchange
14.5K Followers
1.1K Following
4.6K Posts
Reporter covering security at Ars Technica. DM me on Signal: DanArs.82.
Site:https://arstechnica.com/author/dan-goodin/
It would appear that if a Microsoft account holder wants to go passwordless, they MUST install Microsoft Authenticator. Authy, Google Authenticator and similar apps won't work. Can anyone confirm?

Microsoft writes:

"For example, if you have a password and “one time code” set up on your account, we’ll prompt you to sign in with your one time code instead of your password. After you’re signed in, you’ll be prompted to enroll a passkey."

I don't understand this. Why would Microsoft remove the password requirement and rely solely on a 1-time code? And what happens if the user decides not to use a passkey?

Windows RDP lets you log in using revoked passwords. Microsoft is OK with that.

Researchers say the behavior amounts to a persistent backdoor.

Ars Technica
If me wanting to view any of your shit requires zuckerburg begging me to log in or create an account, I will just as soon fuck off.
April was the first full month since I installed my 4.1 kW solar system and accompanying batteries. And just like that, I went from drawing 200-250 kWh per month from the grid to 3 kWh. For the month, I produced 583 kWh, 284 kWh of which I exported 284 kWh to the grid.

Mike Waltz Accidentally Reveals Obscure App the Government Is Using to Archive Signal Messages

https://www.404media.co/mike-waltz-accidentally-reveals-obscure-app-the-government-is-using-to-archive-signal-messages/

Mike Waltz Accidentally Reveals Obscure App the Government Is Using to Archive Signal Messages

A photograph of Trump administration official Mike Waltz's phone shows him using an unofficial version of Signal designed to archive messages during a cabinet meeting.

404 Media

Trump officials, they're just like us!*

*put off verifying their Signal PIN

Reuters got a photo of Mike Waltz checking Signal in a cabinet meeting and hoo boy, that entire government is running on it

Edited to add: it's not even Signal, it is an app called TM SGNL which "captures" all the Signal messages and archives them... in plaintext... over unencrypted channels...

https://www.reutersconnect.com/item/us-national-security-advisor-mike-waltz-attends-a-cabinet-meeting-held-by-president-trump-at-the-white-house-in-washington/

https://www.404media.co/mike-waltz-accidentally-reveals-obscure-app-the-government-is-using-to-archive-signal-messages/

For World Password Day today 🔑✨

Here again is my tutorial on
how to install the excellent local-only password manager KeePassXC (with a YubiKey)!

This is what I use to store all my passwords! 🔑🔑🔑🔑🔑  

My only disappointment is not starting to use it earlier. Keep your passwords safe! For free! And offline!

https://infosec.exchange/@Em0nM4stodon/114184594797507039

#WorldPasswordDay #Security #Privacy #KeePass #KeePassXC

Em :official_verified: (@Em0nM4stodon@infosec.exchange)

Attached: 1 image New Privacy Guides article 🔐✨ by me: If you want to keep your password manager local-only, KeePassXC is a great solution! It's free, Open-source, Easy to install and use, Doesn't require an account, Works on Linux, macOS, and Windows, And the team is here! 👉 @keepassxc@fosstodon.org Here's how to set it up with a YubiKey: https://www.privacyguides.org/articles/2025/03/18/installing-keepassxc-and-yubikey/ #PrivacyGuides #KeePassXC #Privacy #Security #PasswordManager #Passwords #FOSS

Infosec Exchange

I'm looking forward to being at #CYBERUK25 next week. Lots of interesting looking sessions and I'm sure it will be great to catch up with a lot of people too. Who will I see there? 🙂

I should also note that I have availability for writing news, features and analysis from the show. I already have several ideas and proposals about what to potentially write about, so if you're looking for editorial from one of the premier cybersecurity events in the calendar, please do get in touch! ✍

(Especially because I'm discovering that going as free agent means the costs of travel and accommodation are all coming out my own pocket! It's why I'm so late to sign up, but I couldn't feel FOMO twice in two weeks. So an opportunity to make that money back would be most welcome. 😅 )

https://dannypalmer.co.uk/

Danny Palmer

Award-winning cybersecurity writer and editor with over a decade of experience covering cybersecurity threats and trends.

