Profile pic

modem_down, modem_down@thebrainbin.org

Instance: thebrainbin.org
Joined: 1 week ago
Posts: 21
Comments: 36

RSS feed

Posts and Comments by modem_down, modem_down@thebrainbin.org

ChromeOS uses a Linux kernel, so one could say desktop Linux usage is >12%.



their setup required a couple large antennas that the victim would need to stand in between. Not impossible, but you’d notice with each side being half a meter away.

So yes, it’s a technical risk, but not one that I’d bother putting much effort into avoiding. And the being able to use the key via NFC is probably worth the risk.

This was my conclusion, too, but I didn’t want to prejudice the discussion. Thanks for corroborating.

IMO, using a Faraday pouch isn’t “much effort”, and is therefore worth doing if the HST is being carried in unfamiliar/non-secure locations.



Interesting point. Would realistic human-edited ("Photoshopped") content have to be labelled? That could be a good thing!

(Might cause embarrassment for fashion magazines unless they stop doing it.)


Even if you can [exploit NFC] at 1m, thats close enough that it can just be stolen from you.

Stealing the HST should not give the user a false sense of security. Not so dangerous.

Silently exfiltrating the private key (or data for a replay attack), OTOH, would leave the user with a false sense of security. Dangerous.

your link to rfidgate appears broken

Wfm. Here’s an archive link.


Thanks! I didn’t know they were normally made of composites.

Looks like there are some ways (1, 2) to reuse/recycle the latter, but I agree wood would be better for this.


Aren’t turbine blades usually aluminium? How is wood more “recyclable” than that?


This coverage has a better headline: Trump blames Minnesota governor for cyberattacks against the state. Cites no evidence.

Funding restrictions and denialism, plus starting a war against a cyberattack-capable nation, made infrastructure attacks inevitable.

Security researchers have been publicly raising the alarm about SCADA vulnerabilities for 20+ years.


If it’s a server for self hosting you definitely don’t want anything that requires interaction at boot.

Depends on use-case. If you only plan to boot it when you’re physically present, it’s fine.


i believe a much better secure layer is something similar to what Novacustoms, Purism attempt to do: verify if somebody else not you try to access the laptop.

You’re thinking of Heads, which I agree is ideal for supported motherboards.



RSS feed

Posts by modem_down, modem_down@thebrainbin.org

Comments by modem_down, modem_down@thebrainbin.org

Great to see Europe leading the way here. If other jurisdictions pass similarly responsible legislation, then those jurisdictions will gain similar benefits.


The article has an interesting passage about how Irish aluminium is currently being sold to Russia for weapons, and the EU is (rightly) trying to stop this.


For plain text & Markdown, you don’t even need Collabora. Since 2019, NextCloud has a built-in collaborative text editor.


it’s the only way!

TBF I was trying to follow the docs, aber ich spreche kein Deutsch.


I overlooked this line from the docs:

Benötigt werden cmake, git, libgd und libusb - bei manchen Distributionen (z.B. Ubuntu) sind die Header-Files in separaten Paketen “libusb-dev” die ggf. noch nachinstalliert werden müssen.

I should have done sudo apt install libgd-dev libusb-1.0-0-dev before attempting compilation.



@GrapheneOS@grapheneos.social

It would be trivially detected by widely distributed standard forensic software including the non-Premium variant of Cellebrite able to run on a laptop.

By “duress profile”, I mean that if user has enabled a “duress profile” feature in Settings, then entering the duress PIN would:

  1. Erase (the encryption key for) all profiles and storage outside the duress profile; then
  2. Unlock the duress profile.

So, how would forensic software detect that the unlocked profile is a duress profile?


@GrapheneOS@grapheneos.social everyone seems to be clamouring for the same thing: add “duress profile” to the roadmap. Keep up the good work.


On 18 Jan 2025, before Proton and Mullvad CEOs came out in support of the far right, Freedom of the Press Foundation (FPF) recommended:

  • Mullvad (Sweden)
  • Mozilla VPN* (USA/Sweden)
  • Proton VPN (Switzerland)
  • Tunnelbear (USA/Canada; owned by McAfee in USA)
  • IVPN (Gibraltar)
  • Windscribe (Canada)

I’ve crossed out the first three, since Mozilla VPN uses Mullvad, and Mullvad’s and Proton’s CEOs support extremists.

Nym is not on the list, so presumably didn’t meet FPF’s requirements.


if you follow a user their future posts will be sent to your server. We were talking about implementing a backfill option, but there is no eta yet

Thank you for explaining. That must indeed be the reason I couldn’t see those toots on Mbin.

so no guarantee it will be implemented at all. But since it is an annoying problem, maybe it will

Backfill would be great! Server capacity concerns notwithstanding.

In the meantime, clearer wording for the info banner would be an easy, helpful UX improvement:

  • Before subscribing: “This Fediverse profile is hosted on a different server than yours. If you, or another user on your server, were to subscribe to this profile, the profile’s subsequent posts would be displayed here. The profile’s older posts can be viewed on their server

  • After subscribing: “This Fediverse profile is hosted on a different server than yours. Now that you have subscribed, the profile’s future posts will be displayed here. The profile’s older posts can be viewed on their server



Thanks for your reply. I should have been clearer!

It’s not the banner that bothers me, it’s the fact that that microblog’s posts (toots) aren’t being displayed when viewed from Mbin!

Is there anything I can do in order to get those posts to propagate through to Mbin? Would I have to contact the admin for the Mbin instance hosting my account? Something else?



@Auster@thebrainbin.org

one thing you can do is to browse the subscribed microblog feed, https://thebrainbin.org/sub/microblog

Thanks, this is the kind of thing I hoped for!

you can also go to the general settings, https://thebrainbin.org/settings/general, and set “Homepage” as “Subscriptions”, and “Front page default view” as “Microblog”, so https://thebrainbin.org/ becomes a mirror of https://thebrainbin.org/sub/microblog

Excellent tip, thank you!


@Pamasich@kbin.earth thanks. Unforunately, I can’t see a globe icon or the word “All”.

Here’s a screenshot showing Edward Betts’s Mastodon profile as viewed from Mbin. As you can see, I follow his Mastodon account from my Mbin account.

I can see his posts on that page. But what I can’t figure out is how to see his posts, and posts from other Mastodon accounts I follow, in a single page or feed on Mbin.

Screenshot of Edward Betts's profile as viewed from Mbin.


I’m all for extra public transit, but 140mph on a bus (not a guided bus) sounds highly unsafe. 70mph is more realistic.

Kinetic energy rises with the square of velocity, so a 140mph bus would have 4x the KE of a 70mph bus.

  • 70mph crash: dangerous but should be survivable for seat-belted passengers.
  • 140mph crash: probably fatal to everyone on board and anyone in its path.