the one with the little toddler locked out on the patio while mommy gives us a crotch shot (and i do believe it's real) really makes me upset. :|
- Joe Silence is not dead
Every time someone says "floater" I remember the strange juxtaposition of sexy and, er, "waste product" and I DON'T WANT that association in my brain!!!!
- Rick Cogley
Photobomb site is all about this meme :)
- Hasitha
from iPod
The floater one is truly disgusting and some of the ones involving kids are funny/maddening (having sex in the car with your kid in the backseat?! Really?!), but the creepy ginger kid behind Kate Beckinsale takes the cake.
- Rebecca Sun
Chart is woefully incomplete without reference to Aliens (especially the queen) or Predator
- LANjackal
The scientific accuracy of this chart is questionable. It looks like the Megatron silhouette is from the Transformer's cartoon. The 50 foot woman is crouching. And the line from Ghostbusters is "killed by a 100-foot marshmallow", which presumably doesn't include the hat.
- Andy Bakun
In my head they were totally the wrong way around! I think they just got bigger the smaller I was!
- Chris Lloyd
E-trade offers them for $25 https://us.etrade.com/e.... The way it works is that this keychain thing spits out a new number every minute, and you include that number with your password at login. Even if someone gets your password (due to a keylogger or the like), it will quickly be invalid.
- Paul Buchheit
Blizzard almost never has them in stock. Whenever they get a batch they sell out in a few hours. Apparently they work. lol
- Heather
I do not know how reliable they are now but a few years ago, the quartz in this would get out of sync for a non trivial percentage of users, which resulted in a lot of customer support issues.
- Edwin Khodabakchian
bought one for the hubby's warcraft account. he hasn't been hacked since. (nearly once every couple weeks prior to that)
- Nathalie, Dreamer of FF
I would pay for this option also and being that I run GApps at work, would also do it for all staff.
- Travis Koger
from iPhone
What would keep someone from writing this as an iPhone/Android app?
- Matt Cutts
It would need to hook into the Google auth system Matt. (or automatically change my password every minute, which would probably trigger some abuse system inside google)
- Paul Buchheit
Matt: Nothing, as demonstrated by Blizzard's implementation of it as a free iPhone app already. :)
- Stephen Mack
I wish this could end phishing, but it can't, because "it will quickly be invalid" doesn't help much if it's used to generate a session token the very moment it's entered. Perhaps the key should ask you what OS/browser you're using, how recently you logged in on that machine, etc. -- facts known to Google and associated with your browser session -- and generate different numbers depending on your answers. Tricky business.
- Daniel Dulitz
It doesn't solve all problems Daniel, but it does solve some. The twitter hack for example was apparently due to a guessed password or something (though I'm not up-to-date on the news, so maybe that's no longer the story).
- Paul Buchheit
Frankly, I want an RFID-like chip in my cell phone + ubiquitous RFID readers. The cell phone would also require you to type a password or PIN, so it's something you have + something you know. And there's a fake PIN that looks like it worked but causes a lockdown behind the scenes, so if you get mugged you tell people the PIN is 5555 when your PIN is really 2343.
- Matt Cutts
Paul, it's just a lot easier to make this happen if it solves the _biggest_ problem. :-)
- Daniel Dulitz
I think the biggest problem is that people want absolute convenience and absolute security. I have never had any personal information stolen or accounts hacked. It might be because I'm a boring person not worth stealing from, but it could also be that I don't put information all over the place. I only use my phone to make calls, I only download from well known sites, I don't allow porn...
more...
- Heather
I disagree with that reasoning Daniel. The phishing problem is real, but today's Twitter problem for example does not appear to have been phishing related, and probably would have been prevented by a device such as this -- is that not sufficient evidence that this solvable problem is worth solving? It also prevents people from using bad passwords, using the same password on multiple accounts, etc, which is very useful in the apps-for-your-domain context.
- Paul Buchheit
As soon as PayPal offered theirs I bought it immediately and like many others, I'm in line to get one for our two WoW accounts. I loved these as a Systems Admin where we required them to get past the firewalls if you were a remote worker.
