HNHacker News
TopNewBestAskShowJobs

kenniskrag

509 karma · joined June 23, 2019

submissionscomments
kenniskrag··on Small programming tricks
You have a link? :-) (Still a student)
kenniskrag··on Giving up on smart rings
In a hospital, they may need to remove the ring quickly for example, if your finger was injured and begins to swell.
kenniskrag··on How Fairphone built the Fairphone Gen 6+
Certification takes time and probably overlaped with the phone development. Fairephone is small compared to e.g. samsung and they describe themself more "stable" and long-term support than bleeding edge.
kenniskrag··on 4.5B Posts Scraped from TikTok
Because a lot of things is public online and can't be copied and sold e.g. due to copyright, patents and trademark. Also if you access a website you are bound to a ToS contract and this is a breach of that contract.
kenniskrag··on AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint
Yes. In this case probably not fineeprinting is not allowed because not strictly necessary (cookie law) and therefore needs consent from user.
kenniskrag··on AliExpress runs silent WebAudio fingerprinting that breaks Bluetooth multipoint
Yes. In this case probably not allowed because not strictly necessary (cookie law) and therefore needs consent from user.
kenniskrag··on Software Engineering fundamentals matter more
The problem with this analogy is responsibility. Same set of problems if you have a self driving car imho. Not?
kenniskrag··on AI agent hacks gym to get its user a spot in pilates class
If you publish the bug then it could be unfair competition in my opinion. There was a product test where the mentioned some flaws of a medicine but didnt mention other producers of same drug. They broke the UC rules and paid some money: https://politchronik.swiss/de/prozesse/57953-das-kassensturz...
kenniskrag··on AI agent hacks gym to get its user a spot in pilates class
If you access "private" data it's also unlawful acording to 143. Pentesting is a hot topic but there are comapnys acusing you of hacking if you send them a security report (hacking). If they mention a bug bounty program then you are allowed to test their security as described in this program but not more.
kenniskrag··on AI agent hacks gym to get its user a spot in pilates class
In switzerland it depends 143bis StGB:

Any person who, with the intention of securing an unlawful gain for themselves or another obtains for themselves or another data that are stored or transmitted electronically or in some similar manner and which are not intended for them and have been specially secured to prevent their access shall be liable to a custodial sentence not exceeding five years or to a monetary penalty.

kenniskrag··on Tailscale didn't stop the Hugging Face intrusion
Env variables are considered best practice (factor 3): https://developer.ibm.com/articles/creating-a-12-factor-appl...

If I would avoid env then i need to put it in some kind of conf file and configure the app to read this file (e.g. mount into container). If I use a fault then i need some kind of credentials to receive the credentials.

So again what do I gain if I avoid env variables in containers?

kenniskrag··on Tailscale didn't stop the Hugging Face intrusion
Why should that help to have no env variables?
kenniskrag··on 'VPNs are lawful technical tools,' says EU Court in landmark copyright ruling
I just use my home router as VPN to not care if the 100 apps om my phone have a working encryption. I also use it to access my home services so that they are not exposed to the internet. I also use it to limit exposure on my VMs on a cloud hoster.
kenniskrag··on The unreasonable difficulty of time series forecasting
Exists randomness or is it just lack of information? :)
kenniskrag··on EF Core 11 makes your split queries faster
I think compression would reduce the problem not? I think if you swap the wire format to something like jsonb you would need to parse it again anyway and pay the cpu time.
kenniskrag··on DNSSEC disruption affecting .de domains – Resolved
acme.sh supports multiple CAs there is even a RFC for CAs that describe the api.
kenniskrag··on DNSSEC disruption affecting .de domains – Resolved
I would define high as "double time needed to fix a dns issue" and account for weekends
kenniskrag··on Microsoft Edge stores all passwords in memory in clear text, even when unused
What's the threat model. Where do you store the decryption key?

E.g. if my app needs a db connection I can ask a vault service but I need creds for that. The vault service can rotate the creds very fast but is it addition security.

kenniskrag··on Microsoft Edge stores all passwords in memory in clear text, even when unused
Edit:

Banking has no selfservice password reset. A lot of work for customer support due to identification. Nobody wants to do that for free and if the accounts are freenyou may get DOSed by bots which trigger passwort resets.

kenniskrag··on Microsoft Edge stores all passwords in memory in clear text, even when unused
> But then your hardware dies

A lot of services have password reset email features. If the email account has passkey you're screwed. But restore by snail mail can be possible but slow (for paid services). More secure? Don't know but same category of problems already known due to sim swapping attacks in mobile sector. But for sure the Mail account is a high value target.

Storing passkeys in a database may be possible but complex to do it right e.g. backup verification, avoiding to leak while backup etc.

kenniskrag··on Mastodon: Don't use "Mastodon" or "mstdn" in domain names
Pull request to notify on setup (2 weeks old): https://github.com/mastodon/mastodon/pull/38548
kenniskrag··on State of Homelab 2026
Is that legal? Do you avoid uploading somehow?
kenniskrag··on Password managers less secure than promised
Not if the advertise zero knowledge encryption. As far as I understand the password sharing / collaboration feature is often the problem.

Second: The provider can get the passwords with a simple server change.

kenniskrag··on Password managers less secure than promised
> Much like the other products we analyse, 1Password lacks authentication of public keys. This trivially enables sharing attacks similar to BW09, LP07 and DL02, something that the 1Password whitepaper...

> IMPACT. Complete compromise of vault confidentiality and integrity. The adversary can read and decrypt all vault con- tents encrypted after the attack, including passwords, credit card information, secure notes, and other sensitive data stored in the vault. Similarly, they can inject new items into the vault after the attack. REQUIREMENTS. The client fetches key material from the server, for example due to the user logging in on a new device. If executed on a non-empty vault, the attack results in the client losing access to all items already in their vault, while leaking any new items added to the vault after the attack took place. If the attack is executed at the time of vault creation, the attack is effectively undetectable by the client, since it cannot distinguish between a ciphertext it created and the ciphertext created by the server during the attack. PROPOSED MITIGATION. A straightforward mitigation is to have the client sign vault keys using the RSA private key in the keyset before encrypting them with the RSA public key. Ideally, two different key pairs would be used for...

from the paper: https://eprint.iacr.org/2026/058.pdf

kenniskrag··on Discord Alternatives, Ranked
In europe you need identification to buy a sim or esim.

https://www.reddit.com/r/europe/comments/9ziqfi/european_cou...

kenniskrag··on Supreme Court wants US input on whether ISPs should be liable for users' piracy
> online access is as necessary as water We have paper money and also can work and buy stuff offline.

I would say online access is as necessary as a car. Possible without but less flexible.

kenniskrag··on Supreme Court wants US input on whether ISPs should be liable for users' piracy
Driving licence is a bad argument because there is public transportation service. If you're reckless or have other issues the licence is revoked.
kenniskrag··on We are shutting down Ondsel
One reason was, that the security model wasn't enough anymore. E.g. every application was trusted and can listen to key inputs e.g. steal passwords and credit card infos. Btw there was an issue that screenshotting in wayland was not possible. But easy in X11 because everything was visible.

Don't know much about the architecture about wayland but I think grahic driver handling changed in wayland too.

kenniskrag··on Andrew S. Tanenbaum Receives ACM Software System Award
One of these: https://media.pearsoncmg.com/bc/abp/cs-resources/products/se...
kenniskrag··on Please support "skip to main content" on your docs site
qutebrowser does that.

https://en.m.wikipedia.org/wiki/Qutebrowser

Page 1 of 11Next →