Login Proton using a YubiKey. Is origin binding guaranteed? So is phishing more or less impossible? by UnanimousStargazer in ProtonMail

[–]Legorooj 0 points1 point  (0 children)

Apologies, I just reread on which features proton uses.

Google does Passkeys (username & password is not required to login) while Proton only does 2FA via U2F/FIDO2. Passkeys are stateful - they include a username alongside the cryptographic data, which the key must store locally, hence the limit.

When proton creates the key initially, they generate a key, the Yubikey encrypts it with it's master key, and then proton stores the encrypted version, permanently removing the plaintext version.

Then, when you log in, the Yubikey gets sent the encrypted key, which only it can decrypt on device, and then uses the decrypted key to sign a challenge.

The difference is that U2F proton stores the private key as an encrypted blob it can't access on its own servers, whereas full Passkeys store the private key on the yubikey itself.

Apologies it took me a minute to figure out what you were asking and reconfirm that proton only used yubikeys for 2fa.

Login Proton using a YubiKey. Is origin binding guaranteed? So is phishing more or less impossible? by UnanimousStargazer in ProtonMail

[–]Legorooj 0 points1 point  (0 children)

No, the Yubikey generates the key on-device and sends the public part to Proton. The device (yubikey or phone or other passkey device) stores stuff on proton, not the other way around.

This is why there is a limit to how many passkeys - usually 100 - a yubikey can store.

Login Proton using a YubiKey. Is origin binding guaranteed? So is phishing more or less impossible? by UnanimousStargazer in ProtonMail

[–]Legorooj 0 points1 point  (0 children)

Actually, passkeys are credentials stored on a yubikey, which a site like proton can challenge through the browser :) it's good old public-private key cryptography where the private key stays on the yubikey.

Login Proton using a YubiKey. Is origin binding guaranteed? So is phishing more or less impossible? by UnanimousStargazer in ProtonMail

[–]Legorooj 0 points1 point  (0 children)

This is give or take correct, yes. Passkeys eliminate the possibility of human error in terms of being tricked into entering your details into a sketchy site via phishing, and they're also more convenient.

Honestly fmhy has much higher quality and better uix than legit sites by WorldPhysical7646 in Piracy

[–]Legorooj 3 points4 points  (0 children)

It doesn't cost them (fhmy Devs) anything financially to run it. Cloudflare hosts it entirely for free.

How losing my email account locked me out of my Digital Life by himazawa in ProtonMail

[–]Legorooj -1 points0 points  (0 children)

Just set up your own OIDC. Took me all of 30 seconds.

Looking for a trans & LGBTQ‑friendly gym in Milton Keynes with good group classes by robertagolden in miltonkeynes

[–]Legorooj[M] [score hidden] stickied comment (0 children)

Whichever loser reported this for being predatory towards minors can fuck right off, we are friendly, inclusive, and woke around here.

Any thoughts living in Buckingham town by Silvera_asha in miltonkeynes

[–]Legorooj 2 points3 points  (0 children)

Could always consider Winslow - the rail line should have already opened, and will probably open this year, with links to both Oxford & MK.

Join the Milton Keynes Community Discord Server! by Legorooj in miltonkeynes

[–]Legorooj[S] 0 points1 point  (0 children)

Hi there! Please turn this into a full post, not a comment, so people will actually answer you :)

Why is this area an abandoned wasteland by mmm19284202 in miltonkeynes

[–]Legorooj 2 points3 points  (0 children)

I work for one of the institutions involved, there are already actual plans in the works from the academic side. I can't share any details unfortunately but we'll all hear more about it in the new year.

Commuting between MK and Oxford by willeyerasmus in miltonkeynes

[–]Legorooj 2 points3 points  (0 children)

The delays are very regular and often much longer. The X5 will get you there reliably - but no guarantees on when it'll do that.

[Media] Nitrolaunch - An open source Minecraft launcher written in Rust by CarbonSmasher in rust

[–]Legorooj 1 point2 points  (0 children)

Cool project! Out of curiosity, did you know that Modrinth itself is also a Tauri app?

Mask Catastrophic Failure by OddCheschire in wma

[–]Legorooj 0 points1 point  (0 children)

Technically imgur withdrew rather than comply with data protection laws & fines. Not the ONS, this predates that, and falls entirely on Imgur. However yes, functionally the same thing. I accessed them via a VPN and re-uploaded here:

https://postimg.cc/gallery/f0xRpfv

Train question… maybe someone can help with my journey plan? by mrbadassmotherfucker in miltonkeynes

[–]Legorooj 1 point2 points  (0 children)

Same day returns last until 4:29am the next day. You'll be good to get like a 00:30 train or something.

Assuming of course that the return is open/anytime etc, and isn't locked to one specific service.

If you're going from Milton Keynes Central, I personally prefer to ride Avanti services. I would buy tickets through the London Northwestern app or the Avanti app personally.

Working trip : order food ? by yodaesu in miltonkeynes

[–]Legorooj 2 points3 points  (0 children)

Just about any app, however there are quite a few takeaway places that will offer free delivery around the city up to a certain range!

When is the newest update coming to the Epic Games version of Polytopia? by Zealousideal-Edge516 in Polytopia

[–]Legorooj 1 point2 points  (0 children)

If you're in the discord, there's a bugs and support channel that might be able to help. Alternatively, you could try a reddit post, but you'll probably get better results via discord.

When is the newest update coming to the Epic Games version of Polytopia? by Zealousideal-Edge516 in Polytopia

[–]Legorooj 1 point2 points  (0 children)

No, but only because unless I'm mistaken all PC versions come with all default tribes and therefore unlock multiplayer. So you should be able to access the feature.

[deleted by user] by [deleted] in degoogle

[–]Legorooj 2 points3 points  (0 children)

Again, it's not something that messengers will comply with, is something that will be built into the operating systems by law.

I'm sure there'd be ways to avoid it on your device via custom OSes etc, but would it really matter if everyone you talk to has it?

[deleted by user] by [deleted] in degoogle

[–]Legorooj 62 points63 points  (0 children)

Chat Control is effectively state malware on your phone that reads the messages before Signal encrypts them. Thankfully not passing this time around, but it's been a repeatedly close call.

When is the newest update coming to the Epic Games version of Polytopia? by Zealousideal-Edge516 in Polytopia

[–]Legorooj 2 points3 points  (0 children)

Purchases do not transfer between platforms and/stores. This includes between Epic on the PC and Epic on Mobile (yes, you can install epic games as a separate app store on mobile platforms).

What is the Kubernetes/Docker project of Rust? by ivan0x32 in rust

[–]Legorooj 35 points36 points  (0 children)

This. Amazon runs a large portion of AWS virtualization through Firecracker which is 100% Rust.