[-] [email protected] 2 points 1 hour ago

The alternative is safeStorage, which uses the operating system's credential management facility if available. On Mac OS and sometimes Linux, this means another process running in the user's account is prevented from accessing it. Windows doesn't have a protection against that, but all three systems do protect the credentials if someone copies data offline.

Signal should change this, but it isn't a major security flaw. If an attacker can copy your home directory or run arbitrary code on your device, you're already in big trouble.

[-] [email protected] 4 points 19 hours ago

You'd need write access to the user's home directory, but doing something with desktop notifications on modern Linux is as simple as

dbus-monitor "interface='org.freedesktop.Notifications'" | grep --line-buffered "member=Notify\|string" | [insert command here]

Replacing the Signal app for that user also doesn't require elevated privileges unless the home directory is mounted noexec.

[-] [email protected] 3 points 21 hours ago

I don’t recall Signal ever claiming their desktop app provided encryption at rest.

I'm not sure if they've claimed that, but it does that using SQLCipher.

[-] [email protected] 32 points 21 hours ago

If someone can read my Signal keys on my desktop, they can also:

  • Replace my Signal app with a maliciously modified version
  • Install a program that sends the contents of my desktop notifications (likely including Signal messages) somewhere
  • Install a keylogger
  • Run a program that captures screenshots when certain conditions are met
  • [a long list of other malware things]

Signal should change this because it would add a little friction to a certain type of attack, but a messaging app designed for ease of use and mainstream acceptance cannot provide a lot of protection against an attacker who has already gained the ability to run arbitrary code on your user account.

[-] [email protected] 3 points 22 hours ago

Kiwi Browser runs nearly every extension that runs on desktop Chromium, including uBlock Origin.

[-] [email protected] 145 points 1 day ago

Signal should change this, but it's typical of the traditional desktop OS security model in which applications running under the user's account are considered trustworthy. Security-oriented software like Signal should take a more hardened approach, but this is not some glaring security hole.

[-] [email protected] 6 points 1 day ago

Sure: don't use Mastodon to participate in Lemmy communities.

You can of course, which you clearly already know. Tagging a community in s top-level post even results in a good experience, but subscribing to communities does not, and you can't vote.

Maintaining accounts on both is a good idea.

[-] [email protected] 2 points 1 day ago

That's what I have on mine too.

[-] [email protected] 3 points 1 day ago

I reviewed it. It's my favorite small headlamp, and also pretty good as a handheld pocket light. The related handheld-only M150 is also nice.

[-] [email protected] 5 points 1 day ago

I reviewed it. It's one of the better options in its class.

[-] [email protected] 7 points 1 day ago

I find it important to have some tools with me. Even if I'm really unlikely to use them, being a useful person who can fix stuff and solve problems is a major component of my self concept.

I also find the tools interesting in their own right. Lots of people like trinkets and gadgets, and there may be no explaining it to someone who doesn't immediately find that sort of thing appealing.

81
submitted 1 day ago by [email protected] to c/[email protected]
  • Old leather wallet
  • Flashlight (Skilhunt H150)
  • Knife (Spyderco UKPK)
  • Pepper spray (Sabre Red, with a pocket clip from a random flashlight)
  • Phone (Pixel 4A)
  • Keys, and another flashlight (Skilhunt EK1)
  • Flash drive (Sandisk 128gb)
  • 1.38€
[-] [email protected] 15 points 1 day ago* (last edited 1 day ago)

  • Old leather wallet
  • Flashlight (Skilhunt H150)
  • Knife (Spyderco UKPK)
  • Pepper spray (Sabre Red, with a pocket clip from a random flashlight)
  • Phone (Pixel 4A)
  • Keys, and another flashlight (Skilhunt EK1)
  • Flash drive (Sandisk 128gb)
  • 1.38€

See also [email protected]

23
submitted 6 days ago by [email protected] to c/[email protected]
15
submitted 3 weeks ago* (last edited 3 weeks ago) by [email protected] to c/[email protected]

I've been self-hosting email with Maddy for a bit, but haven't shared any of the addresses widely yet in part because I haven't set up a spam filter. I'm pleased with Maddy; there's much less to learn to get a server up and running with sane default behavior than with the email software of old.

Ideally, I'd like to go beyond just spam filtering and have something with arbitrary categories like newsletters and password resets. I would prefer that it learn categories when I move messages to IMAP folders from a mail client. Maddy can feed messages into arbitrary programs and pick a destination folder based on their output.

Web searches turn up a ton of classification programs, most of which seem to be more interested in playing accuracy golf with well-known corpora than expanding functionality beyond simple spam filtering.

39
submitted 2 months ago by [email protected] to c/[email protected]

I often use a commercial VPN service, which I suspect is not rare among Lemmy users. Most of the time, I'm able to post to lemmy.world, but on occasion I am not. The default web UI provides zero feedback, just a spinning submit button forever, but if I look in the browser dev tools, I can see it's being blocked.

I understand that some limitations are necessary to prevent spam and other abuse, however this is a very blunt instrument. The fact that I have a 10 month old account with consistent activity should outweigh any IP address reputation issues.

Perhaps the VPN limitations could be narrowed in scope to cover only account creation and posts from young accounts.

20
submitted 3 months ago by [email protected] to c/[email protected]
19
submitted 6 months ago by [email protected] to c/[email protected]

If I want to quickly pitch "you should follow X, Y, and Z using RSS because [problems with social media]" to people who have never heard of RSS, what readers should I recommend?

I want at least web (not self-hosted), Android, and iOS options. Native apps for Mac and Windows would be nice as well. Linux users probably already know what RSS is.

There absolutely must be a free option good for at least 25 feeds because unfamiliar tech is a hard enough sell without having to pay. I'll grudgingly accept ads if that's the tradeoff for something beginner-friendly.

12
submitted 9 months ago by [email protected] to c/[email protected]

When I attempt to upload images to lemmy.world via the desktop web UI, I get the following error message:

SyntaxError: JSON.parse: unexpected character at line 1 column 1 of the JSON data

Looking at network traffic in dev tools, I see that I'm getting a 403 page from Cloudflare saying:

Sorry, you have been blocked You are unable to access lemmy.world Why have I been blocked? This website is using a security service to protect itself from online attacks....

I also get error messages when trying to upload images using Connect and Sync on an Android device. I successfully uploaded images in the past.

136
submitted 10 months ago by [email protected] to c/[email protected]

We just hit 2000 subscribers! I’d like to thank everyone for showing up here to create a new community, and what better way than giving stuff away?

I’m giving away the Nitecore MH10 v2 I reviewed. I can ship it anywhere in the USA or EU, but EU winners will have to wait until mid September. This is a basic, beginner-friendly flashlight that can accept almost all 18650 and 21700 batteries.

To enter, leave a top-level comment on this post before midnight UTC on Sunday, August 27, 2023. Only accounts that have posted or commented on /c/flashlight prior to this being posted are eligible to win.

14
submitted 11 months ago by [email protected] to c/[email protected]
1
submitted 11 months ago by [email protected] to c/[email protected]

cross-posted from: https://lemmy.world/post/1730120

Caught a cute moment on film. Look at that balance!

6
submitted 11 months ago by [email protected] to c/[email protected]
10
submitted 1 year ago by [email protected] to c/[email protected]
  • Skilhunt M150 v2 (519A swap)
  • Kershaw Launch 5
view more: next ›

Zak

joined 1 year ago
MODERATOR OF