Danny Palmer
@GossiTheDog @mttaggart
Thanks.
Yes, you can still RDP in with the old password after the account has been switched to passwordless. No Microsoft Authenticator required.
×
April was the first full month since I installed my 4.1 kW solar system and accompanying batteries. And just like that, I went from drawing 200-250 kWh per month from the grid to 3 kWh. For the month, I produced 583 kWh, 284 kWh of which I exported 284 kWh to the grid.
@dangoodin if you have a battery and you can time when to dump it into the grid, itll help even more

@Viss

I don't understand. Right now, I produce all the power I consume during day light hours. During this time, I'm feeding to the grid, minus the 4-8 kWh I use to recharge my battery. When the sun goes down, I draw off my battery until the next day. So I'm basically never drawing from the grid at all. How would I time things to get even more benefit?

@dangoodin @Viss Some utilities have different rates at different times of day or based on demand.
@dangoodin because in california we're stuck with time of use rates, which change during the day - so if you dump your battery during the most expensive time, you get a better rate. if you can charge from the grid overnight you can amplify it a bit more

@Viss

OK, now I see what you mean.

@dangoodin @Viss In some parts of the Northeast US, the electric company will pay to install a thermal mass battery for heating, where the mass is heated during cheaper rate hours and then used to heat the home or hot water when rates are higher. My aunt and uncle had one of these years ago
@wcbdata @dangoodin thats pretty neat!
@Viss @wcbdata @dangoodin we had them decades ago in the UK, electric storage heaters. Rather bulky but very reliable. Just a heating element, controls and a box full of bricks. They weren't subsidised, and the old radio teleswitch control system is being replaced, and peak rate times are different nowadays.

@Viss @dangoodin TOU arbitrage is meaningful only during summer rates, so starting yesterday. The bump during peak hours in the winter is too small to offset the difference between what you pay to receive from the grid and what you get when you send to the grid.

They make it sound like the dollar amount is the same in both directions, but it isn't really.

Also, be aware that these are the boom months for solar, especially where you are in SF. You'll be pretty heavy in deficit spending from about late October through mid March. You'll learn the seasonal pattern, and from what I can gather about you, you're going to have fun doing it.

@mweiss @Viss

This is helpful insight. That said, I'm currently generating 3.5X what I'm consuming. I don't know what that multiple will be come Winter, but I wouldn't be surprised if its still 1.5 or 2. My hope is that the amount I draw from the grid even during those months will be negligible. 🤞

@dangoodin @Viss if you're generating 3x consumption, then you need to get on moving your gas appliances to electric. The payback will be very quick, particularly since you're on NEM3, IIRC.

On the stormiest days, my production was about 1/7 that of the sunniest days, so you're likely to be close to net zero even in January with your current pattern. But an electric water heater will be your biggest year round consumer, so you'll be able to move to a more reasonable balance.

@mweiss @Viss

Well, there are workers installing a heat pump, which is replacing the gas furnace, as I type. I plan on replacing the gas dryer and gas stove next (although my understanding is that gas stoves are expensive to buy and have installed so not sure when I'll be able to afford that). I have an on-demand (tankless) water heater that runs on gas. The only space for it is in a tiny crawl space. My understanding is that electric tankless heaters aren't all that great. Given our low use of hot water, I think I can live with a gas powerered one, at least until electric tankless heaters improve.

@dangoodin @Viss the heat pump is going to be good for you. Induction stoves aren't cheap, but they're both more efficient and better for your indoor air quality. Not that I've been able to make the switch just yet either.

The water heater is an issue. If you don't have the space for a tank, you're pretty well stuck for now. Heating water at your place is a tankless job, and gas is your only viable option.

@dangoodin Lol, you used up like 50 cents worth of electricity. Do you pay by check?
@dangoodin Cool. How much are you saving per month?

@tmiller

Probably about $100 now. As I replace my gas appliances with electric ones, I'll save even more. Heat pump is being installed as we speak and should be up and running tomorrow.

@dangoodin neat! I hope you got a cool grid formering inverter for both yourself when theres an outage and for the girds health!

@slut

This is the first I have ever heard of such a thing. I just did a quick search online. but can't tell if this is something homeowners get or that power companies provide. My solar installer never mentioned these things to me.

@dangoodin @slut you got batteries installed in a grid connected system in California. As far as I know, you have that function as a requirement for the permit. Check with your installer just to be sure.

@mweiss @slut

Also helpful. Thanks.

@dangoodin How much did the system and batteries cost?
@KitsuneVixi @dangoodin What kind of batteries, and how much capacity? I have solar, but only grid-tied, no batteries, not sure it makes sense yet for me.