<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: kenniskrag</title><link>https://news.ycombinator.com/user?id=kenniskrag</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Thu, 18 Jun 2026 10:23:21 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=kenniskrag" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by kenniskrag in "DNSSEC disruption affecting .de domains – Resolved"]]></title><description><![CDATA[
<p>acme.sh supports multiple CAs there is even a RFC for CAs that describe the api.</p>
]]></description><pubDate>Wed, 06 May 2026 09:15:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=48034071</link><dc:creator>kenniskrag</dc:creator><comments>https://news.ycombinator.com/item?id=48034071</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48034071</guid></item><item><title><![CDATA[New comment by kenniskrag in "DNSSEC disruption affecting .de domains – Resolved"]]></title><description><![CDATA[
<p>I would define high as "double time needed to fix a dns issue" and account for weekends</p>
]]></description><pubDate>Wed, 06 May 2026 09:14:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=48034061</link><dc:creator>kenniskrag</dc:creator><comments>https://news.ycombinator.com/item?id=48034061</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48034061</guid></item><item><title><![CDATA[New comment by kenniskrag in "Microsoft Edge stores all passwords in memory in clear text, even when unused"]]></title><description><![CDATA[
<p>What's the threat model. Where do you store the decryption key?<p>E.g. if my app needs a db connection I can ask a vault service but I need creds for that. The vault service can rotate the creds very fast but is it addition security.</p>
]]></description><pubDate>Tue, 05 May 2026 05:45:52 +0000</pubDate><link>https://news.ycombinator.com/item?id=48018533</link><dc:creator>kenniskrag</dc:creator><comments>https://news.ycombinator.com/item?id=48018533</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48018533</guid></item><item><title><![CDATA[New comment by kenniskrag in "Microsoft Edge stores all passwords in memory in clear text, even when unused"]]></title><description><![CDATA[
<p>Edit:<p>Banking has no selfservice password reset. A lot of work for customer support due to identification. Nobody wants to do that for free and if the accounts are freenyou may get DOSed by bots which trigger passwort resets.</p>
]]></description><pubDate>Tue, 05 May 2026 05:42:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=48018515</link><dc:creator>kenniskrag</dc:creator><comments>https://news.ycombinator.com/item?id=48018515</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48018515</guid></item><item><title><![CDATA[New comment by kenniskrag in "Microsoft Edge stores all passwords in memory in clear text, even when unused"]]></title><description><![CDATA[
<p>> But then your hardware dies<p>A lot of services have password reset email features. If the email account has passkey you're screwed. But restore by snail mail can be possible but slow (for paid services). More secure? Don't know but same category of problems already known due to sim swapping attacks in mobile sector. But for sure the Mail account is a high value target.<p>Storing passkeys in a database may be possible but complex to do it right e.g. backup verification, avoiding to leak while backup etc.</p>
]]></description><pubDate>Tue, 05 May 2026 05:40:22 +0000</pubDate><link>https://news.ycombinator.com/item?id=48018498</link><dc:creator>kenniskrag</dc:creator><comments>https://news.ycombinator.com/item?id=48018498</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=48018498</guid></item><item><title><![CDATA[New comment by kenniskrag in "Mastodon: Don't use "Mastodon" or "mstdn" in domain names"]]></title><description><![CDATA[
<p>Pull request to notify on setup (2 weeks old):
<a href="https://github.com/mastodon/mastodon/pull/38548" rel="nofollow">https://github.com/mastodon/mastodon/pull/38548</a></p>
]]></description><pubDate>Thu, 16 Apr 2026 17:25:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=47796671</link><dc:creator>kenniskrag</dc:creator><comments>https://news.ycombinator.com/item?id=47796671</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47796671</guid></item><item><title><![CDATA[Mastodon: Don't use "Mastodon" or "mstdn" in domain names]]></title><description><![CDATA[
<p>Article URL: <a href="https://github.com/mastodon/mastodon/discussions/22785">https://github.com/mastodon/mastodon/discussions/22785</a></p>
<p>Comments URL: <a href="https://news.ycombinator.com/item?id=47796358">https://news.ycombinator.com/item?id=47796358</a></p>
<p>Points: 4</p>
<p># Comments: 8</p>
]]></description><pubDate>Thu, 16 Apr 2026 17:05:28 +0000</pubDate><link>https://github.com/mastodon/mastodon/discussions/22785</link><dc:creator>kenniskrag</dc:creator><comments>https://news.ycombinator.com/item?id=47796358</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47796358</guid></item><item><title><![CDATA[New comment by kenniskrag in "State of Homelab 2026"]]></title><description><![CDATA[
<p>Is that legal? Do you avoid uploading somehow?</p>
]]></description><pubDate>Mon, 13 Apr 2026 05:23:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=47747918</link><dc:creator>kenniskrag</dc:creator><comments>https://news.ycombinator.com/item?id=47747918</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47747918</guid></item><item><title><![CDATA[New comment by kenniskrag in "Password managers less secure than promised"]]></title><description><![CDATA[
<p>Not if the advertise zero knowledge encryption. As far as I understand the password sharing / collaboration feature is often the problem.<p>Second: The provider can get the passwords with a simple server change.</p>
]]></description><pubDate>Sat, 21 Feb 2026 22:59:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=47105846</link><dc:creator>kenniskrag</dc:creator><comments>https://news.ycombinator.com/item?id=47105846</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47105846</guid></item><item><title><![CDATA[New comment by kenniskrag in "Password managers less secure than promised"]]></title><description><![CDATA[
<p>> Much like the other products we analyse, 1Password lacks
authentication of public keys. This trivially enables sharing
attacks similar to BW09, LP07 and DL02, something that the
1Password whitepaper...<p>> IMPACT. Complete compromise of vault confidentiality and
integrity. The adversary can read and decrypt all vault con-
tents encrypted after the attack, including passwords, credit
card information, secure notes, and other sensitive data stored
in the vault. Similarly, they can inject new items into the vault
after the attack.
REQUIREMENTS. The client fetches key material from the
server, for example due to the user logging in on a new device.
If executed on a non-empty vault, the attack results in the
client losing access to all items already in their vault, while
leaking any new items added to the vault after the attack took
place. If the attack is executed at the time of vault creation,
the attack is effectively undetectable by the client, since it
cannot distinguish between a ciphertext it created and the
ciphertext created by the server during the attack.
PROPOSED MITIGATION. A straightforward mitigation is to
have the client sign vault keys using the RSA private key in
the keyset before encrypting them with the RSA public key.
Ideally, two different key pairs would be used for...<p>from the paper: <a href="https://eprint.iacr.org/2026/058.pdf" rel="nofollow">https://eprint.iacr.org/2026/058.pdf</a></p>
]]></description><pubDate>Sat, 21 Feb 2026 22:54:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=47105780</link><dc:creator>kenniskrag</dc:creator><comments>https://news.ycombinator.com/item?id=47105780</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47105780</guid></item><item><title><![CDATA[New comment by kenniskrag in "Discord Alternatives, Ranked"]]></title><description><![CDATA[
<p>In europe you need identification to buy a sim or esim.<p><a href="https://www.reddit.com/r/europe/comments/9ziqfi/european_countries_requiring_registration_of/" rel="nofollow">https://www.reddit.com/r/europe/comments/9ziqfi/european_cou...</a></p>
]]></description><pubDate>Tue, 10 Feb 2026 11:04:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=46958084</link><dc:creator>kenniskrag</dc:creator><comments>https://news.ycombinator.com/item?id=46958084</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=46958084</guid></item><item><title><![CDATA[New comment by kenniskrag in "Supreme Court wants US input on whether ISPs should be liable for users' piracy"]]></title><description><![CDATA[
<p>> online access is as necessary as water
We have paper money and also can work and buy stuff offline.<p>I would say online access is as necessary as a car. Possible without but less flexible.</p>
]]></description><pubDate>Tue, 26 Nov 2024 10:56:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=42244573</link><dc:creator>kenniskrag</dc:creator><comments>https://news.ycombinator.com/item?id=42244573</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42244573</guid></item><item><title><![CDATA[New comment by kenniskrag in "Supreme Court wants US input on whether ISPs should be liable for users' piracy"]]></title><description><![CDATA[
<p>Driving licence is a bad argument because there is public transportation service. If you're reckless or have other issues the licence is revoked.</p>
]]></description><pubDate>Tue, 26 Nov 2024 10:53:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=42244557</link><dc:creator>kenniskrag</dc:creator><comments>https://news.ycombinator.com/item?id=42244557</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42244557</guid></item><item><title><![CDATA[New comment by kenniskrag in "We are shutting down Ondsel"]]></title><description><![CDATA[
<p>One reason was, that the security model wasn't enough anymore. E.g. every application was trusted and can listen to key inputs e.g. steal passwords and credit card infos. Btw there was an issue that screenshotting in wayland was not possible. But easy in X11 because everything was visible.<p>Don't know much about the architecture about wayland but I think grahic driver handling changed in wayland too.</p>
]]></description><pubDate>Mon, 18 Nov 2024 12:15:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=42171728</link><dc:creator>kenniskrag</dc:creator><comments>https://news.ycombinator.com/item?id=42171728</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=42171728</guid></item><item><title><![CDATA[New comment by kenniskrag in "Andrew S. Tanenbaum Receives ACM Software System Award"]]></title><description><![CDATA[
<p>One of these: <a href="https://media.pearsoncmg.com/bc/abp/cs-resources/products/series.html#series,series=Tanenbaum" rel="nofollow">https://media.pearsoncmg.com/bc/abp/cs-resources/products/se...</a></p>
]]></description><pubDate>Sat, 22 Jun 2024 19:23:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=40761440</link><dc:creator>kenniskrag</dc:creator><comments>https://news.ycombinator.com/item?id=40761440</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40761440</guid></item><item><title><![CDATA[New comment by kenniskrag in "Please support "skip to main content" on your docs site"]]></title><description><![CDATA[
<p>qutebrowser does that.<p><a href="https://en.m.wikipedia.org/wiki/Qutebrowser" rel="nofollow">https://en.m.wikipedia.org/wiki/Qutebrowser</a></p>
]]></description><pubDate>Tue, 04 Jun 2024 03:33:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=40570423</link><dc:creator>kenniskrag</dc:creator><comments>https://news.ycombinator.com/item?id=40570423</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40570423</guid></item><item><title><![CDATA[New comment by kenniskrag in "Claude is now available in Europe"]]></title><description><![CDATA[
<p>Which ones? I try to learn how these systems work</p>
]]></description><pubDate>Tue, 14 May 2024 11:03:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=40353830</link><dc:creator>kenniskrag</dc:creator><comments>https://news.ycombinator.com/item?id=40353830</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40353830</guid></item><item><title><![CDATA[New comment by kenniskrag in "Looo.lol – a binary math site"]]></title><description><![CDATA[
<p>You can edit the url to use any number. :)</p>
]]></description><pubDate>Sat, 06 Jan 2024 00:48:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=38887093</link><dc:creator>kenniskrag</dc:creator><comments>https://news.ycombinator.com/item?id=38887093</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38887093</guid></item><item><title><![CDATA[New comment by kenniskrag in "We don't have official RSS feed support for now, but we're working on a solution"]]></title><description><![CDATA[
<p>which rss reader do you use?</p>
]]></description><pubDate>Mon, 11 Dec 2023 13:03:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=38600281</link><dc:creator>kenniskrag</dc:creator><comments>https://news.ycombinator.com/item?id=38600281</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38600281</guid></item><item><title><![CDATA[New comment by kenniskrag in "Untrusted Device Encryption"]]></title><description><![CDATA[
<p>Generally it depends on the threat vector.<p>* Do you trust the hardware<p>* Do you trust the OS<p>* Do you trust the user<p>* Do you trust the software<p>On a rootkit you don't trust the OS anymore. So a safe location inside the OS space isn't an option anymore. But often you are not a root user (e.g. android, windows in a corporate environment)<p>If you have OS backups there is a risk it is readable by others (e.g. cloud, different IT department). There is also a risk a user uploads the config somewhere.<p>If you want to rotate keys you would have to search all keys compared to a centralized location.</p>
]]></description><pubDate>Thu, 07 Dec 2023 10:21:00 +0000</pubDate><link>https://news.ycombinator.com/item?id=38554867</link><dc:creator>kenniskrag</dc:creator><comments>https://news.ycombinator.com/item?id=38554867</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=38554867</guid></item></channel></rss>