modem_down, modem_down@thebrainbin.org
Instance: thebrainbin.org
Joined: 1 week ago
Posts: 21
Comments: 46
"People are arseholes. They're just always gonna be that way."
Posts and Comments by modem_down, modem_down@thebrainbin.org
Comments by modem_down, modem_down@thebrainbin.org
I feel the same way, but can you explain how a VPN would help achieve that in the face of Google’s proposed developer verification scheme?
How would that help you?
The article says, “unverified apps will only be easily installable in the sanctioned countries where verification doesn’t exist.”
So even if you used a VPN to trick Google into thinking you live in a sanctioned country, you wouldn’t be able to distribute apps to those countries without breaking sanctions.
For 20+ years. Fixed in 2019.
it’d be like saying we should disarm Ukraine, ‘cause then Russia doesn’t have a reason to invade them
Putin’s All-Russia People’s Front’s policies toward Ukraine have many similarities to Netanyahu’s Likud party’s policies toward Gaza. Both sets of policies are tragic, causing many innocent people’s deaths.
Nevertheless, Ukraine and Gaza are different enough for one to reasonably reach different conclusions about how best peace can be achieved in each place:
- Ukraine’s weapons are protecting Ukraine against Russian attacks and invasion attempts. Therefore, it is in Ukraine’s interests to have them. Hamas’s weapons are not protecting Gaza against Israeli attacks or invasion. There is no obvious benefit from Hamas having them.
- Servant of the People, and Ukraine, do recognise Russia, and have not seriously proposed eliminating it. Hamas does not officially recognise Israel, and has seriously proposed eliminating it.
- Argentina, Australia, Canada, Costa Rica, Ecuador, Honduras, Israel, Japan, New Zealand, Paraguay, Philippines, Switzerland, Trinidad and Tobago, the UK, the USA, the EU, and the Organization of American States, all designate Hamas a terrorist organisation. This reduces the aid Gaza receives. They seem unlikely to reverse the designation unless Hamas disarms. None of them designate Servant of the People, or Ukraine, a terrorist organisation.
Those points lead me to believe Hamas should disarm.
I also believe countries giving aid to Israel should make it formally contingent on Israel withdrawing from Gaza and the West Bank, to pre-1967 borders, and recognising Palestinian statehood. However, it looks like the US is going to stop aid to Israel regardless.
Kdenlive is the top-ranked FOSS video editor on AlternativeTo.
I agree with that ranking, having also tried 5 or 6 of the other entries on the list.
Trust isn’t really the point. Everyone knows Israel and Hamas don’t trust each other. I’m more concerned with whether the violent conflict can be reduced, and a stable peace achieved.
Are Hamas’s arms doing Gaza any favours? Not that I can see.
AFAICT, if Hamas disarmed:
- Israel’s only(?) excuse for mass military action in Gaza would disappear.
- International support (already shaky) for Israeli military presence in Gaza would decrease.
- One or more of Australia, Canada, Costa Rica, Ecuador, Honduras, Israel, Japan, New Zealand, Paraguay, Trinidad and Tobago, the United Kingdom, the United States, or the European Union might end their designation of Hamas as a terrorist organisation, which could in turn increase the aid and other international support available to Gaza.
If you think I’m wrong, I’d be glad to know why.
Terrorism arises in defense to oppression.
Technical point: that isn’t exhaustively true. Terrorism can be, and sometimes is, committed against vulnerable parties by more privileged ones.
Progress report 1
I’m ruling out HMAC-SHA1, because:
- Plain vanilla HMAC-SHA1 uses a shared secret. I don’t want the PC/server to have a copy of the credential. May also be susceptible to MITM/relay attacks.
- Rolling-code HMAC-SHA1 only partially solves those problems.
- Encrypted rolling code HMAC-SHA1 solves those problems, but I haven’t found a reliable source for using it with LUKS.
If using
systemd, pick FIDO2:- Avoids flaws of HMAC-SHA1.
- Native support in
systemd, so “future-proof”. - Wider support than OpenPGP. More HST vendors to choose from, including cheaper options than NitroKey or Yubikey: useful if each sysadmin (or colleague, or relative) needs an HST.
- Compatible with QubesOS.
Otherwise, OpenPGP:
TBD: Clevis/Tang:
- Remote/network-based unlocking.
Thank you for this! That thread is helpful in itself, and also links to other relevant resources - including by Lennart Poettering (controversial guy, but the canonical source on systemd).
ChromeOS uses a Linux kernel, so one could say desktop Linux usage is >12%.
A young ‘un! Macintosh, surely.
their setup required a couple large antennas that the victim would need to stand in between. Not impossible, but you’d notice with each side being half a meter away.
So yes, it’s a technical risk, but not one that I’d bother putting much effort into avoiding. And the being able to use the key via NFC is probably worth the risk.
This was my conclusion, too, but I didn’t want to prejudice the discussion. Thanks for corroborating.
IMO, using a Faraday pouch isn’t “much effort”, and is therefore worth doing if the HST is being carried in unfamiliar/non-secure locations.
OS X (obsolete & unsupported since 2018) has more users than macOS?!
Also, where did you get those stats? https://gs.statcounter.com/os-market-share/all/north-america has different numbers to yours.
Link to stats: https://gs.statcounter.com/os-market-share/desktop/north-america
Interesting point. Would realistic human-edited ("Photoshopped") content have to be labelled? That could be a good thing!
(Might cause embarrassment for fashion magazines unless they stop doing it.)
Even if you can [exploit NFC] at 1m, thats close enough that it can just be stolen from you.
Stealing the HST should not give the user a false sense of security. Not so dangerous.
Silently exfiltrating the private key (or data for a replay attack), OTOH, would leave the user with a false sense of security. Dangerous.
your link to rfidgate appears broken
Wfm. Here’s an archive link.
Aren’t turbine blades usually aluminium? How is wood more “recyclable” than that?
This coverage has a better headline: Trump blames Minnesota governor for cyberattacks against the state. Cites no evidence.
Funding restrictions and denialism, plus starting a war against a cyberattack-capable nation, made infrastructure attacks inevitable.
Security researchers have been publicly raising the alarm about SCADA vulnerabilities for 20+ years.
If it’s a server for self hosting you definitely don’t want anything that requires interaction at boot.
Depends on use-case. If you only plan to boot it when you’re physically present, it’s fine.
RetroFed




Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?
Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283
Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?
Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283
Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?
Which approach do you think is better, and why?
Many thanks for this clarification - and for hosting The Brain Bin!
The "Tags" field in Mbin
When creating a new Mbin thread, there is a field called Tags.
Drought leaves Swiss border lake popular with tourists all but drained (reuters.com)
Lake Brenets, a long, winding lake on the Swiss-French border, is all but drained and has been unnavigable for more than a week amid a prolonged drought that has hit waterways across Europe.
‘A “blatantly incompetent chud” and a “Kremlin asset” who plotted to “overthrow the government” on January 6, 2021.’
I’m sympathetic to many parts of the despair you shared. As for naming it as a whole:
Gnosticism? (Belief in a malevolent deity…)
Nihilism?
Fatalism?
Misanthropy?
As you said, though, “there is room for human connection even in a gulag”. Positives can be found in life. Look for the good bits. Play to your strengths. Help others when possible. Maybe look for charities or state agencies that can help you with the job-hunt? Stay healthy.
Great to see Europe leading the way here. If other jurisdictions pass similarly responsible legislation, then those jurisdictions will gain similar benefits.
The article has an interesting passage about how Irish aluminium is currently being sold to Russia for weapons, and the EU is (rightly) trying to stop this.
For plain text & Markdown, you don’t even need Collabora. Since 2019, NextCloud has a built-in collaborative text editor.
it’s the only way!
TBF I was trying to follow the docs, aber ich spreche kein Deutsch.
I overlooked this line from the docs:
I should have done
sudo apt install libgd-dev libusb-1.0-0-devbefore attempting compilation.Ptouch-print compile error: Could not find GD library
Trying to install ptouch-print:
@EUCommission@ec.social-network.europa.eu, what’s up with this? It doesn’t seem in any way justifiable.
@GrapheneOS@grapheneos.social
By “duress profile”, I mean that if user has enabled a “duress profile” feature in Settings, then entering the duress PIN would:
So, how would forensic software detect that the unlocked profile is a duress profile?
@GrapheneOS@grapheneos.social everyone seems to be clamouring for the same thing: add “duress profile” to the roadmap. Keep up the good work.
On 18 Jan 2025, before Proton and Mullvad CEOs came out in support of the far right, Freedom of the Press Foundation (FPF) recommended:
Mullvad (Sweden)Mozilla VPN* (USA/Sweden)Proton VPN (Switzerland)I’ve crossed out the first three, since Mozilla VPN uses Mullvad, and Mullvad’s and Proton’s CEOs support extremists.
Nym is not on the list, so presumably didn’t meet FPF’s requirements.
Thank you for explaining. That must indeed be the reason I couldn’t see those toots on Mbin.
Backfill would be great! Server capacity concerns notwithstanding.
In the meantime, clearer wording for the info banner would be an easy, helpful UX improvement:
Before subscribing: “This Fediverse profile is hosted on a different server than yours. If you, or another user on your server, were to subscribe to this profile, the profile’s subsequent posts would be displayed here. The profile’s older posts can be viewed on their server”
After subscribing: “This Fediverse profile is hosted on a different server than yours. Now that you have subscribed, the profile’s future posts will be displayed here. The profile’s older posts can be viewed on their server”
https://alternativeto.net/software/find-my-iphone/?license=opensource