111 karma · joined March 17, 2014
> When a user first turns on Advanced Data Protection, web access to their data at iCloud.com is automatically turned off. This is because iCloud web servers no longer have access to the keys required to decrypt and display the user’s data. The user can choose to turn on web access again, and use the participation of their trusted device to access their encrypted iCloud data on the web.
Then they explain that if you turn it on again, your devices will send your keys to Apple's servers for the duration of the web session. Technically this leaks your keys to Apple forever, but they promise that they keep it for the duration of the session.
Flare provides proactive external cyber threat detection. We help security teams visualize and manage external cyber risk. This mostly means open and dark web crawling, analysis and priorization.
Most of our stack is typed python running in k8s (AWS EKS) microservices. Frontend is VueJS with TypeScript.
Apply here: https://flaresystems.bamboohr.com/careers/27 or contact me directly alexandre@flare.systems
Anyways, I'll use this opportunity to say that it has always been great to work with the guys at Syncthing. They responded quickly to every issue that we have ran into. For example, the switch from FontAwesome to ForkAwesome was done for due to a Debian issue:
You can't blame them, their user base is in free fall.
They are focusing on exactly what you are saying, putting together a UI that non-technicals can use.
It turns out that the skills that the company has acquired by doing this pays back with consulting contracts.
It is mainly developed by Savoir-faire Linux. A free software consulting company based in Montreal: https://savoirfairelinux.com
2. It is fully decentralized. OpenDHT is the backbone of the network. Calls are made using the sip protocol and are initialized with ICE (https://en.wikipedia.org/wiki/Interactive_Connectivity_Estab...).
Some situations require extra nodes: - If ICE can't open a connection with: ip-to-ip, UPNP, udp hole punching, it will revert to using a TUN/STUN server hosted by Savoir-faire Linux. Note that you can configure your own TURN/STUN server in the Ring settings.
- The first time that Ring connects to the network, it needs a "bootstrap server". A bootstrap server isn't really a super node, it is just a "know active node". Every DHT-supporting bittorrent client supports this. Note that you can point ring to another bootstrap server in the settings.
- Ring uses an optional blockchain (ethereum) based service to register usernames. This isn't part of all ring nodes by default. It has to be installed separately and then you must point your ring client to it. You can chose not to use usernames if you want and call people with their full RingID instead.
3. We have several clients, all of them use native frameworks. - GNU/Linux: GTK - Android: native android libraries - Mac: native mac libraries - Windows UWP: native UWP libraries - Windows win32: native win32 libraries - IOS: native ios libraries
4. Ring (sflphone) was released in 2004. At first, it was a SIP softphone app. It only became decentralized a few years ago. However, the app still supports SIP.
The development has been generously funded by Savoir-faire Linux since 2004 and there is no plan to stop. Savoir-faire Linux has taken every step to ensure that Ring remains free. Joining the GNU project, (2016) was one of these steps: - https://lists.gnu.org/archive/html/info-gnu/2016-11/msg00001...
Ring is comparable to Tox, but it has much less bugs.
Full disclosure: Ring dev here. I can answer questions.
Keep in mind that some of the platforms you have listed here are not decentralized. When using a fully decentralized system like ring, you must be willing to compromise on some functionality.
http://www.bootc.net/archives/2013/06/09/my-perfect-gnupg-ss...
Coupled with a standard yubikey+gpg agent setup
Maybe look at my dotfiles if you are stuck:
By default, Syncthing is pre-configured with community-hosted discovery servers:
- https://github.com/syncthing/syncthing/blob/master/lib/confi...
The community also hosts relay servers, so if your two devices can't communicate with eachother directly, it will work anyway.
Relay servers take bandwidth. Anyone can run a relay server, and it will automatically join the relay pool and be available to Syncthing users. This is documented here:
- https://docs.syncthing.net/users/strelaysrv.html#strelaysrv
It would also be possible to host your own private relay and discovery pools, if you need that for some reason.
- https://github.com/syncthing/syncthing/releases/tag/v0.14.7
Also, It will improve further with File System Notifications (from what I understand?):
But really, you may not need S3 at all and just sync between your devices with Syncthing: https://syncthing.net/
Shameless plug: Syncthing is in official Debian repositories! https://tracker.debian.org/pkg/syncthing
The real issue is small players getting buried under legal fees.
Would it make sense to run the Client + Server on my laptop? Will you package a version of the Client that includes the server?
What I really want is a replacement for Thunderbird. Thunderbird does not ask me to run a server anywhere else. Will N1 do that?
I'm sure the bulk of HN users won't want to use your hosted server solution.
As far as we know, it's not really free and open source. There is hidden stuff to enable "Diamonds" the item that lets you do every single fun thing in this game.
So we have developped The HabbitRPG Black Market. It integrates into habbit RPG and lets you buy diamonds: https://github.com/titilambert/Habit-Black-Market
I may be wrong and it may just be badly documented.
Syncany can work with any backend (like AWS S3) and is encrypted.
It is more of a dropbox replacement while sycnthing is a btsync replacement.