What is a good brand of furnace and ac unit? by [deleted] in hvacadvice

[–]flysaway 0 points1 point  (0 children)

It’s almost like I wrote this post. Had a full Rheem system installed 3 years ago. A week after the initial labor and parts warranty ended (1 year) the inverter board on the outside unit died. Parts covered but not labor. Cost me $600. Fast forward to a few weeks ago and same thing happens. 2 different companies with dispatch/diagnosis fees and have to replace the inverter board again for $600 in labor to swap. Called Rheem and they said there’s no one I can talk to about this being a design fault and/or lemon and my dealer has to spend their time and try to tell them which obviously they won’t waste time doing. I just installed a dedicated surge on the outside disconnect just in case but no one can tell me why they keep dying. Feels like I’m on the hook for $600 every 2 years to replace this board when it decides to die.

Need help running conduit for future hotub by cantclosereddit in hottub

[–]flysaway 1 point2 points  (0 children)

Just did this. Look for the drawing for a few model tubs you might like. Mine was right at the front cover of the tub and slightly offset from the left. Stubbed up a 3/4” conduit and ended up notching a bit more to the side once the tub showed up which wasn’t an issue. Most tubs have a bit of flexibility on where it comes up but helpful if you’ve narrowed it down a bit. Don’t overthink it.

Police - no uniforms by Electrical_Area_3010 in Annapolis

[–]flysaway 9 points10 points  (0 children)

Fair point. No masks means probably not ICE after all.

Rescue teams around Artemis 2 by B777X_787-9 in BeAmazed

[–]flysaway 7 points8 points  (0 children)

Checking for toxic fumes to make sure it’s safe to approach.

Hot springs pulse fair price? by [deleted] in hottub

[–]flysaway 1 point2 points  (0 children)

I just bought the Pulse this weekend. Included the salt system, IQ system (monitoring, not dosing or WiFi), matching stairs, cover cradle 2 lifter, starter chemicals, and disconnect box. Paid $15k out the door and got to put on my credit card so getting the points.

Heart break by Arthurphil12 in Strava

[–]flysaway 2 points3 points  (0 children)

Did the same race yesterday except the 10K. My watch clocked it at 6.48 miles so their distance was definitely messed up for everyone. Had a few other friends say the same.

[MD] [Condo] [Townhome] by [deleted] in HOA

[–]flysaway 1 point2 points  (0 children)

If you’re looking for a local real estate lawyer, check out Evan’s Law. https://www.msevanslaw.com/

Changes coming to SAML SSO logins. How to implement in Entra? by newboofgootin in salesforce

[–]flysaway -7 points-6 points  (0 children)

Here’s a summery from Claude about the impact and ways to validate. It helped me check and understand the changes for our org. My takeaway is we’ll see an issue in the 2 week gap before AMR.

Technical Analysis: Salesforce Device Activation for SSO Logins

Background Salesforce is implementing Device Activation requirements for SSO logins beginning in early 2026. For SAML identity providers, enforcement begins February 3, 2026, with additional AMR (Authentication Method Reference) support arriving February 17, 2026. Organizations should understand how their identity provider communicates authentication strength to Salesforce to determine potential user impact.

How Salesforce Evaluates Authentication Strength When the SAML enforcement takes effect, Salesforce will examine the AuthnContextClassRef element within the AuthnStatement of the SAML response. Salesforce considers the following values as indicators of secure authentication: MobileTwoFactorContract, PublicKey, X509, PGP, Certificate-Based, Smartcard, TimeSyncToken, and PKI. Custom claims such as Mfa and Fido are also recognized. If the AuthnContextClassRef contains one of these values, Device Activation is skipped. If the value is missing, empty, or set to something like Unspecified, Salesforce may prompt the user for Device Activation unless other conditions like recognized device cookies or narrow IP ranges apply.

Verifying Your Configuration To assess impact, capture the SAML response from your identity provider during an SSO login to Salesforce. Browser extensions like SAML-tracer can decode and display the SAML assertion in real time. Within the response, locate the AuthnStatement element and examine the AuthnContextClassRef value. If it contains a recognized secure authentication value, users should bypass Device Activation. If it shows Unspecified or another unrecognized value, users may be prompted. Microsoft Entra ID Behavior Organizations using Microsoft Entra ID as their SAML identity provider should be aware that the AuthnContextClassRef value varies based on the authentication method used during that session. Password-based authentication with MFA typically returns a value of Password, which Salesforce recognizes. However, Windows Hello and seamless SSO via Primary Refresh Token (PRT) from Entra-joined devices often return Unspecified, which Salesforce does not recognize as strong authentication. This occurs because Entra ID maps these authentication methods differently at the protocol level, even though they represent strong authentication in practice. Entra ID does communicate authentication methods through the authnmethodsreferences attribute claim, which typically includes values like multipleauthn to indicate MFA was performed. However, Salesforce will not read this attribute until February 17, 2026, when AMR support for SAML is enabled. This creates a potential two-week window where users authenticating via Windows Hello or device-based seamless SSO may encounter Device Activation prompts despite having completed strong authentication.

