• 1 Post
  • 185 Comments
Joined 1 year ago
cake
Cake day: June 16th, 2023

help-circle






  • That’s not actually a solution when talking single-use either. Remaking the bottles from recycled glass is incredibly energy intensive and not an environmentally friendly process either. Multi-use bottles are much better, but the cleaning required also isn’t that simple and also relatively energy intensive (far from remaking the bottles of course).

    There’s also practical downsides to glass (heavy, breakable), but those are subjective and their relevance highly depends on the use case.

    Ideally, we wouldn’t buy stuff to drink in any kind of bottle, but just use tap water. possibly just buy some concentrated stuff to then make your actual drink at home. Nothing beats the effectiveness of transporting water through a simple pipe, but that isn’t even possible everywhere in the world due to drinking water quality issues…


  • One of the basic rules is that “you can’t prove a negative”. You can only prove it by it contradicting something that has proof, which isn’t gonna work for something like this. As a plain example: you can’t prove you were not at McDonald’s at 8 o’clock last night, but if there’s video of you being somewhere else at that time it proves it only because it would require you to be in two places at once.

    So the best you’ll probably do is promising really hard that you did your best to look for it? The problem is that it may well exist, but hasn’t gotten any traction and might be a 1 person thing in some repo somewhere, undocumented and badly searchable with a bad project name.


  • The “key” of an m.2 defines what the pins mean, basically what signal they carry (PCIe, USB, …). There’s a nice table here, if you scroll down a bit. Some are extensions to others, and are pin compatible (meaning the things they have in common are on the same pins).

    A key and E key are very similar, while E just provides a few more interfaces, but importantly A doesn’t provide anything the E doesn’t. So any card that can work in A can also work in E. This is why A+E is so common: they don’t require the Mainboard to provide E, only A, but both will work so both notches are present.




  • In this context “self host” can ironically mean using a cloud service for hosting. You can use a file based password manager and just sync the database. Solutions like KeePass have apps for many platforms, and they can often even directly load from cloud storage, like Google drive, OneDrive or DropBox. The password database is strongly encrypted, and even if your storage gets compromised, your passwords are still safe (assuming a good password or some then better security was used to encrypt it).

    You give up the convenience of having a single service and having to get each device to access the file. But that’s it. It’s not that hard and so much better than a password service, even if just for their attack surface, or the “likely target” these are.


  • Ah the Internet classic: calling someone’s comment irrelevant, when you clearly haven’t even read, or at least not understood it. It isn’t that long of a comment. Try reading it again.

    Oh whatever, here’s another attempt at explaining it: there’s a huge difference if my passwords are in a place where people generally keep passwords, or if they are where only my passwords are. If someone has never heard of me, but they attack my cloud-password-solution and get in, they still get my passwords. Someone attacking me personally, if he’s truly competent as a hacker, in probably screwed either way. At least he can only attack me, he can’t attack “some public thing” and get my stuff “by accident”. Think “personal safe in my home” compared to “public bank” (ignoring the fact that a bank is insured and all that for this analogy).

    Your second point would be valid if open source didn’t exist. First of all I didn’t imply that it was inherently safe, I implied that there isn’t a single point of trust, which was my would point. Even if you can’t read/audit it yourself, there are projects that have public audits by reputable security companies. Plus if there truly were backdoors, assuming a non-tiny user base, someone would’ve probably noticed.

    Then your final point seems to acknowledge the attack surface, but the problem with the “locally encrypted blob” is that this statement from the cloud provider is another thing you just have to believe them on. They might do that, they might not. Many don’t even claim that, because people like convenience and want options for password recovery to their password service. those two are mutually exclusive.


  • Stop using “the cloud” to store your passwords. Unless you control said cloud, you have to trust someone to not fuck up their security that you now depend on. Everyone eventually does.

    The difference is also, that someone who’s job is storing other people’s passwords is by definition a target. So is the fuck up, someone will notice. If you host those yourself, or you rent a place where you can host them for yourself, that is just one person’s server. The interest and possible gain for someone gaining access is so small, it’s even unlikely. So when you inevitably fuck it up, the chances someone notices before you do are relatively small.






  • Maybe they down vote because they think I don’t like the research or think it’s pointless (far from it). The only thing I dislike is the reporting about it, and even there mostly the clickbaity headlines intentionally misrepresenting the facts. It’s clearly intentional, because when reading the articles it usually becomes quite clear that the author was well aware.

    I can also imagine that articles like that stop at least a couple of people here and there from adopting solar for their home, cause they read what they think means that there’s about to be a 10% efficiency increase for panels. Clearly that’s a time to wait, not to buy! The number is people that only read the headline is probably uncomfortable high, but I got no clue what the actual percentage is, or if those that don’t click through take the headline at face value…



  • That’s pretty definite by any measure.

    Not really, sorry. The complaint still is that the announcements are of some magical huge improvement that is just not real. They might work in a prototype, maybe in a laboratory, or the thing just disintegrates after being exposed to water or something. Of course the results influence existing or future products, that’s how the real world improvements come about.

    By the time you modify the prototype (or whatever) into something that is actually real world production viable, with a reasonable lifespan and production costs, there’s barely anything left in common with the hyperbolic announcement about fantasy stuff.

    I stand by that statement you highlighted. And the fact that it isn’t hyperbole. With all of these achievements being released as clickbait news articles, somehow when something exciting it’s actually everything the market, it’s crickets. Like solid state or “salt” batteries are starting to become products, seen any articles on those posted here recently? Or in news outlets in general? I haven’t, but I honestly could’ve just missed them, or they didn’t gain as much traction.