Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Devian666
Aug 20, 2008

Take some advice Chris.

Fun Shoe

22 Eargesplitten posted:

:spergin: but there are 208.8 billion permutations for 8 letter long strings, not including upper case, not allowing numbers, or symbols. The odds of any given one having been harvested, especially when you end up with upper case, numbers, and allowed symbols, is fairly low.

Small enough for a rainbow table to be useful.

Adbot
ADBOT LOVES YOU

Moneyball
Jul 11, 2005

It's a problem you think we need to explain ourselves.

hailthefish posted:

:spergin: If you had a Yahoo account in 2013, the chance of that account's password being compromised is literally 100%

https://www.nytimes.com/2017/10/03/technology/yahoo-hack-3-billion-users.html

So that's who dropped Jamaal Charles

22 Eargesplitten
Oct 10, 2010



hailthefish posted:

:spergin: If you had a Yahoo account in 2013, the chance of that account's password being compromised is literally 100%

https://www.nytimes.com/2017/10/03/technology/yahoo-hack-3-billion-users.html

The point is that you don’t use the same password for everything, you randomly generate a new one every time you register for a site. 1 million doesn’t even register in terms of possibilities for one specific short length of string using not even close to half of the available characters.

What are the limitations of a rainbow table? 32 character alphanumeric case sensitive is 2.27^57.

Basically I learned about password hashing 8 years ago in college, and that was just how to make a hash table. None of the security stuff involved in attempts to get the data out.

EugeneJ
Feb 5, 2012

by FactsAreUseless
https://www.fastcompany.com/40549479/students-are-using-their-loan-money-to-buy-cryptocurrency-study

quote:

The Student Loan Report surveyed 1,000 current college students with student loan debt about whether they were asked whether they used their student loan money to invest in cryptocurrencies like Bitcoin and found that 21.2% of them have Sallie Mae to thank for their cryptocurrency investment. Many students borrow a little more money than is necessary to pay for tuition and books, according to Student Loan Report. The leftover cash is typically used for college living expenses, but some wily students think that investing in Ethereum or Ripple may be a better investment than a bachelor's degree in comparative English literature.

:suicide:

Higgy
Jul 6, 2005



Grimey Drawer

At least a comparative lit degree has intrinsic value since its printed on paper

Spokes
Jan 9, 2010

Thanks for a MONSTER of an avatar, Awful Survivor Mods!

Higgy posted:

At least a comparative lit degree has intrinsic value since its printed on paper

left, lit degree. right, altcoins

:zaurg:

Panfilo
Aug 27, 2011

EXISTENCE IS PAIN😬
I assume futuristic debtors prisons will have debtors running on hamster wheels to power the same bitcoin mining operations that led them to folly.

bob dobbs is dead
Oct 8, 2017

I love peeps
Nap Ghost
bwm: owing 107k to the state revenue and 7k on copay for your neck surgery, making it so you have to fundraise for your dead gay comedy forum

the next named thread should be lowtax

Weatherman
Jul 30, 2003

WARBLEKLONK

Panfilo posted:

I assume futuristic debtors prisons will have debtors running on hamster wheels to power the same bitcoin mining operations that led them to folly.

Yeah I think I saw that episode of Black Mirror.

Elephanthead
Sep 11, 2008


Toilet Rascal

bob dobbs is dead posted:

bwm: owing 107k to the state revenue and 7k on copay for your neck surgery, making it so you have to fundraise for your dead gay comedy forum

the next named thread should be lowtax

Providing this forum and getting your back fixed is not bad with money. The bad with money part is providing a service for a one time fee and promising the service forever. This forum is like a pretty horse, but the horse is not pretty and it smells bad and you can't ride it and it requires a full-time chef, chauffeur, and horse yacht captain.

Tamba
Apr 5, 2010

22 Eargesplitten posted:

:spergin: but there are 208.8 billion permutations for 8 letter long strings, not including upper case, not allowing numbers, or symbols. The odds of any given one having been harvested, especially when you end up with upper case, numbers, and allowed symbols, is fairly low.