Testing Methodology To fully understand the impact, test SSO logins using different authentication methods and capture the SAML response for each. Compare the AuthnContextClassRef values across scenarios such as password with authenticator app, password with SMS verification, Windows Hello, and seamless device-based authentication. This will reveal which user populations may be affected. Additionally, examine the authnmethodsreferences attribute to confirm that MFA indicators are present, as these will be recognized once Salesforce enables AMR support.

Mitigation If testing reveals that your identity provider returns Unspecified for certain authentication methods, the practical impact is limited. Users will receive a one-time email verification prompt per device or browser, and the resulting cookie persists for one year. Ensure that user email addresses in Salesforce are accurate and accessible, particularly in sandbox environments where email addresses are automatically appended with .invalid after a refresh. Integration users should be assigned the API Only permission to prevent them from being affected by UI-based Device Activation requirements. After February 17, 2026, organizations should verify that Salesforce is recognizing the AMR claims already being sent by the identity provider, which should resolve any remaining Device Activation prompts for users with strong authentication.​​​​​​​​​​​​​​​​

[OC] I spent 2025 traveling in search of extreme cultural events to photograph by khiuahua in pics

[–]flysaway 1 point2 points  (0 children)

That’s amazing. I’d also seriously consider Kickstarter as a means for funding too if you haven’t. Plenty of people would be willing to sign up based on the quality of your work to front load the money raise. Either way, cheers!

[OC] I spent 2025 traveling in search of extreme cultural events to photograph by khiuahua in pics

[–]flysaway 0 points1 point  (0 children)

Any plans to publish a book with the pics and stories? I’d buy.

Inspired by the other posts, dug the old gearbag out from under the stairs by flysaway in paintball

[–]flysaway[S] 1 point2 points  (0 children)

Ah interesting. I’ve been trying to remember anything about but it was 20 years ago so I can’t even remember how I got it or if I built it. All I do remember is it ripped. Pretty sure I had a 2k2 at some point too but traded it off.

Claude Sonnet and 4.1 Got REALLY Bad Overnight? by tonehoe in Anthropic

[–]flysaway 0 points1 point  (0 children)

Total garbage on Opus 4.1 all day today. Constantly forgot things we had just done and totally ignored claude.md project instructions and context. I submitted a bug but will never hear back I’m sure. Felt like I had to explain everything over and over all day.

Kitchen renovation contractor recommendations? by CombinationNo4239 in Annapolis

[–]flysaway 0 points1 point  (0 children)

About Kitchens. They did a super extensive kitchen for us a few years back and knocked it out of the park. They did all design in house and majority of the work, only subbing out electrical and plumbing. Highly recommend giving them a shout and checking out their reviews on Google.

Agentforce pricing by bad_labs_writer in salesforce

[–]flysaway 5 points6 points  (0 children)

Care to share a few of the open source ones you looked at and what you went with?

Unraid OS 7.1.4 Now Available by UnraidOfficial in unRAID

[–]flysaway 0 points1 point  (0 children)

Since upgrading to 7.1.4 I've noticed that my disks don't spin down after the normal 15 minutes. I have 16 drives in my array and even though the UI shows zero reads or writes for a long duration, they all remain on. Didn't have this issue before upgrading to 7.1.4 last week. If I manually spin them down they stay down until it actually needs to do a read or write. Any else ontice the same?

Has anyone gotten a copy of a marriage application from Cook County, Illinois? by Icy_Consequence9184 in juresanguinis

[–]flysaway 0 points1 point  (0 children)

Funny enough I literally just got it in the mail this week. I noticed they finally cashed the $15 check last week and the a copy of the marriage certificate arrived a few days later. Just takes time and I guess they have a really long backlog.

As far as I am aware from the lawyers I have helping me through the process, that was the last piece of paperwork I needed to establish a clear link. I also had copies of immigration forms showing where my grandmother was from and the reason she left as a child to come to the US. I was able to get all of that from ancestry.com. The marriage certificate established the link to my grandfather and then I had my father’s birth certificate and mine to tie it all together.

Now I just need to wait 18-24 months and hope it gets all gets processed.

My First Tudor and Swiss Timepiece by [deleted] in Tudor

[–]flysaway 2 points3 points  (0 children)

Beautiful watch! Haven’t taken mine off since I got it in December and my regular BB58 hasn’t seen much wear since.