11 karma · joined August 29, 2021
[0]https://www.tesla.com/blog/panasonic-enters-supply-agreement...
Do you have plans on having something like export to SQL or import from SQL?
I know this is a bit paranoic but its the best i can do. Also most of my passwords are on a kpdb file so with the master credentials someone could get all the access to everything (that would go to my VERY close family for example)
my way of tokenizing: https://github.com/chrsBlank/Fernet_Tokenization i posted here before, i am making a social app and i dont like JWT tokenization so i made my own.
fbchatbot: https://github.com/chrsBlank/FbChatBot no longer working due to facebook api changes, i wrote that at 16yo because i could not focus on studying since i was talking to people on FB back then, this sent automatic messages and if the message contained "important" i would get a desktop notification
small toolset for various things: https://github.com/chrsBlank/autosave started as an autosaver (ctrl-S) and has more stuff implemented, i actively add more things that my coworkers ask.
Cayde,Newlight,SmartS: all projects that "started" either with friends or alone and never came to actually make them. Cayde is my personal AI that runs on a personal server (no data leaves the LAN). NewLight was gonna be an encrypted P2P messager with interesting features. SmartS would have been a "cart" for websites that could predict if the price would go down soon telling you to hold. All public on my GH: https://github.com/chrsBlank
If you decide to go with it, i recommend that you get a domain and set it up as a DDNS through cloudflare.
1)Allowing the server to use a token without validation.
2)Using the same private key for different applications.
3)Using a weak signing algorithm.
4)Choosing a short and/or low-entropy private key.
5)Keeping sensitive data in a JWT's payload.
6)Confusing the keys.
I encourage the storing of the token so you can cross check the information with a "local authentic copy". That way issues 1 and 6 of JWT are fixed and issue 5 since you dont actually store "information" in the key EVEN if someone steals your key he can not steal sensitive data from it. Now i put information in quotes because you do put something, ike the username to make the key unique to to user, but username was already "public information" so no "user personal data" leakage in case of a disaster.Thanks for your feedback : )
To address issues 2,3 and 4 2) You may use the "same key" but you have the option to change it whenever you want 3/4) Fernet is a VERY strong encryption algorythm
For anyone interested -> https://www.amazon.com/Altered-Carbon-Richard-K-Morgan/dp/07... (there is also the takeshi kovacs novel which i found that it isnt different )
Having a constant flow of these data can make a pretty accurate "end-product" document.