<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: tiberious726</title><link>https://news.ycombinator.com/user?id=tiberious726</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 18 Apr 2026 09:21:35 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=tiberious726" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by tiberious726 in "Put your SSH keys in your TPM chip"]]></title><description><![CDATA[
<p>> TPM isn't for "security" in the abstract, it's fundamentally for authentication<p>What on earth do you think I make my users present keys for???<p>You know all those guides saying "you should never copy an ssh private key over the network. Make a new one for each device" that every idiot dev ignored? Now I can enforce that.</p>
]]></description><pubDate>Thu, 16 Apr 2026 20:09:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=47798820</link><dc:creator>tiberious726</dc:creator><comments>https://news.ycombinator.com/item?id=47798820</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47798820</guid></item><item><title><![CDATA[New comment by tiberious726 in "Put your SSH keys in your TPM chip"]]></title><description><![CDATA[
<p>This article's method is bad, basically the same as systemd-creds (not itself bad, just extremely compatible), take a look at tpm-ssh-agent or gnupg for how to do that part the right way (the party they don't do right is bind/sign to pcrs, which is just low hanging fruit in today's day and age...)</p>
]]></description><pubDate>Thu, 16 Apr 2026 20:07:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=47798797</link><dc:creator>tiberious726</dc:creator><comments>https://news.ycombinator.com/item?id=47798797</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47798797</guid></item><item><title><![CDATA[New comment by tiberious726 in "Put your SSH keys in your TPM chip"]]></title><description><![CDATA[
<p>If you run into the link to this, is love to read it. Proper, modern, pcrphase binding with a signing key should remove these firmware update issues irt the raw pcr value changing</p>
]]></description><pubDate>Thu, 16 Apr 2026 20:04:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=47798757</link><dc:creator>tiberious726</dc:creator><comments>https://news.ycombinator.com/item?id=47798757</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47798757</guid></item><item><title><![CDATA[New comment by tiberious726 in "Put your SSH keys in your TPM chip"]]></title><description><![CDATA[
<p>The authors of both this article and ssh-tpm-agent (disjoint set) really need to learn about pcrphases and the signing keys therefor: <a href="https://github.com/Foxboron/ssh-tpm-agent/issues/15" rel="nofollow">https://github.com/Foxboron/ssh-tpm-agent/issues/15</a></p>
]]></description><pubDate>Thu, 16 Apr 2026 19:52:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=47798613</link><dc:creator>tiberious726</dc:creator><comments>https://news.ycombinator.com/item?id=47798613</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47798613</guid></item><item><title><![CDATA[New comment by tiberious726 in "FSF trying to contact Google about spammer sending 10k+ mails from Gmail account"]]></title><description><![CDATA[
<p>I set up my orgs SPF/DKIM/DMARC (we self host, they have feelings about corporate data sovereignity...) it look about 30 min having never touched them before, and maybe another 15 to write an ansible playbook to rotate the keys.<p>We do have a _tremendous_ amount of spam fail these checks, as well as a few legitimate organizations.... Some of our peer companies have sent out notices that they will bounce anything that fail these checks in the coming years, and we're probably going to to do the same before too long.<p>It's trivially easy, and absolutely valuable</p>
]]></description><pubDate>Thu, 16 Apr 2026 18:37:48 +0000</pubDate><link>https://news.ycombinator.com/item?id=47797627</link><dc:creator>tiberious726</dc:creator><comments>https://news.ycombinator.com/item?id=47797627</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47797627</guid></item><item><title><![CDATA[New comment by tiberious726 in "Show HN: BAREmail ʕ·ᴥ·ʔ – minimalist Gmail client for bad WiFi"]]></title><description><![CDATA[
<p>Random web apps are not. Imap pop and smtp don't sanely support mfa, so the insurance industry is slowly killing them off</p>
]]></description><pubDate>Wed, 08 Apr 2026 16:47:27 +0000</pubDate><link>https://news.ycombinator.com/item?id=47692751</link><dc:creator>tiberious726</dc:creator><comments>https://news.ycombinator.com/item?id=47692751</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47692751</guid></item><item><title><![CDATA[New comment by tiberious726 in "curl > /dev/sda: How I made a Linux distro that runs wget | dd"]]></title><description><![CDATA[
<p>It whines about licensing, but I switch between booting my windows installation bare metal and as a VM all the time</p>
]]></description><pubDate>Wed, 25 Mar 2026 22:21:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=47524056</link><dc:creator>tiberious726</dc:creator><comments>https://news.ycombinator.com/item?id=47524056</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47524056</guid></item><item><title><![CDATA[New comment by tiberious726 in "Google details new 24-hour process to sideload unverified Android apps"]]></title><description><![CDATA[
<p>I still use emacs gnus with Gmail. You need a token instead of old fashioned imap auth, but it works fine</p>
]]></description><pubDate>Fri, 20 Mar 2026 22:20:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=47461473</link><dc:creator>tiberious726</dc:creator><comments>https://news.ycombinator.com/item?id=47461473</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47461473</guid></item><item><title><![CDATA[New comment by tiberious726 in "Babylon 5 is now free to watch on YouTube"]]></title><description><![CDATA[
<p>Still trying to figure out how it's related to B5</p>
]]></description><pubDate>Sat, 14 Feb 2026 22:14:46 +0000</pubDate><link>https://news.ycombinator.com/item?id=47018941</link><dc:creator>tiberious726</dc:creator><comments>https://news.ycombinator.com/item?id=47018941</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=47018941</guid></item><item><title><![CDATA[New comment by tiberious726 in "Unix Hater's Handbook Stinks"]]></title><description><![CDATA[
<p>Genera would like to have a word</p>
]]></description><pubDate>Sat, 15 Nov 2025 19:34:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=45939971</link><dc:creator>tiberious726</dc:creator><comments>https://news.ycombinator.com/item?id=45939971</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45939971</guid></item><item><title><![CDATA[New comment by tiberious726 in "Steam Machine"]]></title><description><![CDATA[
<p>You mean valve's?</p>
]]></description><pubDate>Wed, 12 Nov 2025 19:59:05 +0000</pubDate><link>https://news.ycombinator.com/item?id=45905552</link><dc:creator>tiberious726</dc:creator><comments>https://news.ycombinator.com/item?id=45905552</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45905552</guid></item><item><title><![CDATA[New comment by tiberious726 in "Stop 'reactions' to email by adding a postfix header (2024)"]]></title><description><![CDATA[
<p>Yes</p>
]]></description><pubDate>Sun, 02 Nov 2025 13:20:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=45790112</link><dc:creator>tiberious726</dc:creator><comments>https://news.ycombinator.com/item?id=45790112</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45790112</guid></item><item><title><![CDATA[New comment by tiberious726 in "Government Urges Total Ban of Our Most Popular Wi-Fi Router"]]></title><description><![CDATA[
<p>Anything with an sfp slot and a decent "optic" should blow tp-link's link stability out of the water. In about the same price range, have you tried mikrotik?</p>
]]></description><pubDate>Fri, 31 Oct 2025 22:55:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=45777615</link><dc:creator>tiberious726</dc:creator><comments>https://news.ycombinator.com/item?id=45777615</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45777615</guid></item><item><title><![CDATA[New comment by tiberious726 in "IDEs we had 30 years ago and lost (2023)"]]></title><description><![CDATA[
<p>In unconfigured emacs, you can literally just go Buffer>Save in the toolbar. If you didn't know to look in the buffer menu, then you didn't read even a little bit of the tutorial that appears when you open it</p>
]]></description><pubDate>Mon, 20 Oct 2025 17:30:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=45646628</link><dc:creator>tiberious726</dc:creator><comments>https://news.ycombinator.com/item?id=45646628</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45646628</guid></item><item><title><![CDATA[New comment by tiberious726 in "I am giving up on Intel and have bought an AMD Ryzen 9950X3D"]]></title><description><![CDATA[
<p>The extra unused memory might even act as shielding to cosmic rays, but the extra electrical load on the memory controller might more than balance that out for unbuffered sticks</p>
]]></description><pubDate>Sun, 14 Sep 2025 21:14:29 +0000</pubDate><link>https://news.ycombinator.com/item?id=45243296</link><dc:creator>tiberious726</dc:creator><comments>https://news.ycombinator.com/item?id=45243296</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45243296</guid></item><item><title><![CDATA[New comment by tiberious726 in "GrapheneOS and forensic extraction of data (2024)"]]></title><description><![CDATA[
<p>Seedvault is the /worst/. I ranted about it here a few months ago, and the lead dev says he's aware they really need something better: <a href="https://news.ycombinator.com/item?id=42541520">https://news.ycombinator.com/item?id=42541520</a></p>
]]></description><pubDate>Sun, 14 Sep 2025 20:54:36 +0000</pubDate><link>https://news.ycombinator.com/item?id=45243156</link><dc:creator>tiberious726</dc:creator><comments>https://news.ycombinator.com/item?id=45243156</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45243156</guid></item><item><title><![CDATA[New comment by tiberious726 in "Ask HN: The government of my country blocked VPN access. What should I use?"]]></title><description><![CDATA[
<p>Exactly this. Hell, for OP's use case of accessing things like twitter, a good old fashioned https proxy would be entirely fine, and likely not even illegal.</p>
]]></description><pubDate>Fri, 29 Aug 2025 00:13:04 +0000</pubDate><link>https://news.ycombinator.com/item?id=45058475</link><dc:creator>tiberious726</dc:creator><comments>https://news.ycombinator.com/item?id=45058475</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45058475</guid></item><item><title><![CDATA[New comment by tiberious726 in "Sam Altman now says AGI, or human-level AI, is 'not a super useful term'"]]></title><description><![CDATA[
<p>Didn't the terms of that deal define AGI as "an AI that generates at least 1 billion in annual revenue"?</p>
]]></description><pubDate>Wed, 13 Aug 2025 12:39:53 +0000</pubDate><link>https://news.ycombinator.com/item?id=44887726</link><dc:creator>tiberious726</dc:creator><comments>https://news.ycombinator.com/item?id=44887726</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44887726</guid></item><item><title><![CDATA[New comment by tiberious726 in "Managing EFI boot loaders for Linux: Controlling secure boot (2015)"]]></title><description><![CDATA[
<p>If you use the -m flag with enroll-keys, won't that also load the MS keys, which the Nvidia firmware should be signed by, allowing verification to pass?</p>
]]></description><pubDate>Wed, 23 Jul 2025 20:53:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=44663923</link><dc:creator>tiberious726</dc:creator><comments>https://news.ycombinator.com/item?id=44663923</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44663923</guid></item><item><title><![CDATA[New comment by tiberious726 in "Linux and Secure Boot certificate expiration"]]></title><description><![CDATA[
<p>Eh, that's basically what we have now with boards where you can delete the MS keys and enroll your own. Just with different defaults and no support nightmare</p>
]]></description><pubDate>Mon, 21 Jul 2025 16:53:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=44637418</link><dc:creator>tiberious726</dc:creator><comments>https://news.ycombinator.com/item?id=44637418</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44637418</guid></item></channel></rss>