# I am the Watcher. I am your guide through this vast new twtiverse.
# 
# Usage:
#     https://watcher.sour.is/api/plain/users              View list of users and latest twt date.
#     https://watcher.sour.is/api/plain/twt                View all twts.
#     https://watcher.sour.is/api/plain/mentions?uri=:uri  View all mentions for uri.
#     https://watcher.sour.is/api/plain/conv/:hash         View all twts for a conversation subject.
# 
# Options:
#     uri     Filter to show a specific users twts.
#     offset  Start index for quey.
#     limit   Count of items to return (going back in time).
# 
# twt range = 1 196321
# self = https://watcher.sour.is?offset=150825
# next = https://watcher.sour.is?offset=150925
# prev = https://watcher.sour.is?offset=150725
And to finish the day off: https://lyse.isobeef.org/abendhimmel-2023-09-18/
Today's morning sun made for a nice scenery: https://lyse.isobeef.org/morgensonne-2023-09-18/
[47°09′43″S, 126°43′31″W] Transfer 75% complete...
Huh hey @lumen I didn't even notice you run a Yarn pod 👌 Whot! 🥳
Huh hey @lumen I didn't even notice you run a Yarn pod 👌 Whot! 🥳
Huh hey @lumen I didn't even notice you run a Yarn pod 👌 Whot! 🥳
Hey @burgermeister 👋
Hey @burgermeister 👋
Hey @burgermeister 👋
On my blog: Developer Diary, World Water Monitoring Day https://john.colagioia.net/blog/2023/09/18/water.html #programming #project #devjournal
[47°09′58″S, 126°43′14″W] Transfer 50% complete...
Pinellas County - Base: 5.03 miles, 00:09:34 average pace, 00:48:05 duration
tired legs. bit humid probably because it is now pouring 3 hours later.
#running
Pinellas County - Base: 5.03 miles, 00:09:34 average pace, 00:48:05 duration
tired legs… bit humid probably because it is now pouring three hours later.
#running
Pinellas County - Base: 5.03 miles, 00:09:34 average pace, 00:48:05 duration
tired legs… bit humid probably because it is now pouring three hours later.
#running
Pinellas County - Base: 5.03 miles, 00:09:34 average pace, 00:48:05 duration
tired legs… bit humid probably because it is now pouring three hours later.
#running
[47°09′50″S, 126°43′01″W] Transfer 25% complete...
**** ⌘ Read more****
[47°09′07″S, 126°43′38″W] Sample analyzing complete -- starting transfer
@mckinley Nope.
@mckinley Nope.
@mckinley Nope.
🧮 USERS:1 FEEDS:2 TWTS:727 ARCHIVED:66923 CACHE:2289 FOLLOWERS:14 FOLLOWING:14
Fim de semana produtivo, mas agora vou dormir 72h seguidas Badges da Festa do Software Livre e do Team Community Global Gathering
Fim de semana produtivo, mas agora vou dormir 72h seguidas Badges da Festa do Software Livre e do Team Community Global Gathering
Holiday is over. It was nice and relaxing. Time for bed now. 🥱
garden: welcome PET01 to equipment/computers, also update chaos awakening act 3
[47°09′16″S, 126°43′04″W] Analyzing samples
awesome
awesome
[47°09′21″S, 126°43′11″W] Taking samples
We made a bike tour in the heat of the day. The sun was brutal with 27°C in the shade. Man, this one section was suuuuper steep and you couldn't hill-start anymore once stopped for a quick rest, because you just spun out the tire in the loose gravel. No chance. So we had to push (I didn't mind that, though). My mate's battery then flattened, so he had no other choice anyways. Luckily, I have an old-school bicycle with no electronics (if you don't count the lights). So the rest of the hills weren't too bad for me, but he was huffing and puffing badly.

We had waffles with apple sauce for lunch at a closed ski hut out in nature. It was very peaceful, nobody around, just birds and critters. After resting a bit we tried out the scout camera. Today's mission was to get a bit familiar with that equipment. All the pictures were taken with that DSLR, a Nikon D5200 with a 18-105mm lense. Quite a heavy rig compared to my small digicam. Looking at the pics on a big screen, we gotta keep practicing. This lense is certainly not made for macro shots. We have another one that's probably suited for that, but I didn't want to bring the whole bag. And more zoom would also be nice for all the birds. But we don't have a larger zoom lense.

