Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
Liskni_si
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
1.
▲
by
Liskni_si
4mo ago
2007 is when xrandr 1.2 came and made it feasible to use on a laptop - enable/disable outputs dynamically without restarting X. Xinerama (the extension that enables one virtual screen over multiple outputs) existed before but the layou
2.
▲
by
Liskni_si
4mo ago
> So realistically no application did this. Old versions of GIMP (back when the toolbars etc. were separate windows) used to let you move any of its windows to a different X screen. And by "move" I don't mean drag - there
3.
▲
by
Liskni_si
4mo ago
What about this (actively maintained) fork of uBO that polyfills some MV2 APIs to make uBO work as an MV3 extension: https://github.com/r58playz/uBlock-mv3 Anyone tried that?
4.
▲
by
Liskni_si
4mo ago
I'm somewhat aware of some of this but also... External keyboard only works if you're using the laptop as a desktop computer. It's not really practical if one uses a laptop as a laptop. And yeah I know there are people luggin
5.
▲
by
Liskni_si
4mo ago
Not just hard - impossible. To the point of making it harder to find a job, as very few jobs let you use a non-Windows ThinkPad. (I mean yeah, of course AuDHD makes it harder to find a job, no surprise there. But it's a shame that lapt
6.
▲
by
Liskni_si
4mo ago
Anyone else still using the 7x13 "misc fixed" font that comes with X11? I just can't switch. Perfectly readable on both 14" 1920×1200 and 35" 3440×1440. Yes it's small but that's kinda the point. The only
7.
▲
by
Liskni_si
6mo ago
What if "the IT department" is just this one guy who asks me to Cc him an invoice when I buy a laptop and that's the end of it? (yes that's a real story from my career, and the company was 100+ employees at the time)
8.
▲
by
Liskni_si
6mo ago
> But they won't get your private key. Indeed, that was my point exactly a couple posts up the thread. :-) > you may realise that something wrong happened I think I can iterate on the exact mechanics to make this less likely. I m
9.
▲
by
Liskni_si
6mo ago
Okay let me elaborate how I envision that attack to work: 1. attacker wants to use your yubikey-backed ssh key, let's say for running ssh-copy-id once with their own key so they can gain access to your server 2. thus they need to trick
10.
▲
by
Liskni_si
6mo ago
Perhaps one extra bit to add: you've mentioned consuming slots on the device - that's what happens if you generate a resident key. Those keys live on the device and can be used from any computer you plug them into, without having
11.
▲
by
Liskni_si
6mo ago
Well I wasn't talking about ssh keys at all - that's where the misunderstanding comes from. I was simply trying to counter your claim that TPMs are never ever useful for individuals. They can be useful to individuals worried about
12.
▲
by
Liskni_si
6mo ago
I don't see how entering a passphrase into a compromised boot loader/kernel/initramfs is as safe as a measured boot with TPM providing the decryption key only if nothing seems to have been tampered with. Can you elaborate ple
13.
▲
by
Liskni_si
6mo ago
I really don't think this is true for FIDO2 like Yubikey. My understanding is that your ssh client gets a challenge from the server, reads the key "handle" from the private key file, and sends both to Yubikey. The device then
14.
▲
by
Liskni_si
6mo ago
Yeah but they already mentioned that they expect the attacker to hijack your ssh command so you'll touch it yourself, thinking you're authorizing something else than you actually are. It does mean that they can't use the key
15.
▲
by
Liskni_si
6mo ago
Fair point. Ubuntu 18.04 won't support this. :-)
16.
▲
by
Liskni_si
6mo ago
TPMs can be useful to you as an individual if you're trying to protect against an evil maid attack. Although I think Linux isn't quite there yet with its support for it. The systemd folks are making progress though.
17.
▲
by
Liskni_si
6mo ago
They can use the key as long as they can access your computer, but they shouldn't be able to get the secret key out of the TPM or Yubikey and use it elsewhere while your computer is off. That's the main point of HSMs.
18.
▲
by
Liskni_si
6mo ago
It's also a bit outdated. OpenSSH supports FIDO2 natively, so all this gnupg stuff is unnecessary for ssh. One can even use yubikey-backed ssh keys for commit signing. And the best thing is that you can create several different ssh key
19.
▲
by
Liskni_si
6mo ago
Many of those are "Merge branch 'master' into armanc/subtitle-sync-refactor". Rebasing the PR on top of master would bring that down to like 15 or something.
20.
▲
by
Liskni_si
6mo ago
It's awesome that they're adding a UI for stacked branches¹! The UX of the CLI tool seems weird, though. Why do I need to explicitly create and add branches to the stack if all I really want is to open PRs from my commits? Here&#x
21.
▲
by
Liskni_si
6mo ago
They haven't fixed the fork issue, the FAQ clarifies this. I suspect the target audience is squash merging corpos. Everyone else can just do normal PRs with atomic commits reviewed individually...
22.
▲
by
Liskni_si
6mo ago
Not a single one, but it can be done with 2. Assuming you're currently on the most recent branch (furthest from the trunk), `git rebase -i --update-refs trunk` will rebase all the intermediate branches. If you need to make a change to
23.
▲
by
Liskni_si
6mo ago
That's not that unusual though. Many countries' age of consent is ~15 so you can legally do it sooner than you can film it.
24.
▲
by
Liskni_si
6mo ago
I tried to do something similar well over a decade ago during an internal hackathon (the motivation back then being speeding up destructive integration tests). My idea was to have the memory be a file on tmpfs, and simply `cp --reflink` to
25.
▲
by
Liskni_si
9mo ago
You can comment on the individual commits' changes, but you can't comment on the commit (e.g. its message) itself. I believe you can do this in Gerrit.
26.
▲
by
Liskni_si
9mo ago
Happens on merge, sure, but the end result is that you kinda lose the individual commits. You can still find them in the PR, but you won't see them in the git history, so git blame will just point you to the one big squashed commit. If
27.
▲
by
Liskni_si
9mo ago
You do if you find yourself in a team where PRs are squash-merged. :-(
28.
▲
by
Liskni_si
9mo ago
I've seen porn in Google's own Chrome too.
29.
▲
by
Liskni_si
1y ago
In general, yes, it is easier to exfiltrate the token because if you can control some of the code that runs with the token available as an env var, you can do whatever. In the specific case of the attack described in the blog post, though,
30.
▲
by
Liskni_si
1y ago
If you can change a GitHub Actions workflow to exfiltrate a token, what prevents you from changing the workflow that uses Trusted Publishing to make changes to the package before publishing it? Perhaps by adding an innocent looking use of a
More ›