HN user

vanburen

4,747 karma
Posts346
Comments33
View on HN
www.tomshardware.com 6d ago

Linus Torvalds rebukes anti-AI stances in the Linux kernel code review process

vanburen
4pts1
www.tomshardware.com 1mo ago

New one-meter-cubed 3D printer pumps out large-scale prints at 3kg an hour

vanburen
3pts0
www.tomshardware.com 2mo ago

Claude-powered AI coding agent deletes company database in 9 seconds

vanburen
33pts14
www.engadget.com 3mo ago

Donut Lab's battery claims reportedly subject of whistleblower complaint

vanburen
1pts0
www.tomshardware.com 4mo ago

Claude Code deletes developers' production setup, including database

vanburen
43pts28
www.macrumors.com 4mo ago

Apple Announces Low-Cost 'MacBook Neo' with A18 Pro Chip

vanburen
80pts3
www.tomshardware.com 4mo ago

Intel's make-or-break 18A process node debuts for data center with 288-core Xeon

vanburen
301pts294
arstechnica.com 5mo ago

Nvidia's 10-year effort to make the Shield TV the most updated Android

vanburen
21pts3
www.bagaag.com 5mo ago

Todoist Actual Backup

vanburen
1pts0
www.youtube.com 6mo ago

My PC running directly from Batteries [video]

vanburen
2pts0
www.extremetech.com 7mo ago

Company Thinks It Can Power AI Data Centers with Supersonic Jet Engines

vanburen
1pts1
arstechnica.com 7mo ago

After years of resisting it, SpaceX now plans to go public. Why?

vanburen
10pts2
videocardz.com 7mo ago

WebGPU is now supported by all major browsers

vanburen
2pts0
www.phonearena.com 8mo ago

T-Mobile customers with 4G-only and early 5G phones will soon need to upgrade

vanburen
2pts0
www.theregister.com 8mo ago

UK government on the lookout for bargain-priced CTO

vanburen
6pts1
www.youtube.com 9mo ago

New Anti-Tailgating Camera Reveals Statistics [video]

vanburen
5pts0
simwood.com 11mo ago

WhatsApp have just fixed the PSTN (and simultaneously killed it)

vanburen
2pts0
www.engadget.com 11mo ago

Google announces first nuclear site to power its data centers

vanburen
2pts1
www.ghacks.net 1y ago

Google says hackers used app specific passwords to bypass MFA

vanburen
1pts1
www.gov.uk 1y ago

UK Gov enables drivers to use preferred apps in all car parks

vanburen
8pts3
www.youtube.com 1y ago

Why Trump's tariff chaos makes sense (big picture) [video]

vanburen
8pts0
upgradedpoints.com 1y ago

Where in the U.S. Does Middle-Class Income Stretch the Furthest?

vanburen
9pts8
www.brentozar.com 1y ago

The Problem with SQL Server's Licensing Costs (2023)

vanburen
2pts0
bitwarden.com 1y ago

Security vendors join forces to make passkeys more portable for everyone

vanburen
3pts1
www.anandtech.com 1y ago

Kioxia Demonstrates Raid Offload Scheme for NVMe Drives

vanburen
36pts53
www.youtube.com 2y ago

Most HEPA Air Purifiers Are a Scam (There's a Better Option) [video]

vanburen
2pts0
www.tomshardware.com 2y ago

US sanctions PC cooling and power supply maker DeepCool for selling to Russia

vanburen
7pts0
www.extremetech.com 2y ago

MSI to Announce CAMM2 Memory for Desktops at Computex

vanburen
4pts0
arstechnica.com 2y ago

Analyst on Starlink's rapid rise: "Nothing short of mind-blowing"

vanburen
3pts0
www.ubicept.com 2y ago

Synthesizing audio from 7200 FPS video (2023)

vanburen
2pts0

You can also get antennas with suction cups. I have used this before to get 4G internet in a house with no access downstairs, by sticking the antenna on an upstairs window.

An outdoor antenna would be better, but yeah more of a pain. I guess it really depends on how badly someone wants SMS.

