Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
OSI-Auflauf
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
OSI-Auflauf
2y ago
This can be boiled down to half a page. Why put in the chatgpt manure to.inflate it.
2.
▲
by
OSI-Auflauf
2y ago
Ugh so much inflated text and self congratulation to something that in the end boils down to trusting you as authority again.
3.
▲
by
OSI-Auflauf
2y ago
https://www.watchvigilantesinc.com/
4.
▲
by
OSI-Auflauf
2y ago
Don't waste your time with dns adblocking. If you are serious about network side blocking do tls interception (lmao) but that is a lot of maintenance, adds other attack surface and the average openwrt device isn't beefy enough for
5.
▲
by
OSI-Auflauf
2y ago
I use wg-quick via the parameterized systemd unit (wg-quick@.service) all the time and never had selinux blocks. Which fedora are you on?
6.
▲
by
OSI-Auflauf
2y ago
Seen devices with IPMI that had by design unauthenticated admin login to the IPMI from the host side that was not removable. They also could flash IPMI firmware from the host. So if your server with such an IPMI is infected you can't t
7.
▲
by
OSI-Auflauf
2y ago
Shoutout to Heads for even attempting to make this. But even that is far from complete. At least the UX is a little better than standard.
8.
▲
by
OSI-Auflauf
2y ago
Lennart is technically doing good work. While his tools are less complicated than the current hilariously convoluted standard boot process, they are still too complicated to use well. He also misses the point with the attack scenarios. If y
9.
▲
by
OSI-Auflauf
2y ago
Many surface brand devices had a toggle in the bios for something like "security level" for years. Which is a switch between Windows signing CA only and Windows signing CA + 3rd party CA. The latter allows shim distros to boot. Yo
10.
▲
by
OSI-Auflauf
2y ago
If firmware not buggy: If Secureboot is set up to use keys which never signed any bootloader that lets you modify the system pre-login.: Then it kind of matters. If you have a gaming board: Firmware integrity checks are mostly e
11.
▲
by
OSI-Auflauf
2y ago
Thats interesting. Are you ok for a 1on1 talk about this topic?
12.
▲
by
OSI-Auflauf
2y ago
Both do that.
13.
▲
by
OSI-Auflauf
2y ago
You compare apples with oranges. Because if you'd compare the apples , you'd notice one of them has no usable E2E. Yes oranges umm phone numbers is a problem. They have that both. Only one can additionally read the contents. Thats
14.
▲
by
OSI-Auflauf
2y ago
Irs super complicated to use. And you need an existing Telegram account to actually handle that cryptocurrency to buy these pseudo-numbers outside of the telephone namespace. Guess what you need to register those. An actual working phone nu
15.
▲
by
OSI-Auflauf
2y ago
That repo is not fully open. Release lag -> Telegram foss needs to wrangle the release every time. Fdroid CI takes its time.
16.
▲
by
OSI-Auflauf
2y ago
Yes and thats why users spend sometimes months on old builds. Also which distro packages Telegram? Fedora doesn't. Debian does but at times it was so old the client crashed from receiving server comms because it wasn't fully compa
17.
▲
by
OSI-Auflauf
2y ago
You need a phone number to sign up for Telegram as well. And you can correlate username to phone number not that hard in most standard setting cases.
18.
▲
by
OSI-Auflauf
2y ago
Telegram Foss clients exist only because of unpaid volunteers that take Telegrams messy mix of open and closed parts and rip closed parts out and replace them. The Telegram organisation is notoriously late to release the source code to thei
19.
▲
by
OSI-Auflauf
2y ago
Because theirs was particularly bad. They xored a server provided nonce in their modified DH scheme making their side able to mitm the key exchanges.
20.
▲
by
OSI-Auflauf
2y ago
Signal has got Usernames now. You can block number discovery. You can't resolve username to number. Your main account ID internally is not your number anymore. If 2 users add you using 2 different links or usernames. Its now harder to
21.
▲
by
OSI-Auflauf
2y ago
On Signal vs Telegram: Telegrams Encryption is off most of the time. They have serverside access to messages. The optional E2E is annoying to use and isnt even available on every platform. For example Tdesktop afaik still has no E2E support
22.
▲
by
OSI-Auflauf
3y ago
> p2p, signing, local first, yadda yadda curl | bash is the recommended way to install.
23.
▲
Ask HN: How do you ensure trust in infra?
3 points
by
OSI-Auflauf
3y ago
|
1 comments
24.
▲
by
OSI-Auflauf
3y ago
When does this come from a not user hostile company?
25.
▲
by
OSI-Auflauf
3y ago
What use is that when the policy is defined by the same person?
26.
▲
by
OSI-Auflauf
3y ago
It seems the Cloudflare extended challenge page. At least it requires turning on JIT in hardened chromium builds which loosely correlates to usage of webassembly.