waffle

joined 1 year ago
[–] waffle 2 points 3 hours ago

Damn already working on an app? That's so cool! Starting E2EE there is definitely a good idea then!

MeroChat is such a nice project, thank you for working on it <3

[–] waffle 2 points 11 hours ago (2 children)

The server might always send a modified script that just uploads the plaintext private key.

Yeah, you'd need a way to validate the client code before it's executed to solve that issue

Section "2. Client application security" of MEGA's Security Whitepaper discusses this exact problem. Their best solution to that issue is to just cram the whole frontend in a signed web extension and not serve any code to the user when the extension is active, which is not very user friendly but works for those who want an extra layer of protection

I just can't find a good user-friendly implementation, sorry for not being of more help. The web just isn't E2EE-friendly ig :/

[–] waffle 5 points 1 day ago* (last edited 12 hours ago) (4 children)

Yeah, I'm not used to E2EE in the browser either and StackExchange seems to agree that there's no nice solution :/

The sanest option in terms of user practicality to me appears to be storing the private key on the server, maybe encrypted with the user's password, and sending it to the user on successful login where it would be decrypted client side. It seems like it's more or less what MEGA is doing since they have a similar issue

If the server having temporary access to the user's password is an issue maybe the password could be partially pre-hashed before being sent?

It's be interesting to talk about it with someone with more experience, especially since implementing all of that will be a pain so it can't be redone every Thursday

[–] waffle 5 points 1 day ago (6 children)

I know Matrix has E2EE with some public documentation on its implementation. Maybe it could help you? Idk how familiar you're with E2EE or what kind of implementation you'd want, anything will have drawbacks :/

[–] waffle 23 points 3 days ago

Nothing forbids sharing US news in this community. Anything interesting on the globe goes afaik :)

Also while many countries don't have inequality issues in the "highly privatised health care" industry, I genuinely can't name a single country without inequality issues and Luigi's story may be inspirational to some of these ppl facing inequalities so imo it's good to see it shared here!

[–] waffle 2 points 6 days ago (1 children)

Damn, that's sad. Since I already have tons of games I want to play I'll probably never end up getting it then. Thanks for telling me :/

[–] waffle 3 points 1 week ago

No worries! I've just realized you were asking for games on sale (reading is hard ugh...) so hopefully the ones you want will be discounted mb ^^'

[–] waffle 28 points 1 week ago (6 children)

Great games that came out in 2024:

  • UFO 50
  • Peglin
  • ANIMAL WELL
  • Balatro

2024 games that I haven't tried yet but seem promising:

  • Pepper Grinder
  • Yellow Taxi Goes Vroom
  • Lorelei and the Laser Eyes
  • Rabbit and Steel
  • Another Crab's Treasure
  • Felvidek

All are in no particular order. Dunno if you'll like those but these ones come to mind :)

[–] waffle 4 points 3 weeks ago

I'm sorry what the hell did you call me??

[–] waffle 68 points 1 month ago (3 children)

The encrypted files are very suspicious and, in the new canary, they removed the part that stated they didn't receive a gag order: https://web.archive.org/web/20240405132835/https://cock.li/transparency/warrant-canary.txt

It's possible that it's Vincent's way of warning the users of a gag order. He may be an insufferable edgy little twat but he cares a lot about transparency and, had he received a gag order, he would definitely try to communicate it

Maybe I'm just being paranoid, you tell me

[–] waffle 7 points 2 months ago (1 children)

Yes! uYouPlus is amazing although it can be a pain to install because of Apple's shenanigans. It's a collection of patches over the official YouTube app

[–] waffle 5 points 10 months ago* (last edited 10 months ago)

It runs fine! :)

32-bit Windows programs can run on 64-bit Windows just fine thanks to WoW64 (with probably very few exceptions)

49
submitted 10 months ago by waffle to c/games
 

There's also a bunch of other discounts on RPG Maker engines & games available on this Steam page

19
anime_irl (sh.itjust.works)
 

The king of cave will live a paradise life (洞窟王からはじめる楽園ライフ ~万能の採掘スキルで最強に!?~)

69
anime_irl (sh.itjust.works)
 

The Witch’s Servant and the Demon Lord’s Horn

36
anime_irl (sh.itjust.works)
 

Love Me for Who I Am (不可解なぼくのすべてを, Fukakai na Boku no Subete o)

view more: next ›