HN user

mazone

43 karma
Posts0
Comments27
View on HN
No posts found.

In a corporate setting my experience is that it is rarely worth it to add any obscurity on top of security. Your biggest challenge is getting peoples time and resources, and you need to use that time to implement security controls. A secondary objective you have is to build security culture over time and teach people too see patterns where more security is needed, so it is important to select what to teach to get maximum impact.

Many companies usually want to compare themselves to Apple and at the same time say they are disruptors and innovators but Apple is probably the best company at being okey with being left behind. Many think about them as experts in products but for me they always been best att copy what others are doing and refine it, maybe not neccassary better technical but always seen the market fit better then others. Like poker, the later you need to take your decision the more information you have.

I don't remember the last time i had a meeting that was productive. Last time i worked in the office, the hallway discussions where the productive ones and now working remote most of the time is just being able to work with good people that understand text and work by messages that works good. Even video meetings with good people tends to be waste of time.

You are correct. Would need something like distributed ledger to fully prove things.

It might not be possible to verify 100% but the more transparency the better i guess. Seeing the 3 way handshake and connection information, the timings, location of the server. Would need to be quite elaborate to fake. Just thought was a fun idea. Have the customer allowed in to production. A lot more difficult then publish privacy page, source code, fake audit reports.

I wonder if it would be possible to allow people to ssh into the edge servers with enough access to verify no access logs are stored but not enough to cause any problems. Admit i have not thought it through but would be cool having people verify the live environment while running.

I love kde and it is what i use but still having the bug from time to time that the panels dissapear and have to relaunch plasmashell, also i wish they merged the virtual desktops and activities into one concept and allowed different wallpapers on each.

The theme settings is also confusing because of gtk apps, global theme etc. Feels everything around theming could be made nicer.

Prob some more nitpicks but overall it is a really great desktop environment.

Trying not to sound too cold, he seemed like a very nice guy and i did not know him. It was not surprising for me. I remember seeing interview with him when he took things very personal and could not let things go some year back. Thought at that time that he was at high risk of suicide. He seemed to have a self loathing personality / depression and obsessive behaviors.

Staying on the Internet and be dependent on it in some way financially working as a streamer with all the short form communication and negativity online. Together with cyber bullies etc. A lot of things creating a perfect storm for what seemed to be a sensitive and very nice guy. Easy to say that his family and real life friends should have seen it too and make him change path but in reality it is difficult. Especially since things that make it worse like sitting down and playing chess all day / night and not getting enough sleep, together with cyber bullies is also the things that you love, you earn money on and you have many of your friends there.

The most dangerous about the touch screen in my car is a warning message that come up first when the entertainment system boots, warning about using the screen while driving that i need to accept.

iPhone Air 11 months ago

Recently got a iphone 16 pro to my mom. First thing i reacted on when opening the package was. Damm that is a thick phone. Compared to my S25 and older android phones i have the iphone 16 feel old and clunky, like from another era.

It is not about MFA or not but to demonstrate the process is secure for the purpose.

It can be complicated but a example. TOTP that is very common used with passwords is regarded as MFA (tho most of the time software based on phone) but have many problems regardless

- many time replayable - can be intercepted - implementations look different - recovery code reuse problems etc.

On the other hand, using only passkeys dont have those problems but with passkeys, many times you cannot decide on what device a user have registrated the passkeys in a enterprise setting. example they could be apple passkeys, chrome passkeys, windows, hardware key(yubikey) etc and all of them behave different when it comes how they ex can be copied/ synced between users devices. So from where they can be used.

So for any authentication flow, you need to look at the full picture. What is the process when credentials are lost? How do user onboard etc.

Is a good entry point to say. We should use MFA or similar but the details matter.

PCI DSS from 4.0 actually have something called customized approach for everything. If you can prove and the QSA agrees that you fullfill the goal of a requirement, you can be quite flexible. Example i am doing things like not using passwords at all and only passkeys, or only ssh keys protected by hardware security key etc. Together with agents trying to verify the devices connected are company owned and hardened in different ways. Your milage might vary depending on how good your auditor is but PCI DSS standard do have quite a bit of flexibility in it.

I do managing, coding, design, governance and overall what i call "improve the company" within my areas of expertise and context switching and commitments are the most challenging things. Need to be very disciplined and know the other areas are currently very stable and under control to carve out time for the other things. It is not impossible but it have to be very focused and the problem domain need to be quite good understood before jumping in. Example, writing a internal tool that in worst case get delayed for later is easier to start working on then being part of customer facing product development as all of a sudden i would need to jump into some urgent management tasks or overall just let the governance and long term company quality go down.

One example is flee markets, or different type of second hand. Christmas markets etc. Some do accept debit / credit cards but a lot is swish only.

For cards, depends on the bank. I know my bank at-least do send the card abroad to my current home and as long as i keep my digital authenticator ID (bank ID) i am able to access that, renew cards. Do most banking services etc.

I also managed to get a new bank authenticator by going to the embassy and get signed papers etc, however it took about 5 months or so if you don't have any cash that might become a issue. :)

DOOM CAPTCHA 2 years ago

on mobile phone. Just back up directly from the start to the door behind you so you dont get shoot then snipe them from a distance. captcha solved.

Worked 5 years as a contractor for a system made to be used for all of the healthcare in a country. Payed by tax payer money. Some serious money. I never understood what the system actually was supposed to do during those 5 years. Started as some custom authorization server for new healthcare laws and then ended up as some kind of desktop app that had a launcher to launch apps. No idea what the purpose really was and heard it got cancelled a couple of years after i left.

You basically just install steam from within your linux distributions package manager. I use and recommend some arch based distro but for Ubuntu it should be apt-get or some gui tool like synaptic.

After you installed steam it will probably just work. You might need to go into settings -> steam play and enable proton. that's it.

Play only on linux since the last year or so and got away from the dedicated windows machine i had to have for only gaming. I had some bugs in the beginning but with recent versions of proton it feels a lot more stable. I don't have any bugs anymore in any games and don't notice any slowdowns or degraded performance. It is quite amazing.

1. 13" , 14" laptop

2. IPS matte good quality display with similar resolution to 2560x1440p, Superb colors and peak brightness.

3. At-least 32GB RAM but pref up-gradable RAM to 64GB

4. Linux full support, preferable AMD

5. Keyboard similar to old thinkpad 7 row style. General going back to retro style with proper keys, Topre switches or why not a mechanical keyboard if possible.

6. Trackpad of high quality. Atleast similar to Apple. Not seen any that have it yet on pc. If not possible, add a trackpoint and remove the trackpad.

7. Ports! Please have many ports. As many as possible.

8. Hardware quality. hinges, case and overall. Make it durable.

9. Battery time, make it last.

10. No spyware or bloatware. Published schematics of the laptop and help the open source community.

11. Good quality parts in chipset for wifi, bluetooth, sound. Latest AMD. Should not be a issue.

12. No intel inside stickers or other stickers on my laptop. If have to put a logo on it, make the logo very small and not in your face.

Okey, so what can i be without to make the above possible and

- No frills or extras. - No touch display. - Medium powered CPU. ( think road warrior not full fledged desktop replacement ) - No discrete GPU needed if it makes my laptop warmer, or make battery go down faster. Integrated GPU is "good enough" - No need for fingerprint sensor, even if convenient. - No magic bars or other innovation someone thought would be good. - Weight and thickness is less important then manufactures seem to think. To a degree. Slim laptops get warmer, rather have it a bit ticket with more room for battery etc.

Do the basics correct. A modern take on the Thinkpad x220. Remove things that don't matter and make a classic awesome laptop for the ages.