shelbyfinally's comments

shelbyfinally | 8 years ago | on: Mass Psychology Supports the Pricey Stock Market

> We'll see how strong the passive buy-&-hold ideology really is when the tide goes out.

You already know the answer to that. Passive index investors will pull out in record numbers.

I can't believe how many people I know who think "just put all your money in index funds and you'll be a millionaire when you retire." Now I don't have any better advice, but they only say this because of the gains they've seen in the last 7 years, like it's invulnerable. Even when I use my investing website's retirement calculator, it defaults to a 9% gain each year for the rest of my life.

We're in uncharted territory. We could enter a 25-year stagnation. We could be at the beginning of the most prosperous time in history. Nobody knows. And nobody can predict it.

shelbyfinally | 8 years ago | on: Three Equifax Managers Sold Stock Before Cyber Hack Was Revealed

I'll give another example. My medical practice tried to do GPG encryption in a shared DropBox folder. Within the first week, someone decrypted half the files into the same shared folder...

It was all just a test with non-critical data, but the test was a total failure. And that didn't even get into key-related issues.

shelbyfinally | 9 years ago | on: We Got Phished

It's Yubikey.

Google Authenticator doesn't do any kind of push notification when you log in. Each endpoint uses a shared secret (the server and the mobile app share that secret beforehand) to generate a time-limited code.

shelbyfinally | 9 years ago | on: Webcams used to attack Reddit and Twitter recalled

We have IP cameras (Axis) on a dedicated VLAN that doesn't have access to/from the WLAN, and things work pretty well. I don't trust VPN's (NSA clearly watered down the IPSEC standard and can definitely compromise most IPSEC connections [not sure about IKEv2]; OpenVPN is a messy pile of shit that is undoubtedly swamped with vulnerabilities), but do allow a VPN into my camera network. The compromise I made is to send a notification email for each established VPN connection, regardless of how it was established, so at least I'll probably know if someone else connects.

With Nest, you have to use their "cloud" for it to be fully functional, which to me makes it a no-go for anybody like you who is actually concerned with his/her security/privacy.

The most popular IP camera on Amazon is a Chinese camera gets your Wifi password through their app via the "cloud". Fuck that.

page 1