I'm not sure what problem this is solving. This seems like chainguard but being built in "your ci" (github) vs "their ci". Images may be a bit smaller, but this is already a feature set that wolfi already allows for. Besides that chainguard is not full-source bootstrapped.
HN user
dgrove
my public key: https://keybase.io/drgrove; my proof: https://keybase.io/drgrove/sigs/7vNTktyLv2POAACx2FJXZP2H_CuAyrmGv17wvdW9DLk openpgp4fpr:c92fe5a3fbd58dd3ec5aa26bb10116b8193f2dbd
Also login over a VPN unless you want your IP leaked to everyone else
Just because you make exceptions doesn't mean everyone else does
This feels like MilkSad.info and the 2020/2021 Cake Wallet flaws all over again
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-3991...
Looks like the XMPP adapter hasn't been open sourced so it can't be built
https://github.com/SAMA-Communications/sama-server/tree/main... https://github.com/SAMA-Communications/xmpp-adapter
Also I don't see anything about E2EE support
scp has the assumption that you have a login on the computers you're trying to share data from. wormhole allows for sharing with others without providing login access to the computer
Because a single hot key for signing on a random build server has never fucked anyone before?
https://www.techtarget.com/whatis/feature/SolarWinds-hack-ex...
The lack of package signing and reproducible builds leaves a lot to be desired
HKPK doesn't have a ton of adoption and only works in browsers. So this does nothing for curl, wget, pip
Sure, so you add it as part of the P2MS script but that doesn't solve the issue of every re-key costing money
Is this because you have a time-locked transaction to move the funds from the P2MS to a P2PKH? How does that work when it's "re-keyed"? Wouldn't each re-key move to a new P2MS and have a transaction fee associated with it as well as have a second transaction for the HTLC transaction?
The only problem with LN is that is actively requires an internet connection. Wherein Bitcoin could be done offline similarly to a Card Imprinter
Bitcoins entire premise is around the movement of unspents. If you always use the same wallet for every transaction it is pretty easy to track who sent the money. If you instead are always sending your money to a newly derived wallet from your HD (Hierarchical Deterministic) root it does make it much more difficult to track what money was money being spent on something and what money is part of a persons total value
3rd Party browsers are not, they have their own sync infrastructure. This is mostly affecting builds of Chromium that are not directly built by Google https://groups.google.com/a/chromium.org/g/embedder-dev/c/NX...
"Stocks only go up"
iCloud security code can come over SMS if your account is configured as such, therefore the above example of a SIM port applies
Lots of talk about passwords, but fewer about password managers. The password managers listed in this do not protect against backdoors. Lastpass, for example keeps all your passwords in plain text once you've unlocked it. Passwords stored in Apples Keychain can be synced across devices and a remote attacker can do something like a sim port, gain access to your iCloud account and then sync to their computer leaving you vulnerable.
Password managers should be bound to hardware tokens and each password should be individually encrypted, as well and individually decrypted that also force physical tap.
Password Store is a perfect example of this. Physical password managers are also on the rise, see: Ledger and Mooltipass
Multiple teams I've been on at multiple companies have done this process, but with donuts and other foods. A little bit of public shame goes a long way.
I use pass for my password manager which links to my yubikey that has my gpg key on it. My yubikey has touch enabled which means that even if someone got access to my machine with my yubikey on it and asked me to tap they would only get that single password. As far as TOTP is concerned it's the same thing. The TOTP section of my yubikey has it's password and also requires a tap
Google Authenticator does not help prevent against a compromised device (as all TOTP secrets and seeds are on device) and is truly a pain when working with multiple phones. Personally I use Yubico Authenticator as all the TOTPs live on my Yubikey. That, in combination with a password then clicking on a totp i want and tapping my yubikey provides me with only that code. When I first seed the yubikey with a new TOTP i also backup a copy of the QR code text and save it into my password manager in the unfortunate event of having to swap out yubikeys.
perhaps something that can be automated
This is solved using WKD. Thunderbird already supports this with enigmail enabled
Use the elliptic curve version instead https://security.stackexchange.com/questions/46802/what-is-t...
This is built into modern browsers so you can use that as the basis for HMAC if you can't trust TLS or have something like an open URL for a lambda function that in theory should only be hit by someone's webhook (ie. Slack)
And all of your DNS traffic since it's not over TLS
You're not inherently trusting your VPN service to: a) not track you b) not keep logs c) not disclose this information to your actual ISP
You're also now just sitting behind whatever ISP your VPN uses which knows everything you're doing and sells it back to who-ever.
If your not rotating your VPN services that still allows you to be tracked via that IP. At the end of the day all your data still belongs to someone and can be used for whatever. Until DNS over TLS is complete and rolled out across the board your metadata can still be used.
Not to mention all of the other things associated with this. Even being connected to a VPN via your phone will still leak information like your coarse location, wifi networks and bluetooth beacons nearby which all get sent to your primary phone carrier and whatever applications you use.
I'm not dismissing that, I'm just stating that we were literally here 5 days ago talking about another alternative. One that already has an entire team backing it and keeping security in mind. There are probably 10s to 100s of different android builds with and without google. There are definitely a few that will outshine others: Cyanogen, Oxygen, Lineage, AOKP, TWRP to name a few that stick out in my mind. It's just funny that not even 5 days later we're back again with another android fork that google-less.
The CopperheadOS post was 5 days ago and was in the top 10 for the majority of the day. Which also had the original title of being a Google-less Hardened version of Android.
How quickly HN forgets. There are tons of Google-less Android builds. You can even run AOSP (Android Open Source Project) without Googles' binaries. When I want to use something without Google, I use CopperheadOS https://news.ycombinator.com/item?id=16030391
Widevine is not a "Chrome-only" feature. Firefox, Edge and even Opera have Widevine support.
That is touchpal
I have. They do the typical, "oh, service is actually partially out in your area. Please try again in 12 hours."