L.F. Domingo

34 Followers
115 Following
48 Posts
#mauistrong
recovering cybersecurity consultant now 3rd year PhD @ UMD INFO.
pronounsshe/her/hers
websitelinktr.ee/lovelydomingo

For some reason guys in tech who cause serious harms seem to only understand the idea of failing upward.

The public evilbrag is a basic stepping stone in that upward mobility.

"As automated decision systems (ADS) get more deeply embedded into business processes worldwide, there is a growing need for practical ways to establish meaningful transparency. Here we argue that universally perfect transparency is impossible to achieve. We introduce the concept of contextual transparency as an approach that integrates social science, engineering and information design to help improve ADS transparency"

https://www.nature.com/articles/s42256-023-00623-7

Introducing contextual transparency for automated decision systems - Nature Machine Intelligence

An increasing number of regulations demand transparency in automated decision-making processes such as in automated online recruitment. To provide meaningful transparency, Sloane et al. propose the use of ‘nutritional’ labels that display specific information about an automated decision system, depending on the context.

Nature
L.A.’s Scoring System for Subsidized Housing Gives Black and Latino People Experiencing Homelessness Lower Priority Scores – The Markup

An investigation by The Markup found racial disparities in L.A.’s intake system for unhoused people

Do you have questions about generative AI? Is there any reason to be optimistic about this technology? What should we worry about?

We'll be exploring these and more at the upcoming salon hosted by ❤️Fight & 🐦amnestyusa on Mar 23 at 2pm ET. Register today https://www.emergingtechforactivists.com/

Emerging Tech for Activists

Amnesty International and Fight for the Future host sporadic seasons of salons on emerging tech. Our first season, Web3 for Activists, is available now. Season 2, Generative AI for Activists, is happening throughout 2023. Join us to hear technologists and human rights organizers hash out the best ways to intentionally shape a human-first future for […]

Fight for the Future

A queer gaming collective (KRITIQAL) is doing an itch.io bundle for the cost of a shitty wizard game by bigots, you can get 69 good magic games by LGBTQ+ creators. their summary of the bundle:

  • 69 magical works from LGBTQ+ creators
  • $60, or the price of one AAA wizard game
  • proceeds split evenly between participants
  • no TERFs allowed

https://itch.io/b/1712/trans-witches-are-witches

Trans Witches are Witches by Nathalie and 56 others

Trans Witches are Witches: 69 items for $60.00

itch.io

I signed a petition on Action Network telling Maryland University Campus Presidents, Chancellor Perman, and Incoming Governor Moore to Support the Right to Living Wages and Collective Bargaining for Maryland Higher Ed Workers!

Can you join me? https://actionnetwork.org/petitions/support-the-right-to-living-wages-and-collective-bargaining-for-maryland-higher-ed-workers?source=direct_link&

Support the Right to Living Wages and Collective Bargaining for Maryland Higher Ed Workers!

We, the undersigned, demand that the Maryland General Assembly, incoming Governor Wes Moore, and the leadership of Maryland State higher education institutions support living wages and the passage of a bill that would give Maryland State higher education workers the right to bargain collectively. As members of the university communities within the state of Maryland, we believe that workers should have a strong and collective voice in decisions that affect our working conditions, salaries, and benefits. Collective bargaining is a fundamental right that allows workers to negotiate fair and equitable contracts with our employers, and it is essential for promoting fairness, respect, and dignity in the workplace. Across the United States, many public and private higher education institutions engage in collective bargaining, including many peer institutions. Collective bargaining encourages transparency and accountability between workers and management. Without this, the highest levels of State higher education administration have dramatically increased their own ranks and salaries for years while denying living wages and job security to the majority of State higher education employees. USM institutions, for example, currently pay poverty level wages to their undergraduate and graduate student workers and are rapidly replacing traditional full-time faculty positions with low paid, contingent positions. Higher education workers serve an important role in the education and research mission of our universities. We deserve to be treated with respect and to have a say in the decisions that affect our lives. We demand that the members of the Maryland General Assembly and the leadership of Maryland higher education secure funding that allows a living wage and support collective bargaining rights for State higher education workers.

Does anyone feel like sitting down in front of the computer and playing around with their notes a bit?

I just wrote down how I set up and try to maintain my (academic) reading list in #Obsidian using the #Projects plugin by @marcusolsson and #Zotero. Might post it again after the holidays, but for now, here's the description of my approach for those who asked. Thus, fulfilling my promise from this thread: https://hcommons.social/@natalie/109557676423033978

https://nataliekraneiss.com/your-academic-reading-list-in-obsidian/

@obsidianmd @phdlife @phdstudents #phd #literaturereview #studying #readinglist #organization #planning #tracking

Natalie (@[email protected])

Attached: 3 images May I once again share my excitement about the #Projects plugin for #Obsidian from @[email protected]? I've finally managed to format my references from #Zotero so that they show up in Projects without any problems. Now I can finally create a reading list and easily track and change the status of books from within the Projects view. Wonderful. Can't wait to continue reading for my dissertation next year and finally track what I want to read or have read each week. But for now, it is a reading break here! @[email protected] @[email protected] @[email protected] #phd #literaturereview #studying #projectplanning

hcommons.social

Many of you have been asking for my thoughts on the #LastPass breach, and I apologize that I'm a couple days late delivering.

Apart from all of the other commentary out there, here's what you need to know from a #password cracker's perspective!

Your vault is encrypted with #AES256 using a key that is derived from your master password, which is hashed using a minimum of 100,100 rounds of PBKDF2-HMAC-SHA256 (can be configured to use more rounds, but most people don't). #PBKDF2 is the minimum acceptable standard in key derivation functions (KDFs); it is compute-hard only and fits entirely within registers, so it is highly amenable to acceleration. However, it is the only #KDF that is FIPS/NIST approved, so it's the best (or only) KDF available to many applications. So while there are LOTS of things wrong with LastPass, key derivation isn't necessarily one of them.

Using #Hashcat with the top-of-the-line RTX 4090, you can crack PBKDF2-HMAC-SHA256 with 100,100 rounds at about 88 KH/s. At this speed an attacker could test ~7.6 billion passwords per day, which may sound like a lot, but it really isn't. By comparison, the same GPU can test Windows NT hashes at a rate of 288.5 GH/s, or ~25 quadrillion passwords per day. So while LastPass's hashing is nearly two orders of magnitude faster than the < 10 KH/s that I recommend, it's still more than 3 million times slower than cracking Windows/Active Directory passwords. In practice, it would take you about 3.25 hours to run through rockyou.txt + best64.rule, and a little under two months to exhaust rockyou.txt + rockyou-30000.rule.

Keep in mind these are the speeds for cracking a single vault; for an attacker to achieve this speed, they would have to single out your vault and dedicate their resources to cracking only your vault. If they're trying 1,000 vaults simultaneously, the speed would drop to just 88 H/s. With 1 million vaults, the speed drops to an abysmal 0.088 H/s, or 11.4 seconds to test just one password. Practically speaking, what this means is the attackers will target four groups of users:

1. users for which they have previously-compromised passwords (password reuse, credential stuffing)
2. users with laughably weak master passwords (think top20k)
3. users they can phish
4. high value targets (celebs, .gov, .mil, fortune 100)

If you are not in this list / you don't get phished, then it is highly unlikely your vault will be targeted. And due to the fairly expensive KDF, even passwords of moderate complexity should be safe.

I've seen several people recommend changing your master password as a mitigation for this breach. While changing your master password will help mitigate future breaches should you continue to use LastPass (you shouldn't), it does literally nothing to mitigate this current breach. The attacker has your vault, which was encrypted using a key derived from your master password. That's done, that's in the past. Changing your password will re-encrypt your vault with the new password, but of course it won't re-encrypt the copy of the vault the attacker has with your new password. That would be impossible unless you somehow had access to the attacker's copy of the vault, which if you do, please let me know?

A proper mitigation would be to migrate to #Bitwarden or #1Password, change the passwords for each of your accounts as you migrate over, and also review the MFA status of each of your accounts as well. The perfect way to spend your holiday vacation! Start the new year fresh with proper password hygiene.

For more password insights like this, give me a follow!

"You cannot divorce yourself from yourself. You know you are the hyphen in American-raised. Your identity scrawls the length and breadth of the page, American-raised girl. American-raised Filipina. Because you have always had one foot planted in the West, one foot floating on the islands, and your arms have stretched across the generations, barely kissing your father’s province, the dreams your mother has for you.” (1/3)
“Because you were meant for the better life, whatever that is, been told you mustn’t forget where you come from, what others have done for you. Because all your life you’ve simply been told. Just told.” (2/3)