CaptainSpaceman

@CaptainSpaceman@lemmy.world

This profile is from a federated server and may be incomplete. View on remote instance

CaptainSpaceman ,

Absolutely disgusting. Privacy is a right!

CaptainSpaceman ,

The 3rd emoji is just bs. Then again, most of his post is bs

SSH login without user name? ( docs.gitlab.com )

I was reading GitLab's documentation (see link) on how to write to a repository from within the CI pipeline and noticed something: The described Docker executor is able to authenticate e.g. against the Git repository with only a private SSH key, being told absolutely nothing about the user's name it is associated with....

CaptainSpaceman ,

When authenticating with git over SSH, the private key should be considered secret and well protected.

That means the corresponding public key that was uploaded to the git server is enough to authenticate and no username is required. However, a password protected privare key is possible and extra layers of security can be added to the authentication mechanism.

As far as resource based attacks based on public key searching, I doubt many servers have significant enough public keys on a single host to even notice. Most repos are siloed and have specific teams/individuals assigned to them, so only a small number of public keys even gets loaded.

I dont know enough about the server side mechanics to be sure, but imo the attack surface is pretty small.

CaptainSpaceman ,

While true, in most cases the username is simply "git" and not a specific username tied to the pub/priv keypair

CaptainSpaceman ,

I usually recommend FOSS keyboards, seems to be the safer bet

CaptainSpaceman ,

It may not be that simple though.

Chatgpt is licensing their product to lots of entities and then the licensees relabel the AI as their own with a line somewhere that says "powered by Chatgpt" or similar.

For example, Bing AI is just chatgpt-4.

So if DDG is simply licensing out chatgpt, id definitely have eprivacy concerns.

CaptainSpaceman ,

Gaming PC means video games, video games have historically been Windows or maybe Mac compatible. Only in the past couple years have game makers started making Linux compatibility a priority, and even then its a small percentage.

Until all systems align, Windows will continue to dominate. But things like HTML5 over Flash are helping those efforts!

CaptainSpaceman ,

Doesn't the VPN own your traffic though?

Private VPN seems the only real way

CaptainSpaceman ,

Best guess would be a privacy focused chat app like Signal or Matrix.

Otherwise you may want to look at crypto bases file storage ala Filecoin or potentially even Pixelfed

CaptainSpaceman ,

Absolutely. They are entrenched in their regulations so much that it takes forever to change things.

Years ago, I had an account at an american big4 bank with an 8 character password and was going through and making all my passwords unique. I was changing everything to random strings of 20-30 characters (this isnt the best practice, btw, but still better than 8chars), so when I get to this bank account it capped me at 15chars. I couldnt believe the forced low entropy they gave me for something as vital as a bank account.

I asked them why, and basically they said their system would break with anything over 15chars.

CaptainSpaceman ,

Back then? Who knows

CaptainSpaceman ,

Can you not just backup the instance on Mastodon?

CaptainSpaceman ,

Then users need to spin up their own instance, right? Then all their posts stay backed up if they choose?

Seems like a mediocre problem to get bent out of shape enough to move to a centralized platform.

CaptainSpaceman ,

I always disregarded it since it came as bloatware on my old samasung phones

CaptainSpaceman ,

The other 2 commenters are wrong. URLs as they appear in your web browser are NOT encrypted when sent over https protocols.

The only data that is encrypted is POST data, and ONLY if it is sent over HTTPS.

So for example, a website login page crafts a URL like https://some.example.com/login?sessionID=12345678 and when you log in to the site extra parameters like Username and Password are sent via POST data, then anyone listening to your web traffic (like the NSA or your neighbor with wireshark) will br able to see the website and the sessionID, but not the login details as they will only show up encrypted.

However, if the site is ran by idiots who pass the data in the URL like this https://some.example.com/login?sessionID=12345678&username=Homer&password=Simpson, then ANYONE listeneing would have your credentials.

CaptainSpaceman ,

Its fancy IRC with voice channel support, etc

CaptainSpaceman ,

Yea, ive gotten pretty wide adoption from friends and family on Signal, but id love to have a comparable product with even more features/security/privacy

Matrix may get there eventually, but for now its Signal.

CaptainSpaceman ,

Ever since uTorrent started mining on users computers, ive been on QBT

CaptainSpaceman ,

neither of you are looking at all the data harvesting that occurs on platforms like Meta and Reddit. Telemetry, keystrokes (not just submitted, but any key typed iincluding backspaced ones), and more, and NONE of that is harvested on this platform.

CaptainSpaceman ,

FOSS 4 Life, bb!

CaptainSpaceman ,

woohoo! we got moderated content!!! cant wait for all the “organic” ads that pop up in my feed from users spouting the benefits of Tide^TM brand soap!!!

[Discussion] How do you feel about age verification on Porn sites? ( lemmings.world )

Porn sites Pornhub, XVideos, and Stripchat face stricter requirements to verify the ages of their users after being officially designated as “Very Large Online Platforms” (VLOPs) under the European Union’s Digital Services Act (DSA)....

CaptainSpaceman ,

Probably not, its just religious pearl clutching for the most part that has been passed down unnecessarily

Free the bodies, let everyone be naked and we will all stop giving a shit

[Thread, post or comment was deleted by the author]

  • Loading...
  • CaptainSpaceman ,

    Seems unlikely, GPS data is far more accurate and lots of security minded m people turn off WiFi when away from home but still need gps when out and about

    [Thread, post or comment was deleted by the author]

  • Loading...
  • CaptainSpaceman ,

    Basically Android makes deals with big companies, Apple charges flat rate for everyone

    CaptainSpaceman ,

    i dont download porn (anymore) but if I did use a plex server for it I would absolutely partition it off from other users on my server

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • All magazines