GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Marcin Cieślak (saper@mastodon.social)

  1. Embed this notice
    Marcin Cieślak (saper@mastodon.social)'s status on Friday, 09-May-2025 12:25:19 JST Marcin Cieślak Marcin Cieślak
    in reply to
    • abadidea
    • feld

    @feld @0xabad1dea Quite happy with NSS, but this is definitely something not even remotely OpenSSL-compatible

    In conversation about 22 days ago from mastodon.social permalink
  2. Embed this notice
    Marcin Cieślak (saper@mastodon.social)'s status on Thursday, 12-Sep-2024 00:33:02 JST Marcin Cieślak Marcin Cieślak
    in reply to
    • feld

    @feld what did you expect

    In conversation about 9 months ago from mastodon.social permalink
  3. Embed this notice
    Marcin Cieślak (saper@mastodon.social)'s status on Wednesday, 19-Jun-2024 08:15:36 JST Marcin Cieślak Marcin Cieślak
    in reply to
    • Adrianna Tan

    @skinnylatte Maybe it is a feeling when living in a well-connected market garden.

    I was on vacation in some rural eastern European area and decided to buy stuff directly from the peasants: "Sorry no potatoes today, it was raining yesterday".

    I realized how much I was shaped by the supermarket culture.

    In conversation about a year ago from mastodon.social permalink
  4. Embed this notice
    Marcin Cieślak (saper@mastodon.social)'s status on Sunday, 24-Mar-2024 00:55:51 JST Marcin Cieślak Marcin Cieślak
    in reply to
    • Paul Cantrell

    @inthehands I wonder if the concept of documentation fades away

    I realized I tend to avoid software that forces me to study the concepts and the philosophy of it first from the documentation (For example, #Lilypond didn't let me to go quickly into writing things there).

    Watching some junior devs at work - they rely exclusively on prompts given by the IDE, giving at most one-line descriptions of function arguments.

    When that fails, they refer to library source code, never the documentation

    In conversation about a year ago from mastodon.social permalink
  5. Embed this notice
    Marcin Cieślak (saper@mastodon.social)'s status on Monday, 23-Oct-2023 07:27:34 JST Marcin Cieślak Marcin Cieślak
    in reply to
    • feld
    • kravietz 🦇
    • Kevin Beaumont
    • Alex White
    • vpz

    @feld @kravietz @PlaneSailingGames @GossiTheDog @vpz

    ok, now I got to understand that the Keychain is an encrypted data structure stored somewhere (it could be Apple's key-value store). Reading this story I gather that a whole thing is encrypted with a symmetric wrapping key. This wrapping key can be either obtained by the syncing identity or derived from the recovery code.
    So devices exchange the key exchange key among themselves during pairing? Could recovery code be seen as a #SPOF?

    In conversation Monday, 23-Oct-2023 07:27:34 JST from mastodon.social permalink
  6. Embed this notice
    Marcin Cieślak (saper@mastodon.social)'s status on Wednesday, 18-Oct-2023 05:57:02 JST Marcin Cieślak Marcin Cieślak
    in reply to
    • Kevin Beaumont

    @GossiTheDog can you provide some context? I am not sure I get this...

    In conversation Wednesday, 18-Oct-2023 05:57:02 JST from mastodon.social permalink
  7. Embed this notice
    Marcin Cieślak (saper@mastodon.social)'s status on Wednesday, 18-Oct-2023 05:57:00 JST Marcin Cieślak Marcin Cieślak
    in reply to
    • kravietz 🦇
    • Kevin Beaumont
    • Alex White

    @PlaneSailingGames @GossiTheDog

    I am no expert on #Webauthn but maybe some "pure-device-based-no-backup" attestation type could be added. But then, in turn, the relying party would need to require that and only that. Unlikely to happen.

    Does this mean that relying parties might need to maintain "trusted" lists of attestation CAs in the future?

    Here it would be unlikely that Google, Apple and Microsoft certificates will not be included on those lists by default.

    pls help @kravietz :)

    In conversation Wednesday, 18-Oct-2023 05:57:00 JST from mastodon.social permalink
  8. Embed this notice
    Marcin Cieślak (saper@mastodon.social)'s status on Wednesday, 18-Oct-2023 05:56:56 JST Marcin Cieślak Marcin Cieślak
    in reply to
    • kravietz 🦇
    • Kevin Beaumont
    • Alex White

    @GossiTheDog @kravietz @PlaneSailingGames

    got it! in short: FIDO good, passkey bad

    In conversation Wednesday, 18-Oct-2023 05:56:56 JST from gnusocial.jp permalink
  9. Embed this notice
    Marcin Cieślak (saper@mastodon.social)'s status on Wednesday, 18-Oct-2023 05:56:53 JST Marcin Cieślak Marcin Cieślak
    in reply to
    • kravietz 🦇
    • Kevin Beaumont
    • Alex White
    • vpz

    @vpz @GossiTheDog @kravietz @PlaneSailingGames

    (i)Cloud accounts have been targeted for hijack for quite a long time.

    what is the point of cloud-based passkeys?

    so I am going to protect myself against hijacking, say, my Github account, but my Apple account stays less protected?

    But if I go ahead and buy a real hardware fido key, I can use it for all services, including Github and (probably) Apple, so why bother with the cloud-based solution?

    In conversation Wednesday, 18-Oct-2023 05:56:53 JST from gnusocial.jp permalink
  10. Embed this notice
    Marcin Cieślak (saper@mastodon.social)'s status on Wednesday, 05-Apr-2023 12:53:07 JST Marcin Cieślak Marcin Cieślak
    in reply to
    • Jon Dubovsky
    • clacke@libranet.de is my main

    @jond @notclacke
    Looks like it is actively being worked on:

    https://git.pleroma.social/pleroma/pleroma/issues/165

    In conversation Wednesday, 05-Apr-2023 12:53:07 JST from mastodon.social permalink

User actions

    Marcin Cieślak

    Marcin Cieślak

    Internet is a read/write medium. Alors à quoi bon remuer le bourbier de votre inconscient de papilionacées ?

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          111068
          Member since
          5 Apr 2023
          Notices
          10
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.