Hacker Newsnew | past | comments | ask | show | jobs | submit | mlfreeman's commentslogin

The author of this ticket seems to come across as an arrogant know-it-all that thinks "the threats i thought of (or personally face) are the only threats that are significant, fuck anyone in a different situation."

I proudly print my entire KDBX file including passkey private keys and I encourage my elderly parents to do so too.

Lightning strikes (and assisting people with cleanup and repair from them) have taught me that there are definitely a class of threats that will leave me with paper but possibly no technology until I can go buy a cheap laptop to restart my digital life, SO BEING ABLE TO BACK EVERYTHING UP IS ABSOLUTELY ESSENTIAL.

His website says he's in Boston, so I seriously doubt he's ever seen what lightning can do or dealt with a hurricane or tornado.

In general, if you're in the FIDO Alliance and had anything to do with the kind of micromanagement that passkeys can allow, FUCK YOU. Go get a job at Walmart as a greeter. We'll all be better off.


>I proudly print my entire KDBX file including passkey private keys and I encourage my elderly parents to do so too.

Do you mean you print the raw values to paper or some encoding that would let you reconstitute the file (some giant QR code or something?)?


I print a nice HTML document - each entry has each field/value in a HTML table and each group gets its own header.

On macOS I use Strongbox's Print Database capability. On Windows, I'm testing a KeePass plugin I created that does the same thing and more (not quite ready for public release).

If I'm still around and coherent, I can re-type it into a KDBX-supporting app by hand (or maybe if I'm lucky only enough entries to get to a backup in cloud storage).

If the worst happens and I'm no longer capable of using a computer, it's an obviously-important document for whoever is cleaning up after me (I bet most people would understand the importance of a document with a bunch of usernames and passwords). They won't have to somehow break into my computer first to be able to figure out what online/digital matters of mine need to be dealt with.

EDIT: My current printout is 46 pages long.


>EDIT: My current printout is 46 pages long.

Wow. Roughly how many entries do you have and how do you handle updates? I'm often being asked to change passwords and of course create new login entries.


57 groups, 307 entries. I try to reprint whenever I get an oil change (so a few times a year).

I don't reprint for every password change. I will for major accounts. I will also immediately print for certain new accounts but not all (e.g. I didn't reprint for my HN account).

The Strongbox printout has the last printed date on it and my KeePass plugin even includes the SHA256 of the KDBX file just to be sure.


The visualizer reminds me of my thermal camera.

I have heard claims of devices (mostly TVs) supposedly coming with secret 5G cell uplinks built in [never heard a specific model mentioned though].

If there were more variants covering more commonly-used RF bands, people could walk around and literally check for once.

(incidentally i'm sure three letter agencies have had this sort of tech in their bug-detecting toolkit for a LONG time)


Whos paying the telcos for those 5G connections and also has the FCC been degraded so much that they would allow for undeclared radios in consumer products?


More likely 4G LTE MTM (https://www.verizon.com/business/products/internet-of-things...). It's dirt cheap and paid for by the vendor of the device it is in (usually) in the name of 'telemetry'.

I've seen so many random industrial devices and parts come into our plant that have their own cellular it's wild.


You really think these are in TVs going unoticed and someone is paying for each radio?


I have $100 devices in industrial devices that have them. In bulk, they cost next to nothing (not quite as cheap as RFID but getting there).


But in your scenario they are an integral and necessary part of the device, so it's costed in.

In a television it's an added cost and it's unclear if serving ads really can offset that extra $25-100 of hardware (and included data) you ship on a $200-1000 television.

It's also unclear to me if the low data packages they come with would be enough to serve meaningful ads to begin with. Those devices usually come with a fixed plan of 100MB/month for 5yrs (or along those lines). Modern smart tv ads are very often video or at least hi res images.


> In a television it's an added cost and it's unclear if serving ads really can offset that extra $25-100 of hardware (and included data) you ship on a $200-1000 television.

Amazon seems to have done the math and found that it makes sense to give a $20 discount on a $180 device if it lets them display very unobtrusive ads on the lockscreen. So I don't think you are correct.


Why are you assuming the primary motivator is to serve ads? Smart TVs were already caught running content ID against the contents of the screen and phoning that data home. "Routing at the edge" is the euphemism for the logical extension of that.

> extra $25-100

Your estimated costs are off by at least one order of magnitude, probably two.

Of course none of this makes much sense in a world where smart TVs have ubiquitous wifi, most consumers have one, most consumers run the stock OS, and most consumers connect it to the public internet. It would be entirely viable if not for that status quo.


My truck (Ford) has some cell connectivity that I’ve never paid for. At scale it’s likely very inexpensive.