If cell service is available in at least one area of the property, you could have a dedicated sim for receiving SMS 2FA and use a 4G router to forward the SMS to an email, e.g. Teltonika have this functionality [1].

The 4G router also has the benefit of being able to use externally mounted antennas. Which might help in low signal areas.

Not ideal, but might at least be a solution for some people.

[1] https://wiki.teltonika-networks.com/view/SMS_Forwarding_Conf...

Totally agree with this.

I wish Yubikey allowed users to import their own FIDO2/webauthn seed and overwrite the factory generated one, and then also allow the resident passkey functionality to be disabled.

It should be up to the user if they want to have multiple duplicate hardware authenticators and be able to backup their seed however they wish.

Usernameless always seemed like an optimization too far to me.

I think it's totally reasonable, and probably a good thing for users having to use their username at login. Especially as it reminds them what username they are using for that service.

I could totally see a situation where a user uses a Usernameless passkey for years to access a service and for some reason loses access to the Usernameless passkey, and then has also forgotten the username for the service, so cannot even start an account recovery process.

"New firmware-based battery charge control, which offers fixed a 75%/80% threshold setting. To use this, you need to update your system firmware to at least version 13.0, which you can do by simply updating your macOS partition to at least that version or newer. This new charge control method also works in sleep mode."

This is interesting, am I correct in thinking this a feature implemented by Apple and now supported by the Asahi team? Does that mean that macOS supports this charge control feature?

I really hope Apple brings the same charge limiting to iPhone as well.

FIDO Alliance 4 years ago

Personally I would store it in a Keepass DB stored offline on a USB drive, in a safe location.

FIDO Alliance 4 years ago

At least as I understand it, in implementations like yubikey the FIDO2 secret is baked-in to the yubikey for security, which is good as it shouldn't be possible to remove the private key.

However the main issue I have is that the user cannot import their own secret into the yubikey, so you cannot choose to use your own secret vs the factory generated one, or choose to have multiple yubikeys using the same secret, which would be useful as you wouldnt need to enrol multiple secrets with each service.

Examining Btrfs 5 years ago

I think Synology runs BTRFS on top of LVM, so that may mitigate some of the issues.

"24 words written on paper."

That's cool, I didn't realise it was possible to backup the webauthn secret this way.

I googled but couldn't find any documentation on how to set this up, could you let me know how you set this up?

Not being able to make backup of the Webauthn secret is why I have stuck with TOTP so far.

Maybe they should look at hosting at 1984.is instead, as they seem to have a more robust policy in place regarding take downs:

"Unwavering loyalty to our customers and their fundamental rights is a core value of 1984, hence the name to remind us of what can happen if we fall asleep on our watch. We state that 1984 as a company and its officers will always go the extra mile to protect our customers' civil rights, including the freedom of expression, the freedom of the press, the right to anonymity and privacy. 1984 will always do everything within its legal power to inform our customers of any inquiries from any authorities, lawyers or courts into the customer's affairs that we may become aware of. It is essential that the jurisdiction that the company operates in is Iceland, where the IMMI legislation is forthcoming, making Iceland a haven for freedom of the press and freedom of expression in general." [1]

[1] https://www.1984.is/about/

If Not SPAs, What? 6 years ago

The hydrogen client for matrix.org (1) has an interesting approach using vanilla JavaScript and indexeddb.

From a previous this week in matrix(2): "Hydrogen tries to be the lightest Element. It is written entirely in vanilla javascript (no React, no Webpack) for complete control, structured as an MVVM app, leveraging the raw performance of indexeddb."

(1) https://github.com/vector-im/hydrogen-web (2)https://matrix.org/blog/2020/08/14/this-week-in-matrix-2020-...

Agree, it would of been better to focus on a name where getting the .com was feasible. At least element is better than riot.

If the boards contained personally identifiable information and then that data was transferred so that other people could access it, wouldn't that be considered a data breach?

I guess people affected by this could submit a subject access request to get their data back.