HN user

66fm472tjy7

162 karma
Posts0
Comments42
View on HN
No posts found.

I do love the cloud version of passkeys, but I also have a backup YubiKey

How does this work, exactly? Does you cloud password/key manager allow syncing to the YubiKey?

Or do you register a second passkey that you store on the YubiKey whenever you create a passkey?

If it is the latter, do all services that allow passkey authentication also allow registering multiple passkeys? How many?

could do two backup YubiKeys [...] keep one YubiKey in a safe deposit box

If you register a new passkey on the primary, do you then have to take the backup YubiKey out of the safe deposit box to put it on it as well?

I haven't seen this kind of question answered when sites prompt me to use passkeys instead of passwords.

It seems to me like those who like passkeys/consider them simple are those who entrust all their credentials to proprietary cloud software vendors that sync them to all their devices.

Those of us who are not comfortable with that and want to keep our credentials offline and sync/backup them ourselves have questions about how the registration/backup/sharing flows work exactly.

I see this as part of a trend together with remote attestation, age verification, CSAM scanning, restricting sideloading, etc that will lead to most interactions over the internet only being allowed if big tech and/or government can verify the participants, the contents, and the hardware and software used.

Even among techies, many support these developments, so it is just a matter of time before we have no choice but to join the former group.

Occasionally occurring issues are so annoying. I lived with these issues for years before becoming able to reliably reproduce them by accident and thus making a good guess on the cause:

My system would randomly freeze for ~5 seconds, usually while gaming and having a video in the browser running a the same time. Then, it would reliably happen in Titanfall 2 and I noticed there were always AHCI errors in the Windows logs at the same time so I switched to an NVMe drive.

The system would also shut down occasionally (~ once every few hours) in certain games only. Then, I managed to reproduce it 100% of the time by casting lightning magic in Oblivion Remastered. I had to switch out my PSU, the old one probably couldn't handle some transient load spike, even though it was a Seasonic Prime Ultra Titanium.

  Put an expiration date on the storefront and make it clear that your software is not guaranteed to continue working after date X
False, it says[0]
  providing reasonable means to continue functioning of said videogames without the involvement from the side of the publisher
It MUST be possible to continue playing the game using reasonable means. It is not sufficient to declare an EOL date.
  Have your server source code (stripped down of proprietary stuff) ready for public release at EoL
This would only be sufficient if the proprietary dependencies are reasonable easy to acquire.
  Allow customers to reverse engineer the binaries and communication protocol after EoL
I don't think this reverse engineering could currently be disallowed in the EU, so it would not be affected by the initiative.
  Package dedicated server binaries with the game
True, it would meet the requirements of the initiative, but it would be sufficient to provide the server after EOL.

----

[0] https://citizens-initiative.europa.eu/initiatives/details/20...

puts tinfoil hat on

Ensuring that a critical mass of people use remote attestation[0] capable devices.

The next step is a browser API[1] for this so that content owners can exclude devices capable of storing the content, or stripping out ads/tracking, etc.

Sure, there will be a cat-and-mouse game where people will figure out how to fake the attestation for some period of time, but general computation[2] is probably on the way out.

----

[0] https://en.wikipedia.org/w/index.php?title=Trusted_Computing...

[1] https://news.ycombinator.com/item?id=36817305

[2] https://www.youtube.com/watch?v=HUEvRyemKSg

I cannot confirm this behavior. With a router running FRITZ!OS:7.57 configured to use Google's DNS (in the router only) I get the following on Windows 10

  > nslookup google.com
  Server:  fritz.box
  Address:  fd00::[redacted]

  Non-authoritative answer:
  Name:    google.com
  Addresses:  2a00:1450:4001:828::200e
            142.250.181.238
Update: the connection does have the DNS suffix, so according to the superuser answer linked in OP (which is the first result when looking up what a DNS suffix is), it should get appended to lookups on windows, but it looks like it isn't in my case.
  > ipconfig
  [...]
  Connection-specific DNS Suffix  . : fritz.box

A company should have every right to deny service

Plenty of utility companies are already being forced to provide service. As the EDPB opinion says, a lot of big tech is

decisive for participation in social life or access to professional networks, even more so in the presence of lock-in or network effects

Untargeted advertising pays 90+% less than targeted advertising

I don't think that such a large difference is rational. "Untargeted" advertising can still be based on the content being viewed, just not on surveilling the viewer.

If they lose money by serving a user content because they denied targeted advertising, they should be able to deny them service or have them pay up.

As I understand it the opinion does not categorically rule this out

Controllers should ensure that the fee is not such as to inhibit data subjects from making a genuine choice

That is why NOYB also focuses[0] on the fact the the fee is disproportionate:

The current average revenue for programmatic advertising in the EU is € [1.41] per user - across all websites per month [...] visiting the top 100 websites can already cost more than € [1500] per year if you do not consent to tracking

---

[0] https://noyb.eu/en/statement-edpb-pay-or-okay-opinion, https://weis2019.econinfosec.org/wp-content/uploads/sites/6/...

I feel like commenters in this thread are talking past each other.

Some are saying "of course sites are still tracking you in incognito!", but is is unclear to me what they mean by this. I see the following interpretations:

1. Sites can still use local storage so they can track you for the duration of your incognito session, but they cannot connect this tracking to your regular session or other incognito sessions as incognito sessions start with empty local storage and discard it at the end of the session.

2. Sites do not rely on local storage, instead using fingerprinting via a combination of IP, HTTP headers, information they can query via JS, etc., so incognito has no effect on sites' ability to track you.

3. Google has special privileges in Chrome to track you when you are incognito.

It is possible. Don't give them money and only provide basic shelter

In the EU you would have to reduce your welfare state to that level for your own citizens as well. The ECJ says[0]:

It follows that the level of social security benefits paid to refugees by the Member State which granted that status, whether temporary or permanent, must be the same as that offered to nationals of that Member State

[0] https://curia.europa.eu/juris/document/document.jsf?text=&do...

In my experience, people are sensitive to different aspects/weaknesses in game graphics. For instance, I don't really notice any difference between 60 and 120 FPS. I am also not very bothered by traversal stutter.

What I AM sensitive to however, is temporal instability - it just draws my attention and hurts immersion. Here DLSS makes a huge difference, as shown here[0].

Therefore it is sad that Bethesda chose[1] to deliver worse than possible image quality for 80%+ of their PC customers[2].

----

[0] https://youtu.be/ciOFwUBTs5s?feature=shared&t=336

[1] https://news.ycombinator.com/item?id=37452149

[2] https://archive.ph/mqPLK, nvidia has 75% market share here, but you have to look at the higher end parts only and exclude Intel as Starfield does not run at all on their GPUs[3]

[3] https://in.ign.com/starfield/193351/news/starfield-intel-fin...

I am not optimistic that the de-facto end of general computation can be prevented, or that there will even be noteworthy opposition.

There are so many powerful interests that stand to gain from preventing e.g. ad-blocking and content capture. Thanks to Windows 11 requiring TPM, it is just a matter of time until hardware support for remote attestation is ubiquitous even on desktop computers.

Meanwhile, our (including myself) attention is (perhaps justifiably to some extent) on the latest news about $EXISTENTIAL_THREAT and how $THE_OTHER_SIDE did $EVIL_THING fed to us by the algorithm. Organizations that used to effectively fight threats to freedom like this (FSF, pirate parties, CCC, EFF, etc) have lost a lot of their support/influence and clarity of purpose over the last decade.

Everything should be a drop-in replacement

This is not true for many applications. Due to the removal of many APIs from the JDK with Java 9, I needed the following dependency artifactIds to be able to move a JEE application with SOAP web services to Java 11: jaxb-api, jaxb-core, jaxb-runtime, istack-commons-runtime, jboss-jaxws-api_2.2_spec, glassfish-corba-omgapi, jboss-annotations-api_1.2_spec, activation, jboss-saaj-api_1.3_spec, saaj-impl, stax-ex, jsr181-api, txw2.

Many of these spec API/implementations are provided by different artifacts that are incompatible with each other. Some I only discovered when something failed at runtime as they perform implementation lookups and you don't get compile errors.

Additionally, many of the Maven plugins we used no longer worked and our application server failed to start.

We need this in our corporate client device fleet to counter specific threats

Can you please expand on what you verify via remote attestation and against which attack vectors this protects you?

