irq0

joined 2 years ago
[–] [email protected] 20 points 3 weeks ago

You're saying that like it's a bad thing?

[–] [email protected] 3 points 3 weeks ago

The CAB Forum only govern public CAs and certificates and the use of certs on the public internet. Your private PKI will be unaffected by the new changes. On top of that the change will be introduced gradually, the first reduction is in March 2026 and will limit certs issued after March 2026 to 200 days so even if you saw some impact for some reason you'd still have a couple of months to put a fix in place

Freshman need to accept the cert once (hopefully after checking the fingerprint)

Nobody is checking the fingerprint, nobody

[–] [email protected] 57 points 1 month ago (1 children)

I hate it , thanks!

[–] [email protected] 137 points 1 month ago (4 children)

Mr President there's been a second signal chat

[–] [email protected] 1 points 6 months ago (3 children)

Take it as a ranty blog interspaced with some furry art.

You can just ignore the furry art if it's not your style because helpfully all of the important content is in the text.

Soatok links to the same Latacora blog on the first line and says that they're only really going to reword what's said there.

I’m not here to litigate the demerits of PGP. The Latacora article I linked above makes the same arguments I would make today, and is a more entertaining read.

PGP/GPG maintainers have had many years to fix the problems that have been identified but they haven't. Is it safe when used "properly"? Yes! It's absolutely safe when used properly but the problem is it's hard to use full stop.

I'm not saying modern solutions are perfect, because they're not but the alternates that Latacora ( and Soatok ) suggest are better. Do you want to encrypt a file? Use age. Use minisign/signify for signing. They do do one thing and do it well. Signal is easy to use and sorts all of the key management for you. Most people don't know what a private key is. They just know they want encrypted messaging because of the NSA or Snowden or whatever his name was on the news, they can't remember and they don't really care.

PGP has legitimate use cases but the vast majority of people don't have those cases and should just use Signal. Signal and the Signal protocol is the centralised tool you're looking for.

[–] [email protected] 6 points 9 months ago

running an LLM chat bot to deceive the enemy in their own language and ray tracing graphics on the helmet HUD

Exactly this, yes

[–] [email protected] 41 points 10 months ago (2 children)

The condom seems a bit ambitious for your average Gamescon attendee

[–] [email protected] 12 points 11 months ago (18 children)

I feel like I'm missing something here...

Who's going to be fingerprinting DHCP messages on your home network?

Outside of that, fingerprinting or tracking any DHCP info would be the least of my concerns. You have 0 control over any data the moment your devices connect to a public network. What use is DHCP info when you can person-in-the middle all the traffic anyway?

And anyway, what info are you concerned about? Having had a VERY quick browse of RFC2131 the worst thing would be "leaking" the device MAC address which can be discovered via several other means anyway

[–] [email protected] 57 points 1 year ago (1 children)

I didn't wake up planning to watch a 4hr video in the failure of the Star Wars hotel but I'm weirdly glad I did

[–] [email protected] 9 points 1 year ago

Well no cardboard that's for sure

[–] [email protected] 30 points 1 year ago (1 children)

They're not trying to hide anything. They have a Hitler character too

144
Fr(ule)ed (infosec.pub)
 
186
Hmm (i.imgur.com)
 
117
Bob rule (i.imgur.com)
 
 

I'm not sure I "get" the high-end torches at all... that said I have a dragon soul coming on Wednesday

 
 
 
view more: next ›