Unfortunately, it's used to spy on you, and insurance companies are known to buy the data to profile customers or prospective customers. The good thing about Fords is that the cell modem often has its own fuse.


Secret 5G is not as common because there is a huge incentive to resell the free service. Maybe with eSIM it will be harder. Kindles uses to have a free data plan SIM.


> huge incentive to resell the free service

Not all mobile data APNs go to the Internet. You can't resell an IP service that lands on an RFC1918 network with exactly one IP:port available; the API endpoint.

Not saying I've seen this in devices, but I have built and run mobile data networks with private APNs.


Telcos sell off peak only 5g for cheap. Only to large companies that are willing to work with the limits. Often it is low bandwidth.


This is interesting. Do you have any specific examples?


No. I did see in the 5G design that that type of thing was a consideration. It may well be that phone companies aren't selling like that, however it certainly would make sense that they would be looking for companies who want a deal. Most of the cost of service is fixed, and a large number of customers want service during particular peak times and so they can serve that peak data even at off peak times such as when everyone's asleep and so if they could sell that time only that is a little bit more money. It only makes sense if those buying off peak times do have other alternatives that they would turn to instead.


The FCC is literally powerless nowadays for all intents and purposes. They've abrogated so much of their authority to the states now that they might as well be eliminated. What little authority that remains with it is bought and paid for to the point that I'm sure you could get anything "approved" if you wanted.


> has the FCC been degraded so much that they would allow for undeclared radios in consumer products?

Well... most TVs already have a WiFi/BT chipset for stuff like advertisements or, especially with Apple, high-bandwidth video streaming. There is already a radio module present, but (IIRC) you don't have to disclose what exactly that module is capable of.


You definitely are required to disclose what frequencies are used and at what power.


Uhh yes you absolutely do need to disclose exactly what each is capable of. Each radio must itself be approved by the FCC and documented


> I have heard claims of devices (mostly TVs) supposedly coming with secret 5G cell uplinks built

This is occasionally mentioned on HN, but I have not yet seen a specific instance of this. Please share if you know something about secret 5G cell modems used to spy on people.


It always impresses me that technology ideas once exposed in the nefarious background of the Snowden revelations, has now become mainstream, almost passé among the technocratie, but then I remember that there is a very dominant event horizon where all technology is weaponized/de-weaponized according to the intentions of its users..

It's going to been pretty wild to see QuadRF being applied for things. I can only imagine there are weapons-technologists who will bolt this onto hunter/killer drones at some point. A lynchpin technology for the inevitable drone wars.


I’ve seen websites say during checkout “your address wasn’t in our db but this one was” showing what was clearly a cleaned up form (changed “Circle” to Cir, uppercased, turned ZIP into ZIP+4) so there are ways.

You would have to tell the user “use the corrected/matched one only” though. Some sites offer the correction but don’t make you use it.


The downside is this service is not up-to-the-minute accurate. I rented a new-construction house and it was the better part of a year before it made it into the USPS address correction database, despite receiving mail just fine.

Might be acceptable collateral damage, but it’d exclude some people.


I think offering suggested edit is ok but requiring the edit be accepted is unwise.


Unfortunately I've had websites strip out the house number in the "cleaned up" address.


Weren't there iPhones that had wifi chips that ran Linux?


Uh, I just noticed the Windows NT for GameCube port actually claims Wii support too...so maybe one day we'll see a Wii dual boot NT4 and OS X 10.0


Also don't forget about working in "That's no moon. It's a space station." somewhere.


I followed the instructions link and read the scripts...although the TinyGPU app is not in source form on GitHub, this looks to me like the GPU is passed into the Linux VM underneath to use the real driver and then somehow passed back out to the Mac (which might be what the TinyGrad team actually got approved).

Or I could have totally misunderstood the role of Docker in this.


https://docs.tinygrad.org/tinygpu/ are their docs, and https://github.com/tinygrad/tinygrad/tree/4d36366717aa9f1735... is the actual (user space) driver.

My read of everything is that they are using Docker for NVIDIA GPUs for the sake of "how do you compile code to target the GPU"; for AMD they're just compiling their own LLVM with the appropriate target on macOS.


> In the future we will also be merging another project into this app which is a collection of data from personal weather stations across the country. That data is really cool because it can fill in coverage gap. https://www.pwsweather.com/map/?ob=temps

I have four stations uploading there - looking forward to see the result!


Please provide links to the relevant regulations from an actual government website such as eCFR in the US (https://www.ecfr.gov/)


The regulation would likely come from an industry body like the GSM alliance or some other thing that gates certification without which carriers won't allow the phone model onto their network, not governments.


And the ToS probably has a clause that says "we can alter the deal any time we want and you should pray we don't alter it further".


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: