Commercial Flights Are Experiencing ‘Unthinkable’ GPS Attacks and Nobody Knows What to Do::New “spoofing” attacks resulting in total navigation failure have been occurring above the Middle East for months, which is “highly significant” for airline safety.
GPS is old, the amount of data you get from the satellite is small, essentially satellite id and timestamp. If we would redesign this today, you could include a digital signature.
Sure, but… you can google this to verify … one can probably manipulate GPS by introducing delay, i.e. resend data from a sat that was hear some seconds ago. With this signal the location will be off.
Ignore my ignorance. Are you saying the aircrafts track where they are going by calculating their position from gyroscope data? And this is more precise than GPS?
That’s like using the accelaration sensors in your phone to navigate. Or sailing with compass and nautical maps.
Possible. Tech isn’t even that novel. But still impressive.
This is the goal, sure, but what does this actually mean on device that’s mostly governed by software?
There’s a chip (like a yubikey) in the device that can hold cryptographic keys.
That’s good because the key cannot (easily) be extracted from the device.
That’s good as long as no one has physical access to your device.
With physical access, you hope that the device’s unlock mechanism is reasonably secure. That’s biometrics OR password/pin.
The ‘or’ is the problem. For practical reasons you don’t want exactly one method hard-wired. You have a fingerprint scanner (good enough), the secure element (good enough) and lots of hard- and software in between (tricky).
I’m not against biometrics (to unlock a device) because it’s convinient and much better than not locking the device at all. I’m also not against device trust (which you need if you want to store crypto keys sonewhere without separate hardware), but the convience of a single-device solution (laptop or phone) comes with a risk.
If an attacker can bypass the unlock method or trick you into unlocking or compromise the device, your secrets are at risk. Having the key stored in the secure enclave (and not in a regular file on the hard disk) prevents copying the key material, but it does not prevent using the key when the attacker has some control over the (unlocked) device.
A yubikey is more secure because it’s tiny and you can carry it on your keychain. The same chip inside your laptop is more likely to fall into the hands of an attacker.
You are not wrong, but you we should understand what class of attacks we are protecting against. Will biometrics stop your maid from using your device? Probably less. Will it stop the FBI? Not so sure.
Now, you may say, an FBI raid is not what you worry about on a daily basis. Agree.
If you are trying to keep the photos on your device safe from snooping, your good. Attacker needs the device and your fingerprint.
When we talk online accounts, I’d count device+fingerprint as one factor. Sure, the maid from the example above can’t login into your gmail without your fingerprint, but most attacks are online. Your device sends a token to gmail, a cookie, a String; that’s like a password. One factor.
Technically, it’s slightly better than a password, because this token can be short-lived (although often it’s not), could be cryptographic signature to be used exactly once (although…), you cannot brute-force guess the token… But IF the token leaks, the attacker has full access (or enough to cause damage).
That’s why I would suggest an independent second factor, such as password. Yes, a password. Not for your daily routine (biometrics+device is much better), but maybe for high-risk operations.
Some Microsoft employees fume over the company’s open offer to hire hundreds of OpenAI staff::Current employees point to layoffs and a salary freeze this year at Microsoft and wonder why it’s promising to match the pay of OpenAI staff.
This. Job hopping works for some time even when you are young, when you learn fast and when everyone is hiring.
I took me one year to get out of my managerial job and I took a paycut, went to work a smaller company with lesser job title. My previous job was too good on paper. In reality it was a total shitshow. I was open to take the first reasonable offer, but recruiters were hesitant to even talk to me.
And it’s not just job titles. Skills fade if you are in position where you don’t continue learning.
The x permission on directories is exactly for this purpose. You can use the directory. You cannot read (requires rx), you cannot write (w), but you can ‘cd’ and operate on files in the directory.
This is important, you can lock someone out from a directory tree buy not giving them ‘x’ on the root. So, if your home is rwx------, no one but the owner can do anything in your home. This is effective even if some files and subdirectories have less restrictive permissions.
I like to try websites out before tying my identity to them. How do you do it? Simplelogin? I honestly won’t manually make a new gmail for every new website I try and I to want the option to see what emails I get.
Johann Tschürtz, Klubobmann der FPÖ im burgenländischen Landtag, sagte anschliessend, die Abschiebung „war nicht für die Schüler gedacht, da diese ja auch nicht straffällig sind“....
Meiner Meinung nach sollte hier nicht die Schlagzeile sein, dass die Ampel verfassungswidrig Corona-Gelder anders verwenden wollte. Sondern dass die Ampel 60 Milliarden für Klimaschutz ausgeben wollte, und die Union das für so schlimm hält, dass sie dagegen klagt....