Watch this
https://www.youtube.com/watch?v=7U-RbOKanYs

Especially the part where he says that a single high end GPU can try 10 billion hashes per second if its using a weak algorithm.

Krispy Wafer
Jul 26, 2002

I shouted out "Free the exposed 67"
But they stood on my hair and told me I was fat

Grimey Drawer

hailthefish posted:

:spergin: If you had a Yahoo account in 2013, the chance of that account's password being compromised is literally 100%

https://www.nytimes.com/2017/10/03/technology/yahoo-hack-3-billion-users.html

Even worse, Yahoo does the email infrastructure for ISP's. So accounts without @yahoo in the name whose users have never even been to yahoo.com are impacted by the hack. Back when I worked at AT&T, a friend who used to work in the email side claimed that since all the authentication was done on the AT&T side, our ISP accounts were not impacted. But then we got letters saying, "whoops, guess what".

gently caress Yahoo.

22 Eargesplitten
Oct 10, 2010



Tamba posted:

Watch this
https://www.youtube.com/watch?v=7U-RbOKanYs

Especially the part where he says that a single high end GPU can try 10 billion hashes per second if its using a weak algorithm.

Oh look, he says that short passwords with just lower case letters can be brute forced very quickly. Just like the example I gave, because I didn't want to deal with exponential notation when typing on my phone. And for explaining the number of possibilities for a brute force he used the same calculation that I did. He even said that once you get to 9+ characters (using all possible characters) it's going to be difficult to brute force even with MD5. And the entire point of a randomly generated password is that it's not very unlikely to be in a dictionary.

The whole thing I was trying to say, which has apparently been misunderstood repeatedly, was that any randomly generated password is extremely unlikely to be in the 1 million Yahoo passwords BarbarianElephant mentioned, or even in the 14 Million RockYou password list mentioned in the Computerphile video. Sure, it's got to deal with all of the other security issues passwords have, but 1 million passwords is barely a drop in the bucket of possible strings, so "$@^$^U@$(^999uu935nlknglke11horse" is a lot more secure than Grandma's "Harold1923", even with BFC's spirit animal in it.

All this aside, it needs to be pointed out that one of the passwords in the example password list was ganjagoblin. And I need to figure out how to make Computerphile videos appear obviously work relevant because that was a really cool video.

Or maybe I'm missing something, I'm rarely up this early.

Cacafuego
Jul 22, 2007

Relevant crosspost:

silvergoose
Mar 18, 2006

IT IS SAID THE TEARS OF THE BWEENIX CAN HEAL ALL WOUNDS




A good robot household imo.

The Slack Lagoon
Jun 17, 2008



I lived in an old apartment and previous tenants had put up.wall decals that said. Life's too short to drink cheap wine. We tried to take them down but it pulled the horse hair plaster off the wall when we tried so we adopted it as our own motto

Duckman2008
Jan 6, 2010

TFW you see Flyers goaltending.
Grimey Drawer

Elephanthead posted:

Providing this forum and getting your back fixed is not bad with money. The bad with money part is providing a service for a one time fee and promising the service forever. This forum is like a pretty horse, but the horse is not pretty and it smells bad and you can't ride it and it requires a full-time chef, chauffeur, and horse yacht captain.

I’m still shocked he hasn’t tried to move to something simple like $10 a year.


I’m nervous on where I will get my bad with money stories if Something Awful itself goes down the bad with money drain and the forums disappear. I tried reddit once and just not a fan.

Betazoid
Aug 3, 2010

Hallo. Ik ben een leeuw.
The New Yorker has taken a look at everyone's favorite magazine, Teen Bo$$.

https://www.newyorker.com/books/page-turner/the-very-unnerving-existence-of-teen-boss-a-magazine-for-girls

CellBlock
Oct 6, 2005

It just don't stop.



