Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)𝒍
𝒍𝒆𝒎𝒂𝒏𝒏 @ lemann @lemmy.dbzer0.com
Posts
6
Comments
486
Joined
2 yr. ago

MFA

Jump
  • Unironically this...

    Passkeys don't work on my rooted device - they seemingly set up correctly, but sites like GH claim your device passkey doesn't exist when you try to actually login. When you go to the affected site's account settings to add the device as a passkey again, an error of some kind claims the passkey already exists 🤷‍♂️

    Deleting/re-adding has no effect. Using FF with device biometric passkey auth

  • MFA

    Jump
  • Some third party apps allow you to import your Steam OTP, such as Gnome Authenticator

    However to obtain it in the first place you need to either use SteamDesktopAuthenticator (GitHub), an android emulator on your PC, or a rooted device to export your key...

  • I was curious about this too and had a little look myself, all I can find is that other companies interested in interopability are implementing MLS encryption instead of implementing the Signal protocol in their apps.

    Can't find any info on Signal's blog about interest in adopting MLS encryption, or considering interopability with Meta apps that already use (or may use) the Signal protocol... unless I've missed something or been looking in the wrong place

  • I would suggest using any cloud storage provider with a third party client, that automatically encrypts your files before uploading them, ensuring the cloud provider does not have any kind of access to your keys.

    I personally use gocryptfs then mirror that to B2, but IIRC rclone and some other third party alternatives have built-in pre-upload encryption options that are easier to setup and use

  • A per-user rate limit of some sort could have reduced the attack surface I think? Something like that would be quite a bit of dev work to implement though...

    At least the situation was promptly resolved and users nuked, although R.I.P. to any smaller Lemmy servers that went down due to the massive spam wave

  • Do any gifs work for you?

    My assumption would be that the content scanner developed by our instance admin doesn't support gifs (or media with multiple frames). Uploading them to another image host would probably be the solution here IMO

    https://github.com/db0/fedi-safety/issues/12

  • Oh sorry my bad!

    In that case, I think it's pretty poor that Apple hasn't made any progress on this after having the specs available for so long, also considering you can already get your hands on third party Android apps that can arbitrarily use BLE to detect all kinds of nearby devices.

    To me it feels like Apple is trying to saturate as much of the market as they can before they bake in support for third party tracker detection