@kolle

1 Followers
84 Following
97 Posts
🇩🇰 Retired software engineer.
👨‍🏫 Former associate professor in engineering
🤓 Open Source and Linux nerd
🍺 Homebrewer
🚗 Citroën car lover
Websitehttps://www.kolle.dk/index.html
Verificationhttps://www.kolle.dk/index.html

Google has just updated its 2FA Authenticator app and added a much-needed feature: the ability to sync secrets across devices.

TL;DR: Don't turn it on.

The new update allows users to sign in with their Google Account and sync 2FA secrets across their iOS and Android devices.

We analyzed the network traffic when the app syncs the secrets, and it turns out the traffic is not end-to-end encrypted. As shown in the screenshots, this means that Google can see the secrets, likely even while they’re stored on their servers. There is no option to add a passphrase to protect the secrets, to make them accessible only by the user.

Why is this bad?

Every 2FA QR code contains a secret, or a seed, that’s used to generate the one-time codes. If someone else knows the secret, they can generate the same one-time codes and defeat 2FA protections. So, if there’s ever a data breach or if someone obtains access .... 🧵

#Privacy #Cybersecurity #InfoSec #2FA #Google #Security

With all that in mind, here's a suggestion:

➡️ *IF* mastodon.social becomes more than 50% of the Fediverse, either by total users or monthly active users, the rest of us should defederate it.

Sticking with mastodon.social because "that's where the people are" is pointless. Centralised growth will simply cause the governance problems we've seen on Twitter and Facebook to be replicated on here.

Growth has to be decentralised in order to protect the independence of all Fedi servers.

(4/4)

Here's what Eugen Rochko's Mastodon gGmbH organisation now controls:

-The Mastodon server software & API (though the current version is FOSS)
-The mastodon.social server, which has 1 in 7 of all Fediverse users
-The official Mastodon apps, now telling people to just sign up on mastodon.social
-The official website at joinmastodon.org
-The trademark for the word "mastodon", which lets them dictate terms to any server which uses it

This is a tempting package for any potential buyers.

(2/4)

I don't think people are realising the danger the Fediverse is in.

The only thing stopping corporations and VCs taking over this place is that the Fediverse is spread out on many different servers, which makes it very difficult to purchase.

If most of the Fediverse ends up on mastodon.social, which is now a strong possibility, there will be nothing to stop most of it being sold to Musk or Zuckerberg or whoever.

The bigger mastodon.social becomes, the more likely a buyout is to happen.

(1/4)

When you finally hear those three golden words: “IT’S RACE WEEK!” 💪🇦🇿

#HaasF1 #AzerbaijanGP

Great moments in software engineering

Newfoundland, ca. 1000 CE: A bug in the Google Maps route-planning algorithm at high latitudes causes Leif Eriksson and his crew to miss Greenland entirely. They instead become the first Europeans to reach North America. They name the place "Vimland" in honor of a text editor sacred to Odin. Emacs-using natives soon attack the Vikings on several Usenet groups.

#gmise #softwareengineering #humor #midjourney #aiart

Somewhere, someone finally made this and I think it's beautiful

https://www.thingiverse.com/thing:4687836

#hardware

Ethernet | RJ45 clip to secure/repair/fix broken tab by guss67

This clip was design to fix/repair/secure the broken or loose tab of a RJ45 Ethernet connector and avoid crimping. Designed to prevent from moving, wiggling, falling from the connector and easy to install.UPDATE v.4.9 | 28/01/2021Added the 3 following files which have slightly wider body (0.25mm) than 4.7 version and small upgrade on the tip.1. "4.9.nf.supported" (extension) comes "with supports" for the ones are not very familiar with. But I still prefer S3D's supports.2. "4.9.nf" (extension) with "no fillet", to make it easier printing with supports.3. "4.9" (extension) with fillet, for "smooth edges". On FDM printers isn't that much noticeable.UPDATE v.4.7 | 01/01/2021Added another version with "no fillet" (".nf" extension), actually it has sharp edges to make it easier printing with supports.PrintingSuggested printing orientation is the one as the files are stored, why?Printing the tab from the base to the tip in X-Y axis makes it stronger and more flexible since its printed in one continued string.If you change the orientation with the tip on top then tab's base will start from the bottom and builds up while the Z axis is sticking the rest of it till the tip. With this orientation the tab has more possibilities to brake since Z layers don't bond the same as the method I suggested.*If you have another solution let me know.Supports Supports needed and you need to be experienced with good slicer settings. Also attention needed when removing them from the actual print.Or you can print the file with "4.9.nf.supported" (extension) which comes with supports. But I still prefer S3D's supports.Installation note:1.Before install the "printed clip" check the left overs of the broken tab. If it is too long the tip of the "printed clip" might not click underneath the left-over. So, I suggest to leave a length of the broken tab about "0,5-1,0mm". If the broken tad left-over is to small or cuted flash then the printed one might not click and hopefully that would work well, haven't tested that scenario.2.Follow the sketches to install the "printed clip", also while sliding in if you find it a bit hard some wiggling might help.*You may call it the "ScorpioNet" or "Devil's Network Tail"! Designed in InventorIf you enjoy and want to support my work you can donate me on the link below,Thank you!

Thingiverse - Digital Designs for Physical Objects
Source unknown to me, unfortunately
"Hi, I'd like to hear a TCP joke."

"Hello, would you like to hear a TCP joke?"

"Yes, I'd like to hear a TCP joke."

"OK, I'll tell you a TCP joke."

"Ok, I will hear a TCP joke."

"Are you ready to hear a TCP joke?"

"Yes, I am ready to hear a TCP joke."

"Ok, I am about to send the TCP joke. It will last 10 seconds, it has two characters, it does not have a setting, it ends with a punchline."

"Ok, I am ready to get your TCP joke that will last 10 seconds, has two characters, does not have an explicit setting, and ends with a punchline."

"I'm sorry, your connection has timed out. Hello, would you like to hear a TCP joke?"
A reminder to non-Americans: assigning Pi Day to 22nd July is not only more accurate than 3.14 (22/7 is 3.14285), it's also more likely to annoy Americans.