Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Firstyear

@firstyear@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Senior LDAP/IDM Tech Debt Collector
@SUSE. Supermarket Thought Leader. Author of Kanidm, concread and webauthn-rs. he/him

835 Followers
227 Following
50 Posts
Joined November 04, 2022
Open post
Firstyear @firstyear@infosec.exchange
· 1mo ago

Four word horror story:
"Vibe coded certificate authority"
Im sorry.

36
0
19
0
Open post
Firstyear @firstyear@infosec.exchange
· 1w ago
Ifyou want a slop-free identity manager, then consider giving https://github.com/kanidm/kanidm a look
GitHub

GitHub - kanidm/kanidm: Kanidm: A simple, secure, and fast identity management platform

Kanidm: A simple, secure, and fast identity management platform - kanidm/kanidm

3
1
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 1w ago
Replying to
@dan_lerch@mastodon.social No problem, there has been some progress in that direction recently, but mostly our focus has been on some user-facing changes like account signups.
1
2
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 1w ago
Replying to
@dan_lerch@mastodon.social Okay, you might want to follow https://github.com/kanidm/kanidm/issues/1553 then which is our tracker for it.
GitHub

kanidm_unixd: Support PAM authentication via FIDO2/WebAuthn/"Passkeys" · Issue #1553 · kanidm/kanidm

Is your feature request related to a problem? Please describe. Currently, my understanding is that kanidm_unixd only supports passwords for PAM authentication, and not FIDO2/WebAuthn/"Passkeys". De...

1
1
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 1w ago
Replying to
@dan_lerch@mastodon.social No problem, and if you ever have any issues, feedback, suggestions or want to contribute, you know where to find us!
1
0
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 1w ago
Replying to
@dan_lerch@mastodon.social When you say you want passkey login, do you mean "usb security keys" or "the user scans a qr code with their phone and auths from a passkey on the phone?" Yeah, last I checked the freeipa passkey situation was pretty messy.
1
1
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 4mo ago
74
5
25
0
Open post
Firstyear @firstyear@infosec.exchange
· 1w ago
Replying to
@amethyst@toots.n7.gg There is a good reason to request the username first with no password input, especially for accounts that dont have a password at all eg passkeys. But the ux can still be done well if attention is paid. In Kanidm we fixed this by having a hidden password + totp field on the first username page, and then we stash those for the next steps so that its all prefilled for you.
1
0
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 2mo ago
Replying to
Or in meme form, passkeys be like:
23
0
3
0
Open post
Firstyear @firstyear@infosec.exchange
· 2mo ago
Oh to be a little lion, enjoying a hanmock #caturday
26
0
6
0
Open post
Firstyear @firstyear@infosec.exchange
· 4mo ago

RE: @acarsdrama@live.acarsdrama.com

Its not commonly known but all 737s have a standard issue furry on board that can be unleashed midflight to resolve technical issues.

live.acarsdrama.com

ACARS Drama: "Air to Ground Message: OK. WE WILL UNLEASH THE …" - ACARS Drama

39
1
14
0
Open post
Firstyear @firstyear@infosec.exchange
· 3mo ago
Fuck xml.
11
4
1
0
Open post
Firstyear @firstyear@infosec.exchange
· 4mo ago

Something I setup a few years ago that I have never regretted since is an ArchiveBox instance at home - It's been fantastic as a way to not only bookmark but keep copies of information that I've found useful over time. Also cool because it automatically archives links/references too which can be great for preservation.

15
0
6
0
Open post
Firstyear @firstyear@infosec.exchange
· 4w ago

Does anyone happen to know if Alpine is slop free still?

1
0
1
0
Open post
Firstyear @firstyear@infosec.exchange
· 4mo ago

This might be the most unhinged crate I've ever seen https://docs.rs/decrust/latest/decrust/

docs.rs

decrust - Rust

🔥 Decrust – The World’s Most Advanced Rust Error Correction Framework

13
3
8
0
Open post
Firstyear @firstyear@infosec.exchange
· 2mo ago
Replying to
@peterwilsoncc@aus.social The 64 char limit is to prevent a KDF DOS attack during authentication. Bcrypt limits input to 72 bytes for a similar reason.
4
2
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 5mo ago

IMPORTANT! We have released Kanidm v1.9.3 which contains six security fixes, two rated HIGH for remote unauthenticated denial of service. Please upgrade immediately! https://github.com/kanidm/kanidm/releases/tag/v1.9.3

github.com
11
0
5
0
Open post
Firstyear @firstyear@infosec.exchange
· 2mo ago
Replying to
@daisy@cloudisland.nz @xssfox@cloudisland.nz @daedalus@eigenmagic.net What you are referring to as Daisy is actually Daisy/Linux
2
0
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 2mo ago
Replying to
@hackuador@functional.cafe The thing is that even if someone else does something unlawful, the car driver should not have been in a position where that happened. Consider that was a motorbike rider (which I formerly was). If you are in a position where someone does something unlawful and you have to evade and then *hit a bus* you are dead. Literally. Dead. So ultimately as a motorcyclist I was trained to pre-empt and monitor the road as your life is on the line every second - you must build a safety margin at all times or else. Those skills *have* saved my life multiple times. In other words this was an avoidable situation - there was no need for a car to torpedo a bus. The driver of that car was in an unsafe position *before* the former performed the unlawful action. If you are a motorcyclist you would be dead. If you were on a bicycle, you would be dead. So why is it that operator of a nearly 1 ton metal machine is given a slap on the wrist for what *could have been* multiple deaths? Why was the other driver given a similarly trivial slap on the wrist for endangering others. Ultimately my point is that we have a separation in our society where car drivers are given a free pass for highly dangerous actions - we make excuses for the actions that would otherwise be deadly.
1
1
2
0
Open post
Firstyear @firstyear@infosec.exchange
· 2mo ago
Replying to
@jana@social.jsteuernagel.de the scanning of the qr code sets up a cable tunnel which is proxied via google. So whatever you do on the phone is then sent via google to land on the browser.
1
2
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 2mo ago
Replying to
@jana@social.jsteuernagel.de Ahh it looks like what happens is that a caBLE tunnel is setup (which btw, still goes via google, sorry to let you know). Then via that caBLE tunnel, your phone can use the yubikey to sign the request since cable is pretty much ctap2-over-noise-tunnel-started-by-bluetooth-qr-magic.
1
4
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 5mo ago
Replying to
@xssfox@cloudisland.nz I'll do it.
4
0
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 2mo ago
Replying to
@xssfox@cloudisland.nz look the thought has crossed my mind. And if it was going to happen itd be in a password manager ....
1
0
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 5mo ago
Replying to
@jpm@aus.social @mike@social.chinwag.org Not even kidding, recently when I tried out OmniOS it kernel panicked on my system and a dev helped me debug it then and there on the spot. Was an amazing experience, and I haven't seen that level of kindness and patience in a distro/os in a long time.
3
1
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 4mo ago
Replying to
Currently in the problem space I have I think I need to split T into two traits - one for setup and one for the main operations so that during setup the inner type that does impl T can be returned, while still allowing a outer operations of A / B to follow a trait S. That way I can make C that uses A's setup S and returns a B impl T.
2
0
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 5mo ago
Replying to
@mike@social.chinwag.org @jpm@aus.social @voltagex@aus.social Would be cool, but I'm in Brissy
0
2
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 3mo ago
Count Binface is giving me life, and oh how I wish we had someone like this in Australia.
0
0
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 2mo ago
Replying to
@hailey@hails.org @xssfox@cloudisland.nz Spittin truths here holy shit
0
0
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 2mo ago
Replying to on social.chinwag.org
@mike@social.chinwag.org Yeah fair mate. If you ever want to know more lmk, I'm always happy to help out. But generally a pw + totp in a password manager is pretty good in many cases.
0
0
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 2mo ago
Replying to
@decryption@aus.social Its william at firstyear dot id dot au - I sent you some yubikeys a few years back.
0
1
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 2mo ago
Replying to
@LapTop006@aus.social @devopscats@toot.cat yeah always happy to help out :)
0
0
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 3mo ago
Replying to
@ideogram@social.coop There is a gardening service called "lawn and order" around too.
0
2
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 2mo ago
Replying to
@daisy@cloudisland.nz Daisy.
0
1
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 2mo ago
Replying to on social.chinwag.org
@mike@social.chinwag.org Solid response. But it is a lot easier to understand as a high-entropy password that is hot-glued into my password manager. But when I use it I can't be phished and a bunch of other attacks just go away. Generally my advice is engage with passkeys on your terms, not the websites or vendors.
0
0
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 3mo ago
At this point, I feel like it's actively negligent to have openssl or gnutls in your project as a dependency.
0
0
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 3mo ago
Replying to
@xssfox@cloudisland.nz Yeah - facing a similar issue with mirror hosting rn too.
0
0
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 1w ago
I need some advice on flashing a bare esp32-c3-12f board - with probes I can get a flasher to connect to serial and read it booting, but there are connectivity issues and it wont flash or reset. Pretty likely ive wired it wrong, but there is so much slop these days I cant find the wiring needed. Any help is welcome :)
0
4
1
0
Open post
Firstyear @firstyear@infosec.exchange
· 2mo ago
Replying to
@arichtman@eigenmagic.net Yeah I love to see all the places that Kanidm ends up in, it's quite fun.
0
0
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 2mo ago
Replying to
@decryption@aus.social Can you email me about it and I'll help you out tomorrow?
0
2
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 2mo ago
Replying to
@jana@social.jsteuernagel.de If I recall its based on what browser you use. https://github.com/kanidm/webauthn-rs/tree/master/cable-tunnel-server
GitHub

webauthn-rs/cable-tunnel-server at master · kanidm/webauthn-rs

An implementation of webauthn components for Rustlang servers - kanidm/webauthn-rs

0
0
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 1w ago
Replying to
@xssfox@cloudisland.nz I connected the strapping pins to the flasher, which I assume should set them correctly.
0
1
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 3mo ago
My partner got a new electric toothbrush and it seems the head has a pressure relief valve so that if you "suck" on the head you bring in air instead. Im struggling to find the design and engineering why this is part of the design. Any ideas?
0
1
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 1w ago
Replying to
@xssfox@cloudisland.nz Yeah. I think I probably need to step back and really just re-assert everything is working as I expect.
0
0
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 2mo ago
Replying to
@xssfox@cloudisland.nz At country scale 6% is *A LOT* of users who missed this alert.
0
0
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 2mo ago
Replying to
Maybe the bus should have worn high-vis.
0
0
0
0
Open post
Firstyear @firstyear@infosec.exchange
· 2mo ago
Replying to
@miniBill@mastodon.uno @peterwilsoncc@aus.social That leads to an attack called hash-schucking.
0
1
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 17:06:08 UTC