HNHacker News
TopNewBestAskShowJobs

gepeto42

767 karma · joined August 21, 2014

https://irrelephant.co/@g/
submissionscomments
gepeto42··on I made my phone slow on purpose
Absolutely does. But it would definitely keep you away from switching between 13 Slack groups!
gepeto42··on I made my phone slow on purpose
I feel like my phone is so sluggish when in low power mode (even a 17 Pro), that it could work for this.
gepeto42··on AI Defense Matrix: an open framework for defending AI systems
After using the cyber defense matrix quite a bit, it felt obvious AI required it to evolve.

Will definitely try this one out for security architecture projects etc.

gepeto42··on Show HN: SmokedMeat, like Metasploit, but for CI/CD (open-source)
The last year has shown that this vector is getting weaponized for real so it's great to see more tools to help defenders!

Is this something only companies with public repos should be worried about?

gepeto42··on LG UltraFine Evo 6K 32-inch Monitor Review
Been running it for about two months.

A few thoughts:

1 - I replaced 2x4k 27inch monitors, and so far so good, only annoyance is sometimes I want to share an entire screen as a reflex, I have to remember to have a more window focused workflow.

2 - The power brick is GIGANTIC, but it charges one of my laptops at 96w

3 - It is a bit blurry due to the antiglare coating. Might be annoying to some.

4 - The built-in USB hub is good enough for my Razer Kiyo Pro Ultra, and it gets switched to my active computer, unless I am using HDMI (no USB link available separately from the Thunderbolt or USB-C main ports)

In general, I wanted an Apple XDR display, but with multiple inputs. The results are not as good from an image point of view, but better from a productivity point of view.

gepeto42··on Ask HN: Why does the US Visa application website do a port-scan of my network?
They’d likely block you if they detected something like RDP open, cause that would likely indicate you’re hiding your real IP address.
gepeto42··on Magic/tragic email links: don't make them the only option
Thanks for recognizing it, it was absolutely by design!
gepeto42··on Magic/tragic email links: don't make them the only option
I don't have my home email on work devices. I also don't have my email on my gaming PC (I agree this must be rarer). I don't have all of my work emails on my personal devices either. So now when I log in I need to DM myself links over Slack, or forward emails around...
gepeto42··on Magic/tragic email links: don't make them the only option
I have to admit I bought it mostly to annoy a few very specific friends, but then I kept using it. I would not recommend trying to host anything serious on such a TLD.

If you check the early comments on the thread I posted the full content for someone else who could not reach .zip domains.

gepeto42··on Magic/tragic email links: don't make them the only option
You're right, I forgot to even cover that part because I was focused on how annoying they are to me as a user, not necessarily as a service provider. I also forgot to mention how they train people to click on links, how my inbox now consists of dozens of emails per day telling me to either click to login, or warning me that I logged in.

I have my own domains for email so I haven't had the issue of someone else entering my email but I keep hearing from friends getting that.

gepeto42··on Magic/tragic email links: don't make them the only option
Yeah that would not surprise me, in general. I don't think that would be 404's goal, since they provide full-text RSS feeds I could share with a friend easily, but I could see that happening with other services.
gepeto42··on Magic/tragic email links: don't make them the only option
As someone in the security industry, I find it amazing how much we've told people (in awareness training) to "not click things on the thing-clicking machine™" while simultaneously having processes like password resets that require doing it.

™Kelly Shortridge 2021 (https://x.com/swagitda_/status/1503751776134180873)

gepeto42··on Magic/tragic email links: don't make them the only option
Even with passkeys or TOTP 2FA, we've decided email is the root, for better or for worse (for people with gmail, it's likely better than SMS would be on a crappy carrier, but it depends on so many factors, including how many hundred apps have Gmail read access via OAuth...)
gepeto42··on Magic/tragic email links: don't make them the only option
To be fair to 404, they're trying to limit the amount of data they hold which IS good, but in the end they need to have the email address of subscribers.
gepeto42··on Magic/tragic email links: don't make them the only option
What I'd recommend is if you're worried about this (or worried about it in certain instances), disable biometrics to unlock the device itself. Then, passkeys on it don't really matter anymore.
gepeto42··on Magic/tragic email links: don't make them the only option
I meant Ricky’s post is great and if I had known about it first I might not have written mine! Added a link to it at the bottom of mine.
gepeto42··on Magic/tragic email links: don't make them the only option
Thanks for that link, I had not seen it and if I had known Ricky Mondello had written that, I probably wouldn't have bothered.

I'm still used to Apple people being almost completely invisible publicly.

gepeto42··on Magic/tragic email links: don't make them the only option
Some of them make it way easier for threat actors to obtain large amounts of domains for cheap or free, without fear they'll disappear right away.

Paul Vixie had a great talk and research about this ~2018: https://www.youtube.com/watch?v=nkoNjntc5Lw

gepeto42··on Magic/tragic email links: don't make them the only option
Yeah the Stratechery implementation for podcasts is great. The more annoying thing is each of them has its own domain and requires logging in, if you don't know you can dig into Stratechery.com. I would prefer if I could login to it with a passkey or username+pwd, but it's a much better system overall than just dropping an email link.
gepeto42··on Magic/tragic email links: don't make them the only option
You're welcome. Been thinking about it for a few days, and I had to do it. I don't disagree there's some benefits but being told "IT'S BETTER!" annoyed me quite a bit.
gepeto42··on Magic/tragic email links: don't make them the only option
Because I'm an idiot who likes hosting stuff on bad gTLDs, here's the markdown content of the actual post for you and everyone behind some corporate firewall that blocks dot zip:

The term "Magic Links" once meant a [futuristic PDA](https://en.wikipedia.org/wiki/Magic_Link). Nowdays, companies like [Auth0](https://auth0.com/docs/authenticate/passwordless/authenticat...) use it to refer to the slightly-magical feat of including a login link in an email.

