Hacker Newsnew | past | comments | ask | show | jobs | submit | Xaiph_Rahci's commentslogin

> Andreas seems to be such a nice, humble guy.

Truer words have never been spoken!

His monthly update videos are so soothing to watch.


> "Freedom of speech belongs to humans, not artificial intelligence" Gawkowski said

Wow, I never imagined I'd come across this sentence outside a sci-fi story.


> absolutely zero reason

A prevailing theory is that advanced users opt out of telemetry, where as regular users don't. So Microsoft has no idea what advanced users use and the OS gradually becomes less sophisticated.


I guess similar issue with Safari not showing the url path by default, which is completely ridiculous. It is a large part of the UX. It is not going to be of benefit to anyone.


Chrome also hides things in the url that might confuse us helpless users[1], I think they made that terrible UI change before Safari followed them off the cliff. Another reason to use FF.

1: https://support.google.com/chrome/thread/25855505/how-to-mak...


Because doing this reduces the 2FA into 1FA (i.e. there is no longer a possession factor).


Yes, if your vault is hacked, your 2fa will become 1fa, but:

- 2fa is still good for stopping someone who steals your password but not your whole vault - 2fa blocks people from guessing your password (through brute force etc)

So there is still quite a bit of benefit.


There are different ways to avoid this.

Nearly all of my 2FA are in Bitwarden, because it's just so damn convenient. But my Bitwarden itself uses YubiKey as 2FA.

Since I adopted this setup last year, it's been the best if both worlds for me.


>my Bitwarden itself uses YubiKey as 2FA.

I want to do the same but haven't switch yet.

- Is the YubiKey USB-C? Is the connector type an issue when plugging it into various computers?

- Where do you keep your YubiKey (plugged into your laptop, on a keychain, somewhere else).

- How do you open your vault on mobile?

- Do you have a backup YubiKey somewhere in case you lost the main one?


The whole concept of yubikeys bothers me. If it is lost, broken, or stolen, access to everything it protected is effectively gone. Same for SMS if you have an eSIM and your phone is lost or destroyed (as happened to me recently, and was a nightmare). TOTP synchronized to multiple devices seems to be the only way to have MFA while protecting oneself from getting locked out. I'm open to being convinced otherwise.


... The posession factor is the encrypted file that stores your secrets. It is in fact the same factor that Aegis uses, because it also uses an encrypted file to store your secrets. I'm not sure what you're expecting Aegis to do that is different from storing TOTP secrets in an encrypted file.


You missed the bit where I mentioned keeping my TOTP secret keys separate from my passwords by storing them in separate vaults, each of which is separately encrypted on-device with a different password. Cloud synchronization is optional.


The goal is to protect your data from brute force not from yourself, it’s perfectly reasonable to have 2fa in your password manager, saying it’s 1fa is just fud


It's not fud.

2FA traditionally means relying on one thing you know (i.e. a password) plus one thing you have, or one thing you are (biometrics).

Every single one of my passwords is unique and randomly generated and at least 32 characters, none of them are getting brute forced unless there is a sudden gigantic leap in quantum computing. And if that happens, the world has bigger problems than my passwords.

Having a separate identity factor, something that I own, is not to save me from myself. It's to save me if someone steals my phone or laptop and is able to get into it.

Now we all face different threat models and if your threat model doesn't call for having a totally separate identity factor, great! There's nothing wrong with that. But we don't all face your threat model, and some of us do indeed need a second identity factor that's not stored in the same place as the password.


> Having a separate identity factor, something that I own, is not to save me from myself. It's to save me if someone steals my phone or laptop and is able to get into it.

What if that second factor is physical and stolen along with the things it was supposed to protect? What if your biometrics are cloned in some way?

Having TOTP synchronized across devices, but protected by passwords mitigates those risks as well as the risk that you lock yourself out by loss of a physical token.


> Every single one of my passwords is unique and randomly generated and at least 32 characters, none of them are getting brute forced unless there is a sudden gigantic leap in quantum computing.

One of the threat models that I consider is there being a bug in the particular RNG/encryption algorithm implementation used to get that encrypted password. In that case, my password can possibly be brute forced much faster than purely random guessing.


Mine is very similar (fortune -c | cowsay -f tux)

I don't think I've ever seen a cookie repeat in over 10 years, but it might just be my poor memory


The default data file[1] contains 500kB of plaintext fortunes, this seems plausible.

[1]: http://bxr.su/OpenBSD/games/fortune/datfiles/fortunes


What I got is pretty accurate:

https://imgur.com/a/vH0zq5b

(seed: 3919562)


> You can't.

Ellipse Select Tool 🡢 Draw Circle 🡢 Edit 🡢 Stroke Selection 🡢 Stroke


A physical OEM USB dongle on PC side, whether Bluetooth or not, and an On/Off switch on the peripheral side would have certainly prevented the issue in discussion.


Surely if you disable bluetooth in the OS it'll disable any bluetooth dongles as well?


Usually from computer’s point of view these devices look like regular USB mice or keyboards so disabling Bluetooth will not disable them.


> How do you go about managing your photos?

1. Saved all Photos in PC directories as follows: $HOME/Pictures/<YYYYMMDD - Event>

2. Ensured '$HOME/Pictures' is regularly backed up to at-least one more disk.

3. Just use the File Manager (with Thumbnails) & Image Viewer to view the Photos.

> Does it feel like digital clutter?

No, not one bit.

> How do you approach memory making through photos?

Capture as many as possible, delete duplicates/similar. Retain good ones.


People who get existential crisis out of this can find relief in the fact that the Universe can expand faster than the decay. So, it is possible that decay never reaches your region of Space.


They should also get relief in the fact that there doesn't appear to be any reason to think our universe is even subject to that "risk".


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: