

I like programming and anime.
I manage the bot /u/mahoro@lemmy.ml
Jeff Geerling: Self-hosting your own media considered harmful (updated). Youtube removed his content, saying that self hosting content is "dangerous or harmful content"
1y 10d ago in selfhosted from www.jeffgeerling.comI think a few folks haven't read the article or know who Jeff Geerling is. The title of this article is confusing.
Jeff posted a video on YT about how to self-host your own media in 2024. He recently got a violation from YT that YT considers his video to be harmful and dangerous. He appealed, got denied, but then the update is that YT removed the violation.
Coffee
1y 3mon ago in adhd@lemmy.dbzer0.com from lemmy.oneI almost spit out my coffee from this meme!
Permanently Deleted
1y 4mon ago in technology from bitwarden.comI understand this change by Bitwarden, but I wish they gave us the option to turn this off or at least given us more time before forcing this on us.
There's a lot of comments talking about how this increases security, which is true. But it also increases the risk of account lockout. This is especially true in two scenarios: traveling and incapacitation.
Traveling - for those of us who travel frequently, we carry all of our belongings with us. This makes us particularly vulnerable to account lockouts. We can't securely store backup devices or documents in easily accessible locations. We can't easily rely on trusted friends or family because they are so far away. Also, internet accounts are more likely to lock us out anyway because we are logging in from a different country, which is suspicious behavior.
Incapacitation - god forbid, if there comes a time when we are permanently or temporarily incapacitation, it becomes important for our loved ones to access accounts. When we are in the hospital, it's important that our loved ones get access to our personal accounts. I personally have advanced directives and have worked with an estate lawyer to make sure that my Bitwarden account becomes available. I also have instructions for immediate trusted family on how to access my vault if I were ever in the hospital. With this short notice, I need to scramble to get all of that updated and provide a way for them to access the account without my 2FA devices.
The above scenarios are based off of my real experience. These are real and likely risks that I have to account for. Security is not just making sure that outside bad actors CANNOT gain access, but it also means that the right people CAN get access at the right time.
What am I going to do? I'm weighing my options.
- I believe the self-hosted version of Bitwarden does not require this. This comes with its own set of risks though.
- Pay for premium, which comes with lockout support - I need to see if this can take care of both use scenarios above.
- Turn on 2FA and memorize the recovery code. While viable, since I will only use the recovery code once, I'm likely to forget it.
- Change the email to a non-2FA email address, only used by Bitwarden, with a strong but easily memorable password. This email must allow access from foreign countries without lockout (gmail is out). I'm actually strongly considering this.
This is being purposefully obtuse. Choosing to force users to memorize a recovery code increases the likelihood of lock outs.
There is a real risk of account lockout, especially for those of us who travel frequently. Lockouts are a significant risk when you need to carry all your belongings and devices.
There are also some of us who also think about what happens to us when we are incapacitated and a loved one needs access to our passwords. In a situation, it's important to balance security vs expediency to access critical information. This new policy disrupts that.
At the very least, I wish Bitwarden would have given us more time to force this policy. I have to scramble to make changes to my estate planning documents and get in contact with my lawyer to change my advanced healthcare directives.
APOD - Titan Touchdown: Huygens Descent Movie
1y 4mon ago in scienceOne of my favorite achievements from a space agency. I hope we can return back to the Saturnian system with more landing probes!
Yes, you should use a Python venv in a container like docker
1y 5mon ago in python@programming.dev from www.bitecode.devThen create one venv for everything
Write code that is easy to delete, not easy to extend
1y 7mon ago in programming@programming.dev from programmingisterrible.comThis is a classic piece, and I love the contradictions in the text. It encapsulates my feelings on good software and code that it almost becomes an art than a science.
"Rascal Does Not Dream" light novel series by Hajime Kamoshida and Keji Mizoguchi has ended after over 10 years. The final volume, Volume 15, is titled "Rascal Does Not Dream of a Dear Friend."
1y 8mon ago in manga@ani.social from sh.itjust.worksWhat a wild ride! Can't believe it's been ten years.
PSA: You should know that Debian Testing does not receive security updates in a timely manner, and is not intended for production use
1y 8mon ago in linux@programming.devPSA for Debian Testing users: read the wiki
https://wiki.debian.org/DebianTesting
Control-F security returns 18 results. This is well known and there's even instructions on how to get faster updates in testing if you want.
Steam does the opposite of forcing Arbitration on its users
1y 8mon ago in games from lemdro.idMy thought was that a lawsuit is more expensive than arbitration, but settling a class action lawsuit is cheaper than thousands of arbitrations.
Is there software that tracks internal dependencies for CI/CD?
2y 10mon ago in devops@programming.devLet transit take you out to the ball game: Ride Metro, Sound Transit, and Kitsap Transit for free July 10-11 - King County
2y 11mon ago in seattle from kingcounty.govTrying to figure out why comments aren't showing up on other instances
2y 11mon ago in memes@sopuli.xyz from programming.devHy - A dialect of Lisp that's embedded in Python
2y 11mon ago in python@programming.dev from github.comThe problem with federated web apps
2y 11mon ago in programming@programming.dev from www.devever.net[META] What do you think of our bot, Mahoro-chan?
2y 11mon ago in manga@lemmy.ml[Fixed] Broken link in the sidebar
2y 11mon ago in meta@programming.devCLI tools hidden in the Python standard library
2y 11mon ago in python@programming.dev from til.simonwillison.net[DISC] Otaku ni Yasashii Gal wa Inai!? (Gal Can’t Be Kind to Otaku!?) - 9.4
2y 11mon ago in manga@lemmy.ml from mangadex.org





