davidmitchell2's comments

davidmitchell2 | 1 year ago | on: Server Setup Basics for Self Hosting

While these seems to be secure... tampering with default settings always cause PITA; especially during automated upgrades. In addition, ssh port changes are all security thru obscurity.

davidmitchell2 | 3 years ago | on: Russian GPlay users can no longer download previously paid-for apps as of 5 May

Pretty sure EU and US will not diverge so much like Russia did. Russia is also tiny market (both population, GINI, internet penetration). See EU-US Privacy Shield - courts may say but nothing practical.

May be India/Middle-Eastern countries might but still there is so much inter-dependency everywhere - no one dares to annoy other.

There are lots of executives, politicians across EU/US living + having family in either places. So unlikely.

davidmitchell2 | 3 years ago | on: Ask HN: How do I get my Google account back?

Yes, I just tested it with one my accounts that has NO recovery email address/phone. ONLY U2F key.

Select forgot password; the it asks Insert U2F Key. Then recovered. Yes, it may be that if one loses U2F key in Metro it is dangerous but some risk is always there. (i.e) how many times have you lost your key in your life? If more than one per year then keep one U2F at work and one at home.

davidmitchell2 | 3 years ago | on: No Fixed Address Bank Account

Lets be honest - not having cards working for a day is not the same as earthquake. Sure people will miss trains/rent etc. 1 or 2 business may go under but for 90 % people all will be fine. Heck I am sure if many shops/metro will be free if some one like erste bank or Sparkasse does not work.

davidmitchell2 | 3 years ago | on: Ask HN: How do I get my Google account back?

That is what it means by encrypted data storage. Only the user has access. If they managed to see/recover your files then it is not encrypted.

(at the end, people will complain at both ends - some want convenience and do not care if companies see data. Others want total encryption and do not care if lost.

davidmitchell2 | 3 years ago | on: Ask HN: How do I get my Google account back?

From: https://ente.io/privacy#account-data

> Data security is very important to ente, whether that is your personal information or any other data. That is why we publish our client-side browser and mobile app software and why we have provided information in this Policy on collection and storage of all data whether or not it is personal information.

How does this prove Data security?

> And what is this: our architecture has been reviewed by cryptographers and engineers from IBM Research, ETH Zurich, IIT Delhi, Google, Facebook, Amazon, Microsoft, ...

Any white-paper?

davidmitchell2 | 3 years ago | on: Ask HN: How do I get my Google account back?

2. Instead of that use separate firefox profiles - one exclusively of Gmail. Another for casual browsing. If you clear cookies all the time then it seems like you are logging in so many times per day. This could be a warning sign of hacked account - for google. (i.e) do not do unusual things.

3. At the end U2F is the proper solution, albeit late!

davidmitchell2 | 3 years ago | on: Ask HN: How do I get my Google account back?

> Because I've been warned by security conscious people never to use phone number

Sadly you read only one part of the warning from security conscious people. The main part is to get U2F/FIDO key or use QR-code/authenticator. The same security conscious people use Fdroid/AndOTP where you can export all your 2FA codes.

There NO reason to say if I shatter my phone. Yes, you can also print recovery codes and keep it at home.

davidmitchell2 | 3 years ago | on: Ask HN: How do I get my Google account back?

> presumed that the security message was because of new IP addresses that must have been assigned. While I was initially able to log in to my accounts after replacing both the routers, o

1. Verify if your router or router software that you installed in your PC is doing something fishy.

2. As long as you have a browser window with cookies - even new IP address should NOT matter. It should allow you. I am almost always working in cafes with different IPs it - just works.

3. Please please verify your recovery email ID. Some times I have made the mistake of typing first.last@ instead of without dots. Send an email to your recovery ID to test.

Please get a 2FA U2F token.

davidmitchell2 | 3 years ago | on: Using a RaspberryPi as a Display Adapter

While I sincerely appreciate the user, I often find we in Linux/OSS/FOSS are complicating our lives. Anyone wanting decent batterylife please get some JasperLake or GeminiLake refresh notebooks. These are available in eBay or retail for $200 - $300. I have a Dell latitude 3190 (fanless/HD screen), and Acer Swift 314 (fanless/IPS/FHD), and Acer Aspire 317 (FHD - 17 inches) - has decent HDMI (but barrel charger) 2 X USB. Close to 1.3 kg. Battery life - seems at least 12 hours. Sure I usually ssh and work remote.
page 1