Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Boulth
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
Boulth
7y ago
Do you know a HSM that use key wrapping and are OpenPGP compatible? I've seen only X.509 compatible ones.
62.
▲
by
Boulth
7y ago
> you might as well move that logic to the packaging system Depends on who do you mean by "you". Software vendor can definitely write a script but they have no power over distributions to "move that logic to the packaging
63.
▲
by
Boulth
7y ago
The problem with deb, rpm, etc is that you need to add instructions to all supported systems one by one. Check out this site for reference: https://www.sublimemerge.com/docs/linux_repositories and compare with curl URL
64.
▲
by
Boulth
7y ago
>Like my email server having to poll every other email server in the world to discover if I have new messages. In AP you don't need to follow anyone to have messages for you delivered directly to your inbox. You have to check other
65.
▲
by
Boulth
7y ago
Note that CTAP and WebAuthn are newer and although they contain U2F for backwards compatibility reasons U2F doesn't contain CTAP2 and WebAuthn. U2F is also surprisingly simple protocol (two specs on FIDO site).
66.
▲
by
Boulth
7y ago
That's right. I'm using this kind of setup on Arch (including Secure Boot signing of the EFI kernel).
67.
▲
by
Boulth
7y ago
Agreed. Two remarks though: mailing lists often mangle messages thus breaking signatures (bad mailing lists!) and not all providers send forensic reports (e.g. Gmail doesn't send spoofed messages). I my case most spoofed messages were.
68.
▲
by
Boulth
7y ago
Yeah but U2F is more secure (non exportable key, non phishable). With AWS OTP is the only viable option.
69.
▲
by
Boulth
7y ago
You don't need signingkey if you have a GPG key with the same email as your git user.email (I guess that's the majority of cases).
70.
▲
by
Boulth
7y ago
Exactly this. And that's why AWS's U2F feature is basically useless. They should've allowed to add multiple keys simultaneously.
71.
▲
by
Boulth
7y ago
> Although I see their point about non-REST, I think there's still a case for having a REST flavour available even if it may not be the most efficient. I was pretty disappointed when I found out how ugly are JMAP requests. I'd
72.
▲
by
Boulth
7y ago
It doesn't have any significant effect in my experience. Maybe it's my browsing habits that I frequently visit a large number of sites that are new (think sites linked from HN).
73.
▲
by
Boulth
7y ago
I agree w.r.t. TB16. While it works (unlike TB15) it's very loud (fan is enabled 90% of time). Generally I'm not fond of XPS 13 (9350) but later firmwares got rid of most issues (except extremely long boot time). On the other hand
74.
▲
by
Boulth
7y ago
I just finished the book and I agree, it's excellent. Although I knew most of the facts reading it from the source in one cohesive work along with the background looks impressive.
75.
▲
Richard Stallman Resigns as FSF President
(stallman.org)
40 points
by
Boulth
7y ago
|
28 comments
76.
▲
by
Boulth
7y ago
Multiple keys: yes, through a config file (can be also useful for team access). I'm not sure about "other forms of credentials" though. Pass is just a simple GnuPG wrapper if gpg can do something pass can do it too.
77.
▲
by
Boulth
7y ago
See sibling comment. Additionally it's possible to use the same Yubikey token on laptop and phone (through NFC or USB). Convenient and secure! Second benefit is Yubikey can hold authentication subkey that can be used to SSH to a server
78.
▲
by
Boulth
7y ago
Too bad that Passbolt doesn't use native GnuPG for decryption. This is technically possible as evidenced by Mailvelope.
79.
▲
by
Boulth
7y ago
Not to mention pass, due to its connection to GnuPG, can protect secrets using Yubikey that require 6 digit PIN (will lock after 3 tries) and touching the blinking dot.
80.
▲
by
Boulth
7y ago
The list definitely is long but I don't see Debian or Archlinux there: https://www.openinventionnetwork.com/community-of-licensees/
81.
▲
by
Boulth
7y ago
I'm using Arch for 2 years (it's my first distro) and I've had only a handful of problems. Usually it's not packaging (deps etc) but rather corner cases and fresh bugs. For example recently kernel had a big that froze di
82.
▲
by
Boulth
7y ago
That's super interesting! I've been pondering better package management tools for a while as the current landscape seems stagnated. I hope some ideas from distri will make their way into mainstream distros. Maybe the more agile on
83.
▲
by
Boulth
7y ago
Exactly. Additionally Microsoft requires vendors to allow disabling Secure Boot on x86 (not so on ARM). I'm on mobile so excuse me the lack of source link.
84.
▲
by
Boulth
7y ago
Seconded. I read Programming Rust and it was excellent. Too bad there is no second part. I didn't get too far in the Rust book though.
85.
▲
by
Boulth
7y ago
The biggest pain point in these security guidelines is context. For example this Array override issue has been fixed in major browsers 11 years ago [0]. Unless someone codes for IE6 I'd consider this not a real problem. [0]: https:&#x
86.
▲
by
Boulth
7y ago
Hiding "www" subdomain looks like an ugly workaround for missing support for DNS SRV records in HTTP/browsers.
87.
▲
by
Boulth
7y ago
Are your org's documents public? I'd be excited to read about the practical effects of such deployment (from CERN too).
88.
▲
by
Boulth
7y ago
Looks good. I'm missing ACME request signing in comparison.
89.
▲
by
Boulth
7y ago
That should be highlighted more. Not using git sendmail is the problem, not format=flowed.
90.
▲
by
Boulth
7y ago
It would be great if you inserted a screenshot of your client in action in the README.md. In my experience screenshots have excellent information density when it comes to evaluating software :)
More ›