8
102
unskilled5117

@feddit.org

unskilled5117 3 points a day ago path: 0 24375579, hotness: undefined, score: 3, children: 3
unskilled5117 3 points 5 days ago

This is the most uptodate option i know of, using DeDrm/noDrm and Calibre, havent tested it myself though.

path: 0 24312571, hotness: undefined, score: 3, children: 0
unskilled5117 213 points 2 years ago

This is an important issue IMO that needs to be addressed and the official response by Bitwardens CTO fails to do so.

There is not even a reason provided why such a proprietary license is deemed necessary for the SDK. Furthermore this wasn’t proactively communicated but noticed by users. The locking of the Github Issue indicates that discussion isn’t desired and further communication is not to be expected.

It is a step in the wrong direction after having accepted Venture Capital funding, which already put Bitwardens opensource future in doubt for many users.

This is another step in the wrong direction for a company that proudly uses the opensource slogan.

path: 0 12990720, hotness: undefined, score: 213, children: 10
unskilled5117 132 points 2 years ago

I haven’t looked into the technicals much further than the support page.

The way i read it, it sounds like the companies will get some general data if their ads work without a profile about you being created. I would be fine with that. What I don’t like is the lack of communication to users about it being enabled.

PPA does not involve websites tracking you. Instead, your browser is in control. This means strong privacy safeguards, including the option to not participate.

Privacy-preserving attribution works as follows:

  1. Websites that show you ads can ask Firefox to remember these ads. When this happens, Firefox stores an “impression” which contains a little bit of information about the ad, including a destination website.
  2. If you visit the destination website and do something that the website considers to be important enough to count (a “conversion”), that website can ask Firefox to generate a report. The destination website specifies what ads it is interested in.
  3. Firefox creates a report based on what the website asks, but does not give the result to the website. Instead, Firefox encrypts the report and anonymously submits it using the Distributed Aggregation Protocol (DAP) to an “aggregation service”.
  4. Your results are combined with many similar reports by the aggregation service. The destination website periodically receives a summary of the reports. The summary includes noise that provides differential privacy.

This approach has a lot of advantages over legacy attribution methods, which involve many companies learning a lot about what you do online.

PPA does not involve sending information about your browsing activities to anyone. This includes Mozilla and our DAP partner (ISRG). Advertisers only receive aggregate information that answers basic questions about the effectiveness of their advertising.

This all gets very technical, but we have additional reading for anyone interested in the details about how this works, like our announcement from February 2022 and this technical explainer.

path: 0 11154408, hotness: undefined, score: 132, children: 36
unskilled5117 93 points 2 years ago

The problem with passkeys is that they're essentially a halfway house to a password manager, but tied to a specific platform in ways that aren't obvious to a user at all, and liable to easily leave them unable to access of their accounts.

Agreed, in its current state I wouldn‘t teach someone less technically inclined to solely rely on passkeys saved by the default platform if you plan on using different devices, it just leads to trouble.

If you're going to teach someone how to deal with all of this, and all the potential pitfalls that might lock them out of your service, you almost might as well teach them how to use a cross-platform password manager

Using a password manager is still the solution. Pick one where your passkeys can be safed and most of the authors problems are solved.

The only thing that remains is how to log in if you are not on a device you own (and don’t have the password manager). The author mentions it: the QR code approach for cross device sign in. I don’t think it’s cumbersome, i think it’s actually a great and foolproof way to sign in. I have yet to find a website which implements it though (Edit: Might be my specific setup‘s fault).

path: 0 12914523, hotness: undefined, score: 93, children: 14
unskilled5117 89 points 2 years ago

Seems like people in the comments are misunderstaning the point entirely. This protocol is about import and export from password managers and not about having them synced between devices. It would prevent a lock in effect. This is a great development!

FIDO Alliance’s draft specifications – Credential Exchange Protocol (CXP) and Credential Exchange Format (CXF) – define a standard format for transferring credentials in a credential manager including passwords, passkeys and more to another provider in a manner that ensures transfer are not made in the clear and are secure by default.

path: 0 12896131, hotness: undefined, score: 89, children: 8
unskilled5117 79 points a year ago

This is a clickbait headline. The headline implies that the German State is using AI to censor. It is not! While there might be a lot to criticize the German State/Goverment for, this is not it.

It is a different actor developing a model, not the state. One can rightly criticize that, but that is definitely protected under scientific freedom.

[…] the Decoding Antisemitism project at the Center for Research on Antisemitism at the Technical University Berlin […]. With the help of a large language computing model, the project aims to create “an [AI] algorithm that will automatically recognize antisemitic statements in web comments . . . so that antisemitic posts can be removed more efficiently and accurately” by online platforms.

path: 0 17393311, hotness: undefined, score: 79, children: 26
unskilled5117 51 points 2 years ago

The Republican vice presidential nominee and Ohio senator claimed in an interview with YouTuber Shawn Ryan that a top EU official had threatened to arrest the billionaire [Musk] if he allowed former President Trump back on X.

“So what America should be saying is, if NATO wants us to continue supporting them and NATO wants us to continue to be a good participant in this military alliance, why don’t you respect American values and respect free speech?” Vance asked. “It’s insane that we would support a military alliance if that military alliance isn’t going to be pro-free speech. […]

“I’m not going to go to some backwoods country and tell them how to live their lives,” Vance added. “But European countries should theoretically share American values, especially about some very basic things like free speech.”

The US ranked 26th in the world when it comes to free speech, with several members of the European Union higher up the list, according to the 2024 Global Expression Report.

If anyone is interested these countries are ahead of the USA from 1-25: Denmark Switzerland Sweden Belgium Estonia Norway Finland Ireland Germany Iceland Portugal Austria New Zealand Canada Argentina Spain Czech Republic Italy Latvia Costa Rica Uruguay France Dominican Republic Netherlands Vanuatu

path: 0 13376831, hotness: undefined, score: 51, children: 5
unskilled5117 45 points 2 years ago

Great to see progress! Why is it behind their official github releases though? Latest version is 2024.10.2 and not 2024.09.0. It is four releases, meaning more than a month, behind.

path: 0 13245366, hotness: undefined, score: 45, children: 6
unskilled5117 41 points 2 years ago

You are just spreading misinformation! Cite your sources!

There is a strategy used, which allows the government to find out who an account belongs to. They ask the push providers (Apple/Google) for data on the push token from e.g. a messaging app. This way they associate the account from an app with an identity.

Nothing there about message content. It is still safely E2EE.

I don’t know how it works in your country, but in mine, phone numbers are already associated with identities, so nothing gained as the gov can just ask signal for the phone number of an account, instead of having to ask signal and the push provider to get the identity. (Edit: apparently it’s hashed, so there seems to be a use for this.) Signal isn’t about Anonymity but Privacy. There is a difference.

If you have another vulnerability cite it!

path: 0 12474702, hotness: undefined, score: 41, children: 11
unskilled5117 36 points 2 years ago

What does Ente mean? 

In Malayalam, Vishnu's native language, "ente" means "mine". Thus "Ente Photos" has the literal meaning "my photos".

This was a good name, but still Vishnu looked around for better ones. But one day, he discovered that "ente" means "duck" in German. This unexpected connection sealed the deal. We should ask him why he likes ducks so much, but apparently he does, so this dual meaning ("mine" / "duck") led him to finalize the name, and also led to the adoption of "Ducky", Ente's mascot Source

path: 0 12594124 12594398 12594520 12594806, hotness: undefined, score: 36, children: 1
unskilled5117 36 points 2 years ago

The lock-in effect of passkeys is something that this protocol aims to solve though. The “only managed by your device” is what keeps us locked in, if there is no solution to export and import it on another device.

The protocol aims to make it easy to import and export passkeys so you can switch to a different provider. This way you won’t be stuck if you create passkeys e.g. on an Apple device and want to switch to e.g. Bitwarden or an offline password manager like KeyPassXC

The specifications are significant for a few reasons. CXP was created for passkeys and is meant to address a longstanding criticism that passkeys could contribute to user lock-in by making it prohibitively difficult for people to move between operating system vendors and types of devices. […] CXP aims to standardize the technical process for securely transferring them between platforms so users are free […].

path: 0 12896694 12899030, hotness: undefined, score: 36, children: 8
unskilled5117 34 points a year ago

Most people don’t know that it wasn’t just VW. Sadly I don‘t think you will find any moral acting car manufacturer out there.

Automakers who have been caught using a defeat device within a diesel vehicle, in a similar manner to Volkswagen include: Jeep and Ram under FCA[391] (now a part of Stellantis), Opel[392] (when under GM), and Mercedes-Benz.[393]

While not all using defeat devices, diesel vehicles built by a wide range of carmakers, including Volvo, Renault, Mercedes, Jeep, Hyundai, Citroen, BMW, Mazda, Fiat, Ford and Peugeot[48][49] had independent tests carried out by ADAC that proved that, under normal driving conditions, many diesel vehicles exceeded legal European emission limits for nitrogen oxide (NOx), some by more than 10 times, and one by 14 times.[49]

Beyond exclusively diesel or passenger vehicles, automakers such as: Hino[414] (subsidiary of Toyota), Hyundai and Kia,[415] Nissan,[416] Mazda, Yamaha Motors, Suzuki,[417] Subaru,[418] and others have been proven to be falsifying fuel economy or emissions on non-diesel powered and/or commercial vehicles.

Soure (Wikipedia)

path: 0 17291627 17292596, hotness: undefined, score: 34, children: 1
unskilled5117 31 points 2 years ago

On iOS you can enable Guided Access and restrict what one can do, for example disable touch and lock it to an app, until you enter a Code. I imagine Android will have something similar.

This obviously doesn’t protect against electronic forensics, but it does protect against just opening different apps and searching through the phone manually.

path: 0 13857130, hotness: undefined, score: 31, children: 3
unskilled5117 31 points 2 years ago

The dual root partitions we described in Deepin 20.5 are gone, but version 23 still sets up a moderately complex partitioning scheme, including an EFI system partition, a 1.5 GB /boot partition, a swap partition, and a 15 GB root partition, and the rest of the disk given to a partition labeled _dde_data. All are in plain old ext4 format, but there's some magic being done with the data partition that we didn't have time to trace. It appears to be mounted at multiple places, including /home/var/opt, and a mount point called /persistent beneath them all. We're not sure exactly how it's been done, but the distro has some kind of atomic installation facility with rollback.

Lack of proper documentation by Deepins Devs is enough of a red flag for me to never consider trying it.

path: 0 11973481, hotness: undefined, score: 31, children: 1
unskilled5117 29 points a year ago

The preceding open letter to Organic Maps shareholders gives some context for the decision to fork.

The Organic Maps project has been built and promoted under the premise of being an open community project, so it's troubling to discover that the majority of shareholders consider it to be their sole property. More concerns include lack of transparency and accountability in project governance and violation of stated Free and Open Source Software values. (see Addendum for the details)[…]

Interesting and troubling read, didn’t know that about Organic Maps.

path: 0 17005666, hotness: undefined, score: 29, children: 0
unskilled5117 23 points a year ago

Why would that need listening? I imagine if one is pregnant you are searching for lots of information online: symptoms, physicians, due date etc.

path: 0 16683055 16685685, hotness: undefined, score: 23, children: 0
unskilled5117 23 points 10 months ago

Do the references work for anyone? For me they lead to completely unrelated studies with no connection to caffeine.

path: 0 19180720, hotness: undefined, score: 23, children: 1
unskilled5117 23 points 6 months ago

Just so you know, the extend of the symptoms you are describing is not what you would expect from slightly elevated BP (definitions differ e.g. ESC)

path: 0 20911952, hotness: undefined, score: 23, children: 2
unskilled5117 22 points a year ago

That seems highly unlikely to me. Could a reason be website scrapers for AI using different user agents to prevent being blocked? The recent reports of different projects plagued by scrapers fit the timeline

path: 0 18265901 18266193, hotness: undefined, score: 22, children: 3

thanks for using Leebra!

go to feed...