thecookingsenpai

joined 11 months ago

This is why I love the Internet

[–] thecookingsenpai@lemmy.world 49 points 10 months ago (10 children)

Thank you Roku, a step forward towards self hosting and self managing of every service

[–] thecookingsenpai@lemmy.world 2 points 10 months ago

Maybe is because I am not native but I did not get it

Like, to me looks like a further reason to transition to a serverless authentication

 

cross-posted from: https://lemmy.world/post/10918621

Reason: wrong community

Work in Progress: Adding more details on the motivation

I have this proposal for ActivityPub

NOTE: This proposal is based on https://www.w3.org/TR/activitypub/#authorization and https://www.w3.org/wiki/SocialCG/ActivityPub/Authentication_Authorization consulted on 06 January 2024.

  • Considering that the entire section on safety considerations is presented as non-normative
  • Given that "at the time of standardisation there are no strongly agreed mechanisms for authentication. " as per the above reference
  • Assuming that the ultimate goal is to have a decentralised, persistent and verifiable identity.

Premise: The following proposal represents a radical and potentially disruptive change to the current ActivityPub specifications. In particular the following parts:

  • ActivityPub clients authenticate to a server using OAuth 2.0 bearer tokens.
  • Related OAuth considerations

It is also important to note that the following proposal can coexist with current OAuth authentication.

The proposed encryption algorithm (ED25519) can and should be updated in the event of a vulnerability or major upgrade.

Suggestion

I have no idea how to write a document like this correctly, and I am probably doing it wrong, but my only goal is to stimulate discussion.

The proposal is as follows.

ActivityPub clients authenticate against a server using ED25519 signatures In general, bearer tokens can be easily replaced by signatures in almost every aspect. Advantages:

  • Servers don't need to store anything other than a session token.
  • Authentication is decentralised and context independent
  • Your key is your identity: no server breach can expose your data
  • There are mature libraries like node-forge (for nodeJS and TS) and many others that allow easy implementation of authentication.

I have tried to think about possible downsides, but the goal of this post is to stimulate discussion, please keep it respectful, but of course criticism and additions are welcome!

[–] thecookingsenpai@lemmy.world 4 points 10 months ago

Thats so specific

[–] thecookingsenpai@lemmy.world 16 points 10 months ago

Tbh i never found an app that runs better on snap than on deb

Same goes for almost anything like snap

[–] thecookingsenpai@lemmy.world 2 points 10 months ago

That post tho

 

Out of frustration after hours digging and finding them, I want to share with anyone that needs them the working drivers for all the (ones I know) Goodix fingerprint drivers, usually found on Lenovo IdeaPad (like the IdeaPad 3 Slim) but also on other laptops.

The url contains all the info needed.

The debian packages have been mirrored from either Dell's repo and AUR backdigging.

It should be only for debian/ubuntu based distro but by extracting the .deb archives and copying the directory structure I am pretty sure they will work anywhere.

Anyway, issues and pull requests are more than welcome.

I did not find these anywhere else.

List of supported devices:

0.0.4

  • 27c6:538c
  • 27c6:533c
  • 27c6:530c
  • 27c6:5840

0.0.6

  • 27c6:550a

EDIT: Now the repo is also nice

[–] thecookingsenpai@lemmy.world 1 points 10 months ago

You would be surprised in finding out that the majority of blockchains out there aren't Quantum resistant, tho (elliptic curves being the reason mainly but I am not an expert)

[–] thecookingsenpai@lemmy.world 6 points 10 months ago (1 children)

No pale idea, i hope it goes well for the dev but i think he is ok if he takes it down

[–] thecookingsenpai@lemmy.world 20 points 10 months ago (2 children)

The lion, the witch and the audacity of this bitch

(in 4 bitch as a gender neutral way of saying whining child while doing a rhyme)

[–] thecookingsenpai@lemmy.world 14 points 10 months ago

I cant wait to see them sueing each one of the thousands forkers

[–] thecookingsenpai@lemmy.world 28 points 10 months ago

Just the usual whining from corps isnt it

[–] thecookingsenpai@lemmy.world 14 points 10 months ago (8 children)

There should be more education on the difference between "privacy being available if you look for it" VS "privacy being ensured since the beginning and forever no matter what"

Spoiler: the last one does not exists

 

cross-posted from: https://lemmy.world/post/10904853

cross-posted from: https://poptalk.scrubbles.tech/post/567593

Haier hits Home Assistant plugin dev with takedown notice

I'm not really big on "let's make a movement", but this independent dev has been hit with a cease-and-desist from making a FOSS Home Assistant addon for their Haier air conditioners.

Haier claims that they are losing out on millions of dollars due to this plugin which... lets you control their air conditions from home assistant. They haven't bothered to explain how that's possibly worth millions of dollars - they're just claiming it.

So of course they hit the Streisand button and are demanding that he takes it down. He of course is complying... in a couple of days. Maybe you see where this is going.

It would be an absolute shame if any of you just happened to create a fork, or clone the code, or mirror it in your own instance. An absolute shame.

Just so everyone here knows which repositories NOT to clone or fork, here are the two links:

and please, don't repost this anywhere, or share it in other communities, or anything like that. It's a shame that so many people already know and are making clones. I'm just letting you know so you don't do anything like telling others who may make their own copies.

(sidenote: Haier owns GE Appliance, so for our American folks it may affect you folks too)

view more: next ›