Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
infokiller
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
infokiller
5y ago
Are you using alternatives to Qubes tools such as the secure clipboard (qvm-copy-to-vm), or just using a lower security setup?
2.
▲
Web Search Navigator: Keyboard Navigation for Google, YouTube, GitHub, Amazon
(github.com)
2 points
by
infokiller
6y ago
|
1 comments
3.
▲
by
infokiller
6y ago
Web Search Navigator is a Chrome/Firefox extension that adds keyboard shortcuts to Google, YouTube, Github, Amazon, Startpage, and Google Scholar. Note that this extension focuses on searching, not general keyboard navigation. For the
4.
▲
by
infokiller
6y ago
Do you mean sharding them using something like Shamir Secret Sharing, splitting in order to be able to transfer/store a large blob, or something else?
5.
▲
by
infokiller
6y ago
Thanks for mentioning the octocouplers implementation, it looks very interesting and I'll look it. Other options I'm aware of to avoid USB and complex drivers/protocols: - Scanning QR codes (for example https://air
6.
▲
by
infokiller
6y ago
> You could do the same thing with the application binary itself and have them compare hashes. This is not scalable to software updates, which happen much more frequently than (long term) key updates. With hashes you would need to publ
7.
▲
by
infokiller
6y ago
> Right. If you already have a secure channel to receive the signing key over, you can just use it to receive the software to begin with. Note that the secure channel sometimes has more limited bandwidth. An example would be reading pa
8.
▲
by
infokiller
6y ago
If you define untrusted software as anything not coming from your distro's official package manager, many people run lots of untrusted software on their Linux systems. Think of PPAs (Debian/Ubuntu/etc), the AUR (Arch/Man
9.
▲
by
infokiller
6y ago
> And where it matters more, hardware compartmentalization. With the caveat that you need to use secure air-gapped communication, and you probably want to use Qubes on each of the separate machines as well [1]. [1] https://w
10.
▲
by
infokiller
6y ago
While I can appreciate your vision, that seems too detached from the current reality. Software development is a highly distributed system with many human participants with different (and sometimes conflicting) goals and skills. And to make
11.
▲
by
infokiller
6y ago
> Xorg already provides a full suite of security protocols that allow fine grained control over every aspect of any application down to the single pixmap via access control hooks. One notable exception is OpenSSH, which uses the SECURI
12.
▲
by
infokiller
6y ago
I agree that Android app security model is much better than desktop Linux (of course, they had the privilege of designing a new system without backward compatibility concerns and after learning lessons from other systems). The main issue wi
13.
▲
by
infokiller
6y ago
Signatures are meaningful when the keys are more secure than the servers hosting the data. If you download software from a hacked server that serves you malware, the signature check will fail. In contrast, the execute bit can be changed by
14.
▲
by
infokiller
6y ago
I think it's unlikely that pip will be able to easily install something like Sage anytime soon, but one could use conda [1] which is pretty popular in the scientific community, or alternatively docker [2]. It also seems there's su
15.
▲
by
infokiller
7y ago
Even if the security is not significantly enhanced over a content blocker, tracking using JS will be much harder (assuming the cloud device is randomized in some way).
16.
▲
by
infokiller
7y ago
May I suggest adding an options page to configure the keybindings (and store them in browser.storage.sync)? Happy to send a PR.
17.
▲
Show HN: Google Search Navigator – navigate Google like a boss
(github.com)
9 points
by
infokiller
8y ago
|
2 comments