

And the auto-submitting TOTP entry form where you’re apparently not allowed to make a typo. And obscuring the TOTP number like it’s a password or state secret.
I’m beautiful and tough like a diamond…or beef jerky in a ball gown.


And the auto-submitting TOTP entry form where you’re apparently not allowed to make a typo. And obscuring the TOTP number like it’s a password or state secret.


Audio transcribing should be the little “waveform” icon at the right of the text input:

Image generation, I’m not sure as that’s not a use-case I have and don’t think the small-ish models I run are even capable of that.
I’m not sure how audio transcribing works in OpenWebUI (I think it has built-in models for that?) but image generation is a “capability” that needs to be both part of the model and enabled in the models settings (Admin => Settings => Models)


I feel like I’m stepping around landmines replying this, but I never liked the analogy either. It works fine at a small scale, and I’m fine with that, but everyone here wants to apply it universally at a macro scale to the point it’s just ridiculous.
e.g. If a nazi moves in down the street, and everyone else doesn’t up and move, regardless of their financial situation, you live in a nazi neighborhood. Guess you and your kids should just go live in your car because…moral purity or something.


Solutions that work for a corporate application where all the staff know each other are unlikely to be feasible for a publicly available application with thousands of users all over the world
This is something of a hybrid. There will be both general public users as well as staff. So for staff, we could just call them or walk down the hall and verify them but the public accounts are what I’m trying to cover (and, ideally, the staff would just use the same method as the public).
Figure if an attacker attempts the ‘forgot password’ method, it’s assumed they have access to the users email.
Yep, that’s part of the current posture. If MFA is enabled on the account, then a valid TOTP code is required to complete the password reset after they use the one-time email token. The only threat vector there is if the attacker has full access to the user’s phone (and thus their email and auth app) but I’m not sure if there’s a sane way to account for that. It may also be overkill to try to account for that scenario in this project. So we’re assuming the user’s device is properly secured (PIN, biometrics, password, etc).
If you are offering TOTP only,
Presently, yes, but we’re looking to eventually support WebAuthn
or otherwise an OTP sent via SMS with a short expiration time
We’re trying to avoid 3rd party services, so something like Twilio isn’t really an option (nor Duo, etc). We’re also trying to store the minimum amount of personal info, and currently there is no reason for us to require the user’s phone number (though staff can add it if they want it to show up as a method of contact). OTP via SMS is also considered insecure, so that’s another reason I’m looking at other methods.
“backup codes” of valid OTPs that the user needs to keep safe and is obtained when first enrolling in MFA
I did consider adding that to the onboarding but I have my doubts if people will actually keep them safe or even keep them at all. It’s definitely an option, though I’d prefer to not rely on it.
So for technical, human, and logistical reasons, I’m down to the following options to reset the MFA:
I’m leaning toward #3 unless there’s a compelling reason not to.


I thought about generating a list of backup codes during the onboarding process but ruled it out because I know for a fact that people will not hold on to them.
That’s why I’m leaning more toward, and soliciting feedback for, some method of automated recovery (email token + TOTP for password resets, email token + password for MFA resets, etc). I’m trying to also avoid using security questions but haven’t closed that door entirely.
Personally, I love that layout.
I’m always at a loss for what to put up as wall decorations, and I hate rats nests of cables. Win-win!


Loops finally seems usable now. I tried the beta a while back and it was kinda “Meh” but it’s improved significantly since. And you can browse on the website now, too. I’m not into short form videos, but credit where it’s due.
Well, I do like short form videos, but I hate panning for the gems and just let my friends send me the ones that rise to top.


It’s so common for “anti-censorship” to be code for “Nazi-friendly” that I’m immediately suspicious of any platform that uses that as a selling point.
I’m similarly suspicious, but it’s not just code for “nazi-friendly” but also crackpots, maladaptives, etc. Rational people who read and say “anti-censorship” in this context know it means that it’s not beholden to corporate or government interests. But everyone else seems to want to interpret that as “I can say whatever I want! How dare you mod anything I say?! Freeze-peach, y’all!”
I wish they’d pick a different term for these non-corporate alternatives, but I don’t have a better suggestion to offer right now.


Remembering your vacation to Mexico.


Speaking of noticing things:



Oh, boy, that brings back memories of being a teenager in the early 90s. Grandpa gifted me his old CB, got it setup and tuned in, and immediately turned it off.
It’s just that back then, those people weren’t glamorized with fancy titles like “podcaster” or “influencer”. They were just garden variety cranks everyone knew to just ignore.


Truth.
And given all that’s happened between the original run of KoTH and the present, I found Dale a lot less charming in the reboot.


I’m not saying the concept didn’t exist then. There was just a higher barrier to entry than buying a microphone.
Nedry was literally a computer scientist and systems designer / programmer from Cambridge. Arnold was a theme park engineer (designing rides and control systems; some programming involved but a whole different paradigm than developing large systems).
Source: Have read the novel 50+ times.
Arnold was an engineer, though. He was competent in using the system and not totally lost when poking around the code, but he’s no computer scientist. Basically, he was a power user / sysadmin rather than a developer.
Fucking with and/or interfering with someone trying to bring their lost pet home is in the top 3 dick moves you can do as a human.
Just a plain, simple tailor 😎
Literally the best thing you can do for your experience here is just start blocking any account that starts throwing out political labels at any other account. Just block and don’t look back.
The irony there is that there’s a link between microplastics and Parkinson’s.
https://www.nih.gov/news-events/nih-research-matters/nanoplastics-may-help-set-stage-parkinsons-risk