@abucci@anthony.buc.ci If I were to cut a release today, I’d have to move all remaining work to the next milestone I guess 🤔 – Slow progress 🤣 but progress nonetheless 😅
@abucci@anthony.buc.ci Haha 🤣
@abucci@anthony.buc.ci Hmmm some kind of online table editor is probably a good idea here, I tried to find one that wasn’t some blasted Google or Office365 pile of privacy eroding garbage, but haven’t found one 😅
Salty.im Blob Storage v1 - HedgeDoc 👈 Updated this doc a bit more today with @abucci@anthony.buc.ci’s help 🙏 Kind of need everyone’s help though (please) to help with the threat modelling part, and any other feedback comments of course 👌 Still some work to do…
cc @xuu
@abucci@anthony.buc.ci Thanks! 👌
@abucci@anthony.buc.ci I have a question about this process… How far do I go? Am I going overboard? 🤔 I’ve identified 4 pieces of affected data, along with your already listed 7 actors and 5 different vulnerabilities. If this ends up (which it’s looking like it so far) a matrix, that’ll end up with hundreds of rows 😳 How do you actually go about doing this without going insane? 🤣
Markdown Table Editor and Generator - Table Convert Online – Great little online Markdown table editor (with other supported export formats) 👌
@lyse@lyse.isobeef.org Sorry I missed the link somehow 🤣 Sooo cute 😅
@stigatle@yarn.stigatle.no No worries 👌 Enjoy!
@stigatle@yarn.stigatle.no Just about to have the 2nd weekly call for the day (10pm here), after that I’ll call it a night and go to bed. You’re welcome to join btw 👌
=> https://meet.jit.si/Yarn.social
Otherwise I’m looking forward to family breakfast out in the morning 🤞
@stigatle@yarn.stigatle.no Docker is really not as bad (honestly) as some folks make out. Its a great packaging tool and honestly it’s a pretty nice way (I find) to manage multiple services. It sure beats SystemD 😅
refuse to print clear text passwords if stdout is a terminal
But then you lose the very rare (admitely) use-case of:
- I generate a strong password and store it
- I then show the password on my terminal
- Get my wife/daughter to manually type it in to another device
🤣
Now, it’s up for debate if this kind of behavior is appropriate for a password manager. 😅
This is worth the debate for sure. As an aside, whenever I have to show the password on the terminal for some reason or another, I always make sure I clear the terminal buffer and history with ^L^R
😅
@lyse@lyse.isobeef.org Got a close up? 🤔
@abucci@anthony.buc.ci That’s what I love most about what we’ve created here (Yarn.social) 🤣 A truly global, decentralised “thing” 😅
@abucci@anthony.buc.ci Whoohoo! Score +1 for @prologic@twtxt.net and security 😅 (even if I suck at writing whatever dafuq that kind of doc is called you’re helping/guiding me to write 🤣)
@abucci@anthony.buc.ci Today is Saturday for me 🤣 And currently 11.30am 😅
@abucci@anthony.buc.ci I think you’ve raised such a good point, I’d encourage you to raise this upstream with gopass, possibly even submit a PR 👌
@abucci@anthony.buc.ci I think you raise a good point really, in that the default should be to copy to clipboard IMO. Hmmm 🤔
@movq@www.uninformativ.de Oh wow! 🥶 It is snowing quite hard? 🤔
@bender@twtxt.net Sure, I get it. But convenience often breaks security 🤣
So today 😅
@bender@twtxt.net Sorry yes, Saturday! Fuck I forgot about the day differences 🤣
@stigatle@yarn.stigatle.no As @movq@www.uninformativ.de said it doesn’t matter about who initiates the tunnel, the traffic can flow in either direction. So that’s fine. But I would initiation the tunnel from your home end so your connection is outbound only and you can maintain basically a complete inbound firewall (block everything inbound, except your tunnel traffic) – At some point I’d love to get off Cloudflare and do this myself 👌
@jlj@twt.nfld.uk Ahh I see. Makes sense now 👌 Thanks!
@eaplmx@twtxt.net @abucci@anthony.buc.ci Human greed
@abucci@anthony.buc.ci I don’t have that experience either 🤔 I use gopass
primarily now, finally migrated to it completely everywhere, but I’ve never had this problem with pass
either. It is quite explicitly about its operations, and I use a the gopass browser extension/bridge as well.
@ychbn@twtxt.net By the way… I added your domain ychbn.com
to the list of permitted domains for inline images 👌
@stigatle@yarn.stigatle.no very nice! Wallpaper worthy 👌
Generally I don’t sync passwords on my mobile device, but there is a pass mobile app
@eaplmx@twtxt.net Witu gopass you can have multiple repos 👌
@abucci@anthony.buc.ci Thank you🙇♂️
@abucci@anthony.buc.ci Okay. Thanks! I’m not good at writing this sort of thing, so maybe you could me through some basics?
@bender@twtxt.net Its actually a good idea and good security to keep your passwords separate from your OTP. If your password manager is comprised, so are your OTPs if you use the same tool for both.
I guess the good thing is they don’t get very far.
@nmke-de@yarn.zn80.net Yeah this is true. Runtime is a bit unfair though, C has no runtime really.
Yarn.social Weekly Call;
- When: 5am UTC and 12pm UTC
- Where: https://meet.jit.si/Yarn.social
All are welcome! Come say hi, chat or just hang out 🤗
I may have to expand upon how “files” are shared with other users – too early in the morning to think ☕️x2
Salty.im Blob Storage - HedgeDoc – Sanity check a design proposal I’m working with @xuu on? 🙏 Basic idea is to have a secure blob store that clients can store arbitrary files/objects to, like ratchet state that is private to the client, as well as a place to upload arbitrary files to for sharing with other users in chat.
@abucci@anthony.buc.ci I guess as you said, pros/cons right? I’m planning on buying a secondary NAS (also running ZFS) and I’m tossing up between whether I go with a 2-way mirrored vdev setup or RAID-Z1. I mean if you have decent backups, there’s no worry right? 🤔 Just potential downtime of “data”.
@lyse@lyse.isobeef.org Looks very cold 🥶 Nice sheep though! 👌
@off_grid_living@twtxt.net It rains here most of the night, can’t say I noticed anything in particular… But then again I’m not going outside to measure the pH level of the water, nor do I drink it 😅
@xuu Oh!
You edited that Twt :D after it was replied to by the looks
:D
@xuu This is weird, I’m seeing the same here… Edge case somehow? 🤔
@lyse@lyse.isobeef.org No, it is what is known as a “Jamaican Boa” or commonly called a “Coastal Python”
Hey @kdx@kdx.re What clinet are you using?
@mckinley@mckinley.cc Wow! 😱
This data will allow us to correlate telemetry IDs with download tokens and Google Analytics IDs. This will allow us to track which installs result from which downloads to determine the answers to questions like, “Why do we see so many installs per day, but not that many downloads per day?”
Also wtf?! 🤦♂️ #EvilTracking