Roberto Selbach 

101 Followers
552 Following
128 Posts

Software engineer in Québec 🇨🇦, mostly doing cloud and identity (IAM) stuff.

I'm also a husband and a dad. And I have a dog. I'm also a big geek who loves scifi, comics, and Legos.

Je parle français , I also speak English 🇨🇦, falo português 🇧🇷, hablo castellano 🇦🇷 und kann ich ein bisschen Deutsch 🇩🇪



#golang #lego #comics #space #cloud #identity

Webhttps://roberto.selbach.ca
LocationQuebec, Canada
Pronounshe/him
I ate way too much turkey. That is all.

Elon Musk, de héros à zéro par le chemin le plus court

https://bit.ly/3PPvLKA

Elon Musk, de héros à zéro par le chemin le plus court

Toutefois, Musk n’en est pas à un revirement près et peut assurément rebondir au cours des mois à venir.

Le Devoir

Hey folks: Mastodon might get quote-toots as a feature. It might not. The folks who want the feature have reasonable, legit reasons to want it, and the people who are opposed to the feature have solid reasons they don't.

It's a tradeoff. Please let's not make it a crusade -- either way.

Ok Google, where's my car?

#blizzard #snow #MeanwhileInCanada

Moved my instance over to #aws today. The process is not trivial but it is less complicated than I expected.

‘ChatGPT is so good at generating convincing answers it is easy to forget that it is a model of language and not a source of wisdom.’

@[email protected] on AI chatbots, in the new issue:

http://lrb.co.uk/the-paper/v45/n01/paul-taylor/on-chatgpt

Paul Taylor · On ChatGPT · LRB 5 January 2023

London Review of Books

À tout le monde au Québec pis a l'est du pays, bonne chance ce soir pis demain 🌨️

Je suis tellement content de pas avoir besoin de sortir de chez moi pour les prochains jours 😬 #BombeMétéo

LASTPASS NEWS ALERT AND COMMENTARY:
LastPass attackers know your name and billing address and all websites you have saved passwords for, and if your master password isn't sufficiently strong may be possible to brute-force open everything on attacker's machines.

PLEASE READ BEFORE PROCEEDING: https://blog.lastpass.com/2022/12/notice-of-recent-security-incident/

The fact LastPass doesn't encrypt website URLs is a known flaw it appears they never fixed on purpose, going back almost 6 years:
https://hackernoon.com/psa-lastpass-does-not-encrypt-everything-in-your-vault-8722d69b2032

This eventual possible security breach was planned-for as part of LastPass' design for username and password protection. This doesn't break the core offering.
But it has stripped away multiple layers of protection and will hasten my looking at @bitwarden

It's impossible to be completely secure in a massive offering. However I have always disagreed with their decision to not 100% encrypt all metadata, and this event shows that was a foolish choice when seen against the inevitable of the entropy our complex electronic systems.

In the end, a password manager is still right choice in comparison to alternative. And a cloud-native offering like LastPass strongly hedges against data loss by normal users trying to manage their own vault. That is an undersold primary risk, not hackers. Still, very disappointed.

Current password setup:
- Primary vault is LastPass with 2FA
- Core fallback "key" accounts like email that allow pw reset are only in a KeyPass db file with 20char password, synced via OneDrive+2FA.
- This is then further backed-up with BackBlaze, using 40char encryption key

Security Incident December 2022 Update - LastPass

We are working diligently to understand the scope of the incident and identify what specific information has been accessed.

The LastPass Blog

So as a business Twitter looks extremely screwed. Given there is competition for talent and the low chance of business upside, it’s hard to imagine hiring a strong team to keep the product going.

I expect the product to stagnate over time as small superficial changes can be made (shipping half a dozen badges) while substantial changes cannot. All this with a backdrop of a business that is hemorrhaging money faster than it makes.