kubikpixel, to rust German
@kubikpixel@chaos.social avatar

Nun ja, auch wenn Passkey was gutes ist und von grossen Firmen bereits angeboten im Einsatz ist, fast keine kleinere Firma investiert in die Tools daführ. Dies auch mMn weil sie es als "zu teuer & unnötig" ansehen.

»Chance verpasst – Webauthn-rs-Entwickler hält Passkeys für geplatzten Traum:
#Passkey's sollen Anmeldevorgänge sicherer und benutzerfreundlicher machen. Der Entwickler einer #Webauthn-Bibliothek für #Rust sieht das Vorhaben inzwischen als gescheitert an.«

🔑 https://www.golem.de/news/chance-verpasst-webauthn-rs-entwickler-haelt-passkeys-fuer-geplatzten-traum-2404-184648.html

kubikpixel,
@kubikpixel@chaos.social avatar

🧵 …wie im obigen verlinkten Artikel schon erwähnt, kann ich durchaus @bitwarden oder deren in Rust entwickelten Klon @vaultwarden_releases empfehlen, obwohl ich persönlich @keepassxc bevorzuge und über eine @nextcloud Instanz die Daten zwischen den Geräten synchronisiere 🔑


#itsicherheit #passwort #pwmanager #keepassxc #keepass #bitwarden #it #websec #rust #rustlang #sicherheit

kubikpixel, to javascript
@kubikpixel@chaos.social avatar

«JavaScript Bloat in 2024»
– by @nikitonsky

Fast Internet is not really available these days. Not because of the connection, but because of the excessive data flow and JavaScript application on the pages. In my opinion, this is often too much of a good thing.

☝️ https://tonsky.me/blog/js-bloat/

postmodern, to random

are there SSTI tests that can pinpoint exactly which template engine is being used. {{ 7*7 }} only tells you that SSTI is possible, but not which engine is being used. {{ }} is used by Liquid, Jinja, Vue.js, and Angular.js, so testing with {{ }} doesn't narrow things down.

zsoltsandor, to Vivaldi

Hey @Vivaldi noticed that vivaldi.net is one of the all-greens on Hardenize.
I'd move my mails to vivaldi.net, but I have size worries, still use other providers, & own domain.
Do you have any plans to implement paid size plan, & features like automatic IMAP fetch, external sending SMTP, own domain management?

#vivaldi #netsecurity #netsec #websecurity #websec #mailsecurity #mailsec #dnssec #dane #tls #tlsrpt #mtasts #spf #dmarc #dkim #security #privacy

konstantin, to random

I just read about the backstory for the .zip and .mov TLDs and Google's thinking seems totally orthogonal to reality:

Google marketers say the aim is to designate “tying things together or moving really fast” and “moving pictures and whatever moves you,”

.mov is a movie, and .zip is an archive, and no amount of Google marketing can change that. Moreover, yes, black holing these domains sounds like a good idea.

https://arstechnica.com/information-technology/2023/05/critics-say-googles-new-zip-and-mov-domains-will-be-a-boon-to-scammers/

konstantin,

I found the delegation report for the .zip domain, it references the "New gTLD Application Process Completed" https://www.iana.org/reports/c.2.9.2.d/20140910-zip

I'm new to this but the report itself, doesn't have the word “security” in it at all https://www.iana.org/reports/tld-transfers/gtld-readiness-1-1678-17174.pdf.

There is a "Did the Application successfully complete the Technical and Operation Capability review? - Yes" but I need to read more what exactly are the technical parameters for a new TLD string to be acceptable.

Strangely enough, there is also a "Public Comment Period" with "Was the public provided an opportunity to submit comments on the Application? - Yes"

Has anyone in the history of anything ever heard of ICANN public comment for new TLDs?

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • Durango
  • everett
  • cisconetworking
  • magazineikmin
  • mdbf
  • rosin
  • ngwrru68w68
  • thenastyranch
  • Youngstown
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • megavids
  • ethstaker
  • normalnudes
  • tester
  • cubers
  • tacticalgear
  • InstantRegret
  • osvaldo12
  • modclub
  • Leos
  • provamag3
  • GTA5RPClips
  • anitta
  • lostlight
  • All magazines