10 Followers
73 Following
50 Posts
Diversität und Gleichheit, Kooperation und Freiheit, Bildung, inkusive menschenrechte. (er/sein/weiß)
https://social.cologne/@GeorgEhring/109790487471790320
...vielleicht auch interessant für #BNE-Aktive im #FediLZ?
(Wenn es einen besseren Weg gibt, Beiträge vor dem Boosten mit Hashtags zu versehen, bitte ich um Info)
@leadohm @psy4f
GeorgEhring (@[email protected])

Die Medien sollten die Klimakrise äußerst wichtig nehmen und die Zusammenhänge zum praktischen Leben aufzeigen, rät @[email protected] im DLF-Interview. Unangenehme Gefühle benennen, sie sind bei dem Thema angemessen. Und konkrete Handlungsmöglichkeiten zeigen. @[email protected] haben einen Leitfaden für die Berichterstattung über die #Klimakrise herausgegeben. https://www.deutschlandfunk.de/klimakrise-medien-psychologie-bewaeltigung-100.html

Mastodon
Bildungspolitische Sprecherin: "Also, ich glaube nicht, dass das deutsche Schulsystem soziale Ungleichheit fortschreibt."
Ernährungspolitischer Sprecher: "Also, ich glaube nicht, dass vegetarische Ernährung dem Klima nützt."
Sprecher*in für Energiepolitik: "Also, ich glaube nicht, das Atommüll radioaktiv ist." (2/2)
#lukaskoehler, #klimapolitik|scher Sprecher der #FDP glaubt im #deutschlandfunk-Interview faktenfrei herum ""Also, ich glaube nicht, dass der Autobahnkauf [sic!] selber auslöst, dass wir mehr #Verkehr haben." (ab Min. 10:50) https://www.deutschlandfunk.de/int-lukas-koehler-fdp-fraktionsvize-zu-klimaschutz-und-autobahnen-dlf-32ff222c-100.html (1/2)
Int. Lukas Köhler, FDP-Fraktionsvize, zu Klimaschutz und Autobahnen

Deutschlandfunk

@kevlin

Christine Lemmer-Webber (@cwebber) described ChatGPT as Mansplaining As A Service, and honestly I can’t think of a better description. A service that instantly generates vaguely plausible sounding yet totally fabricated and baseless lectures in an instant with unflagging confidence in its own correctness on any topic, without concern, regard or even awareness of the level of expertise of its audience.

...zum Bookmarken:
Swarm Support | Digitalcourage
Wir stellen datenschutzfreundliche Tools und Hilfsmittel zur Verfügung.
https://digitalcourage.de/swarm-support
Danke!
Swarm Support | Digitalcourage

Wir stellen datenschutzfreundliche Tools und Hilfsmittel zur Verfügung

Digitalcourage

Many of you have been asking for my thoughts on the #LastPass breach, and I apologize that I'm a couple days late delivering.

Apart from all of the other commentary out there, here's what you need to know from a #password cracker's perspective!

Your vault is encrypted with #AES256 using a key that is derived from your master password, which is hashed using a minimum of 100,100 rounds of PBKDF2-HMAC-SHA256 (can be configured to use more rounds, but most people don't). #PBKDF2 is the minimum acceptable standard in key derivation functions (KDFs); it is compute-hard only and fits entirely within registers, so it is highly amenable to acceleration. However, it is the only #KDF that is FIPS/NIST approved, so it's the best (or only) KDF available to many applications. So while there are LOTS of things wrong with LastPass, key derivation isn't necessarily one of them.

Using #Hashcat with the top-of-the-line RTX 4090, you can crack PBKDF2-HMAC-SHA256 with 100,100 rounds at about 88 KH/s. At this speed an attacker could test ~7.6 billion passwords per day, which may sound like a lot, but it really isn't. By comparison, the same GPU can test Windows NT hashes at a rate of 288.5 GH/s, or ~25 quadrillion passwords per day. So while LastPass's hashing is nearly two orders of magnitude faster than the < 10 KH/s that I recommend, it's still more than 3 million times slower than cracking Windows/Active Directory passwords. In practice, it would take you about 3.25 hours to run through rockyou.txt + best64.rule, and a little under two months to exhaust rockyou.txt + rockyou-30000.rule.

