lemmy.one

tekeous, to memes in Firefox reader view 🔛🔝

Reader mode is just regular Chad, me with my RSS reader with built in reader mode is the real Giga Chad

Churbleyimyam,

I hope you are using newsboat and opening web pages in w3m

GBU_28, (edited ) to lemmyshitpost in it's a puzzling one i'll tell you hwat

The fastest way to handle lemmygrad or hexbear is to just rile them up real good in their communities.

Rather than me banning them, they all ban or block me. Ezpz.

cupcakezealot, to programmer_humor in every damn time ...
@cupcakezealot@lemmy.blahaj.zone avatar

that’s specifically why i don’t trust them

nutbutter, to privacyguides in BVG out here recommending the best 2FA Apps!

In India, they force us to install proprietary apps, which are probably spying on us.

Star,

They don’t, though? Who’s forcing you to install a proprietary 2FA app in India. Unless you’re saying in general.

nutbutter,

My bank, for example, does not let us use any 2FA app we want. They have their own separate app, made for handling 2FA for that specific bank only.

And in general too, yes. Like Arogya Setu. The app we had to install to prove our vaccination status.

giggling_engine, to linuxmemes in Linus does not fuck around
@giggling_engine@lemmy.world avatar

I wish I could talk to my engineers like that, maybe they’d stop fucking everything up.

BirdyBoogleBop,

Oh they would stop. Working there.

squaresinger,

If all your engineers fuck everything up, maybe the problem is with their leadership who never learned to communicate clearly and professionally.

saltesc, to lemmyshitpost in it's a puzzling one i'll tell you hwat

Honestly, why even give a shit?

Of all the things to spend time and energy considering about, comment activity and lemmy.ml is an interestingly niche investment choice.

If you consider anything, it should be retrospectively a positive. You’re cut from that pointless niche now. Go prosper.

empireOfLove, (edited )

I really don’t care, I actually thought it was kind of hilarious i was just yelling into a federated void for two weeks before my slow ass finally realized something was off lmfao hence the meme about the really bad moderation system

LemmyIsFantastic, to lemmyshitpost in it's a puzzling one i'll tell you hwat

100% mods just toss them around to ban opinions they don’t like. I even got one for genocide that I’m not even able to see what I said. Good Lord I wish I could see what pissed them off so much.

1024_Kibibytes, to linux in Request for help, I broke some graphics

Reboot and see if it still happens. If it does, is it always the same characters that are missing?

A quick search for “Linux missing characters” says it could be the font that you’re using.

TheFriendlyDickhead, (edited ) to memes in Firefox reader view 🔛🔝

The sad thing is that well made websites can be a beautiful thing. But with the amount of ads they ruin that experience. And by enabling read mode all that website design that came up in the last year’s is gone again

peopleproblems,

It is possible to have a well designed website with ads. Unfortunately, once you start using analytics, you can figure out how to “tweak” your design to increase engagement with ads, thereby increasing revenue.

Before long, your well designed website is a crappy website because that brings in the bacon.

Etienne_Dahu, to memes in Firefox reader view 🔛🔝

You forgot the key weakness of read mode: its dark mode is not real black (), but dark grey. The difference is staggering with OLED screens.

jol,

I hate dark backgrounds though. Too much contrast.

bob_lemon,

There’s a reason most dark programming color schemes don’t have true black as their background, and it’s precisely this.

cmgvd3lw,

But if done right (with grey text or something), it could be phenomenal.

mexicancartel,

Darker text is the solution

Aria, (edited )

@-moz-document url-prefix(“about:reader”) {background-color: ;} in your usercontent.css

Etienne_Dahu,

Thanks, I only had to add !important and it changed the background.

Laticauda, (edited )

Dark grey makes for a better dark mode than black anyway.

hswolf, to privacyguides in BVG out here recommending the best 2FA Apps!
@hswolf@lemmy.world avatar

If you get Bitwarden pro (really cheap), you can save an OTP link together with the site credentials, it’s really good for keeping everything in one place

SaltyIceteaMaker,
@SaltyIceteaMaker@iusearchlinux.fyi avatar

Proton pass can also do this

PracticalParrot,

I do this. I want to point out it is absolutely TERRIBLE for security. It’s turning 2 factor back into 1 factor authentication.

goodhunter,

Consider your threat model. You could use a yubikey for Bitwarden log in.

kniescherz,

I would argue its more like a 1.5 factor. Not secure when your bitwarden gets compromised. But more security for stolen, leaked, phised passwords.

I currently have 60 OTPs in Bitwarden, I probably would not have activated 2FA on so many sites without BW.

IdleSheep, (edited )
@IdleSheep@lemmy.blahaj.zone avatar

This isn’t really a good idea because then you’re putting all your eggs in one basket. The whole point of 2FA is that the second factor is in a separate location so if your first factor (password) gets compromised the second one (OTP code) still protects your account. If both factors are in one place you’re back to a single point of failure instead of 2, losing a key benefit of 2FA.

If you’re gonna do this, at the very least have 2FA with a security key on your bitwarden vault.

kniescherz,

You lose security, sure. But you are gaining so much more ease of use. Bitwarden autofills your credentials and puts your token into your clipboard. Also it syncs your tokens to all devices. Effectifly this makes a site as easy to login as a site without 2fa.

