• 8 Posts
  • 210 Comments
Joined 2 years ago
cake
Cake day: April 27th, 2024

help-circle

  • Ok, krass. Dann bist du da einfach empfindlicher bzw. ich unempfindlicher.

    Ich hab früher mit reeelativ scharfen Messern auch immer getränt. Seit ich ein wirklich SCHARFES Messer habe (was auch regelmäßig gewetzt wird usw) hab ich das vielleicht noch bei 3 Zwiebeln im Jahr (von… Ka… 400?). Daher geb ich das immer als Empfehlung. Aber klar, Allheilmittel gibt es wohl einfach nicht.


  • Es gibt kein Küchengerät, was ich mehr hass zu säubern also einen Blender/Mixer.Selbst in der Spülmaschine nimmt der viel Platz weg und braucht ewig, danach richtig trocken zu werden.

    Ne Zwiebel ist in 30s geschält und geschnitten, und wenn dein Messer ansatzweise scharf ist, weinst du dabei auch nicht.


    1. Signal
    2. XMPP
    3. Matrix

    In that order. I self-host both XMPP and Matrix, and I wouldn’t want to stop using matrix. Spaces, arbitrary amounts of self-chats, and so on are great. I use matrix every day.

    But for chatting… It sooner or later fails you. It’s slow. Notifications break. Messages are shown as sent, but somehow do not appear in the recipient’s devices until TWO WEEKS LATER (yeah IDK, happened twice already, in different chats and directions. Best part is, I’m not even federated!). Encryption is great IF YOU KNOW SOME CRYPTOGRAPHY BASICS, and utterly confusing otherwise.

    XMPP just works. Especially the calls, holy shit, I had to fight Matrix for so long to make voice and video calls work, and xmpp just… Works. Notifications are way more reliable (as in, have been absolutely perfect). I really like monocles as a chat app on Android. (The downside is: can’t decrypt old messages on new devices, and desktop clients are ugly.)

    So why Signal above XMPP?

    Because it’s not your fault should something ever break in a vital service. Also the encryption and privacy afforded by it a great.


  • I’ll second Pocket-ID.

    I originally had Authentik setup. It worked well enough. However, their packaging constantly broke and no-one seemed to care.

    Switched to Pocket-ID and won’t be looking back. Passkey-based OAuth was all I wanted anyways. (Also, the logins themselves are noticeably faster!)


  • Hab eine Geschichte die nur so halb zum Thema passt, aber egal:

    Hatte eine OP anstehen, brauchte davor vom meiner Hausärztin ein paar Labore und ein EKG. Also Termin gemacht, hin, Blut abgenommen, und dann an die Maschine angeschlossen. Dauerte nicht lange und ich war fertig, alles wieder ab. Maschine druckt langen Bogen Papier aus.

    Hausärztin wirft einen Blick drauf, zieht die Augenbrauen zusammen, starrt das Papier ein paar Sekunden lang mismutig an und macht ein misbilligendes “Hmmmmmmmmmmm”. Steht auf, geht nach draußen. Ich sitze 10 Minuten in dem Zimmer und dreh’ Däumchen.

    Sie kommt mit dem EKG-Ausdruck und ihrem Kollegen wieder rein, meint “Also Frau smiletolerantly, ich habe mich jetzt eingehend mit meinem Kollegen beraten und wir sind uns beide einig. Sind Sie sich bewusst, dass Sie irgendwann innerhalb der letzten paar Wochen einen Herzinfarkt hatten?” (Randnotiz: Ich bin zu diesem Zeitpunkt 22 und habe eine völlig durchschnittliche Figur und Fitness.)

    Ich bisschen bedeppert “ähhh… Nein? Sind Sie sich sicher? Kann ich die OP trotzdem machen?”, worauf mir versichert wurde, dass man sich sicher sein, nein definitiv keine OPs in meiner näheren und so-Gott-wolle mittelfristigen Zukunft, und stattdessen solle ich mir doch bitte vorne eine Kopie meiner Unterlagen abholen und in die Notaufnahme des Uniklinikums gefahren werden, pronto, keine Umwege, gehe nicht über Los. (“Das ist ja nicht so weit, das Laufe ich” vs. “Sie sollten sich auf jeden Fall ein Taxi nehmen” wurde dann in den Kompromiss “ich nehm nen E-Scooter” runtergehandelt.)

    Ich also ab in die Uniklinik Düsseldorf, Anliegen vortragen, eingeordnet werden, dann 4h warten. Ich in der Zwischenzeit natürlich mittlerweile mit genug Panik, um das Herz wirklich zum Platzen zu bringen. Hab schon unter Tränen meine Partnerin kontaktiert, jetzt nicht im Glauben augenblicklich drauf zu gehen, aber hey, tolle Nachrichten sind das ja selbst im besten Fall nicht.

    Kann endlich gesehen werden, erläutere nochmal die Situation, die Ärztin dort macht nochmal eine umfangreiche Anamnese. Schließlich neues EKG. Maschine druckt den Graphen aus. Ärztin sieht sich das an, wirkt nicht super happy, und stellt fest: “Nö da ist nichts. War vermutlich einfach eine Elektrode locker”.

    Ich hab ne neue Hausarztpraxis.
















  • Huh - you’re right. I went back to Signal’s X3DH spec because I was sure I was right, but it seems I misremembered how the “prekey bundles” work: Users publish these to the server, allowing (in my original assumption) for the server to just swap them out for a server/attacker-controlled key bundle for each Alice and Bob.

    However, when Alice wants to send Bob an initial message and she gets a forged prekey bundle, Bob will simply not be able to derive the same key and communication will fail, because Bob knows what his SPK private key is, while the server only knows the public key.


  • A compromised server would allow the server to man-in-the-middle all new connections (as in, if Alice and Bob have never talked to each other before, the Server/Eva can MITM the x3dh key exchange and all subsequent communication). That’s why verifying your contact’s signatures out-of-band is so important.

    (And if you did verify signatures in this case, then the issue would immediately be apparent, yes.)

    Edit: I was wrong. See below.