Readit News logoReadit News
leevlad commented on Crypto.com accounts had unauthorized withdrawals   crypto.com/product-news/c... · Posted by u/codechicago277
eli · 4 years ago
What stops the attacker from fetching the image or text?
leevlad · 4 years ago
In this case you set the anti-phishing code in your account settings (arbitrary string). Then they include it in all email comms (in the top right of the email body). So if you get an email from what looks like "Crypto.com", but with a different anti-phishing code - then you can be certain that it's phishing.
leevlad commented on Improving first impressions on Signal   signal.org/blog/keeping-s... · Posted by u/feross
MaxGanzII · 4 years ago
I think we may be talking about different PINs.

I am not talking about the PIN you would have to enter when starting Signal, to get into Signal.

I Googled a bit and found an approachable blog post from the time this all happened, here;

https://blog.cryptographyengineering.com/2020/07/10/a-few-th...

This has refreshed my memory of events.

In short, Signal wanted to store what had been purely client-side information (contact lists, for example) on their server, but - in principle at least - in a form Signal could not access.

The PIN in question is used to provide access to that information.

> Server state comment aside, it seems your main complaint is about a pop-up PIN entry UI that can be opted out of?

The dialog to force the user to set the server-side PIN disabled the app. You either had to do it, or stop using Signal. There was no opt-out.

I had a look at the app now. I found the settings you mentioned. It's not clear to me from what I see there is this if an app-locking PIN, a SIM protection PIN, or a server-side state PIN, or all three rolled into one.

In any event, at the time it happened, the presented dialog was full-screen and could not be dimissed; even if there had been options to disable this (and there were not prior to the full-screen dialog - I looked, in an effort to dismiss the permanent partial-screen dialog) you could not get to them, because it was a full-screen dialog which you could not dismiss; you could not get to the app, and so could not get to settings.

The only option was to stop using Signal or provide a PIN so your client-side state could be stored server-side.

leevlad · 4 years ago
Fair. And I think I know what you're referring to.

Yes, they do upload your contact list, but I believe there's a prompt at setup time that allows you to opt out? It might even be an OS-level prompt to the tune of "Signal would like to access your Contacts". Not 100% sure on that one as I haven't set up a brand new Signal installation in years.

It's done to help their user acquisition. It uploads your contacts to match against other contact lists and let you know who's on Signal. I recall seeing a blog post explaining how they are doing it in a fully encrypted way, possibly using Secure Enclave (? though I think the 2021 version of that would probably involve ZK proofs/homomorphic encryption of some kind, and I hope they put some time into that).

I don't recall ever having to set a PIN specifically for that. And besides, a 4-6 digit PIN would be a terribly insecure way to "encrypt" anything server-side :) But yes, that would be a shame if it were the case.

leevlad commented on Improving first impressions on Signal   signal.org/blog/keeping-s... · Posted by u/feross
MaxGanzII · 4 years ago
Signal was superb for a long time, and then received a hefty chunk of funding, and, although I may be wrong, has declined since then, and in fact jumped the shark about a year ago.

They attempted ever more forcefully to make users to set a PIN to protect server-side state; it started with a dialog at the bottom of the screen, obscuring about 20% of the user list, which could not be dimissed, and then after a few weeks progressed to the a full page dialog, which could not be dismissed - rendering the app unusable.

All you saw upon starting was the full page dialog demanding you set a PIN to continue using Signal.

I did not want any server-side state, and so did not set a PIN, and stopped using Signal. After a few weeks, the full-page dialog went away, and I found I could use Signal again.

Signal actually blocked usage of the app to force users to adopt unwanted new functionality. It's hard to imagine any app doing well with such mis-management.

I opened a thread discussing the problem on their support/public discussion forum, which was deleted. I also at first opened a bug report on Git, before I understood it was all intentional, this was also deleted.

Since this experience, I've regarded Signal as on the way out, but it's still the best there is right now.

leevlad · 4 years ago
Correct me if I'm wrong, but I believe your comment is misguided.

The PIN is a security option that prevents a SIM-swapping attacker from registering a new device under your phone number unless they know the PIN. You can opt out of it (and it might be opt-in to begin with). You can also easily opt out of PIN reminders. Both of these options are in Settings -> Account.

