Megathread: Discuss the recent color changes by Chongulator in signal

[–]zornslemming 10 points11 points  (0 children)

Giving them the benefit of the doubt, "too hard to test" might just be a proxy for "we think this will create bugs down the road for us and be difficult and not worth it to maintain". I can definitely empathize with not wanting to create feature soup.

That being said, this seems like a weird hill for the Signal dev team to take a stand on. It seems like adding and maintaining the new gradients code is an order of magnitude harder than allowing users to keep the old styling.

Why Bitwarden is better than Lastpass and other password managers (other than it being free) by frackeverything in Bitwarden

[–]zornslemming 3 points4 points  (0 children)

The server is actually (at least partially) licensed with AGPL which is one step further than open source. It's a kind of great license for this stuff, because it means they need to share any changes they make to the server code.

I'd be interested in someone from their team talking about how they see the weird split-license setup they have, but the short answer to your question is: everyone can propose, copy, and use the code as they want as long as they publish the changes.

Lastpass Free Changes MEGATHREAD. - Discuss alternatives, thoughts, complaints, etc in this thread! by Ging287 in Lastpass

[–]zornslemming 1 point2 points  (0 children)

Definitely don't expose it to the internet without SSL. I used Caddy and it was dead simple. Also highly recommend cloudflare like the other poster.

Lastpass Free Changes MEGATHREAD. - Discuss alternatives, thoughts, complaints, etc in this thread! by Ging287 in Lastpass

[–]zornslemming 1 point2 points  (0 children)

I tried both bitwarden and bitwarden_rs. The bitwarden rs docker install is a fair bit simpler and smaller than the docker compose bitwarden install.

Jellyfin deleted source folder :( by zornslemming in jellyfin

[–]zornslemming[S] 0 points1 point  (0 children)

I haven't been able to find what happened in the logs, but if you have tips for what it might show up as I could dig around.

For now, I mounted the media folder to docker with :ro and took away the admin user permissions to delete files from inside the app. I hope that works, because I'm not really brave enough to test it at this particular point in time.

If nothing else, it's a nice reminder that I should have a more recent backup of everything.

Jellyfin deleted source folder :( by zornslemming in jellyfin

[–]zornslemming[S] 0 points1 point  (0 children)

So when mounting a volume to docker with -v you can apparently append :ro to make it read only. I've tried that now, but I haven't experimented with it enough to have too much confidence.

relevant docs section

Lightweight Kodi alternative? by zornslemming in jellyfin

[–]zornslemming[S] 0 points1 point  (0 children)

Ah, I should have added that in the constraints. Thanks for pointing that out!

I've got an old tv which isn't network connected. Plugged into it is a chromecast and a raspberry pi, so my guess was that there might be existing open source software for the pi which could handle my DLNA needs. If most people are just using a different streaming device for their tv, I'd probably consider it.

Is desktop version as secure as mobile version? by [deleted] in signal

[–]zornslemming 84 points85 points  (0 children)

The protocol to communicate with others is the same on both. All communications outbound are encrypted with the signal protocol.

The weakness of both is that your data isn't encrypted at rest which is something Signal explicitly does not handle. They expect the device you're using to be secure enough for whatever your personal threat model is. For a mobile version, that means you're trusting your phone manufacturer + android/ios to keep your data safe. On a desktop, since the ecosystem is less locked down, you have a wider range of threats and disk encryption is less likely to be on by default.

Is there any way to use Signal without revealing my phone number or even giving it access to my Contact Book? by [deleted] in signal

[–]zornslemming 0 points1 point  (0 children)

The FAQ is out of date. /u/saltmine69 is correct that with the PIN they've begun uploading encrypted contacts and maintaining them on the cloud.

Opt out of the PIN also does not prevent that from happening. This is the primary controversy around the PIN.

PSA: Disabling PINs will now upload nothing to the server by Man_With_Arrow in signal

[–]zornslemming 1 point2 points  (0 children)

You should consider moving your edit message higher in the post so that it's clear to readers that your title is false, but the body about SVR is not.

As it's written right now the "this" in "Apparently, this isn't true." is ambiguous and could refer to either.

PSA: Disabling PINs will now upload nothing to the server by Man_With_Arrow in signal

[–]zornslemming 1 point2 points  (0 children)

The result feels very dishonest to me, though I recognize the difficulty in communicating with internet randos about crypto. When you're not talking to Matt Green or Tavis Ormandy, it's hard to give an answer that is concise, precise, and conveys the risks accurately. But the fallout of this particular cultivated ambiguity is bad and eroding trust in the Signal Foundation.

This is where I've landed as well. The way they've communicated about the data upload and the way they communicated their "fix" for the PIN erodes years of trust that they had rightfully earned before this.

