Natanael
Cryptography nerd
Fediverse accounts;
@Natanael@slrpnk.net (main)
@Natanael@infosec.pub
@Natanael@lemmy.zip
Bluesky: natanael.bsky.social
- 1 Post
- 965 Comments
Natanael@slrpnk.netto
Linux@lemmy.ml•Just "bricked" a VM while testing secure boot and I'm not sure how
2·21 days agoCould be that you loaded an incomplete set the second time…? 🤷
Natanael@slrpnk.netto
Linux@lemmy.ml•Just "bricked" a VM while testing secure boot and I'm not sure how
2·22 days agoThat would make it stop at the end of the bootloader with decryption failure, not full bricking
Natanael@slrpnk.netto
Linux@lemmy.ml•Just "bricked" a VM while testing secure boot and I'm not sure how
9·22 days agoCould be a UEFI bug in the VM itself;
Could also be that you didn’t sign your boot image since that command seems to load the secure boot signing key into the UEFI firmware, if you cleared other signing keys then potentially no code can load. You would have to load the keys for whatever UEFI firmware vendor is used (presumably that made by the VM software maker) or sign it yourself, etc.
Natanael@slrpnk.netto
Technology@lemmy.world•Dutch authorities allegedly seize VPN server without a warrant — company claims that law enforcement will return it after analyzing the device fullyEnglish
561·22 days agohttps://repository.tilburguniversity.edu/bitstreams/97187bcf-4ad2-402c-ac05-e565346d09b6/download
EU has similar laws and Dutch law allows for striking illegally collected evidence if the infringement was severe
Natanael@slrpnk.netto
Ask Lemmy@lemmy.world•How many daily drivable desktop operating system( familie)s are there?
6·23 days agoAbsolutely tiny yet has a lot of functionality
Just give it a grill faceplate
Natanael@slrpnk.netto
World News@lemmy.world•‘Trumpist’ Czech PM-elect refuses to sell business empire amid conflict of interest rowEnglish
1·4 months agoJust realized my post could be read wrong.
I meant that the above would be forced onto candidates as they sign up for an election.
Natanael@slrpnk.netto
World News@lemmy.world•‘Trumpist’ Czech PM-elect refuses to sell business empire amid conflict of interest rowEnglish
101·4 months agoMove all control of all business into a fully independent trust, or something. Maybe even one controlled in a different country if you’re really paranoid.
Natanael@slrpnk.netto
Games@lemmy.world•Steam Hardware [new Steam Controller, Steam Machine, and VR headset Steam Frame, coming in 2026]English
16·4 months agoYup, FEX to translate x86 to ARM.
Natanael@slrpnk.netto
Privacy@lemmy.ml•Can Google read my Signal messages on stock Android?
11·4 months agoMost of those things would only be possible by hiding them in a system update
Natanael@slrpnk.netto
Privacy@lemmy.ml•Can Google read my Signal messages on stock Android?
11·4 months agoIt’s possible but complicated.
Since apps have access to the TPM API they can encrypt their own data in such a way that only the app’s own authorized processes can retrieve the decryption key from the TPM chip
Natanael@slrpnk.netto
Privacy@lemmy.ml•Can Google read my Signal messages on stock Android?
63·4 months agoThere’s measures they could use in theory, but if you switch keyboard app away from Google’s and set private text mode, enable screenshot protection, etc, then you should be good.
Natanael@slrpnk.netto
Privacy@lemmy.ml•Is it better to enable javascript in LibreWolf or switch to a different browser when a site needs it? Does switching browsers help in general?
10·4 months agoFor sites you visit occasionally, it’s better to enable tab isolation (use the containers feature) and then enable JS only for that domain (note the difference between allowing JS from that domain in any tab, vs only allowing that tab with that domain to use JS, you should do the latter)
https://addons.mozilla.org/en-US/firefox/addon/multi-account-containers/
If you’re switching to a different browser you may as well use the same browser but a second clean profile and use private tabs so it doesn’t retain history. Using private tabs in your main browser profile does also help but isn’t perfect because there’s still some metadata leaks occasionally.
Using a different browser could ironically make you easier to track - how unique you are is the main signal used to track you (user agent, OS, language, etc), and going for an even more rare config will help their tracking even if you delete session cookies. Especially if they have a tracker across multiple domains you visit from different browsers from the same IP, with similar device fingerprinting results across browsers. That’s a strong signal those sessions are linked. You want to NOT stand out to maintain your privacy.
You can either follow the instructions or spend one of your 9 lives
Natanael@slrpnk.netto
Technology@lemmy.world•The Windows Subsystem for Linux is now open source.English
4·10 months ago[Windows subsystem] for [executable environment] is the naming scheme. The default is Win32, there’s one for POSIX (practically never used), and Linux runs in another.
Natanael@slrpnk.netto
Ask Lemmy@lemmy.world•Is there a term for *exploiting the letter of the law for malicious gain*, particularly knowing that the opponent will be bound by the letter of the law despite the negative outcome?
4·11 months agoMalicious compliance is when you follow a order or law knowing that it will backfire on those who issued it.
“Lawfare” is a comparable term but not quite it (basically legal harassment campaigns).




Now you have to update your CalDav entries