Hacker Newsnew | past | comments | ask | show | jobs | submit | JaneLovesDotNet's commentslogin

Can you share a public video that demonstrates this? I've never seen it. Not saying it can't be true.



The tone of that comment does sound a bit "dick-ish", but I can't be totally sure without knowing his history with that CEO. Thanks and I'll keep an eye out for more evidence like this. In videos he seems pretty nice to me, although it could of course be a facade.


One could argue reclaiming a company from a multinational corporate conglomerate back into founder hands is hardly “evil”.


And breaking a promise, siphoning money from a nonprofit, and making billions in the process.


Just an example of unapologetically going “Founder Mode”.


Wow he is very good at taking over companies


Did you read the article? The hubris and avarice required here doesn’t develop overnight.


imho https://pairdrop.net/ is the best one of these


PairDrop is quite nice, it's my go to as it always works. It's a fork of the simpler SnapDrop.


There's a little mention that's easy to miss:

> With a powerful new emulator, Prism, your apps run great, whether native or emulated.

Curious to hear more about what strides they've made there.

UPDATE: Found more details here -> https://arstechnica.com/gadgets/2024/05/microsoft-says-prism...

10-20% faster emulation


I ran windows under qemu, with a GPU, and a dedicated soundcard, and multi-monitor for years - even though ostensibly there was a 10-15% "overhead" due to emulation/virtualization. I had exactly zero issues, and to be quite frank i couldn't tell any difference in framerates, especially compared to my windows laptop running the same games with roughly equivalent GPUs.


Could you share a little more about your setup? I assume a linux host, and perhaps 2 GPUs with one per OS? I'm guessing it's a desktop build and not a laptop (iGPU+dGPU)?

I've really wanted to switch fully to linux, but I still use some "power" features in MS Office which apparently don't play nice on linux. Dualbooting Fedora is decent... when I can understand what's happening and don't need to go 4 layers deep every time I have a problem, unfortunately.


ryzen 3700 64GB(total), gentoo on NVME, nvidia 1060; windows on another NVME as a qcow (or whatever), nvidia 1070ti, 8 physical cores no HT, 32-48GB RAM.

you have to disable the specific GPU you want to use for another OS in the kernel command line - this means you need two different spec/brand GPUs, probably. There were some tweaks that i could probably dig out eventually, but most of what i used to troubleshoot were the archlinux wiki and forum posts pointing to blogs. However if you're just needing Office, just installing windows in qemu on literally any GPU will probably be just fine!

you can rsync the qcow to back up the entire windows OS.

for me to run games and audio software in windows my command line was:

qemu-system-x86_64 -enable-kvm -m 1024 -cpu host,kvm=off -smp 4,sockets=1,cores=4,threads=1 -device virtio-scsi-pci,id=scsi -device vfio-pci,host=0d:00.0,x-vga=on -device vfio-pci,host=0d:00.1 -drive if=pflash,format=raw,readonly,file=/mnt/m2bay/ovmf/OVMF_CODE.fd -drive if=pflash,format=raw,file=/mnt/m2bay/ovmf/OVMF_VARS.fd -drive file=/mnt/m2bay/windows10-01.img,id=disk,format=raw,if=none -device scsi-hd,drive=disk -drive file=/mnt/synology/iso/Windows_10-32_64_pro_home.iso,id=isocd,if=none -device scsi-cd,drive=isocd -drive file=/mnt/synology/iso/virtio-win/virtio-win-0.1.171.iso,id=virtiocd,if=none -device ide-cd,bus=ide.1,drive=virtiocd -usb -device usb-host,hostbus=1,vendorid=0x046d,productid=0xc31c -device usb-host,hostbus=5,vendorid=0x1a2c,productid=0x0042 -soundhw hda -vga none -object input-linux,id=kbd,evdev=/dev/input/by-id/usb-Logitech_USB_Receiver-event-kbd,grab_all=y -object input-linux,id=mouse,evdev=/dev/input/by-id/usb-Logitech_USB_Receiver-if01-event-mouse

you press both ctrl buttons to switch back and forth between host and guest, windows gets its own ip. Running office wouldn't require >60% of that stuff

i should note that command line is probably from the first time i got it working, i'd have to boot that machine to get the latest version


Thanks a lot! I'll come back to this when I set up my system properly.


I think it's very close to landing into the release version. I've seen people discuss it working in the testflight/beta release on iOS


https://pairdrop.net

I've tried all the options in this thread but only discovered pairdrop 20 minutes ago (thanks to this thread) and it's by far the best option.


I've been using localsend, mostly without issues. This thread has made me discover pairdrop.net and I have to say it's miles better. I've switched all my devices over now. The iOS integration with the provided shortcut + permanent pairing, in particular, is really good.