- bear (aka Mike Taylor)
+1 Paul, I've been a SecureID user many years at work, and with ETrade, so I've got two, so far, but it makes you wonder if every account you used required SecureID, you'll eventually need a REALLY BIG keychain. ;)
- .LAG liked that
There is no reason why the same SecureID fob can't be used with more than one site.
- Jauder Ho
Matt Cutts: BlackBerry (maybe only BES) has had "password under duress" for a while. When enabled you swap the first and last characters of your handset password, it unlocks but also triggers admin side alerts. Quite cool, but I suspect the only people that use it will be the military :)
- Alex Lomas
jh: yeah, RSA should probably offer this as a service; get one SecurID from them, and you can register it with any site that supports it.
- Tudor Bosman
Paul, no, I don't think the fact that some hacks would be prevented by a method is sufficient reason to implement that method. Apps has supported SAML for quite a while, see http://code.google.com/apis... , so Apps admins can use auth methods of their choice including this one. If I'm going to take your $25 for a token, I'd like to make it more...
more...
- Daniel Dulitz
@jh, @Tudor: yeah it would be great if one SecureID could service multiple accounts for the owner, but i think each key fob is unique to the account holder and service they're issued for; some foreknowledge of the site/account the fobs will be used for is required. with the one I use at work, I signed some paperwork, sent it to Tech, and then got the fob few days later. Sounds like a potential customer-service nightmare for RSA if they when that route.
- .LAG liked that
They'd probably pick up more paid accounts. Just the concept would probably convince numerous new users.
- Charlie Anzman
Great idea! It's also a great way of branding the name if it's on a key chain of something else cool. Verisign offers it as a second layer of security on their OpenID accounts. They were charging before, but I just checked and it's free now. I'll have to get it for my account. Two-factor identification should be standard everywhere, especially on bank accounts.
- Michael Fidler
I'm waiting for Google to handle all my Internet passwords, all encrypted behind a master Google accounts password and a security calculator/keychain type of mechanism. I wouldn't perhaps need to use that physical extra security code each time I log in. It could be set to once a day, and secure login can be reset at any time during the day (if you don't feel confortable using public web terminal at a netcafe, you can simply activate secure login for any activity done after you logout.
- Charbax
Also, I believe Google should easily show me a complete log of all activities on my Google account, this way I could find out if something fishy is going on. If one is paranoid while using a public terminal, there should be a "monitor in realtime all activity" window so you can see if anything weird is going on while you are logged in and you should imediately be able to cancel/restore/logout in realtime once any of that fishy activity has been detected.
- Charbax
For $25 -- that's worth the peace of mind.
- CarolAnnB
Matt, regarding RFID: I've seen applications using bluetooth for a similar purpose. If a specific phone comes within range, the computer unlocks/wakes up/launches the missiles/etc. I'm not sure that RFID adds much, though I'm unfamiliar with how easy it is to spoof the identity of either bluetooth or RFID.
- DGentry
in case you weren't aware, there are other options for SecurID other than the fob - like the mobile app http://www.rsa.com/node... or software token (RSA is an EMC company, my employer)
- Stuart Miniman
I have my paypal key, I feel secure because of it. And it only cost me $5.
- Luis
The future of security is going to include some strong password/identity tools. Agreed on the value of the rsa key, could our smart phones generate similar sequences without risking theft?
- Mark Essel
from iPhone
@Charbax: Gmail (and possibly other apps?) does show you when someone else is logged in at the same time as you are, as well as their IP. Not precisely what you're suggesting, but is still quite helpful.
- Joel Webber
surprised these things are still popular. Years ago we used them at GE and perhaps they still do... But wouldn't it be more convenient to add a dynamic part to a password with a question like your wife's age + XX, or day first child was born + XX or year this picture was taken + XX. The variation of lets say 5 questions plus a random addition or subtraction would add enough variation and security no ? curious to see this your comments.
- Bart LePoole
I have the Paypal one, and one for my BofA account. I would definitely get one for Google and for my Amazon account. *HINT*
- Ha3rvey (not Akiva)
Why would I want one for every account? Why can't I use the same one for all my accounts?
