More of a BBS, I'd argue. Replace dialing with a modem with SSH, and otherwise the analogy holds decentky well.
HN user
T3OU-736
I thought he is with you
Of the varied reasons for not using them, can you share yours?
D'oh. Typo. OFFPAD not OFFOAD.
That is what I was thinking, too, but rather than the keyfile being an actual file, it is, instead, on the USB-C HW token. So, to decrypt your KeePassXC db, you'd need the physical token to do the decryption, and ask it to be, effectively, an HSM.
https://keepass.info/help/kb/yubikey.html talks of different ways of doing something like that, but I've not played with it yet.
Another option is just to store passkeys natively on the token itself?
There's a [DEFCon 33 talk](https://youtu.be/xdl08cPDgtE?si=SwZ-87jzDbNeP1Mx) on this, too.
I... Am not sure how I feel about it. On tech merits, this absolutely makes sense - the tech is slinging private keys around, and their secure storage is a hard problem.
On the practical merits - maybe? Token-backed decryption of the password manager's database seems like a devent solution? But does this happen? Is there a password manager which uses the public key derived from FIDO2 token's on-chip private key to decrypt the database?
On-token storage is limited (though 100 passkeys on a YK 5 Nano is fairly generous) - but what if we just used the YK as the "Private key is here and ONLY here" setup?
I kinda like the OFFOAD+ design - it promises to show me to where I am authenticating. With origin binding should be a nobrainer, but still, it speaks to me.
Not quite filesystem navigation, but SGI IRIX's Performance CoPilot software had an IrixGL (OpenGL's precursor) UI for monitoring things like memory state, CPU/storage loads, etc.
The PCP is absolutely nowhere _near_ the graphical wizardry of the state of this app, and the overlay of executing code atop a given directory structure is quite beautiful (practicality be damned), but I can see the inspiration.
I do wonder if, on a modern Linux system with SELinix, this model (code accessing a directory) is actually closer to viable? SELinux's contexts/labels for subjects overlaying with the same for objects can, I imagine, be visualized. The normal access patterns would be way too overwhelming, I think - but exceptions/policy violations? :ponder:
SGI's HW also had ccNUMA (cache-coherent Non-Uniform Memory Access), which, given the latencies possible in systems _physically_ spanning entire rooms, was quite a feat.
The IRIX OS even had functionality to migrate kobs and theor working memory closer to each other to lower the latency of access.
We see echoes of this when companies like high-frequency traders pay attention to motherboard layouts and co-locate and pin the PTS (proprietary trading systems) processes to specific cores based on which DIMMs are on which side of the memory controller.
```you should know the Uvalde school shooter was a minor but he managed to buy the guns legally from a gun shop on credit!```
That does not appear to be true. The investagiom reporting shows that the shooter bought the guns after he turned 18 - the legal age to purchase them (long guns, aka rifles - different from pistols) in the state of Texas.
Buying things on credit seems like a reasonable way to do business in general - are you suggesting that all deadly weapons should be sold for cash to increase the difficulty of legally acquiring them and so lowering the frequency of mass shootings?
```… the pipe was so fast, you could only pcap if you had a SCSI hard drive!```
This is why NSA asked for (and got from SGI) a guranteed rate I/O API - to make sure that whstever the signal intelkigence platform sensors captured could be written to storage.
(Not disagreeing that this is a dupe), but this is The Verge's coverage of Lumafield's findings.
Not sure if there is any additional value in the re-coverage, though it does feel like the message is important enough to be spread, and I suspect there is more readers of The Verge than the original source.
Distributing (and controlling) the necessary decryption seems like a helaciously difficult challenge for general/commercial aviation. Who are the authorized recievers of the ebcrypted data? How do we revoke access as time goes on? How do we handle normal key rotation (so that the adversary can't have unlimited time to crack/bruteforce the current keys)?
(Not my core field, so this is SWAG-ish): There is also a separate but equally important problem of signal vs noise - isolating the signal for decryption. Doable, but fairly costly to implement, and far more brittle than I suspect would be acceptable.
It feels like we have disparate mental models for what is happening.
Mine was that the noise generation was part of the adversary's actions (as is the presence of the drones themselves).
Are you suggesting that the noise (+encrypted data) is part of the airport's standard procedures, and authorized users pick out (and decrypt) the data, and everything else (like Command & Control) of adversarial devices is overwhelmed by the overall noise?
Would your signal eminate from the drones, or a dedicated platform?
Against the drones, that would be difficult to prevent, but the limitations imposed by the transmitter gear (size, weight, inverse square law of area being jammed) would probably limit the impact.
The dedicated platform would be located via signal strength analysis and likely physically destroyed.
