• 0 Posts
  • 16 Comments
Joined 2 years ago
cake
Cake day: July 2nd, 2023

help-circle






  • Cloony The Clown by Shel Silverstein

    I’ll tell you the story of Cloony the Clown Who worked in a circus that came through town. His shoes were too big and his hat was too small, But he just wasn’t, just wasn’t funny at all. He had a trombone to play loud silly tunes, He had a green dog and a thousand balloons. He was floppy and sloppy and skinny and tall, But he just wasn’t, just wasn’t funny at all. And every time he did a trick, Everyone felt a little sick. And every time he told a joke, Folks sighed as if their hearts were broke. And every time he lost a shoe, Everyone looked awfully blue. And every time he stood on his head, Everyone screamed, “Go back to bed!” And every time he made a leap, Everybody fell asleep. And every time he ate his tie, Everyone began to cry. And Cloony could not make any money Simply because he was not funny. One day he said, “I’ll tell this town How it feels to be an unfunny clown.” And he told them all why he looked so sad, And he told them all why he felt so bad. He told of Pain and Rain and Cold, He told of Darkness in his soul, And after he finished his tale of woe, Did everyone cry? Oh no, no, no, They laughed until they shook the trees With “Hah-Hah-Hahs” and “Hee-Hee-Hees.” They laughed with howls and yowls and shrieks, They laughed all day, they laughed all week, They laughed until they had a fit, They laughed until their jackets split. The laughter spread for miles around To every city, every town, Over mountains, 'cross the sea, From Saint Tropez to Mun San Nee. And soon the whole world rang with laughter, Lasting till forever after, While Cloony stood in the circus tent, With his head drooped low and his shoulders bent. And he said,“THAT IS NOT WHAT I MEANT - I’M FUNNY JUST BY ACCIDENT.” And while the world laughed outside. Cloony the Clown sat down and cried.




  • That was the beginning of the end for me. I think by the time I got to that part the series had already been going downhill but I remember that being a really sharp turning point.

    I tried to press on a little further. The introduction of the straw man nation with the innocent child king who’s only existence was to be blown the fuck out by the brilliance of objectivism is when I finally decided I just couldn’t go on.


  • Ooo, I was trying to think of what to answer in this thread and you just reminded me of another Orson Scott Card book, Empire.

    Absolute trash. Prior to that I had read all of the Ender and Bean series and loved them. Didn’t know much about Card personally, but picked up this book because it was supposed to be tied in with a video game I was looking forward too.

    Reading this book is how I found out what a shitty person he really is. It was basically all him hitting you over the head with his shitty fascist ideology while jerking off to a bunch of military porn like a dollar store version of Tom Clancy. I never did play the game.




  • What you want is NIST 800-63b https://pages.nist.gov/800-63-3/sp800-63b.html#memsecret

    Specifically sections 5.1.1.1 and 5.1.1.2.

    Excerpt from 5.1.1.2 pertaining to complexity and rotation requirements:

    Verifiers SHOULD NOT impose other composition rules (e.g., requiring mixtures of different character types or prohibiting consecutively repeated characters) for memorized secrets. Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.

    Appendix A of the document contains their reasoning for changing from the previous common wisdom.

    The tl;dr of their changes boil down to length is more important than any other factor when it comes to password security.

    Edit to add:

    In my personal opinion, organizations should be trying to move away from passwords as much as possible. If your IT team seems to think this system is so important that they need to rotate passwords every month, they should probably be transitioning to hardware security tokens, passkeys, or worst case, password with non-sms MFA.

    Now I know nothing about the actual circumstances and I know there are plenty of reasons why that may not be possible in this specific case, but I’d feel remiss if I didn’t mention it.


  • Any organization still doing this is a decade behind best practices. NIST published new recommendations years ago that specified getting rid of the practice of regular forced password resets specifically because they encourage bad practices that make passwords weaker.

    Of course it doesn’t help that there are some industry compliance standards that have refused to update their requirements, but I don’t know of any that would require monthly password changes.