eekrano

joined 1 year ago
MODERATOR OF
[–] eekrano 12 points 4 months ago (2 children)

CrowdStroke

[–] eekrano 3 points 1 year ago (3 children)

Some people have reported being able to add TOTP from mobile. Most people that reported on desktop have the same issue. It's a lemmy thing, not just the instance. Lemmy needs to have you validate your TOTP before committing it to your account so you don't get locked out for turning it on but not being able to actually add it.

26
submitted 1 year ago by eekrano to c/coolguides
 
[–] eekrano 2 points 1 year ago (1 children)

@[email protected] you are tasked with securing your network, please list all websites that should be blocked by default.

[–] eekrano 2 points 1 year ago

Thanks for the insight, that's good to know. What do you do if you need to move from one organization to another (it seems to be only allowed to move from personal vault to organization, not org -> personal or org -> org)

[–] eekrano 1 points 1 year ago (1 children)

Same here. I added it to Keepass, then opened a private browser and tried to log in and it wouldn't take it. So one of 2 things:

  1. Most sites have you enter a code to validate that you have it right before applying the changes to your account - I did not get this in Lemmy
  2. They simply don't validate that you have 2FA set up correctly by asking you for a code prior to actually enabling it on your account and the log in with 2FA is broken.

I went ahead and removed 2FA so I wasn't locked out of my account if I get logged out somehow until this is fixed.

16
submitted 1 year ago* (last edited 1 year ago) by eekrano to c/selfhosted
 

Hi All, Recently set up VW and imported my Keepass DB. All the folders went to "Collections" (200+ top level folders, multiple levels beneath that for some folders, about 1500 entries total) and handing out permissions to users seemed like a horrible manual experience.

Looking into this, it seems like Bitwarden has had open tickets for 5+ years for:

  • Inherited ACLs
  • Shared folders

5 years is long enough to make me think they're never coming or Bitwarden doesn't really care about these features enough to ever implement them. Of course, if they don't implement them, VW won't either as they mimic BW.

The best workaround I found was to move everything multiple people should have access to into its own vault and add users as managers to that vault. But you can't move items from one vault to another, only from a personal to a company vault- arg.

I see so much love for this app and I WANT to love it, but these (IMO) make it almost unusable for multiple users.

So how are you all handling what seems to be a serious usability issue? I want to like VW/BW, but it seems like it's missing basic functionality that every other password manager has - and even more worrying that BW don't seem to care about implementing it.

Please let me know how you're getting around these issues in a sane way that can be easily managed in the future- or if you're all just "dealing with it" or what. Thank you.

[–] eekrano 1 points 1 year ago (2 children)

Catch the error and dump the response body to see what you're getting. Might just be the server is overloaded and not responding with the expected JSON. The full body should give you more clues

[–] eekrano 3 points 1 year ago

I'm going to read about GitHub being down (with a link to this repo) on Monday, aren't I?

[–] eekrano 3 points 1 year ago

I haven't spun up an instance, so I don't have a good idea what the DB looks like, but are IP addresses captured on either account signup and/or vote casting?

It's isn't a silver bullet, but it's prohibitively more expensive to spin up instances to cast votes for bot users versus running through a script on a single machine. If you've got an IP you might be able to pinpoint bot activity and the accounts associated with it (until they get smarter, at least)

[–] eekrano 1 points 1 year ago

Yes, captcha is the default minimum that should be implemented.

Also reasonable is to log account creation with IP and timestamp, which allows retroactively remove offenders if patterns occur, or [more easily] determining if 500 account signed up within 5 minutes from a single IP.

While kind of a pain, but fairly efficient: require a phone number with text verification to enable an account.

Yes I know there's ways around each of these, but it makes it much harder to spin up many accounts through rudimentary means.

[–] eekrano 2 points 1 year ago

Comment / post ratio is useless as well for this though.

  1. Create a server
  2. Create 10,000 bot accounts
  3. Have 85% of bot accounts create a random post
  4. Have 40% of post a comment on the main level posts

Looks like I pretty busy, totally real server by the aforementioned metric

 

cross-posted from: https://lemmy.world/post/212576

As we've seen in the past week, a large amount of users don't care why subreddits are blacked out or why, they just want their timeline back to normal.

It's understandable, most users just want something to "work" when they want to use it and don't give any thought to what that means. We've already seen mods be replaced, deleted histories come back to life, whatever it takes for Reddit to make it seem "normal" so they don't lose users. Heck, even some of those who have left Reddit may be tempted to go back and read / comment on things they see there, because Reddit obviously isn't going to die overnight. So how do we continue the fight in the current environment Reddit has put us in while still getting a message across the users?

My thought is the following, and I'm putting it here because I think recent migrants are/were more than semi-casual reddittors, and it's clear we've got some development talent out there. I'm a developer as well but I'm looking for:

  1. Thoughts on the approach I'm suggesting
  2. Thoughts on implementation / usage
  3. Overall feelings regarding this in general

The idea

Make browser plugin(s) and / or a website that [knowingly to the user] intercept comment post requests for reddit and stores the post content elsewhere. In its place, all that is submitted to reddit is a link to a website (where people can click to view users intended comment text) along with a blurb about "reddit owning your comment data".

The browser plugin can also find these comments within posts and automatically query and get the raw text and replace it within a reddit page to make viewing these posts easier for everyone.

The idea being that the more users install the extension to easily read these posts, the more users obfuscate their posts so that other users also need the extension to more easily read comments on reddit.

Not only does this protect user data from being owned by Reddit, it makes it so Google searches will not find content on reddit.

Example post before and after:

(Unencrypted, or viewed with the browser extension installed)

(The posted content stored in reddit)

There's my idea. A few thoughts / notes:

  • Is this possible? I haven't checked out manifest V3 or made a browser extension in a long time, but with what RES already does I assume this would be doable.
  • Is it worth it? Will enough people want to read comments stored in this manner to "join the fight"? Who knows
  • Should it store the comment data elsewhere, or just store encrypted text in the reddit comment itself?

Anyway. I know we've got a lot of ex-redditors here, a lot of very talented developers, and a fight still going on that deserves a next step from the users.

Open to any and all thoughts from. This is just a musing on a potential next step - I haven't decided if I'm going to start developing anything yet.

view more: next ›