modem_down
“People are arseholes. They’re just always gonna be that way.”
- 4 Posts
- 11 Comments
modem_down@thebrainbin.orgto
Technology@lemmy.world•Sweeping cyberattack on water systems in multiple states has US officials on edge
0·1 day agoThis coverage has a better headline: Trump blames Minnesota governor for cyberattacks against the state. Cites no evidence.
Funding restrictions and denialism, plus starting a war against a cyberattack-capable nation, made infrastructure attacks inevitable.
Security researchers have been publicly raising the alarm about SCADA vulnerabilities for 20+ years.
modem_down@thebrainbin.orgOPto
Selfhosted@lemmy.world•Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?
0·1 day agoIf it’s a server for self hosting you definitely don’t want anything that requires interaction at boot.
Depends on use-case. If you only plan to boot it when you’re physically present, it’s fine.
modem_down@thebrainbin.orgOPto
Selfhosted@lemmy.world•Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?
0·1 day agotang
Thanks. TIL about Clevis/Tang.
modem_down@thebrainbin.orgOPto
Selfhosted@lemmy.world•Unlocking LUKS with NitroKey/Yubikey: FIDO2, HMAC-SHA1, or OpenPGP?
0·2 days agoYes. Here are some common self-hosting scenarios:
- Home server containing family files: scans, photos, device backups, …
- Office server containing business files: sensitive documents, device backups, …
- Web or email server containing websites, Fediverse instances, emails, etc
In all those cases, full disk encryption (FDE) is a sensible precaution to protect the data in case the server is physically stolen.
Linux is probably the most common OS kernel for self-hosting. On Linux, LUKS (Linux Unified Key Setup) is probably the best FDE system. It’s mature and reliable. But anyone self-hosting a Linux server with LUKS FDE is faced with the question of where to store the keys.
Hardware security tokens (HSTs) are widely considered a safer place for keys than SSDs, HDDs, or USB storage. They follow the smartcard principle: a private key can be written to an HST but not read from it (security vulnerabilities excepted). Instead, they implement cryptographic algorithms to prove possession of the private key. So, anyone self-hosting a Linux server with LUKS FDE should strongly consider storing their private key(s) on an HST.
However, there is more than one way to do that. Hence the question in my OP.
modem_down@thebrainbin.orgto
Europe@feddit.org•Logitech to ship mice with replaceable batteries in Europe only, following Nintendo
0·3 days agoGreat to see Europe leading the way here. If other jurisdictions pass similarly responsible legislation, then those jurisdictions will gain similar benefits.
modem_down@thebrainbin.orgto
Europe@feddit.org•Germany's Merz demands sweeping EU budget cuts
0·4 days agoThe article has an interesting passage about how Irish aluminium is currently being sold to Russia for weapons, and the EU is (rightly) trying to stop this.
@EUCommission@ec.social-network.europa.eu, what’s up with this? It doesn’t seem in any way justifiable.
modem_down@thebrainbin.orgto
Technology@lemmy.world•US prosecutors charge Atlanta man after GrapheneOS phone wipes itself during airport search
0·6 days agoIt would be trivially detected by widely distributed standard forensic software including the non-Premium variant of Cellebrite able to run on a laptop.
By “duress profile”, I mean that if user has enabled a “duress profile” feature in Settings, then entering the duress PIN would:
- Erase (the encryption key for) all profiles and storage outside the duress profile; then
- Unlock the duress profile.
So, how would forensic software detect that the unlocked profile is a duress profile?
modem_down@thebrainbin.orgto
Technology@lemmy.world•US prosecutors charge Atlanta man after GrapheneOS phone wipes itself during airport search
0·6 days ago@GrapheneOS@grapheneos.social everyone seems to be clamouring for the same thing: add “duress profile” to the roadmap. Keep up the good work.



Aren’t turbine blades usually aluminium? How is wood more “recyclable” than that?