• 1 Post
  • 227 Comments
Joined 5 months ago
cake
Cake day: April 4th, 2026

help-circle

  • https://nostr.com/

    No idea what the Google login thing was. If I had to take a wild guess, maybe you found some place that also offers some key management/signing features as a way to make things more user friendly?

    I’ll buy that. I just have trouble squaring things like that with things like gpg-agent and how they cache passphrases and keep them from swapping to disk, etc. I’d want to know more about it and whether it’s generated in the browser or on the server. I’m also not even sure how I’d go about doing some sort of review of the javascript algorithms or where their random numbers come from. I’m not throwing shade on them; I just don’t know.

    iris.to […] Primal.net

    I’ll look.


  • Hard pass for me I think on nostr. The signup says to continue with google (heard of 'em) or NIP-07 (not heard of 'em), and the generate nsec button offers me an opportunity to download “my” private key. The file has a keypair and a helpful message that I can share the public key, and that I should never share the private key that it just sent me.

    Maybe there’s something I’m missing, but all the previous systems I’m used to use that to mean that you generate the keypair yourself, and then you can post the public key publicly while you should always keep the private key private which breaks the guarantee of the math that only the person with the private key can undo the message that the public key locked.

    I feel like there’s something I’m not understanding.


  • Correct, except I signed my public key. You now have cryptographic proof that I’m me. And as me, you can take my word for it that I only made that key to see what signed messages would look like on lemmy so that I could post in these sorts of situations and so that I could test Kleopatra. It’s not intended to be used for anything serious.

    It should also enable anyone who wanted to send an encrypted message to me to do so.


  • -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512
    
    We could all do it today.  The technology has existed for a
    very long time now.  We somehow allowed the market to get to
    a point where the crypto mostly benefits the corporations
    using people as a product.
    
    - -----BEGIN PGP PUBLIC KEY BLOCK-----
    Comment: User ID:	lemmy_posting_key
    Comment: Valid from:	7/31/26 2:00 AM
    Comment: Valid until:	7/31/29 12:00 PM
    Comment: Type:	255-bit EdDSA (secret key available)
    Comment: Usage:	Signing, Encryption, Certifying User IDs
    Comment: Fingerprint:	3965EF2558DE27BDF057EBD6D1800E8356A14454
    
    mDMEamxIKxYJKwYBBAHaRw8BAQdAHa59Q90fLXONJ/dheGvaTUsh8RxpYbN5/kLk
    VwhuJ8S0EWxlbW15X3Bvc3Rpbmdfa2V5iJYEExYKAD4WIQQ5Ze8lWN4nvfBX69bR
    gA6DVqFEVAUCamxIKwIbAwUJBaV4ZQULCQgHAgYVCgkICwIEFgIDAQIeAQIXgAAK
    CRDRgA6DVqFEVPHlAP9zcGI0AvP/I1fqIYfks8gArPWsbbXFMA3xdXuxpB0fkQD+
    NEKRbjZaoyQ5MU2IAlHdfC0DWCL7gyJ/aXtJQZPOAg24OARqbEgrEgorBgEEAZdV
    AQUBAQdA0itDkHmO4JKPtyK0+c+7KvaB1ub/ees6koIZo2S13wEDAQgHiH4EGBYK
    ACYWIQQ5Ze8lWN4nvfBX69bRgA6DVqFEVAUCamxIKwIbDAUJBaV4ZQAKCRDRgA6D
    VqFEVIaOAP9FUfaxNBI+gsBA4s6INSqhWCxhRPWCgQAk0wltsgpnkgD/bfpilGAx
    XBvfnJBlHbel5z73T4IEBqIvDTHX6t9AUQo=
    =kclm
    - -----END PGP PUBLIC KEY BLOCK-----
    -----BEGIN PGP SIGNATURE-----
    
    iHUEARYKAB0WIQRUzy5RsYePpEjLPsQmKLxeU5C8sgUCaqIEbwAKCRAmKLxeU5C8
    soZBAQCuGIZLW0SKpqqNrVOheG8U/t8YLrvLSal/MI5f3HgfowEAr6AV0lsrLmlV
    5BIldH/5q5WIbiZOiyPM4O/oerODSQQ=
    =jnr7
    -----END PGP SIGNATURE-----
    



  • That’s my guess. If the telemetry they’re getting never gets any bigger then the actual bandwidth it uses and the revenue from selling advertising packages, etc, would likely make up for it.

    Any time I’ve guessed something along the lines of “there’s no way a company would do that” or “people wouldn’t let a wiretap inside their home” I’ve been wrong. The pure TV market is essentially tapped out so the companies in that space are expanding by gathering more and more data so they can grow to make shareholders happy. Eventually there’s no more data to gather with current hardware limitations, so they have to get more creative in how they package the same old data into a new product.

    I don’t doubt for a second that the hardware won’t be built into new smart devices after a certain point. Maybe as part of a TV branded “cable service” over 6G, maybe as a requirement for warranty past whatever the minimum is. Who knows how the companies will pay for the NRE because they’ll make it back on selling the telemetry to advertisers and marketing companies with subscription services for gravy. Maybe they do point to point connections so that if your neighbor has the service then your TV can talk through theirs. The point is there’s a business case to be made for investigating whether it’s profitable or not, and the testing like the guys in the video are doing will now require specialized RF equipment that’ll be easily out of reach from a cost perspective for a while.


  • And this will have exactly the same effect where almost nobody changes their purchassing habits with regards to LG products. When the 6G cell tower network is rolled out1 the chances of detecting bullshit like this will drop to zero.

    [1] The 6G network will use very, very high frequencies for communication. This means the range will be greatly reduced and more towers will be needed, but the bandwidth will be much larger. There has already been discussion about there being no need for in-home wifi since the coverage will be good enough with 6G that a personal wifi router wouldn’t be needed, and equipment for sweeping for 6G devices will not be cheap.


  • Scene from a US classroom made up of high school seniors:

    “Now class, you’re all about to get ready to head out in the world, most of you are 18 or soon will be, and you’ll be adults! So today in this class we’re going to discuss some serious topics (that are still approved by the administrators!) Isn’t that fun? OK, it’s an open discussion but I’ll lead: what’s your favorite color? You can pick any one you want since you’re practically adults! But before we get into the discussion, let me just take a sip of my Lipton® Diet Green Tea Pineapple Mango. It’s so refreshing! This is what I’m having today, but tomorrow I’m going to have my favorite: Lipton® White Tea Raspberry! Isn’t being an adult fun! Now, let’s all have a safe discussion the shareholders will just love!”










  • Not on to advocate for internet open just for people privileged to have access in their homes.

    Gotcha.

    Are you calling Firefox a scraper then?

    I’m sure there’s a way to wire it up that way. It’s bound to have a Turing complete language in it somewhere and by definition it has all the tools to copy down files from the internet. If I were going into the scraping business I’d personally start with a scraper and give it a Firefox user agent. In short, scraping is about intent as much as tooling, and there’s no way to convey and enforce intent over HTTP. From a practical standpoint there’s a spectrum of activities that approximately go from Browsing to Scraping to DDoS in that order that really only differ in terms of scale.

    Why would you call “2” a scraper and “1” otherwise?

    If I’m hosting content then if #2 is a scraper and #1 is a browser, and they don’t cost me anything different then I don’t really care (someone else who’s done that kind of stuff can weigh in if I’m wrong). What a lot of sites seem to be reporting is that they have a small, steady hosting cost per month until WHOOM! an AI company scrapes their whole site and their hosting cost jumps that month, then the next month and the next as well because companies that would destroy copies of rare books to feed to their training don’t care. Facebook got called out sort of recently for scraping some entire pornsite’s content. It sounds like what you’re describing is just timeshifted browsing. I doubt anyone notices unless you’re really describing what you’re trying to do incorrectly.

    Nonsense. The author was sloppy in their phrasing. That is not what he means by “follow robots.txt”. By “follow”, he means “obey”, not visit.

    You’ll often hear/read “follow” used by itself to imply “follow the rules,” in this case “follow the rules specified by robots.txt.”

    From a technical standpoint an LLM recommends trying this code snippet to make httrack ignore the robots.txt file:

    httrack "http://example.com/" -O "/path/to/save/files" -%v -s0
    

    I haven’t tried it personally.