I have kept a list of other similar file sharing tools to send files p2p https://gist.github.com/SMUsamaShah/fd6e275e44009b72f64d0570...


Could you add https://drop.lol to the list (also open source)?

Disclaimer: I'm the author of drop.lol.


Your website hijacks the "Back" button (e.g., when I press CMD+[). That's a big no.


My apologies, this is not intentional, just has been an issue I have had always forgotten about. I'll take another look at it now.

Thanks for reminding me.

Update: Fixed. (Expected this to require a rewrite but... it was just a matter of passing one option to react-router.)


It still hijacks back button on Brave/Chrome.


Have you tried clearing cache? (I've configured the server to be a bit more aggressive about caching to improve load speeds, but JS bundle updates should be available instantly.)

I've just tested on Chromium 118.0.5993.70, Firefox 118.0.2 and Safari (iOS 17.0.3) and the issue seems to be gone.


Back button works for me on Firefox 118.0.2 (Linux). Posting because the other guy might not respond, I think the bug made him a little mad.


Just added


A table with feature checkboxes for comparison would be nice.


I actually have switched to Localsend from Pairdrop. My experience is that is Pairdrop is slow especially compared to Localsend. This is while hosting the application on my local network.

I do prefer the WebApp approach so I don't have to install something on each machine before sharing files, but the bug ticket in Pairdrop does not make me hopeful for a good solution (see: https://github.com/schlagmichdoch/PairDrop/issues/44)

Are you able to achieve similar performance in Pairdrop that you did with Localsend?


I haven't compared performance, as it's not a bottleneck for me. A 70mb file took a few seconds. Localsend could very well be faster, being a native app.


I don't know. After discovering PairDrop too, thanks to comments here, I've been testing it out to see if it could replace Warpinator [1] as a means to send files & directories between my PC and my Android phone when I'm at home.

First impression has been quite disappointing... I installed the PWA to my phone's home screen. Then opened up and paired with my PC as trusted device. Tried to send a PDF file from PC to phone, a dialog shows up with

File Received. PC has sent: file.pdf. Close/Download.

Upon clicking Download, Firefox (which is configured in Android as the default web browser) opens up, on the Homepage tab. Nothing else happens, and the file isn't downloaded. So I'm left pretty much confused about what should have happened vs. what did actually happen.

(EDIT: Turns out installing the PWA from Firefox doesn't work as well as doing the same from Chrome. The latter does actually integrate it as a real Android app, and it then works as expected. The Firefox integration of PWAs with Android is a bit lacking, it seems.)

Good thing about Warpinator (and something I use a lot) is that you can enable accepting files without confirmation, and then you can drag & drop a whole folder to have it appear on the other device as-is. Something extremely useful but that I doubt web apps can achieve.

[1]: https://github.com/linuxmint/warpinator


SyncThing works really well after you set it up. It's not as straightforward as pairdrop but it has served me well.


You should know that WebRTC is not ideal for this use-case, it has inherent performance and discovery issues. All web-based solutions are flawed until hypothetically the browsers and/or WebRTC step up their game. Fine for a pdf or something, but try it with large files and you’ll very likely have a bad time.

I must say LocalSend seems pretty great (even though they’re a “direct competitor” to my app https://payload.app/ )


I was able to copy 4GB+ files over WebRTC from Safari (iOS) to Firefox (Linux) without hiccups. The speed is not great though most of the time.


any plans for android app in future?


Yeah for sure. Lack of mobile the biggest downside right now.

Send an email and I can put you in the announcement list (1-2 posts per year tops).


Have you looked at Tauri mobile or it isn't capable yet?


Better than AirDrop too, which shows a notification and then you totally forget where the file went.


Been running my own PairDrop docker container for some months now and it has been amazing.


What's the value prop of running your own instance vs just using pairdrop.net infra itself?


Running it on your own infrastructure?


That's not a value proposition. That's more of a definition :-P

I'm thinking things along the lines of privacy, security, speed, etc


Lots of reasons to self host things for this privacy is a big one but owning a service instead of renting means you don’t need to worry about the landlord or service provider raising prices or kicking you out.


SnapDrop/PairDrop is famous for going offline sometimes. It happened to me once.


>I have to say it's miles better

In what ways?


I must be in the minority here, but I feel YouTube provides enough value that it's worth paying for to get rid of ads.


Correct me if I'm wrong but isn't it fair to say that passkeys secured on your phone are more secure than 1FA (password) but less secure than "traditional" 2FA?

   Passkey 2FA: unlock your phone and the passkey on your phone can log you in.

   Traditional 2FA: remember a password AND unlock your phone (where your TOTP is stored) and you can login
If I were to rate all 3 methods on a scale of 1 to 10, for convenience and security, I'd say:

     Method       Convenience   Security       

  Password only:      4/10        2/10

  Passkey 2FA:        9/10        8/10

  Traditional 2FA:    6/10        9/10
Fair?


Passwordless authentication > hardware-backed MFA > TOTP/HOTP MFA > SMS MFA > no MFA

The reason being is the secret used to authenticate you is non-portable (since it's based on asymmetric crypto, it doesn't need to be shared). On the other hand, portable credentials, like TOTP/HOTP code AND passwords are responsible for almost all compromise today.

Bearer token based authentication will always be inferior to FIDO/U2F - it's not even the same ballgame.


No, if you break into a site using passkeys, it gives you literally zero information that can be used to authenticate as any of the users. Think about the prevalence of data breaches in the past decade, and the sharp rise in the effectiveness of password stuffing, and think about why this change might be a good idea.

Also even with traditional 2FA, TOTP can be phished. See https://github.com/kgretzky/evilginx2

WebAuthn almost entirely eliminates phishing risk (at least with respect to credential harvesting), and Passkeys are a really nice, clean UX for using WebAuthn.


>No, if you break into a site using passkeys, it gives you literally zero information that can be used to authenticate as any of the users. Think about the prevalence of data breaches in the past decade, and the sharp rise in the effectiveness of password stuffing, and think about why this change might be a good idea.

An implication of that is passkeys let you use the same authenticators across multiple services safely. Instead of keeping track of unique passwords across all those services (or worse, reusing passwords), you can just have a passkey-registered phone and one or two Yubikeys for backups/convenience. You'd be a very hard target for account compromise. That setup is highly phishing-resistant and immune to credential-stuffing, without the cognitive load of passwords.


Nobody should be using a remembered password anymore. Most people are likely using the phone for both the password and the MFA code.


> Nobody should be using a remembered password anymore.

Nobody is a strong number, why?

I don't want to use biometrics for logging in to my SSH terminal. I dislike having to use my phone for authentication methods.

I go many places without my phone. Even tempted to gon on holiday without it. Maybe I'm just one of the few who actually enjoys turning it off when coding, developing or whatever.


Not wanting to use biometrics directly for over-the-web authentication is one thing. Not taking the time to understand the technology being employed by Passkeys is entirely another. That’s your fault.


> That’s your fault.

No one's explained it to me. Other than "DoNT UsE PaSsWoRds", that's not my fault.

Why should I have to learn it, why should my mother have to learn it. This an a totally thrown in your face situation.

Theres plenty of posts in this thread explaining to why its a flawed design. You tell me why not.


There are plenty of posts in this thread that are misrepresenting the technology, in a few cases deliberately. If you feel strongly enough to comment, you owe it to yourself and the discussion to go to the source and understand what it's about - that's what I mean by that's your fault. You clearly understand enough to A) argue against biometrics over the wire and B) feel you can comment on Passkeys.

Most, if not all (I've not read every post) of the 'flaws' mentioned generally exist in computer security; for example, no one is impervious to a thug and a weapon. The implementation is as simple as generating a key pair; the private key is stored in a secure enclave, either on device or in a secure location, and the public key is shared with the 3rd party. All services provide some recovery method upfront, clearly stating the importance of a backup. There is only so much they can do before you accept the responsibility for managing your security and privacy online. Resorting to "won't someone think of the children" doesn't help either. My mother, who is 74, has no problem with passkeys.

Is it perfect? No. There are 'better' competing standards, but they don't have anywhere near the consensus of the broader security field. Is it better than the current status quo? Definitely. Public key cryptography is significantly better than username/password combinations, even with TOTP or HTOP second factors, though ultimately, it will be a while before they disappear.


Right, in which case passkeys would be equally secure. But if you DO memorize the password (for example for your most sensitive account), then it feels like traditional 2FA is more secure.

That being said passkeys win if you also take convenience into account. I've updated my original comment with convenience scores to reflect that.


Agree


Would this work as a tool to sync a central server's parts of your postgres data to your distributed webapp backends local-copy, as opposed to all the way to user front-end. i.e. nodejs instead of the browser.

Or is there a better tool for that?


yes, ElectricSQL works for webapps with nodejs: https://electric-sql.com/docs/integrations/drivers/server/no...


I wonder if there's been a scientific study that tries to correlate the tone of a statement, with its reliability.

My gut feel is that such emotionally charged statements are likely inversely correlated with accuracy.

I'm surprised this is the twitter account of a reputable organization.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: