Some interesting developments seem to be going on with the Calyx project, first with the founder/CEO stepping down and then with this interesting message around rotation of signing keys.
https://calyxos.org/news/2025/08/01/a-letter-to-our-community/
Any #infosec folks wanna help me with some decent data to backup the following point? I am trying to make the point to some executives that a #password policy requiring minimum 8 characters with 1 symbol, mixed case, and 1 number is just not reasonable in 2025. (I'm commenting on another company's policy, not my own!)
What is a good example of a policy (e.g., NIST 800-63 or whatever) that said 49 bits was no good?
I currently say: 49 bits of entropy was unacceptably low in 2005. It is unthinkably low in 2025. What can I point to that might resonate better than "bits of entropy?"
Using the classic method with Shannon's estimate, I figure it's on the order of 49 bits of entropy but that's only if it's purely random from the full character set, and we konw that's not true.
I'm not looking for rhetorical suggestions. I'm good at rhetoric. I'm looking for references I can point to (like "XYZ published in 2011 that the minimum acceptable password was 56 bits of entropy")
feel free to boost for fun
#security #cybersecurity
The Case for Political Performance Ratings
https://rall.com/2025/08/07/the-case-for-political-performance-ratings
#TedRall
Mexit, not Brexit, is the new priority for the UK - https://www.theregister.com/2025/08/08/opinion_column_mexit_not_brexit/ "A #Microsoft Exit strategy isn’t just a good idea, it’s vital. It must go a long way beyond a farewell to Redmond"
I keep hearing AI proponents say that it's critical to develop these AI-using skills *now*, because otherwise you'll be left behind.
But isn't the whole point that AI means you can just let all your skills atrophy and let the magic box do things for you?
Any AI system that you can't just sit down and use is *surely* not the True AI. ;-)
“I’m a guy who has been running independent websites and dealing with ad networks for more than 15 years and this book demystified a lot for me.”
https://tedium.co/2025/08/07/ari-paparo-yield-google-antitrust-review/
Elite universities are caving to Trump’s authoritarian demands. Here’s what you can do to fight back: https://indivisible.org/resource/elite-universities-are-caving-trumps-authoritarian-demands-what-you-can-do-next?source=mastodon
Two years ago when researchers found and publicly exposed an intentional backdoor in a TETRA encryption algorithm used to secure radio communications for police/military/intel agencies around the world -- the algorithm involved a key advertised as one strength but secretly reduced to 32 bits -- the European organization that produced the algorithm told users that to secure their communications they could deploy an end-to-end encryption solution on top of the backdoor'd algorithm. Now the same researchers say they found a security problem with the end-to-end solution as well -- another reduced key. Here's my story for Wired:
Google calendar can be poisoned with invisible, malicious Gemini prompts:
https://www.darkreading.com/cyberattacks-data-breaches/google-gemini-ai-bot-hijacks-smart-homes
Do I have to stop clicking on calendar invitations? What are the alternatives?
If Google can't get security or "AI" right, what hope is there that anyone will?
We're going to need journalists to stop talking about synthetic text extruding machines as if they have *thoughts* or *stances* that they are *trying* to *communicate*. ChatGPT can't *admit* anything, nor *self-report*. Gah.
https://www.wsj.com/tech/ai/chatgpt-chatbot-psychology-manic-episodes-57452d14
Psst... looking for a new club to join? 👀
Great news, ours is looking for new members: https://codeberg.org
#Australia Completely Loses The Plot, Plans To Ban Kids From Watching #YouTube - https://www.techdirt.com/2025/08/06/australia-completely-loses-the-plot-plans-to-ban-kids-from-watching-youtube/ "The end result will be that Australia has basically taught a generation of teenagers not to trust the government, that their internet regulators are completely out of touch, and that laws are stupid."
I have just been introduced to Sharon Goldman's AI journalism and it's some of the funniest shit I've seen in my life.
She's really out there prompting ChatGPT to write what reads like Kindle Unlimited-tier softcore erotica and getting paid.
Even her "About" page on LinkedIn has two em-dashes and one --, so like, what's going on here? Local journalist can't write five sentences without an LLM? What are DOING out here?
This just in: my friends chucked out a shitty "CO2" #sensor.
Actually a breathalyzer:
https://hackaday.com/2023/02/18/anatomy-of-a-fake-co2-sensor/
It's a really pretty design! And while the man in the video says it's useless, I actually started a CO2 sensor project this winter, but I didn't have a display or case.
Now I guess I do!
But it turns out driving a matrix of #LCD segments is surprisingly difficult.
Here's a picture of connections. Wish me luck figuring out.
#ShlaerMellor, #FunctionPointAnalysis, #punk, #environmentalist, #unionAdvocate, #anarchosocialist
"with a big old lie and a flag and a pie and a mom and a bible most folks are just liable to buy any line, any place, any time" - Frank Zappa