• 0 Posts
  • 93 Comments
Joined 2 years ago
cake
Cake day: April 24th, 2023

help-circle
  • They might’ve done so out of necessity. I don’t know if the dev(s) of the Simple Tools apps were working on it full time, but if they were and just not enough contributions were coming in from it… Well everyone has to eat.

    As the saying goes, “everyone has their price”. It’s easy to condemn the developers for their choice until you’re in the exact same scenario as they were. Whether that’s because they were starving, or even just offered enough money to make their lives a lot easier - not too many people would turn it down.


  • Ah I see, that’s unfortunate then. For what its worth, I still think the bot is a great idea for discoverability and bridging the two services together! I hadn’t seen it before since I usually have bot users muted and happened to see this comment chain while logged out.

    I’ve given it a follow from my Mastodon account since I do tend to miss quite a few cool Lemmy posts it seems, and I think it’ll help me find some communities in general that I’ll want to subscribe to from over here.





  • Precisely, yep! It follows the same rules as subscribing to communities on Lemmy however - if you’re the first on an instance to subscribe, it may not pull the full backlog of videos - and at least one person needs to be subscribed for the instance to continue getting updates from the channel.

    Try heading to !thelinuxexperiment_channel@tilvids.com for example, and you’ll see Nick’s channel come up as a community and each video that they upload will be its own “post”.

    Note that when you lookup stuff on PeerTube, you have to use the channel name - not the uploader’s username. So the one I linked would work, but if you replaced the start with thelinuxexperiment it wouldn’t work, since that is a user and not a channel.





  • Continuing on what Rolling Resistance said (sorry for the delay, had to step away for a while), I know plenty of people who do use a password manager and still use a static password in some places (hell, I’ve been guilty of that in a few places - but generally on network-isolated systems). Some people also don’t use 2FA because they find it inconvenient.

    Passkeys are more or less very similar to how SSH keys work if you’re familiar with those, your device (or password manager) generates a secret key that it only has access to, and then gives the public key to the website (and a new keypair is generated for every single website). When you login to a website, the website sends you a challenge which you sign with your private key, that the website can then verify using the public key that you used when enrolling the passkey. This way, a website never has any form of secret - making say password hash leaks less relevant, whereas in theory you could give your public key(s) and post it on Google’s homepage without any repercussions… but don’t quote me on that one.

    So even if you use a password manager, if you still have a few websites that share the same password, and one of those gets compromised - those other websites may still be vulnerable which wouldn’t be possible with a passkey.





  • Have you found any other decent online-centric banks to switch to? I’ve been wanting to switch away from ONE for pretty much the reasons you listed, but through a basic search I didn’t see anything else to was too appealing to me.

    And the 2FA thing is ridiculous, at one point they didn’t actually have the email option (or it was very well hidden) - had a bit of a rough month at some point and wasn’t able to pay my phone bill which got it suspended, I also happened to have my card locked and got kicked out of the app so… I couldn’t unblock my card to pay the phone bill, which I needed to get the 2FA code to login in… Ended up having to reach out to support and they were able to show me how to request a 2FA code over email.

    This wouldn’t even be a problem with most sites because I always use TOTP/Webauthn via my Yubikey when I have the option, and for something as critical as my bank account I really do not want SMS/Email to be an option for 2FA (I get why they have it, but I’d like to be able to turn it off for my account).







  • Yes, although like someone else mentioned - I don’t, and ever wouldn’t try to host it at home, but on a server at a data center. The network is operated by a person I know and trust.

    No IP reputation issues that I’ve run into, but even going in I knew that its very rare I send emails so it probably wasn’t going to be an issue either way. I’ve only had it running for about two years now, but in that time frame I’ve sent one email out where I “started the conversation”, and three emails where I was replying back to someone who already had my email in their address book.