modem_down, modem_down@thebrainbin.org
Instance: thebrainbin.org
Joined: 1 week ago
Posts: 21
Comments: 42
Posts and Comments by modem_down, modem_down@thebrainbin.org
Comments by modem_down, modem_down@thebrainbin.org
Kdenlive is the top-ranked FOSS video editor on AlternativeTo.
I agree with that ranking, having also tried 5 or 6 of the other entries on the list.
Trust isn’t really the point. Everyone knows Israel and Hamas don’t trust each other. I’m more concerned with whether the violent conflict can be reduced, and a stable peace achieved.
Are Hamas’s arms doing Gaza any favours? Not that I can see.
AFAICT, if Hamas disarmed:
- Israel’s only(?) excuse for mass military action in Gaza would disappear.
- International support (already shaky) for Israeli military presence in Gaza would decrease.
- One or more of Australia, Canada, Costa Rica, Ecuador, Honduras, Israel, Japan, New Zealand, Paraguay, Trinidad and Tobago, the United Kingdom, the United States, or the European Union might end their designation of Hamas as a terrorist organisation, which could in turn increase the aid and other international support available to Gaza.
If you think I’m wrong, I’d be glad to know why.
Terrorism arises in defense to oppression.
Technical point: that isn’t exhaustively true. Terrorism can be, and sometimes is, committed against vulnerable parties by more privileged ones.
Progress report 1
I’m ruling out HMAC-SHA1, because:
- Plain vanilla HMAC-SHA1 uses a shared secret. I don’t want the PC/server to have a copy of the credential. May also be susceptible to MITM/relay attacks.
- Rolling-code HMAC-SHA1 only partially solves those problems.
- Encrypted rolling code HMAC-SHA1 solves those problems, but I haven’t found a reliable source for using it with LUKS.
If using
systemd, pick FIDO2:- Avoids flaws of HMAC-SHA1.
- Native support in
systemd, so “future-proof”. - Wider support than OpenPGP. More HST vendors to choose from, including cheaper options than NitroKey or Yubikey: useful if each sysadmin (or colleague, or relative) needs an HST.
- Compatible with QubesOS.
Otherwise, OpenPGP:
TBD: Clevis/Tang:
- Remote/network-based unlocking.
Thank you for this! That thread is helpful in itself, and also links to other relevant resources - including by Lennart Poettering (controversial guy, but the canonical source on systemd).
ChromeOS uses a Linux kernel, so one could say desktop Linux usage is >12%.
A young ‘un! Macintosh, surely.
their setup required a couple large antennas that the victim would need to stand in between. Not impossible, but you’d notice with each side being half a meter away.
So yes, it’s a technical risk, but not one that I’d bother putting much effort into avoiding. And the being able to use the key via NFC is probably worth the risk.
This was my conclusion, too, but I didn’t want to prejudice the discussion. Thanks for corroborating.
IMO, using a Faraday pouch isn’t “much effort”, and is therefore worth doing if the HST is being carried in unfamiliar/non-secure locations.
OS X (obsolete & unsupported since 2018) has more users than macOS?!
Also, where did you get those stats? https://gs.statcounter.com/os-market-share/all/north-america has different numbers to yours.
Link to stats: https://gs.statcounter.com/os-market-share/desktop/north-america
Interesting point. Would realistic human-edited ("Photoshopped") content have to be labelled? That could be a good thing!
(Might cause embarrassment for fashion magazines unless they stop doing it.)
Even if you can [exploit NFC] at 1m, thats close enough that it can just be stolen from you.
Stealing the HST should not give the user a false sense of security. Not so dangerous.
Silently exfiltrating the private key (or data for a replay attack), OTOH, would leave the user with a false sense of security. Dangerous.
your link to rfidgate appears broken
Wfm. Here’s an archive link.
Aren’t turbine blades usually aluminium? How is wood more “recyclable” than that?
This coverage has a better headline: Trump blames Minnesota governor for cyberattacks against the state. Cites no evidence.
Funding restrictions and denialism, plus starting a war against a cyberattack-capable nation, made infrastructure attacks inevitable.
Security researchers have been publicly raising the alarm about SCADA vulnerabilities for 20+ years.
If it’s a server for self hosting you definitely don’t want anything that requires interaction at boot.
Depends on use-case. If you only plan to boot it when you’re physically present, it’s fine.
i believe a much better secure layer is something similar to what Novacustoms, Purism attempt to do: verify if somebody else not you try to access the laptop.
You’re thinking of Heads, which I agree is ideal for supported motherboards.
tang
Thanks. TIL about Clevis/Tang.
I can only see three ways to get FOSS firmware on your printer:
- If someone reverse engineers the firmware to create a FOSS version.
- If the Software Freedom Conservancy, who recently raised funds to tackle Bambu Labs’s license violations, finds a violation in BL firmware and succeeds in legally compelling BL to release the corresponding source code.
- If you sell your BL printer and replace it with one that already has FOSS firmware.
I read them before writing my OP. I’m still not sure what you’re getting at.
I would be grateful if you could say what you mean, instead of initiating an oblique guessing game.
RetroFed




Kdenlive is the top-ranked FOSS video editor on AlternativeTo.
I agree with that ranking, having also tried 5 or 6 of the other entries on the list.
Trust isn’t really the point. Everyone knows Israel and Hamas don’t trust each other. I’m more concerned with whether the violent conflict can be reduced, and a stable peace achieved.
Are Hamas’s arms doing Gaza any favours? Not that I can see.
AFAICT, if Hamas disarmed:
If you think I’m wrong, I’d be glad to know why.
Technical point: that isn’t exhaustively true. Terrorism can be, and sometimes is, committed against vulnerable parties by more privileged ones.
Progress report 1
I’m ruling out HMAC-SHA1, because:
If using
systemd, pick FIDO2:systemd, so “future-proof”.Otherwise, OpenPGP:
smartcard-key-luksseems unmaintained on GitHub and on GitLab.TBD: Clevis/Tang:
Thank you for this! That thread is helpful in itself, and also links to other relevant resources - including by Lennart Poettering (controversial guy, but the canonical source on systemd).
ChromeOS uses a Linux kernel, so one could say desktop Linux usage is >12%.
A young ‘un! Macintosh, surely.
This was my conclusion, too, but I didn’t want to prejudice the discussion. Thanks for corroborating.
IMO, using a Faraday pouch isn’t “much effort”, and is therefore worth doing if the HST is being carried in unfamiliar/non-secure locations.
German startup to scale up fully recyclable wind turbine blades (recyclingportal.eu)
Crossposted from https://feddit.org/post/33469423
OS X (obsolete & unsupported since 2018) has more users than macOS?!
Also, where did you get those stats? https://gs.statcounter.com/os-market-share/all/north-america has different numbers to yours.Link to stats: https://gs.statcounter.com/os-market-share/desktop/north-america
Interesting point. Would realistic human-edited ("Photoshopped") content have to be labelled? That could be a good thing!
(Might cause embarrassment for fashion magazines unless they stop doing it.)
Stealing the HST should not give the user a false sense of security. Not so dangerous.
Silently exfiltrating the private key (or data for a replay attack), OTOH, would leave the user with a false sense of security. Dangerous.
Wfm. Here’s an archive link.
Are NFC hardware tokens (Yubikey, NitroKey) less secure than USB-only ones? If so, how to mitigate?
Yubikey and NitroKey offer NFC and non-NFC versions of their flagship hardware security tokens (HSTs).
Full text of the roadmap for Hamas to disarm and Israel to leave Gaza (apnews.com)
In your view, does this roadmap increase or decrease the likelihood of a peaceful outcome - and why?
Thanks! I didn’t know they were normally made of composites.
Looks like there are some ways (1, 2) to reuse/recycle the latter, but I agree wood would be better for this.
Aren’t turbine blades usually aluminium? How is wood more “recyclable” than that?
AI labels to be compulsory on authentic-looking content under EU rules (theguardian.com)
Crossposted from https://piefed.world/c/technology/p/1300905/ai-labels-to-be-compulsory-on-authentic-looking-content-under-eu-rules
AI labels to be compulsory on authentic-looking content under EU rules (theguardian.com)
Crossposted from https://piefed.world/c/technology/p/1300905/ai-labels-to-be-compulsory-on-authentic-looking-content-under-eu-rules
AI labels to be compulsory on authentic-looking content under EU rules (theguardian.com)
Crossposted from https://piefed.world/c/technology/p/1300905/ai-labels-to-be-compulsory-on-authentic-looking-content-under-eu-rules