Duckman2008 posted:

I’m still shocked he hasn’t tried to move to something simple like $10 a year.


I’m nervous on where I will get my bad with money stories if Something Awful itself goes down the bad with money drain and the forums disappear. I tried reddit once and just not a fan.

Yeah, at least Something Awful makes a good-faith effort to remove the pedos and racists. Reddit basically caters directly to them.

Krispy Wafer
Jul 26, 2002

I shouted out "Free the exposed 67"
But they stood on my hair and told me I was fat

Grimey Drawer

CellBlock posted:

Yeah, at least Something Awful makes a good-faith effort to remove the pedos and racists. Reddit basically caters directly to them.

The solution is to plan on $5 a year but charge $10 so people who can't afford it can petition for scholarships. Like a talent show. Dance goon dance!

Hoodwinker
Nov 7, 2005

CellBlock posted:

Yeah, at least Something Awful makes a good-faith effort to remove the pedos and racists. Reddit basically caters directly to them.
Linear forums discussion is a superior format too to prevent any one post from becoming too heavily weighted by a vote-based system. It encourages every user to try to read every post in order. You know, like how an actual discussion would work. Reddit is great for maximizing the most popular posts and minimizing the least popular ones, for whatever metrics encourage popularity.
This article is good. Its topic is horrifying.

Hoodwinker fucked around with this message at 15:53 on Mar 27, 2018

22 Eargesplitten
Oct 10, 2010



I would 100% seriously pay $5/mo for SA, $10 if it came with stuff like plat, archives, free av change for yourself every x months. I get more use by far out of this forum than I do Netflix.

Just leave the one time $19 as an option too.

Moneyball
Jul 11, 2005

It's a problem you think we need to explain ourselves.
Reddit is terrible, but occasionally you run across some great thread titles

quote:

Men who know how to install Linux, how much pussy do you get?

Bhodi
Dec 9, 2007

Oh, it's just a cat.
Pillbug

CellBlock posted:

Yeah, at least Something Awful makes a good-faith effort to remove the pedos and racists. Reddit basically caters directly to them.
not anymore now that they are a real company they are tragically banning hundreds of subreddits like r/FatPeopleHate r/Coontown r/KillAllJews and r/DogSex

you can see people whine about it here TW:reddit link

Krispy Wafer
Jul 26, 2002

I shouted out "Free the exposed 67"
But they stood on my hair and told me I was fat

Grimey Drawer

Moneyball posted:

Reddit is terrible, but occasionally you run across some great thread titles

Not much considering how often they compile their own kernels.

ego symphonic
Feb 23, 2010

Hoodwinker posted:

Linear forums discussion is a superior format too to prevent any one post from becoming too heavily weighted by a vote-based system. It encourages every user to try to read every post in order. You know, like how an actual discussion would work. Reddit is great for maximizing the most popular posts and minimizing the least popular ones, for whatever metrics encourage popularity.

This article is good. Its topic is horrifying.

Jia is great. For a UVA alum anyways.

Switchback
Jul 23, 2001

AreWeDrunkYet posted:

Definitely use two factor auth on any platform you remotely care about protecting your identity on. The password just needs to be good enough, but don't use 123456 or some nonsense.

As long as you never go places without cell service or travel or work offshore, cause then you’re hosed!


Reddit is awful. It’s all so manipulated and propagandized, you never know if someone is real or a shill for some agenda. I feel like most of us joined SA back when we were teenagers, so while we have our share of weirdo maladjusted neckbeards at least they are real people.

Do new people join SA? How many of us are there left? Oh man hosting these forums for one time tenbux is some BWM. Pretty cheap for like 16+ years of entertainment.

Not a Children
Oct 9, 2012

Don't need a holster if you never stop shooting.

Switchback posted:

Do new people join SA? How many of us are there left? Oh man hosting these forums for one time tenbux is some BWM. Pretty cheap for like 16+ years of entertainment.

New people join but not at nearly the rate they did ~10 years ago. It still has a pull as a well-moderated site with interesting people who put actual effort into posting, but it doesn't have the ego appeal of reddit's karma system. It's also gained a reputation as a leftist forum in general, I think, so that has colored its curb appeal a bit. That, and I think people simply don't have the patience to wade through nearly uncurated posts anymore.

Moneyball
Jul 11, 2005

It's a problem you think we need to explain ourselves.
:chloe:

Motronic
Nov 6, 2009

Switchback posted:

As long as you never go places without cell service or travel or work offshore, cause then you’re hosed!

You don't need cell service for 2FA auth apps to work on your phone. And if you don't have cell service isn't not likely you have internet service so what the hell would you be logging into anyway?

Hoodwinker
Nov 7, 2005

You don't want to use SMS-based 2FA anyways because then you're vulnerable to a SIM swap. Device-based authenticators are a better option.

Switchback
Jul 23, 2001

Motronic posted:

You don't need cell service for 2FA auth apps to work on your phone. And if you don't have cell service isn't not likely you have internet service so what the hell would you be logging into anyway?

Offshore. We get internet in the middle of the ocean, it’s poo poo but it works. Then projects get delayed and you’re out for way longer than anticipated and you can’t login to your banking website to pay your bills because it’s texting you a code to enter into your dongle to get the other code that lets you log in.

Also travelling? All the time I’m on wifi with no cell service, or on a tourist SIM so I wouldn’t get the SMS.

I have been locked out of accounts so many times that I’d rather risk the identity theft.

Switchback fucked around with this message at 17:35 on Mar 27, 2018

Switchback
Jul 23, 2001

Hoodwinker posted:

You don't want to use SMS-based 2FA anyways because then you're vulnerable to a SIM swap. Device-based authenticators are a better option.

What if you lose your phone?

Hoodwinker
Nov 7, 2005

Switchback posted:

What if you lose your phone?
This is still a problem if you use SMS-based 2FA though??? There are ways to recover your authenticator if you lose your device.

Sirotan
Oct 17, 2006

Sirotan is a seal.


Switchback posted:

What if you lose your phone?

Install the app on another device? Google Authenticator can be run as a Chrome app, for example.

Haifisch
Nov 13, 2010

Objection! I object! That was... objectionable!



Taco Defender

Switchback posted:

Reddit is awful. It’s all so manipulated and propagandized, you never know if someone is real or a shill for some agenda. I feel like most of us joined SA back when we were teenagers, so while we have our share of weirdo maladjusted neckbeards at least they are real people.
IMO one of the things keeping most parts of reddit awful is that it's a lot of people's first(and possibly only) exposure to moderated forums, resulting in huge temper tantrums and cries of "free speech!" whenever the admins do stuff or whenever the mods of a popular subreddit do stuff. There's also a surprising number of people who think it's practical for communities to self-moderate with downvotes.

Of course that's made it easier for pedos/racists/nazis to gain traction there, since they can hide behind that logic when the banhammer comes their way.


Duckman2008 posted:

I’m still shocked he hasn’t tried to move to something simple like $10 a year.
:same: The "pay once to post and never again(except for cosmetic stuff like avatars)" model doesn't really work when you don't have a constantly growing stream of new registrations. Hell, even just making people pay $5-10/mo to maintain Plat/archives status would help.

I know the donate button is always there and there's nothing stopping people from deciding to regularly donate :10bux:, but realistically speaking not many people are going to go out of their way to do that even if they would go along with paying the same amount if it was the only way to keep posting.

Motronic
Nov 6, 2009

Switchback posted:

Offshore. We get internet in the middle of the ocean, it’s poo poo but it works. Then projects get delayed and you’re out for way longer than anticipated and you can’t login to your banking website to pay your bills because it’s texting you a code to enter into your dongle to get the other code that lets you log in.