The alternative is on desktop always get your smartphone, open some app type a token or on the phone to switch to multiple apps to get your credentials. Not fun imho.

I currently activated 2fa on over 60 sites, I doubt I would use it as much without BW.

For me, the key benefit of 2Fa is getting more security against leaked, stolen, phished passwords, and that still holds up.

IdleSheep, (edited )
@IdleSheep@lemmy.blahaj.zone avatar

The alternative is on desktop always get your smartphone, open some app type a token or on the phone to switch to multiple apps to get your credentials. Not fun imho.

There are desktop apps for OTP, you don’t need a phone. And since you only need to setup an OTP secret once, doing it for your phone and pc isn’t that big of a deal.

I have my OTP secrets in 3 places, 2 yubikeys and my phone’s authenticator app, with the former meant for my PC.

For me, the key benefit of 2Fa is getting more security against leaked, stolen, phished passwords, and that still holds up.

If your vault doesn’t have 2FA too this doesn’t hold up though. Means you’re trusting a single service that can get hacked with all your secrets. Sure, your other accounts are more protected against leaks and stuff, but if your password vault isn’t, you didn’t really change much, just pointed the hackers to one single place.

Yes I know hacking a password vault isn’t some walk in the park and rarely happens, but the point is any leaks from it would be 10 times more catastrophic for you if all your OTP secrets are also stored in it. I’ll spare myself from that nightmare with the small inconvenience that is a separate, offline OTP app.

kniescherz,

Good points!

I got the vault protected via yubikey of course ;)

derpgon,

If you get Vaultwarden, absolutely free, you don’t have to pay and have full control over your data. It’s a win-win!

z3rOR0ne, to programmer_humor in every damn time ...
@z3rOR0ne@lemmy.ml avatar

What is this, a VSCode message? I use NeoVim on Linux and can only vaguely recall such a message from a time long ago…in a galaxy far far away…

agent_flounder,
@agent_flounder@lemmy.world avatar

Yeah vscode.

Today’s stupid question: are vim and neovim not the same thing? I just type vi (ancient habit) and use whatever it is that executes. (I can go search but interacting here is more fun lol)

Dhs92,

I believe neovim is just a fork of vim that’s still updated and has support for more modern features.

9point6,

FWIW I think vim is also still updated, there was a release this year I believe

emptiestplace,

and then Bram died :(

9point6,

oh… oh shit. That had somehow slipped my mind

:(

emptiestplace,

Yeah, it doesn’t make a lot of sense. People talk about “when Linus dies”, and obviously that will be devastating, but in my mind Bram just was. I wish I’d made a point of meeting him, or at least sending him an email to say thanks. Not for vim specifically, though I will probably use it until my fingers quit working. As with countess others, Bram inspired me to learn about ICCF Holland, and from there I had the privilege of supporting a child in Uganda through school. That’s what I’d want to thank him for. And vim.

z3rOR0ne,
@z3rOR0ne@lemmy.ml avatar

Neovim is a fork of Vim. It uses Lua for configuration instead of the original Vim’s VimScript, but still has a lot of interoperability with original Vim plugins and configuration options.

1984, (edited )
@1984@lemmy.today avatar

Neovim is better in many ways, and because it has lua support, it’s so much easier to write plugins for it. So there are thousands of plugins right now, and entire neovim distributions that are configured to work like an IDE, like Lazyvim for example.

www.lazyvim.org

I’m a huge fan and I have written plugins myself since it’s easy and rewarding.

But on the server, I don’t bother installing neovim. Ordinary vim is fine for simple editing tasks. But if you want a customized experience to replace VS Code on your computer, you want neovim and not vim.

backhdlp,
@backhdlp@lemmy.blahaj.zone avatar

Average Neovim user (I use Neovim btw)

Tsubodai,

Neovim extension for vscode. Love it.

Kalkaline, to memes in how th did they make it?
@Kalkaline@leminal.space avatar

Are you asking for real? They probably put it in an upsidedown box to let it rise and bake.

Vespair,

It’s literally just a Japanese-style square lidded bread pan.

For one example (pardon the gross Amazon link): a.co/d/5omfwxk

Kalkaline,
@Kalkaline@leminal.space avatar

There we go

aniki, to privacyguides in BVG out here recommending the best 2FA Apps!

andOTP is opensource, backs up locally, remotely, encrypted, or unencrypted. has no back doors, and will work with any DFA i can chuck at it.

its an archived project but still works fine in modern android

github.com/andOTP/andOTP

vox,
@vox@sopuli.xyz avatar

why not 2fas

frogmint,

Why not Aegis?

OfficerBribe,

Are there well known TOTP apps with backdoors?

aniki, (edited )

Anything closed source could have backdoors. Trust no one.

Why does MS Authenticator need GPS permissions?

play.google.com/store/apps/datasafety?id=com.azur…

OfficerBribe,

As per their FAQ:

Permission to access your location

Q: I got a prompt asking me to grant permission for the app to access my location. Why am I seeing this?

A: You will see a prompt from the Authenticator app asking for access to your location if your IT admin has created a policy requiring you to share your GPS location before you are allowed to access specific resources. You’ll need to share your location once every hour to ensure you are still within a country where you are allowed to access the resource.

aniki, (edited )

And? I don’t give a shit what the admins of my network want. It’s DFA – they don’t deserve to know that. Ergo, I don’t use the MS app. They can kiss my ass and fire me if they don’t trust where I am.

OfficerBribe,

It’s a security / compliance policy. There is a very high chance your company has not even enabled it, have not seen anyone using it.

As I see it, you would and could use it only if you force MS Authenticator notification as the only MFA method and it is important in which country MFA prompt originates. Usually it is IP based block / whitelist which checks IP from which login originates which seems like a much more useful info, then you can also allow any MFA method.

You can always deny permissions to apps.

aniki,

You’re not convincing me.

It’s rather sick to an app that’s open source

OfficerBribe,

Your question was why GPS permission is needed, you should now know why.

I am using MS Authenticator and Aegis. Using MS authenticator only for work accounts that have been setup for number matching feature, it is pretty nice to simply enter 2 digits in app than entering 6 digits in client itself any time you need to approve MFA.

Everything else that supports standard TOTP whether work related or personal is on Aegis - it is a much better TOTP app.

aniki,

i dont care

ReversalHatchery,

That depends. More of the popular ones don’t encrypt the secret keys, they can just be read out with root access or even with the use of ADB (the pull command), not even speaking about reading the memory contents while booted to a recovery.
Some even uploads the keys to a cloud service for convenience, and they consider it a feature.

OfficerBribe,

Sounds more like a bad design than purposefully left backdoors. Very few devices are rooted and usually you cannot get root without fully wiping your device in process. As for cloud upload, that indeed is convenient for most regular users. I prefer encrypted offline backup like Aegis does, but you need to think about regular folk if they would loose or wipe their device.

ReversalHatchery,

It’s not bad design, it’s definitely intentional, however I agree that it’s probably not for having backdoors, but for convenience. Average people forget their passwords all the time, and with encryption that level of carelessness is fatal to your data if they have not saved it somewhere, which they probably didn’t do.

Very few devices are rooted and usually you cannot get root without fully wiping your device in process.

I’m pretty sure the system is not flawless. Probably it’s harder to find an exploit in the OS than it was years ago, but I would be surprised if it would be really rare. Also, I think a considerable amount of people use the cheapest phones of no name brands (even if not in your country), or even just tablets that haven’t received updates for years and are slow but “good for use at home”. I have one at home that I rarely use. Bootloader cannot be unlocked, but there’s a couple of exploits available for one off commands and such.

XioR112, (edited )
@XioR112@lemmy.world avatar

Here is active fork.
github.com/helloworld1/FreeOTPPlus

lemann,

This is what I use. Also supports exporting/importing data to and from Gnome Authenticator so you have 2FA on your computer too 👍

aniki,

Sick! I didn’t think to look at the forks but that’s amazing.

computerscientistI, to linuxmemes in Linus does not fuck around

I wonder if the guys here who are moaning like the snowflakes they are about Linus’ way of conveying the message (not the message itself) are from the US? I sometimes really wonder about the US mindset. The boss is critisizing you justifyably but in an inadequate tone? Hell breaks lose. But as an employee insisting on healthcare, an adequate number of days on paid time off, unionazing or at least have an able workers’ representation? Nah, that’s unheard of.

How about having some priorities? Grow a pair and chose your battles more wisely. The boss criticizes you? If he’s right, own up to your mistakes. Want some rights you are actually entitled to? Yeah, that’s what you fight for.

SK4nda1,

Telling your coworker “Shut the fuck up?” Is not acceptable. The way communication happens matters.

Sanyanov,

Here’s a crazy idea: have both!

Don’t allow your boss to speak to you like that, unionize, and fight for your workers rights - including the right for dignity and respect, listed in the Universal Declaration of Human Rights, but also for higher pay and better working conditions.

How does one hurt the other?

Also, I’m Russian.

corrupts_absolutely,

heres a free critique of your message!
this is garbage ane idiocy, shut the fuck up.
you are also free to say thanks!

uis,
@uis@lemmy.world avatar

Thank you for showing everyone that you can’t read

uis,
@uis@lemmy.world avatar

Found “recent” post on LWN.

After twenty plus years of watching LKML and Linus’s behavior in general, I have to concur with you. Reading a lot of the ‘linus is an asshole’ threads, there’s generally a clear runup towards an outburst.

Just recently he called some developers out because it seemed evident they weren’t testing their patchsets on bare metal. So it’s not just code that gets called out, it’s also development methods that end up causing upstream pain.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • localhost
  • All magazines
  • Loading…
    Loading the web debug toolbar…
    Attempt #

    Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 22881544 bytes) in /var/www/kbin/kbin/vendor/symfony/http-kernel/Profiler/FileProfilerStorage.php on line 174

    Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 10502144 bytes) in /var/www/kbin/kbin/vendor/symfony/error-handler/Resources/views/logs.html.php on line 36