Exists randomness or is it just lack of information? :)
HN user
kenniskrag
I think compression would reduce the problem not? I think if you swap the wire format to something like jsonb you would need to parse it again anyway and pay the cpu time.
acme.sh supports multiple CAs there is even a RFC for CAs that describe the api.
I would define high as "double time needed to fix a dns issue" and account for weekends
What's the threat model. Where do you store the decryption key?
E.g. if my app needs a db connection I can ask a vault service but I need creds for that. The vault service can rotate the creds very fast but is it addition security.
Edit:
Banking has no selfservice password reset. A lot of work for customer support due to identification. Nobody wants to do that for free and if the accounts are freenyou may get DOSed by bots which trigger passwort resets.
But then your hardware dies
A lot of services have password reset email features. If the email account has passkey you're screwed. But restore by snail mail can be possible but slow (for paid services). More secure? Don't know but same category of problems already known due to sim swapping attacks in mobile sector. But for sure the Mail account is a high value target.
Storing passkeys in a database may be possible but complex to do it right e.g. backup verification, avoiding to leak while backup etc.
Pull request to notify on setup (2 weeks old): https://github.com/mastodon/mastodon/pull/38548
Is that legal? Do you avoid uploading somehow?
Not if the advertise zero knowledge encryption. As far as I understand the password sharing / collaboration feature is often the problem.
Second: The provider can get the passwords with a simple server change.
Much like the other products we analyse, 1Password lacks authentication of public keys. This trivially enables sharing attacks similar to BW09, LP07 and DL02, something that the 1Password whitepaper...
IMPACT. Complete compromise of vault confidentiality and integrity. The adversary can read and decrypt all vault con- tents encrypted after the attack, including passwords, credit card information, secure notes, and other sensitive data stored in the vault. Similarly, they can inject new items into the vault after the attack. REQUIREMENTS. The client fetches key material from the server, for example due to the user logging in on a new device. If executed on a non-empty vault, the attack results in the client losing access to all items already in their vault, while leaking any new items added to the vault after the attack took place. If the attack is executed at the time of vault creation, the attack is effectively undetectable by the client, since it cannot distinguish between a ciphertext it created and the ciphertext created by the server during the attack. PROPOSED MITIGATION. A straightforward mitigation is to have the client sign vault keys using the RSA private key in the keyset before encrypting them with the RSA public key. Ideally, two different key pairs would be used for...
from the paper: https://eprint.iacr.org/2026/058.pdf
In europe you need identification to buy a sim or esim.
https://www.reddit.com/r/europe/comments/9ziqfi/european_cou...
online access is as necessary as water We have paper money and also can work and buy stuff offline.
I would say online access is as necessary as a car. Possible without but less flexible.
Driving licence is a bad argument because there is public transportation service. If you're reckless or have other issues the licence is revoked.
One reason was, that the security model wasn't enough anymore. E.g. every application was trusted and can listen to key inputs e.g. steal passwords and credit card infos. Btw there was an issue that screenshotting in wayland was not possible. But easy in X11 because everything was visible.
Don't know much about the architecture about wayland but I think grahic driver handling changed in wayland too.
qutebrowser does that.
Which ones? I try to learn how these systems work
You can edit the url to use any number. :)
which rss reader do you use?
Generally it depends on the threat vector.
* Do you trust the hardware
* Do you trust the OS
* Do you trust the user
* Do you trust the software
On a rootkit you don't trust the OS anymore. So a safe location inside the OS space isn't an option anymore. But often you are not a root user (e.g. android, windows in a corporate environment)
If you have OS backups there is a risk it is readable by others (e.g. cloud, different IT department). There is also a risk a user uploads the config somewhere.
If you want to rotate keys you would have to search all keys compared to a centralized location.
yes because more than one process can access the file.
A "password manager" provides a defined api and schields the password away from everything. It can also ask the user if process x can access the key y.
TL;DR: Windows Defender had a bug that made certain system calls expensive on CPU cycles when Defender's Real-time Protection feature is enabled. After discovery, Mozilla reported this issue to Microsoft. Microsoft is releasing a patch that should result in lower CPU usage when using Firefox on sites like YouTube (a ~75% CPU usage reduction was noted when browsing YouTube in Firefox with the fixed version of Defender).
Is https://www.portvintages.com/ the book?
chocolate
I recently saw a green dot on the right corner during camera usage on android. Probably a (new) feature of android.
Nice idea. From the docs:
Endlessh is an SSH tarpit that very slowly sends an endless, random SSH banner. It keeps SSH clients locked up for hours or even days at a time. The purpose is to put your real SSH server on another port and then let the script kiddies get stuck in this tarpit instead of bothering a real server.
Since the tarpit is in the banner before any cryptographic exchange occurs, this program doesn't depend on any cryptographic libraries. It's a simple, single-threaded, standalone C program. It uses poll() to trap multiple clients at a time.
Sometimes the default after creating the VM. Sometimes it is, if you start in the recovery mode (usually with a random long password)
Is there an algorithm to convince you?
I'm younger than the years he is hiding :)