I had a moment to start reading and start entering my date of birth, before it suddenly rewrote the date and then launched the walkthrough.
HN user
cflee
I'm curious, which ultraportable is that?
It's definitely not all assigned to Singapore or to ap-southwest-1, the ip-ranges.json file reports assignments to other regions, i.e.
3.0.0.0/15 ap-southeast-1 EC2 (Singapore) 3.8.0.0/14 eu-west-2 EC2 3.16.0.0/14 us-east-2 EC2 3.40.0.0/14 eu-west-1 EC2 3.80.0.0/12 us-east-1 EC2 3.104.0.0/14 ap-southeast-2 EC2 3.112.0.0/14 ap-northeast-1 EC2 3.120.0.0/14 eu-central-1 EC2
They continue doing the key wrapping with HMAC for U2F. Resident keys are for the "passwordless" authentication method under FIDO2.
U2F requires that the server must know exactly which keyHandles to request, based on the username (and probably password) that is supplied earlier by the user, so that the token can take the keyHandle and derive the key.
In FIDO2 "passwordless" mode, there's no username or other identifier presented, so it's just a generic request for credential from the server -- the authenticator has to independently figure out which key to present based only on the origin/domain, and maybe even present a list of stored keys (probably effectively a list of accounts?) to the user for selection. So it'd need some local/resident storage of various bits like the origin, maybe a user-chosen account name, and the actual credential, since it can no longer rely on the server to do store all these bits.
That is really great if you don't have any outbound deliverability issues due to IP reputation on a VPS host! Under those circumstances, that sounds like a great arrangement.
I think that is not quite the norm, lots of these hosts (and home internet connections) tend to have rather bad reputations, and chasing down the various RBLs can get really old really fast, especially since the most common response is to silently blackhole so you don't get a bounce.
I haven't had any issues with my personal domain in years, ever since I moved it from random web host to GApps, to deal with IP reputation issues, and have SPF+DKIM setup. (but my domain is a .net one)
WebAuthn is backward compatible with U2F tokens, but naturally only for use as second factor. They defined CTAP1 as the U2F protocol for existing tokens, then defined the new CTAP2 for communication with the new tokens, and made both part of the spec.
From a Yubico blog post (https://www.yubico.com/2018/05/what-is-fido2/):
WebAuthn and CTAP2 are both required to deliver the FIDO2 passwordless login experience, but WebAuthn still supports FIDO U2F authenticators, since CTAP1 is also part of the WebAuthn specification.
Technical Manual at https://support.yubico.com/support/solutions/articles/150000...:
Like FIDO U2F, the FIDO2 standard offers the same high level of security, as it is based on public key cryptography. In addition to providing unphishable two-factor authentication, the FIDO2 application on the YubiKey allows for the storage of resident credentials. As the resident credentials can store the username and other data, this allows for truly passwordless authentication. YubiKey 5 Series devices can hold up to 25 resident keys. If RSA keys are used, there is a maximum of three RSA with the rest being ECC.
I wonder what the user experience will be like at 25 resident keys, they mention that the YubiKey Manager (ykman) can set/change FIDO2 PIN and reset FIDO entirely, but nothing about managing individual resident keys/credentials.
It seems like it might be a bit challenging to manage this, especially if end-users accidentally register the authenticator multiple times or run out of the 25 slots for some other reason, and be told that they need to reset the whole authenticator and do recovery for all their sites...
Does anyone have an opinion on the new "three-message modification of the standard DH key exchange" they introduced for calls?
From their API doc: https://core.telegram.org/api/end-to-end/voice-calls#key-ver...
Party A will generate a shared key with B — or whoever pretends to be B — without having a second chance to change its exponent a depending on the value g_b received from the other side; and the impostor will not have a chance to adapt his value of b depending on g_a, because it has to commit to a value of g_b before learning g_a.
The use of hash commitment in the DH exchange constrains the attacker to only one guess to generate the correct visualization in their attack, which means that using just over 33 bits of entropy represented by four emoji in the visualization is enough to make a successful attack highly improbable.
They say they are using 333 emoji to represent ~34 bits.
> With SIM cards, users can switch to a new phone by just moving the SIM, or switch to a new provider while keeping their phone (assuming its unlocked) by just replacing the SIM.
Unlocked phones are still relatively rare in the US so I don't agree with your second point either.
As you point out, where GSM networks are concerned, this observation is mostly specific to the US - swapping phones and swapping SIMs has been a reality in the rest of the world for years.