Huh. So, making cell site simulators be more useful than just for doing wholesale surveillance?
Wonder if the goal is as wholesome (tool for rescue) as it seems, or there is some sort of commodization of this sort of tools being done, and so should not be subject to any special restrictions or regulation.
In the US, the terminology tends to split into "fired" (implies "for valid reasons") vs "laid off" (implies "position was terminsted, this was not about the employee or their qualities and performance").
Consider writing an actual letter to the CEO instead. I suspect it will more likely stand out.
(This is a bit of a continuation of what `whiteandnerdy` posted in a different comment) - the distributed trust model seems to assume that the governments won't cooperate to seize different necessary distributed things across borders. I am reasonably sure that this is not an assumption which holds true - plenty of multi-national raids on criminals happen (and classifying people who hold decryption bits to stuff governments want as being criminals is a fairly trivial task).
If you stop making progress, start back at step 1 because iCloud Drive frequently gets stalled for some reason or another
It feels utterly wrong that there is not an Event Log entry (I am not an iCloud user, so cannot easily check) or some other, better log in place.
The snide cynic in me wants to reach for the whole "Apple does not expose this sort of detailed data to the user", but for backups, that seems important enough for that to not be the case?
Another text editor from the makers of Edlin. (Sorry, could not help myself!)
Interesting.
Hit the front page (Android, Firefox Focus) Have a feed. Tried to follow https://atac.seraum.com/event/did-16-billion-login-credentia...
Got:
``` 404 - Not Found
The event you are looking for (did-16-billion-login-credentials-leaked) does not exist.
Return to the Live Feed
```
Hitting back gave a header, but instead of the feed items, I see `Could not load the feed. Please try again later.`
Looks like a neat tool, and a valuable addition to the network bandwidth/latency/performance toolkit.
(Admittedly, it has been a while since I have done it) It did feel odd that there was not a mention of time discipline for the client/server and the impact on finer-grained stats. Perhaps, at least, mention that NTP (or, ideally, PTP, but that is a fair bit more involved) is strongly recommended to be running and stable (NTP's own jitter being low)?
The relation between GutHub creds being compromised and persional (Social Security) numbers being accessed is not obvious, and feels weird.
Were SSNs in a GH repo?
Credentials for GH access grabted access to the database with SSNs in it?
Those both seem, in their own right, quite bad.
Another aspect of supporting hugely dispersed CPUs a-la SGI Origin 3000 series (say, Origin 3400) is the support for performance telemetry of the attendant interconnecting pieces.
On SGI, the CrayLink HW had perfomance counters visible via the Performance CoPilot (nee PCP).
On Linux, NUMA arch has similar things (numastat, Intel's PCM, other tools). Depending on the workload, it may matter, but if the OS/tooling does not expose the counters, it isn't even possible to quantify the impact.
SGI's IRIX, due to the sheer physical size of their larger ccNUMA systems (AFAIK, AMD's NUMA is from SGI's ccNUMA), had the option to auto-migrate the workloads when certain CPU to working memory latency thresholds were reached.
Aha. Very good point. SW self-reporting requires buy-in, though, which seems like a pretty high barrier.
I am very much hoping the effort succeeds, but I am also mindful of the fact that the site to which I have linked is more successful by virtue of having better coverage.
Htm. So, how does this compare, and/or is different from https://endoflife.date?
I am assuming/hoping this incorporates something like an nVidia Jetson.
I am, however, quite pessimistic, that this NAS stays ub-enshittificated. (Un-shittified?).
A neat possibility would be to (notwithstandkng the privacy implications) is to use the NAS-level checksumming of files, something like SHA-256 or even MD5, and cross-check with known kaka files to detect backups of infected things.
Buuut, sunce this reminds me of the whole apple CSAM fiasco, so not likely.
As a non-repentant digital hoarder, I struggle with organizing data, and especially, managing the various ways to identify things using multiple, overlapping criteria.
This seems to suggest that their on-the-edge [proof needed :)] ML model helps with that.
Given that a NAS quite frequently has multiple, independent users' data, segmenting the model's learning sources and attendant suggestions is an interesting challenge.
Usually, at that level, an HSM (Hatdware Security Module (ex: https://www.entrust.com/products/hsm), but also a fair number of processes and procedures around things like private key generation, key attestation, key verification, certificate renewals, etc etc etc).
There are some parallels with a TPM, but also a great deal of divergence (more so than in common, really).
Consider adding ppid to the mix - cometimes _what_ started a process is also quite valuable (if firefox starts bash, worry more than, say, sshd)
I cannot help but winder if, as a part of 'Fix, don't toss' mentality, there is an attendant[1] additional tenacity present.
[1] Or a pre-requisite. Correlation, not causation and all.