HN user

throwaway41597

219 karma
Posts0
Comments149
View on HN
No posts found.

Not that simple. When carbon in the soil rises beyond a certain percentage (a tree falls) it'll convert back to CO2 because of the bugs eating it. But if the percentage starts at zero (in a desert) and an ecosystem settles there, the percentage will rise and stay above zero for as long as the ecosystem survives. Basically the plants generate matter as fast as wildlife eats it.

This sequestration can be long term if things go well or it can be short term if plants die in large numbers (because of climate change, diseases...).

Trees excel at harvesting water. When you water a tree, there is evaporative cooling like an artificial cooler but during the night, the dew falls back on the leaves and the ground where some of it finds its way back to the trees (possibly via an invertebrate first). Also the reflectiveness of leaves helps. Then there's the soil where layers of dead leaves, wood and others accumulate, sequester CO2 and create a sponge. Finally, by virtue of making the region cooler, rain is more likely to fall. Humans can probably engineer something better but the bar is high.

You're not describing how a tiling WM fails to satisfy your needs. My guess is you're unhappy with toolbars being repeated in each tile, is that it? If so, I believe Suckless's striped-down browser is the closest, together with a tiling WM.

If code editors are indicative, yes some power users tend to like a tiling window manager bundled in the app. So you may be right but I think it's out of scope for Firefox which targets the masses and it's definitely off-topic here.

I'm very curious as well because my very limited understanding tells me the answer is nothing. The relay hides your identity. Your phone checks the attestations so it won't send your data to servers not running the published software which ensures encryption keys are ephemeral. Once your session is done, the keys are deleted.

Law enforcement would need to seize the right server among millions while it's processing your request and perform an attack on it to get the keys before they're gone.

My next question is what happens if/when the attestation keys are stolen.

The goal is money and control. They enact a partial "solution" so later on they'll say they need more access to private data because of the loopholes. Meanwhile the industry of surveillance and compliance grows providing more paper pushing jobs to the establishment. Power-tripping politicians also get the ability to spy on opponents and basically anyone they please.

The same argument of diminishing returns, that quality of life doesn't improve much when going from 130k€ to 1M€ can be applied to capital controls. Is this 10k€ limit really what is needed to save the welfare state? Were the previous controls not enough?

Or is it that the welfare state is collapsing on its own and grasping at straws?

Chrome allows you to export saved password in CSV (chrome://settings/passwords) So I'd say it is a regression in this regard. You won't be able to switch to an other browser easily, you'll have to go to each websites and change/add authentication methods as far as I know.

The lock-in is very real and relevant.

Websites already have a hard time to get users to sign up, so requiring them to enroll backup authenticators (which they won't have) is not going to work. Printing or writing down backup codes is even worse from a UX point of view.

IIRC the spec has a flag to hint that the passkey is backed up (in iCloud or your Google account) so the relying party (website) knows whether backups are mandatory but that means the secret doesn't stay on your device and goes to the mothership. Then I don't see why the spec wouldn't standardize the transfer of secrets from one company to the other.

I think he means that you don't point your domain's public DNS records straight to your home IP (where your NAS sits), but rather via Cloudflare.

If so, doesn't Cloudflare do HTTPS termination? Meaning that all your photos would be visible to them during transit.

Thanks for your reply. I think the issue you describe is more due to the website. A website that accepts Passkeys should provide a way to enroll a competitor. In this case it could be as simple as copying a code in one browser and pasting in the other. This isn't too bad if you consider that typing a user+password pair is also annoying though more familiar. Of course, it gets near impossible if the device is dead and the user wants to switch brands without any backup. But again, websites enrolling only one authenticator and no alternative are somewhat negligent.

I think people who evangelize Webauthn need to carefully convey the risks and remind everyone that end users need backups (multiple authenticators, backup codes...). Hopefully, down the road, it will force interoperability between big manufacturers so one authenticator can authorize another for all websites in one go (this probably requires websites to have a standard way to enroll new authenticators).

My separate observation about a lack of support for hardware keys to be "paired" to support an off-site backup

This is worrying me more. Interoperability between tech giants is bad but the sovereign solution may never get there.

I wasn't sure what your concern was, but is it that?

1 ) Hardware authenticators won't spit their root secret, almost by design.

2 ) Webauthn doesn't require that the authenticator store the list of accounts, also by design (for privacy). So if you want to switch from iPhone to Android, you have to remember all websites you used Passkey on, and go one by one hunting down the right security settings page.

Wood is often protected by plastics. Acrylic wood finish and paint are plastic. Particle boards such as those in many Ikea furniture are covered with a plastic sheet.

If you don't use plastic you need to switch to solutions requiring more maintenance and offering less protection like vegetable oil or pine tar.

No need to. Trees bury about half their biomass as roots. Then leaves and branches fall on the ground and bury older leaves and branches. Of course it's long and inefficient (because of fungus, bugs...) but plants do it without our input so we need to let them do their thing. Calling this process net neutral is a falsehood.

Of course it's not enough to balance human emissions. Sequestering carbon in fields, as pointed out, is a win-win solution which may do a large part in canceling emissions.

With the rise of the internet I now consider my identity to be valuable. So I don't give it away for free.

I personally don't want my identity checked unless I'm asking someone to trust me. And I'd rather use a trust-minimizing system before going there. You don't need your id checked when going to the restaurant or the theater. You need to check someone's id when they take your money and promise you something in return (and even then, there may be a better way).

I don't see a single instance of trade being limited even if all transactions were between established identities.

Do you buy something if you need to send a copy of your id? Do you use a website if it requires Facebook connect?

The issues of tight tracking you mention would be amplified by widespread use of id checks so I think it's essential not to do them often.

Compare this to 3Dconnexion, a maker of expensive 3D mice for CAD software. They rubberized their mice but the rubber decayed after a couple of years (spent $200+ in the 00's and got a gooey piece of junk 3-4 years later). For a decade, they've been ignoring customers and saying the issue was fixed in a later version.

So have one drive with FDE and a USB drive with /boot but in no explicit way configured to boot the first drive?

Or maybe a better setup is an internal drive with /boot and a system stripped from sensitive files then somewhere in the drive an hidden partition (not sure how to avoid the vanilla OS overwriting the hidden partition), then you can either boot the vanilla OS or map the hidden partition and boot from it.

That's what I was trying to avoid to be honest. I'd like to keep the 5000 tabs and the tab containers. Maybe I should try migrating to a new profile. Thanks anyway!

This version is painfully slow for me. Yet, starting with a clean profile seems to do the trick. Does anyone know how to troubleshoot it so I don't need to lose all my configuration. I have only 3 addons, but 5000 tabs/21 windows. Also a decade of random about:config tweaks which I suspect are the cause. Issues started with version 87 but got a lot worse today. (I'm on Ubuntu with mozilla.org binaries, Intel Haswell)

Thank you Mozilla!

edit: this is so bad I can't even scoll through about:config to take a look. Typing this text has a >1s delay. Looks like I'm going to need to bite the bullet.