Last week, the great website you should subscribe to if you haven't already (it's great, when you're not logged out), [404 Media](https://www.404media.co/), posted ["We Don't Want Your Password"](https://www.404media.co/we-dont-want-your-password-3/) in defense of so-called magic links.

Of course, as stated in the article, such email links are harder to phish than passwords, can't lead to a breach of passwords, and protect the site itself against users who might reuse passwords previously compromised.

The article even covers some of my annoyances with this system, but throws out this sentence:

> [We find this to be a much easier login process and wish it was more common across the web where appropriate.](https://www.404media.co/we-dont-want-your-password-3/)

Easier than what? Easier than a long password, without a password manager? Easier than a passkey? Easier than an OTP sent to the same email address?

This sentence reads to me as one written by someone mostly working and _living_ from a single laptop and mobile device. The second part of the sentence, calling for more sites to do this is why I am writing this.

For any scenario with a minimal amount of complexity, like users with multiple computers, and you're looking at a scenario where the site's unwillingness to deal with other login methods shoves friction on the end-user.

### What makes them tragic:

1. Multiple devices. Who doesn't use at least a few computers weekly? I don't have my email on my gaming PC, nor do I have it on my work laptops. 1. Slower. From 2 seconds slower to minutes slower, depending on SMTP delays as well as how awkward it is to get the link to the right browser. 1. Anti-mobile. As mentioned by 404 in their own article, this breaks the ability to use in-app browsers, which is quite annoying especially for RSS reader type apps. It makes interacting with any local link in the RSS feed extremely annoying. 1. Indirect security downsides. Pushing people to access personal email on work devices (or vice-versa) isn't exactly a win for security.

Another annoying _passwordless_ system is to email or SMS an OTP the end user can type in.

While this sucks, it at least allows you to easily log in in situations where you don't have a clear and easy copy/paste path from the email client to the browser you want to log in to.

[Stratechery](https://stratechery.com/), powered by [Passport](https://passport.online), uses this type of scheme (click link OR type in OTP), which is still shifting annoyances onto end-users to free developers from implementing passkeys, but at least has a bit more of an appreciation for end-users.

If you insist on using magic/tragic links by default, at least consider offering a robust alternative, such as [passkeys](https://fidoalliance.org/passkeys/), especially if your audience is technical and privacy-focused.

gepeto42··on Magic/tragic email links: don't make them the only option
Yeah exactly. Plus, sometimes SOMETHING will click the link before it even gets to the person's inbox (some enterprise spam filter with a sandboxed browser for example).

edit: saw that nicce basically said that a second before I hit post.

gepeto42··on Magic/tragic email links: don't make them the only option
Yeah. To be honest, I kind of setup this blog as a joke when the dot zip gTLD came up, as an inside joke with a few fellow security people who (rightfully) are against the ever expanding list of TLDs we have to deal with.
gepeto42··on Apple: Let Us Be Polymacous
I mean, I’d be fine with streaming the webcam from my phone to my work Mac via USB if I knew my work Mac couldn’t also back up the phone. But I agree it might be a lot of effort, feature by feature.
gepeto42··on Launch HN: Thorntale (YC W24) – Presentation software that works with your data
Nice!

Good luck with your product. As someone who regularly worked with tools like R Studio or Jupyter notebooks, it boggles my mind to still see monthly and quarterly presentations that are the same, except for some (badly) copy-pasta'd data, so there is a need for this!

gepeto42··on Launch HN: Thorntale (YC W24) – Presentation software that works with your data
I work in security and a use case I've had in the past and hacked together using a combination of Power BI and powerpoint (hey, license was already paid for!) was exporting tons of data from logs, load into Power BI to generate charts and metrics that related to security (especially vulnerability management). It was the same slide every time, just new data.

One thing that could be useful though is the ability to export a snapshot of what the slides would've been on any given day, for reference in the future (data might not be available in 2 years etc).

gepeto42··on Insecure vehicles should be banned, not security tools like the Flipper Zero
One of the authors here. Someone just told me we were on the HackerNews front page, made me happy we just went with a static website on GitHub pages.

I will go through the comments later, but for now, if you are Canadian, please get in touch with your MPs.

I am working with some media as well for additional coverage in the next week, but if you know Canadian journalists that might be interested in this, please get in touch with them, educate them directly if you want or send them to me (my LinkedIn is in the signatures, the first two names in bold = authors).

Thanks for helping this story reach more people.

gepeto42··on Show HN: Anytype – local-first, P2P knowledge management
I completely agree with the threat model of "an attacker on your machine can get to the keys" but I'd like to add two security use cases that makes encrypting indexes valuable:

1. Off-the-shelf malware exfiltrates data, as seen in ransom attacks. I'd feel better if the index was encrypted. It's unlikely an attacker would manually spend time trying to find the keys in RAM unless your app became very famous :)

2. Syncing files on a work laptop where IT might snoop.

Obsidian does not encrypt files at all locally, and for that reason I would feel quite self-conscious about loading a vault with potentially private notes.

Ironically, Obsidian is much better if you only have ONE big vault, but because of this, I have to live with 3 vaults (different threat models for each).

gepeto42··on Ask HN: How are you dealing with the job market anxiety?
For me it was conferences, and after landing one remote US job then through contacts it became the new normal over a decade or so.
gepeto42··on Firmware Software Bill of Materials (SBoM) Proposal
I really dislike when people say SBoM could help with the Solarwinds scenario, because it would not.

Once the CI/CD environment is compromised, how would the SBoM be trustworthy anyway?

Page 1 of 3Next →