Profile pic

modem_down, modem_down@thebrainbin.org

Instance: thebrainbin.org
Joined: 1 week ago
Posts: 20
Comments: 31

RSS feed

Posts and Comments by modem_down, modem_down@thebrainbin.org

Even if you can [exploit NFC] at 1m, thats close enough that it can just be stolen from you.

Stealing the HST should not give the user a false sense of security. Not so dangerous.

Silently exfiltrating the private key (or data for a replay attack), OTOH, would leave the user with a false sense of security. Dangerous.

your link to rfidgate appears broken

Wfm. Here’s an archive link.


Thanks! I didn’t know they were normally made of composites.

Looks like there are some ways (1, 2) to reuse/recycle the latter, but I agree wood would be better for this.


Aren’t turbine blades usually aluminium? How is wood more “recyclable” than that?


This coverage has a better headline: Trump blames Minnesota governor for cyberattacks against the state. Cites no evidence.

Funding restrictions and denialism, plus starting a war against a cyberattack-capable nation, made infrastructure attacks inevitable.

Security researchers have been publicly raising the alarm about SCADA vulnerabilities for 20+ years.


If it’s a server for self hosting you definitely don’t want anything that requires interaction at boot.

Depends on use-case. If you only plan to boot it when you’re physically present, it’s fine.


i believe a much better secure layer is something similar to what Novacustoms, Purism attempt to do: verify if somebody else not you try to access the laptop.

You’re thinking of Heads, which I agree is ideal for supported motherboards.



I can only see three ways to get FOSS firmware on your printer:

  1. If someone reverse engineers the firmware to create a FOSS version.
  2. If the Software Freedom Conservancy, who recently raised funds to tackle Bambu Labs’s license violations, finds a violation in BL firmware and succeeds in legally compelling BL to release the corresponding source code.
  3. If you sell your BL printer and replace it with one that already has FOSS firmware.

I read them before writing my OP. I’m still not sure what you’re getting at.

I would be grateful if you could say what you mean, instead of initiating an oblique guessing game.


Yes. Here are some common self-hosting scenarios:

  • Home server containing family files: scans, photos, device backups, …
  • Office server containing business files: sensitive documents, device backups, …
  • Web or email server containing websites, Fediverse instances, emails, etc

In all those cases, full disk encryption (FDE) is a sensible precaution to protect the data in case the server is physically stolen.

Linux is probably the most common OS kernel for self-hosting. On Linux, LUKS (Linux Unified Key Setup) is probably the best FDE system. It’s mature and reliable. But anyone self-hosting a Linux server with LUKS FDE is faced with the question of where to store the keys.

Hardware security tokens (HSTs) are widely considered a safer place for keys than SSDs, HDDs, or USB storage. They follow the smartcard principle: a private key can be written to an HST but not read from it (security vulnerabilities excepted). Instead, they implement cryptographic algorithms to prove possession of the private key. So, anyone self-hosting a Linux server with LUKS FDE should strongly consider storing their private key(s) on an HST.

However, there is more than one way to do that. Hence the question in my OP.


RSS feed

Posts by modem_down, modem_down@thebrainbin.org

Comments by modem_down, modem_down@thebrainbin.org

Even if you can [exploit NFC] at 1m, thats close enough that it can just be stolen from you.

Stealing the HST should not give the user a false sense of security. Not so dangerous.

Silently exfiltrating the private key (or data for a replay attack), OTOH, would leave the user with a false sense of security. Dangerous.

your link to rfidgate appears broken

Wfm. Here’s an archive link.


Thanks! I didn’t know they were normally made of composites.

Looks like there are some ways (1, 2) to reuse/recycle the latter, but I agree wood would be better for this.


Aren’t turbine blades usually aluminium? How is wood more “recyclable” than that?


This coverage has a better headline: Trump blames Minnesota governor for cyberattacks against the state. Cites no evidence.

Funding restrictions and denialism, plus starting a war against a cyberattack-capable nation, made infrastructure attacks inevitable.

Security researchers have been publicly raising the alarm about SCADA vulnerabilities for 20+ years.


If it’s a server for self hosting you definitely don’t want anything that requires interaction at boot.

Depends on use-case. If you only plan to boot it when you’re physically present, it’s fine.


i believe a much better secure layer is something similar to what Novacustoms, Purism attempt to do: verify if somebody else not you try to access the laptop.

You’re thinking of Heads, which I agree is ideal for supported motherboards.



I can only see three ways to get FOSS firmware on your printer:

  1. If someone reverse engineers the firmware to create a FOSS version.
  2. If the Software Freedom Conservancy, who recently raised funds to tackle Bambu Labs’s license violations, finds a violation in BL firmware and succeeds in legally compelling BL to release the corresponding source code.
  3. If you sell your BL printer and replace it with one that already has FOSS firmware.

I read them before writing my OP. I’m still not sure what you’re getting at.

I would be grateful if you could say what you mean, instead of initiating an oblique guessing game.


Yes. Here are some common self-hosting scenarios:

  • Home server containing family files: scans, photos, device backups, …
  • Office server containing business files: sensitive documents, device backups, …
  • Web or email server containing websites, Fediverse instances, emails, etc

In all those cases, full disk encryption (FDE) is a sensible precaution to protect the data in case the server is physically stolen.

Linux is probably the most common OS kernel for self-hosting. On Linux, LUKS (Linux Unified Key Setup) is probably the best FDE system. It’s mature and reliable. But anyone self-hosting a Linux server with LUKS FDE is faced with the question of where to store the keys.

Hardware security tokens (HSTs) are widely considered a safer place for keys than SSDs, HDDs, or USB storage. They follow the smartcard principle: a private key can be written to an HST but not read from it (security vulnerabilities excepted). Instead, they implement cryptographic algorithms to prove possession of the private key. So, anyone self-hosting a Linux server with LUKS FDE should strongly consider storing their private key(s) on an HST.

However, there is more than one way to do that. Hence the question in my OP.


Which of the 4 recipes I posted are you referring to as “this”?


Thanks, please post relevant steps if you have specific recommendations.


Many thanks for this clarification - and for hosting The Brain Bin!


‘A “blatantly incompetent chud” and a “Kremlin asset” who plotted to “overthrow the government” on January 6, 2021.’


I’m sympathetic to many parts of the despair you shared. As for naming it as a whole:

Gnosticism? (Belief in a malevolent deity…)

Nihilism?

Fatalism?

Misanthropy?

As you said, though, “there is room for human connection even in a gulag”. Positives can be found in life. Look for the good bits. Play to your strengths. Help others when possible. Maybe look for charities or state agencies that can help you with the job-hunt? Stay healthy.


Great to see Europe leading the way here. If other jurisdictions pass similarly responsible legislation, then those jurisdictions will gain similar benefits.


The article has an interesting passage about how Irish aluminium is currently being sold to Russia for weapons, and the EU is (rightly) trying to stop this.


For plain text & Markdown, you don’t even need Collabora. Since 2019, NextCloud has a built-in collaborative text editor.


it’s the only way!

TBF I was trying to follow the docs, aber ich spreche kein Deutsch.


I overlooked this line from the docs:

Benötigt werden cmake, git, libgd und libusb - bei manchen Distributionen (z.B. Ubuntu) sind die Header-Files in separaten Paketen “libusb-dev” die ggf. noch nachinstalliert werden müssen.

I should have done sudo apt install libgd-dev libusb-1.0-0-dev before attempting compilation.