Hacker Newsnew | past | comments | ask | show | jobs | submit | Panino's commentslogin

Don't bother with cookies at all unless they serve the interests of the user. And in that rare case, only do a cookie banner if required by law, and here's how to do it: just pretend it's "fine print." Make it functionally invisible, but good enough to get away with it. Nobody will complain about your cookie banner not being annoying enough.

The EU cookie directive, at least, does _not_ require notification if the cookies are functionally necessary.

Among other changes 10.4 adds post-quantum keys (composite ML-DSA 44 and Ed25519), not enabled by default.

When pq key agreement was added in 2019, it took almost 3 years for it to become enabled by default. This isn't criticism, just an observation. I don't have a pressing need for pq sigs. Always happy for new OpenSSH releases though!


> Among other changes 10.4 adds post-quantum keys (composite ML-DSA 44 and Ed25519), not enabled by default.

The draft was only published a few months ago:

* https://datatracker.ietf.org/doc/draft-miller-sshm-mldsa44-e...

The draft is a 'personal document', so not associated with the IETF/WG.


I recently added ml-dsa-44 to solokeys, both piv and fido2. To my understanding ssh+fido2 doesn’t support pq yet, but if anybody’s reading and knows how to make it happen, I’d be really interested.


> It's always the most insufferable people that make the biggest hullabaloo about a project they have nothing to do with and have never contributed to.

Agreed, and similarly, as a hobbyist programmer who loves Rust and Go, I've always felt that the people who command others to "rewrite it in xyz" are not themselves developers, they're "ideas people." There's a mass of these people whose main interactions with the world are through the dramatic forcing of their correct opinions.

> I run a smallish project with ~1k stars and I've stopped maintaining it last year because people feel like they're absolutely owed features or bug-fixes or whatever.

That's a bummer and it's something I'm fearful of. I post some code on my website, not on a github type site, and don't interact with people about it. It's nice and plenty of people do it. Is that something you'd consider?


Will Prowse has a very active, high quality Youtube channel about DIY solar where he talks about all things solar: generation, safety, cabling, inverters, batteries and more.


It's been a while now but once out of curiousity I tested the text to speech functionality (with my eyes closed) on an iPhone and another device (a laptop maybe?), and found iOS to be more advanced but still lacking. I don't know much about this but it's nice to see improvements. GrapheneOS seems to be a high value project in terms of dollars-to-output.


Yeah I've never regretted a Monero donation to them.

They accept more than 11 different payment methods[1] for donations and pay most of their devs in Monero.

[1] https://grapheneos.org/donate


I'd like to donate with Monero, despite my misgivings about the privacy guarantees of RingCT, because I support the spirit of both projects. but I don't want to raise a red flag to my banking institutions or government. what's the least sketchy-looking way to acquire Monero to donate to projects like this?


Least sketchy? Haveno[2] is one of the exchanges that the getmonero.org site recommends. However, the platform with the most "institutional support" (if that's what you meant by least sketchy) that allows you to buy XMR is probably Kraken[2], but IIRC they have KYC that takes a few days before you can buy.

[1]: https://haveno.exchange/

[2]: https://www.kraken.com/


I have never purchased Monero anonymously, I just buy it straight from fiat on Kraken.

What I do:

Fiat-->Kraken-->Monero-->Self-custody Monero Wallet

If you don't want anyone to know you purchased Monero(which is not necessary for most people because once you have the Monero, it's untraceable and all anyone can know is that you bought Monero, similar to how anyone can know you have cash once you withdraw from the ATM, but it's untraceable) then the easiest way would be to buy a different crypto (that you are okay with bank/govt knowing you bought) and then swapping it to Monero.

Now, I don't know the extent to which you would be passively traced if you bought a traceable crypto like Bitcoin on Kraken, withdrew to CakeWallet and swapped on Trocador. It would depend on if the instant exchange on Trocador shares info with Kraken or they both use the same Chainalysis company.

What you could do to break the link is buy ZCash on a CEX like Kraken, withdraw to CakeWallet, shield it(I think it's automatically shielded, but Ive never used ZCash), and then swap on Trocador for Monero.

