Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
lucgommans
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
10 ms
·
61.
▲
by
lucgommans
4y ago
Right now? For broad applicability it is the computational overhead. There are some applications that are doable now, such as reading data anonymously from a small-ish dataset (or a low-volume service where you can afford to wait a minute
62.
▲
by
lucgommans
4y ago
Ah, another one for my list, and this one from a big vendor like Cloudflare! On my to-do list is a little project that takes many password "managers" like these, which are really just hash functions with an interface (called "
63.
▲
AnyZone – DNS delegations without configuring a domain
(anyz.one)
1 points
by
lucgommans
4y ago
|
0 comments
64.
▲
Library and command line tool to detect SHA-1 collisions (2017)
(github.com)
9 points
by
lucgommans
4y ago
|
0 comments
65.
▲
by
lucgommans
4y ago
(If I would guess at the meaning behind your question given the examples mentioned, the short answer would be: I'm not so fanatical about privacy that I prefer complex glitchy software with missing features over software that has prope
66.
▲
by
lucgommans
4y ago
Screenshot: https://snipboard.io/my8dLf.jpg because the page is huge and takes a while to load. Just noticed this while scrolling through the diff. Apparently info about an f-droid variant was already committed to the repos
67.
▲
Threema is coming to F-Droid
(github.com)
23 points
by
lucgommans
4y ago
|
4 comments
68.
▲
by
lucgommans
4y ago
Most certainly, too many to count. A few are on github, e.g. https://github.com/lgommans/mountall.sh , various others are on https://lucgommans.nl/p/ If you're just having a look around, I mig
69.
▲
by
lucgommans
5y ago
If you've ever ctrl+c'd restic, you'll know the message > signal interrupt received, cleaning up
70.
▲
by
lucgommans
5y ago
Makes perfect sense. Restic kind-of supports this because you can just kill the client after an hour and, tomorrow, it'll see which objects are there already. I'm not deep enough into the project to know whether this is like an of
71.
▲
by
lucgommans
5y ago
Depends which back-end you use and which configuration. (Assuming "node" here means a backup client and not a backup-hosting server.) If you just put stuff on some standard storage (FTP, B2, etc.) without any permissions set up, t
72.
▲
by
lucgommans
5y ago
There is also https://github.com/restic/others which has some keywords (e.g. is it encrypted, does it do compression) for most FOSS backup solutions. It can be outdated or incomplete for some entries, though.
73.
▲
by
lucgommans
5y ago
This point hides a lot of goodness in something that I didn't even understand on the first read: > - We have added checksums for various backends so data uploaded to a backend can be checked there. All data is already stored in file
74.
▲
by
lucgommans
5y ago
"of course" thank you, yes this is really very obvious. As if Signal can't see whom I'm talking to if they wanted to. Yes, their marketing material says as much (and they genuinely try to make it hard for themselves), bu
75.
▲
by
lucgommans
5y ago
Not everything government-funded must be government-backdoored, that is quite the conspiracy theory for an open source application. You can also download the APK directly from the website (not using Google's store), which will self-upd
76.
▲
by
lucgommans
5y ago
That's what they claim to store (and I believe it), but that's not all they can be forced to collect. As a simple example, they could easily log whenever account xyz connects to do a token exchange for using sealed sender. Asking
77.
▲
by
lucgommans
5y ago
> who even cares whether the smiley face is white or black or whatever else? If it doesn't matter, why not let people choose whatever they like? Personally I'm also wondering if having specifically white and specifically black
78.
▲
by
lucgommans
5y ago
"CNE" is a fancy word for "exploits" that I had to look up, for anyone else not in the know of this specific terminology... And yeah this is a blanket statement you can use for any application: nation states can get at y
79.
▲
by
lucgommans
5y ago
It does, but that's my point: it ships with its own updater rather than leaving me to just manage updates with a proper repository client (like apt, dnf, f-droid, google store, whatever).
80.
▲
by
lucgommans
5y ago
I hadn't even thought of this, that's a good point and (afaik) negates the entire excuse of Signal's not to be on F-Droid.
81.
▲
by
lucgommans
5y ago
Your comments sound pretty damning and got me curious if there was some conspiracy I didn't yet know about, but then I click to the source and it turns out that this is not a silent change to upload more data without users knowing anyt
82.
▲
by
lucgommans
5y ago
> The above discusses the marketed features The above discusses what I notice in practical terms. As a privacy nut, I want to use an encrypted messenger for my friends and family so I dove into the privacy aspect pretty deep. I work in s
83.
▲
by
lucgommans
5y ago
Similar here. Just an hour ago I had to jiggle Signal to send a message, their implementation is super wonky compared to whatever Wire, Telegram, Threema, etc. uses and it'll often not work for hours. There is also zero indication on w
84.
▲
by
lucgommans
5y ago
I'm fairly sure you must have gotten a fake f-droid store that installs malware instead. I didn't know those were out there. The real one can be found at: https://f-droid.org You can also download individual apps (APK
85.
▲
by
lucgommans
5y ago
The same advantage as having 30 updaters run in the background versus running apt update Imagine every app you install, from your calculator to your chat applications, has to have its own updater. That's why I like F-Droid rat
86.
▲
by
lucgommans
5y ago
I did not mean to make this a political discussion when I submitted this news. If there are other open source app stores that Wire is on, feel free to add those in a comment and/or a submission. Coming here just to hate on f-droid for
87.
▲
by
lucgommans
5y ago
> I have never heard of wire, I will check it out. Looks interesting on first glance. It's basically Signal but without the popularity, despite predating it. Why Signal took off and Wire stagnated, I am not sure. The network effect
88.
▲
by
lucgommans
5y ago
Exactly, this is only tangentially related to rooting. Google doesn't need root on your device for their closed Play Services to install software, but the component that you want to have this installation capability does need some syst
89.
▲
by
lucgommans
5y ago
I'd rather it keeps a username/password on their central service, than authenticate with my phone number. End to end encryption is achieved through key verification, same as on Signal, Threema, tg secret chats, PGP, etc. Your pass
90.
▲
Wire is now on F-Droid
(f-droid.org)
282 points
by
lucgommans
5y ago
|
238 comments
More ›