Hacker Newsnew | past | comments | ask | show | jobs | submit | preisschild's commentslogin

This is wrong. The US did not give weapons to the Taliban (voluntarily). If you mean Operation Cyclone their receiver was not the Taliban but the mujahadeen, which, yes, consisted of Taliban, but also of enemies of the taliban (northern alliance)

The Northern Alliance contain some people who are probably even worse than the Taliban so while you are technically right I am not sure it matters.

> They’ve never interfered in my politics or started any wars

They actively back russia and deliver them weapons and support them with their attempted Genocide in Ukraine. They also actively threaten Taiwan.

Not to mention them claiming almost the entire South China Sea even though this being against international law and threatening smaller nations into submitting to them


It also supports the Android Storage Access Framework, so other forms of network "cloud" storage are also supported as long as the client ("cloud storage app") implements the correct api, so not only webdav

Are you using telematica/fonira as your ISP too? Have been hosting an email server for years now.

I dont think Forgejo will have a long term future unless they implement federation. When many project needs to have their own host anyways collaboration between hosts needs to be better.

They're already working on federation. But also I disagree with your assessment.

Its obvious they do it for soft power, but at least they actually deliver something useful to the world and not something locked down that only a single company owns.

You can't have good privacy without good security

[flagged]


It turns out that companies also 'attack' your phones to get your data. E.g. at some point Facebook/Yandex apps opened localhost sockets for tracking pixel code to connect to:

https://localmess.github.io/


GrapheneOS largely prevented it for Vanadium before this came to light and fully fixed it long before Chromium did. Android 17 prevents cross-profile loopback connections, which is one of many important privacy improvements in it. Android 17 fixed a massive number of privacy weaknesses including vulnerabilities which will not have patches backported. Only a subset of High and Critical severity patches are backported to older Android releases. Only a subset of that subset are shipped by /e/ despite claiming to provide the latest patch level.

[flagged]


Fully agree. In the end everybody has to make their own threat assessment and make their choices based on that. I think research is particularly important to unravel what data leakage there are in various phones and apps, so that people can make informed choices. I think this kind of information presented presented in a neutral way is sorely missing.

We definitely don't see privacy and security as binary.

Privacy depends on fixing widely abused privacy weaknesses by patching privacy vulnerabilities and shipping major privacy improvements. /e/ is missing many standard Android privacy patches and protections. Privacy also depends on security to avoid it being bypassed. It's also missing many of the standard Android security patches and protections. GrapheneOS preserves the baseline and makes major privacy and security improvements along with being far better at patching vulnerabilities rather than far worse.

/e/ and Fairphone don't do the bare minimum to protect user privacy and security by keeping up with updates. Both are missing crucial standard patches and protections needed against many real world adversaries including widespread privacy abuse by apps.


I think technically you can just register the public key of the passkey and only need it on-hand for login

Technically i would think so too, but is that how it's implemented? (I legit don't know, but my feeling was always that you had to add them while they're present, especially as there's different passkeys for different sites, to do it offline do you pregenerate 100 keys for each device to assign later?)

You can register multiple passkeys for a single user, there is no lock in

You can choose either if your password manager supporte Passkeys

Of course. I was just pointing out that their claim about the lack of portability across devices was untrue.

Perhaps they should’ve said platforms. Because if you wanted to migrate those passkeys off your password manager and into a different platform like Apple Pass or Google how is that accomplished?

There's a protocol, FIDO Credential Exchange Protocol (CXP) which is currently at proposed standard status. It is supported by Apple and Google and some third party password managers (1Password, Bitwarden, and Dashlane). (1Password is kind of annoying though as its CXP export only supports exporting everything. There is no way as far as I can tell to export just a single item yet).

Once 1Password supports proper single export when I make a new passkey I'll store it there and later export it to Apple.

Meanwhile I simply make two passkeys. I've only run into I think two sites that supported passkeys but would not let me make two.

On most sites making a second passkey is as simply as going to your security settings, finding the passkey settings there, hitting the "add another passkey" link, and pointing your phone at the QR code it shows, and then on those phone choosing the password manager that you did not use for the first passkey.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: