As a summer lifeguard when I was younger, I agree with the premise - drowning doesn't look it. Each time I encountered it the key was someone simply staring at me - they don't raise their hands or call for help. It even happened once in my own home swimming pool when a pre-teen got in over his head. His parents definitely didn't notice. Except the very first time when I went over to see what the problem was I now extend a cleaning net to them - they grab on very fast and tightly.
HN user
landmass
Absolutely! I now won't enter the site because they kill the back button.
Why would you want to? Just create a new passkey on the other machine. If you're saving them in a password manager, just create a new entry, "Another Machine's Passkey."
There are two types of passkeys (1) resident, hardware-bound, non-copyable, installed on Yubikey etc., and (2) non-resident, copyable.
Technically, by not being copyable, a resident key isn't a "Passkey," but that's just terminology and it serves the same purpose as a passkey.
I've installed KeePassXC on my Mac and Linux machines and it stores Passkeys. Low-tech syncing is by Signal Notes to Self. If there were an audited app for iPhones I'd still be using that method; there isn't, so I've moved to Bitwarden. Passkeys seems to work fine on Bitwarden.
DuckDuckGo also suffered from the SEO infection, but recently - the last week or so, perhaps - it has improved. SEO probably still controls it, but when I put in "-Amazon" it does not present Amazon findings - remarkable! I'm also seeing a significant number of "no result" results. It isn't perfect but it's much better than six months ago.
As a long-time user of KeePassXC, I switched because of the difficulty of syncing databases. Basically, I used the sneakernet and a thumb drive whenever I thought I needed to for five or six devices - it became wearing. At first after the change I kept the critical account - banks, email, and the like - solely on KeePassXC. As I began to trust Bitwarden I began to slowly add those accounts, too.
Also, while I trust Bitwarden sync, I'm not quite as sure of the various apps that implement the KeePassXC on iOS. I'm still not aware that any have been audited, so to my mind Bitwarden is more secure.
Still, the possibility of a change of management philosophy at Bitwarden also wore on me, so not wishing to be solely dependent on an app that I might no longer trust, I continued to maintain my KeePassXC vault, duplicating any new Bitwarden entries. It's a simple way to backup Bitwarden, though a bit time-consuming.
Syncing KeePassXC is simpler now than before I migrated; sneakernet is no longer required, having been replaced by Signal and "Note to Self." It's still not as simple as Bitwarden's sync, so I'll maintain that unless I have a trust reason to change. FWIW
If there hasn't been a study of the negative effect of inviting crypto miners to use cheap energy I'm not surprised. It would probably show a huge negative effect and Texas isn't interested in disagreements with its power policy. They have carefully shielded ERCOT from having to show transparency. Industry and crypto mining are paid to reduce power usage during ERCOT-declared emergencies but ordinary user are not.
I was told by a furniture store owner 20 years to use local cabinet makers to build bookshelves for you. He said never to have shelves installed in your house - a movable bookshelf costs the same as an installed one and you can take it with you when you move.
My participation has changed since the API change. I use old.reddit and uBlock Origin as I always have. I limit myself to scanning a few sub-reddits to ensure nothing bad has happened to Bitwarden and Yubikey, I don't log in and certainly don't contribute as I used to. If/when old.reddit stops functioning I'll stop even that low level of participation.
Curious about how Passkeys work at the website level. Passkeys strikes me as essentially an authentication method.
1. Signing up or logging in to a website today you'd expect your password to be hashed, stored, and protected. (I understand some are stored in plain text, but that isn't part of this question.) Assuming you want to change over, or create a new account, to passkeys, how do they store and protect that account?
2. Assuming you're still using a password manager for the foreseeable future, does it make sense to use passkeys to access that? IIRC, most password managers will use your password/passphrase (plus a lot of processing) to encrypt your vault. Even if you authenticate with passkeys and gain access, how do you decrypt your vault without your password/passphrase? It's clear that authentication does no good if your vault is already sitting on the black hat's desktop, as LastPass discovered, so a basis for encryption is still required. It appears to me that anything that requires an encrypted holding will still require passwords/passphrases.
My limited syncing requirements are met with Signal. Put something into "Notes to Self" and it then exists anywhere I have Signal, which is on everything.
That password thing isn't as useful as I'd hoped. Mine is maybe 20 digits and I use it frequently when I'm calling my phone carrier for routine activities - they do check it.
For traveling overseas I needed a different SIM card and bought one at a local store (to be repaid by my carrier). The clerk at the store did not need my password because I showed him my valid identification. Password was useless in this case.
