Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
kenniskrag
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
4 ms
·
1.
▲
by
kenniskrag
12d ago
Certification takes time and probably overlaped with the phone development. Fairephone is small compared to e.g. samsung and they describe themself more "stable" and long-term support than bleeding edge.
2.
▲
by
kenniskrag
13d ago
Because a lot of things is public online and can't be copied and sold e.g. due to copyright, patents and trademark. Also if you access a website you are bound to a ToS contract and this is a breach of that contract.
3.
▲
by
kenniskrag
27d ago
Yes. In this case probably not fineeprinting is not allowed because not strictly necessary (cookie law) and therefore needs consent from user.
4.
▲
by
kenniskrag
27d ago
Yes. In this case probably not allowed because not strictly necessary (cookie law) and therefore needs consent from user.
5.
▲
by
kenniskrag
1mo ago
The problem with this analogy is responsibility. Same set of problems if you have a self driving car imho. Not?
6.
▲
by
kenniskrag
1mo ago
If you publish the bug then it could be unfair competition in my opinion. There was a product test where the mentioned some flaws of a medicine but didnt mention other producers of same drug. They broke the UC rules and paid some money: ht
7.
▲
by
kenniskrag
1mo ago
If you access "private" data it's also unlawful acording to 143. Pentesting is a hot topic but there are comapnys acusing you of hacking if you send them a security report (hacking). If they mention a bug bounty program then
8.
▲
by
kenniskrag
1mo ago
In switzerland it depends 143bis StGB: Any person who, with the intention of securing an unlawful gain for themselves or another obtains for themselves or another data that are stored or transmitted electronically or in some similar manner
9.
▲
by
kenniskrag
2mo ago
Env variables are considered best practice (factor 3): https://developer.ibm.com/articles/creating-a-12-factor-appl... If I would avoid env then i need to put it in some kind of conf file and configure the app to read
10.
▲
by
kenniskrag
2mo ago
Why should that help to have no env variables?
11.
▲
by
kenniskrag
2mo ago
I just use my home router as VPN to not care if the 100 apps om my phone have a working encryption. I also use it to access my home services so that they are not exposed to the internet. I also use it to limit exposure on my VMs on a cloud
12.
▲
by
kenniskrag
2mo ago
Exists randomness or is it just lack of information? :)
13.
▲
by
kenniskrag
2mo ago
I think compression would reduce the problem not? I think if you swap the wire format to something like jsonb you would need to parse it again anyway and pay the cpu time.
14.
▲
by
kenniskrag
4mo ago
acme.sh supports multiple CAs there is even a RFC for CAs that describe the api.
15.
▲
by
kenniskrag
4mo ago
I would define high as "double time needed to fix a dns issue" and account for weekends
16.
▲
by
kenniskrag
5mo ago
What's the threat model. Where do you store the decryption key? E.g. if my app needs a db connection I can ask a vault service but I need creds for that. The vault service can rotate the creds very fast but is it addition security.
17.
▲
by
kenniskrag
5mo ago
Edit: Banking has no selfservice password reset. A lot of work for customer support due to identification. Nobody wants to do that for free and if the accounts are freenyou may get DOSed by bots which trigger passwort resets.
18.
▲
by
kenniskrag
5mo ago
> But then your hardware dies A lot of services have password reset email features. If the email account has passkey you're screwed. But restore by snail mail can be possible but slow (for paid services). More secure? Don't kno
19.
▲
by
kenniskrag
5mo ago
Pull request to notify on setup (2 weeks old): https://github.com/mastodon/mastodon/pull/38548
20.
▲
Mastodon: Don't use "Mastodon" or "mstdn" in domain names
(github.com)
4 points
by
kenniskrag
5mo ago
|
8 comments
21.
▲
by
kenniskrag
5mo ago
Is that legal? Do you avoid uploading somehow?
22.
▲
by
kenniskrag
7mo ago
Not if the advertise zero knowledge encryption. As far as I understand the password sharing / collaboration feature is often the problem. Second: The provider can get the passwords with a simple server change.
23.
▲
by
kenniskrag
7mo ago
> Much like the other products we analyse, 1Password lacks authentication of public keys. This trivially enables sharing attacks similar to BW09, LP07 and DL02, something that the 1Password whitepaper... > IMPACT. Complete compromise
24.
▲
by
kenniskrag
7mo ago
In europe you need identification to buy a sim or esim. https://www.reddit.com/r/europe/comments/9ziqfi/european_cou...
25.
▲
by
kenniskrag
2y ago
> online access is as necessary as water We have paper money and also can work and buy stuff offline. I would say online access is as necessary as a car. Possible without but less flexible.
26.
▲
by
kenniskrag
2y ago
Driving licence is a bad argument because there is public transportation service. If you're reckless or have other issues the licence is revoked.
27.
▲
by
kenniskrag
2y ago
One reason was, that the security model wasn't enough anymore. E.g. every application was trusted and can listen to key inputs e.g. steal passwords and credit card infos. Btw there was an issue that screenshotting in wayland was not po
28.
▲
by
kenniskrag
2y ago
One of these: https://media.pearsoncmg.com/bc/abp/cs-resources/products/se...
29.
▲
by
kenniskrag
2y ago
qutebrowser does that. https://en.m.wikipedia.org/wiki/Qutebrowser
30.
▲
by
kenniskrag
2y ago
Which ones? I try to learn how these systems work
More ›