<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-03-25T01:54:52Z</updated>
  <generator>https://yabu.me</generator>

  <title>Nostr notes by Daniel J. Summers ~ East TN, USA</title>
  <author>
    <name>Daniel J. Summers ~ East TN, USA</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://yabu.me/npub1za0u4ztucv9zdnvt2p2jujjtgtjvc3hktq23ptld957fq25kslmssg6q06.rss" />
  <link href="https://yabu.me/npub1za0u4ztucv9zdnvt2p2jujjtgtjvc3hktq23ptld957fq25kslmssg6q06" />
  <id>https://yabu.me/npub1za0u4ztucv9zdnvt2p2jujjtgtjvc3hktq23ptld957fq25kslmssg6q06</id>
  <icon>https://fedi.summershome.org/media/fa357e69-6643-45df-b03e-48840fc738ee/xbox-avatar-gray.png</icon>
  <logo>https://fedi.summershome.org/media/fa357e69-6643-45df-b03e-48840fc738ee/xbox-avatar-gray.png</logo>




  <entry>
    <id>https://yabu.me/nevent1qqsgyu3xf6qfqgxa7k6hl5drf4umuth2ycjmj05p5yqu3n86vxarn2gzyqt4lj5f0nps5fkd3dg92tj2fdpwfnzx7evp2y90a5kneyp2j6rlwle7yag</id>
    
      <title type="html">anymore, it seems. It used to be about freeing up time used by ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsgyu3xf6qfqgxa7k6hl5drf4umuth2ycjmj05p5yqu3n86vxarn2gzyqt4lj5f0nps5fkd3dg92tj2fdpwfnzx7evp2y90a5kneyp2j6rlwle7yag" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqstr84x6ph0nsmhkrt97ajdffm2s23qaaj5cpmqd4rmd4ul2jcn5vssuh5up&#39;&gt;nevent1q…h5up&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;anymore, it seems. It used to be about freeing up time used by busywork, or providing a wider view of things. The computer works for you; now, we work for the computer.
    </content>
    <updated>2025-10-30T20:21:15Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8hume0t22y03ufqdd2uyntfm78wqu2cdqkerckjc7j6rwm6v85sgzyqt4lj5f0nps5fkd3dg92tj2fdpwfnzx7evp2y90a5kneyp2j6rlwmvctgx</id>
    
      <title type="html">Yeah - that&amp;#39;s the rub. One of the things that I&amp;#39;ve done ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8hume0t22y03ufqdd2uyntfm78wqu2cdqkerckjc7j6rwm6v85sgzyqt4lj5f0nps5fkd3dg92tj2fdpwfnzx7evp2y90a5kneyp2j6rlwmvctgx" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsqlcjm9zhtuzxsshv4jdk89nesfult2k5u0mx9xdun2v7jrccs4ug4jkrw2&#39;&gt;nevent1q…krw2&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Yeah - that&amp;#39;s the rub. One of the things that I&amp;#39;ve done throughout my time in tech is adjust details up and down (in a 100-foot view vs. 50,000-foot view) to help folks understand things at their level. The risk of SMS second factors - i.e., the entire process is only as strong as its weakest factor - is something for which I currently don&amp;#39;t have a good answer. I feel like one has to be out there - I just haven&amp;#39;t found it yet.
    </content>
    <updated>2025-07-06T00:50:50Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsr2palznqag7kmk45d8d3lk8av45vy7cd08fs8r90tpxkv39s0x7qzyqt4lj5f0nps5fkd3dg92tj2fdpwfnzx7evp2y90a5kneyp2j6rlwkf9h0p</id>
    
      <title type="html">I guess this is the distinction. I completely agree with ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsr2palznqag7kmk45d8d3lk8av45vy7cd08fs8r90tpxkv39s0x7qzyqt4lj5f0nps5fkd3dg92tj2fdpwfnzx7evp2y90a5kneyp2j6rlwkf9h0p" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsw0ag78qxtm0mrsjqd2c742z5fvqfd3lfrdt2evak4safmf2jzstg7qwwn0&#39;&gt;nevent1q…wwn0&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I guess this is the distinction. I completely agree with &amp;#34;highly spoofable&amp;#34; - I&amp;#39;d even go so far as to call it eminently spoofable. But, if risk = vulnerability * (threat / likelihood - as a decimal number no greater than 1) - any number times 0 is 0.&lt;br/&gt;&lt;br/&gt;SMS spoofing/cloning are non-zero risk, even for folks who celebrated a holiday yesterday - but, how do we communicate that to the average user in a way that gets their attention, but isn&amp;#39;t so catastrophic that it fades into the background noise of &amp;#34;everything is going to get you eventually&amp;#34;?&lt;br/&gt;&lt;br/&gt;This is a genuine question I&amp;#39;ve had, as a security-conscious developer, for several years. The vulnerabilities are real - security professionals can provide chapter-and-verse for that. Communicating the threat, though, is where the industry comes up short. &amp;#34;This is like bathroom graffiti!&amp;#34; doesn&amp;#39;t land with most folks. IOW - if the given is &amp;#34;these ignorant users believe their data is not at risk&amp;#34; - do you have ideas of how we can convince them that they&amp;#39;re wrong?&lt;br/&gt;&lt;br/&gt;What I&amp;#39;ve done, up to this point in my career, is make my stuff as secure as possible. I&amp;#39;d love an out-of-the-box take, though, that breaks through the tech-bubble noise and convinces people not to panic, but to actually consider their risk and adjust their behavior. :)
    </content>
    <updated>2025-07-06T00:38:23Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsv3c9uwern2mxluuzxczuj3j9xzs2srp64tuya5h74dqthtzl5g8gzyqt4lj5f0nps5fkd3dg92tj2fdpwfnzx7evp2y90a5kneyp2j6rlw88y6z7</id>
    
