[-] unskilled5117@feddit.org 1 points 6 days ago

Yep, the problems that require more than the steam flatpak can deliver would of course still be there. But you wouldn’t suddenly be on a depreciated distro without a path forward. Thats what I meant by not totally screwed.

[-] unskilled5117@feddit.org 4 points 6 days ago* (last edited 6 days ago)

Even if this were to happen, you could easily rebase to Aurora (KDE version of Bluefin) or Fedora Kinoite. You wouldn’t be totally screwed.

[-] unskilled5117@feddit.org 80 points 1 month ago* (last edited 1 month ago)

This is a clickbait headline. The headline implies that the German State is using AI to censor. It is not! While there might be a lot to criticize the German State/Goverment for, this is not it.

It is a different actor developing a model, not the state. One can rightly criticize that, but that is definitely protected under scientific freedom.

[…] the Decoding Antisemitism project at the Center for Research on Antisemitism at the Technical University Berlin […]. With the help of a large language computing model, the project aims to create “an [AI] algorithm that will automatically recognize antisemitic statements in web comments . . . so that antisemitic posts can be removed more efficiently and accurately” by online platforms.

[-] unskilled5117@feddit.org 34 points 1 month ago* (last edited 1 month ago)

Most people don’t know that it wasn’t just VW. Sadly I don‘t think you will find any moral acting car manufacturer out there.

Automakers who have been caught using a defeat device within a diesel vehicle, in a similar manner to Volkswagen include: Jeep and Ram under FCA[391] (now a part of Stellantis), Opel[392] (when under GM), and Mercedes-Benz.[393]

While not all using defeat devices, diesel vehicles built by a wide range of carmakers, including Volvo, Renault, Mercedes, Jeep, Hyundai, Citroen, BMW, Mazda, Fiat, Ford and Peugeot[48][49] had independent tests carried out by ADAC that proved that, under normal driving conditions, many diesel vehicles exceeded legal European emission limits for nitrogen oxide (NOx), some by more than 10 times, and one by 14 times.[49]

Beyond exclusively diesel or passenger vehicles, automakers such as: Hino[414] (subsidiary of Toyota), Hyundai and Kia,[415] Nissan,[416] Mazda, Yamaha Motors, Suzuki,[417] Subaru,[418] and others have been proven to be falsifying fuel economy or emissions on non-diesel powered and/or commercial vehicles.

Soure (Wikipedia)

85

I am looking for some recommendations on how to secure the data of my physical servers (against physical theft), that I am about to set up. I am new to selfhosting but have a few years of experience running Linux on a desktop.

My usecase is a simple debian(?) server at home with Paperless ngx and Tailscale for when I am away from home. 

The question is how to encrypt the data while still being able to keep the server updated.

Coming from Desktop my first thought was to simply enable FDE on install. But that would mean supplying the password everytime the server needs to reboot for an update. Could someone provide some insights on how often updates to debian require a reboot? 

My second thought was to use an encrypted data partition. That way the server could reboot and I could use wireguard to ssh in and open the partition even when I am away from home for a longer time.

I am open to other ideas!

92

It is our goal to eventually have a similar offering so that a 100% open source, freedom-respecting alternative ecosystem is available for those who want it.

Thunderbird Appointment

Appointment is a scheduling tool that allows you to send a link to someone, allowing them to pick a time on your calendar to meet

Thunderbird Send

Send is the rebirth of Firefox Send

Thunderbird Assist

Assist is an experiment that, through a partnership with Flower AI will allow users to take advantage of AI features. The hope is that processing can be done on devices that can support the models

Thundermail

Thundermail is an email service. We want to provide email accounts to those that love Thunderbird, and we believe that we are capable of providing a better service than the other providers out there, that aligns with our values

33

cross-posted from: https://feddit.org/post/8827678

Support for FIDO2 (WebAuthn) two-step login on macOS is added with release v2025.2.1. This means you will be able to use a security key (e.g. Yubikey) as a second factor to protect your login.

It is now supported on:

  • Desktop: Windows, MacOs
  • Browser extensions: all FIDO2 supported Browsers
  • Mobile apps: Android and iOS 13.3+
9
submitted 3 months ago* (last edited 3 months ago) by unskilled5117@feddit.org to c/bitwarden@discuss.tchncs.de

Support for FIDO2 (WebAuthn) two-step login on macOS is added with release v2025.2.1. This means you will be able to use a security key (e.g. Yubikey) as a second factor to protect your login.

It is now supported on:

  • Desktop: Windows, MacOs
  • Browser extensions: all FIDO2 supported Browsers
  • Mobile apps: Android and iOS 13.3+
[-] unskilled5117@feddit.org 48 points 7 months ago

The Republican vice presidential nominee and Ohio senator claimed in an interview with YouTuber Shawn Ryan that a top EU official had threatened to arrest the billionaire [Musk] if he allowed former President Trump back on X.

“So what America should be saying is, if NATO wants us to continue supporting them and NATO wants us to continue to be a good participant in this military alliance, why don’t you respect American values and respect free speech?” Vance asked. “It’s insane that we would support a military alliance if that military alliance isn’t going to be pro-free speech. […]

“I’m not going to go to some backwoods country and tell them how to live their lives,” Vance added. “But European countries should theoretically share American values, especially about some very basic things like free speech.”

The US ranked 26th in the world when it comes to free speech, with several members of the European Union higher up the list, according to the 2024 Global Expression Report.

If anyone is interested these countries are ahead of the USA from 1-25: Denmark Switzerland Sweden Belgium Estonia Norway Finland Ireland Germany Iceland Portugal Austria New Zealand Canada Argentina Spain Czech Republic Italy Latvia Costa Rica Uruguay France Dominican Republic Netherlands Vanuatu

[-] unskilled5117@feddit.org 45 points 8 months ago* (last edited 8 months ago)

Great to see progress! Why is it behind their official github releases though? Latest version is 2024.10.2 and not 2024.09.0. It is four releases meaning more than a month behind.

[-] unskilled5117@feddit.org 207 points 8 months ago* (last edited 8 months ago)

This is an important issue IMO that needs to be addressed and the official response by Bitwardens CTO fails to do so.

There is not even a reason provided why such a proprietary license is deemed necessary for the SDK. Furthermore this wasn’t proactively communicated but noticed by users. The locking of the Github Issue indicates that discussion isn’t desired and further communication is not to be expected.

It is a step in the wrong direction after having accepted Venture Capital funding, which already put Bitwardens opensource future in doubt for many users.

This is another step in the wrong direction for a company that proudly uses the opensource slogan.

[-] unskilled5117@feddit.org 93 points 8 months ago* (last edited 8 months ago)

The problem with passkeys is that they're essentially a halfway house to a password manager, but tied to a specific platform in ways that aren't obvious to a user at all, and liable to easily leave them unable to access of their accounts.

Agreed, in its current state I wouldn‘t teach someone less technically inclined to solely rely on passkeys saved by the default platform if you plan on using different devices, it just leads to trouble.

If you're going to teach someone how to deal with all of this, and all the potential pitfalls that might lock them out of your service, you almost might as well teach them how to use a cross-platform password manager

Using a password manager is still the solution. Pick one where your passkeys can be safed and most of the authors problems are solved.

The only thing that remains is how to log in if you are not on a device you own (and don’t have the password manager). The author mentions it: the QR code approach for cross device sign in. I don’t think it’s cumbersome, i think it’s actually a great and foolproof way to sign in. I have yet to find a website which implements it though (Edit: Might be my specific setup‘s fault).

[-] unskilled5117@feddit.org 37 points 8 months ago* (last edited 8 months ago)

The lock-in effect of passkeys is something that this protocol aims to solve though. The “only managed by your device” is what keeps us locked in, if there is no solution to export and import it on another device.

The protocol aims to make it easy to import and export passkeys so you can switch to a different provider. This way you won’t be stuck if you create passkeys e.g. on an Apple device and want to switch to e.g. Bitwarden or an offline password manager like KeyPassXC

The specifications are significant for a few reasons. CXP was created for passkeys and is meant to address a longstanding criticism that passkeys could contribute to user lock-in by making it prohibitively difficult for people to move between operating system vendors and types of devices. […] CXP aims to standardize the technical process for securely transferring them between platforms so users are free […].

[-] unskilled5117@feddit.org 87 points 8 months ago* (last edited 8 months ago)

Seems like people in the comments are misunderstaning the announcement entirely. This protocol is about import and export from password managers and not about having them synced between devices. It would prevent a lock in effect. This is a great development!

FIDO Alliance’s draft specifications – Credential Exchange Protocol (CXP) and Credential Exchange Format (CXF) – define a standard format for transferring credentials in a credential manager including passwords, passkeys and more to another provider in a manner that ensures transfer are not made in the clear and are secure by default.

17
submitted 9 months ago by unskilled5117@feddit.org to c/linux@lemmy.world

cross-posted from: https://feddit.org/post/3179293

Install instructions for OpenSuse Tumbleweed/ MicroOs using Full Disk Encryption secured by a TPM2 chip and measured boot or a FIDO2 key.

Nice to see OpenSuse pushing forward on securing the Linux Desktop with FDE and measured boot. Hope to see other distros following.

16

Install instructions for OpenSuse Tumbleweed/ MicroOs using Full Disk Encryption secured by a TPM2 chip and measured boot or a FIDO2 key.

Nice to see OpenSuse pushing forward on securing the Linux Desktop with FDE and measured boot. Hope to see other distros following.

[-] unskilled5117@feddit.org 42 points 9 months ago* (last edited 9 months ago)

You are just spreading misinformation! Cite your sources!

There is a strategy used, which allows the government to find out who an account belongs to. They ask the push providers (Apple/Google) for data on the push token from e.g. a messaging app. This way they associate the account from an app with an identity.

Nothing there about message content. It is still safely E2EE.

~~I don’t know how it works in your country, but in mine, phone numbers are already associated with identities, so nothing gained as the gov can just ask signal for the phone number of an account, instead of having to ask signal and the push provider to get the identity.~~ (Edit: apparently it’s hashed, so there seems to be a use for this.) Signal isn’t about Anonymity but Privacy. There is a difference.

If you have another vulnerability cite it!

29
submitted 10 months ago by unskilled5117@feddit.org to c/linux@lemmy.ml

I use 2 different computers in 2 different locations both running Universal Blue.

I was wondering if there is any way to create a backup system where i could backup Computer1 over the internet to Computer2 and continue work like nothing happened with all the user data and installed applications being there. The goal is to only need to transfer the user data/applications and no system data (that should be the same for both because of Ublue, right?), to keep the backup size small.

To be clear, i need help figuring out the backup part, not the transfering over the internet part.

If I were to backup the directories on Computer1, which store user data, with for example borgbackup, could I restore them on Computer2 and have a working system? Or would there be conflicts because of more low level stuff missing like applications and configs? Which directories would I need and which could be excluded?

Is there a better option? Any advice is appreciated!

I also came across btrfs snapshot capabilities and thought they could possibly used for this. But as far as I understand it, that would mean transferring the whole system and not only the data and applications. Am i missing something?

[-] unskilled5117@feddit.org 139 points 11 months ago* (last edited 11 months ago)

I haven’t looked into the technicals much further than the support page.

The way i read it, it sounds like the companies will get some general data if their ads work without a profile about you being created. I would be fine with that. What I don’t like is the lack of communication to users about it being enabled.

PPA does not involve websites tracking you. Instead, your browser is in control. This means strong privacy safeguards, including the option to not participate.

Privacy-preserving attribution works as follows:

  1. Websites that show you ads can ask Firefox to remember these ads. When this happens, Firefox stores an “impression” which contains a little bit of information about the ad, including a destination website.
  2. If you visit the destination website and do something that the website considers to be important enough to count (a “conversion”), that website can ask Firefox to generate a report. The destination website specifies what ads it is interested in.
  3. Firefox creates a report based on what the website asks, but does not give the result to the website. Instead, Firefox encrypts the report and anonymously submits it using the Distributed Aggregation Protocol (DAP) to an “aggregation service”.
  4. Your results are combined with many similar reports by the aggregation service. The destination website periodically receives a summary of the reports. The summary includes noise that provides differential privacy.

This approach has a lot of advantages over legacy attribution methods, which involve many companies learning a lot about what you do online.

PPA does not involve sending information about your browsing activities to anyone. This includes Mozilla and our DAP partner (ISRG). Advertisers only receive aggregate information that answers basic questions about the effectiveness of their advertising.

This all gets very technical, but we have additional reading for anyone interested in the details about how this works, like our announcement from February 2022 and this technical explainer.

30
submitted 11 months ago by unskilled5117@feddit.org to c/linux@lemmy.world

OpenSuse leading the development in regards to boot security, an area in which Linux Distros are lagging behind other operating systems.

Full Disk Encryption is designed to protect data in cases of device loss, theft or unauthorized booting into an alternative operating system. Depending on the hardware configuration of a system, Aeon’s encryption will be set up in one of two modes: Default or Fallback.

Default Mode:

This mode utilizes the Trusted Platform Module(TPM) 2.0 chipset […], Aeon Desktop measures several aspects of the system’s integrity. These including:

  • UEFI Firmware
  • Secure Boot state (enabled or disabled)
  • Partition Table
  • Boot loader and drivers
  • Kernel and initrd (including kernel command line parameters)

These measurements are stored in the system’s TPM. During startup, the current state is compared with the stored measurements. If these match, the system boots normally.

view more: next ›

unskilled5117

joined 1 year ago