varx/tech

Boston-area meat construct ␥ I just do what the plants tell me ␥ I'd rather be undermining the client-server paradigm

This is the more tech-y alt of cybersecurity.theater/@varx

pronouns
he/they
languages
📖 en, es; ✍️ en, ~es
that cavern thing I'm always nattering about
2025-12-13

@david Nice! :-D It looks good.

My own solution was to add a clip to my belt, then dangle the keys off of that into my pocket.

I used to clip the ring directly to the belt, but then the keys would poke holes in my shirt. Now they dangle about halfway down the pocket and stay out of trouble.

Many shirts suffered before I figured out the culprit.

A ring of keys connected to a 1 inch wide strap of black nylon webbing; the other end of the strap is connected to another metal ring, and this one is held in a clip that slides onto a belt. The webbing is 4-5 inches long and has been inexpertly sewn together with fishing line.
2025-12-13

@paco There's often a gap between the law and common sentiment but yeah, that's a pretty awkward headline.

2025-12-13
2025-12-12
2025-12-12

Gandi refuses to delete my account unless I upload a government ID, claiming that this is required under GDPR.

Pretty sure this is bullshit, especially because there's nothing for them to compare the ID to.

varx/tech boosted:
2025-12-11

<gets an e-mail from a recruiter at an AI company>

"We have customers all around the world powered by our multi-billion dollar technology."

<runs a five second web search>

<the AI company is a startup, incorporated nineteen days ago, and has three employees>

2025-12-11

@GuerillaOntologist I want to run through there yelling and flailing my arms. :-)

2025-12-11

@david The character in the first image appears to be Nancy. :-)

2025-12-10
varx/tech boosted:
2025-12-10

@wxcafe I think ... I understand why...

They rewrote account.gandi.net and made a 404 of the facet id static file ...

account.gandi.net/api/u2f/trus

This will break any FIDO1 auth ...

Like I said ... incompetence.

2025-12-10

@meejah You can probably think of Python "extras" as Rust "features", at least when it comes to dependencies.

(In Rust, feature also control which *code* is included, while in Python the code is still there but is broken if the dependencies are missing.)

2025-12-10

@meejah Extras are additional sets of optional dependencies.

The idea here is that the package can include optional functionality without pulling in additional, heavy dependencies by default.

Let's say you're writing a telemetry library. It supports a handful of backends, including Datadog and New Relic, so it has code that expects the ddtrace and newrelic pip packages to be installed. But most users don't want to install all of the transitive dependencies for *both* of those backends.

So the package instead could define an extra for each backend. Someone can then install the package as `meejah-telemetry[newrelic]` and they get the New Relic dependencies, and when they go initialize it for NR functionality, it works. If they just install `meejah-telemetry` without the extra, and try to init it for NR, the library will complain about missing imports.

2025-12-10

@amsomniac you fool, trying to access a chromesite using a browser

varx/tech boosted:
mccmcc
2025-12-09

@whitequark only the spin up electrons are suitable for production use

2025-12-09

@waldoj This makes me wonder if they discovered that they had just completely bungled their implementation and had to replace all of the auth records.

(And then also bungled their migration plan.)

2025-12-09

Fascinating, they even removed passkeys: mastodon.social/@waldoj/115690

2025-12-09

Wow, Gandi doesn't even have a way to initiate account deletion from their dashboard. You have to file a support ticket or something.

2025-12-09

It's unacceptable to remove strong MFA from an account with no warning or migration period.

It's also very weird that #Gandi claims my U2F keys are "no longer compatible". Yes, there are newer protocols (like passkeys) but you can still keep the old MFA method active!

And the icing on top is that I was indeed able to just re-register my old keys. Which means they were still compatible, and there was no point to the entire exercise.

2025-12-09

#Gandi just sent me an email notifying me that they've disabled my security keys and switched me over to email #MFA.

But don't worry, I can just re-add them!

I have... several concerns.

Dear user,

Gandi is evolving, and so is its security!

Security keys now use a new protocol. Keys registered before September 10, 2019, are no longer compatible and have been deactivated.

Therefore, we have removed your security keys: [redacted1],[redacted2] from your account.

To maintain a satisfactory level of security, we have enabled MFA via email for your account.

However, you can re-register them in your administration console, in the ACCOUNT application (https://docs.gandi.net/en/account_management/security/security_key.html).

Please feel free to contact us if needed.

Sincerely,

The Gandi Team
2025-12-09

@gsprs Well, you were kind of being a dick.

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst