
I mean, “america” (specifically USA) bad, but that user has no idea bitwarden encrypts the password before sending it to the server.

I mean, “america” (specifically USA) bad, but that user has no idea bitwarden encrypts the password before sending it to the server.

no, no that, thats gross. but they can go elsewhere.

Do those of you that despise smart glasses think you’ll have the same moral issues with optical implants?
yes.
What could be done to avoid the issues you have with the glasses when it comes to implants, if anything?
mostly nothing. it could be a solution if they could be easily verifiably made for anyone that these don’t have any wireless connections, or any kind of connection to a computer network. and that these have no capability of storing recordings. but this is not possible.
Do you intend to discriminate against people with augments if you live long enough to see them in widespread use?
Unfortunately, yes. just like I want to keep robots and surveillance cars out of my life, and my environment. but that is already not working out, as people are perfectly comfortable with their cars recording all their neighborhood.
It doesn’t require a reboot for updates the way KDE Discover would for example
it does not require that. turn that off in the system settings, and enjoy the consequences
the consequences:
(though occasionally I run into bugs if I don’t reboot)

and details: https://wiki.mozilla.org/SecurityEngineering/Certificate_Transparency
this sounds important:
This information has a 10 week expiration time. That is, if 10 weeks have passed since the information has been updated (typically by updating Firefox itself), the implementation will no longer enforce certificate transparency.
this also means, it can’t truly verify SCT’s that were issued since the last browser update?

it seems Firefox started doing the CT validation too, without needing to contact the CT log service: https://developer.mozilla.org/en-US/docs/Web/Security/Defenses/Certificate_Transparency#browser_requirements

apparently certs can have a cryptographic proof of having been included in the CT logs. but what do browsers do if the letsencrypt cert has no such proof?

if its not human readable, how will people know its the place they want to go to? I don’t think bookmarked onionsites is a particularly good idea

Actually the problem is that they are too widespread. if something happened, and they started creating fake certificates, for outside force or otherwise, they can’t just be blocked because literally half of the internet or more breaks. what’s worse, if browser vendors trued that, people would be downgrading their browser to the last version accepting it, and become exposed to publicly revealed security vulnerabilities. not all because its a bit complicated, but enough would do to have it cause an even greater problem.

It’s actually to prove that a web server belongs to (or is trusted by for delivering their content) a specific website.
qualified certificates go a step further, by proving that a web server belongs to a specific company or a real person. but that’s costly, because verification is inherently more difficult.

you don’t know how bitwarden works, do you?

which is still there if you are not using lets encrypt, because they can strongarm them to make a fake cert for your domain, and install a proxy repackaging HTTPS traffic with the fake certificate. all browsers trust the lets encrypt root certificate, so they won’t see anything suspicious.
the only thing there today to detect this (but not avoid) is certificate transparency logs. all modern certificates are required to be added to this log, for the CA to remain compliant. but browsers are not checking the logs, that would be a lot of additional traffic and how do they decide if a certificate was created maliciously? also, lets encrypt could afford being noncompliant, browser vendors can’t realistically just distrust their root certificate, many sites would become inaccessible.

But, can someone talk about this in a way I can wrap my head around why the divide seems so big?
there are too many people who don’t care about shit until they see results (good or not). like our greatest billionaires.

That ‘digital shit’ has about as much value as what you flush down the toilet, individually, but combined into representative market statistics it’s digital gold - predictive information about what will sell, how much of it will sell at what prices, where and when.
the advertising industry has left that behind many years ago. the question now is not what will sell, but how will they sell literally any garbage, how do they get you to buy that any garbage, and how do they make you actually want that any garbage above anything else. its mass manipulation from start to end, with the knowledge about everyone how to press their buttons.

100k lines? are you sure you couldn’t outsource more tasks to existing tools?

The ultimate goal is to get this 100% AI/LLM free, but for now the LLMs are still doing a lot of the heavy lifting of configuring the target devices to install the player.
why don’t you use ansible for that, or even just some bash script? you could generate it even if you want

in that case, meshtastic does not do routing. like a network switch or a wifi AP is not a router (except combined consumer devices but that’s an other thing)
though, doesn’t meshtastic have some kind of relayed operation? that would count as routing, I think.

totally different things. reticulum is routing, meshtastic is the transport. you don’t route anything without a transport

only until device attestation does not exist on the web. google has already tried to make it a thing, and the public backlash only caused them to continue development in chrome on android
would it? I doubt it. people eat up everything.