• 0 Posts
  • 469 Comments
Joined 1 year ago
cake
Cake day: June 16th, 2023

help-circle

  • This is my thought. I could imagine Biden announcing that Obama was coming in to play a very key role in his administration and that might give him a boost. That while technically the buck stops with Biden still, that Obama is very close to contribute.

    This would sidestep the “annointed one” problem, avoid skipping the primary, and while it’s short of a new candidate, it gets a very popular person near the presidency who couldn’t have been the candidate.

    I couldn’t imagine them starting from scratch at this point, couldn’t imagine who they would pick that people would already resonate with.




  • I was thinking the debate rules actually saved Trump from his worst impulses. Biden was allowed to speak at full length and Trump gets to appear like he can participate in a civilized conversation while Biden would sometimes go off the rails while trying to fill his time. A lot of his embarrassments started in a decent place, but pivoted badly in the middle.

    Trump confidently lied repeatedly without consequences, and so long as someone is unaware that it’s lies, I could imagine them finding Trump’s rhetoric credible that night.


  • I’ll agree, but he was at the same time more bold, like saying everyone wanted to overturn Roe v Wade. Confident and competent lying can get you far, but if you lie about how the people watching would feel, you undermine all your other lying.

    There are few things more maddening than claiming you know how someone feels more than they themselves do. A very credible liar can be undone if they lie that well on a matter the audience personally knows better. Suddenly all the benefit of the doubt purchased by the confidence is erased.








  • Basically, you have:

    • TOTP - no particular investment needed, so very popular, but a bit onerous
    • Various MFA vendors that tie into their cloud services. I hate these since it means I generally have to get additional apps, with uneven platform support
    • Webauthn/Passkey - Cool, integration with my phone, a Fido usb key, windows hello if applicable, no need for external service, uses asymmetric encryption so it’s not shared secret and it’s more convenient… Almost no one bothers to implement it for their service though, despite it being pretty damn easy.

  • Yes, shared secret based, but not a big deal because it is machine generated and unique per account. The ‘server has your credential’ is only a problem if the credential is reused across services. If you have access to read TOTP secrets from the server, you probably don’t need those TOTP secrets to further compromise the service.

    But webauthn/passkey is a better approach. Properly managed SSH keys are good too, but folks aren’t too happy about how ssh keys are commonly pretty lax. Client certificates similarly would have worked, but never took off. Similar story for smartcards.





  • Though the rooftop solar isn’t optimal from an efficacy standpoint, it has other selling points. You have residential solar and a battery? Congratulations, you don’t have to worry so much about power outages. This is particularly a selling point for rural living, where outages happen more often and last longer.

    The abstract “it’s greener” is a less potent sales pitch than “your fridge, heating, and a/c can still work even if the grid is gone”.