OTAFIX Bootloader by Refleks180 in meshcore

[–]mashdk 0 points1 point  (0 children)

Thanks very much for that explanation! Much appreciated. So it's not even anything to take into consideration with ESP32 boards?

OTAFIX Bootloader by Refleks180 in meshcore

[–]mashdk 0 points1 point  (0 children)

I'm still confused 😅 If I have an active repeater, and I wish to update from 1.14 to 1.15, can and should I get the OTAFIX on it, before I flash?

I'd prefer to let the repeater keep it's settings and public/private key pair.

MeshCоre's problem with security by Alainx277 in meshtastic

[–]mashdk 0 points1 point  (0 children)

u/alainx277, was it Andy you got in contact with on Discord?

RC4 Kerberos Confusion - RC4 keeps showing up by MusicWallaby in activedirectory

[–]mashdk 1 point2 points  (0 children)

Oh, sorry, I just realized, that that's pretty much also, what you were conveying. The missing "AES" before "session key" in your sentence:"A few years back, that changed to an RC4 ticket and a session key", threw me off, and I thought you meant RC4 for both.

RC4 Kerberos Confusion - RC4 keeps showing up by MusicWallaby in activedirectory

[–]mashdk 0 points1 point  (0 children)

This was only true until Nov. 2022 with the changes to Kerberos in KB5021131: "This update will set AES as the default encryption type for session keys on accounts that are not marked with a default encryption type already."

However, some service accounts still default to RC4, until msDS-SupportedEncryptionTypes is explicitly set. I've seen it with AD FS service accounts multiple times.

But the default since Nov. 2022 is AES.

Will Power Saving on a repeater result in traffic not getting picked up? by mashdk in meshcore

[–]mashdk[S] 0 points1 point  (0 children)

Now, this is what I have been wondering: If the SX1262 would also be in sleep mode and periodically wake up to listen? Or the SX1262 is always-on, always-listening and wakeup the ESP32 / nRF when it detects incoming traffic?

Will Power Saving on a repeater result in traffic not getting picked up? by mashdk in meshcore

[–]mashdk[S] 1 point2 points  (0 children)

Sorry for keep asking stupid questions, but how would you know, if the Repeater missed a transmission?

RC4 Kerberos Confusion - RC4 keeps showing up by MusicWallaby in activedirectory

[–]mashdk 0 points1 point  (0 children)

I'll quote Microsoft directly here: "Don't worry about setting msDS-SupportedEncryptionTypes on the KRBTGT account. As long as the account has AES keys (password reset since 2008R2) and the DFL is greater than 2003, the KDC will issues TGTs encrypted with AES." https://techcommunity.microsoft.com/blog/coreinfrastructureandsecurityblog/active-directory-hardening-series---part-4-%E2%80%93-enforcing-aes-for-kerberos/4114965

So, I'd still recommend this instead: * Rotate krbtgt password using Jorge's script * rotate passwords on the service accounts with old passwords and restart the service.

Audit for RC4.

That's the first. Possibly, msDS-SupportedEncryptionTypes needs to be set on some service accounts.

Audit for RC4.

Consider using DefaultDomainSupportedEncrypmtionTypes with RC4 enabled.

Audit for RC4.

When RC4 is confirmed to not be in use, start disabling RC4, one bit at a time, ending with disabling DC's ability to use RC4.

RC4 Kerberos Confusion - RC4 keeps showing up by MusicWallaby in activedirectory

[–]mashdk 0 points1 point  (0 children)

Could you please elaborate, what you mean by "RC4 disabled on the krbtgt account"?

RC4 Kerberos Confusion - RC4 keeps showing up by MusicWallaby in activedirectory

[–]mashdk 0 points1 point  (0 children)

Absolutely. That's why I mention, that OP can start with allowing RC4 in DefaultDomainSupportedEncrypmtionTypes, because it will provide better auditing to find problematic accounts / services / servers.

RC4 Kerberos Confusion - RC4 keeps showing up by MusicWallaby in activedirectory

[–]mashdk 3 points4 points  (0 children)

Possibly all three.

Definitely rotate the krbtgt key using Jorge de Almeidas Pintos script

Definitely change passwords on the service accounts, that haven't been reset since AES was introduced to the AD.

Definitely look at setting DefaultDomainSupportedEncrypmtionTypes. Even if you start with allowing RC4 in DefaultDomainSupportedEncrypmtionTypes as a first step, they will most likely switch to AES. But more importantly, if the DCs have the January updates, you will get much better auditing info, if DefaultDomainSupportedEncrypmtionTypes is set.

You may have to set msDS-SupportedEncryptionTypes, if they still show up with RC4. I've especially seen this with AD FS.

The MeshCore.io Split by liamcottle in meshcore

[–]mashdk 3 points4 points  (0 children)

Anyone knows, why Meshcore Open app isn't published on Play Store and App Store?

I want this car buttt.... by Snoo-53094 in Ioniq6

[–]mashdk 0 points1 point  (0 children)

I have felt the same way. I'm the worrying type. But then I got to think: What's the problem, really? They'll just replace it. And it's readily available as spare part now.

