WhyJiffie
@WhyJiffie@sh.itjust.works
- Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative? 1 week ago:
I mean, “america” (specifically USA) bad, but that user has no idea bitwarden encrypts the password before sending it to the server.
- Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative? 2 weeks ago:
and details: wiki.mozilla.org/…/Certificate_Transparency
this sounds important:
This information has a 10 week expiration time. That is, if 10 weeks have passed since the information has been updated (typically by updating Firefox itself), the implementation will no longer enforce certificate transparency.
this also means, it can’t truly verify SCT’s that were issued since the last browser update?
- Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative? 2 weeks ago:
it seems Firefox started doing the CT validation too, without needing to contact the CT log service: developer.mozilla.org/…/Certificate_Transparency#…
- Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative? 2 weeks ago:
apparently certs can have a cryptographic proof of having been included in the CT logs. but what do browsers do if the letsencrypt cert has no such proof?
- Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative? 2 weeks ago:
if its not human readable, how will people know its the place they want to go to? I don’t think bookmarked onionsites is a particularly good idea
- Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative? 2 weeks ago:
Actually the problem is that they are too widespread. if something happened, and they started creating fake certificates, for outside force or otherwise, they can’t just be blocked because literally half of the internet or more breaks. what’s worse, if browser vendors trued that, people would be downgrading their browser to the last version accepting it, and become exposed to publicly revealed security vulnerabilities. not all because its a bit complicated, but enough would do to have it cause an even greater problem.
- Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative? 2 weeks ago:
It’s actually to prove that a web server belongs to (or is trusted by for delivering their content) a specific website.
qualified certificates go a step further, by proving that a web server belongs to a specific company or a real person. but that’s costly, because verification is inherently more difficult.
- Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative? 2 weeks ago:
you don’t know how bitwarden works, do you?
- Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative? 2 weeks ago:
which is still there if you are not using lets encrypt, because they can strongarm them to make a fake cert for your domain, and install a proxy repackaging HTTPS traffic with the fake certificate. all browsers trust the lets encrypt root certificate, so they won’t see anything suspicious.
the only thing there today to detect this (but not avoid) is certificate transparency logs. all modern certificates are required to be added to this log, for the CA to remain compliant. but browsers are not checking the logs, that would be a lot of additional traffic and how do they decide if a certificate was created maliciously? also, lets encrypt could afford being noncompliant, browser vendors can’t realistically just distrust their root certificate, many sites would become inaccessible.
- Comment on AI bot hacking/scraping Home Assistant 3 weeks ago:
the whois info for the IP might have an abuse email address, try that
- Comment on Why hasn't sh.itjust.works changed to a better domain? 3 weeks ago:
that mostly matters for domains on billboards, flyers and in ads. but you’ll only see this domain in links on your computer, where it’s just a click regardless of the length.
- Comment on Expanding my laptops HDD capacity 4 weeks ago:
maybe a friend has the 3d printer? also, reduce, reuse, recycle. and finally, it likely consumes less power.
- Comment on Expanding my laptops HDD capacity 4 weeks ago:
what made you choose that distro?
- Comment on QubesOS workstation + homeserver, and DANE for TLS without 3rd party company 4 weeks ago:
I already considered that, and for an untrusted website I already don’t trust the content or the scripts. So it doesn’t matter if it was modified or not, it’s still untrusted.
but then why are you reading it? is it cat photos and cooking recipes only? or does it have articles about pricey things you could buy, news, life improvement tips, car and other thing repair docs/advice?
- Comment on QubesOS workstation + homeserver, and DANE for TLS without 3rd party company 4 weeks ago:
I remember reading about some kind of an alternate DNS root servers. they have some unique TLDs (sounds risky though, the possibility of future name clashes). not too popular, but it is being used. I think this is it: opennic.org
but there are more: icannwiki.org/Alternative_Roots
though, it will not salvage the .org TLD. such a shame it got to that…
- Comment on QubesOS workstation + homeserver, and DANE for TLS without 3rd party company 4 weeks ago:
I don’t agree, I think there is a difference in likely outcomes. but even without scripts, you don’t want you article’s content (text, images, statements or names) be falsified by an attacker. Unless you are just reading the article to waste time, and magically what you read will not influence your views.
- Comment on [AIP] I've been working on the perfect UI for cron and supervisor for several months now. Tell me what you think. 4 weeks ago:
If you inspect the generated timer you see the same format in the OnCalendar line.
but without the command
What do you mean by persisted? The service and timer will both be there as long as the timer doesn’t end. Which it won’t in my example.
I mean saved to a file so that it will still be there after reboot
- Comment on QubesOS workstation + homeserver, and DANE for TLS without 3rd party company 4 weeks ago:
SSL/TLS have very specific benefits. None of which matter that much for reading random articles on the web.
it is a huge benefit if a man in the middle cannot run scripts on your computer.
So I don’t see the problem with this website doing their own thing to bring attention to the potential issues of the current system.
there is no problem with that. this could work, with the required patch to firefox, also in the repo.
- Comment on QubesOS workstation + homeserver, and DANE for TLS without 3rd party company 4 weeks ago:
then why use DANE. this is just plain old TOFU
- Comment on QubesOS workstation + homeserver, and DANE for TLS without 3rd party company 4 weeks ago:
the repo readme writes about this. Firefox does not yet support DANE, it needs a patch, included in the repo.
- Comment on QubesOS workstation + homeserver, and DANE for TLS without 3rd party company 4 weeks ago:
you are probably aware, but with DNS you are still dependent on a third party, namely the whims of the united states. check what happened with austiciti.org recently
- Comment on [AIP] I've been working on the perfect UI for cron and supervisor for several months now. Tell me what you think. 4 weeks ago:
thank you. this creates it, but is there a way to view or edit its current configuration in a similar format? and this is not persisted, is it?
- Comment on [CBH] PdfDing has migrated to Codeberg 5 weeks ago:
do the files get modified after uploading? some filesystems can deduplicate based on contents, maybe it wouldn’t take double space that way.
- Comment on [AIP] I've been working on the perfect UI for cron and supervisor for several months now. Tell me what you think. 5 weeks ago:
I generally like some things that syatemd gives, but is there an easier way to create timed automations with systemd timers?
with cron, its just a single line with the recurrence pattern and the command. with systemd, you have to create a timer unit file with several lines, a service unit file with several lines, put them in the right directory, reload systemd, enable the timer. timers are not difficult, but much more convoluted than the crontab.
- Comment on [AIP] I've been working on the perfect UI for cron and supervisor for several months now. Tell me what you think. 5 weeks ago:
is systemd available for windows and mac?
- Comment on [AIP] I've been working on the perfect UI for cron and supervisor for several months now. Tell me what you think. 5 weeks ago:
it seems it has already been
- Comment on UK/EU homelabbers: would you host a hardened Pi so I can watch baseball I already pay for? 5 weeks ago:
OxyLabs seems to block Streaming in their TOS
but you won’t be streaming, technically you just need that for the login
- Comment on littleFedi - a new light-weight fediverse server 1 month ago:
they haven’t published binaries either though
- Comment on Means to privately connect to my home server other than Tailscale? 1 month ago:
vibecoding and security don’t pair well.
- Comment on Observability 1 month ago:
Prometheus is mostly for regularly collected statistics and state. what would you recommend for statistics that are only collected when something happens? stats that aren’t available on schedule. as an example, take UPS state changes to battery mode or overvoltage mode. Prometheus can’t collect them when they are short lived.