HNHacker News
TopNewBestAskShowJobs

vanburen

4,768 karma · joined June 27, 2016

submissionscomments
vanburen··on Have you restarted your computer this week?
Something like the Casio GW-M5610-1ER would be good option.

Charges from solar and can get time updates over Multiband 6 if your region has coverage.

vanburen··on SMS 2FA is not just insecure, it's also hostile to mountain people
You can also get antennas with suction cups. I have used this before to get 4G internet in a house with no access downstairs, by sticking the antenna on an upstairs window.

An outdoor antenna would be better, but yeah more of a pain. I guess it really depends on how badly someone wants SMS.

vanburen··on SMS 2FA is not just insecure, it's also hostile to mountain people
Yeah wont work for everyone, but a directional antenna mounted high up on house might have a better chance than a phone antenna.
vanburen··on SMS 2FA is not just insecure, it's also hostile to mountain people
Yeah this is a big problem. I have been sent 2F messages via WhatsApp by some services (e.g. PayPal).

This isn't great, but better then SMS and having to have a separate app for each authenticating service though.

A vendor neutral service would be a lot nicer.

vanburen··on SMS 2FA is not just insecure, it's also hostile to mountain people
If cell service is available in at least one area of the property, you could have a dedicated sim for receiving SMS 2FA and use a 4G router to forward the SMS to an email, e.g. Teltonika have this functionality [1].

The 4G router also has the benefit of being able to use externally mounted antennas. Which might help in low signal areas.

Not ideal, but might at least be a solution for some people.

[1]: https://wiki.teltonika-networks.com/view/SMS_Forwarding_Conf...

vanburen··on FIDO Alliance publishes new spec to let users move passkeys across providers
Agree. Passkey should be reserved for credentials that can be synced or exported to different providers, as this is what is most analogous to a password from a user perspective.

There should be a different standardized term used for hardware bound keys. So users wont get confused.

vanburen··on NanoKVM: Affordable, Multifunctional, Nano RISC-V IP-KVM
This article has some more details: https://www.cnx-software.com/2024/07/08/20-nanokvm-is-a-tiny...
vanburen··on The Era of the Line Cook
https://archive.ph/8x3LK
vanburen··on Passkeys: A shattered dream
Totally agree with this.

I wish Yubikey allowed users to import their own FIDO2/webauthn seed and overwrite the factory generated one, and then also allow the resident passkey functionality to be disabled.

It should be up to the user if they want to have multiple duplicate hardware authenticators and be able to backup their seed however they wish.

vanburen··on Passkeys: A shattered dream
Usernameless always seemed like an optimization too far to me.

I think it's totally reasonable, and probably a good thing for users having to use their username at login. Especially as it reminds them what username they are using for that service.

I could totally see a situation where a user uses a Usernameless passkey for years to access a service and for some reason loses access to the Usernameless passkey, and then has also forgotten the username for the service, so cannot even start an account recovery process.

vanburen··on Experimental Alzheimer's, drug addiction ultrasound trials helping patients
Youtube link for the 60 mins episode: https://www.youtube.com/watch?v=7BGtVJ3lBdE
vanburen··on Wi-Fi jamming to knock out cameras suspected in nine Minnesota burglaries
Single pair Ethernet would be a great option for home automation.

I think it is mostly used for industrial applications at the moment, but don't see why it cant be used in consumer applications as well

vanburen··on Limitless white hydrogen under our feet may soon shatter all energy assumptions
Non pay-walled link: https://archive.ph/3c7Hs
vanburen··on Ask HN: IP cameras that don't require an app or internet?
I just purchased an Amcrest IP4M-1041B and IP4M-1041W (Different colors of the same model) and they have a functional web interface.

They are available on Amazon.

vanburen··on OpenGL 3.1 on Asahi Linux
"New firmware-based battery charge control, which offers fixed a 75%/80% threshold setting. To use this, you need to update your system firmware to at least version 13.0, which you can do by simply updating your macOS partition to at least that version or newer. This new charge control method also works in sleep mode."

This is interesting, am I correct in thinking this a feature implemented by Apple and now supported by the Asahi team? Does that mean that macOS supports this charge control feature?

I really hope Apple brings the same charge limiting to iPhone as well.

vanburen··on OpenEPaperLink: Alternative Firmware for ZBS243-Based eInk Shelf Labels
It would be awesome if smart shelf labels could be used to help customers to search for and locate specific items in a store.

Something ultra wideband based, like air tags, would be great.

vanburen··on AMD Dragon Range 12-Core Mobile CPU Is 90% Faster Than Ryzen 6900HX in PassMark
Thanks for pointing that out, I changed Intel to Ryzen in the title.
vanburen··on Tell HN: Google deleted my spreadsheet, review request says file can't be found
Sorry to hear you lost access to the document, I hope you can regain access.

It might be be a good idea to use a tool like Rclone to create a local copy of the data going forward. It allows you to download Google sheets as .xlsx files.

vanburen··on FIDO Alliance
Personally I would store it in a Keepass DB stored offline on a USB drive, in a safe location.
vanburen··on FIDO Alliance
At least as I understand it, in implementations like yubikey the FIDO2 secret is baked-in to the yubikey for security, which is good as it shouldn't be possible to remove the private key.

However the main issue I have is that the user cannot import their own secret into the yubikey, so you cannot choose to use your own secret vs the factory generated one, or choose to have multiple yubikeys using the same secret, which would be useful as you wouldnt need to enrol multiple secrets with each service.

vanburen··on Examining Btrfs
I think Synology runs BTRFS on top of LVM, so that may mitigate some of the issues.
vanburen··on How to bypass Sprint/T-Mobile 2FA in under 5 minutes
"24 words written on paper."

That's cool, I didn't realise it was possible to backup the webauthn secret this way.

I googled but couldn't find any documentation on how to set this up, could you let me know how you set this up?

Not being able to make backup of the Webauthn secret is why I have stuck with TOTP so far.

vanburen··on Apple's iCloud+ “VPN”
It may be worth looking at the AAISP L2TP Service[1].

They are a domestic ISP, so I guess iplayer should work over the service.

[1]: https://www.aa.net.uk/broadband/l2tp-service/

vanburen··on Don't use third party auth to sign in
It should be possible to enable Cloud Identity Free on your gsuite tenant. So you can use a free identity account for your admin account and only pay for gsuite on your main email account.

https://support.google.com/cloudidentity/answer/7384506?hl=e...

vanburen··on OVH Cloud shuts down Guerrilla Mail
Maybe they should look at hosting at 1984.is instead, as they seem to have a more robust policy in place regarding take downs:

"Unwavering loyalty to our customers and their fundamental rights is a core value of 1984, hence the name to remind us of what can happen if we fall asleep on our watch. We state that 1984 as a company and its officers will always go the extra mile to protect our customers' civil rights, including the freedom of expression, the freedom of the press, the right to anonymity and privacy. 1984 will always do everything within its legal power to inform our customers of any inquiries from any authorities, lawyers or courts into the customer's affairs that we may become aware of. It is essential that the jurisdiction that the company operates in is Iceland, where the IMMI legislation is forthcoming, making Iceland a haven for freedom of the press and freedom of expression in general." [1]

[1]: https://www.1984.is/about/

vanburen··on If Not SPAs, What?
The hydrogen client for matrix.org (1) has an interesting approach using vanilla JavaScript and indexeddb.

From a previous this week in matrix(2): "Hydrogen tries to be the lightest Element. It is written entirely in vanilla javascript (no React, no Webpack) for complete control, structured as an MVVM app, leveraging the raw performance of indexeddb."

(1) https://github.com/vector-im/hydrogen-web (2)https://matrix.org/blog/2020/08/14/this-week-in-matrix-2020-...

vanburen··on Riot is now Element
Agree, it would of been better to focus on a name where getting the .com was feasible. At least element is better than riot.
vanburen··on Trello handed over my personal account to my previous company
If the boards contained personally identifiable information and then that data was transferred so that other people could access it, wouldn't that be considered a data breach?

I guess people affected by this could submit a subject access request to get their data back.

vanburen··on PrivateStorage.io: A secure and privacy-focused cloud storage solution
I think it has been considered:

https://github.com/syncthing/syncthing/issues/109

https://www.bountysource.com/issues/1474343-support-for-file...

https://forum.syncthing.net/t/encryption-for-remote-syncthin...

Unfortunately there doesn't seem to have been much movement towards making it a feature.

vanburen··on What Can I Do About Bufferbloat?
This video gives an overview of setting up the EdgeRouter X: https://www.youtube.com/watch?v=o-g2P3R84dw
Page 1 of 2Next →