2,956 karma · joined August 29, 2013
By keeping him out of jail, Mi5 stood to gain more intelligence
We noticed one of our partner websites had an unusual number of unique ingredients. It turned out every ingredient was a link to another recipe to make that ingredient, along the lines of your idea.
However for some reason (presumably SEO) they took this to the extreme and everything was a recipe. Including apples.
The recipe for “apple” is
1. Take 1 Apple
2. Eat and enjoy
But since Apple is a prerequisite for this recipe, infinite looping is a risk in the kitchen now
I sit with a pile of raspberry Pis I throw into different rooms about the house and want to stick assorted tasks on them. My open question was how can I just image them, plug them in and centrally configure what runs on them with no more sd card or Mac detection shenanigans when I change their job.
I’ll be giving this a try!
Granted they didn’t break the session in flight, but there is a low bar to achieve the same thing
I rate this more likely and it’s one reason I still use TOTP stored in the same place as the password for other services.
A lot of sites are susceptible to cdn JavaScript compromises, and at least with TOTP stored in the same place as the password, a password replay attack has a very tight window of usability
It has become quite a community around the software and breakout hardware in itself
On the other hand, I think any ISP at the mercy of openreach is doomed to have limited support.
I have fibre to the property, and was having periods of 1hr-2hr day of my gigabit speeds dropping to 4-5MB. openreach themselves were blindly sending engineers to look for an issue that couldn’t physically be at my house.
Not much you can do there either as an ISP or as a customer besides wait for openreach to figure out they’re wasting their own time
- we don’t comment on individuals
- we don’t comment on hypotheticals
- we don’t comment on anonymous sources
- we don’t comment on politics.
TL;DR we don’t comment on anything, ask someone else!
I really don’t like hardware becoming waste because we don’t have a better iot cert pool update story
I trust YouTube to know how to bake their own cert and trustworthy tls libraries into their apps but I’m not sure if that’s common in other apps
GitHub actions auto build new version releases for me so major versions become available as soon as they are released and I click the button
My understanding is power is expended when current flows through a metal with resistance, and that loss is in the form of heat. The lower the resistance, the lower the loss and therefore lower the heat
This would be an extension of the recent HSTS preload list trend of associating a particular TLD (e.g. .dev) with a particular mechanism, and would not affect other tlds than (say) .lan or ip ranges
If you directly went to 10.254.127.1, or some-domain.lan, that should validate differently to going to accounts.google.com
Until I hear a convincing story of how I will do the usual lan tasks of
- connect to my router to fiddle with settings
- see the management interface on my printer
- join my parents network and do things for them without having to explicitly trust a CA
- And most importantly, see consumers who don't understand any of those things be able to do these things all out of the box
I can't see how it is a viable expectation
I totally love encryption. It's great. But seriously: what domain will I visit to fix my pppoe settings. Who's going to control that domain, and who's going to renew the certs for it. Because if the answer we will expect consumers and SMEs to trust a certificate authority created by a factory with its own crappy security practices, I'm not sure how that's an improvement
Otherwise we are breaking things to "fix" something that doesn't "fix" anything. if someone is MITMing my lan, it doesn't matter whether my router is TLS or not. it's compromised
I am pro-HTTP for these use cases for as long as browsers have more serious warnings against self signed certs, old SSL/TLS versions and weak algo choices than the warnings for HTTP.
Hardware deserves to be supported as long as it physically works rather than as long as its embedded TLS stays supported