[-] AYO_Official@lemmy.ml 2 points 2 weeks ago

You're getting it wrong this is probably a problem about reading the post from mobile. My previous posts were not that packed with code so it wasn't a big issue but I updated the CSS so it is way more comfortable to read now.

12

cross-posted from: https://lemmy.ml/post/53245270

Last post published was setting up Anubis (the bot protection) because I felt that documentation was lacking. This time I am publishing a "getting started" on Wayland for the same reason.

This guide is about programming a client application showing a window. It is coded in C++ but very close to C so hopefully anyone can read it and implement on their own.

If you find it nice please share the word around, this could help me a lot.

I feel their is not enough in-depth explanation of the whole protocol and there are some crazy caveats (like the most known article this is inspired from would not work on big-endian machine). This took me a lot of time to write and make a "simple" code to test (800 lines file).

22

Last post published was setting up Anubis (the bot protection) because I felt that documentation was lacking. This time I am publishing a "getting started" on Wayland for the same reason.

This guide is about programming a client application showing a window. It is coded in C++ but very close to C so hopefully anyone can read it and implement on their own.

If you find it nice please share the word around, this could help me a lot.

I feel their is not enough in-depth explanation of the whole protocol and there are some crazy caveats (like the most known article this is inspired from would not work on big-endian machine). This took me a lot of time to write and make a "simple" code to test (800 lines file).

[-] AYO_Official@lemmy.ml 3 points 1 month ago

The principle is pretty simple : use a little bit of compute. If you're a bot and want to visit many sites the cost will add up, if you are a human going to a website the 1 second cost for the initial page is not a big deal.

Also notice the difference with the extremely annoying cloudflare checkbox asking if you are a human that became ubiquitous lately. I'd rather wait a second.

[-] AYO_Official@lemmy.ml 3 points 1 month ago

Actually same, this blog is also a nice way for me to document how my server was setup.

I am quiet distro hopping because of ARM based distribution never really working nicely (GPU acceleration, old hardware not being updated). I need to remember what is what and why as my main job is not really taking care of servers but coding.

[-] AYO_Official@lemmy.ml 4 points 1 month ago

Fixed, thanks. Sadly url is *** forever.

37
submitted 1 month ago* (last edited 1 month ago) by AYO_Official@lemmy.ml to c/opensource@lemmy.ml

cross-posted from: https://lemmy.ml/post/52500169

This is a little bit of a wall of text but I hope it will be a nice sample for such a setup.

18
submitted 1 month ago* (last edited 1 month ago) by AYO_Official@lemmy.ml to c/selfhost@lemmy.ml

This is a little bit of a wall of text but I hope it will be a nice sample for such a setup.

[-] AYO_Official@lemmy.ml 4 points 2 years ago

This is were the manifest/permission is important. I cannot emphasize enough that I had to code this myself because, at the time, nothing else would be OK with me. This was because of 1- way too big of a code base, 2- way too many permissions.

It is indeed a problem that extensions are not as well maintained as Linux distribution packages but in this specific instance the extension has no right to read any information nor send requests to any server.

[-] AYO_Official@lemmy.ml 2 points 2 years ago

If you have any concern I would gladly hear technical insight about the threat model involved. The cross-post on the Privacy communities sparked more conversation if you want to follow up on that point : https://lemmy.ml/post/12744864.

Extension "authenticator" has been around for more than a decade now. I am sharing something that is small, simple, auditable and secure (no permission to do anything but past on clipboard).

[-] AYO_Official@lemmy.ml 2 points 2 years ago* (last edited 2 years ago)

There is an irony in password managers that stores your password but need a password (passphrase would be better). A password for your passwords. Fundamentally this is because the only secured space, only you can get in and no one else, is your own brain.

Most password leaks are usually caused by bad implementations on the server side. I have an authentication protocol to avoid many password leakages I'd like to share one day (double salt, one from client, one on server so password is never shared to the server).

[-] AYO_Official@lemmy.ml 2 points 2 years ago

Websites have no way to creep into your browser, extensions included. Usually it is the other way around. Such a leak would be catastrophic for the browser (thinks of all the password manager). At least here it is not even a password manager but only the TOTP so you still have your password as security (still this will never happen realistically).

[-] AYO_Official@lemmy.ml 8 points 2 years ago* (last edited 2 years ago)

Database is encrypted in the local storage of the extension. So far Firefox is secure enough so this is not accessible from outside (it is encrypted anyway). The encryption is using the crypto web API (native from web browser) to use PBKDF2 key. It is decrypted with your password so the database is in RAM (not saved anywhere unencrypted) as long as the browser is open or you click to "logout".

You can export/import all the entries with a simple JSON format (for now, simple "name"+"secret" for each entry). You should encrypt this export file or save it in a encrypted volume yourself.

[-] AYO_Official@lemmy.ml 7 points 2 years ago* (last edited 2 years ago)

Thank you for your constructive comment.

Indeed many people thinks 2FA as 2 devices. I am not sure where that came from and what specifically make people think that way. Despite all my research and experience using 2 devices solve no specific security problem. I think there is a whole topic to be argued on this (should I make a blog post on this?).

As for me I have Aegis on my smartphone (really perfect nothing to say). But I have many unwanted/unnecessary 2FA to go through every day (for the last 3 years). I am cleaning my cookie/connection every time I close my web browser and I am not keeping my computer on all the time. Therefore those 2FA needs to be done a lot (I mean at least 3 time a day). I do not interact much with my smartphone, also this is the least secure device I own so web browser extension is an OK way. I used to have a python script I could have run from one of my IoT through ssh. So far I don't see any vector of attack this would prevent compared to browser extension.

I see hundreds of thousands of users using other extensions that I wouldn't run on my system and I am sharing a better solution, nothing perfect, nothing that requires mass adoption.

[-] AYO_Official@lemmy.ml 14 points 2 years ago

Well this is 600 lines of code, if you cannot audit that you can indeed ignore it for now. Once again this is the only auditable code out there and not asking for unrelated permissions.

45
submitted 2 years ago* (last edited 2 years ago) by AYO_Official@lemmy.ml to c/privacy@lemmy.ml

cross-posted from: https://lemmy.ml/post/12744832

As I updated the version to 1.4.0 , adding the 'import' feature I am sharing this here.

I made this extension because I couldn't find one that wouldn't ask for too much permissions (such as accessing all websites data).

Eventually I found it nice to have a TOTP that can really be audited, the code is 649 lines of JS, 214 CSS and 52 HTML. Feel free to fork, copy part of it, contribute or just request fix/features.

I have used it for more than a year every day and it works nicely.

62
submitted 2 years ago* (last edited 2 years ago) by AYO_Official@lemmy.ml to c/opensource@lemmy.ml

As I updated the version to 1.4.0 , adding the 'import' feature I am sharing this here.

I made this extension because I couldn't find one that wouldn't ask for too much permissions (such as accessing all websites data).

Eventually I found it nice to have a TOTP that can really be audited, the code is 649 lines of JS, 214 CSS and 52 HTML. Feel free to fork, copy part of it, contribute or just request fix/features.

I have used it for more than a year every day and it works nicely.

[-] AYO_Official@lemmy.ml 3 points 3 years ago

Next part is going to be security and some storage off-loading on memory (mostly avoiding logs on storage). Then probably a part 3 on server stack (nginx/apache) and network.

I never encounter this CG/NAT, I'm wondering how it goes with online game for instance (wouldn't it be a no-go for many casual users?). I have set-up once a VPN as a reverse-proxy, buying the lowest tiers of VPS (Virtual Private Server) as it would had a public IP to use and just forward everything to the server (which was in a shared space so kind of the same as CG/NAT). This is not 100% host but at least the VPS is just a gateway and doesn't hold anything and is easily replaceable.

15
submitted 3 years ago by AYO_Official@lemmy.ml to c/selfhost@lemmy.ml

I am making a series of blog posts about website and application hosting. There are many topics I'd like to talk about (IP, DNS, logs, linux settings). I am sharing here some knowledge and documenting for myself too.

This first post is not the most interesting in my opinion as this is talking about the basis : hardware and Linux distribution. I am not talking about non-Linux OS (OpenBSD, FreeBSD, etc). For the next one I will document way more commands and process to go through (iptable, fail2ban, logs on memory, etc).

I don't consider myself good at writing so any help is welcome, I try to put as many images/charts as possible but this one is tricky. Feedbacks are welcome.

view more: next ›

AYO_Official

0 post score
0 comment score
joined 3 years ago