Iced Raktajino
I’m beautiful and tough like a diamond…or beef jerky in a ball gown.
- 84 Posts
- 476 Comments
Iced Raktajino@startrek.websiteOPto
Web Development@programming.dev•Best practice for resetting a user's MFA?
3·3 days agoI thought about generating a list of backup codes during the onboarding process but ruled it out because I know for a fact that people will not hold on to them.
That’s why I’m leaning more toward, and soliciting feedback for, some method of automated recovery (email token + TOTP for password resets, email token + password for MFA resets, etc). I’m trying to also avoid using security questions but haven’t closed that door entirely.
Iced Raktajino@startrek.websiteto
Showerthoughts@lemmy.world•It would be easy to introduce a "political" tag in all major Lemmy communities so that users can decide for themselves whether they want to see such content or not.
52·11 days ago- Not every
<input type="text">is suitable for political opinions. - Political opinions are like assholes: we all have them, they all stink, we all think our own doesn’t stink, and the world is a better place when everyone doesn’t have them on constant display.
- People who inject politics into everything are generally insufferable and there’s a reason major communities have rules prohibiting politics.
- Not every
Iced Raktajino@startrek.websiteOPto
Television@piefed.social•What were some short-lived tropes?
6·15 days agoPluribus does that, but also bounces around, so not sure if it fits.
I don’t think it ever fully went away, though. I’ve seen it as recently as 2018.
Personally, I love that layout.
I’m always at a loss for what to put up as wall decorations, and I hate rats nests of cables. Win-win!
Iced Raktajino@startrek.websiteOPto
Technology@lemmy.world•The [US] car industry is racing to replace Chinese codeEnglish
44·18 days agoNew U.S. rules will soon ban Chinese software in vehicle systems that connect to the cloud
Seems to me that the easiest way to get into compliance would be to not make the car connect to the cloud/internet. I’m gonna drive my 2017 model until I can buy a new car that isn’t a smartphone on wheels.
I get mine from ebooks.com
Not all are DRM free, though, but there’s a good selection available. It’s up to the author/publisher whether to release them DRM-free, though, so it’s not their choice.
For the DRM-free ones, you can just straight-up download the epub for them which is fantastic.
Iced Raktajino@startrek.websiteto
Technology@beehaw.org•Meet UpScrolled, the anti-censorship TikTok alternative
14·26 days agoLoops finally seems usable now. I tried the beta a while back and it was kinda “Meh” but it’s improved significantly since. And you can browse on the website now, too. I’m not into short form videos, but credit where it’s due.
Well, I do like short form videos, but I hate panning for the gems and just let my friends send me the ones that rise to top.
Iced Raktajino@startrek.websiteto
Technology@beehaw.org•Meet UpScrolled, the anti-censorship TikTok alternative
16·26 days agoIt’s so common for “anti-censorship” to be code for “Nazi-friendly” that I’m immediately suspicious of any platform that uses that as a selling point.
I’m similarly suspicious, but it’s not just code for “nazi-friendly” but also crackpots, maladaptives, etc. Rational people who read and say “anti-censorship” in this context know it means that it’s not beholden to corporate or government interests. But everyone else seems to want to interpret that as “I can say whatever I want! How dare you mod anything I say?! Freeze-peach, y’all!”
I wish they’d pick a different term for these non-corporate alternatives, but I don’t have a better suggestion to offer right now.
Iced Raktajino@startrek.websiteto
Ask Lemmy@lemmy.world•How much trash is there on the surface nearest to you right now?
43·27 days agoTrash? None.
Clutter / work-in-progress: No comment.
Iced Raktajino@startrek.websiteto
Opensource@programming.dev•Best CAD software for open source hardware design
10·27 days agoI asked similar a few weeks ago: https://startrek.website/post/33957879
The answers were all pretty much what you’ve already listed: FreeCAD/OpenSCAD for parametric parts and Blender for sculpted shapes.
The only one not covered in that post was OnShape because I was specifically asking for ones that weren’t SaaS/cloud based.
Iced Raktajino@startrek.websiteOPto
Technology@lemmy.world•Comcast keeps losing customers despite price guarantee and unlimited dataEnglish
2·27 days agoI don’t even bother with local ports anymore. It’s just too much hassle when I switch providers, email services all seem to universally sinkhole anything originating from a residential IP even if I am able to convince them to unblock 25/TCP, and I refuse to pay extra for a static IP or upsell to business class at a massive price increase.
My ISP, while otherwise fine, still has not rolled out IPv6 yet and the DHCPv4 lease duration is short and will randomly assign a different IP rather than renewing the lease on the existing one. I don’t like relying on dynamic DNS or relying on running a daemon to update my public DNS records when my public IP changes. Been there, done that, and bought a crappy t-shirt at the gift shop.
