Hacker Newsnew | past | comments | ask | show | jobs | submit | more computerfriend's commentslogin

If you log into your GitLab account from a Hong Kong IP address, they'll delete your account after 60 days and tell you to use JiHu, a Chinese company, instead.


> We wish to express our deep gratitude to Jason Lau, CISO and the Crypto[.]com Security Team, who we approached first to help independently verify this zero-day vulnerability.

Bizarre choice.


Advertising has been a net negative and the mathematics produced by string theory research is amazing.


Here's a similar analysis for Hong Kong: https://khwongk12.medium.com/7-eleven-vs-circle-k-5964b8f008....


> completely failing to mention what he is fighting for.

Not so.

> Denis Kapustin, a far-Right extremist and former football hooligan, ...

> Since 2019, he has been banned from entering the Schengen Area for promoting neo-Nazi ideology.

from the article.


Oops, not completely then.

I scrolled through the irrelevant section "Outsmarting Russians" devoted to the events that has been reported on many times before, but they buried two paragraphs about this "commander" being a Nazi there. I don't think many people would read through this haystack of already known events in search of the needle they don't even know is there.

"The drones had been smuggled into Russia and assembled, and launched from trucks deep within Russian territory, in another huge victory for Ukraine’s spies.

Ukraine’s latest intelligence success means Denis Kapustin, a far-Right extremist and former football hooligan, is inside Ukrainian territory and “preparing to continue carrying out assigned tasks”, said a Ukrainian commander.

The commander’s family moved from Moscow to Germany when Mr Kapustin was 17 and he relocated to Ukraine in 2017.

Since 2019, he has been banned from entering the Schengen Area for promoting neo-Nazi ideology."

Quite abrupt switch of topic, don't you think? It's like the editor cut and pasted these paragraphs from more prominent place to the place which 90% of readers won't read. It's not the first time I see this dark pattern in Western media.


So if the section that's irrelevant is the one with your "concerns" then why on earth are we expected to care about the thing you are calling irrelevant.


[flagged]


I'm a bit concerned by that, yes. Your portrayal isn't very accurate, as this thread shows clearly, but yes it's a bad situation.

Regardless, you're doing a hero's version of moving the goalposts here, which tends to undermine the point.

The small point I'll make for you is that white nationalist / neo nazi agenda is unforgivably bad, regardless of "the enemy of my enemy is my friend".

The small point I'll make for myself is that war is complicated and nasty and we, the world of folks not currently at war, aren't doing enough to shape this conflict according to our stated values.


Every American destroying submarine cables might be, yes.


The crew of the ship? Do they even know what the captain is doing? Does the captain even know, or are they just following instructions (which still seems culpable if you are the officer in charge).


This is true (modulo travel and extradition) regardless of where in the world you live.


You can put a transition on details > summary.


> better UX with PGP instead of SSH

This might be true of comparing GPG to SSH-via-PIV, but there's a better way with far superior UX: derive an SSH key from a FIDO2 slot on the YubiKey.


I do it with FIDO2. It's inconvenient when having multiple Yubikeys (I always end up adding the entry manually with ssh-agent), and I have to touch the Yubikey everytime it signs. That makes it very annoying when rebasing a few tens of commits, for instance.

With GPG it just works.


For what it's worth: You can set no-touch-required on a key (it's a generation-time option though).


Sure, but then it is set to no-touch for every FIDO2 interaction I have. I don't want to touch for signing, but I want to touch when using it as a passkey, for instance.


This is a per-credential setting, so you can have your SSH signing key be a no-touch key and still use touch confirmation for everything else.

(see "uv" option here https://fidoalliance.org/specs/fido-v2.0-ps-20190130/fido-cl... - the -sk key types in SSH are just a clever way of abusing the FIDO protocol to create a signing primitive)


Oh, I need to check this! Thanks!


Use the PIV applet for SSH and signing Git commits instead? Git supports S/MIME and SSH can use keys over PKCS#11 basically out-of-box on OSs that don't ship gpg-agent (that just interferes with SmartCard usage in general).


Talk to a psychiatrist about ADHD.


Indeed.


[flagged]


So they can get access to medication that may help improve their life?


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: