Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
dbrgn
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
18 ms
·
211.
▲
by
dbrgn
5y ago
This is mostly about updates (TOFU): If the OS installs the update, then you know it comes from the same developer.
212.
▲
by
dbrgn
5y ago
Post-build modifications are the whole point of App Bundles :) See https://developer.android.com/platform/technology/app-bundle... for details.
213.
▲
by
dbrgn
5y ago
In the case of Debian and F-Droid, they do so transparently, often with reproducible builds. The fact that packages are signed by those groups is one of the reasons why they are trusted. I would not consider "signed automatically by Go
214.
▲
by
dbrgn
5y ago
Can it? Does it run with root permissions? (Honest question, I don't know.) If it's bound by the OS permission system and doesn't have full root, it might be able to replace apps with another version that is signed by a diffe
215.
▲
by
dbrgn
5y ago
The keys aren't surfaced, but a TOFU (trust on first use) model applies. If a new APK is signed by a different signing key, the OS will reject the update. To my knowledge, the only way to force-install an update signed with a new signi
216.
▲
by
dbrgn
5y ago
Yup, I'm pretty sure this makes reproducible builds totally impractical for any apps installed through the Play Store. Apps that currently provide reproducible builds: Signal, Threema, Telegram. (Probably others as well.)
217.
▲
by
dbrgn
5y ago
In contrast to Omnisec and Crypto AG with their security by obscurity, the Threema apps are fully open source with reproducible builds: https://threema.ch/en/open-source/
218.
▲
by
dbrgn
5y ago
> 2) No emoji colors Colored emoji are working fine in my alacritty terminal. Here's my fontconfig file: https://github.com/dbrgn/dotfiles/blob/master/fonts.conf
219.
▲
by
dbrgn
5y ago
Yes, it's very simplistic. It does not claim otherwise. However, it did manage to detect a rootkit on one of my system once (many years ago, when I used to phpMyAdmin, which had some kind of RCE). So it's better than nothing, and
220.
▲
by
dbrgn
5y ago
This is called the "RAS Syndrome" (where "RAS" stands for "redundant acronym syndrome"): https://en.wikipedia.org/wiki/RAS_syndrome
221.
▲
by
dbrgn
5y ago
rkhunter and samhain are two other similar tools. Both are available in the regular Debian repositories.
222.
▲
by
dbrgn
5y ago
> But any dynamically fetched code/modules/packages will suffer the same risk. A package manager usually employs signatures. In that case, the problem could have been avoided (unless the signing process itself is also compromis
223.
▲
by
dbrgn
5y ago
How would they do that? The bash script is a static file on a public host. Users can simply download it, without Codecov knowing about the repos it's being used in. Never automatically download any remote code without at least checking
224.
▲
by
dbrgn
5y ago
Public key signatures would be even better. Then you only need to install / audit / trust the public key once, versus updating the checksum for every new release. Of course, this assumes that signing isn't compromised too, if
225.
▲
by
dbrgn
5y ago
There's a Rust RFC and Linus doesn't hate it. Great news!
226.
▲
by
dbrgn
5y ago
There are a lot of weird "clones". I wouldn't say that Matomo is a Google Analytics clone, until recently it didn't even have an import function. I wouldn't say that Bitwarden is a LastPass clone. It's simply a
227.
▲
by
dbrgn
5y ago
Note that Grammarly is essentially a keylogger. The content you're typing gets sent to their servers. It doesn't work like your typical client-side spellchecker. Their business model may be OK, it's just something that you ne
228.
▲
by
dbrgn
5y ago
Chrome is owned by a US company, so no guarantee about backdoors for the NSA since it's not fully open source.
229.
▲
by
dbrgn
6y ago
There are more examples. Mitsubishi Pajero is called Mitsubishi Montero in some spanish-speaking countries since Pajero means "wanker". In Switzerland, Nestlé rebranded their "Fuze Tea" to "Fuse Tea" since if y
230.
▲
by
dbrgn
6y ago
I have not yet read in detail how you use SGX. But setting up SGX requires complicated processes and signing contracts and other paperwork with Intel. (Correct me if this is wrong.) Given that setting up the "systems" requires a h
231.
▲
by
dbrgn
6y ago
This might be a legitimate reason to keep the source code non-public temporarily. However, the communication strategy by Signal about this was horrible (or rather non-existent). People in the user forum ( https://community.signalu
232.
▲
by
dbrgn
6y ago
MobileCoin was advised by Moxie, Signal integrates MobileCoin and the footer at https://www.mobilecoin.com/ states "MobileCoin uses and recommends Signal Private Messenger". There certainly seems to be a link, and
233.
▲
by
dbrgn
6y ago
Whoa, SE looks incredible. Thanks for your work on that! Are there any plans to support non-English ebooks as well? Edit: Regarding non-English ebooks, I was thinking about books like "Der Vogelflug als Grundlage der Fliegekunst"
234.
▲
by
dbrgn
6y ago
Thank you internet! This is really cool, just like I pictured it :) My living room RPi based music solution is an old Grundig radio from the 50s, modified so I can control the volume using the actual volume control. Playback sources (curren
235.
▲
by
dbrgn
6y ago
Clauses like that are really really hard. CC has the NC clause, which is problematic because it may not be clear what consists of commercial use and what doesn't. If a non-profit uses a picture for a fundraiser, is that commercial or n
236.
▲
by
dbrgn
6y ago
I planned to do that with old 64 MiB or 128 MiB SD cards and a car radio with SD support: One SD card = one album. However, nobody still makes SD cards this small, and using a 16 GiB card for 1 album seems wasteful :) But floppy disks would
237.
▲
by
dbrgn
6y ago
I see great potential for a Raspberry Pi based online radio player, where the playlist is transferred using a text file on a 3.5" floppy disk. That would mean that you could choose your radio station (or Spotify playlist) by picking ou
238.
▲
by
dbrgn
6y ago
That is a great trick, thank you!
239.
▲
by
dbrgn
6y ago
I can warmly recommend Pixelfed, it would be great to get some talented photographers on board. However, it's more like Instagram and not really suited for uploading a high-quality high-resolution portfolio. It's also not really s
240.
▲
by
dbrgn
6y ago
> It's the worst community for monetising that in any way. That sounds fantastic, I'll take a look! Edit: It's not CC0 though, right? The Pexels License looks similar to the Unsplash License.
More ›