Also travelling? All the time I’m on wifi with no cell service, or on a tourist SIM so I wouldn’t get the SMS.

I have been locked out of accounts so many times that I’d rather risk the identity theft.

If these are typical travel patterns for you how is it that you don't have a phone what works over wifi if there are no towers available?

Switchback posted:

What if you lose your phone?

Back up your 2FA poo poo. Use the Authy app.....I mean, there are plenty of choices here.

sleepy gary
Jan 11, 2006

Switchback posted:

Offshore. We get internet in the middle of the ocean, it’s poo poo but it works. Then projects get delayed and you’re out for way longer than anticipated and you can’t login to your banking website to pay your bills because it’s texting you a code to enter into your dongle to get the other code that lets you log in.

Also travelling? All the time I’m on wifi with no cell service, or on a tourist SIM so I wouldn’t get the SMS.

I have been locked out of accounts so many times that I’d rather risk the identity theft.

In addition to what others have said: you can get a US-based google voice number (for free) to send and receive SMS and phone calls while on wifi or local cell service anywhere in the world.

OctaviusBeaver
Apr 30, 2009

Say what now?
Reddit is great because you can search for "truck" in /r/personalfinance and be entertained for hours

https://www.reddit.com/r/personalfinance/comments/86jbpg/owe_16k_on_truck_worth_5k_and_only_gross_20k_a/

Owe 16k on truck worth 5k and only gross 20k a year with 2 kids. Need major advice on now broken truck. posted:

This post is for a coworker who owes a 16k (400 a month) on a truck that has recently broken down.

It’s a (2005?) Ford F-150 and she purchased it a couple years ago. When it’s all said and done she will have paid a bees dick under 24k.

She also has 2 kids she supports with a small child support check that’s not always guaranteed. So she can’t really work more than the 40 hours she does now. The only other major bill is 1.5k to the hospital.

What do you think she should do?

https://www.reddit.com/r/personalfinance/comments/85ci7i/cant_afford_my_truck_anymore/#bottom-comments

https://www.reddit.com/r/personalfinance/comments/85ci7i/cant_afford_my_truck_anymore/#bottom-comments posted:

I know im terrible with my money trying to finally face this instead of ignoring it so save the judgements please...i bought a truck last october for 38,400. My payments are 800/monthly for 48 months and im currently finishing my 13th month so ive paid 10,400. A quick black book search valued my trade in from 13-15000 so i would still owe over 10grand if i traded it in right now. Me and my wife both work full time and we definitely need 2 vehicles. I owe canada revenue close to 40gs and got another 20grand-ish bill coming at tax season. Credit card are maxed at a value 14,300. I rent. I have 3 kids. I make roughly just over 8grand a month as a personal contractor and dont even know where to start.

How can you make that much and be that poor?!

Younger brother is set on buying $35K truck. Help me convince him otherwise posted:

He just got a good job with a construction company a few weeks ago. Its his first REAL job and he brings home $500 a week after taxes and he works on the weekends on the side sometimes pulling in an extra $200. He's in Denver so he should have something with 4 wheel drive. He currently drives an old volvo station wagon which I admit he should replace.

I mean why not buy a car worth 150% of you annual income?

https://www.reddit.com/r/personalfinance/comments/80mxpq/an_interesting_way_to_finance_a_new_truck_purchase/

An interesting way to finance a new truck purchase? posted:

I owe 49k on my mortgage pay off in 4 years, it is worth 400k. My banker suggested paying for a new truck by putting the purchase on my house payment and set payments for 10 years or 15 years. Said that this beats any other financing deal in interest and payments. I get the truck and lower my mortgage payments considerably. I can always pay off all in the future with the sale of my condo in 3-4 years.

Is this a good idea??????

of course she did

Adbot
ADBOT LOVES YOU

DariusLikewise
Oct 4, 2008

You wore that on Halloween?
Trucks are BWM unless you own them as part of a corporation and write down the value every year

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply