• 0 Posts
  • 19 Comments
Joined 2 years ago
cake
Cake day: October 5th, 2023

help-circle
  • If this is really as straightforward as it sounds then I’d consider this the best case scenario. Google could have gone full Apple style lockdown or even just have implemented this flow on a per app basis, but needing to wait 24hr one time to enable unverified app installation isn’t a bad idea from a security perspective. It prevents a bad actor with temporary access from being able to do much while not getting in the way of us power users after the initial 24hr period.

    My bigger problem is how Google is leveraging their monopoly to implement this single-handedly and only for themselves. If they had instead gone through AOSP this perhaps could have been implemented in a better way to allow other parties than just Google to be the verifier, and that 24hr waiting period could be applied to any verifier that is not the phone’s default. I’d argue this would be an equally reasonable security measure considering how many scams are out there preying on those who aren’t technologically savvy, yet would maintain transparency.




  • I can’t say I’ve had a great time with audio in either personally, though it’s indeed much easier to fix audio problems in Linux. But just yesterday pipewire must have hung or crashed preventing all browser based video playback entirely, which due to the symptoms not appearing audio related was quite annoying to debug. I still have no idea what caused it in order to avoid it happening again in the future.





  • These attacks are more around the encryption and all require a fully malicious server. It sounds like Bitwarden is taking these seriously and personally I’d still strongly prefer it to any closed source solution where there could be many more unknown but undiscovered security concerns.

    Using a local solution is always most secure, but imo you should first ask yourself if you trust your own security practices and whether you have sufficient hardware redundancy to be actually better. I managed to lose the private key to some Bitcoin about a decade ago due to trying to be clever with encryption and local redundant copies.

    Further, with the prevalence of 2FA even if their server was somehow fully compromised as long as you use a different authenticator app than Bitwarden you’re not at major risk anyways. With how poorly the average person manages their password security this hurdle alone is likely enough to stop all but attacks targeted specifically at you as an individual.



  • If there were ever an election to not vote third party in, I’d argue it’s these upcoming elections. They are effectively over the validity of the constitution itself, since the Republicans have clearly demonstrated they have no intention to follow it. A vote for Democrats isn’t a vote for Democrats as much as a vote against fascism.

    The system itself is incredibly flawed and the Democrats are truly spineless. I have zero hope that they’d do anything to actually fix the system’s problems, but when the alternative is becoming even more like Nazi Germany I don’t see how voting third party could have any benefit. With the recently increased federal voter ID requirements beyond normal registration I worry that it may be too late to have truly free and fair elections already.





  • Snaps bundle dependencies and sandbox applications. The dependencies aspect is what matters more to me, but apparently there’s also security benefits if you were to try to install a malicious program.

    You can remove snapd, doing so also removes a number of built in apps. But at that point you may start questioning why you’re not just using Debian stable and add the stuff you want. Both of these options pretty much defeat the point of what Ubuntu was.



  • I get what Canonical was going for with snaps but wow did they ever ruin Ubuntu’s reputation. It used to be the clear choice for anyone who wanted a generic Linux where you don’t have to configure everything yourself. Sure some people didn’t like Unity but the core distro still worked well and was stable. With snaps, package management has become more complex than other distros while decreasing performance if memory limited (and who isn’t nowadays). The number of times I’ve had something not work in the “stable” snap package is far too many, and it’s pretty much always fixed by installing the same package with apt.

    I get the reasoning for sandboxing applications, but they needed to wait until it was more stable to make the default. At this rate I doubt we’re ever going to get a truly mainstream desktop Linux distro rivaling macos and Windows…



  • Every company I’ve worked at has “annual” raises for cost of living. But sadly according to management they now average 2% when throughout COVID they were closer to 5%. Further, this company has made excuses to delay the review cycle 3 of the past 5 years I’ve been there, meaning they’ve now done 4 review/raise cycles over a full 5yr period. Employees definitely work less hard now, and many have left. I was also going to leave but just got promoted (with a whole 6% raise!)… So maybe I’ll stick around another 6mo?


  • I’ve used these in San Francisco and Colorado Springs. You press a button to open the door, then once inside another button to lock it. You then have up to 5 minutes to do your business before the door will open again iirc. Toilet paper is carefully rationed out and dispensed. Once you are done and leave the door will close behind you and sprayers pop out pretty much everywhere, washing down every single surface. Sometimes the toilet also folds up for a more thorough cleaning of the seat. This means they’re always a little wet inside, but also remarkably clean. SF in particular really impressed me with these, I expected them to be absolutely disgusting and tried my best to avoid them until I had no choice. The US needs public toilets, and assuming the maintenance costs are low enough the self cleaning ones really aren’t as bad as an unattended public toilet sounds on the surface.