Skip Navigation

Posts
21
Comments
42
Joined
2 wk. ago

"People are arseholes. They're just always gonna be that way."

  • I feel the same way, but can you explain how a VPN would help achieve that in the face of Google’s proposed developer verification scheme?

  • How would that help you?

    The article says, "unverified apps will only be easily installable in the sanctioned countries where verification doesn’t exist."

    So even if you used a VPN to trick Google into thinking you live in a sanctioned country, you wouldn't be able to distribute apps to those countries without breaking sanctions.

  • it'd be like saying we should disarm Ukraine, 'cause then Russia doesn't have a reason to invade them

    Putin's All-Russia People's Front's policies toward Ukraine have many similarities to Netanyahu's Likud party's policies toward Gaza. Both sets of policies are tragic, causing many innocent people's deaths.

    Nevertheless, Ukraine and Gaza are different enough for one to reasonably reach different conclusions about how best peace can be achieved in each place:

    • Ukraine's weapons are protecting Ukraine against Russian attacks and invasion attempts. Therefore, it is in Ukraine's interests to have them. Hamas's weapons are not protecting Gaza against Israeli attacks or invasion. There is no obvious benefit from Hamas having them.
    • Servant of the People, and Ukraine, do recognise Russia, and have not seriously proposed eliminating it. Hamas does not officially recognise Israel, and has seriously proposed eliminating it.
    • Argentina, Australia, Canada, Costa Rica, Ecuador, Honduras, Israel, Japan, New Zealand, Paraguay, Philippines, Switzerland, Trinidad and Tobago, the UK, the USA, the EU, and the Organization of American States, all designate Hamas a terrorist organisation. This reduces the aid Gaza receives. They seem unlikely to reverse the designation unless Hamas disarms. None of them designate Servant of the People, or Ukraine, a terrorist organisation.

    Those points lead me to believe Hamas should disarm.

    I also believe countries giving aid to Israel should make it formally contingent on Israel withdrawing from Gaza and the West Bank, to pre-1967 borders, and recognising Palestinian statehood. However, it looks like the US is going to stop aid to Israel regardless.

  • Trust isn't really the point. Everyone knows Israel and Hamas don't trust each other. I'm more concerned with whether the violent conflict can be reduced, and a stable peace achieved.

    Are Hamas's arms doing Gaza any favours? Not that I can see.

    AFAICT, if Hamas disarmed:

    • Israel's only(?) excuse for mass military action in Gaza would disappear.
    • International support (already shaky) for Israeli military presence in Gaza would decrease.
    • One or more of Australia, Canada, Costa Rica, Ecuador, Honduras, Israel, Japan, New Zealand, Paraguay, Trinidad and Tobago, the United Kingdom, the United States, or the European Union might end their designation of Hamas as a terrorist organisation, which could in turn increase the aid and other international support available to Gaza.

    If you think I'm wrong, I'd be glad to know why.

  • Terrorism arises in defense to oppression.

    Technical point: that isn't exhaustively true. Terrorism can be, and sometimes is, committed against vulnerable parties by more privileged ones.

  • Progress report 1

    • I'm ruling out HMAC-SHA1, because:
    • If using systemd, pick FIDO2:
      • Avoids flaws of HMAC-SHA1.
      • Native support in systemd, so "future-proof".
      • Wider support than OpenPGP. More HST vendors to choose from, including cheaper options than NitroKey or Yubikey: useful if each sysadmin (or colleague, or relative) needs an HST.
      • Compatible with QubesOS.
    • Otherwise, OpenPGP:
      • Like FIDO2, solves HMAC-SHA1 flaws.
      • However:
        • smartcard-key-luks seems unmaintained on GitHub and on GitLab.
        • LUKS with OpenPGP isn't well-documented for non-Debian-based distros.
    • TBD: Clevis/Tang:
      • Remote/network-based unlocking.
  • Thank you for this! That thread is helpful in itself, and also links to other relevant resources - including by Lennart Poettering (controversial guy, but the canonical source on systemd).

  • their setup required a couple large antennas that the victim would need to stand in between. Not impossible, but you'd notice with each side being half a meter away.

    So yes, it's a technical risk, but not one that I'd bother putting much effort into avoiding. And the being able to use the key via NFC is probably worth the risk.

    This was my conclusion, too, but I didn't want to prejudice the discussion. Thanks for corroborating.

    IMO, using a Faraday pouch isn't "much effort", and is therefore worth doing if the HST is being carried in unfamiliar/non-secure locations.

  • Uplifting News @lemmy.world

    German startup to scale up fully recyclable wind turbine blades

    recyclingportal.eu /archive/96839
  • Even if you can [exploit NFC] at 1m, thats close enough that it can just be stolen from you.

    Stealing the HST should not give the user a false sense of security. Not so dangerous.

    Silently exfiltrating the private key (or data for a replay attack), OTOH, would leave the user with a false sense of security. Dangerous.

    your link to rfidgate appears broken

    Wfm. Here's an archive link.

  • Cybersecurity @sh.itjust.works

    Are NFC hardware tokens (Yubikey, NitroKey) less secure than USB-only ones? If so, how to mitigate?

  • politics @lemmy.world

    Full text of the roadmap for Hamas to disarm and Israel to leave Gaza

    apnews.com /article/gaza-hamas-israel-deal-text-7347ef0f3b745f22c12b67f786b70f0f
  • Uplifting News @lemmy.world

    AI labels to be compulsory on authentic-looking content under EU rules

    www.theguardian.com /technology/2026/jul/31/ai-labels-to-be-compulsory-on-authentic-looking-content-under-eu-rules
  • Buy European @feddit.uk

    AI labels to be compulsory on authentic-looking content under EU rules

    www.theguardian.com /technology/2026/jul/31/ai-labels-to-be-compulsory-on-authentic-looking-content-under-eu-rules
  • Fuck AI @lemmy.world

    AI labels to be compulsory on authentic-looking content under EU rules

    www.theguardian.com /technology/2026/jul/31/ai-labels-to-be-compulsory-on-authentic-looking-content-under-eu-rules
  • Fuck AI @lemmy.world

    EU to crack down on AI deepfakes, illicit imagery and hacking with new team in Brussels

    apnews.com /article/eu-ai-regulation-deepfakes-hacking-f4fcee1f9750e2b32cdf26ad73ee5ec2
  • If it's a server for self hosting you definitely don't want anything that requires interaction at boot.

    Depends on use-case. If you only plan to boot it when you're physically present, it's fine.

  • i believe a much better secure layer is something similar to what Novacustoms, Purism attempt to do: verify if somebody else not you try to access the laptop.

    You're thinking of Heads, which I agree is ideal for supported motherboards.

  • Uplifting News @lemmy.world

    EU to crack down on AI deepfakes, illicit imagery and hacking with new team in Brussels

    apnews.com /article/eu-ai-regulation-deepfakes-hacking-f4fcee1f9750e2b32cdf26ad73ee5ec2
  • I read them before writing my OP. I'm still not sure what you're getting at.

    I would be grateful if you could say what you mean, instead of initiating an oblique guessing game.

  • Yes. Here are some common self-hosting scenarios:

    • Home server containing family files: scans, photos, device backups, ...
    • Office server containing business files: sensitive documents, device backups, ...
    • Web or email server containing websites, Fediverse instances, emails, etc

    In all those cases, full disk encryption (FDE) is a sensible precaution to protect the data in case the server is physically stolen.

    Linux is probably the most common OS kernel for self-hosting. On Linux, LUKS (Linux Unified Key Setup) is probably the best FDE system. It's mature and reliable. But anyone self-hosting a Linux server with LUKS FDE is faced with the question of where to store the keys.

    Hardware security tokens (HSTs) are widely considered a safer place for keys than SSDs, HDDs, or USB storage. They follow the smartcard principle: a private key can be written to an HST but not read from it (security vulnerabilities excepted). Instead, they implement cryptographic algorithms to prove possession of the private key. So, anyone self-hosting a Linux server with LUKS FDE should strongly consider storing their private key(s) on an HST.

    However, there is more than one way to do that. Hence the question in my OP.

  • Homelab @selfhosted.forum

    Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?

  • Selfhosted @lemmy.world

    Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?

  • Linux @lemmy.world

    Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?

  • Linux @programming.dev

    Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?

  • Linux @sh.itjust.works

    Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?

  • Sysadmin @lemmy.world

    Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?

  • Linux @lemmy.ml

    Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?

  • AskMbin @thebrainbin.org

    The "Tags" field in Mbin

  • Climate @slrpnk.net

    Drought leaves Swiss border lake popular with tourists all but drained

    www.reuters.com /business/environment/drought-leaves-swiss-border-lake-popular-with-tourists-all-drained-2026-07-30/
  • Vegan @slrpnk.net

    Study finds that industrial chicken farms are accelerating the spread of a major foodborne disease

    www.ox.ac.uk /news/2026-07-24-study-finds-that-industrial-chicken-farms-are-accelerating-the-spread-of-a-major
  • Linux @lemmy.ml

    Ptouch-print compile error: Could not find GD library

  • AskMbin @thebrainbin.org

    Is there a fix for, "This profile is from a federated server and may be incomplete."