You're missing that HTTP-01 challenge grants you no ability beyond what the check has demonstrated, i.e. you have proven that you're able to serve random file from a webserver, so the grant is to allow you to serve them via TLS connection.
There are no comparable _technical_ proof-of-registration methods because all of them would require actual access to registrar control panel and be outright silly ('point the domain to a random nameserver').
So no, proper registrars never use webserver control as means to prove identity or ownership.
Webserver control is never used and must not be used to prove domain ownership. If you're pwned and have to re-point to a server stood up from backup, having registrar relying on someone being able to put up a random file on a compromised machine would be a total security disaster.
I don't really get why you need handoff if your score is accurate. If it is, and it is low for a given response, just let the harness re-run the prompt with a different seed until the score is high enough. If this approach doesn't work, your score is most likely garbage.
Love: I truly have redundancy for most critical accounts, meaning I have 4 separate passkeys assigned, each not tied to one SPoF -- one in 1Password, one in iCloud -- both synced everywhere I logged in and if I'm ever banned/locked out of both of them somehow, I still have two additional USB keys (token2) as a fallback.
Hate: every fucking service seems to have different idea on how to implement them, whether to allow them as the only factor, how many to allow to have in any particular account.
On a separate note, for the hw side of things I'm kinda sad that old yubikey nano approach when the token is just sitting flush on the side of the laptop and I tap it occasionally is just dead, because every vendor moved to mandatory PIN to store passkeys on hardware tokens. I get the rationale but still.
> I never understood the popularity of Tailscale, though that is on me.
> I guess self hosting Wireguard is too boring to warrant any further discussion?
It's popular because you don't have to deal with NAT punching. It "just works", all the time. And Wireguard is not too boring, it's just not enough on its own.
I'm all for self-hosting and this is exactly why I prefer to use Tailscale and not have to manage jump-hosts and STUN points on some cloud, given that I won't be able to make it as reliable as Tailscale and as cheap as Tailscale (effectively $0). So this is literally the only tradeoff I made while self-hosting everything else.
- well-designed apps retain enough state to be useful offline or in places with spotty coverage; PWAs can kinda be made to work like this but IIRC iOS will happily evict them under disk pressure;
- notifications. I've read that Apple have implemented them for home screen installed web apps but for reasons unknown I have not seen this in action even once.
Not really. The incentive is to make you hooked on the process, so you bring the same process to the workplace, and start paying corporate prices, not individual subscription prices. For that to work Claude Code, prompt, and the rest of the mechanics has to be more or less uniform.
What is the incentive for me to join the public mesh? Do you have any fairness guarantees, e.g. if I contribute 1/8th of the VRAM required to run a particular model, do I get at least 1/16th of the inference share, or anything similar to this?
I've settled on using .internal and Knot as a authoritative NS, step CA + ACME to issue short-lived certs, and a Split DNS resolver from Tailscale as the only external dependency (mostly as a convenience for when I'm on the road).
I do have a luxury of all the homelab VMs being rebuildable via IaC, so I've just injected CA trust at that step.
The biggest PITA so far were 3rd party docker images, each with its own way to inject custom CA.
There are degrees to "AI contributors". E.g. recently I have stumbled upon rare edge case in an OSS tool written in Rust. It would have taken me a week+ to be able to contribute a minor change in a clean and Rust-idiomatic way as this is not the language I'm proficient in, and Claude did that in 1 hour, with 3 or 4 rounds of tweaks from me to reduce the walls of text and make the contribution matching the of the original project. Alternative was just swiping it under the rug or opening an issue instead (thus placing the burden on the maintainer).
I do think I helped out.
And I have discovered this edge case when fiddling with my homelab which is my hobby.
Lexa (to be more precise, Lyoha) is a shortened version of Alexey (Aleksei); but if it wasn't reserved for that, Lyoha sounds a bit rude (and a more gentle version akin to Sasha would be Lyosha).
- DNS block & SNI filtering: I expect BrightData to rotate the endpoints if this issues gains enough attention. It will take some time once all the apps embedding the SDK catch up, but if they're smart SDK may already have a backup C&C connection they will try to reach out to after prolonged unavailability of the current endpoints.
- TLS fingerprint: unless SDK pins it, it's the cheapest one to rotate continously.
- MDM solution: almost unattainable to private users; not clear how stable the SDK name is to rely on.
Not saying I have a better approach. It seems behavior like this should be explicitly banned on Apple/Google's side with immediate termination of their publisher accounts.
I tried Darktable and I don't doubt it's a powerful RAW editing software but it feels like to be effective with it you need to care about the software more than you do about photography. With Lightroom/Capture One etc. it's the opposite. Darktable is just too 'out there'
But if you somehow managed to do that, no one in the right mind would argue that you're free to undelegate the domain or point it to a NS you control.