Just a Southern Saskatchewan retiree looking for a place to keep up with stuff.

  • 1 Post
  • 260 Comments
Joined 1 year ago
cake
Cake day: June 12th, 2023

help-circle



  • Also, for what it’s worth, TD is not just the only bank I know of, but the only website I know of that allows for a user-generated username to be used for login. My TD username was generated by the password generator of my password manager :)

    So they don’t get it all wrong.



  • Over the years, I’ve been with all the big Canadian banks and a couple of different credit union networks. They’re all trash, in my opinion. I’ve sent security notices to all of them and never had a response, nor any evidence that they addressed the problems. TD just happens to be the place we landed after giving up on everyone else.

    As for transaction downloads, I couldn’t tell you. I gave up on ever having access to my data, so I just record it manually.


    Security notice examples:

    TD was running their SSL/TLS in a way that made them vulnerable to downgrade attacks.

    A credit union finally upgraded their login page to allow a real password instead of just a 6-digit PIN. It took repeated complaints and some customer lobbying to get that, but the new page also blocked access to pasting and autofill, negating the utility of a password manager.



  • jadero@lemmy.catoCanada@lemmy.caCRA now allows 2FA apps
    link
    fedilink
    arrow-up
    1
    ·
    edit-2
    9 months ago

    Authentication is only ever as strong as it’s weakest link. All the fancy passwords, MFA, passkeys or whatever mean nothing in the face of “I forgot my password” email resets and the like.

    I know people who just hammer randomly on the keyboard whenever they get asked for a password, then use the “I forgot my password” system to get “authenticated,” providing yet another set of random keystrokes as the new password.

    And it’s not horrible, I guess. They’re using strong passwords. They’re never reusing passwords anywhere, not even for successive logins at the same site. They have to be explicitly targeted by someone who is willing to target their email system.

    This does nothing to secure against mass breaches, but neither does the strongest authentication system. But, like any of the strongest authentication systems, account takeover requires deliberate targetting.






  • So far we’re kind of getting by.

    I don’t hold out much hope, though, because the rich, the powerful, and the politicians all seem to want strictly private healthcare while the vast majority of the population wants not just effective and accessible public healthcare, but to expand coverage to dental, vision, hearing, and pharmaceuticals.

    Never mind the hardships that come from transitioning to a different system, the usual result of this kind of disconnect is violent revolution.



  • Oh yes, the term limits should be reduced. But one thing I like about the appointment system (also easily managed under sortition) is that individual terms are just that, individual. That is, there isn’t a wholesale sweep of all sitting members at once, the way there is with Parliament.

    I don’t know how something like that could be managed in a purely elected body and think it’s worth keeping. I suppose there wouldn’t really be a problem with having everyone elected via what we now call byelection.

    That makes me wonder if party politics, campaigning, and electioneering would change if Parliamentary terms were individualized instead of globalized to the Parliament as a whole.


  • In principle, I like the idea of having a check on Parliament. Not a block that can prevent things from happening, but something that can slow things down a bit when necessary and maybe cause Parliament to rethink what they’re up to or moderate their actions. In general, I think the Senate is reasonably effective at that.

    In principle, I like the idea of some kind of regional representation. Not so much that the province with small populations can stand in the way of sound national policy, but enough to limit the exploitation of those provinces in favour of the ones with larger populations. I’m not sure that the Senate has been as effective in that regard as it could have been.

    I really like the idea that no Senator can be an active member of any political party. They should all sit as independents. In fact, I would argue that no Senator should ever have been sitting member of Parliament, and maybe not even held party membership for at least a decade.

    Finally, I would like to experiment with sortition (random selection instead of political appointments or elections) and a properly constrained, yet not powerless Senate seems like the perfect place to try it out.





  • Point taken, but I didn’t forget about it. I go hiking and tenting on the ice on Lake Diefenbaker, so I know all about it. I just didn’t know how to bring it in without lending yet more credence to all the myths and misconceptions.

    There are a lot of differences between actual -25C with no wind and windchill of -25C. For example at -25 with no wind, my wool parka with a fairly open knit is perfect on its own for a wide range of activities. But with a windchill of -25, I’m better off with my fleece bunny hug under a windbreaker, then layering up with a tightly knit wool sweater when I’m inactive.

    When I still biked, -15 with no wind quickly turned into -25 windchill, but if the windchill was already -25, hopping on the bike didn’t make a huge difference, so I dressed about the same in both cases.