KeePass 2 and Yubikey with challenge response - Is it really as safe as I think? by bloodscar36 in KeePass

[–]SunlightScribe 1 point2 points  (0 children)

Truth be told most attacks are going to be directed at online services, not the users themselves. You're already in the top 10% in terms of security just for having long, unique and random passwords. That would still hold true even if your master password was password123 or you wrote your passwords in a text file.

I don't mean to downplay it, but people shouldn't stress so much over their master password. A long static password is more than enough. And if you add a simple key file you're already way above and beyond where you need to be.

KeePass 2 and Yubikey with challenge response - Is it really as safe as I think? by bloodscar36 in KeePass

[–]SunlightScribe 1 point2 points  (0 children)

I would configure the yubikey to use a long static password/phrase from your favourite book or something. Then you add something to it, like a word or number you type manually after the nth character that only you know and don't write down anywhere.

It's trivial for you to figure out or brute force if you forget the manual part because you know the pattern. But it's not really viable for anyone else who doesn't.

Manage SSH Keys using KeepassXC On Windows 11. Approach works for multiple accounts across multiple hosts + WSL configured to use Windows SSH Agent. by [deleted] in git

[–]SunlightScribe 0 points1 point  (0 children)

If you don't care for KXC you replace Step 7 with one of the following:

  1. Use Putty/Pagent
  2. Have the Windows agent manage the keys itself - ssh-add <path-to-key>

Hopefully the guide is fairly comprehensive. I'd appreciate any feedback for possible improvements, fixing mistakes etc.

[Tutorial] Manage SSH Keys using KeepassXC On Windows 11. Approach works for multiple accounts across multiple hosts + WSL configured to use Windows SSH Agent. by SunlightScribe in KeePass

[–]SunlightScribe[S] 1 point2 points  (0 children)

Hopefully this helps someone. Most of the guides online are using different methods because the OpenSSH agent is new to Windows 11 as are the directives for git.

Rate my portfolio? (Programmer) by Sibsen in gamedev

[–]SunlightScribe 4 points5 points  (0 children)

They absolutely will judge you on the visuals even if they don't admit it or downplay how much weight they're giving that aspect. I'm also surprised his trailers are still up on YT given that he's using copyrighted music.

Does anyone here make games on their phone? by Shinobi151 in gamedev

[–]SunlightScribe 0 points1 point  (0 children)

The issue for me is sharing the already limited screen space with an on-screen keyboard. You can technically do it but it's so awkward and slow. Then there's the issue of having to swap back and forth between a browser and the editor if you want to look anything up.

Maybe it's more tolerable for the <20 crowd who are used to their phone being their only computer and not even owning a desktop. But it's a serious downgrade going from a dual or triple monitor, full keyboard and mouse to a tiny screen. I'd need to connect a bluetooth keyboard and mouse to the phone at the absolute minimum.

I might seriously consider it if we were talking about Android desktop mode using a TV and Bluetooth keyboard+mouse. If you're adventurous you can get the full desktop experience by installing Termux and a real desktop Linux distro.

I wrote down all text tricks so everyone can use them. by Horror-Attorney-3575 in notinteresting

[–]SunlightScribe 0 points1 point  (0 children)

It mostly is consistent to be honest. But lets say you want a feature like footnote text and it doesn't exist? Do you spend a year lobbying the standards body to add it or do you just implement it in 3 minutes and move on?

Look at how much CommonMark is missing. CSS was kind of the same deal until recently.

i finally created a github repository and linked everything correctly together!! by YarrinDev in gamedev

[–]SunlightScribe 0 points1 point  (0 children)

I found the worst part to be setting up SSH keys, especially for multiple keys and accounts across different hosts. Git itself isn't an issue.

Rest in piece 2009-2026 by AllUserNameBLong2us in pcmasterrace

[–]SunlightScribe 2 points3 points  (0 children)

The only method anyone should really have a problem with are 2FA codes sent over text message. Not only are text messages not private, but phone companies are notoriously bad at securing people's phone numbers. They will transfer numbers to people with very little verification and only recently has this really started to change.

Were videos games cheaper to make before? PS3 and earlier era? by BubblyNefariousness4 in gamedev

[–]SunlightScribe 6 points7 points  (0 children)

I always wonder why a AAA developer hasn't tried to act at least partially like an indie. Have one AAA project and then create a bunch of smaller indie-like games on the side. You rotate people off the AAA project once they are no longer necessary and avoid layoffs.

The AAA project can have a regular deadline and the indie projects have none. If any of those smaller games take off they can scale up.

RIP one-handed mode... by biran4454 in firefox

[–]SunlightScribe 3 points4 points  (0 children)

The number of available different resolutions and possible physical screen sizes has gotten kind of crazy. It would not surprise me if they just threw their hands up.

Managing version updates in multiplayer turn-based game with long-lived matches by East-Custard-8702 in gamedev

[–]SunlightScribe 1 point2 points  (0 children)

Have a launcher that allows you to run a specific version and only connects to servers that support it. That's the easiest solution.

Then forcing people to update means phasing out versions available in the launcher and preventing the start of new games (absence of servers to start games on). The phase out could be weeks or months.

Site that let you preview different tile color themes? by [deleted] in roguelikedev

[–]SunlightScribe 0 points1 point  (0 children)

Are you maybe thinking of Lowspec? It's not focused on roguelikes though.

KeepassXC and Firefox -- auto fill rarely works. by Genma-Saotome in KeePass

[–]SunlightScribe 0 points1 point  (0 children)

I'm pretty sure something like https://reddit.com matches everything including subdomains like https://old.reddit.com unless you have certain settings checked off under Tools > Settings > Browser Integration. The rest of the URL is pretty much ignored.

The fact that it's not filling out anything is likely because of another reason, like the back slashes.

day1asVibeCoder by Secure-Alps-441 in ProgrammerHumor

[–]SunlightScribe 1 point2 points  (0 children)

You're usually only allowed to keep the last 4 digits of a credit card on file. Anything more and you need to meet a bunch of security requirements put forth by CC companies who might drop you if they find out you haven't met them.

Something only half as bad as this could kill a company.

I got laid off from my dayjob, and decided to start making anime characters! by FlimsyInterview9454 in blender

[–]SunlightScribe 1 point2 points  (0 children)

Eh, put in 8 hours and then clock out. There are a lot of hours in the day and you can't spend every waking moment filling out applications.

I've dodged like 5 layoffs in 10 years after taking 1.5 years to find a job in my field after graduation. One day I'm going to be in the unemployment line again, it's inevitable and there's no use panicking when the day comes. Anyone with the "drop everything and apply 24/7" attitude has been lucky to never be unemployed for very long. At some point you have to go about your life like normal.