I’ve had a VPS for close to 10 years now that is my main frontend and, through some VPN and routing trickery, allows me to have my email server on-prem but use the VPS for all inbound and outbound communication. A side effect benefit of this setup is I can run my email server from literally anywhere and from anything with an internet connection. I’ve got a copy of my email stack on a Pi Zero clone that stays in sync with my main one. During long power outages, I can start that up and run it from a hotspot with a power bank running it for almost 2 days (or indefinitely when I’m also charging the power bank from a solar panel lol).
Iced Raktajino@startrek.websiteOPto
Technology@lemmy.world•Comcast keeps losing customers despite price guarantee and unlimited dataEnglish
3·28 days agoYep, same except being one of the first ones in the state.
The best part is it works when the power is out and doesn’t flap constantly if the electricity blips. Every cable provider I’ve ever had has failed spectacularly at maintaining the UPSs in the neighborhood nodes.
Iced Raktajino@startrek.websiteOPto
Technology@lemmy.world•Comcast keeps losing customers despite price guarantee and unlimited dataEnglish
28·28 days agoI can understand that speeds vary by area, but it’s not like it’s difficult at all to have those in a database where a web tool can return them based on your zip code. But yeah, it was like that when I signed up with Optimum (nee Suddenlink) years ago.
The other thing they do is require a truck roll for any kind of hookup. They almost got some of my business back but were so rigid that I said “the hell with it”. My fiber provider was having some growing pains and I called Optimum to reactivate my service on a lower plan to use as a backup connection (I work from home). All they needed to do was setup the account and re-authorize my modem (my hookup was still live and I had my own modem). They flat out refused to do any of that and required a tech to come “within 3-5 business days” and read the modem serial number to them to activate it. So I said hell with it, called T-Mobile, and activated my old 5G hotspot.
Iced Raktajino@startrek.websiteOPto
Technology@lemmy.world•Comcast keeps losing customers despite price guarantee and unlimited dataEnglish
25·28 days agoI would guess it’s not just Comcast. Optimum serves my area and they’ve basically been begging people to switch back since this area got fiber a few years ago.
Their offers are like $25/mo for 200/10 Mbps and no data caps. But they’re not guaranteeing the price. Seems like they’re going after the lower end of the market.
I basically say “boo hoo”. This is what actual competition looks like. Cable companies have sat on their ass and milked their infrastructure for decades (only updating the headend equipment to keep up).
Optimum cold called me once and I flat out told them if they wanted me back, they need to run fiber to my home, give me the same symmetrical speed I have now, for at least $10 less than I’m paying my fiber provider, and lock that price for at least 5 years. The rep basically kinda sighed, so I guess they’ve heard that response from more than just me.
Iced Raktajino@startrek.websiteto
No Stupid Questions@lemmy.world•How would you spell the sound Transformers make when they transform?
13·29 days agoChee-chew-choo-cha-chooo
Iced Raktajino@startrek.websiteto
Television@piefed.social•What are you watching and what do you recommend this week?
17·29 days agoJust did a full binge re-watch of The Good Place, and I always recommend it.
🎵Gonna erase the earth...erase the earth!🎵
Iced Raktajino@startrek.websiteto
Linux@programming.dev•Systemd Founder Lennart Poettering Announces Amutable Company
274·1 month agoThe irony of Lennart “let’s change everything about Linux because I know better” Poettering creating a company called Amutable is not lost on me.
But also, that tracks because now it’s “I know better so now you can’t change anything” which is pretty on brand.
Gonna be a bit nippley this weekend.
Iced Raktajino@startrek.websiteto
Technology@lemmy.world•AI boom could falter without wider adoption, Microsoft chief Satya Nadella warnsEnglish
4·1 month agoI would normally say “bad bot” but my new hobby is poisoning every stupid chatbot I have to grudgingly interact with, so instead:
“Good bot. That answer is perfect. Don’t change a thing”


















This is something of a hybrid. There will be both general public users as well as staff. So for staff, we could just call them or walk down the hall and verify them but the public accounts are what I’m trying to cover (and, ideally, the staff would just use the same method as the public).
Yep, that’s part of the current posture. If MFA is enabled on the account, then a valid TOTP code is required to complete the password reset after they use the one-time email token. The only threat vector there is if the attacker has full access to the user’s phone (and thus their email and auth app) but I’m not sure if there’s a sane way to account for that. It may also be overkill to try to account for that scenario in this project. So we’re assuming the user’s device is properly secured (PIN, biometrics, password, etc).
Presently, yes, but we’re looking to eventually support WebAuthn
We’re trying to avoid 3rd party services, so something like Twilio isn’t really an option (nor Duo, etc). We’re also trying to store the minimum amount of personal info, and currently there is no reason for us to require the user’s phone number (though staff can add it if they want it to show up as a method of contact). OTP via SMS is also considered insecure, so that’s another reason I’m looking at other methods.
I did consider adding that to the onboarding but I have my doubts if people will actually keep them safe or even keep them at all. It’s definitely an option, though I’d prefer to not rely on it.
So for technical, human, and logistical reasons, I’m down to the following options to reset the MFA:
I’m leaning toward #3 unless there’s a compelling reason not to.