• 0 Posts
  • 16 Comments
Joined 9 months ago
cake
Cake day: March 6th, 2024

help-circle
  • Even with a 10% pay cut the VC will be remunerated over $1,000,000 per year, even despite the university’s poor financial performance.

    Having worked at a university the waste is in plain sight. Vendor lock-in, consulting fees (especially with the Big 4), high executive pay, and compartmentalisation between professional and academic staff are high on the list.

    In my area (different university) there was a constant stream of poor decision making. Moving to the cloud? Let’s hire a consultant to tell us what to do, and then do it in the worst possible way, instead of using internal capabilities! I suggested that the contract include provisions for “best practice” as listed by the vendor (HashiCorp) but this was ignored. The consultant gave us spaghetti Terraform code and an inefficient, high cost subscription layout.

    The professional and academic staff barely talk in my experience. Academics do their own thing as much as possible. Professional staff throw solutions over the wall, mostly because of the existence of the wall in the first place.

    The university was looking at using “crotch sensors” (motion sensors under the desk) to measure desk utilisation, spending money on “smart” ambient sound solutions etc. in the executive building, and other high cost solutions looking for a problem, at the same time as freezing staff and threatening redundancies. I was denied training but offered access to an LLM subscription (GitHub CoPilot) along with other IT staff, because AI is the going buzzword being parroted by the executives.

    The higher education sector seriously needs an external review… and a proverbial kick up the bum.



  • Here’s the actual paper of the technology (Prio) that it’s based on.

    Some problems stand out:

    • It requires that the organisations (Mozilla and ISRG) not collude to decrypt the secret share (probably reasonable)
    • The paper suggests registering end users to protect against Sybil attacks.
    • The scheme requires the organisations to correctly withhold results from advertisers until there are sufficient results.

    I’m not overly familiar with the tech stack but I’d be concerned about browsers using a persistent UUID to send impressions to Mozilla’s API.

    The biggest elephant in the room is that seemingly nobody wants the damn thing. It offers nothing to users, except maybe a good feeling inside that they’re supporting AdTech. It offers AdTech less than the current deal where they can collect obscene amounts of personal information for targeted advertising.


  • PSA: if your financial institution/government/<other website> is using SMS codes (aka PSTN MFA) for multi-factor authentication they are practically worthless against a determined attacker who can use SIM swap or an SS7 attack to obtain the code. Basically you are secured by a single factor, your password. If your password is compromised it may be sold via black hat marketplaces and purchased by an attacker who would then likely attempt to break that second factor.

    The best way to protect yourself is to use a unique password; a password manager especially helps with this. Sometimes institutions will offer “Authenticator” (TOTP) as a second factor, or PassKey authentication, both secure alternatives to SMS codes.

    Here in Aus I’m working with Electronic Frontiers Australia to try and force some change within government and financial institutions (via the financial regulator). Most banks here use SMS codes and occasionally offer a proprietary app. One of the well-known international banks, ING Bank, even uses a 4 pin code to login to their online banking portal. 😖

    Unfortunately SMS codes are a legacy left from old technology and a lack of understanding or resourcing by organisations that implement it. Authenticator/TOTP tokens have been around for 16 years (and standardised for 13 years), and PassKeys are relatively newer. There is a learning curve but at the very least every organisation should at least provide either TOTP or PassKeys as an option for security-minded users.


  • I have a bicycle crate in my rear rack (40L from memory). I can just throw my backpack and/or shopping in there and be on my way. No issues transporting when empty. I avoid riding in the rain but I guess a waterproof bag would help for that. It’s durable, the main concern is the rear rack. I had to replace the cheaper rack that I bought last year after the welding snapped in a few places over time (I had it held together with duct tape for a while). My new rack should be much more sturdy this time around.

    I have access to borrow a car which I do every few weeks so I don’t need to over engineer my bike setup too much.








  • There are different types of cycling. I would always wear a helmet to work because I live 6km away and it’s a decent ride. There are hills and I often get to a reasonable speed.

    Compare that to someone living in South Brisbane commuting to the CBD, or someone going for a leisurely bike stroll on the riverwalk - they may not go fast at all. We don’t wear helmets whilst walking or jogging, but why is it mandatory for a slow ride?

    The big reason helmets can be offputting is because they can mess up your hair. If the city wants to encourage people who live relatively close to their jobs to ride in, more flexibility on helmets could be a good thing.

    FWIW I do think helmet safety should always be encouraged. Riding down a hill? Going more than a leisurely stroll? Wear a helmet. Makes sense. But it’s really not that necessary for people who are riding slow.



  • I ride all year round in Brissie. I find my comfort level depends on when I ride, distance, speed and my bike setup.

    First, I ride to and from work in the morning and arvo when it’s cooler, not in the middle of the day.

    I ride 6km each direction which is manageable. In winter I barely break a sweat. In summer I have a shower on each side. I can and sometimes do get away without showering by riding slowly. Or I just catch PT if I’m going somewhere else after work.

    The other thing I noticed is that not wearing a bag helps a lot with reducing sweat on my back. I have a basket on the back of my bike and just throw my bag in. A lot of other people use pannier bags.