[twisti]NeXeN: that seems like a convoluted and confusing way to achieve ... the same thing *s do
* raj joined #java
* AlexMag joined #java
* ChaiTRex joined #java
* handicraftsman joined #java
jreicher[twisti]: one thing that isn't a waste of time is to randomise the number of asterisks that are printed with each keypress.
[twisti]it seems like a better option would then be to not display them at all. *s are displayed to help people see if they made a mistake typing - if you take that away, which is reasonable, there is no reason to display them at all anymore, as they give no more information and additionally serve to confuse the user making them think they mistyped
jreicherI think it's more important to see that a keypress happened at all. But I take your point. It's hard to balance useful feedback against compromising information. There's a natural tension.
ParaRemember Lotus Notes which literally printed random amount of eqyptian hieroglyphics when passwords were being typed.
dreamrealpersonally, I think there's no need to hide any of the characters in the passwords: when I type my password, which is obviously *******, I want to see the actual characters so I know it's right: it should be displaying hunter2 like God intended
ParaI need to hide an April Fools' mode into my next app where the password mask shows hunter2 instead of ******
* sponkz joined #java
* jamezp joined #java
* rvalue joined #java
[twisti]how did you know my password???
dreamrealhow did you know MY password!!!
* michele joined #java
dmlloydobligatory 1 2 3 4 5
* gareppa joined #java
* Deneb^ joined #java
sbalmosPassw0rd123!@
* m joined #java
dreamrealI don't know why anyone would bother typing ************* in a channel
dreamrealseems like a waste of time and bandwith
sbalmosit's better than $@@FFA@#@@#%^@
* monkeyPlus joined #java
dreamrealWhy'd you type ************** out
sbalmosdreamreal: because MFA4IRC told me to
sbalmosdreamreal: it's also saying you'll need 075184 as the 2FA code to use. Be quick though. It's only good for another 10 minutes.
dreamreal075184
dreamrealDid I make it on time? hey, cool, my bank just texted me
dreamrealhmm, yes, bank manager, that really is a nigerian prince, he promised me
sbalmosdreamreal: uhm, I'm not in Nigeria, I'm in South Africa
sbalmosdreamreal: you twat, you just ruined it
sbalmosdreamreal: where'd my money go?
dreamrealNigeria! ... it'll come back. He promised.
dreamrealAll I need to do is dial this long international number: it's only 27 digits long and has π and § in it, should be easy
dreamrealI'm on attempt #12 to type it in, though
sbalmosdreamreal: can't you get anything right? it's not §, it's 🌀
dreamrealHe said it was §. Maybe it was a ∞ though
dreamreal... and how did YOU know
* ferdna joined #java
dreamrealI should write a weechat plugin that matches all input against my passwords and actually does replace them with asterisks. That'd be a great idea, right?
cheeseryou could do a simple entropy check and mask out those. that's how github scans for secrets and essentially what do in our sensitive data scanner. there's more to it but that's the first pass that is good enough for irc.
ParaI wonder what's the entropy of standard Finnish...
dreamrealI don't need no entorpy. But I WILL write it in brainfsck...
ParaOr tokenization (the actual kind, not LLM) - if the word doesn't tokenize properly, it's probably a password.
ParaOr the cat trying to do the taxes again, and that is also something worth blocking.
* johnjay joined #java
dreamrealMaybe that's why my taxes were so high this year. I *knew* she couldn't spell, but now my cat can't do math, EITHER? Crikey, why do I even keep her around