modem_down

joined 1 week ago
[–] modem_down@thebrainbin.org 4 points 7 hours ago

Kdenlive is the top-ranked FOSS video editor on AlternativeTo.

I agree with that ranking, having also tried 5 or 6 of the other entries on the list.

[–] modem_down@thebrainbin.org 1 points 8 hours ago

Trust isn't really the point. Everyone knows Israel and Hamas don't trust each other. I'm more concerned with whether the violent conflict can be reduced, and a stable peace achieved.

Are Hamas's arms doing Gaza any favours? Not that I can see.

AFAICT, if Hamas disarmed:

  • Israel's only(?) excuse for mass military action in Gaza would disappear.
  • International support (already shaky) for Israeli military presence in Gaza would decrease.
  • One or more of Australia, Canada, Costa Rica, Ecuador, Honduras, Israel, Japan, New Zealand, Paraguay, Trinidad and Tobago, the United Kingdom, the United States, or the European Union might end their designation of Hamas as a terrorist organisation, which could in turn increase the aid and other international support available to Gaza.

If you think I'm wrong, I'd be glad to know why.

[–] modem_down@thebrainbin.org 6 points 12 hours ago (1 children)

Terrorism arises in defense to oppression.

Technical point: that isn't exhaustively true. Terrorism can be, and sometimes is, committed against vulnerable parties by more privileged ones.

[–] modem_down@thebrainbin.org 2 points 12 hours ago

Progress report 1

  • I'm ruling out HMAC-SHA1, because:
  • If using systemd, pick FIDO2:
    • Avoids flaws of HMAC-SHA1.
    • Native support in systemd, so "future-proof".
    • Wider support than OpenPGP. More HST vendors to choose from, including cheaper options than NitroKey or Yubikey: useful if each sysadmin (or colleague, or relative) needs an HST.
    • Compatible with QubesOS.
  • Otherwise, OpenPGP:
    • Like FIDO2, solves HMAC-SHA1 flaws.
    • However:
      • smartcard-key-luks seems unmaintained on GitHub and on GitLab.
      • LUKS with OpenPGP isn't well-documented for non-Debian-based distros.
  • TBD: Clevis/Tang:
    • Remote/network-based unlocking.
[–] modem_down@thebrainbin.org 1 points 12 hours ago

Thank you for this! That thread is helpful in itself, and also links to other relevant resources - including by Lennart Poettering (controversial guy, but the canonical source on systemd).

[–] modem_down@thebrainbin.org 13 points 13 hours ago

ChromeOS uses a Linux kernel, so one could say desktop Linux usage is >12%.

[–] modem_down@thebrainbin.org 11 points 13 hours ago (3 children)

A young 'un! Macintosh, surely.

[–] modem_down@thebrainbin.org 2 points 13 hours ago

their setup required a couple large antennas that the victim would need to stand in between. Not impossible, but you'd notice with each side being half a meter away.

So yes, it's a technical risk, but not one that I'd bother putting much effort into avoiding. And the being able to use the key via NFC is probably worth the risk.

This was my conclusion, too, but I didn't want to prejudice the discussion. Thanks for confirming.

IMO, using a Faraday pouch isn't "much effort", and is therefore worth doing if the HST is being carried in unfamiliar/non-secure locations.

 

Crossposted from https://feddit.org/post/33469423

The VB1F project, carried out by a consortium of four partners, including Voodin Blade Technology, has been awarded a €48.18 million grant under the Innovation Fund to build the world’s first commercial manufacturing facility in Spain for fully recyclable wooden wind turbine blades.

[–] modem_down@thebrainbin.org 17 points 13 hours ago (7 children)

OS X (obsolete & unsupported since 2018) has more users than macOS?!

~~Also, where did you get those stats? https://gs.statcounter.com/os-market-share/all/north-america has different numbers to yours.~~

Link to stats: https://gs.statcounter.com/os-market-share/desktop/north-america

[–] modem_down@thebrainbin.org 2 points 13 hours ago

Interesting point. Would realistic human-edited ("Photoshopped") content have to be labelled? That could be a good thing!

(Might cause embarrassment for fashion magazines unless they stop doing it.)

[–] modem_down@thebrainbin.org 3 points 14 hours ago (1 children)

Even if you can [exploit NFC] at 1m, thats close enough that it can just be stolen from you.

Stealing the HST should not give the user a false sense of security. Not so dangerous.

Silently exfiltrating the private key (or data for a replay attack), OTOH, would leave the user with a false sense of security. Dangerous.

your link to rfidgate appears broken

Wfm. Here's an archive link.

 

Yubikey and NitroKey offer NFC and non-NFC versions of their flagship hardware security tokens (HSTs).

NFC is convenient, but can under some circumstances send e.g. challenge-response exchanges in clear text.

Smartcards using RFID, a similar though not identical protocol, can be queried from ~100cm away.

  • Are there other ways are NFC HSTs are known to be more risky than their non-NFC counterparts?
  • Should users store NFC HSTs in RFID-blocking pouches, like those used for wireless car keys or contactless bank cards?
 

In your view, does this roadmap increase or decrease the likelihood of a peaceful outcome - and why?

 

Crossposted from https://piefed.world/c/technology/p/1300905/ai-labels-to-be-compulsory-on-authentic-looking-content-under-eu-rules

Companies must ensure people know when they are interacting with artificially generated images, audio and text designed to look real

 

Crossposted from https://piefed.world/c/technology/p/1300905/ai-labels-to-be-compulsory-on-authentic-looking-content-under-eu-rules

Companies must ensure people know when they are interacting with artificially generated images, audio and text designed to look real

 

Crossposted from https://piefed.world/c/technology/p/1300905/ai-labels-to-be-compulsory-on-authentic-looking-content-under-eu-rules

Companies must ensure people know when they are interacting with artificially generated images, audio and text designed to look real

 

Crossposted from https://piefed.world/c/technology/p/1300905/ai-labels-to-be-compulsory-on-authentic-looking-content-under-eu-rules

Companies must ensure people know when they are interacting with artificially generated images, audio and text designed to look real

 

Crossposted from https://thebrainbin.org/m/upliftingnews@lemmy.world/t/1840934

The European Union has introduced a new team to regulate AI companies ... amid rising concerns about AI's risks

 

Crossposted from https://thebrainbin.org/m/upliftingnews@lemmy.world/t/1840934

The European Union has introduced a new team to regulate AI companies ... amid rising concerns about AI's risks

 

The European Union has introduced a new team to regulate AI companies ... amid rising concerns about AI's risks

 

Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283

Which approach do you think is better, and why?

  1. FIDO2
  2. HMAC-SHA1
  3. OpenPGP (alternative guide)

Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?

 

Crossposted from https://thebrainbin.org/m/linux@lemmy.ml/t/1840283

Which approach do you think is better, and why?

  1. FIDO2
  2. HMAC-SHA1
  3. OpenPGP (alternative guide)

Or do you think there is an even better way to use a hardware security token to unlock drives having LUKS full disk encryption?

view more: next ›