- Gabe
paul, that's a great idea for a start-up (btw user should have *one* item for all accounts)
- Massimo MaxKava Cavazzini
Stuart: thanks cool that rsa is proactive about it. It also looks like Matt suggested mobile devices take on this responsibility earlier in the thread
- Mark Essel
from iPhone
These tokens are mostly based on OTP solutions. Google also must consider the other options; PKI - for maksimum security (e-signatures) - And also, Google's application must be supported with most tokens regarding to its support (PKCS etc.)
- Zafer Yılmaz
The OAuth authentication method allows for two separate sets of credentials, one for the client and another for the resource owner (on its behalf).
- tkudo
"They say an elephant never forgets. But apparently Thais have no problem in forgetting the elephant. Though the elephant is the national symbol of Thailand, the country has gone panda-crazy - so crazy that indignant zookeepers have taken the unusual step of painting elephants to look like pandas. The stunt has resulted in panda-monium as the zookeepers try to draw the country's attention back to its neglected giants."
- RAPatton
from Bookmarklet
"There is so much hugging at Pascack Hills High School in Montvale, N.J., that students have broken down the hugs by type: There is the basic friend hug, probably the most popular, and the bear hug, of course. But now there is also the bear claw, when a boy embraces a girl awkwardly with his elbows poking out. There is the hug that starts with a high-five, then moves into a fist bump, followed by a slap on the back and an embrace. There’s the shake and lean; the hug from behind; and, the newest addition, the triple — any combination of three girls and boys hugging at once... A measure of how rapidly the ritual is spreading is that some students complain of peer pressure to hug to fit in. And schools from Hillsdale, N.J., to Bend, Ore., wary in a litigious era about sexual harassment or improper touching — or citing hallway clogging and late arrivals to class — have banned hugging or imposed a three-second rule."
- Bret Taylor
from Bookmarklet
Hugs are awesome. Unless they are coming from creepy people. Generally, though, they are awesome.
- Type Micah
Only in America it occurs to schools to ban hugging or impose an N-second rule. "“Touching and physical contact is very dangerous territory,” said Noreen Hajinlian, the principal of George G. White School, a junior high school in Hillsdale, N.J., who banned hugging two years ago. “It was needless hugging — they are in the hallways before they go to class. It wasn’t a greeting. It was happening all day.”
- ana
People are more physical nowadays. I appreciate this. Especially with the LADIES.
- Mike Nayyar
This hugging is a good thing, with electronic communication being the norm.
- Rick Cogley
the breakdown is very interesting. for us, growing up, it was kisses. affection amongst hard rocks was common too, this still exists today, involving complicated handshakes and hugs.
- Carlos Ayala
I am going to hug the entire FriendFeed team tomorrow. Bret can monitor the second counts.
- Louis Gray
Growing up in Japan, hugging didn't come natural to me. I can't remember my first hug, but I did like a girl's bosoms pressing against me. Those were the days!
- Hiro Asari
@Hiro, lol. :-) Now in Japan, there's even groups that offer "free hugs" on the streetcorner. Japan has changed a lot in the 22 years since I came...
- Rick Cogley
@ana, yeah, only in America. I am American, but I always wonder why people are so uptight about that sort of thing. 3-seconds... jeez.
- Rick Cogley
@Rick I believe you, but I want to see the pics of these people (and the reaction of the passersby).
- Hiro Asari
@Hiro - yeah, I've only seen them once for real, and a couple times in the paper. Peoples' reaction would be interesting yes.
- Rick Cogley
God, only in an American public high school could they turn a perfectly reasonable and healthy interaction into a cause for alarm. We Americans *need* a little more contact, if you ask me.
- Joel Webber
This was pretty common amongst a subset of people when I was in high school in Australia (mid-90s), along with cheek-kissing. It was great.
- Glen Murphy
Hugging is a good thing. It should be encouraged. You know, humans that touch one another, speak to one another, and that generally have social interaction, are happy humans. Deal with issues on a case by case basis and don't make these knee jerk blanket policies
- Chris Gardner
OK, so this is an interesting phenomenon but I found it mighty weird that this story was on the front page, below the fold, of the print edition. The jump? It was to page A3. I'm all for quirky stories on the front page; it diversifies the page and reaches a broader audience. But....
- Christopher Chung
So we are conservative, don't we? To me, only the most friendly will I give my hugs. I could expect the gap between us and our children.
- Juvenn Woo
from fftogo