Levi Broderick
banner
grabyourpitchforks.bsky.social
Levi Broderick
@grabyourpitchforks.bsky.social
Your friendly neighborhood security otter. Part of Microsoft's .NET team. Personal account, not speaking for my employer. 🔥🦦🛡️🔥 -- he/him
Give your hot takes on American culture & cuisine and you, too, can be ratioed!
November 10, 2025 at 8:38 PM
Reposted by Levi Broderick
I’m really proud of this talk and I hope you’ll watch it. I put care in to making it approachable while still delivering my perspective and insights to security professionals. If you don't get the "why" behind passkeys, this talk will help fill that gap. [2/2] www.youtube.com/watch?v=otOb...
Authenticate 2025 Keynote | Ricky Mondello, Apple | Get the Most Out of Passkeys
YouTube video by FIDO Alliance
www.youtube.com
November 7, 2025 at 1:51 PM
Just upload your creds to GitHub like everybody else does. It would save time and then people wouldn't have to phish you.
November 9, 2025 at 9:09 PM
I know plenty of people who don't use dev tools who might immediately benefit from this. Maybe I'll start enabling it on their boxes over the next few weeks. 😈
November 9, 2025 at 7:33 PM
That would be awesome! I wonder if they'd ever add a Misanthrope Mode. Don't notify me about people, but you bet I want a real time alert every time a critter is seen. :)
November 4, 2025 at 7:42 PM
I don't need to know that the postman walked down the driveway, up the stairs, onto the porch, retrieved a package from his satchel, placed it in front of the door, walked off the porch, down the stairs, .... Just say "Postman left a package at the door." Christ.
November 4, 2025 at 7:23 PM
A very frequent example: they give tons of extraneous details spanning multiple sentences rather than a succinct "<Bob> entered the house." It's often so long that the iOS lock screen truncates the text and excludes the actual useful details at the end!
November 4, 2025 at 7:21 PM
The tech is genuinely impressive *when it works*. But G trashed usability in the process because they're trying to use the Nest platform as a "isn't this cool?" tech demo rather than tailoring the experience for a typical residential use case.
November 4, 2025 at 7:19 PM
And for King County, at least, you can pull up the webcams and watch the verification and tabulation happen live!

kingcounty.gov/en/dept/elec...
November 4, 2025 at 7:11 PM
Funny. After reading that chart, I have a hankering for some beignets. 🥺
October 30, 2025 at 3:49 PM
Me, a consummate intellectual: "It is so convenient to schedule the entire household to get vaccinated at the same time!"

Nature: *gleefully rubbing hands together* "Muahahahaha! You fool!"
October 25, 2025 at 10:49 PM
We've looked into making System.Random be backed by a true CSPRNG, but it's impractical for a variety of reasons. One fatal flaw (among many) is that the Random class uses floating point in all its abstractions, which means any call to Next(...) has inherent bias, regardless of PRNG used.
October 17, 2025 at 9:38 PM
That said, it's not a huge issue, but people look to Microsoft's docs for best practice and the docs really should be held to a gold standard.
October 17, 2025 at 9:36 PM
It's not a CSPRNG. We issued a CVE (the number escapes me right now and I don't have email access) for System.Web some months ago due to this exact issue: use of System.Random rather than a true CSPRNG for entropy generation.
October 17, 2025 at 9:34 PM