767 karma · joined August 21, 2014
Will definitely try this one out for security architecture projects etc.
Is this something only companies with public repos should be worried about?
A few thoughts:
1 - I replaced 2x4k 27inch monitors, and so far so good, only annoyance is sometimes I want to share an entire screen as a reflex, I have to remember to have a more window focused workflow.
2 - The power brick is GIGANTIC, but it charges one of my laptops at 96w
3 - It is a bit blurry due to the antiglare coating. Might be annoying to some.
4 - The built-in USB hub is good enough for my Razer Kiyo Pro Ultra, and it gets switched to my active computer, unless I am using HDMI (no USB link available separately from the Thunderbolt or USB-C main ports)
In general, I wanted an Apple XDR display, but with multiple inputs. The results are not as good from an image point of view, but better from a productivity point of view.
If you check the early comments on the thread I posted the full content for someone else who could not reach .zip domains.
I have my own domains for email so I haven't had the issue of someone else entering my email but I keep hearing from friends getting that.
™Kelly Shortridge 2021 (https://x.com/swagitda_/status/1503751776134180873)
I'm still used to Apple people being almost completely invisible publicly.
Paul Vixie had a great talk and research about this ~2018: https://www.youtube.com/watch?v=nkoNjntc5Lw
The term "Magic Links" once meant a [futuristic PDA](https://en.wikipedia.org/wiki/Magic_Link). Nowdays, companies like [Auth0](https://auth0.com/docs/authenticate/passwordless/authenticat...) use it to refer to the slightly-magical feat of including a login link in an email.
Last week, the great website you should subscribe to if you haven't already (it's great, when you're not logged out), [404 Media](https://www.404media.co/), posted ["We Don't Want Your Password"](https://www.404media.co/we-dont-want-your-password-3/) in defense of so-called magic links.
Of course, as stated in the article, such email links are harder to phish than passwords, can't lead to a breach of passwords, and protect the site itself against users who might reuse passwords previously compromised.
The article even covers some of my annoyances with this system, but throws out this sentence:
> [We find this to be a much easier login process and wish it was more common across the web where appropriate.](https://www.404media.co/we-dont-want-your-password-3/)
Easier than what? Easier than a long password, without a password manager? Easier than a passkey? Easier than an OTP sent to the same email address?
This sentence reads to me as one written by someone mostly working and _living_ from a single laptop and mobile device. The second part of the sentence, calling for more sites to do this is why I am writing this.
For any scenario with a minimal amount of complexity, like users with multiple computers, and you're looking at a scenario where the site's unwillingness to deal with other login methods shoves friction on the end-user.
### What makes them tragic:
1. Multiple devices. Who doesn't use at least a few computers weekly? I don't have my email on my gaming PC, nor do I have it on my work laptops. 1. Slower. From 2 seconds slower to minutes slower, depending on SMTP delays as well as how awkward it is to get the link to the right browser. 1. Anti-mobile. As mentioned by 404 in their own article, this breaks the ability to use in-app browsers, which is quite annoying especially for RSS reader type apps. It makes interacting with any local link in the RSS feed extremely annoying. 1. Indirect security downsides. Pushing people to access personal email on work devices (or vice-versa) isn't exactly a win for security.
Another annoying _passwordless_ system is to email or SMS an OTP the end user can type in.
While this sucks, it at least allows you to easily log in in situations where you don't have a clear and easy copy/paste path from the email client to the browser you want to log in to.
[Stratechery](https://stratechery.com/), powered by [Passport](https://passport.online), uses this type of scheme (click link OR type in OTP), which is still shifting annoyances onto end-users to free developers from implementing passkeys, but at least has a bit more of an appreciation for end-users.
If you insist on using magic/tragic links by default, at least consider offering a robust alternative, such as [passkeys](https://fidoalliance.org/passkeys/), especially if your audience is technical and privacy-focused.
edit: saw that nicce basically said that a second before I hit post.
Good luck with your product. As someone who regularly worked with tools like R Studio or Jupyter notebooks, it boggles my mind to still see monthly and quarterly presentations that are the same, except for some (badly) copy-pasta'd data, so there is a need for this!
One thing that could be useful though is the ability to export a snapshot of what the slides would've been on any given day, for reference in the future (data might not be available in 2 years etc).
I will go through the comments later, but for now, if you are Canadian, please get in touch with your MPs.
I am working with some media as well for additional coverage in the next week, but if you know Canadian journalists that might be interested in this, please get in touch with them, educate them directly if you want or send them to me (my LinkedIn is in the signatures, the first two names in bold = authors).
Thanks for helping this story reach more people.
1. Off-the-shelf malware exfiltrates data, as seen in ransom attacks. I'd feel better if the index was encrypted. It's unlikely an attacker would manually spend time trying to find the keys in RAM unless your app became very famous :)
2. Syncing files on a work laptop where IT might snoop.
Obsidian does not encrypt files at all locally, and for that reason I would feel quite self-conscious about loading a vault with potentially private notes.
Ironically, Obsidian is much better if you only have ONE big vault, but because of this, I have to live with 3 vaults (different threat models for each).
Once the CI/CD environment is compromised, how would the SBoM be trustworthy anyway?