Blake Ashley Jr.

@blakeashleyjr
0 Followers
103 Following
72 Posts

I am a DevOps Engineer that has traditionally specialized in web applications (WebOps), specifically massive, complex, popular WordPress sites that should have been a static webpage (like this one.)

I am currently learning the Go programming language and loving it.

I spend my free time writing here, working on my homelab, training in Jiu-Jitsu, reading, or planning my next backpacking trip.

Websitehttps://blakeashleyjr.com
Githubhttps://github.com/blakeashleyjr

Google has just updated its 2FA Authenticator app and added a much-needed feature: the ability to sync secrets across devices.

TL;DR: Don't turn it on.

The new update allows users to sign in with their Google Account and sync 2FA secrets across their iOS and Android devices.

We analyzed the network traffic when the app syncs the secrets, and it turns out the traffic is not end-to-end encrypted. As shown in the screenshots, this means that Google can see the secrets, likely even while they’re stored on their servers. There is no option to add a passphrase to protect the secrets, to make them accessible only by the user.

Why is this bad?

Every 2FA QR code contains a secret, or a seed, that’s used to generate the one-time codes. If someone else knows the secret, they can generate the same one-time codes and defeat 2FA protections. So, if there’s ever a data breach or if someone obtains access .... 🧵

#Privacy #Cybersecurity #InfoSec #2FA #Google #Security

Finally got my new personal site in a firm 1.0 state. Let me know what you think!

https://blakeashleyjr.com

Blake Ashley Jr.

My thoughts on tech, work, and life

Blake Ashley Jr.
@aeva
"Linux is mature now! They even have it on the ISS."
"So that's why there's no sound in space."
All the Biomass of Earth, in One Graphic

Our planet supports nearly 8.7 million species. We break down the total composition of the living world in terms of its biomass.

Visual Capitalist

A couple of weeks ago, I went from 3 monitors to 1, and my productivity and focus has shot up.

I have the 42" LG C2 OLED TV as my primary monitor. Before, I also had 2 24" monitors in portrait mode on each side. These monitors would have my email, chat, calendars, todolist, etc. on them at all times.

As I type it out, it sounds like a terrible idea, but retrospect is 20/20.

With only the one monitor, I keep things essential to the current task in view and use workspaces for everything else.

For everyone freaking out about the official Mastodon app recommending mastodon.social via a prominent button, you can easily migrate instances if you become disenchanted. Everyone should relax:

https://blog.joinmastodon.org/2019/06/how-to-migrate-from-one-server-to-another/

How to migrate from one server to another

With the sad news that KNZK was shutting down we thought it might be useful for people to have a refresher on the features that Mastodon has built in that make moving instances easy and painless. Backing up Your Data Data export If you are moving to a new instance the first thing you will want to do is to get a backup of all of your data. Thankfully this process is painless with the Data Export tab under the “Import and Export” page. Here you can download your followers list, your muted users list and your blocked users list.

Mastodon Blog

Please implement scheduled messages @simplex!

Correlation attacks are a potentially dangerous threat to privacy.

Say a protestor is suspected of posting anti-government comments in a Simplex Chat. Undercover agents watch this person constantly. Over time, they can effectively prove (maybe not to a jury, but they don't care) the person is their dissident. If they were able to schedule messages, this would be impossible if the messages were randomly scheduled.

https://github.com/simplex-chat/simplex-chat/issues/1549#issuecomment-1515642850

Scheduled messages · Issue #1549 · simplex-chat/simplex-chat

Cases like "I have to send this message at noon, but I’m in a meeting and I might forget of it" or "It’s midnight, I don’t want to disturb now" can finally have a dedicated solution. Sliding sidely...

GitHub

If you were dumb like me and used to have a Facebook account anytime between May 24, 2007 through December 22, 2022, you can submit a claim to get money from Facebook from a settlement over privacy. I was a user from 2006-2018 and was very happy to complete this form.

https://www.facebookuserprivacysettlement.com/#submit-claim

In re: Facebook, Inc. Consumer Privacy User Profile Litigation

If you were a Facebook user in the United States between May 24, 2007, and December 22, 2022, inclusive, you may be eligible for a cash payment from a Class Action Settlement.

@JLW_the_Jobber @protonmail @protonvpn
I am trying to frame it as a two-fold migration:

1. Away from Google, towards encryption, privacy, etc, etc.

2. A step back towards a simpler digital life. Do I really need 15 apps interacting with my calendar, email, and contacts? Probably not.

That being said, looking at you Proton, some way to interact via API, bridge, client, etc with my calendar would be a huge feature for me.

In 1930, the 22-million-pound Indiana Bell building was rotated 90 degrees over a month at a rate of 15 inches per hour, while 600 employees worked inside. Despite the slow movement, there was no interruption to the building's services, and none of the employees felt it move. #ConstructionHistory #StructuralEngineering