[![Ödenturm](https://lyse.isobeef.org/fahrradrunde-weiler-ob-helfenstein-2023-09-17/58-vorschau.jpg)](https://lyse.isobeef.org/fahrradrunde-weiler-ob-helfenstein-2023-09-17/58.jpg)

Finally, we encountered an old train from the Märklintage (Märklin days). This weekend they pulled out old locomotives and wagons and had extra tours between Göppingen (where Märklin, the model train manufacturer, has its headquarter) and Geislingen/Steige. Tons of people all along the tracks everywhere.

[![German crocodile pulling old wagons](https://lyse.isobeef.org/fahrradrunde-weiler-ob-helfenstein-2023-09-17/65-vorschau.jpg)](https://lyse.isobeef.org/fahrradrunde-weiler-ob-helfenstein-2023-09-17/65.jpg)
[47°09′33″S, 126°43′22″W] --interrupted--
Pinellas County - Long run: 12.81 miles, 00:11:45 average pace, 02:30:38 duration
drank too much, slept too little. kept the pace where i wanted to when i headed out so that is something. found a nice little area with hills so will definitely be returning.
#running
Pinellas County - Long run: 12.81 miles, 00:11:45 average pace, 02:30:38 duration
drank too much, slept too little. kept the pace where i wanted to when i headed out so that is something. found a nice little area with hills so will definitely be returning.
#running
Pinellas County - Long run: 12.81 miles, 00:11:45 average pace, 02:30:38 duration
drank too much, slept too little. kept the pace where i wanted to when i headed out so that is something. found a nice little area with hills so will definitely be returning.
#running
Pinellas County - Long run: 12.81 miles, 00:11:45 average pace, 02:30:38 duration
drank too much, slept too little. kept the pace where i wanted to when i headed out so that is something. found a nice little area with hills so will definitely be returning.
#running
[47°09′17″S, 126°43′27″W] Waiting for carrier
New repository: aquilax/vale-bulgarian - Vale compatible rules for linting texts in Bulgarian
New repository: aquilax/vale-bulgarian - Vale compatible rules for linting texts in Bulgarian
[47°09′26″S, 126°43′33″W] --white noise--
🧮 USERS:1 FEEDS:2 TWTS:726 ARCHIVED:66921 CACHE:2288 FOLLOWERS:14 FOLLOWING:14
And done! [prologic/objects: Objects is an object storage server (using a directory as backend) with a AWS S3 compatible API written in Go. - objects - Mills](https://git.mills.io/prologic/objects) 🥳 Simple, but it works, anda very lightweight! 👌
And done! [prologic/objects: Objects is an object storage server (using a directory as backend) with a AWS S3 compatible API written in Go. - objects - Mills](https://git.mills.io/prologic/objects) 🥳 Simple, but it works, anda very lightweight! 👌
And done! [prologic/objects: Objects is an object storage server (using a directory as backend) with a AWS S3 compatible API written in Go. - objects - Mills](https://git.mills.io/prologic/objects) 🥳 Simple, but it works, anda very lightweight! 👌
E Nãos? Também jogas Nãos?
E Nãos? Também jogas Nãos?
going thru my own old drawings, exploring those distant worlds, like an archaeologist. tracing origins and evolutions #draw #art #trip #mind
Time to write my own S3-compatible Object Storage server 🤣
Time to write my own S3-compatible Object Storage server 🤣
Time to write my own S3-compatible Object Storage server 🤣
@thecanine Ah, haha, it's a really good one. I thought you drew it.
@ionores Thanks, mate!
[47°09′48″S, 126°43′59″W] Transponder still failing -- switching to analog communication
[47°09′29″S, 126°43′05″W] Transponder jammed
wow,technologies
funny how looking at someone's sketchbook might very well be like looking at an entire hidden world #art #draw #trip #phyilosophy
On my blog: Free Culture Book Club — Poles, part 5 https://john.colagioia.net/blog/2023/09/16/poles-5.html #freeculture #bookclub
[47°09′05″S, 126°43′26″W] Resetting transponder
The sunsets, always spectacular! Nice pict. 📷👍
@movq I mean yeah I totally get that syncing the TOTP seeds is a horrible idea. It defeats the point of a second factor and "something you have". 🤦‍♂️
@movq I mean yeah I totally get that syncing the TOTP seeds is a horrible idea. It defeats the point of a second factor and "something you have". 🤦‍♂️
@movq I mean yeah I totally get that syncing the TOTP seeds is a horrible idea. It defeats the point of a second factor and "something you have". 🤦‍♂️
[47°09′14″S, 126°43′02″W] --no signal--
Day to get things done..?
Day to get things done..?
@prologic

