@Scraft161@tsukihi.me avatar

Scraft161

@Scraft161@tsukihi.me

FOSS enthusiast and anime fan.

DM/PM's are open, just know I will respond when the 5 gremlins in my brain decide they want social interaction by majority vote.

also, I boost a lot of stuff, if you dare follow me expect this to drown your feed if you're not active all the time, if you just want to see my posts you can hide a person's boosts on their profile and it shouldn't drown your feed.

This profile is from a federated server and may be incomplete. Browse more on the original instance.

Scraft161, to random
@Scraft161@tsukihi.me avatar

@jeffowski

was shared to me on discord; and thought I should share it here too.

Scraft161, to infosec
@Scraft161@tsukihi.me avatar

Hardware security key options?

I've been thinking about getting a hardware security key and have heard of yubikey before; but I want to see what my options are and if they are worth it in your opinion.
My current setup is a local KeePassXC database (that I sync between my PC and phone and also acts as TOTP authenticator app), I know that KeePass supports hardware keys for unlocking the database.

I am personally still of the belief that passwords are the safest when done right; but 2FA/MFA can greatly increase security on top of that (again, if done right).
The key work work together with already existing passwords, not replace them.

As I use linux as my primary OS I do expect it to support it and anything that doesn't I will have to pass on.

PS: what are the things I need to know about these hardware keys that's not being talked about too much, I am very much delving into new territory and want to make sure I'm properly educated before I delve in.

@linux @technology @technology @privacy

Scraft161,
@Scraft161@tsukihi.me avatar

I don't have a key yet (which is why I'm asking) and I definitely want it in combination with passwords (they can take the key using force; but they can't take thoughts out of my head just yet).

As for android apps not working with the yubikey: try giving KeePassDX a shot; I got it from F-Droid and it does give me a hardware key field with the option to autofill with "Yubikey challenge-response".

Scraft161,
@Scraft161@tsukihi.me avatar

Let's NOT go that route.

I'm very much looking for a hardware key to avoid biometrics (I can have a field day expressing my opinions on those; but in general they tend to be the weakest MFA factor and most have known working bypasses based on photos).
This leans a little too close to that for me to consider, let alone all of the things you have to consider when putting implants in your body.

Scraft161,
@Scraft161@tsukihi.me avatar

For many TOTP may be a good option; but my experience with TOTP has been less than subpar.

Initially I did use TOTP like you're supposed to; but after my last phone died I had to set up TOTP on the accounts that used it after getting into them without it using backup codes.
This lead me to put the TOTP stuff inside my KeePass vault (as KeePassXC supports TOTP) which is backed up (unlike most TOTP solutions I've used).
The problem now is that my 2FA keys are stored in the same location as my passwords... (not that I'm worried about someone breaking the vault; but this is not how 2FA is supposed to work).

Additionally I have some other issues with TOTP that make it far from ideal for me and hardware keys seem to be a good fit to solve my issues with TOTP.

TechConnectify, to random
@TechConnectify@mas.to avatar

I'm going to irritate a subset of electricians with this new video...

https://youtu.be/vNj75gJVxcE

Scraft161,
@Scraft161@tsukihi.me avatar

@TechConnectify it's weird to see this as in the EU we have Type C for ungrounded and both Type F and Type E for grounded, the last one is usually installed with the ground pin up which I have never seen shielded and comes out of the socket.

both Type C and F never care about orientation unless a type E socket is used in which case the ground pin would always fit on the top.

additionally pins on Type C are always insulated; but for Types E and F the socket itself should be recessed far enough that contact should not be possible when the pins are accessible (although older construction is not always up to code with this; but then we also have Type C sockets that accept E and F even though there is no grounding).
nowadays in new construction the grounded Type F (or E depending on country) is required and Type C sockets (not the plugs) are illegal to build.