      <title type="html">I&amp;#39;d forgotten about SIM swapping (and cloning). That&amp;#39;s ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsv3c9uwern2mxluuzxczuj3j9xzs2srp64tuya5h74dqthtzl5g8gzyqt4lj5f0nps5fkd3dg92tj2fdpwfnzx7evp2y90a5kneyp2j6rlw88y6z7" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs0mszgaeyzw5fpkyua7j8p73uq22el2f6uepw9gv9xhz8df5zf7scq9jxem&#39;&gt;nevent1q…jxem&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;I&amp;#39;d forgotten about SIM swapping (and cloning). That&amp;#39;s definitely a more likely scenario, depending on where you are!
    </content>
    <updated>2025-07-05T15:31:03Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs82x4jwadcy92z96rh5lfc7c22f080z45p3eja72v3xdt23klxcgszyqt4lj5f0nps5fkd3dg92tj2fdpwfnzx7evp2y90a5kneyp2j6rlwghs2gf</id>
    
      <title type="html">Thinking about SMS security @npub10us…p5pu @npub142a…ccwa ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs82x4jwadcy92z96rh5lfc7c22f080z45p3eja72v3xdt23klxcgszyqt4lj5f0nps5fkd3dg92tj2fdpwfnzx7evp2y90a5kneyp2j6rlwghs2gf" />
    <content type="html">
      Thinking about SMS security &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub10usx3fj7rf0l8w86d2zjkxy9cnxrrh4qwt206r72p0q33m5ecxss7np5pu&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Sir Ryan Bemrose&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub10us…p5pu&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub142axprcsl9sppvwjs5jjpmeuj3trgxv00s3yvptkyntc04tx4res23ccwa&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Princess Pheonix of The Lotus&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub142a…ccwa&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1d85tf7a4t8zzw4ajtrpm026ylhwd6hs9202gcwh3w2gk8mwrrs0qcup88k&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;PhoneBoy of The Lotus 🪷&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1d85…p88k&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; - it&amp;#39;s my understanding that SMS is unencrypted w/in the network where it&amp;#39;s sent (so phone-company secure), and that the biggest risk is rogue connection points that may trick the phone into connecting to it. People may underestimate how likely they are to encounter one of those (&amp;#34;who would want MY data?&amp;#34; LOL), but has that threat model changed?&lt;br/&gt;&lt;br/&gt;I agree on the levels of security by content, but it also needs to be the highest level of security that content would need; otherwise, the presence of a certain level of security implies the value of the content being secured. I agree that should be baked in at the design level, not layers bolted on afterwards; but, do you not see some of those as pragmatic steps to save the uninformed masses from themselves&amp;#34;?
    </content>
    <updated>2025-07-05T15:13:44Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs22vj0xylhxernk9zjgycfng6kvqqng62x56eqcrq3fxtthdq9q2szyqt4lj5f0nps5fkd3dg92tj2fdpwfnzx7evp2y90a5kneyp2j6rlwn9g0at</id>
    
      <title type="html">A while back, @npub108h…p7er asked if anyone could write an RSS ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs22vj0xylhxernk9zjgycfng6kvqqng62x56eqcrq3fxtthdq9q2szyqt4lj5f0nps5fkd3dg92tj2fdpwfnzx7evp2y90a5kneyp2j6rlwn9g0at" />
    <content type="html">
      A while back, &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub108hte8kclgqxjqrmg0remdz3l06wtmr2w09lt5acxhje9lk7a3js5zp7er&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;FortyTwo™&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub108h…p7er&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; asked if anyone could write an RSS reader that could be used on an internal network, using vanilla PHP and SQLite. I thought that sounded like fun, and 5 months ago, the first beta was done. Long story short - v1 was released today!&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://git.bitbadger.solutions/bit-badger/feed-reader-central/releases/tag/v1.0.0&#34;&gt;https://git.bitbadger.solutions/bit-badger/feed-reader-central/releases/tag/v1.0.0&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;It&amp;#39;s designed for self-hosting, and will work with PHP 8.2&#43;.
    </content>
    <updated>2024-11-22T02:21:15Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsfuljsjnuhlvr39j0utrzzkfuleh746cd5hf5dljd0cwp6samurqczyqt4lj5f0nps5fkd3dg92tj2fdpwfnzx7evp2y90a5kneyp2j6rlwszmfjl</id>
    
      <title type="html">LOL... well, if you&amp;#39;re going to phrase it that way, I&amp;#39;m ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsfuljsjnuhlvr39j0utrzzkfuleh746cd5hf5dljd0cwp6samurqczyqt4lj5f0nps5fkd3dg92tj2fdpwfnzx7evp2y90a5kneyp2j6rlwszmfjl" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsdhhkccwgwmdmqkh6ljhpj2s7smr5e34agtmy24yyd605lljyz83g0m26hp&#39;&gt;nevent1q…26hp&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;LOL... well, if you&amp;#39;re going to phrase it that way, I&amp;#39;m not going to disagree with you.&lt;br/&gt;&lt;br/&gt;As Jonah Goldberg likes to say, &amp;#34;Trump isn&amp;#39;t Hitler; Hitler could have repealed Obamacare.&amp;#34;
    </content>
    <updated>2024-08-13T19:05:52Z</updated>
  </entry>

</feed>