HNHacker News
TopNewBestAskShowJobs

jlmb

60 karma · joined June 19, 2019

submissionscomments
jlmb··on LibreWolf – Custom version of Firefox, focused on privacy, security and freedom
This approach also assumes that you then compile the browser from source yourself (and also do that for each future update).
jlmb··on Passwords Are Fine
But you can also use passkeys from a computer, no separate mobile device needed!

And for services (like AWS) that don't (yet) support passkeys, a hardware token like a YubiKey is also an option.

jlmb··on Passwords Are Fine
“Passwords are fine” only in a theoretical world where everyone uses passwords “correctly” and securely. But in the real world people don’t, so passkeys are a much better and easier method.

I fail to understand how educating billions (?) of people about proper password hygiene is faster or simpler than moving all authentication to a “tap this button to magically log in” method.

jlmb··on Instagram is threatening legal action against Pixelfed
There is this additional post:

“Someone who works at Meta reached out and advised me to rename the filters asap.” [1]

So maybe the issue is simply that Pixelfed is using identical filter names.

[1] https://mastodon.social/@dansup/109596825332511647

jlmb··on “I’m selling data of 400M Twitter users that was scraped via a vulnerability”
Phone number verification (of any kind) is supposed to make sure that the phone number provided belongs to the account owner.

If the number is not actually validated in a secure (enough) manner, there's no point in using phone numbers at all.

jlmb··on “I’m selling data of 400M Twitter users that was scraped via a vulnerability”
I think the main problem is that SMS sender numbers can be easily spoofed (might depend on country, operator, …), so relying on “this message came from where it says it came from” is not really possible.

It might not be an issue for some types of usage, but sounds risky if used for account security/recovery/etc.

jlmb··on Cloudflare CDN Partial Outage
This is not specifically about Cloudflare’s “challenges“/etc, but —

The reality of operating a big site/service on the internet in 2022 is that it’s sometimes necessary to use methods that annoy a few people (with very non-standard browser settings) in order to protect the service as a whole from a million bots trying to attack it at any given time.

jlmb··on In defense of cryptocurrency
In reality, a crypto wallet is better compared to a bank account, though. Most people don't carry their life savings (or comparable amounts) in cash.
jlmb··on Apple Cash
It's apparently called “proxy payment”: https://www.lhv.ee/en/proxypayment
jlmb··on Apple Cash
In Estonia, you can link a phone number to your IBAN. When making payments, the sender just needs a phone number, and the corresponding IBAN is automatically looked up. (The lookup service is managed by the central bank, and used by all (major) banks.)
jlmb··on Terraria on Stadia cancelled after developer's Google account gets locked
But surely it’s possible to use methods other than what currently seems to be the first and only solution: “your account has been banned, bye”.

For example, if an automated system thinks an account is sending spam, enforcing a (very low) outgoing email rate limit would be a much more reasonable first step.

jlmb··on Our Quest for Faster Boot Times and Offline Support
Maybe, but I would actually argue with the assumption that an image editor is somehow inherently (allowed to be) “more complicated and/or slow” than a productivity app.

Or, more simply: Slack (and other similar products) are not just “chat applications”.

jlmb··on Our Quest for Faster Boot Times and Offline Support
I’m curious: why would you consider Slack to be “simple”?

I see Slack as an incredibly full-featured app. As always, many people might not use all the features, but that doesn't mean that nobody does…

jlmb··on Investigating the impact removing password masking has on consumer trust (2014)
When using a password manager you don't need to ”check the input” or “correct an error” or “see what characters have been typed" (the only ”usability problems” mentioned in the article)