• 3 Posts
  • 78 Comments
Joined 1 year ago
cake
Cake day: June 13th, 2023

help-circle

  • I’d like to see some documentation that says passkeys were intended to never be synced across anything.

    Everything I have ever read is that it’s basically asymmetric cryptography like ssh keys. You have a private one, generate the public and give it to the site. It stops reuse of passwords and site breaches become useless as the public key is useless for attacking an account on another site, etc. (well, besides whatever data was lost in the breach which is outside the scope.)

    I see no reason to limit someone having the private key on their phone, their desktop, etc. Having to generate yet another passkey for every device is inefficient and would decrease adoption of this.





  • Exactly. I don’t know if the AIO image was used and how that all works (I stay away from that and the snap which is just an abomination) but no one should try to selfhost anything for prod unless they know exactly how it works. That and have a staging env. If you’re not up to the task then just pay for some commercial hosting (even if it’s just Nextcloud that is hosted elsewhere.)

    I’ve run the nextcloud image (just docker.io/nextcloud IIRC) pinned for years with k8s and it’s durable and fine. It stays put and I just take the time to update my testing instance, make sure it all works with some cheap smoke tests, then upgrade prod.












  • Honestlly, I’m ambivalent on the navigation bar change. It is quite tall but sometimes helpful.

    As for the url bar, thank GOD they put the full URL back. I think this all “better against phishing” is BS and most users aren’t looking anyhow. If you need to at all differentiate it, but the domain in bold and let the rest of the url be in normal font. But for the love of cake don’t have ONLY the domain. I can’t even explain how frustrating that is. Please keep the full URL mozilla.