Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
throwawayKiwi9
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
throwawayKiwi9
4y ago
I recently searched "best chair posture" and was saddened to see almost the entire first page as affiliate blog top-10 garbage. I could have worded the query more clearly, absolutely, but it's a shame that our world's gr
2.
▲
by
throwawayKiwi9
4y ago
So, clearly not enough time or experience to make scientifically false statements about an entire country of nearly 90 million people, many of which are much smarter than you or I. I don't doubt that problems exist. And I'm sorry
3.
▲
by
throwawayKiwi9
4y ago
So no account for the "genetic" intelligence required to navigate such a society intelligently? You have some extremely disgusting conclusions that aren't based in facts but merely extremely prejudice and racist conjecture am
4.
▲
by
throwawayKiwi9
4y ago
I think the US is much more inclined to use parallel construction and the full extent of the legal system to bring down someone, which while can be similar, is not quite the same as someone simply never being seen again.
5.
▲
by
throwawayKiwi9
4y ago
Pretty cool to set WASM support added now. I may have to revisit the game to grind out golang & rust syntax skills, depending on how difficult it is to use in practice
6.
▲
by
throwawayKiwi9
4y ago
A lot of people who have dealt with much worse volatility in their national currency thought it was a good idea. Many national currencies have performed so much worse than this.
7.
▲
by
throwawayKiwi9
4y ago
If these are VOIP then, sadly, these already won't work with a huge number of services.
8.
▲
by
throwawayKiwi9
4y ago
There's tons of land unused in the US. But I also agree with you. I haven't played with this one yet, but it looks very nice for automated hydroponic setups. https://github.com/kizniche/Mycodo
9.
▲
by
throwawayKiwi9
4y ago
Lmao. Microsoft has a few great open source projects out I'd say. This seems promising to me. But yeah the Azure setup docs look a little easier here, and they mention promoting Azure usage for the backend in this post . Thank God they
10.
▲
by
throwawayKiwi9
4y ago
I see the server hardware requirements, but what about all the sensors/drones/other equipment? I'm curious how much a base working setup would cost.
11.
▲
by
throwawayKiwi9
4y ago
For what it's worth, the whitepaper for their VPN makes some pretty strong claims to user privacy, with the VPN client being open source. Normally Google's privacy policies are fairly vague, but this seems to be very clear about t
12.
▲
by
throwawayKiwi9
4y ago
Chromebooks offer some of the best consumer grade security around for PC hardware. Coreboot, firmware tamper detections, Disk encryption, tightened RBAC, kvm virtualization, lxc containerization, seamless a/b partition updating, option
13.
▲
by
throwawayKiwi9
4y ago
At least from a design perspective, I would highly encourage users to check out Secure Scuttlebutt. It solves many problems highlighted here. Dominic Tarr really did some excellent work building it.
14.
▲
by
throwawayKiwi9
4y ago
Anyone could have easily just downloaded the nonfree iso. However, I think it's so very important that we can simply say "Just go install Debian" to anyone just looking for a rock solid OS.
15.
▲
by
throwawayKiwi9
4y ago
Or even autocrypt integrated directly.
16.
▲
by
throwawayKiwi9
4y ago
I like their pricing structure for bulk accounts. What I'd absolutely love to see is more email services that are Protonmail compatible, utilizing WKD or whatever it they need. Here's something to look at anyway https:/&#x
17.
▲
by
throwawayKiwi9
4y ago
I have worked for a few school districts and the security has always been very poor. Nobody really hardened Windows too much, leaving the attack surface wide open. In grade 8 I discovered blank admin creds. In grade 12 trivially pwned our g
18.
▲
by
throwawayKiwi9
4y ago
Did you skim over the part where there's a toggle to strictly prevent sending messages to unauthorized devices?
19.
▲
by
throwawayKiwi9
4y ago
I agree wholeheartedly and this is why I use Matrix. The fact that a vulnerabilitiy of this magnitude can largely be defeated with precautions, albeit non ideal, are a real testament to the power of e2e. Hopefully we will see the fixes thes
20.
▲
by
throwawayKiwi9
4y ago
You mean, allowed to decrypt unless following the discussed mitigations? I suspect you don't regularly use the client, which is fine, but these warnings and notifications are very annoying and essentially impossible to ignore. You are
21.
▲
by
throwawayKiwi9
4y ago
Yes. I have used Matrix professionally for years and it's pretty simple for me to understand and follow what is unnecessarily editorialized here to keep my conversations safe. I don't understand why this language is not being simp
22.
▲
by
throwawayKiwi9
4y ago
Yes? https://news.ycombinator.com/item?id=33024640
23.
▲
by
throwawayKiwi9
4y ago
"if you follow these instructions without fail, Matrix can provide you with confidentiality and authentication." I was hoping the researchers could clarify these simple mitigation instructions to protect users, assuming they alre
24.
▲
by
throwawayKiwi9
4y ago
Your suggesting to use Slack, where a similar compromise would reveal your entire account message history.. ? Just enforce proper key verification for now and you're fine..
25.
▲
by
throwawayKiwi9
4y ago
Looks like it would only be "likely to go unnoticed" for users that regularly disregard the massive annoying warnings about unverified devices and don't enforce verification
26.
▲
by
throwawayKiwi9
4y ago
It still looks like users that enable the previously mentioned option and/or verify sessions accordingly are fine. I'm just trying to clarify a simple guideline for users looking to continue using Matrix securely with confidence.
27.
▲
by
throwawayKiwi9
4y ago
Yes, Element is very loud about unverified device participants in an encrypted room.
28.
▲
by
throwawayKiwi9
4y ago
Yes, FydeOS is a ChromiumOS fork with their own login server and Android support. They recently open-sourced their base build (including Pi image overlay) on OpenFyde.io
29.
▲
by
throwawayKiwi9
4y ago
Thanks for your work! So a user can mitigate this by keeping encryption enabled and also enabling the option to never send encrypted messages to unverified sessions?
30.
▲
by
throwawayKiwi9
4y ago
No, there are not vulnerabilities in Matrix's encryption. Homeservers are not decrypting all your messages, which is what the subheading seems to suggest. A specific client js library implementation used in Element could have been expl
More ›