> Also kind of curious how syncing to Google servers made this attack worse? Not that clear from the article 🤔

As I understand it: The attacker was able to compromise the Google account of that employee. That would have been pretty been in and of itself. Due to this horseshit “sync” feature, though, the attacker was also able grab all those TOTP seeds that can be used to log in to other sites.

What’s unclear to me is how the attacker got to the *first* factor (probably a normal password). That was probably fished separately? And/Or that employee used the same password everywhere? 🤔
@prologic

> Also kind of curious how syncing to Google servers made this attack worse? Not that clear from the article 🤔

As I understand it: The attacker was able to compromise the Google account of that employee. That would have been pretty been in and of itself. Due to this horseshit “sync” feature, though, the attacker was also able grab all those TOTP seeds that can be used to log in to other sites.

What’s unclear to me is how the attacker got to the *first* factor (probably a normal password). That was probably fished separately? And/Or that employee used the same password everywhere? 🤔
@prologic

> Also kind of curious how syncing to Google servers made this attack worse? Not that clear from the article 🤔

As I understand it: The attacker was able to compromise the Google account of that employee. That would have been pretty been in and of itself. Due to this horseshit “sync” feature, though, the attacker was also able grab all those TOTP seeds that can be used to log in to other sites.

What’s unclear to me is how the attacker got to the *first* factor (probably a normal password). That was probably fished separately? And/Or that employee used the same password everywhere? 🤔
[47°09′15″S, 126°43′22″W] 3802 days without news from Herve
@abucci Can you recommend one?

> Of course, never ever use Google Authenticator. All it does is generate TOTP and HOTP codes, which you can do with any OTP app, preferably an open source one that’s been vetted.

I've been using Google Authenticator for years, but it never had this "sync" feature until recently 🤦‍♂️
@abucci Can you recommend one?

> Of course, never ever use Google Authenticator. All it does is generate TOTP and HOTP codes, which you can do with any OTP app, preferably an open source one that’s been vetted.

I've been using Google Authenticator for years, but it never had this "sync" feature until recently 🤦‍♂️
@abucci Can you recommend one?

> Of course, never ever use Google Authenticator. All it does is generate TOTP and HOTP codes, which you can do with any OTP app, preferably an open source one that’s been vetted.

I've been using Google Authenticator for years, but it never had this "sync" feature until recently 🤦‍♂️
🧮 USERS:1 FEEDS:2 TWTS:725 ARCHIVED:66913 CACHE:2312 FOLLOWERS:14 FOLLOWING:14
Also kind of curious how syncing to Google servers made this attack worse? Not that clear from the article 🤔
Also kind of curious how syncing to Google servers made this attack worse? Not that clear from the article 🤔
Also kind of curious how syncing to Google servers made this attack worse? Not that clear from the article 🤔
Wow !!! 😱 Those sneaky little shitheads!!! Google are unconspicious lying sons of notches 😢 When da fuq did they sneak this feature in?! I didn't even notice this was a thing from a recent upgrade of the app (Authenticator) 🤦‍♂️
Wow !!! 😱 Those sneaky little shitheads!!! Google are unconspicious lying sons of notches 😢 When da fuq did they sneak this feature in?! I didn't even notice this was a thing from a recent upgrade of the app (Authenticator) 🤦‍♂️
Wow !!! 😱 Those sneaky little shitheads!!! Google are unconspicious lying sons of notches 😢 When da fuq did they sneak this feature in?! I didn't even notice this was a thing from a recent upgrade of the app (Authenticator) 🤦‍♂️
On my blog: Toots 🐘 from 09/11 to 09/15 https://john.colagioia.net/blog/2023/09/15/week.html #linkdump #mastodon #socialmedia #week
Thanks, @movq!

When I went to the scout meeting this evening, I first saw a colorful sky, then a shooting star above our camp fire and finally a fairly new starlink chain of about 15 satellites or I don't know how many. There is only photographic evidence of one of these events.
'to ponder' is based on latin 'to weigh' - why are you pondering glass, you should be pondering tungsten
[47°09′30″S, 126°43′37″W] Transfer completed
How Google Authenticator made one company’s network breach much, much worse | Ars Technica

🤦‍♂

WHY are these big companies treated as though they are the be all and end all of infosec? These are rookie mistakes they're making, *at scale*.

> Unfortunately Google employs dark patterns to convince you to sync your MFA codes to the cloud, and our employee had indeed activated this “feature”. If you install Google Authenticator from the app store directly, and follow the suggested instructions, your MFA codes are by default saved to the cloud. If you want to disable it, there isn’t a clear way to “disable syncing to the cloud”, instead there is just a “unlink Google account” option.

Like, never ever put your multi-factor tokens into a single cloud storage location! The whole point of this being "multi" factor is that there is a separate, independent physical factor involved in the authentication process. If the authenticator app on your phone puts the tokens in the cloud, then it reduces the security that comes from having a second factor. This is basic stuff.

Of course, never ever use Google Authenticator. All it does is generate TOTP and HOTP codes, which you can do with any OTP app, preferably an open source one that's been vetted.
How Google Authenticator made one company’s network breach much, much worse | Ars Technica

🤦‍♂

WHY are these big companies treated as though they are the be all and end all of infosec? These are rookie mistakes Google's making, *at scale*.

> Unfortunately Google employs dark patterns to convince you to sync your MFA codes to the cloud, and our employee had indeed activated this “feature”. If you install Google Authenticator from the app store directly, and follow the suggested instructions, your MFA codes are by default saved to the cloud. If you want to disable it, there isn’t a clear way to “disable syncing to the cloud”, instead there is just a “unlink Google account” option.

Like, never ever put your multi-factor tokens into a single cloud storage location! The whole point of this being "multi" factor is that there is a separate, independent physical factor involved in the authentication process. If the authenticator app on your phone puts the tokens in the cloud, then it reduces the security that comes from having a second factor. This is basic stuff.

Of course, never ever use Google Authenticator. All it does is generate TOTP and HOTP codes, which you can do with any OTP app, preferably an open source one that's been vetted.
How Google Authenticator made one company’s network breach much, much worse | Ars Technica

🤦‍♂

WHY are these big companies treated as though they are the be all and end all of infosec? These are rookies errors they're making, *at scale*.

> Unfortunately Google employs dark patterns to convince you to sync your MFA codes to the cloud, and our employee had indeed activated this “feature”. If you install Google Authenticator from the app store directly, and follow the suggested instructions, your MFA codes are by default saved to the cloud. If you want to disable it, there isn’t a clear way to “disable syncing to the cloud”, instead there is just a “unlink Google account” option.
@lyse Uhh, nice 👍
@lyse Uhh, nice 👍
@lyse Uhh, nice 👍
[47°09′31″S, 126°43′10″W] Carrier too weak
**** ⌘ Read more****
@prologic Thanks, I got lucky there.
@prologic @bender I wash my hands of it. :-D
[47°09′46″S, 126°43′09″W] Bad satellite signal -- switching to analog communication
@darch Yup 😅
@darch Yup 😅
@darch Yup 😅
user/bmallred/data/2023-09-15-05-46-48.fit: 6.68 miles, 00:08:51 average pace, 00:59:06 duration

#running
user/bmallred/data/2023-09-15-05-46-48.fit: 6.68 miles, 00:08:51 average pace, 00:59:06 duration

#running