Hikers rescued after following non-existent trail on Google Maps::It was unclear how the trail in British Columbia had appeared on Google Maps in the first place.
I’m also a happy osmand+ user, but once i got lost in the middle of a field / bush. I’m sure there was a trail once, but not safe to follow. Said bush was not very dense, so we though multiple times: Ok, this could be the way. Or that path?
I’ve been seeing all these posts about Linux lately, and looking at them, I can honestly see the appeal. I’d love having so much autonomy over the OS I use, and customize it however I like, even having so many options to choose from when it comes to distros. The only thing holding me back, however, is incompatibility issues....
We ignore them, mostly. You cannot miss what you don’t know.
There are plenty of options however to access software not available natively. Both VMs and Remote Desktop solution work for a wide range applications. Web-based solution can be as good as desktop programs.
So many casual applications are now either web-based or on your (not FOSS) phone, so for my personal use the thought of using Windows has never crossed my mind. Professionally, I resort to remote Windows or a Mac.
So I prefer to use a DNS blocker (DoH) on my IOS devices to block ads, malware, and trackers. For the longest time I’ve been using Aha DNS Blitz because it allows you to choose the exact filter lists you want to enable. Recently I saw Mullvad now has their own DoH service as well and I’m trying it out now. It’s not as...
I’m so fed up of these cookie popups requiring a few extra clicks to reject, are there any extensions that will automatically opt out or reject additional cookies?
8GB RAM on M3 MacBook Pro ‘Analogous to 16GB’ on PCs, Claims Apple::Following the unveiling of new MacBook Pro models last week, Apple surprised some with the introduction of a base 14-inch MacBook Pro with M3 chip,…
Im Gesetzentwurf der Ampel zu irregulärer Migration findet sich ein brisantes Detail: Uneigennützige Helfer im Mittelmeer, etwa von “Sea-Watch” oder “Mission Lifeline”, könnten künftig so kriminalisiert werden wie gewerbsmäßige Schleuser....
They said it would be available on their upcoming flagship product, sure, that’s marketing. To me, this does not imply that the heavy-lifting is on the phone’s hardware.
(And maybe a special-purpose AI, which requires significantly smaller models, can run on the phone, which is a high-end mobile computer.)
Clients like Thunderbird are great because you have everything stored locally so you can easily search offline. They also support encrypting and decrypting emails in PGP. However, they seem to have the same limitation as protonmail where you can’t search through encrypted emails....
This does not answer the question. OP wants to Thunderbird to decrypt PGP mails. Yes, it makes sense to use an encrypting fs, but we are still missing this thunderbird feature.
Honestly, I can’t think of a good reason. This is just how email has always worked. What Thunderbird stores locally is identical to message on the server. It’s not decrypted because no conversion happens when syncing mail.
I agree, it would make sense to keep plaintext emails locally or on a trusted server for practical reasons.
Wenn meine Sprachkenntnisse und meine aktuelle Konzentrationsfähigkeit es zulassen, konsumiere ich Medien eigentlich am liebsten in Originalsprache. Vor allem Bücher von englischsprachigen Autor:innen lese ich eigentlich gerne auf Englisch. Bisher hab ich sie mir dann meistens gekauft. Bei deutschen Büchern bin ich...
Ich verstehe kein Wort, aber ich versuche mal zu helfen.
DAK ist eine normale Krankenversicherung (GKV), wie sie fast jede Person hat, die in Deutschland arbeitet oder studiert oder sich langfristig niederlässt. Diese Versicherung bekommst du üblicherweise, wenn du in DE bist und es kann ein bißchen dauern mit der Bürokratie, je nach persönlicher Situation.
Zu “Mavista” - nie gehört - kann ich nicht viel sagen, aber vermutlich ist das eine Art private Reiseversicherung. Das brauchst du vielleicht für die ersten Monate bis dein Studium und GKV beginnt, vielleicht für den Visumantrag oder wenn du nur kurze Zeit in Deutschland bist. Für eine kurze Zeit sollte das nicht teuer sein. (Aber eine Reiseversicherung übernimmt vielleicht auch nicht alle Kosten, nur akute Dinge während einer Reise.)
Du schreibst nicht viel, aber vielleicht sind die beiden Optionen:
Mavista (Reiseversicherung) für die Einreise + DAK (GKV) für das Studium oder oder
Private Vollkostenversicherung (PKV) für die ganze Zeit (MaVista 48 Monate)
Beides wäre eine adäquate Krankenversicherung für eine Student:in. Es gibt sehr viele Versicherer in DE und wir unterscheiden zwischen GKV (DAK, TK, AOK, …) und PKV (Allianz, HUK, Axa, …). Für dich ist es wichtig, dass du eine Versicherung hast. Die Unterschiede sind für Studenten nicht so groß.
