Posts
21886
Following
434
Followers
823
25. θΔδ*& *NIX Developer.Average Paw Enjoyer. ♿ HSD

lotte adds rac- to words a lot but it doesn’t alter meaning

NSFW posts are not for minors (they will be blocked on sight).

Opinions expressed in this profile are representative of those of your employer.

“u are my favorite therianizing biohazard” — @sodiboo@gaysex.cloud
“you know, maybe i will finally learn to read the content warning before clicking 'view' [—] thanks for this lesson @charlotte” — @ariadne@social.treehouse.systems

pfp by @stickerraccoon.bsky.social

@sodiboo @mjg59 like you constructed an environment where the threat model of it happens to not apply. congrats. almost nothing else is like that. adding exceptions to detect if we are on wireguard or sth to determine whether secure origin restrictions should apply or not adds a whole lot of additional complexity which didn’t exist before. this itself increases the risk that an unencrypted communication gets exposed

2
0
1

@sodiboo @mjg59 again, it’s not emotional support cryptography. it’s part of the https protocol

2
0
2

@fiore one underrated pro of celsius is how you can look at someone saying “it’s x degrees” and instantly disregard their opinions if it’s above 50

0
0
1

@volpeon imagine if this happened a week sooner and the alarm schedule was like

wednesday: local alarm test
thursday: germany-wide alarm test
saturday: alarm test in chemnitz

0
0
0

@volpeon one day after weewoo day in $PHYSICALLOCATION

1
0
0

@fiore best they can come up with requires acting like celsius is 100x more coarse than it is

1
0
1

@mjg59 @sodiboo a simple example imagine family computer A that connects to wireguard-protected resource on server B

using just wireguard authentication all users on the machine could access the service

using tls authentication this could be scoped to anyone with a specific certificate (which could be stored on a physical key and pin-protected)

using application authentication could be scoped to anyone with a specific password or passkey

0
0
0

@sodiboo @mjg59 also wireguard authentication is meaningfully different from tls authentication

wireguard authentication says that the peer machine holds a specific key. unless you do stuff like proxying and the like you know that traffic originating from a specific ip comes from a host holding a specific key (which often is stored in plain text on the disk)

tls authentication on the other hand says that the peer has access to a specific application-specific key that belongs to a specific user or service

2
0
1

@sodiboo @mjg59 emotional support cryptography would be adding application layer cryptography in javacript over https for example

tls over wireguard is technically superfluous but “https everywhere” in almost all cases is a good idea

it’s like how when configuring an internal service you would only have it listen on an internal ip (not ::) and not unblock the port in the firewall. one of these is technically superfluous but it’s good to have both

1
0
3

@Elizafox we may choose to kneel recreationally

0
0
0

@aperture @solonovamax @gen

idk i don’t feel temperatures from 0-10 or 0-100. just a range of “comfortable” and “uncomfortable” in xyz clothing which is dependent on stuff like percipitation and clouds and wind which are not represented in the temperature at all

1
0
2

@aperture @solonovamax @fiore @gen idk it’s an unironic complaint i have seen before and that you are also making fun of. it’s genuinely never a problem that 1°C is a bit larger than 1°F

1
0
2

@aperture @solonovamax @gen uh yeah that’s how celsius works too

if it’s starts with a 1 or 2 it’s fine, 3 or 4 and i want to die

1
0
1

@aperture @solonovamax @gen fahrenheit fans be like: man it’s so hot today, like 621 degrees, to think that earlier this month it was 300

1
0
2

@Starcross @lina idk i would consider a printer that couldn’t print in a4 to be broken

1
0
3

Charlotte lotteheartplural/Cinny cinny_heart_plural thetadelta ursaminor treblesand

Edited 11 days ago

@sodiboo @mjg59 hey so fun fact, private networks aren’t always particularly private and also aren’t free of attackers necessarily

you could be like my previous ISP who assigned private range IPs to cgnat devices with literally 0 firewalling

1
0
3

@sodiboo @mjg59 you know there’s transport encryption, the browser doesn’t know that and it simplifies a lot of checks if you simply assume that the channel is unencrypted

1
0
1

@sodiboo @mjg59 tbh set up right it’s not hard to both have working internal tls with no cert store shenanigans and also HSTS preloaded on the site

1
0
1
re: license stuff (2)
Show content
@joepie91
shoutouts to agpl where a signifficant amount of software uses it as an exit strategy by companies
0
0
1

Charlotte lotteheartplural/Cinny cinny_heart_plural thetadelta ursaminor treblesand

your honor, the llm scrapers have hit the hydra

0
0
1
Show older