The idea here is that ZCash is more friendly to govt so they still know you bought ZCash, but after you bought it, it vanishes from their analysis.

Haveno/Retoswap is great, but I would not encourage it for your first time obtaining Monero because it is not easy for beginners and can be complicated. Also there was an exploit recently. I do think long-term it will be awesome.

> despite my misgivings about the privacy guarantees of RingCT

Yeah well fortunately we are upgrading to FCMP++[1]. Also, a lot of Chainalysis's tracing from this leaked video[2], highly recommend you watch, was based on malicious nodes. They implemented an IP blacklist for malicious nodes, but you can also use Tor for more protection. The best thing for would be to run your own node.

I have a node I host and if you contact me I can give you the URL–it's really fast.

I've given info about buying Monero in the past[3], but not your specific situation. You might find it informative.

[1] https://www.youtube.com/watch?v=jc8Kc0WogAI

[2] https://odysee.com/@tuxsudo:6/chainalysis_XMR:69

[3] https://news.ycombinator.com/item?id=47858801


>The idea here is that ZCash is more friendly to govt so they still know you bought ZCash

Not when it's shielded which is why nobody uses it that way so you might as well just directly buy the superior private currency monero.

>similar to how anyone can know you have cash once you withdraw from the ATM, but it's untraceable

Contrary to popular belief cash is very much not untraceable. Serial number tracking is a thing but probably unlikely to be used against low level targets at scale (yet).


> Not when it's shielded which is why nobody uses it that way so you might as well just directly buy the superior private currency monero.

The person I replied to asked how to buy it without "raise a red flag to my banking institutions or government". I don't think buying Monero would raise a red flag and I would absolutely recommend buying it directly. Unfortunately, it's delisted in many countries so the only option is to buy a different crypto and swap it. For most people Litecoin is fine for that, but if you wanted to prevent anyone from knowing you bought XMR, than I think ZCash is a good choice.

If you swap from a transparent coin to Monero and the exchange that you swapped on shares data, than they could know that you bought Monero. If you use shielded ZCash, I assume that link is broken and all they know is that you shieled your ZCash.

Really, I don't think they have much of a problem with buying XMR as much as depositing and exchanging back to fiat.

>Contrary to popular belief cash is very much not untraceable. Serial number tracking is a thing but probably unlikely to be used against low level targets at scale (yet).

Likely similar with Monero right now. Highly resistant to mass surveillance, but must be used with good OPSEC to remain anonymous against targeted attacks.

As we saw from the leaked Chainalysis video, targeted attacks on Monero users have been done, although it's likely due to the malicious nodes. FCMP++ will greatly mitigate the attack and Monero will gain back footing equal to shielded ZCash for sender privacy.


Even if you don’t value this particular function and even if it’s not as good as Google or Apple, I think it’s important to have viable free alternatives so if Google and Apple rapidly become (significantly more) actively hostile there are viable alternatives.


TBF my only problem with GoS is that Google is actually hostile (as in the seemingly targeted way), that some institutions (like certain banks) are actively hostile, so both of these things create friction or issues for me, and my only personal issue is that they could use someone less abrasive to communicate (I was on the receiving end of someone who could be described as illegitimate child of Linus Torvalds, Leonard Poettering and a lesser basilisk in terms of politeness in response to me asking a normal user question on the discussion forum. Grim)

So, would recommend in general.


I've been using openrsync here and there since it was announced and it's definitely improved over time. I'm looking forward to when I can use it exclusively.

The one place in my usage where it doesn't match Samba rsync is with the following:

openrsync --rsync-path=openrsync -av -e ssh /etc/services example.com:/tmp/services

I would expect openrsync to create a remote file /tmp/services, but instead it creates /tmp/services/services.

Normal directory mirroring as in -av -e ssh /path/to/src/ example.com:/path/to/dst/ works as it does with Samba rsync.


> The one place in my usage where it doesn't match Samba rsync is with the following:

> openrsync --rsync-path=openrsync -av -e ssh /etc/services example.com:/tmp/services

This appears to match "normal" `rsync` behavior as well. I think you need a trailing slash after `services` to sync only the contents.

EDIT: actually my "normal" rsync is openrsync on macOS...


This switch happened in macOS 15.4, it was pretty easy to miss.


sounds like a compliment to the implementation


Or more likely that prior to 15.4, macOS was using an ancient version of rsync because Apple wants to avoid the GPL 3.0. rsync went GPL 3.0 in 2007.


Nonetheless, this matches vanilla rsync.


No, it doesn't.

I think some people may not be reading closely. On Unix, "/etc/services" is a file, not a directory:

  $ file /etc/services                                                                                                                         
  /etc/services: ASCII text
Here are two OpenBSD 7.9 endpoints running Samba rsync:

rsync -av -e ssh /etc/services example.com:/tmp/services

The above command creates a mirror of the local file /etc/services in a remote file called /tmp/services. The outcome is exactly the same as if I had run "scp /etc/services example.com:/tmp/services"

  client$ sha256 -q /etc/services                                                                                                                    
  469d28e72ed0e0994d31b555cc1bed7bc95a23fd1beeb30062affb64db0dd44a

  server$ sha256 -q /tmp/services                                                                                                          
  469d28e72ed0e0994d31b555cc1bed7bc95a23fd1beeb30062affb64db0dd44a
openrsync --rsync-path=openrsync -av -e ssh /etc/services example.com:/tmp/services

The above command creates a mirror of the local file /etc/services in a remote file called /tmp/services/services. The outcome is NOT the same as if I had run "scp /etc/services example.com:/tmp/services"

Please note that "/tmp/services" and "/tmp/services/services" are different.

  client$ sha256 -q /etc/services                                                                
  469d28e72ed0e0994d31b555cc1bed7bc95a23fd1beeb30062affb64db0dd44a

  server$ sha256 -q /tmp/services  
  sha256: /tmp/services: read error: Is a directory
  server$ sha256 -q /tmp/services/services                                                                                                 
  469d28e72ed0e0994d31b555cc1bed7bc95a23fd1beeb30062affb64db0dd44a
Here's an OpenBSD 7.9 client and Ubuntu server both running Samba rsync:

rsync -av -e ssh /etc/services example.com:/tmp/services

The above command creates a mirror of the local file /etc/services in a remote file called /tmp/services. The outcome is exactly the same as if I had run "scp /etc/services example.com:/tmp/services"

If you disagree, please state what operating systems you're using and copy/paste the output of the following commands on each side:

  uname -a
  rsync -V
  openrsync -V
I get

  $ rsync -V
  rsync  version 3.4.3  protocol version 32
  (snipped)

  $ openrsync -V
  openrsync 0.1 (protocol version 27)
Then please run the commands I ran above, in particular

openrsync --rsync-path=openrsync -av -e ssh /etc/services example.com:/tmp/services

And then type "file /tmp/services" on the remote server.


Was there already a /tmp/services directory on the dest?

One of the biggest points of confusion with rsync is how directories and trailing slashes are handled.


I hear that a lot, but I familiarized myself with it once and ever since it makes a lot of sense to me.

Source ending in “/“: You want what’s inside. Source not ending in “/“: You want the thing (i.e. directory itself). For the destination, it does not matter whether it ends in “/“ or not, but for consistency I like adding a “/“ anyway (I want to put thing inside the directory).


Yes, the nice thing about dest having a trailing "/" is that if it exists and is NOT a directory, you are alerted right away.


It's a big source of confusion with cp. One of the UI reasons to use rsync (for mundane non-remote copying) is that it doesn't do different things based on what's present on the target.


> Was there already a /tmp/services directory on the dest?

No. And just to make sure, I ran a quick 'rm -rf /tmp/services' on the remote host, then re-ran openrsync on the client. Same result. This is OpenBSD 7.9 on both sides.

And I 100% agree about trailing slashes.


If you use a trailing slash on the source it copies from the directory, if you omit the trailing slash it copies the directory itself. AFAIK this is pretty standard across POSIX tools


It's not, for example cp -R doesn't change behavior on the basis of a trailing slash on directory names.


