Skip Navigation
andreluis034 andreluis034 @lm.put.tf

Admin of lm.put.tf, there isn't anything special there, just an instance for friends.

Posts 2
Comments 35
How many of you run a Linux phone (Pine64, Librem etc) as your daily driver?
  • Wouldn't unlocking the bootloader and installing a custom ROM be easier, more stable and cheaper than buying a niche product that's unlikely to work properly?

  • How many of you run a Linux phone (Pine64, Librem etc) as your daily driver?
  • What exactly are you looking for? Android IS Linux, do you want to try a different "distribution" just for fun?

  • GitHub: Can no longer search code without being logged in.
  • The code is still accessible, you just can't use the code search function in the web, which normal git doesn't have anyway.

  • Ascendance of a Bookworm: Part 5 Volume 8 Part 1
  • I guess that noble education is finally paying off, sort of... The only other noble one we know that wants to take another duchy is Georgine 🙃

  • Ascendance of a Bookworm: Part 5 Volume 8 Part 1
  • I gotta admit, it's kinda funny how Rozenmyne perceived Ferdinand's Last Will as, "I MUST GO SAVE HIM," while the letter he sent through Justus was basically the opposite, "DON'T DO ANYTHING, YOU FOOL".

  • The future of selfhosted services is going to be... Android?
  • The latest pixel devices (since 6 I think?) already provide accees to a /dev/kvm device, so maybe you could even run a normal Ubuntu server VM on your phone for hosting these services.

  • With lemmy.film down, where should we host the new movies community?
  • Are you sure the content is gone? I assume the communities had users from other servers, if so isn't the content replicated on other servers?

  • Introducing Raspberry Pi 5
  • I guess he means that raspberry pi doesn't run a mainline kernel

  • Introducing Raspberry Pi 5
  • I guess he means that raspberry pi doesn't run a mainline kernel

  • Ascendance of a Bookworm: Part 5 Volume 7 Part 5
  • I'm probably obsessing over nothing, but the illustration showing Tuuli's reaction when her sister said "Tuuli... No matter what happens, I will protect you." was so good! This will probably sound pretty stupid, only now that we had this illustration did I realise how much Rozemyne grew, I was quite shocked.

  • The OTP you want to use was already used
  • Arguably, if you use 2FA to access your passwords in 1password, there’s little difference between storing all your other OTPs in 1password or a separate OTP app. In both cases, since both your secret passwords and OTPs are on the same device (your phone), you lack a true second factor. The most likely way someone would gain access to 1password secured with 2FA is if they control your device and it’s been compromised, and having your OTPs separated wouldn’t provide additional protection there. Thankfully, the larger benefit of OTPs for most people is that they are one-time-use, not that they originate from a second factor.

    As you said if you have both the password manager and the OTP manager in the same device it goes against the concept of 2FA, and you can throw most of guarantees out the window.

    I think one distinction worth making is that the encrypted vault itself is still only protected by one factor, the password. The OTP 1Password asks you is part of their service authentication mechanism. If for some reason the attacker manages to get an encrypted copy of your vault (Via App cache, Browser add-on cache, mitm, 1Password's servers, etc...), "all" the attacker needs is to brute force your password and they can access the contents (Password and OTP seeds) of the vault without requiring the TOPT token. Yes you can mitigate this with a good password/passphrase, but as GPUs/CPUs get faster will that password continue to be good enough in few years time? If your master password becomes "easily" brute forceable, now the attacker has access to all of your accounts because you had the password and OTP seeds in one vault.

    If you truly feel you need a second factor though, you’ll probably want to look at something like a Yubikey or Titan. I’ve considered getting one to secure my 1password vault to reduce the risk of a lost phone compromising my vault.

    I have one, but unfortunately the amount of services that support U2F as a 2FA mechanism is relatively small and if you want to talk about FIDO2 passwordless authentication even less.

  • The OTP you want to use was already used
  • That's a fair point. I just wanted to highlight that there may be cases where a password manager isn't automatically protected by 2FA by the two factors you mentioned (The password you know and the copy of the vault) since in the case of bitwarden fulfilling one can give you the second. In order to actually achieve 2FA in this case, you would need to enable OTPs.

  • The OTP you want to use was already used
  • That’s not quite right though, there’s the factor you know (password to your vault), and the factor you have (a copy of the encrypted vault).

    That would be true for offline vaults, but for services hosted on internet I don't think so. Assuming the victim does not use 2FA on their Bitwarden account, all an attacker needs is the victim's credentials (email and password). Once you present the factor you know, the vault is automatically downloaded from their services.


    This is something I hadn't thought until know, but I guess password managers might(?) change the factor type from something you know (the password in your head) to something you have (the vault). At which point, if you have 2FA enabled on other services, you are authenticating with 2 things you have, the vault and your phone.

  • The OTP you want to use was already used
  • Although it's true that you are increasing the attack surface when compared to locally stored OTP keys, in the context of OTPs, it doesn't matter. It still is doing it's job as the second factor of authentication. The password is something you know, and the OTP is something you have (your phone/SIM card).

    I would argue it is much worse what 1Password and Bitwarden (and maybe others?) allows the users to do. Which is to have the both the password and the OTP generator inside the same vault. For all intents and purposes this becomes a single factor as both are now something you know (the password to your vault).

  • Request Guarantees Here
  • Any chance to get a guarantee on lm.put.tf ? The instance is only used by people I know to avoid trigger happy admins on larger instances that defederate for trivial reasons. There are no real "communities" there and currently there's only 5 users with just 2 being active on the fediverse. The admin account there goes largely unused to prevent the instance from being compromised due to XSS and/or CSRF attacks,

    There is only one community for meta discussions about the instance so that other people may publicly raise issues to be discussed. Unsurprisingly, no one has posted there yet.

  • Ascendance of a Bookworm: Part 5 Volume 7 Part 3
  • I wonder in what bizarre way, Rozemyne will extract the knowledge from Ferdinand. (I guess by printing some books)

    My hypothesis is that Ferdinand was already planning to transfer/write his 30-40% knowledge of the G-book onto the 300 pages of "maximum quality fey paper" that he request from Rozemyne. Maybe he is already expecting to be executed by either the Royal famaly or Georgine/Detlinde and wants to preserve this knowledge somehow.

  • test post
  • Test

  • ADMIN, isn't it time to move from lemmy.world?
  • I think the admin of c/selfhosted is the admin of Lemmy.world

  • What made you choose your instance?
  • Made my own for myself and some friends. We couldn't be bothered creating account on the larger instances and have power tripping admins de-federating instances over trivial issues.

  • test post

    Is this post getting federated?

    7
    Lemmy Support @lemmy.ml andreluis034 @lm.put.tf

    When do images get mirrored in the local instance's pictrs?

    I'm running an instance for me and a couple of friends at https://lm.put.tf/. I've noticed that there seems to be no consistency whether or not post images are mirrored in instance's pictrs

    For example:

    The post https://lm.put.tf/post/22176 from [email protected] has its image mirror from https://sh.itjust.works/pictrs/image/92ec8e81-1f05-4ff7-8ec7-f3bdee3d8087.jpeg to https://lm.put.tf/pictrs/image/747826a6-281f-4b1b-8ba2-7bbf452916dd.jpeg

    However the post https://lm.put.tf/post/22060 from the same community, but posted by a user from lemmy.blahaj.zone does not have a mirror on my instance. The image links to https://lemmy.blahaj.zone/pictrs/image/OpIT86L1vq.jpg

    Why is there a difference in behaviour? is it because the post was done from another instance and not lemmy.world? What is the replication/mirroring logic?

    3