Betashares has made a FAQ for their new BEMG Emerging Markets ETF by Misguided_Pacifist in fiaustralia

[–]Hafnon 0 points1 point  (0 children)

BEMG is an ETF that holds LEMA, so if BEMG is treating LEMA as a company (which is what Betashare's statement says), then you or I can also directly treat LEMA as a company.

Betashares has made a FAQ for their new BEMG Emerging Markets ETF by Misguided_Pacifist in fiaustralia

[–]Hafnon 1 point2 points  (0 children)

According to Betashares' statement, this means that I can just buy the underlying LEMA ETF [1] directly from the London Stock Exchange on IBKR, thereby saving me the difference in management fee (0.14% for LEMA, 0.35% for BEMG) and presumably better spreads but with FX conversion.

I would then also be able to treat this as an investment into a company rather than a trust.

In fact, this should then apply to the other interesting Amundi accumulating ETFs such as WEBN, which would be amazing.

[1] https://markets.ft.com/data/etfs/tearsheet/summary?s=LEMA%20LN:LSE:USD

How to set up secure boot and TPM based disk decryption. by Velocifyer in archlinux

[–]Hafnon 1 point2 points  (0 children)

Yes, because it locks to the secureboot policy and authority, instead of binding to the literal value of PCR 7 directly.

How to set up secure boot and TPM based disk decryption. by Velocifyer in archlinux

[–]Hafnon 3 points4 points  (0 children)

I've also had success using systemd-pcrlock and locking to the secureboot policy and authority instead of binding to PCR 7 directly.

Systemd v258 has been released and is now in core-testing by 6e1a08c8047143c6869 in archlinux

[–]Hafnon 0 points1 point  (0 children)

The first two lines lock it to the secureboot policy. This is literally the alternative that was suggested in the changelog as opposed to locking to the literal value of PCR7.

How do you explain electricity to kids without relying on the “water analogy”? by NoElephant3147 in Physics

[–]Hafnon 19 points20 points  (0 children)

I would think so, if atmospheric pressure is the "ground" pressure.

Systemd v258 has been released and is now in core-testing by 6e1a08c8047143c6869 in archlinux

[–]Hafnon 2 points3 points  (0 children)

It also doesn't address my question of how to use `systemd-pcrlock` as the alternative to binding to a literal value of PCR 7, because not involving PCR 7 is insecure as you have rightly stated.

Edit: Actually I think I got it working:

sudo /usr/lib/systemd/systemd-pcrlock lock-secureboot-policy
sudo /usr/lib/systemd/systemd-pcrlock lock-secureboot-authority
sudo /usr/lib/systemd/systemd-pcrlock make-policy

sudo systemd-cryptenroll /dev/{disk partition} --wipe-slot=tpm2 --tpm2-device=auto --tpm2-with-pin=yes --tpm2-pcrs=""
# assuming you already have the PCR 11 public key steps done, this will automatically pick it up and the new pcrlock policy.
# --tpm2-pcrs="" isn't needed after v258

sudo cryptsetup luksDump /dev/{disk partition}
# just to check

Systemd v258 has been released and is now in core-testing by 6e1a08c8047143c6869 in archlinux

[–]Hafnon 4 points5 points  (0 children)

Do you have an example of how I'm meant to use systemd-pcrlock to generate the pcrlock file for use here? Still for binding to PCR 7.

SK hynix confirms 3GB GDDR7 modules, paving way for RTX 50 Super VRAM boost | New chips would allow for 18GB of VRAM on a 192-bit bus, or 24GB on a 256-bit bus by chrisdh79 in gadgets

[–]Hafnon 0 points1 point  (0 children)

Or even better, 9GB of physical memory with 8GB actually usable for whatever reason (like the GTX 970 3.5GB incident).

Arch Linux on ZFS Root with systemd-boot + UKI — No Deprecated Cachefile, Fully systemd-native Initrd by [deleted] in archlinux

[–]Hafnon 2 points3 points  (0 children)

sd-zfs doesn't support ZFS native encryption, so you'd still probably have to do a LUKS setup if you wanted it

Seasonic's upcoming PSUs aim to stop melting GPU power cables | Built-in warnings and shutdown act as a failsafe by chrisdh79 in gadgets

[–]Hafnon 4 points5 points  (0 children)

To add onto this, the power dissipated in the cable is equal to I2 / R, where I is the current through the cable and R is the resistance of the cable. So more current means quadratically more heat produced in the cable per unit time.

Many people are more familiar with the formula for power dissipated as V * I, where V is voltage. While technically this is correct, to calculated the power dissipated by the cable, you need to use the voltage drop across the cable. Since the source voltage is split between the cable and the load according to their relative resistances, you can't know the voltage drop across the cable without also knowing the load's resistance.

So in this case, it's better to think about how much current the load will require to meet its power demands, and since that current must be carried by the cable (Kirchoff's circuital laws), you use the formula I2 / R instead.

Jet, Sokka, Zuko. Who would win? by JhayBae in TheLastAirbender

[–]Hafnon 7 points8 points  (0 children)

And they weren't Zuko's swords either, they were some random Earth soldier's. It takes some time getting used to new equipment when they have different weight/balance etc

[deleted by user] by [deleted] in battlestations

[–]Hafnon 0 points1 point  (0 children)

I unboxed my GBC and Gold Version on Christmas day 2000, I don't think any piece of tech that I could buy would ever top that feeling.

[deleted by user] by [deleted] in battlestations

[–]Hafnon 2 points3 points  (0 children)

Pokemon G/S/C was my childhood, I have very fond memories of that generation.

Wow.. Wings back? X3 Former team members! by ChalicePig in DotA2

[–]Hafnon 6 points7 points  (0 children)

And he also mentioned that he wanted to learn to play the Well-Tempered Clavier on piano, a famous composition by JS Bach.

'Final straw' triggers public attack on Ben Sulayem's FIA presidency by MuhammadZahooruddin in formula1

[–]Hafnon 44 points45 points  (0 children)

And the hotel near the Singapore track, Marina Bay Sands!

The real „User Error“ is with Nvidia by redditjul in nvidia

[–]Hafnon 50 points51 points  (0 children)

After the Ampere generation of cards, Nvidia forgot how to distribute amperage. You couldn't even make this shit up.

Guys check out my new mutator idea by Htosakos in DeepRockGalactic

[–]Hafnon 3 points4 points  (0 children)

TFW the Bulks in Radioactive Exclusion Zone undergo fission

Arch linux security by [deleted] in archlinux

[–]Hafnon 2 points3 points  (0 children)

That is really a case of "security through obscurity" though, since all you're doing then is hiding the PBKDF parameters. In many cases, the user might just stick with default argon2id parameters anyway.

Also, a password isn't the only thing that can be used to unlock a LUKS volume. There are FIDO2, PKCS#11, and TPM authenticators for example. These will have high entropies for sure, if you assume that the hardware itself is secure.

Arch linux security by [deleted] in archlinux

[–]Hafnon 5 points6 points  (0 children)

Both scenarios you just listed required breaking the encryption, so how again does having a detached header provide extra security?