Tom Scavo

3.9K posts

Tom Scavo

Tom Scavo

@trscavo

Burlington, Vermont, USA Katılım Ekim 2009
267 Takip Edilen242 Takipçiler
Tom Scavo
Tom Scavo@trscavo·
@greenmtnclub FYI: The sign that marks the upper terminus of the Sterling Pond Trail (at the junction with the Long Trail) is missing.
English
0
0
0
0
Tom Scavo
Tom Scavo@trscavo·
@greenmtnclub On your Long Trail map (5th edition), Killington View is shown 0.5 km east of Mount Roosevelt but yesterday I took GPS coordinates at Killington View google.com/search?q=44.01… which shows the view is just 200 ft from the peak. No big deal, just FYI.
English
0
0
0
0
Tom Scavo retweetledi
Pamela Dingle
Pamela Dingle@pamelarosiedee·
Send this dose of tough love to any of your IT managers or CISOs that still cling to password complexity despite strong guidance from NIST or others to the contrary (it is so good, OMG): techcommunity.microsoft.com/t5/Azure-Activ…
English
4
41
95
0
Tom Scavo
Tom Scavo@trscavo·
Climbed Mount Abraham (4006 ft; 1221 m), one of three peaks above the tree line in Vermont, with panoramic views of the White Mountains (NH) to the east, the Adirondack Mountains (NY) to the west, and the Green Mountains (VT) to the north (below) and south. #LongTrail #HikeVT
Tom Scavo tweet media
English
1
0
1
0
Tom Scavo
Tom Scavo@trscavo·
From Burrows Trailhead, hiked the Dean Trail and the Allis Trail in Camel's Hump State Park, Vermont. #LongTrail #HikeVT #VT Here's a view of Camel's Hump (4083 ft; 1244 m) from Allis Lookout:
Tom Scavo tweet media
English
1
0
3
0
Tom Scavo
Tom Scavo@trscavo·
@LoginLlama @conorgil That's an interesting flow: username ==> #U2F ==> password. It prevents brute forcing of both the username and the password, doesn't it?
English
2
0
0
0
Login Llama
Login Llama@LoginLlama·
@conorgil @trscavo Nothing in the spec stops you from doing it, other than needing some sort of userID to look up the credentialID. One example that is close is what Dashlane is doing. They ask for user name then do U2F then ask for a password. The logic is that it stops brute forcing the password
English
1
0
2
0
Black Lives Matter
Black Lives Matter@conorgil·
I'm trying to visually represent why #2FA adoption rates are abysmally low and why it is understandable that average internet users do not enable 2FA on their accounts. Working title is "The 2FA Decision Funnel of Death". Thoughts? Feedback?
Black Lives Matter tweet media
English
20
13
58
0
Tom Scavo
Tom Scavo@trscavo·
Hiked from Skylight Pond Trailhead to Skylight Pond in the Breadloaf Wilderness in the #GreenMountains of Vermont. Here are photos of Skylight Pond, Skyline Lodge, and a view to the east from the summit of Battell Mountain (3482 ft; 1061 m) on the #LongTrail. #HikeVT #VT
Tom Scavo tweet mediaTom Scavo tweet mediaTom Scavo tweet media
English
0
0
1
0
Tom Scavo
Tom Scavo@trscavo·
From Harrington's View on the #LongTrail in Vermont, we can see Bolton Mountain (3725 feet; 1135 meters) on the edge of the Mount Mansfield State Forest #HikeVT #VT
Tom Scavo tweet media
English
1
0
1
0
Tom Scavo retweetledi
Satchin Panda
Satchin Panda@SatchinPanda·
Medical Spending in the last 12 months of life US = ~$80K Germany = ~$52K Taiwan = ~$22K Life expectancy ~80y in all three countries. healthaffairs.org/doi/pdf/10.137…
Satchin Panda tweet media
English
1
24
70
0
Tom Scavo
Tom Scavo@trscavo·
@TokenTwo @conorgil A roaming #FIDO2-certified authenticator (something you have) that supports #CTAP2 necessarily has a pin (something you know). In other words, the authenticator is a multi-factor authenticator. If the pin is disabled, the authenticator can't be used in multi-factor mode.
English
1
0
1
0
Token2
Token2@TokenTwo·
@trscavo @conorgil Webauthn-only is also a broken one - if the key is lost or stolen - the account is compromised (there are fido2 keys without biometric and pin can be disabled)
English
1
0
0
0