Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Borealid
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
14 ms
·
211.
▲
by
Borealid
2y ago
Desktop apps using a UI toolkit like qt, gtk, wpf, etc do by default. The developer needs to do additional work to un-standardize their application.
212.
▲
by
Borealid
2y ago
"Forgejo hosts source code repositories, lets you track and manage issues (and review code changes), and provides all the integrations you'd expect with CI/CD and similar tooling."
213.
▲
by
Borealid
2y ago
Oh, one more thing! > There is no way to name a token to keep track of which one it is Tokens support listing which credentials are stored on them, and most (not 100%, but most) tokens also support storing an arbitrary blob of data at le
214.
▲
by
Borealid
2y ago
I think the passkeys would have remained a great idea if all passkeys were provided either by hardware devices not sold by cloud services vendors, or by software not written by OS vendors. I largely agree with your point, and I don't t
215.
▲
by
Borealid
2y ago
> NFC tokens have basically no security against a close range attacker. How much this matters depends on the threat model. No, the CTAP standard (what FIDO is using for communication with NFC tokens) provides pretty good resistance again
216.
▲
by
Borealid
2y ago
If this is so, could you explain why the dialog for a Google Play Services webauthn login today says "use passkey" (meaning "use google-account-hosted passkey") and "try another way" (meaning "present an o
217.
▲
by
Borealid
2y ago
Have you: A) read the article, paying particular attention to the screenshots therein (ESPECIALLY particularly to the user experience on an Apple device), and B) noted the part of my comment where I say that I should be able to set the choi
218.
▲
by
Borealid
2y ago
No, Apple directly benefits in that users only get the "magical" user experience when using Apple devices. There are two perverse incentives: one for Apple to lock their users into their platform, and one for Apple to implement a
219.
▲
by
Borealid
2y ago
This is extremely obvious in the new FIDO specification for key export, where they neglect to specify the format in which the private keys are encoded. In other words, it's a "standard" designed to let Apple, Google, and Micr
220.
▲
by
Borealid
2y ago
The article author skirts around the key true observation here, which is that passkeys were a great idea until cloud vendors waged war on hardware keys. The concept of a passkey as desired by Yubico was that every user buys a set of hardwar
221.
▲
by
Borealid
2y ago
A Yubikey purchased today actually allows 100 discoverable credentials. Keys running older firmware stored a max of 25.
222.
▲
by
Borealid
2y ago
The huge UI elements are a consequence of optimizing for touchscreens. Mice (and even touchpads) are very precise pointing devices compared to a toddler's chunky fist. Modern UIs are created assuming you'll be using fingers to int
223.
▲
by
Borealid
2y ago
Yes. It's a solved problem for Python with pyenv. Until you want to pin a particular version of Poetry. It's also a solved problem for Ruby with rvm, node with nvm, java with the JDK_HOME env var, Maven with mvnvm, ... Or it'
224.
▲
by
Borealid
2y ago
A venv does not actually install a different Python interpreter. It's bound to the Python version that created it. You cannot make a Python 2.7 venv using a Python 3 interpreter. You need Python 3.10 to create a Python 3.10 venv. There
225.
▲
by
Borealid
2y ago
That doesn't work well (enough) if you have one project that requires Python <3.10 and another that requires Python >=3.10. To really pin everything you'd need to use something like asdf, on top of poetry or a manual virtual
226.
▲
by
Borealid
2y ago
I believe Magisk does this, where upon first launching the app it can "hide" itself by assigning a random package name.
227.
▲
by
Borealid
2y ago
If you only get a few guesses on a bank site, then you can inconvenience large numbers of users cheaply.
228.
▲
by
Borealid
2y ago
I'm just pointing out the logical fallacy in saying "crime rates did not decline faster than elsewhere, therefore the investment was unsuccessful". That observation, alone, doesn't prove anything about the impact had by
229.
▲
by
Borealid
2y ago
Unfortunately, you can't prove the program did not work. If I purchase a can of alligator repellent spray, and after using it I am attacked by one alligator, that isn't proof the spray failed. If I were to have failed to use the s
230.
▲
by
Borealid
2y ago
Thunderbird supports using TLS client certificates or Kerberos as alternatives to a password for IMAP access. When you do choose to store a password locally, it's stored encrypted using a second password of your choice. Since the end r
231.
▲
by
Borealid
2y ago
I used RFC1918 addresses as examples only. 10.7.7.7 shouldn't get dropped, because it's supposed to be routed over the VPN. The DHCP server shouldn't be able to cause VPN-bound traffic to be dropped, in my opinion. As I repli
232.
▲
by
Borealid
2y ago
Okay, I'm glad we've got that sorted out. What I do is put the VPN client into a tagged network namespace (yes, fwmark), and then have a routing rule that makes everything else use a separate routing table. The DHCP server inserts
233.
▲
by
Borealid
2y ago
I don't understand your explanation because you just keep alluding to certain firewall rules but not actually showing them. If you've done this, could you paste an `iptables -L -v` for me? That would make clear exactly what you&#x
234.
▲
by
Borealid
2y ago
I can see how you can write rules that block "bad traffic", but I can't see how you write them so they don't also block some "good traffic" when the network assigns a routing rule. I think the person here might
235.
▲
by
Borealid
2y ago
I think you might be saying to add rules like `iptables -A OUTPUT -d <vpnserver>/32 -j ACCEPT`, `iptables -A OUTPUT -o vpn0 -j ACCEPT`, and `iptables -A OUTPUT -j DROP`. I'm a bit confused though because you only mentioned o
236.
▲
by
Borealid
2y ago
Could you please show me a rule so I can "try it"? I'd love it if this worked. Let's say: - the physical interface name is "wlan0" - the VPN virtual interface name is "tun0" - the VPN server is 10.1.1
237.
▲
by
Borealid
2y ago
I think you missed a step in your progression. Step one, you connect to the network and get routes. Step two, you connect your VPN. Step three, your host starts sending traffic. At this point, your firewall rules are now active and dropping
238.
▲
by
Borealid
2y ago
If you're connected to a random network, whose configuration you don't know in advance, how do you route packets to your VPN server? The usual answer is that the network's router tells you how to do that, by supplying DHCP op
239.
▲
by
Borealid
2y ago
You wrote three different ways to end up with all traffic dropped and a broken VPN connection. Traffic sent to the VPN interface gets encapsulated by the VPN client software and then routed to the Internet. If your firewall rule is dropping
240.
▲
by
Borealid
2y ago
"The packages" are the "the files describing how to go from source code to an organized filesystem hierarchy containing the useful portions of a particular piece of software". That's the good part of nix, much like
More ›