Comments

This profile is from a federated server and may be incomplete. Browse more on the original instance.

heartlessevil, to asklemmy in What's a true fact that is so misleading it's borderline misinformation?

The introduction of seatbelt legislation lead to an increase in nonfatal vehicular injuries

heartlessevil, to asklemmy in What are some good ways to cure boredom while indoors?

Do you have other ways to get around? Maybe moving to a place that does? I realize I'm not answering your question, but there's only so much fun you can have indoors by yourself all the time. You'll end up feeling bored eventually no matter what. You specifically mentioned that outside is scary, which I think is the core problem here. Doing some exposure therapy by yourself or with guidance from a therapist could help.

heartlessevil, to asklemmy in What's the best way to get rid of house centipede?

You could move from a house to a cabin, trailer, or cave. Then you only have to deal with cabin centipedes, trailer centipedes and cave centipedes. But the house centipedes will be a thing of the past.

heartlessevil, to asklemmy in I need to survive for 3 days without pooping, and eating as little as possible. I can pee, but not very often. It can't take up too much space. What food do I pack?

This is the first post on lemmy I've bookmarked, congrats

heartlessevil, to asklemmy in What will happen to Brave browser after the manifest change?

One thing that rings alarm bells for me is that they have a built-in adblocker, but you can enable Brave's ads instead and get a cryptocurrency reward. Brave takes 30% cut on the ads they show this way, so they are essentially replacing the website's monetization with their own monetization. Kind of scummy, and it being a cryptocurrency also looks grifty.

https://brave.com/brave-rewards/ (See "what % of ad revenue"...)

Secondly, the founder has really awful politics, but I will leave that to the reader.

heartlessevil, to asklemmy in What will happen to Brave browser after the manifest change?

Because nearly 90% of users use Chrome or a derivative thereof. People can make a V3 version for Chrome and a V2 version for other browsers, but the APIs are nowhere near compatible, so it's a lot of extra work. If you just make a V3 version, it will work on any updated browser.

heartlessevil, to asklemmy in Can you steal a user's identity if you gain their old domain name?

I imagine it works exactly like email where it is possible to inherit someone else's expired domains.

Checking out the relevant specifications: ActivityPub and WebFinger

  • Both of them identify users by URL, there is no numeric ID, UUID, or public key.
  • Using IDs or UUIDs would not be secure since the imposter could just copy the ID from the previous user as well as the username and domain name.
  • Verifying identity would necessitate the user having a public key as their unique identifier, and federated servers performing a challenge-response that requires the user to have the corresponding private key for that public key.

In conclusion, it certainly seems like you could take over someone else's domain name, and I suspect that public key cryptography is the only way to avoid this.

(edited to add: expired domains aren't the only attack surface here, domain takeover is also a thing, either by transferring the domain or simply changing the DNS records.)

  • All
  • Subscribed
  • Moderated
  • Favorites
  • localhost
  • All magazines
  • Loading…
    Loading the web debug toolbar…
    Attempt #