As for server state - my understanding is that Signal attempts to be zero-knowledge overall, but they definitely store some state on the server. I believe it's encrypted using your private key that's not backed up to the server. Setting the PIN does not change that.

Server state comment aside, it seems your main complaint is about a pop-up PIN entry UI that can be opted out of? I get that it might seem annoying, but it feels like a fairly weak criticism of a messaging platform, certainly not one that should warrant an impression that Signal is "on the way out"?

leevlad commented on Firefox Multi-Account Containers   addons.mozilla.org/en-US/... · Posted by u/rahuldottech
sebazzz · 6 years ago
Firefox Multi-Account contains are awesome for software development and testing! At my work we usually work at tools which have three roles: user, reviewer, administrator so I generally have three containers for these user accounts. This means I can be logged in with all the accounts I need for testing in the same web browser without resorting to private mode (which does not remember cookies between sessions anyway).

In addition, I use the temporary container add-on[0] which also uses containers, but throws them away after being used (like reference counting).

These two tools have seriously improved my ability to both develop and test applications without the hassle of logging out and logging in all the time or needing any tricks when needing multiple clean browsing sessions.

[0]: https://addons.mozilla.org/en-US/firefox/addon/temporary-con...

leevlad · 6 years ago
A few more usecases that I've added to my workflow since discovering container tabs:

* Work/personal separation

* Multiple AWS accounts

Also, I am very impressed with how well they're integrated into Firefox. For example, opening a link in a new tab will preserve the container. CMD+Shift+T will restore a recently closed tab and remember its original container. I really like the color coding too.

leevlad commented on Firefox Replay   firefox-replay.com/... · Posted by u/nachtigall
_bxg1 · 6 years ago
Very cool, but I'd much prefer they spend their time bringing Firefox's dev tools up to par with Chrome's first. I've tried several times to switch to FF completely, but every time I end up switching back on my work computer because of the dev tools.
leevlad · 6 years ago
Curious to hear what's missing. I do some light front-end work (css/react) and have been fully on Firefox for about a year. Haven't looked back.
leevlad commented on 16-inch MacBook Pro   apple.com/newsroom/2019/1... · Posted by u/0x4542
partisan · 6 years ago
This is the most annoying part of their keyboards.

Didn't copy or didn't paste. Or both.

leevlad · 6 years ago
How do you like pasting a TAB into your text editor/terminal every time you want to switch windows?
leevlad commented on 16-inch MacBook Pro   apple.com/newsroom/2019/1... · Posted by u/0x4542
theturtletalks · 6 years ago
Wait til the CMD key loses responsiveness. Hate having to CMD+V multiple times to paste something. Maybe I should just reprogram the option key or go back to my old Mac where all the keys work flawlessly.
leevlad · 6 years ago
I have lost responsiveness in both my CMD key and the E key. Apple agreed to replace the front panel of my MBP for free, so at least there's that.
leevlad commented on Alphabet in bid to buy Fitbit   reuters.com/article/us-fi... · Posted by u/rubayeet
cordite · 6 years ago
Hmm, I don't suppose they will revive pebble.

https://www.theverge.com/2017/2/22/14703108/fitbit-bought-pe...

leevlad · 6 years ago
One can only dream. It was so far ahead of its time, and I still consider it superior to any smartwatch out on the market. I have mine from 5 years ago that still works great. We need more products like this.
leevlad commented on Firefox 70   hacks.mozilla.org/2019/10... · Posted by u/feross
pedrocx486 · 6 years ago
Compared to current Chromium based browsers (I'm using Edge/ium), how does this Firefox release's DevTools compare?
leevlad · 6 years ago
I do a moderate amount of ReactJS dev, and FF has been excellent. I barely noticed the transition from Chrome to FF when it came to my workflows.
leevlad commented on NordVPN confirms it was hacked   techcrunch.com/2019/10/21... · Posted by u/afshinmeh
chickenpotpie · 6 years ago
I thinking about spinning up a Digital Ocean droplet and rolling my own right now
leevlad · 6 years ago
I'd keep in mind that cloud providers have well-known IP blocks that can sometimes be rate-limited by various internet sites/services, primarily to combat botting. You might inadvertently get caught in the IP range that's being actively rate limited by e.g. Instagram. YMMV.

u/leevlad

KarmaCake day147October 9, 2015View Original