Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)EM
Posts
0
Comments
157
Joined
2 yr. ago

  • The way this works in the server world is "95th percentile" billing. They track your bandwidth usage over the course of the month (probably in 5 minute intervals), strike off the 5% highest peaks, and your bill for the month is based on the highest usage remaining.

    That's considerably more honest than charging you based solely on the highest usage you could theoretically use at any time point in a 24 hour period (which is how ISPs define the "max bandwidth") and then charging you again or cutting off your service if you use more than a certain amount they won't even put in writing.

  • It's a step, but only a small one. Still need to do the same for transition related care. And immigrants. And move to require warrants. In fact, there's no legitimate reason to hand these kinds of records over to law enforcement in the first place

  • Probably not. It looks like it's setting the fake address before reading the tunnel parameters, where the real address is stored. Probably a kludge in case the connection address is undefined so the program doesn't crash. So check whether the address is included there.

    Also check the function that establishes the connection. 10.1.1.1 is not a public subnet, so unless there is a VPN device listening at the local address, the tunnel should fail to establish and throw an error, triggering the exception clause in that code. Again, you'll want to confirm that in the code.

  • If your usecase and threat model don't require the pinpad, Onlykey Duo is worth a look. No pin, USB A or C, and still gives you 6 slots to support any combination of Fido2, TOTP, SSH, PGP, and password storage.

  • Manually keying in the pin is only needed when plugging in the device. Challenges for TOTP, FIDO2, etc. are a configuration option, and are only 3 digits if enabled (press any button if disabled).

    As for "excessive amount of security", security as an absolute measure isn't a great way to think about it. Use case and threat model are more apt.

    For use case, I'll point out it's also a PGP and SSH device, where there is no third party server applying the first factor (something you know) and needs to apply both factors on device.

    For threat model, I'll give the example of an activist who is arrested. If their e-mail provider is in the country, they can compel the provider to give them access, allowing them to reset passwords on other more secure services hosted outside the country. The police now have the second factor (something you have), but can't use it because it's locked.

  • https://onlykey.io/

    Built in hardware pin entry means your unlock code can't be captured by a compromised machine. Emulates Yubikey if you need that, handles Fido / U2F, stores up to 12 passwords, acts as PGP and SSH key if you install the (open source) agent.

    The SSH agent implementation is forked from https://trezor.io/ which is advertised more for crypyo wallet uses.

    Edit: For OP's concern about losing the key, it also has the ability to export an encrypted backup that can be restored to a replacement key

  • Even more extreme, actually. I knew one person who was actually, honestly, voluntarily homeless. For years. Living on the street, no car. No obvious mental health issues, had family who would have been happy to take him in, strong social network, active in the community. Didn't want to be tied to all of the things ownership of stuff brings, and was willing to make the many and extreme sacrifices that entails.

    To be clear, this is not the normal homelessness experience. I've known too many homeless people, and the right-wing conspiracy theories of middle to upper class panhandlers on every corner are utter nonsense. Ideologically motivated self justifying cruelty inspiring bullshit. Even when homeless people I have known said it was by choice, I usually knew enough about their situation to recognize it as a face saving salve to their pride (a hard thing to come by in the lower rungs of society, and very precious). But there was that one.

  • Good news - you still can!

    Seriously, open a new tab on your browser NOW and jump on eBay or whatever and buy it. Even if you aren't surprised by how much fun it still is (which you probably will be), you'll be able to stop regretting NOT having it. No downside!