Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
KAMSPioneer
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
31.
▲
by
KAMSPioneer
11mo ago
It's like saying Apple Computers is an Irish company and not a US one because of where they file their corporate taxes.
32.
▲
by
KAMSPioneer
11mo ago
Normally I wouldn't say anything, but since we're on the topic of mixing up two different concepts: I suspect you meant to say "wary." Wary means "cautious," "weary" means "tired."
33.
▲
by
KAMSPioneer
1y ago
Hey, I recognize your username, I bought RCU this year because I wanted to encrypt my reMarkable without losing data. I could have used the cloud or whatever, but I found your software and chose it because it is local-only and FOSS. Also re
34.
▲
by
KAMSPioneer
1y ago
The idea (outlined in the QubesOS documentation) is to clone the git repo of their website, verify the PGP commit signatures, then render the website yourself. Then you can be reasonably sure the website is legitimate, modulo a DoS attack s
35.
▲
by
KAMSPioneer
1y ago
So this attack is to steal my Windows password or Windows Hello credentials, but doesn't get my encryption key...? That's...not ideal, but I think you'll see it's an improvement over unencrypted disks (again, TPMs are fo
36.
▲
by
KAMSPioneer
1y ago
No, GP is misinterpreting Windows's message. It prompts for a recovery key because the TPM is bound to, among other things, Secure Boot == enabled. When Secure Boot is disabled, the TPM notices that and refuses to release the key, that
37.
▲
by
KAMSPioneer
1y ago
> >A server that I want to turn back on all by itself after a power outage can only be done securely with a TPM. > Can you describe how this prevents a MITM attack? I assume you mean a remote server? I've heard of colocation s
38.
▲
by
KAMSPioneer
1y ago
Hard agree. As a new parent, I bought a modern mirrorless camera before my kid was born, and the difference is noticeable. Especially, as you say, around skin details like milia (white spots on a newborn's skin) which often get wiped o
39.
▲
by
KAMSPioneer
1y ago
You can do this by using a dedicated syncoid user and ZFS delegated permissions: https://openzfs.github.io/openzfs-docs/man/master/8/zfs-allo... You'll need to add the --no-elevate-permissions flag
40.
▲
by
KAMSPioneer
1y ago
No, my GP is correct: if the server's RSA private key is compromised it does not allow decryption of any previously-recorded sessions. You would need to compromise the _ephemeral session key_ which is difficult because it is discarded
41.
▲
by
KAMSPioneer
1y ago
I mean, Ansible isn't the best choice for Windows configuration, I would agree, but you're not strictly correct: https://docs.ansible.com/ansible/latest/os_guide/windows_usa...
42.
▲
by
KAMSPioneer
2y ago
Gross and net profit are each their own concept: https://www.investopedia.com/ask/answers/101314/what-are-dif...
43.
▲
by
KAMSPioneer
2y ago
I'm sorry but this is a pet peeve of mine: drag force does not scale exponentially with velocity, it scales with the square of velocity. Your point stands, of course.
44.
▲
by
KAMSPioneer
2y ago
But...you don't need systemd or Quadlets to run Podman, it's just convenient. You can also use podman-compose (I personally don't, but a coworker does and it's reasonable). But yeah I already use a distro with systemd (m
45.
▲
by
KAMSPioneer
2y ago
Podman runs on FreeBSD without systemd, so there you go.
46.
▲
by
KAMSPioneer
2y ago
Well, that's news to me. I don't use consumer routers myself, but I know lots of folks who do. Now, I won't say that I go investigating their home networks, but IPv6 is rather prevalent among the discount ISPs where I live, a
47.
▲
by
KAMSPioneer
2y ago
And? Most consumer routers also implement a stateful firewall with deny-by-default inbound policy. My point is that NAT isn't a security feature, and that firewalls in edge network equipment is table stakes these days.
48.
▲
by
KAMSPioneer
2y ago
Or you can implement a firewall on your gateway device with a default drop policy for inbound traffic. Essentially the same behavior as NAT in terms of unsolicited (usually malicious) inbound traffic, but without the downsides of one-to-man
49.
▲
by
KAMSPioneer
2y ago
It is likely an option, but as per the ReadMe: Nebula uses Elliptic-curve Diffie-Hellman (ECDH) key exchange and AES-256-GCM in its default configuration.
50.
▲
by
KAMSPioneer
2y ago
Read a little further down: > Xiaomi central hub gateway is only available in mainland China. In other regions, it is not available. Nonstarter for many, myself included. ETA: Yes it does say "partial" local control can be done
51.
▲
by
KAMSPioneer
2y ago
It's certainly a different model of deployment. I like it, though it does have its warts. However there is a (community) TF module...? https://registry.terraform.io/providers/Telmate/proxmox/late... (I h
52.
▲
by
KAMSPioneer
2y ago
Your sysadmin will indeed be confused, since ML-KEM public keys are not used for authenticating and are generated by the client and server automatically, analogous to Diffie-Hellman. You can confuse them (albeit much less) when OpenSSH adds
53.
▲
by
KAMSPioneer
2y ago
Can confirm that CBP is worse about this. I once had an agent insist that it was not possible to opt out, because the scan was mandatory. I pointed out that I had walked past no less than four signs proclaiming the opposite (if you are a US
54.
▲
by
KAMSPioneer
2y ago
I mentioned elsewhere in the thread, I (well, my employer) picked up a copy of a book on SELinux System Administration (that's the title) and it has served just this function for me. It won't make you an expert but it takes the vo
55.
▲
by
KAMSPioneer
2y ago
Not excusing that state of documentation by any means, but a good starting point for understanding the actual policy for me was "SELinux System Administration" (ISBN 978-1-80020-147-7). It won't carry you all the way to apply
56.
▲
by
KAMSPioneer
2y ago
But what stops Mallory from simply using this sync method to sync your private key to her Yubikey? I mean, look at the kerfuffle that's been kicked up by this vulnerability, and a key-sharing scheme like the above is much easier to exp
57.
▲
by
KAMSPioneer
2y ago
But that's not the project discussed in the article. Now I'm not saying I agree, but his premise was a Linux-compatible kernel, which Redox most definitely is not. Redox explicitly does not intend to be POSIX, has its own custom (
58.
▲
by
KAMSPioneer
2y ago
That's access control and transport encryption. By encryption I meant the encryption of the private key itself. I would not upload a plaintext private key, especially for privileged account access, even to a server I control.
59.
▲
by
KAMSPioneer
2y ago
Re: hosting your key, I think that's quite reasonable, again, assuming your access control + encryption is good. It's a solid break-glass solution. I would add monitoring that alerts if it is ever used, though. Then you can remedi
60.
▲
by
KAMSPioneer
2y ago
Well great, so I'm addressing nine_k and his question/scenario. As I have been this entire time. And it sounds like you're _agreeing_ that a 30-character random password makes no sense, and a key is easier and better. No? Reg
More ›