purism, to linuxphones
madargon, to linux
@madargon@is-a.cat avatar

Did my taxes via government website... And now I want to scream about support on ...
Why the hell login via identity card is so much pain every damn time?!?

madargon, to linux
@madargon@is-a.cat avatar

I don't understand why the heck support on , at least in my experience is so awful nightmare...

hko, to rust
@hko@fosstodon.org avatar

The oct tool for inspecting, configuring and using OpenPGP card devices (https://crates.io/crates/openpgp-card-tools) is on "This Week in Rust":

https://this-week-in-rust.org/blog/2024/02/21/this-week-in-rust-535/#projecttooling-updates

Yay! 🎉 Thanks again, @dvzrv 😀

hko, (edited ) to rust
@hko@fosstodon.org avatar

I just released version 0.0.1 of the new crate https://crates.io/crates/openpgp-card-state

This crate paves the way for convenient handling of card User PINs, for users whose threat model allows persisting the PIN locally on the host computer.

If a User PIN is stored, applications can obtain it via this crate, and perform cryptographic operations without prompting the user for PIN entry.

Currently org.freedesktop.Secret is supported for storage.

Thoughts are welcome!

hko,
@hko@fosstodon.org avatar

To illustrate the use of openpgp-card-state, here's an early version of an ssh-agent implementation that uses it:

https://codeberg.org/openpgp-card/ssh-agent/src/branch/state

This SSH agent explores an absolutely streamlined UX for doing ssh backed by OpenPGP card-based key material.

After persisting the User PIN once, like this: "$ openpgp-card-state put --user-pin 123456 0000:01234567", the ssh agent can be used without any user interaction.

hko, to rust
@hko@fosstodon.org avatar

I just released version 0.4.2 of the https://crates.io/crates/openpgp-card low level library, and version 0.2.1 of the https://crates.io/crates/openpgp-card-sequoia wrapper.

These releases add support for cards that are configured to use "KDF mode" for PIN presentation.

Thanks to the reporters in: https://codeberg.org/openpgp-card/openpgp-card-tools/issues/43 (and to Gniibe for providing me some insights into KDF-use in Gnuk).

DD9JN, to random
@DD9JN@social.darc.de avatar

Folks who created a or on the command line with 2.4.2, 2.4.3, or 2.2.42 please read:

https://gnupg.org/blog/20240125-smartcard-backup-key.html

f4grx, to webassembly French
@f4grx@chaos.social avatar

Hey, it would be fun to have a interpreter on a ! Load webassembly modules through a globalplatform channel, and have APDUs execute a predefined wasm export. Add ability to import code from other wasm library modules.

( ping @LaF0rge , @whitequark )

eighthave, to debian

Just migrated my and key setup to a new . This only took about 8 hours whereas when I last did this in 2015, it took much longer. I guess this is a sign of process! But these things are still too painful. At least now, the software just works right out of .

hko, to random
@hko@fosstodon.org avatar

I've just released version 0.4.1 of the https://crates.io/crates/openpgp-card low level library.

This release fixes setting key slot creation times to values with trailing zero bytes (that is, unix time <2^24).

Thanks @ryan for finding and fixing this! 😃

jelora, to random French

Deux épisodes de l'émission américaine "The Computer Chronicles" qui parle des technologies Françaises en 1990 avec le Minitel, la carte à puce et le TGV

1er épisode :
:youtube: https://www.youtube.com/watch?v=DUx7dP2S7h4

2e épisode :
:youtube: https://www.youtube.com/watch?v=sbQPrcyCf00

hko, (edited ) to linux
@hko@fosstodon.org avatar
hko, (edited ) to random
@hko@fosstodon.org avatar

I just released version 0.9.5 of the opgpcard CLI tool (https://crates.io/crates/openpgp-card-tools), now with manpage generation and generation of shell completions (work by @dvzrv, thanks! 🥳)

CLondoner92, to london

Freedom of Information release:
Oldest Oyster card still in use

"The oldest card still in use was issued on 30th June 2003. It was last used in August 2023 (information correct as at 8 September 2023)."
https://tfl.gov.uk/corporate/transparency/freedom-of-information/foi-request-detail?referenceId=FOI-1803-2324

hko, (edited ) to random
@hko@fosstodon.org avatar

I've just released new versions of the openpgp-card family of libraries (https://gitlab.com/openpgp-card/openpgp-card/).

