I moved from San Francisco to South Florida as an experiment in being fully remote. It's been pretty good so far, but if I was looking for another job, I'd hit up everyone I know in SF for a remote position first.
There aren't many like-minded people here, and that's kind of nice for a change. I still love San Francisco, but it simply priced me out of living there. I'd rather retire in 5 years here than work another 30 there.
How would that help though? If you have a compromised USB interface, and you're entering your pin on that machine, you could just capture the keyboard input anyway.
> To remove the transmission and on-card storage of OpenPGP PINs in plain text, the YubiKey supports the Key Derived Function (KDF) functionality. With the KDF function enabled, the PIN is stored as a hash on the YubiKey. When entering the PIN to the OpenPGP Smart Card, the OpenPGP client will only pass the hashed value, never passing the PIN directly. KDF functionality is set on the card itself, and communicated to the client; it is transparent to the user. Should the KDF functionality not be enabled, the PIN function will work as previously. The KDF function is listed in section 4.3.2 of the OpenPGP Smart Card 3.4 spec.
Can someone explain to me how KDF matters at all here?
It seems like the keys are encrypted on the yubikey via pin, or at least protected in hardware via pin, and that the pin is stored on the device. KDF seems to take that plain text pin and replace it with a hashed pin. If you steal my yubikey, it looks like KDF would prevent you from... dumping the PIN? But if you could dump the pin, wouldn't you just dump the key instead? I can't seem to figure out the threat model for this feature.
That does sound awful. Here's what I do: block all ads.
I can't stop the data collection, but I can stop ads. If I ever see an ad, I stop what I'm doing and figure out how to remove that ad from my life forever.
So yeah, I'm fully tracked, and I have no privacy, but at least I'm not being influenced by the ads that come from processing all my data.
I also try to block as much data collection as possible, but I realize that's not fully in my control.
As best as I can tell from this thread, if you make use of any service in any way that could be interpreted as unintended by the service provider, you're a criminal.
It makes me wonder if using 1.1.1.1 on my network is a crime. Sure my ISP is letting my DNS queries through, but think of all the analytics that they're missing about me.
Is it also theft if I run sshd on udp 53 and I happen to be able to connect?
How about if I run sshd on tcp 22 and it's not blocked?
Is it illegal if I just want to see if a dns change I made has propagated and I query an A record?
It seems obvious (to me) that a judge would say "It's not theft if you're giving it away. If you have a problem with how people are using your free service, add restrictions. Case dismissed."
I would hope that the court uses their human brain to make a judgment of my intent and the intent of the service provider. My intent is to have free DNS access to communicate with my server. The service provider intended to provide a public access point with free DNS and no restrictions on its use. The conclusion should be obvious.
I'm floored that this is apparently how people are reasoning about the world now. Especially on HN.
There is no circumventing of any access control here. If a service is giving a public access point, on public spectrum, and they let you connect, and they allow you to use DNS, you should be able to use DNS however their access control systems allow you to use it.
Now if you find an exploit in their captive portal that allows you access to their service, then sure, that's illegal, because you're breaking into something.
You can't circumvent access controls if the access control list is wide open.
Or even just let those users alone. Users aren't stealing service if it's not even the same service. It's much slower than buying wifi from the captive portal.
DNS tunnelling is not fast or convenient. Places deploying captive portals have probably looked at the risk to their business from it and have decided not to worry about it.
I can't believe that using a slow DNS connection, intentionally made public, to tunnel traffic would be considered theft or criminal.
How many free samples do I have to eat before I'm a theif? I don't believe I'm a thief until the offer for free samples is rescinded.
How can it be theft of service when they can deny you service at any time automatically by identifying abnormally heavy users and removing them?
This isn't like bypassing the electrical grid by running your own line from somebody else's service.
This is like saying it's theft of service to read a chapter in the bookstore. If you hang out there all day, you might get kicked out, but that's not a crime.
The courts might agree with you, but only because "computers are hard".
There's a world of difference between tunneling over DNS and compromising servers. Or at least, there should be.
> Note: this is most likely illegal .. in every jurisdiction. So .. don't actually do this.
Sad if true. If a service is providing public DNS access without any service agreement, I don't see how making DNS queries with it could be illegal, especially on a public radio channel.
You might be right, but how?
It's certainly within their right to ban you by filtering out certain queries though.
Just out of curiosity, why awk? I've only ever used it for simple text splitting and didn't really know people did more with it. Is it a tool worth learning?
I've had fantastic experience with airvpn. They're cheap, fast, reliable, and support all the configuration types you could want. I'm not affiliated with them but I'm surprised nobody here has mentioned them yet. By far the best VPN provider IMO.