Keep in mind these are the speeds for cracking a single vault; for an attacker to achieve this speed, they would have to single out your vault and dedicate their resources to cracking only your vault. If they're trying 1,000 vaults simultaneously, the speed would drop to just 88 H/s. With 1 million vaults, the speed drops to an abysmal 0.088 H/s, or 11.4 seconds to test just one password. Practically speaking, what this means is the attackers will target four groups of users:

1. users for which they have previously-compromised passwords (password reuse, credential stuffing)
2. users with laughably weak master passwords (think top20k)
3. users they can phish
4. high value targets (celebs, .gov, .mil, fortune 100)

If you are not in this list / you don't get phished, then it is highly unlikely your vault will be targeted. And due to the fairly expensive KDF, even passwords of moderate complexity should be safe.

I've seen several people recommend changing your master password as a mitigation for this breach. While changing your master password will help mitigate future breaches should you continue to use LastPass (you shouldn't), it does literally nothing to mitigate this current breach. The attacker has your vault, which was encrypted using a key derived from your master password. That's done, that's in the past. Changing your password will re-encrypt your vault with the new password, but of course it won't re-encrypt the copy of the vault the attacker has with your new password. That would be impossible unless you somehow had access to the attacker's copy of the vault, which if you do, please let me know?

A proper mitigation would be to migrate to #Bitwarden or #1Password, change the passwords for each of your accounts as you migrate over, and also review the MFA status of each of your accounts as well. The perfect way to spend your holiday vacation! Start the new year fresh with proper password hygiene.

For more password insights like this, give me a follow!

Die Möglichkeiten sich selbst anzuzeigen im Überblick:

- zur Polizei gehen, anrufen, einen Brief oder eine E-Mail schreiben
- dieses Formular ausfüllen: http://letztegeneration.de/selbstanzeige
- diese Petition unterschreiben:
https://www.change.org/p/werde-teil-der-kriminellen-vereinigung-letzte-generation?recruiter=false&utm_source=share_petition&utm_medium=twitter&utm_campaign=psf_combo_share_initial&recruited_by_id=29a80c00-8210-11ed-a047-e7e984646378

@digitalcourage Fürs Protokoll: Die #Bielefeld-Verschwörungstheorie hat es jüngst in den BBC-Wissenschafts-#Podcast "The Infinite Monkey Cage" geschafft (The Infinite Monkey Cage: The Age of Conspiracy, Minute 04:10) #Empfehlung http://www.bbc.co.uk/programmes/p0dcn52l
BBC Radio 4 - The Infinite Monkey Cage, Series 25, The Age of Conspiracy?

Brian Cox and Robin Ince discover if we are living in a golden-age for conspiracy theories

BBC
Hier das Editorial der aktuellen #iz3w zu den #WomenLifeFreedom Protesten in #Iran Der Text beschreibt Eindrücke von einer Kundgebung im verregneten #Freiburg, bei der phasenweise die Sonne durchbricht. Darunter schreibt die Redaktion: „Wir werden weiter über Iran berichten. Damit das so bleibt, entwickeln wir uns fort: Zusätzlich zur Printzeitschrift startet mit dieser Ausgabe unser neuer Webauftritt. Anschauen kann man sich das hier: https://iz3w.org . Neben unseren Print-Texten wird es zukünftig zusätzliche Online-Inhalte geben und wir können zeitnäher berichten.
Damit das online wie offline gut klappt, brauchen wir eure Unterstützung. Abonniert die iz3w (egal ob Print oder jetzt neu online), werbt für sie & #spende.t“
=>Mache ich hiermit sehr gerne 😃
iz3w - Online & Print Magazin zwischen Nord und Süd - informationszentrum 3. welt

Das iz3w publiziert das Online & Print Magazin iz3w. Der südnordfunk (Magazinsendung) – und fernsicht (die Werkstatt für nordsüdpolitische Bildungsarbeit) sind weitere Aktivitäten.

Henrietta Lacks was a poor, Black, young mother diagnosed cervical cancer in 1951. When her cells were collected w/o consent, scientists saw they multiplied fast.

“HeLa” cells changed #science. They’re used globally to study viruses, drugs, hormones, genes, diseases & develop vaccines. Lacks passed away at 31 w no recognition.

Rebecca Skloot’s beautiful book about her life & legacy is changing that. Now her statue will replace Robert E. Lee in VA. https://www.nytimes.com/2022/12/20/us/henrietta-lacks-statue-roanoke-virginia.html?smid=nytcore-ios-share&referringSource=articleShare #history #HistoryRemix

A Statue of Henrietta Lacks Will Replace a Monument to Robert E. Lee

The statue, scheduled to be erected next fall in Roanoke, Va., is part of a local project to recognize Black history in community spaces.