These releases bring a number of breaking changes, but come with many improvements, including a cleaned up and better documented high-level API in openpgp-card-sequoia (https://docs.rs/openpgp-card-sequoia/0.2.0/openpgp_card_sequoia/struct.Card.html).

The releases fix some issues, and build on a new, more generalized card-backend, crate.

Thanks to @NGIZero for supporting this work!

Smartcard Setup Help-Request for RHEL8 Using Active Directory without IDM

So, some background: my organization is moving from RHEL7 using the UI/Coolkey Smartcard setup for autolock on removal and authenticating to the AD. We are in the process of upgrading to RHEL8 in our Secure Area (which means local only connections with zero internet access). This process has been insanely complicated versus...

jelora, to random French

Je viens de voir qu'on pouvait trouver des cartes à puces avec microcontrôleur PIC
https://www.pulsat.com/products/Gold-Wafer-Card.html
Si je parviens à communiquer avec le lecteur de cartes du Minitel, ça serait trop bien si je pouvais faire mes propres cartes
Peut-être en version PCB

BenjaminHCCarr, to boston
@BenjaminHCCarr@hachyderm.io avatar

Teens Hacked Cards to Get Infinite Free Rides—and This Time, Nobody Got Sued
four teens extended other research done by 2008 team to fully "," used by Boston's system. Hackers can now add any amount of money to a card or invisibly designate it a discounted student card, senior card, or even an employee card that gives them unlimited free rides. "You name it, we can make it," says Campbell
https://archive.ph/KjWsL#selection-527.0-527.90

ljrk, to random
@ljrk@todon.eu avatar

Just discovered https://github.com/WICG/web-smart-card/ for teaching instead of ... running pcsc-lite in / over (for ) or exposing the socket (e.g., Linux). Notably the is mentioned as one use case!

I hope this gains similar traction as /// support in browsers, especially with the recent push for , as smart cards are very widely deployed in orgs and slimming down the stack would definitely be a win here.

aspensmonster, to random

Just spent 2.5 shockingly productive hours debugging something in @keyoxide @keyoxide . It looks like Twitter might be blocking keyoxide.org -- or proxy.keyoxide.org -- from accessing the oembed endpoint that (I think) it presently uses for validating Twitter proofs. Or maybe the hosted version of the software at keyoxide.org is just older than the dev branch in the repo. I didn't see any recent commits concerning the issue though, so...

https://codeberg.org/keyoxide/keyoxide-web/issues/163#issuecomment-931046

I'm curious to see if my suspicion turns out to be correct, or if my "productive" time... wasn't. Haven't felt this "tech-capable," if you will, in nearly a year. And I didn't want to yeet my computer into the garbage dump, a la Ron Swanson, either.

I also managed to put my subkeys -- on an environment via without connecting to any networks (yeah yeah, not technically a full airgap I suppose; but better than nothing) -- onto a newer earlier today. Well, "new" as in "I bought two of them nearly a decade ago on the assumption that one of them would eventually break," which... one of them did.

mwfc, to random
@mwfc@chaos.social avatar

I did not follow chips for a while now.
Are there freely programmable ones with + contacts that are not Javacards and let me do baremetal stuff w/o NDA bullshit?

Happy to take s as well

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • tacticalgear
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • Durango
  • cubers
  • Youngstown
  • mdbf
  • slotface
  • rosin
  • ngwrru68w68
  • kavyap
  • GTA5RPClips
  • provamag3
  • ethstaker
  • InstantRegret
  • Leos
  • normalnudes
  • everett
  • khanakhh
  • osvaldo12
  • cisconetworking
  • modclub
  • anitta
  • tester
  • megavids
  • lostlight
  • All magazines