Jason Butz

@jbutz
0 Followers
96 Following
78 Posts
Software engineer and architect, heavy AWS focus. AWS Certification SME and AWS Community Builder. Boardgame lover. Aspiring woodworker.
Homepagehttps://jasonbutz.info

Google has just updated its 2FA Authenticator app and added a much-needed feature: the ability to sync secrets across devices.

TL;DR: Don't turn it on.

The new update allows users to sign in with their Google Account and sync 2FA secrets across their iOS and Android devices.

We analyzed the network traffic when the app syncs the secrets, and it turns out the traffic is not end-to-end encrypted. As shown in the screenshots, this means that Google can see the secrets, likely even while they’re stored on their servers. There is no option to add a passphrase to protect the secrets, to make them accessible only by the user.

Why is this bad?

Every 2FA QR code contains a secret, or a seed, that’s used to generate the one-time codes. If someone else knows the secret, they can generate the same one-time codes and defeat 2FA protections. So, if there’s ever a data breach or if someone obtains access .... 🧵

#Privacy #Cybersecurity #InfoSec #2FA #Google #Security

We now are mirroring the NPR RSS feeds to the #fediverse

https://blog.hello.coop/2023/04/nprs-rise-on-the-fediverse/

NPR's Rise on the Fediverse

This week, NPR chose to no longer post on Twitter. We had been mirroring the @NPR and @nprpolitics Twitter accounts on press.coop, and had a surge of interest in following @[email protected], which is now the most popular accounts on press.coop (see table below). After upgrading our infrastructure to address the heightened load, we updated the […]

HellĹŤ Blog

TIL: lace cards

It’s a computer punch card with every possible spot punched out, so what remains is a flimsy filamentous net of paper that instantly tears and jams up the card reader.

Old-school denial of service attack.

https://en.m.wikipedia.org/wiki/Lace_card

Lace card - Wikipedia

#AWS #CDK users, do you use the CDK's context feature? If so, do you have CICD pipelines? How do you work different environments into the mix? I'm curious how people are using contexts.

#awscdk #CloudDevelopmentKit

About a year ago my wife and I were in #NewMexico. While there we grabbed a couple jars of #HatchChiles . I decided tonight we'd use them, and I made #enchiladas. They're delicious and my best attempt yet, and still so inferior to what we had. New Mexico, we miss your food!
It's okay if you failed today. You can try again tomorrow.

People do not seem to realize this - so here is a #PSA

do NOT UPLOAD PERSONAL DOCUMENTS OR CONFIDENTIAL INFORMATION to ChatGPT!!

#OpenAI reserves the right to use ALL #prompts as future training data. You are making your data PUBLIC by sending it to #ChatGPT

OpenAI for now, says that content provided by API will not be used to train. But they still are keeping it. And that could change at any time in the future

see - https://openai.com/policies/terms-of-use

#AI #LLM

Terms of use

What conferences do you want to attend this year? #AWS #reInvent is on my list, but I'm looking for other ideas too!

#dev #softwaredevelopment #softwareengineer #webdev

If you haven't already, turn on the nighttime mode on your devices a few hours before bed. Blue light disrupts your sleep.
"The older I get the more and more I miss the people I've lost over the years. Maybe being a tour guide wasn't such a good idea" Best bathroom sign I've seen in a while. #newrivergorgebridge