Royce Williams

3.5K Followers
3.9K Following
14.9K Posts

Just doing my undue diligence.

ISP vet, password cracker (Team Hashcat), security demi-boffin, YubiKey stan, public-interest technologist, AK license plate geek. Husband to a philosopher, father to a llama fanatic. Views his.

Day job: Enterprise Security Architect for an Alaskan ISP.

Obsessed with security keys:
techsolvency.com/mfa/security-keys

My 2017 #BSidesLV talk "Password Cracking 201: Beyond the Basics":
youtube.com/watch?v=-uiMQGICeQY&t=20260s

Followed you out of the blue = stole you from someone I respect.

Blocked inadvertently? Ask!

Am I following a dirtbag? Tell me!

Suggestions welcome!

Photo: White 50-ish man w/big forehead, short beard, & glasses, grinning by a display of Alaskan license plates.

Boosts not about security ... usually are.

Banner: 5 rows of security keys in a wall case.

#NonAIContent

#hashcat #Alaska #YubiKeys #LicensePlates

P.S. I hate advance-fee scammers w/heat of 400B suns

❀️:βš›πŸ‘¨β€πŸ‘©β€πŸ‘§πŸ›‘πŸ™ŠπŸŒ»πŸ—½πŸ’»βœπŸŽ₯🍦🌢🍫!

Stuffhttps://www.techsolvency.com/roycewilliams/mastodon
Keybasehttps://keybase.io/royce
GitHubhttps://github.com/roycewilliams
LinkedInhttps://www.linkedin.com/in/roycewilliams
Gravatarhttps://gravatar.com/tychotithonus
Not "dehashed"!https://www.techsolvency.com/passwords/dehashing-reversing-decrypting/
@womble Ah, absolutely makes sense!
@kwf Totally agreed - and you have more experience with that problem surface than I do!
@kwf Hmm, though now that I think about it, persistence of local drift, vs VM instantiation and behavior, shifts this traditional assumption I'm making, too!

@kwf Hmm, fair. Thundering herd (massive, forced synchronized restart) aside -- which should be extremely rare, and only happen if your tens of millions of clients were recovering from a massive power/comms failure that forced them all back to minpoll simultaneously ...

... after each individual peer's initial burst/minpoll flurry, settling down to maxpoll (1024 seconds, which most clients would be running at most of the time) ... I'd expect 10k qps to handle 10m peers, and 100k qps could handle 100m peers ... but would be near capacity.

But also, since local drfit offset is calculated and stored on each client, and since I would expect most clients to support that quenching / Kiss-of-Death thingie ... I'd expect near-capacity conditions to be brief, absorbable, and very low impact for actual time synchronization.

In other words: Dr. Mills thought about this pretty hard. 😁

RE: https://fosstodon.org/@ovid/116334866923361500

My earlier thread on 4,000 years of enshittification got some great responses. One question kept coming up: if the extraction pattern is deeper than capitalism, what is the root cause? I think I have the start of an answer, but it means annoying people across the political spectrum.

1/9

@kwf Always interested in a 2am thought exercise, but ... I thought NTP's client backoff strategy would make sustaining this level of qps unnecessary, by design
There is an entire industry designed to distract enterprises from deploying FIDO authentication. Why solve the problem when you can "manage" it with "risk informed decision frameworks" that require bespoke products and don't really work? πŸ’Έ πŸ”“οΈ

Just one study but we have seen clear decreases in human attention spans, esp since 2012...

"Watching fragmented short videos rather than a single continuous video leads to poorer memory recall and alters how the brain retrieves information. A recent experiment revealed that fast-paced episodic media formats disrupt the neural systems responsible for integrating details and maintaining cognitive control." via PsyPost

https://www.psypost.org/brain-scans-reveal-how-short-videos-impair-memory-and-disrupt-neural-pathways/

#Science #Psychology #SocialMedia

Brain scans shed light on how short videos impair memory and alter neural pathways

A recent brain imaging experiment reveals that watching fragmented short videos leads to measurably worse memory recall compared to viewing continuous content. The fast-paced format reduces brain activity in regions dedicated to focusing attention and processing deep meaning.

PsyPost Psychology News

@womble Fair, though I'm not clear enough on how typing always works to understand that something could be the correct type, but still unwanted data (but maybe this is too belt-and-suspenders)

(in other words, I use Perl's "detainting must work by matching a regex" to constrain input much more closely than "this must be alphanumeric")

Inside of you are two Outlooks