You can also get antennas with suction cups. I have used this before to get 4G internet in a house with no access downstairs, by sticking the antenna on an upstairs window.
An outdoor antenna would be better, but yeah more of a pain. I guess it really depends on how badly someone wants SMS.
If cell service is available in at least one area of the property, you could have a dedicated sim for receiving SMS 2FA and use a 4G router to forward the SMS to an email, e.g. Teltonika have this functionality [1].
The 4G router also has the benefit of being able to use externally mounted antennas. Which might help in low signal areas.
Not ideal, but might at least be a solution for some people.
Agree. Passkey should be reserved for credentials that can be synced or exported to different providers, as this is what is most analogous to a password from a user perspective.
There should be a different standardized term used for hardware bound keys. So users wont get confused.
I wish Yubikey allowed users to import their own FIDO2/webauthn seed and overwrite the factory generated one, and then also allow the resident passkey functionality to be disabled.
It should be up to the user if they want to have multiple duplicate hardware authenticators and be able to backup their seed however they wish.
Usernameless always seemed like an optimization too far to me.
I think it's totally reasonable, and probably a good thing for users having to use their username at login. Especially as it reminds them what username they are using for that service.
I could totally see a situation where a user uses a Usernameless passkey for years to access a service and for some reason loses access to the Usernameless passkey, and then has also forgotten the username for the service, so cannot even start an account recovery process.
"New firmware-based battery charge control, which offers fixed a 75%/80% threshold setting. To use this, you need to update your system firmware to at least version 13.0, which you can do by simply updating your macOS partition to at least that version or newer. This new charge control method also works in sleep mode."
This is interesting, am I correct in thinking this a feature implemented by Apple and now supported by the Asahi team? Does that mean that macOS supports this charge control feature?
I really hope Apple brings the same charge limiting to iPhone as well.
Sorry to hear you lost access to the document, I hope you can regain access.
It might be be a good idea to use a tool like Rclone to create a local copy of the data going forward. It allows you to download Google sheets as .xlsx files.
At least as I understand it, in implementations like yubikey the FIDO2 secret is baked-in to the yubikey for security, which is good as it shouldn't be possible to remove the private key.
However the main issue I have is that the user cannot import their own secret into the yubikey, so you cannot choose to use your own secret vs the factory generated one, or choose to have multiple yubikeys using the same secret, which would be useful as you wouldnt need to enrol multiple secrets with each service.
It should be possible to enable Cloud Identity Free on your gsuite tenant. So you can use a free identity account for your admin account and only pay for gsuite on your main email account.
Maybe they should look at hosting at 1984.is instead, as they seem to have a more robust policy in place regarding take downs:
"Unwavering loyalty to our customers and their fundamental rights is a core value of 1984, hence the name to remind us of what can happen if we fall asleep on our watch. We state that 1984 as a company and its officers will always go the extra mile to protect our customers' civil rights, including the freedom of expression, the freedom of the press, the right to anonymity and privacy. 1984 will always do everything within its legal power to inform our customers of any inquiries from any authorities, lawyers or courts into the customer's affairs that we may become aware of. It is essential that the jurisdiction that the company operates in is Iceland, where the IMMI legislation is forthcoming, making Iceland a haven for freedom of the press and freedom of expression in general." [1]
The hydrogen client for matrix.org (1) has an interesting approach using vanilla JavaScript and indexeddb.
From a previous this week in matrix(2): "Hydrogen tries to be the lightest Element. It is written entirely in vanilla javascript (no React, no Webpack) for complete control, structured as an MVVM app, leveraging the raw performance of indexeddb."
If the boards contained personally identifiable information and then that data was transferred so that other people could access it, wouldn't that be considered a data breach?
I guess people affected by this could submit a subject access request to get their data back.