HNHacker News
TopNewBestAskShowJobs

deknos

587 karma · joined March 31, 2017

submissionscomments
deknos··on IPv6 is not insecure because it lacks a NAT
Of course it's not insecure because of NAT.

NAT (in all its forms) is just a very convenient technology for many people and niche situations.

And adoption of IPv6 will be hindered as long as NAT is not a first class citizen.

And of course, mostly NAT should not be used as "firewall replacement". But what many firewall proponents forget here:

NON-IT People at home cannot run and manage a firewall (and proxies). For them, NAT is a convenient and mostly okayish replacements.

Another niche would be IP Packet Handling of VMs.

deknos··on A decentralized peer-to-peer messaging application that operates over Bluetooth
hm, than i think it's better to use the LORA stuff, no? if i need an external device with my device anyway, i can use one of them.

because the fun thing is cool, but people want some usable...

deknos··on A decentralized peer-to-peer messaging application that operates over Bluetooth
but for that to work, you need to attach an antenna, no? and where do i get such an FM transmitter? AND android does not support it in the software level, and there's no protocol for the waves?
deknos··on A decentralized peer-to-peer messaging application that operates over Bluetooth
is there an actual real good comparison of bitchat vs. briar from all sides? protocols, cryptography, supplychain, which software stack, usability and so on?
deknos··on HTTP RateLimit Headers
Now do HTTP Hashcash ratification! :D
deknos··on 25 Years of Wikipedia
yes, but question can be done in different ways. and tilo jung always at least, not cared, if his questions are offensive... or trying to up the interviewed person

a group of people seems to think, that journalists should trip up people, like in interrogations, instead of being hard in the topic but nice in the tone.

deknos··on The PGP problem (2019)
on another note: it's so funny that this says, that email should not be used, when the whole world uses email. it's so far detached from reality...
deknos··on The PGP problem (2019)
you cannot selfhost it. it's not verified and audited independently as a whole system.

for some people, that's important

deknos··on The PGP problem (2019)
i like the approach by the bsd people. shut the f* up and code.

as long as there's not (audited and verified) replacements for each niche, we still have to use it.

sadly even gpg (because of all this fud'ing around) even falls now the grace and tries to say "well, not THAT application, only THAT".. sigh.

deknos··on IPv6 just turned 30 and still hasn't taken over the world
huh, i was NOT aware of that. NICE!

now applications (including DNS/NAT) have to support it

i also forgot something (but not against your comment):

* there needs to be guidelines how applications should differentiate between used ipadresses (link, site, global and so on)

deknos··on IPv6 just turned 30 and still hasn't taken over the world
but not on the same computer. and the application does not have to figure out which one it has to use.
deknos··on IPv6 just turned 30 and still hasn't taken over the world
IMHO:

And it will not be, as long as

* (S|D)NAT are not first class citizen in IPV6 Standards and Implementation * there's no mapping of the IPv4 Adresspace into the v6 space, so people can reroute stuff which is needed.

because only then, we can a) migrate b) rebuild the same structures.

because people will never let go of something.

deknos··on Gpg.fail
and now certain people in corporate security only trust gpg, because they grew up with it :D
deknos··on Gpg.fail
We need a keyring at a company. Because there's no other media for communicating, where you reach management and technical people in companies as well.

And we have massive issues due to the fact that the ongoing-decrying of "shut everything off" and the following non-improvement-without-an-alternative because we have to talk with people of other organizations (and every organization runs their own mailserver) and the only really common way of communication is Mail.

And when everyone has a GPG Key, you get.. what? an keyring.

You could say, we do not need gpg, because we control the mailserver, but what if a mailserver is compromised and the mails are still in mailboxes?

the public keys are not that public, only known to the contenders, still, it's an issue and we have a keyring

deknos··on Fahrplan – 39C3
Okay, that's it. i think i will do some data analysis and do a talk at some place next year about the outcome of the analysis which talks are there and if there's really a trend. :D
deknos··on Fahrplan – 39C3
again this myth. look at past fahrplans, there was always quite some political stuff. you just agreed with it and therefore it was not inconvenient.
deknos··on Coursera to combine with Udemy
will this mean i loose my saved courses o_O?
deknos··on Useful patterns for building HTML tools
It's so sad that there's no wysiwyg editor besides seamonkey which is truly opensource and no electron stuff.. sigh :(

also sad, that XHTML was abandoned.

deknos··on Android and iPhone users can now share files, starting with the Pixel 10
can please someone build a iphone+ android app which does conveniently what cimbar (cimbar.org) does? than we do need much less of those filesharing activities, because videos go up to a few mb, and bigger than that.. well you can encrypt, share key via such an app and then upload to whereever.
deknos··on Drilling down on Uncle Sam's proposed TP-Link ban
> The real lesson here: If you're successful, don't skimp on security/software! Also, don't abandon software/firmware security support for your products so quickly.

Why? Microsoft and Cisco also skimp on security.

deknos··on Email verification protocol
to be honest, i am kinda wondering, why mailserver do not publish on some http service:

- whom the accept mails from under which conditions - who's blocked and why - perhaps hashed-and-salted-email-addresses for verification - how much spam (as the receiver understands it) happened from where - that you produce tokens with hashcash, so you unknown senders can verify themselves with that per mail/receiver

deknos··on Tangled, a Git collaboration platform built on atproto
i just hope, this is really a thin service and not again running with javascript and also works over tor..
deknos··on Neutts-air – Open-source, on device TTS
i though this uses coqui which is not really opensource?
deknos··on Magic Wormhole: Get things from one computer to another, safely
1. i wish syncthing also would implement this 2. is it already postquantum secure?

(to all the quantum-computer-will-never-come-people: i like to be prepared in CASE it comes, otherwise no one will prepare and users are in the dust, once it is there)

deknos··on PyOCI – Publish and install private Python packages using OCI/Docker registries
as long as we can convert the OCI to an bootable VM image, i am fine with that. But i also think, there's an size limit
deknos··on SSH3: Faster and rich secure shell using HTTP/3
how complex is this to understand for auditors? i fear of the ever increasing complexity of protocols which are security-relevant...
deknos··on Why use mailing lists?
i am still of the opinion, if they would extend sieve quite a bit and standardize markdown/reST/asciidoc as rendered in emailreaders, we could probably get much more usage of mail again

(sieve would need additional features of sending/processing mails and reencrypting imho)

but mail is still less broken then mobile phone networks.

deknos··on All New Java Language Features Since Java 21
You know what's quite more important?

* Performant and safe standard library. * batteries included * a good way to actually care about managing dependencies, during build and runtime.

Okay, you got your stuff, please everyone now let's care about the standard library and that it really good.

deknos··on All New Java Language Features Since Java 21
i would prefer it, if they improve and extend the java standard library and the tooling for libraries

many people will tell you that the standard library is not as performant as it could be and does not have as many batteries as python and try managing your dependencies...

that would be far more important than the next super duper feature IMHO.

deknos··on Bcachefs Goes to "Externally Maintained"
i run btrfs on servers and desktops. it's usuable.
← PreviousPage 2 of 11Next →