PS: I used the types from this site documenting the plug standards around the world: https://www.worldstandards.eu/electricity/plugs-and-sockets/

thelinuxcast, to mastodon
@thelinuxcast@fosstodon.org avatar

Can we just pause for a moment and think about, again, how stupid a name #X is for a social media site? Every time I'm forced to go there because the peons refuse to come here to , I am reminded how dumb that name is.

Scraft161,
@Scraft161@tsukihi.me avatar

@thelinuxcast
The upside is that we can now call Elon's tweets Xcrements, which is a pretty accurate representation of the content and how he runs the company, this has to be some form of X-it strategy.

thelinuxcast, to random
@thelinuxcast@fosstodon.org avatar

I need some good color schemes. Send me ideas, please.

Some things off the beaten path would be great.

Scraft161,
@Scraft161@tsukihi.me avatar

@thelinuxcast been happy on Tokyo night myself, there's a couple themes, but not nearly everything has a theme for it (there's a GTK one, but I haven't seen a Qt one yet).
All by all it looks really good doubly so in neovim with treesitter.

BrodieOnLinux, to random
@BrodieOnLinux@linuxrocks.online avatar

Wait, how did I only just realize that Sylphy and Y'shtola are voiced by Ai Kayano, I guess before the time skip we never saw Sylphy with any confidence so it was easy to miss

image/png

Scraft161,
@Scraft161@tsukihi.me avatar

@bill88t @BrodieOnLinux +1, the anime is not nearly the same quality as in S1 and there's a lot of content that has been cut but is crucial for giving context to Rude us as a character

thelinuxcast, to random
@thelinuxcast@fosstodon.org avatar

What window managers/desktop environments do you have installed?

Am I the only one who has more than one?

I have:

xfce4
qtile
bspwm
xmonad
dwm
openbox
icewm

Maybe a little excessive?

Scraft161,
@Scraft161@tsukihi.me avatar

@thelinuxcast custom dwm, been looking into Wayland for a good while but Nvidia has put a stop in that as far as I'm concerned.

I do wish I could give hyprland a proper try but the GPU configuration straight up prevents any hardware acceleration on Wayland and it works under X11 after hours of fiddling.

thelinuxcast, to random
@thelinuxcast@fosstodon.org avatar

I hate to say it, but I hate not having an on going challenge. What non-distro challenge should I take on? People who say emacs will be blocked.

Scraft161,
@Scraft161@tsukihi.me avatar

@thelinuxcast nutshell is an interesting one, it can do a lot of things but it's not a sh clone like bash or zag and things are different in interesting ways.

BrodieOnLinux, to random
@BrodieOnLinux@linuxrocks.online avatar

The best part about Twitter breaking viewing the site without logging in is it also breaks embeds, luckily vxtwitter still somehow functions

Scraft161,
@Scraft161@tsukihi.me avatar

@BrodieOnLinux I never really understood why I would have to log in. Yes I am going to look at questionable art, yes you know it's my device and yes it is the same IP I used to create the damn account.
You already know it is me so why would I have to pretend that you don't?

BrodieOnLinux, to random
@BrodieOnLinux@linuxrocks.online avatar

With all this Red Hat stuff happening right now I want to make something very clear, going around harassing Red Hat employees, and Fedora contributors is not useful to the discussion and won't make anything change.

Scraft161,
@Scraft161@tsukihi.me avatar

@BrodieOnLinux sometimes it amazes me that people love jumping the gun before thinking about who is responsible for making this decision in the first place.

we all need to stop attacking each other and focus our attention at the actual issue so we can try and come to a solution rather than meaningless infighting.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • tacticalgear
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • Durango
  • cubers
  • Youngstown
  • mdbf
  • slotface
  • rosin
  • ngwrru68w68
  • kavyap
  • GTA5RPClips
  • provamag3
  • ethstaker
  • InstantRegret
  • Leos
  • normalnudes
  • everett
  • khanakhh
  • osvaldo12
  • cisconetworking
  • modclub
  • anitta
  • tester
  • megavids
  • lostlight
  • All magazines