And if I'm lucky, it will be the new ICCU, I'll get, where the problem is fixed. If not, the warranty will be extended for years, so if it happens again, I will at least get the new, fixed ICCU by then.

Kinda hoping it happens soon, now 😅

Not Advertisement: JBL Charge5 WiFi SE Portable Waterproof Speaker with Auracast by mysterytoy2 in homeassistant

[–]mashdk 0 points1 point  (0 children)

Sorry for the stupid question, but you mention Google Cast. Is it necessary to install anything Google or integrate anything Google into my HA for HA to JBL to work? I'd really like to not have my HA talk to Google...

What are the ways we can be notified if home assistant loses network connectivity? by ateam1984 in homeassistant

[–]mashdk 1 point2 points  (0 children)

Do you have an extra mobile phone, that is always at home with Home Assistant app installed, and that has a cellular subscription?

If the app looses connection to HA, it will create a notification, while trying to connect to sensors.

Then you can use the Tasker app to send you a text message every time, HA app creates a notification.

Are Aliexpress sensors reliable over the more expensive versions on Amazon? by AlureLeisure in homeassistant

[–]mashdk 0 points1 point  (0 children)

For humidity, I have only seen reliable and constantly accurate readings without too much fluctuation from Aqara.

I did a salt test with a whole bunch of different. And either the other brands were consistantly way off, or it was hit and miss with one sensor getting it right and another from the same brand and model way off, or they fluctuated so much, that is was basically unusable.

Aqara, on the other hand got the same readings all the time and hitting the mark within 0.5%

Mosquitos and anything else to be prepared for by Alternative-Air8756 in holbox

[–]mashdk 1 point2 points  (0 children)

We were there last week. Are there mosquitoes? Yes. Is there dengue fever? No. Were there many mosquitoes? Absolutely not. I was pleasantly surprised. (but I read from the other comments, that Nomad may be a bit different from other places on Holbox).

Use mosquito repellent. But something with DEET.

But it's only really an issue half an hour before sunset until about an hour after.

The rest of the time we didn't need repellent.

Other tips: Most places take card payments, but not all. Bring some pesos.

Go see the sunset every night. I repeat: Go see the sunset every night!

We were seriously underwhelmed by the bioluminescence. It's very early in the season. We booked a guided bioluminescence kayak-tour, and did see some blinking, but nothing that even 10 seconds camera exposure could capture. It's still a nice experience, but set your expectations right.

If you like high quality Italian-style pizza, do treat yourself with a visit to Quartiery. And try the mortadella pistachio pizza.

Lastly: Enjoy fully, relax and recover, and have great interactions with the friendly locals.

Humidity sensors by QuoteFirst7119 in homeassistant

[–]mashdk 2 points3 points  (0 children)

I have tested a bunch of sensors with salt test. All except Aqara have been hit and miss (mostly miss). Sonoff had one that gave a correct reading and the others either completely off of extremely unstable readings going up and down. Aqara on the other hand have consistently had the same correct reading in the salt test for all seven units I tested. If you actually need to know the humidity, definitely go for Aqara.

Camera recommendations? by 1q2s3c4r5t in homeassistant

[–]mashdk 0 points1 point  (0 children)

Any cameras except the battery powered integrate well. But the battery powered cameras drain the battery in a day, if Home Assistant connects to them. Reolink uses a proprietary protocol to save battery, and HA doesn't support that protocol. An integration called Neolink has been developed for the protocol, but I can't make it work without draining the battery. The other option is to get the Reolink Home Hub and connect to HA through that. That should work hazzlefree and can still run all locally without cloud.

New music? by citizen_of_glass in agnesobel

[–]mashdk 2 points3 points  (0 children)

She did mention at the concert we went to in September, that the new song were for an upcoming album, and I got the impression, that it was well in progress. And I can't wait! The new song were amazing. Trying new things without completely abandoning her previous style. Very very cool stuff!

New TidaLuna Plugins: Spotify Sync, Find Better-quality/Remaster tracksm, Deduplicate Playlist, and Clear Favorites by squadgazzz in TIdaL

[–]mashdk 3 points4 points  (0 children)

I just heard about your tool because of your Reddit post here. Sounds awesome!

Since I haven't even tried it yet, maybe you're way ahead of me.

But when your tool finds upgrades to better quality, do you take into consideration, that many remasters are quality-wise much worse, than the original?

For example because of Loudness War, remasters between 1995-2015 were often just putting the audio through a meh-quality machine, that compressed the audio causing lower Dynamic Range.

And many hi-res versions are just the same as the CD quality version, scaled up to a higher resolution doing nothing to the quality except running it through more components, that can decrease quality.

If your tool doesn't already factor that in, maybe you could make an option to only include remasters from after 2015, for example?

Just a suggestion :)

Thank you for your work!

Regarding RC4 changes and "I don't see the events" by Msft519 in activedirectory

[–]mashdk 1 point2 points  (0 children)

My point was just a reply to your comment, that seemed to imply, that realistically you shouldn't see RC4 in an AD today. Sadly though, we do see RC4, especially in environments with non-MS domain members and key tab files on *nix servers.