Does this protect you against the usual attack vectors of your employees logging in on phishing sites, downloading malware, running office macros etc? Stealing your data usually does not need any root/kernel access.

In the first iteration of using confirms, we did not have the outbox but only logged how long it took to get the confirmation. After 3 seconds, we would throw out the expected confirmation. If a confirmation took longer than that, we would log that we received an unknown confirmation.

We hoped it would be fast enough that we can just wait for the confirmation before committing the transaction.

The official documentation says

This means that under a constant load, latency for basic.ack can reach a few hundred milliseconds

I never did statistics, just looked at the log. IIRC most were acceptable but > 3s occurred frequently enough (and we even had instances of messages never being confirmed, IIRC) that we abandoned that plan.

We considered using Debezium[0], but decided on the current solution as it could be solved entirely with the current services and infrastructure whereas Debezium would have required us to deploy (writing this from memory so this might be inaccurate/incomplete) Kafka, Zookeeper, and a connector service.

[0] https://debezium.io/

We use RMQ for most of our asynchronous processing. In most cases, we get a HTTP call and publish a message to the RMQ after committing the DB transaction, then we send the response to the HTTP client.

We found out the hard way that RMQ does not behave like a transactional DB. Just because publishing worked does not mean the message will be delivered.

Our solution is to also write the message into an outbox table in the DB. We then publish the message using confirms[0]. RMQ asynchronously sends us a confirmation when it has really persisted the message. We then delete the outbox entry. If we do not receive the confirmation in time, a timer will re-publish the message.

Therefore I disagree with the suggestion of using a library wrapping the native RMQ one. We are using spring-amqp and this made it harder to understand what is going on. In the end, for a large project you will have to understand nuances of RMQ (and other infrastructure you are using). Using a leaky abstraction over it means you now have to understand both the underlying product and the abstraction.

[0] https://www.rabbitmq.com/confirms.html#publisher-confirms

and there's absolutely nothing that can be done to stop them

Congress could pass laws saying that the EPA can regulate greenhouse gas emissions, that states cannot forbid abortions, etc.

If you think that these rulings are not plausible interpretations of the law, Congress can even define the size of the court[0]. They could pack the court with judges who will interpret the law in their favor.

It is my understanding that the Democratic Party that holds the majority in both chambers claims to be in favor of these policies, so why aren't they taking action?

[0] https://en.wikipedia.org/wiki/Judiciary_Act_of_1869

Once the vast majority of devices are remote attestation capable (Windows 11 requiring TPM will accelerate this trend), content providers may refuse to serve you unless you attest that you are running a walled-garden OS that won't allow you to ad-block, capture content, run any sort of proxy server, etc.

At some point, even ISPs might require remote attestation to allow you to connect your device to the internet. The IETF is already working on standards for the attestation of network devices[0][1].

I speculate that there will temporarily (perhaps similarly to iOS jailbreaking, which is not available at this time for the newest devices/iOS version[2]) be exploits allowing you fool the attestation by e.g. redirecting it to another device as the author suggests, but the end effect will be that vast majority of people will be effectively confined to a walled garden and even determined hobbyists will only be able to use their general computation capable devices to access all content (or even connect them to the internet) some of the time.

[0] https://archive.fo/uQULm

[1] https://datatracker.ietf.org/doc/draft-ietf-rats-tpm-based-n...

[2] https://en.wikipedia.org/w/index.php?title=IOS_jailbreaking&...

Log4j maintainers have been working sleeplessly on mitigation measures; fixes, docs, CVE, replies to inquiries, etc.

They've been doing a poor job of communicating. Considering the attention this issue is getting, they should have a prominent notice on their project page[0] about it like the one Logback[1] has telling people that they are not affected.

Furthermore, even their post about the issue[2] still fails to clarify many details like

* are people using newer JDK versions safe, like one commenter in this very thread assumed[3] ?

* does it only affect the format string and not parameters as many [falsely] claimed when the news started making the rounds ?

* what should people trying to block exploitation on a firewall level look for ?

for a feature we all dislike yet needed to keep due to backward compatibility concerns.

They have not recognized the security risk posed by what is effectively an expression language interacting with user-submitted data. Java projects used in server-side templating like OGNL, JSP and JSF implementations, Spring keep having security vulnerabilities with this even after 20+ years. It is an effectively impossible task to get this 100% secure.

The ridicule Log4j is getting serves a purpose beyond fun: it lets people know that the project's maintainers are not up to the task and another logging library should be used instead, as there might be more issue still undiscovered or added in the future.

[0] https://archive.ph/ZhjWO

[1] https://archive.fo/QkzIy

[2] https://archive.fo/NvjKP

[3] https://archive.fo/5cNtw

I would have preferred giving lower priority in hospitals to voluntarily unvaccinated persons seeking COVID treatment. That would require no violation of personal freedoms and avoid the great economic cost of implementing a lockdown at the start of the touristic winter season at the cost of letting these people suffer the consequences of their belief that the vaccine is more dangerous than the disease.

  those feature are either horrible
I speculate that most users of languages that have these features (Kotlin has all of them) would be unhappy if you took them away.
  algebraic data types and pattern-matching -- will lead to better development practices, rather than making it easier to work with inferior ones.
I am not arguing against those features, but the ones I asked for seem easier to implement by comparison as they are already in other successful JVM languages. Furthermore, they are far more frequently useful for my use case of web services storing, transforming and moving data around, often without caring too much about their semantics. I speculate that a large portion -probably a majority- of JEE/Spring devs are in the same position.

I am disturbed by how universally true you seem to consider your positions - as if there were no cases in which mutability is preferable to immutability (even if that is sometimes just due to the way some ORM or serialization library works).

If these features are such bad ideas there should be plenty of stories of Kotlin/C# devs cursing the language for providing them with these footguns.

Having a JDK dev respond like this only strengthens my argument that cageface has no reason to fear that Kotlin will lose steam - Java has different priorities. There is nothing wrong with that, but more developers who want these features should be aware that they will not be getting them from future Java versions.

I don't think this is going to happen with Brian Goetz as language architect. He refuses to add many features that would address everyday pain points such as:

* null safe navigation operator

* properties

* mutable records

* a way to ignore checked exceptions (or at least having the stream API take functional interfaces that can throw exceptions)

* adding functional methods like .filter()/.map() directly to collections instead of having to .stream().map(..).collect(toList())

Now that every first world country has vaccine doses in excess of demand, I think a better alternative to all these restrictions would be to just give the voluntarily unvaccinated a lower priority during triage if they need a hospital bed for a COVID infection.

Of course, efforts should be made to expand capacity (my government was unfortunately too incompetent train more medical staff for this since the start of the pandemic).

Obviously, these people think that the disease is less dangerous than the vaccine. They should bear the consequences of their choice. Let's not endanger other's lives/prolong their suffering (surgeries are already being delayed again in my country).

I realize this could be a slippery slope, e.g. someone could argue that we should give lower priority to smokers, obese, or addicted people. However, the vaccine does not require any lifestyle changes and at this point it has already been given to billions and has shown a much lower rate of severe side effects than the disease.

A thing that still does not work well is fluid, resizable remote desktop in combination with fractional DPI scaling. X2GO enables the remoting part but does not work modern DEs[0]. Even then, there are bugs when remoting[1].

Also, MS Teams installed from the Ubuntu software store on Ubuntu 21.04 does not support screen sharing. You have to switch from Wayland to X11 to enable it. Even then it is missing features like selecting a single window to share, allowing others to highlight on your screen. It does not matter whether this is Microsoft's fault - Teams is a must have in many organizations and Canonical promotes the app in their store.

[0] https://wiki.x2go.org/doku.php/doc:de-compat

[1] What I have personally encountered: on KDE drkonqi crashes all the time when remote, on GTK-based DEs I get color management prompts and gnome-keyring breaks on local sessions - even worse, it seems to block for minutes then tell the caller that you don't have credentials instead of exiting with an error.

One of their most impressive features is how many product attributes they track and allow you to filter for. E.g. for mainboards you can filter for support for all generations of Ryzen CPU + at least M.2 slots + BIOS flashback (allows you to do BIOS updates without a CPU or RAM) + at least one USB-C + built in IO shield + at least 12 VRM phases + WiFi 6 + in stock: https://geizhals.eu/?cat=mbam4&v=k&hloc=at&hloc=de&hloc=pl&h...