<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[they have a solid point, y&#x27;know.]]></title><description><![CDATA[<p>they have a solid point, y'know.</p><p>users don't have meaningful agency here, but businesses sure the fuck do, and the way tech has treated users is creating perverse incentives and frustrations.</p>]]></description><link>https://board.circlewithadot.net/topic/4e87e436-1abb-4e97-8962-0e58dd9cdec5/they-have-a-solid-point-y-know.</link><generator>RSS for Node</generator><lastBuildDate>Mon, 25 May 2026 06:24:26 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/4e87e436-1abb-4e97-8962-0e58dd9cdec5.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 16 May 2026 22:23:38 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to they have a solid point, y&#x27;know. on Sun, 17 May 2026 18:35:11 GMT]]></title><description><![CDATA[<p><span><a href="https://bsd.network/@phessler" rel="nofollow noopener">@<span>phessler</span></a></span></p><p>Each individual user may not consider a given credential as worth needing MFA, but since most users reuse passwords, it's arguably better move for the <em>ecosystem</em> and site operators to require some kind of MFA. Otherwise, if one site gets popped, a wave of user accounts could be abused in bulk and require operator intervention. Whether or not mass lockout/reset is inconvenient enough for the individual user to think MFA is a good trade-off may vary.</p><p><span><a href="/user/munin%40infosec.exchange">@<span>munin</span></a></span></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/tychotithonus/statuses/116591356263901188</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/tychotithonus/statuses/116591356263901188</guid><dc:creator><![CDATA[tychotithonus@infosec.exchange]]></dc:creator><pubDate>Sun, 17 May 2026 18:35:11 GMT</pubDate></item><item><title><![CDATA[Reply to they have a solid point, y&#x27;know. on Sun, 17 May 2026 01:52:07 GMT]]></title><description><![CDATA[<p><span><a href="/user/munin%40infosec.exchange">@<span>munin</span></a></span> I just posted about an attack on/using agentic finance bots that cost someone $200k. <a href="https://oldbytes.space/@arclight/116587393934910011" rel="nofollow noopener"><span>https://</span><span>oldbytes.space/@arclight/11658</span><span>7393934910011</span></a></p><p>I still can't stop laughing at a Trojan NFT.</p>]]></description><link>https://board.circlewithadot.net/post/https://oldbytes.space/users/arclight/statuses/116587412016459881</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://oldbytes.space/users/arclight/statuses/116587412016459881</guid><dc:creator><![CDATA[arclight@oldbytes.space]]></dc:creator><pubDate>Sun, 17 May 2026 01:52:07 GMT</pubDate></item><item><title><![CDATA[Reply to they have a solid point, y&#x27;know. on Sat, 16 May 2026 22:58:09 GMT]]></title><description><![CDATA[<p><span><a href="/user/munin%40infosec.exchange">@<span>munin</span></a></span> <br />I can never use online banking, and my bank may still allow my account to be compromised. </p><p>I can never fill out a form online with my address, but my address is still online because “public record”</p><p>I can never buy anything online, never use a credit card, but the combination of ALPR and security cameras means my shopping habits are still known when I shop in-person using cash. </p><p>Yeah, consumers are not the problem here.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/TindrasGrove/statuses/116586727961618862</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/TindrasGrove/statuses/116586727961618862</guid><dc:creator><![CDATA[tindrasgrove@infosec.exchange]]></dc:creator><pubDate>Sat, 16 May 2026 22:58:09 GMT</pubDate></item><item><title><![CDATA[Reply to they have a solid point, y&#x27;know. on Sat, 16 May 2026 22:24:37 GMT]]></title><description><![CDATA[<p>if you want users to take security seriously?</p><p>gotta give them some reason to think it will matter.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/munin/statuses/116586596131887110</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/munin/statuses/116586596131887110</guid><dc:creator><![CDATA[munin@infosec.exchange]]></dc:creator><pubDate>Sat, 16 May 2026 22:24:37 GMT</pubDate></item></channel></rss>