Indeed. This is one of the differences between the Unix and the MS/PC/DR-DOS command-line world. In the latter, recognizing empty final pathname components actually did become a way of differentiating such situations. I wrote a set of DOS and OS/2 tools in the 1990s, including COPY and MOVE commands, that had this very behaviour. I wasn't alone.


I was implementing something recently and stumbled across that cp difference. ugh.

the trailing slash is pretty convenient.


that's not a cp difference, cp is the granddaddy here

I think trailing / could be a nice way to indicate some meaningful difference, but since autocomplete always sticks it in, just feels like a bad idea to me. I might like it if directory names always had to have a trailing /, but I am less motivated by "convenience of common cases" and much more by "absolute precision/specificity/unambiguity" belt and suspenders.

(kind of unrelated but along the same lines, I toy with the idea of getting rid of . and .. visible in the filesystem, and make them only part of the syntax of paths. then you could have unambiguous multiple links to a directory: ".. is where you came from" and .. in the root is still the root, so chroot works too)


I think . and .. are useful. there's also perforce's ... which I find interesting (for example foo/... means everything below directory "foo")


> I would expect openrsync to create a remote file /tmp/services, but instead it creates /tmp/services/services.

As someone who has also suffered uncountable years of abuse from rsync, I understand the impulse, but I think it makes a lot more sense (and is a safer default) to create a second ”services”.

If we have a chance to change rsync defaults to something less insane and save future generations from this mess I think we should.


We don't, since we're not implementing a UI from scratch, we're matching something else.

Of the two possible worlds where in one this reimplementation matches what some see as annoyances in the interface or in another they mostly match the interface except for a few cases where the purposefully diverge (for no good technical reason), IMO the latter is far worse and causes more enexpected behavior.

At most, add a special flag to opt into different default behavior so nobody is surprised by running the same command on different systems and getting different behavior.


To be absolutely clear, since on reading this later it may come across as me masquerading as part of the OpenBSD project, I am not affiliated with them. My "We don't" was in response to "If we have a chance to change rsync defaults" which we, as the general public and users (and very likely also any reimplementors) don't have that chance, because rsync has a solid UI that people and tools have integrated for over a decade, and that's not something you can just change.


you responded to a comment that states "we should", your comment is a clear response to that. at least i understood it as intended.


Gandi was so great, once. No upselling, whois privacy by default before it was normal, good prices. I had a domain with them 25 years ago so I was a longtime customer, but never again.

Good writeup. I only used Gandi as a domain registrar so I was only familiar with the insane cost increases. What a terrible company:

> Gandi now informed them that their email would be suspended unless they paid extra, effectively retroactively changing the terms of a service already paid for.


I would also love to hear specific opinions about VeraCrypt because I need to get some Windows users to encrypt some of their seldom-used sensitive files, like HR for example.

They can't use age or any other "right answer" tools. I'm talking about people who don't know their own username, people who don't know that their Windows password is the one they use to log into Windows. "Is that for my email?" Just getting them to use a password manager is like arm wrestling an aligator. If VeraCrypt isn't the best option for them, then what is?


What’s the use case for encrypting the files?

Generally I’d say this is what Sharepoint or Box or a more workflow-specific platform is for. You generally don’t want sensitive data living on individual people’s workstations in an enterprise context, you want it somewhere that you can enforce security settings.


I recently started using Thunderbird for work which uses O365 (horrific service) for mail. I've found that 2FA with O365 to be totally unreliable no matter the client, even using the iOS app.

Does anyone use Thunderbird with Gmail and 2FA, and does it work correctly 100% of the time there?


Watching with a big public group of people you mostly don't know but maybe should is a special experience. This may depend on region, but in the US there used to be frequent midnight openings for superfans like myself. People dress up in costumes, local shops hand out prizes and it's an event. Saw Phantom Menace this way, LOTR, Watchmen, and maybe others, but I haven't seen a midnight opening offered in years. Maybe the theater managers are swimming in the pool on the roof.


In San Francisco, DNA Lounge has an annual event where they decorate the whole place as Cyberdelia. I never miss it if I can help.

A couple years ago my friend and I dressed as FBI agents. It was great fun.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: