Keyoxide: aspe:keyoxide.org:KI5WYVI3WGWSIGMOKOOOGF4JAE (think PGP key but modern and easier to use)

  • 0 Posts
  • 31 Comments
Joined 2 years ago
cake
Cake day: June 18th, 2023

help-circle

  • I cleaned it up. Your editor doesn’t like to nest formatting apparently. Using an editor that lets you write the markdown directly is probably better, and you are probably already familiar with markdown anyway, since it’s used all over the place.

    2025-07-09 “Sometimes, when one door closes (lack of code signing) in life, another one opens (vulnerability).”

    The sentence sumarizes well the situation in the previous version, 8.8.2.

    There were - and still are - many false-positives reported in the previous version v8.8.2, by the antivirus software due to the absence of Windows code signing certificate. How to install the root certificate:

    1. Double-click the certificate, it may tell you it’s invalid, ignore that and click: “Install Certificate…”.
    2. In the Certificate Import Wizard, select “Local Machine”, then click Next.
    3. If prompted by UAC (optional, depending on admin Previleges), click Yes.
    4. Choose “Place all certificates in the following store”, then browse and select “Trusted Root Certification Authorities”. Click Next.
    5. On the final page of the wizard, click Finish to complete the installation.For detailed instructions, see Notepad++ User Manual.

    We’re still trying to obtain a certificate issued by conventional Certificate Authorities, for a better user experience. But let’s be honest: it’s probably not happening. Notepad++ isn’t a business - it’s certainly not an enterprise - and apparently, that makes a popular open-source project invisible to their gatekeeping standards.

    If the “gatekeepers” won’t issue a certificate under the name we deserve - so be it. At least it spares us from wasting time and energy on a frustrting process that demands we beg for a new certificate every 3 years. The Notepad++ Root Certificate may not carry their approval, but it leads us to freedom.

    Edit (2025-12-03): Starting with v8.8.7, Notepad++ binaries - including the installer - are digitally signed using a legitimate certificate issued by GlobalSign. As a result, Installation of the Notepad++ root certificate is no longer required. We recommend that users who have previously installed the root certificate remove it.



  • Steadily improving. I set up my webserver with ech which is the next step, hiding even the domain. A solid chunk of the internet uses cloudflare as an intermediary, which also has ech and only leaves “someone connected to some cloudflare page at this time for that amount of data”.

    As more places roll out deep package inspection, I’m sure in due time more randomization for package sizes will follow, making even the amount of data uncertain.

    Most web metadata is at the http layer anyway and has always been hidden by https.





  • redjard@lemmy.dbzer0.comtoTechnology@lemmy.worldPlex got hacked.
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    1
    ·
    3 months ago

    They also say

    meaning they cannot be read by a third party

    which equally isn’t true.

    If your password is guessable with trillions of attempts, and whatever information and time an attacker wants, then of course can they crack your hash, “read” your password, and try it on other services.

    Sadly the kind of password susceptible to being broken on account of not being strong enough is also the kind people use everywhere because they memorize it. A truly strong password will only be found in a password manager.







  • Not sure about that. I set up a wg vpn server on a system which then became unresponsive whenever wg was fully saturating the network. Turns out there is apparently no way to throttle or prioritize a wg server, the only way I could think of would be to dedicate a vm to solely the wg vpn and throttle that vm in its networking.
    I instead switched to openvpn which can simply be throttled via a line in its configuration.

    Besides that missing feature, openvpn also doesn’t require figuring out the right iptables commands to verbatim paste into its config as startup and shutdown commands. Setting it up was way easier than wg (though openvpn too wasn’t exactly user-friendly).

    WG to me seems too clunky and unfinished for more mainstream usage, though I am sure it wouldn’t be an issue for a large commercial user like mullvad that will have no issue with all that.







  • That applies to play integrity, and a lot of getting that working is juggling various signatures and keys.
    The suggestion above which I replied to was instead about software-managed keys, something handed to the app which it then stores, where the google drm is polled to get that sacred piece of data. Since this is present in the software, it can be plainly read by the user on rooted devices, which hardware-based keys cannot.

    Play integrity is hardware based, but the eu app is software based, merely polling googles hardware based stuff somewhere in the process.