Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)TH
Posts
17
Comments
765
Joined
2 yr. ago

  • Okay, so it's just like Yubikey-type stuff? I've thought about that before but it seems very risky - they recommend you get two and set both of them up so you have a backup, but that would require all websites to support that, right?

    I'm down for using BitWarden, though, if I can substitute it for physical keys.

  • Recurring incidents like these raise the question, how does one strike a balance?

    Relentlessly reporting theoretical vulnerabilities can leave open-source developers, many of who are volunteers, exhausted from triaging noise.

    On the flip side, would it be ethical if security practitioners, including novices, sat on what they thought was a security flaw—so as not to inconvenience the project maintainers?

    This was already answered in the article: verify your security findings. Make a POC that actually exploits the vulnerability, then submit it with your report.

  • I like getting Bee-link boxes - they can be upgraded to 64gb RAM, have plenty of CPU, and can have two drives. I run Proxmox on them and make VMs that then run my services in docker.

    There's been a lot of talk about N100s as well. I haven't looked into them much, but I assume they should be similar. Looks like their max memory is 16gb. I'd stick with Bee-link.

  • In addition to what everyone else in this thread has already covered, the credit card issuers benefit from you having that card in your wallet because they charge the merchant for every transaction. So you're having the merchant pay the credit card company with every swipe, in exchange for whatever benefits the card provides to you.

  • Also as a side note I hate how lots of places just assume you want to download their shitty spyware ridden apps or hand over your phone number or an email.

    Or want notifications. No, recipe site, I don't want desktop notifications from you.