HN user

mlfreeman

146 karma
Posts0
Comments54
View on HN
No posts found.

The author of this ticket seems to come across as an arrogant know-it-all that thinks "the threats i thought of (or personally face) are the only threats that are significant, fuck anyone in a different situation."

I proudly print my entire KDBX file including passkey private keys and I encourage my elderly parents to do so too.

Lightning strikes (and assisting people with cleanup and repair from them) have taught me that there are definitely a class of threats that will leave me with paper but possibly no technology until I can go buy a cheap laptop to restart my digital life, SO BEING ABLE TO BACK EVERYTHING UP IS ABSOLUTELY ESSENTIAL.

His website says he's in Boston, so I seriously doubt he's ever seen what lightning can do or dealt with a hurricane or tornado.

In general, if you're in the FIDO Alliance and had anything to do with the kind of micromanagement that passkeys can allow, FUCK YOU. Go get a job at Walmart as a greeter. We'll all be better off.

The visualizer reminds me of my thermal camera.

I have heard claims of devices (mostly TVs) supposedly coming with secret 5G cell uplinks built in [never heard a specific model mentioned though].

If there were more variants covering more commonly-used RF bands, people could walk around and literally check for once.

(incidentally i'm sure three letter agencies have had this sort of tech in their bug-detecting toolkit for a LONG time)

I’ve seen websites say during checkout “your address wasn’t in our db but this one was” showing what was clearly a cleaned up form (changed “Circle” to Cir, uppercased, turned ZIP into ZIP+4) so there are ways.

You would have to tell the user “use the corrected/matched one only” though. Some sites offer the correction but don’t make you use it.

I followed the instructions link and read the scripts...although the TinyGPU app is not in source form on GitHub, this looks to me like the GPU is passed into the Linux VM underneath to use the real driver and then somehow passed back out to the Mac (which might be what the TinyGrad team actually got approved).

Or I could have totally misunderstood the role of Docker in this.

STFU 6 months ago

In potentially-dangerous-animal country (e.g. grizzly bears, mountain lions, etc), it could be a safety mechanism...I was told repeatedly you need to make some kind of distinctive noise regularly so they won't get startled by you rounding a bend.

I think this is the root of the problem.

I think library/runtime makers aren't saying "let's make an official/blessed take on this thing that a large number of users are doing" as much as they should.

Popular libraries for a given runtime/language should be funded/bought/cloned by the runtime makers (e.g. MS for .NET, IBM/Oracle for Java) more than they are now.

I know someone will inevitably mention concerns about monopolies/anti-trust/"stifling innovation" but I don't really care. Sometimes you have to standardize some things to unlock new opportunities.

In memoriam 1 year ago

The use of "unlikely" just screams that Ofcom will eventually pull a Vader..."We are altering the deal, pray we don't alter it any further".

It appears to literally just be their main page. Menu options bring up content and I logged in and and can still see an in-progress complaint I opened on Jan 7th.

When I back up machines I only pull a full backup 3-4 times a year and then I stack weekly deltas on top of those.

I'd start with that and see how it seemed to work when trying to look through backups and test-restore things.

it does nothing to protect you in the event of a password manager compromise. This is not a hypothetical; LastPass has suffered multiple breaches, and the more popular a solution, the more likely there are to be attacks against that solution.

You can mitigate this risk by not depending on your password manager app to do cross-device sync..keep a file on Dropbox/OneDrive/iCloud Drive/SFTP/etc and use an app like KeePass/Strongbox/etc that just deals in managing credentials.

My KeePass file storage provider doesn't know what the hell I store there because it's encrypted (I hope there are no known issues with KeePass's crypto)

As a bonus, you can keep offline backups to mitigate other risks like house fire, lightning strike induced EMP frying things (happened to me), storage vendor goes out of business, and more.

-------------

I think in the end, there is no universal solution - you really have to try to be reasonable about estimating your own personal threats and risks (such as asking "am I more likely to suffer a password manager compromise or more likely to break a device?") to decide whether to keep 2FA next to passwords or not.

I moved from my own colocated 1U running Mailcow to Fastmail and don't regret it one bit. This was an interesting read, glad to see they think things through nice and carefully.

The only things I wish FM had are all software:

1. A takeout-style API to let me grab a complete snapshot once a week with one call

2. The ability to be an IdP for Tailscale.

Are there any tools that can run (even across network on another box) to analyze possible duplication at various block sizes?

I am NOT interested in finding duplicate files, but duplicate slices within all my files overall.

I can easily throw together code myself to find duplicate files.

EDIT: I guess I’m looking for a ZFS/BTRFS/other dedupe preview tool that would say “you might save this much if you used this dedupe process.”

Wouldn’t this just encourage law enforcement to cite everyone for every little infraction?

Hmm, potentially...if they thought that would secure a much larger slice for themselves by knocking people out of the running...so maybe they'd have to be ineligible. However, in most cases that would require citing a hell of a lot of people (Jacksonville, FL has ~3000 cops for ~1.2m people, so they'd have to each cite several locals a day all 365 days of the year to make a dent in who's getting any money)

Since some criminals would be non-locals, you could also hand out the fines equally to all locals regardless of whether they got busted for anything or not.

Everyone breaks law the eventually. The article mentions the “Miami right” as an example.

Yes, there is a randomness to it all (breaking the law vs breaking and getting caught) but I'm not going to try to compensate for or control it.

So the government can purposefully take on more debt and then find infractions to pay it off?

Yeah, I realized this oversight 5 minutes after I clicked submit. However, perhaps it could be pooled and redistributed equally to pay down equal amounts of debt for all the governments in a region.

The point is that fines/seizures should not be a line item in a government budget EVER because then somehow the government will become dependent on criminal activity to an extent and go looking for it just for the money. It should be a completely unexpected windfall and thus either returned to the people or used to pay down debt. That's my hope, the details could probably take months to hammer out.

I worry that as long as the money remains in government hands at all there would still be abuse.

I had two ideas in this regard.

-----------------------

All fines (and proceeds from auctioning off seized assets) collected by all levels of government should be broken down into two categories:

- Traffic

- Criminal

If you have a drivers license and make it a whole calendar year without getting a traffic citation, you should get an equal slice of the traffic citation money from the feds and the city/county/state that has jurisdiction over the address on your DL.

If you have government ID and make it a whole calendar year without getting cited/arrested (let alone convicted), you should get an equal slice of the criminal seizure/fine money from the feds and the city/county/state that has jurisdiction over the address on your ID.

The funding for the distribution infrastructure should NOT come from the fines/citations/seizures.

In short, redistribute the fine money from those who broke the law to those who didn't (or at least didn't get caught).

-----------------------

The other far simpler option is that all fines/penalties automatically get applied to paying down debt owed by the collecting government.

If somehow a government has no debt (shocked face here) it would kicked upward to pay down debt at a higher level (e.g. city has no debt, so it gets sent to the state...and if somehow the state has no debt, it goes to the US Treasury's donation office).