Actual answer over circle-jerk speculation: To be legal in EU, they must offer one option without required (=forced) consent to tracking. When you pay, you can actually opt-out from any measure that require consent under GDPR.
All European publishers do this. They don’t want your money and probably don’t care much about the tiny minority that actually pays for freedom from tracking. This option exist to create the illusion of choice.
Between uBlock Origin, Privacy Badger, ClearURLs, Decentraleyes, and Privacy Possum, I’m having a hard time deciding which ones I actually need and which ones I don’t. Do they actually do different things, or are they largely the same?
I used Plex for my home media for almost a year, then it stopped playing nice for reasons I gave up on diagnosing. While looking at alternatives, I found Jellyfin which is much smaller and more responsive, IMO, and the UI is much nicer as well....
Which only runs on Windows, but not in a VM, unless you make a small change. Why?
To stop cheating, I assume, but what kind of cheating needs a VM? Maybe I’m old, but we had handwritten cheat sheets on paper.
Are students using cheat software now that solves math problems for an online exam? And if they do, shouldn’t this score bonus points? Sounds like challenging problem to code an AI that she’s your exam.
Ist umfrage-gleichwertigkeit.de legitim? German
Ich habe post vom BMWK bekommen, dass ich an einer Umfrage teilnehmen soll. Der Link zu der Umfrage ist www.umfrage-gleichwertigkeit.de...
Yes, you can have too many CPU cores - Ampere's 192-core chips break ARM64 Linux kernel in two-socket systems, company requests higher core count support (www.tomshardware.com)
DB Schnüffel-Navigator (digitalcourage.de) German
So viel kostet ein Auto im Monat (Mittelklassemodell) 💰 (feddit.de) German
Quelle: www.trend.at/mobilitaet/autokosten-im-monat#Liste...
Commercial Flights Are Experiencing 'Unthinkable' GPS Attacks and Nobody Knows What to Do (www.vice.com)
Commercial Flights Are Experiencing ‘Unthinkable’ GPS Attacks and Nobody Knows What to Do::New “spoofing” attacks resulting in total navigation failure have been occurring above the Middle East for months, which is “highly significant” for airline safety.
Europe Smartphone Shipments Decline 11% YoY in Q3 2023, Recovery Looks Distant (www.counterpointresearch.com)
YouTube warns it might make your viewing experience worse if you don't turn off your ad-blocker (www.businessinsider.com)
Microsoft’s Windows Hello fingerprint authentication has been bypassed (www.theverge.com)
Skandale bei der Lachszucht: Verendeter Fisch als Premium-Lachs (taz.de) German
Lachszucht ist eine Goldgrube, vor allem, je weniger Rücksicht auf das Tierwohl genommen wird. Doch die Branche verliert nun Kundschaft.
Some Microsoft employees fume over the company's open offer to hire hundreds of OpenAI staff (www.businessinsider.com)
Some Microsoft employees fume over the company’s open offer to hire hundreds of OpenAI staff::Current employees point to layoffs and a salary freeze this year at Microsoft and wonder why it’s promising to match the pay of OpenAI staff.
You can't cd or ls in a folder if you have no +x permissions on it. That is all. I wasted 3 hours of my life.
What mobile app do you use with your FreshRSS instance?
I downloaded FreshRSS is not updated and is really lacking in functionality… notifications!...
In Afghanistan gefangen – rechtsextremer Wiener jammert (www.heute.at) German
Via fefe...
Is it better to use a non-FOSS email and phone number forwarder or to use one of each for everything? (www.cloaked.app)
I like to try websites out before tying my identity to them. How do you do it? Simplelogin? I honestly won’t manually make a new gmail for every new website I try and I to want the option to see what emails I get.
Kenya suspends Sam Altman’s eyeball-scanning crypto project (Aug 2023) (www.theverge.com)
Abgeordneter verliest in österreichischem Regionalparlament die Namen von 21 Volksschulkindern und fordert dann "Abschiebung straffälliger Asylwerber" (burgenland.orf.at) German
Johann Tschürtz, Klubobmann der FPÖ im burgenländischen Landtag, sagte anschliessend, die Abschiebung „war nicht für die Schüler gedacht, da diese ja auch nicht straffällig sind“....
Wie viel Prozent eurer Arbeitszeit verbringt ihr WIRKLICH mit arbeiten?
Corona-Sondervermögen: BVerfG erklärt Nachtragshaushalt 2021 für verfassungswidrig (www.spiegel.de) German
Meiner Meinung nach sollte hier nicht die Schlagzeile sein, dass die Ampel verfassungswidrig Corona-Gelder anders verwenden wollte. Sondern dass die Ampel 60 Milliarden für Klimaschutz ausgeben wollte, und die Union das für so schlimm hält, dass sie dagegen klagt....
How Safe is an 8% Withdrawal Rate? (ofdollarsanddata.com)
Washington Post: Gaza reports more than 11,100 killed. That’s one out of every 200 people. (archive.ph)
Original article: washingtonpost.com/…/gaza-rising-death-toll-civil…
Hikers rescued after following non-existent trail on Google Maps (www.smh.com.au)
Hikers rescued after following non-existent trail on Google Maps::It was unclear how the trail in British Columbia had appeared on Google Maps in the first place.
How do y'all deal with programs not supported on Linux?
I’ve been seeing all these posts about Linux lately, and looking at them, I can honestly see the appeal. I’d love having so much autonomy over the OS I use, and customize it however I like, even having so many options to choose from when it comes to distros. The only thing holding me back, however, is incompatibility issues....
DoH blocker for IOS: Mullvad or Aha DNS Blitz
So I prefer to use a DNS blocker (DoH) on my IOS devices to block ads, malware, and trackers. For the longest time I’ve been using Aha DNS Blitz because it allows you to choose the exact filter lists you want to enable. Recently I saw Mullvad now has their own DoH service as well and I’m trying it out now. It’s not as...
Is there any Firefox extension to automatically reject cookie popups?
I’m so fed up of these cookie popups requiring a few extra clicks to reject, are there any extensions that will automatically opt out or reject additional cookies?
Lebensmittelwarnung für Hot Chip Challenge (www.lebensmittelwarnung.de) German
Es wurden stark schwankende und teilweise extrem hohe Gehalte an Capsaicin festgestellt....
8GB RAM on M3 MacBook Pro 'Analogous to 16GB' on PCs, Claims Apple (www.macrumors.com)
8GB RAM on M3 MacBook Pro ‘Analogous to 16GB’ on PCs, Claims Apple::Following the unveiling of new MacBook Pro models last week, Apple surprised some with the introduction of a base 14-inch MacBook Pro with M3 chip,…
Bundesregierung plant Strafen gegen Seenotretter (Süddeutsche) (archive.is) German
Im Gesetzentwurf der Ampel zu irregulärer Migration findet sich ein brisantes Detail: Uneigennützige Helfer im Mittelmeer, etwa von “Sea-Watch” oder “Mission Lifeline”, könnten künftig so kriminalisiert werden wie gewerbsmäßige Schleuser....
Galaxy phones to feature Samsung's own generative AI - The Korea Times (m.koreatimes.co.kr)
Why Not Store Encrypted Emails in Plaintext Locally?
Clients like Thunderbird are great because you have everything stored locally so you can easily search offline. They also support encrypting and decrypting emails in PGP. However, they seem to have the same limitation as protonmail where you can’t search through encrypted emails....
deleted_by_author
Does anybody use Thunderbird on Android a.k.a. K-9
Just recently started using thunderbird to see how it would help managing múltiple Gmail accounts. Has anybody used the app version? Is it good? Bad?
Wo kann man englische eBooks ausleihen?
Wenn meine Sprachkenntnisse und meine aktuelle Konzentrationsfähigkeit es zulassen, konsumiere ich Medien eigentlich am liebsten in Originalsprache. Vor allem Bücher von englischsprachigen Autor:innen lese ich eigentlich gerne auf Englisch. Bisher hab ich sie mir dann meistens gekauft. Bei deutschen Büchern bin ich...
Unterschied zwischen Arten von Versicherung German
Mein Sperrkontogeber hat mir drei verschieden Arten von Versicherung angeboten....
Facebook and Instagram launch an ad-free subscription model in GDPR countries (about.fb.com)
The best Android phone to buy in 2023 - The Verge (www.theverge.com)
How many add-ons do I really need to block trackers?
Between uBlock Origin, Privacy Badger, ClearURLs, Decentraleyes, and Privacy Possum, I’m having a hard time deciding which ones I actually need and which ones I don’t. Do they actually do different things, or are they largely the same?
When using fingerprint to unlock an app, does it register a particular finger or all known to the device?
You use fingerprint to unlock your phone. Here you can register multiple fingers....
Android 14 will turn your phone into a webcam for your PC (www.xda-developers.com)
What are some FOSS programs that you think are a far better user experience than their counterparts? (sh.itjust.works)
I used Plex for my home media for almost a year, then it stopped playing nice for reasons I gave up on diagnosing. While looking at alternatives, I found Jellyfin which is much smaller and more responsive, IMO, and the UI is much nicer as well....
How do you install safe exam browser on linux? Wine? VM?
The only resource I’ve found is this affanindo.github.io/seb-and-linux. Is it possible to use wine?...