Not counting fake IDs that get past clerks, a few years ago Krebs On Security noted that the normal bribe at a phone kiosk was $85 to do the SIM swap illegally.
I'm in the same boat. The people who understand Age assume everyone can use man pages. I can work my way through them, but I could really use a few explanatory articles with examples.
On the positive side, "noblesse oblige" actually works in The West, e.g., The Shire, etc. - (that's how you can tell the books are fantasy.) The lords actually care for their people, there's no grinding poverty, and with few exceptions efficiency is less valued than custom.
When it it runs, Linux is great, but when something breaks fixing it can be labor intensive. When something on Mac stops working a call to Mac support will usually fix it in a couple of hours.
That said, I agree with your 2010 estimate of Mac software peaking in 2010. Mac laptop hardware is still better than Linux laptop hardware. As someone who's considering my first Linux laptop, I need to balance the inconveniences of Linux hardware now with the likely fact I can probably use that laptop significantly longer than current Mac. Somebody has to pay for all those convenient Mac support folks.
Yes. I was interested but finally gave up on the link before it loaded.
I agree with the concept of starting small - I didn't. I have various accounts in various banks and now have 26 accounts that need to be balanced, all in order to have live "net worth" visibility. At first I enjoyed doing it to that level, but not anymore. I need to prune the accounts I enter using .csv and just keep track of current accounts, like checking accounts.
That said, GnuCash is definitely worth the effort - GnuCash has continued while some "easier" financial programs have not. I thought about using it after MicroSoft abandoned MS Money with 10 years of my financial data. I looked at GnuCash but it looked too hard and I migrated to MyMoney instead, but after a few years it dropped support. I again looked at GnuCash but again chose not to face learning the "harder" GnuCash and migrated to MoneyDance; after a few years they changed its default to "Save on exit," rather than allowing me to exit to abandon mistakes and start over. This time I migrated to GnuCash in the hope that it will be longer-lived.
I don't know that I need to have all my financial data for 25 years, but if I'd chosen GnuCash from the start I'd still have it. It turns out that the other systems were not easier, if you include having to re-learn so many financial systems and incompletely migrate existing data.
Amazon Sidewalk shares signals in a blatant misuse of my WiFi password.
My new 65" Sony has never been connected to the internet. We can't get 4K resolution, presumably because it's never been updated. Sony tells me they don't have a USB update available "yet." Had I known this would happen I wouldn't have bought it - my old plasma is still working. I didn't wish to connect just for the update and then disconnect over concerns that they would use that connection to download ads onto the firmware at the same time.
If open-source routers don't interest you, you might try reviewing this site: https://routersecurity.org/
The short answer is the line of routers from Peplink, including their low-end business router, the Pepwave Surf SOHO. The site's owner argues that big box routers put overmuch emphasis on speed at the cost to security; they build a fast router, he feels, but then neglect firmware security updates. I've owned the Surf SOHO since 2017 and have just upgraded to the Peplink Balance 20+ for a little more future-proofing. I can attest that their engineers are still updating the firmware.
Recommendations for American electric kettles for use with hard water? Cleaning calcium residue out through a narrow opening sent me back to my microwave...
Nor do I. Their router recommendations are based on speed, with no consideration given to after purchase firmware updating. Their car reviews in the past were manipulated by choices they compare - Honda vs Kia - with no mention of, say, Toyota. I think the main problem is that they aren't actually reviewing anything - they're measuring other reviewers reactions who are paid to feature certain products and Amazon reviews, which are hugely falsified.
* today: the Amazon shopping experience is so filled with bullshit that it’s actually easier to buy from the producer’s website and pay shipping*
True - After Amazon search doesn't find what I want (it found it yesterday) I've recently taken to using DuckDuckGo site search to bypass Amazon's search issues. Then I bought the TV locally, not even in a big box store. Support your local electronics dealer.
In case of a shooting war all those F-35 would get destroyed by cruise missiles before they could take off. Possibly, but aircraft in their sealed revetments are a difficult target.
Also, an attack of that nature would would certainly trigger Section 5 of the Collective Defense, and then US resupply. I suspect most NATO members who buy the very expensive F-35 do so in the belief (or hope) that the US will replace these aircraft immediately, from US squadrons, if necessary.
Send the KeePassXC .kdbx password database to your cell phone, download it to your phone, then upload it to Strongbox (or other). I find the easiest way to send it to my cell phone is by using Signal's "Notes to Self." All my devices that have Signal and have KeePassXC then have access to the updated database.