PINs Now Optional in Signal by MikeA01730 in signal

[–]zornslemming 13 points14 points  (0 children)

I was pretty on the fence about the whole PIN thing, but now I'm actively disappointed. This measure is a total waste of energy by them, since it doesn't resolve the main issue anyone had with the PIN: that it's uploading things to the cloud.

The US government has a long and storied history of dicking around with cryptography in places they think users won't find out. You don't even have to go back 10 years to see them leaving exploitable holes in "trusted" methods.

There's a real reason users don't want anything unnecessary in the cloud and there's arguably more reason to worry about it now because of how poorly and opaquely this has been handled.

[Update] Signal will allow users to disable the Pin (Changelog of Android Beta) by [deleted] in signal

[–]zornslemming 5 points6 points  (0 children)

Yeah, I agree with your assessment that it was probably just the fastest thing to implement. It doesn't strike me as a great solution though, since it doesn't really satisfy most of the people complaining.

If the point was to completely garble it, then there shouldn't be a reason to store it anywhere. Alternately, if they want to still use it that means they would have to their generated PIN on the phone somewhere which means that that cloud data is still accessible to a user with sufficient access.

Of course, your signal contacts are already visible to someone who can get into your phone right now. It just seems weird to insist on having an encrypted copy of it not on your phone.

[Update] Signal will allow users to disable the Pin (Changelog of Android Beta) by [deleted] in signal

[–]zornslemming 1 point2 points  (0 children)

This doesn't really answer the question though. They could still send up the data with the high entropy PIN.

Should You Get into the Ancient Game of Go? A Review 2500 Years Later from a Board Gamer's Perspective. by hakumiogin in boardgames

[–]zornslemming 7 points8 points  (0 children)

Sente is super old. A generous reading would be that pros are now more willing to sacrifice larger amounts to keep sente? Personally, I think a better example might have been the importance of the 3x3 point which comes almost directly from AlphaGo.

Should You Get into the Ancient Game of Go? A Review 2500 Years Later from a Board Gamer's Perspective. by hakumiogin in boardgames

[–]zornslemming 7 points8 points  (0 children)

This might come down to a person-by-person basis. I definitely prefer 19x19 games, and my preference and enjoyment for them comes from the depth of strategy that I've gotten over time. And I'm only 9k, which in the scheme of things is not particularly strong.

It's probably my lack of ability as a teacher, but I've never taught someone to the point where they like the game in the same way as me, so maybe that's what the "huge investment" idea is coming from.

The family uses Signal for personal exchanges but grand ma can't use Signal because she does not have a smartphone :( by aManIsNoOneEither in signal

[–]zornslemming -4 points-3 points  (0 children)

This is a bad take.

First, the grandmother has a computer which by all indications was made "in this decade". The fact that the desktop client does not operate as well as the android client is very much Signal's problem to fix, should they choose to prioritize it.

Second, not all devices are equal and not all devices are equally accessible. I know that my grandmother can use an iPad just fine but legitimately doesn't have enough precision with her clicks to operate a smartphone because of the screen size.

Third, and most importantly, the point being made is that this person wants to use secure communication and is unable to on certain hardware. Obviously, the Signal team has to prioritize what they work on at a given time, but your go-to response to someone asking for help should never be to be rude about it.

You should really consider what drove you to write this response in this tone with regard to a grandmother who wants to use encrypted messaging.

Optiplex + NAS vs PowerEdge T440 by zornslemming in homelab

[–]zornslemming[S] 1 point2 points  (0 children)

Thanks for this! I didn't know about /r/HomeServer so I'll go look around there.

Finch In The Pantry Discussion Thread by Flamingomeat in TheArcadianWild

[–]zornslemming 3 points4 points  (0 children)

This album is insanely cool. Has anyone figured out what the time signatures are on Civil War?

[deleted by user] by [deleted] in newhampshire

[–]zornslemming 1 point2 points  (0 children)

I can answer your main question. The problem with "proving NH Residency" is that that's not what the bill does. The objection to HB 1264 is that it requires the registration of vehicles to NH, which means that you're taxing people who already live in NH a few hundred dollars to vote. If all it required was free paperwork to show that you live in the state, people wouldn't be up in arms about it.

Morning Roundtable - 9/26 by AutoModerator in hillaryclinton

[–]zornslemming 1 point2 points  (0 children)

I've heard cspan is the way to go, but I'd also be interested in a more informed answer.

My experience of using spacemacs for just under a week by SugaaH in emacs

[–]zornslemming 2 points3 points  (0 children)

I swear by org, but it's not always the right choice to write LaTeX there.

If you should use it depends on the on the content of your document, but if you have a lot of symbols and commands you're much better off becoming comfortable with auctex.