Instead, the main source of friction is frequency bands. When swapping phones, it's not often an issue when switching between locally distributed phone models, since they are the Asia/international models with more band compatibility. When swapping SIMs domestically, it's not an issue for the same reason. When swapping SIMs internationally, phone service typically works, but if you want high speed data _then_ you check for band compatibility.
I'd say that for most of the world, the reduction in friction is real. It's a pity that the US market is so different.
If you only have a 3G device, or a 4G device that doesn't support the available FDD-LTE bands, you might be better off getting a China Unicom HK card instead. They have HSPA+ on 2100 MHz. Google services work fine on them.
The cards are hard or impossible to find within the HKIA transit area, so you will want to either pick it from a street retailer in HK, or order from their English webstore - http://www.cugstore.com/hk_en/. Street prices are usually cheaper.
(No affiliation, just a happy customer from a few months back. I got their "Greater China 30 Days Data SIM" because I was spending time in Macau and Hong Kong as well.)
I don't recommend Redbubble, I just ordered some and they're cheap but the printing quality is just not very good.
I have a few from Unixstickers though, they're printed properly.
(no affiliation, just a customer)
The next KSK Ceremony is happening today (12 November 2015, 18:00 UTC):
In Singapore, direct debit is known as GIRO[1], and practically any large organisation supports or prefers it as a payment option. Companies of all sizes take cheques, fewer take cash or NETS in person. Credit cards and one-off e-banking bill payments are often supported by the larger companies but not always. In fact, my insurance company outright refuses to take credit cards, and tries their very best to push customers onto GIRO. [2]
GIRO authorisation ("Direct Debit Authorisation") until recently was fully paper, often on carbonised forms with manual signature, but some of the banks have started offering electronic authorisation recently.
People here tend to fall into three camps: the cash/NETS (local debit card) folks who queue up at the post office or AXS machines to pay, those who do one-off bill payment on e-banking, and those who use GIRO/credit card. It depends on how comfortable people are with technology and e-banking in particular, as well as how skeptical they are of the billing organisation automatically charging the right amount.
[1] http://www.abs.org.sg/financial_giro.php
[2] http://www.aia.com.sg/en/customer-support/premium-payment-ch...
I don't think you can set this at a key-specific level, but in Keychain Access, you can ctrl-click on the keychain and set it to lock after x min of inactivity / when sleeping.
I'm not sure if you can put your ssh keys on a specific (non-login) keychain.
If you want those, you may want to go to Keychain Access > Preferences > First Aid > uncheck "Keep login keychain unlocked".
You're correct. Sim Lim Tower is where the electronic/electrical stuff is, Sim Lim Square has the computer parts and electronics (cameras etc).
But in Singapore, the mother lode is probably Koba Electronics[1] in Chinatown..
[1] http://dangerousprototypes.com/2012/08/06/global-geek-tour-s...
Yes, the Chinese website (http://cn.wrtnode.com/) is perfectly fine. (Chinese is my second language.)
However, I would not immediately characterise the copy as written by a US/UK college grad though - it feels like it is written by someone who learnt English on the mainland.
I don't really know why companies in various parts of East Asia don't hire/outsource to someone who actually is highly fluent in English to write/edit their copy. Sometimes I suspect it is simply due to cost, other times I suspect they just don't realise that their fluency is not quite.. 'international English' level
(No offence to anyone who runs/writes for East Asian company websites.)
The difference is that in Singapore, you can get charged for incoming calls depending on your contract, but you _don't_ get charged for incoming SMS.
From a Singaporean perspective, that's the most bizarre part of mobile service in the US. I need to get an unlimited texting plan so that I don't get billed for people sending me texts? Whoa!
For those who haven't found the other pages: there are a total of 8 basilicas and chapels that have been rendered in this fashion.
http://www.vatican.va/various/basiliche/index_en.html (English page)
Singapore Airlines' all-business-class flights (Singapore to to Newark or Los Angeles) have been withdrawn at the end of 2013 [1], but probably also due to fuel consumption of the A340-500, not just due to the all-business-class yields not quite working out.
[1] http://www.bloomberg.com/news/2012-10-25/singapore-air-to-en...
Should we just go "AT AT AT" or something instead? Or perhaps adapt from Mandarin speakers, who literally call the @ sign "the little mouse" ;)
Spam remains an issue if for whatever reason you're still using rulesets/blacklists/greylisting and the like, instead of Bayesian filtering.
The Chinese also spotted debris on satellite imagery (on an area that had been thoroughly searched) as well as a "sea floor event" (a week after the claimed event) in the South China Sea. I wouldn't jump to the conclusion that this newest finding is an instance of effectiveness just yet.
edit: whoops, 'peeters posted just as I did
In Singapore, where there are not many people using J2ME phones with a 3G data plan, this is why:
Facebook - not everyone has a Facebook account (think parents, young kids), you're not Facebook friends with everyone you know, and you don't _want_ to be Facebook friends with everyone you need to contact. I think they have been trying to change this on Facebook Messenger, but still, you need a Facebook account, and that's a line that many people refuse to cross on principle.
Hangouts - not everyone has Google account, because they use another email provider (Hotmail, Yahoo, ISP), and don't want to get "a Gmail account" just to use it. Granted, this might work great for Android users, but in practice, nobody uses this here (except maybe for multi-party video conferencing). Practically don't see iPhone users on Hangouts either; it is very much associated with Android (and hiding in the background, many people don't even know they're logged in because they don't use it, and nobody uses it to contact them).
iMessage - doesn't work on Android. Yes, there are many iPhones in the world, but you are incredibly selective about who you need to contact if they all have iMessage. But granted, this works quite transparently between iPhones.
Now, iMessage (and Viber) is probably the closest to the 0-step-to-add-contact way of WhatsApp. Because there's no process to do that, there's no contact-request 'approval' required from the other side, there's no friction. You add someone to your phone book, they show up in WhatsApp, you send a message or add them to a group. That's it.
It is a lot easier to teach folks to use WhatsApp just because of this. It's about as complicated to use as your platform's built-in SMS client. It is a huge contrast with the 101 features of WeChat, and to a lesser extent, LINE. WeChat is _huge_ with the PRC community here, but that's about it. Everyone else is on WhatsApp.
Viber is probably the next in line, but due to WhatsApp's network effects, it just didn't take off. Sure, it has internet voice calls, but it's known for being a little flakey on the call quality, and by default its notifications can be a bit annoying. WhatsApp never pops things up unless someone sent you a message.
Google Translate might not be very clear, but the article actually says that Li Ka-Shing denied authorship of this article on 20 February 2013. (Yes, 2013!)
This current resurgence is probably linked to an English translation being posted on e27 in the past 24 hours, before being subsequently picked up by TRS: http://mirror.e27.co/li-ka-shing-teaches-buy-car-house-5-yea...
Just a note that The Real Singapore is not representative of Singapore's media scene.. while it is not quite an equivalent of The Onion, it is also not the first news source for most locals. I am quite embarrassed to see it linked to on HN.
iNO Mobile here in Singapore has a whole series of elderly-targeted phones, here's one:
http://www.inomobile.com.sg/2012/07/ino-cp10/
actual retail price now is SGD 79, which is about USD 65. I'm not sure if I can get these at our 7-Elevens, but I think they have something similar with large keys.
I think that's because the Java Control Panel updates the JRE, but that just updates the plugins and stuff. The manually downloaded JDK pkg definitely will update the java you invoke in the shell.
I was just checking if Renesys[1] had any analytical updates, but hey, kudos to Cloudflare for a well-written and visualised post!
[1] http://www.renesys.com/blog/2012/11/syria-off-the-air.shtml
Turns out that the Dutch armed forces agree[1] that it's not so easy either:
"The Mine Kafon has just been tested by the Dutch Explosive Ordnance Disposal Unit, which has concluded that it is not suitable for mine clearance (which requires a more systematic approach), but at $50 each could be used as a cheap and safe way to identify dangerous areas that need demining."
Take a look at DMARC. [1] The webpage is horribly ugly, but essentially, it allows a domain to declare that all their outgoing mail are DKIM-signed and SPF-passed.
Paypal and eBay do this. Gmail filters out any DKIM-fail or SPF-fail mails purporting to be from @paypal.com and sends it to spam, with 100% accuracy. Gmail also puts the little 'key' icon next to the sender name, but that's not really important, the point is that any and all fraudulent emails are filtered out with unerring accuracy.
Thus, we don't need to use PGP or whatever, which needs to be handled at the client level. DKIM + DMARC is already here and working at the server level. You don't need to wait for your favourite email client to adopt DMARC.
Yes, if people send emails without going through that SMTP server etc etc.. that's a problem, but also solvable/solved.