Yes, technically. As always, it depends on your threat model.
They suggest a separation of TOTP and the rest in two different files
Yes, technically. As always, it depends on your threat model.
They suggest a separation of TOTP and the rest in two different files
I use a synced kbdx file on Linux (keepass-xc) and Android (KeePassDX) daily with the same keepass file. It handles all my logins, TOTP, passwords, passkeys no problem. I synchronize it using syncthing. When the two machines are on the same WiFi (or on a meshed VPN like tailscale) and can talk to each other, they sync freely.
I know someone who has it set up the same way who also uses Windows in the mix.
I haven’t checked the code, but it seems the writes the file is not actively being held open for reading and writing, with constant updates happening, updates appear to be transactional. I’ve only ended up with two sync errors in 3 years of daily syncing and I was able to merge the two files with the keepass-xc cli merge options.
The key distinction here is the program keepass-xc is not keepass the standard, just a program for reading the kbdx vault. A really good, externally audited, well coded, security first program for reading the vault!
If you’re concerned about the sync, it might be worth checking out how the original program expects DB sync to be done.
If you’re concerned about the manager working across os’s, don’t be. The primary use case, in the browser, is cross-platform by way be being a browser add-on. The brains of the operation are bundled in the keepass-xc app as a local server that only gets enabled when you switch on browser integration in the manager. The browser add-on sends web addresses to that server, and then the manager looks up the response, and sends back the correct credential. This interchange is encrypted during the pairing process.
On Android, KeePassDX hooks in to the built-in passwords, passkeys, and accounts ‘preferred service’ and offers password autofill in the keyboard suggestions bar, and comes with a credential-fill keyboard you can switch to on the fly if needed. It also saves passwords in normal apps, by storing the app id in the credential under a custom field ‘AndroidApp’ to help narrow down hinting. E.g. com.hjiansu.thunder for my Lemmy app, or com.android.settings for WiFi SSIDs and PSKs.


Other people have answered this question but, it’s worth noting that it’s different per country, but there are at least two types of reporting treaties. Type 1, they report to the local government who does the reports to the IRS, or Type 2 where the businesses (FFIs, foreign financial institutions) themselves report account info directly to the IRS via online FATCA portals.
There are very few Type 2 countries.
Edit: Adding links
https://www.irs.gov/businesses/corporations/fatca-governments
https://worldpopulationreview.com/country-rankings/fatca-countries


FYI, scrcpy can be an excellent tool for remote support, but you’d better trust the network the interface is on


Some of it is dark if you sit thinking about it too long. The toaster has a nightmare about choking it’s master with smoke, forks being stuffed in it, and falling in to a full bath. I wouldn’t have thought any of this is scary for a toaster, rather it shows a preoccupation with its master somehow committing suicide with it.
On the flip side, my three year old just watched it, and is now obsessed. We’ve watched it 5 times this week. She loves it - even the “It’s a B movie show” song.


The same way they’re planning to upload new ads.


I was using Slide for Reddit ages. Thunder’s worked for me, pretty much happy.
The only thing I miss from Slide is the option to cache stuff offline for plane rides and stuff.
Maybe Summit will be the answer, because I’m interested in trying piefed and it boasts a ‘Powerful caching system’


I would dearly love to know how many if statements are between me and the brakes.
Also, being able to prove that that the CAN bus and RTOS system was air-gapped from whatever bullshit uplink to the internet ends up in there would be worth ~20K extra to me.




More like every single mugging is going to now involve smashing your glasses just to be safe
Some noise canceling is better than others. If you get a chance to try another set, see if it still hurts
You can never be vulnerable to an exploit if you never reuse the same code twice


You shut your mouth that song is great. It’s no Favorite Game, but it’s still good!


The right way is some sort of inline water flow sensor, so it’ll trigger within seconds of you turning on the shower to warm it up. With an esp32 and a sensor, and some clever use of the sleep function, it’d probably last a year or so on a couple of AA’s.
Low effort and price tech is probably better in a wet environment though! If you just want the mood lighting, get a wireless button and stick it somewhere near. Tap it on, tap it off!
If you want to feel that automatic magic, consider a cheap battery powered temperature sensor. If you fix the chassis to the shower head pipe it’d probably be accurate enough. Also, assuming you need to wait for your shower to heat up, you’d have a pretty good idea when your shower was hot too - when it triggers your automation for the lights!
Just make sure the sensor polls often enough or can be made to report on a significant temperature difference in a timely fashion. Something like this might do it: https://sonoff.tech/products/sonoff-zigbee-temperature-and-humidity-sensor-snzb-02p
Also avoid WiFi for buttons, connection and addressing takes ages and sicks for an instant response needed for something like lighting changes


tl;dr:
If you think something is blocking DNS traffic, you could try configuring DNS-over-HTTPs or DNS- over- TLS and picking a reputable upstream. This should obfuscate the traffic somewhat and get past common DNS interference issues and tactics.
So building on what yourself and everyone else has said, it does seem to be a DNS issue.
I found that at select times my local ISP was up to shenanigans with DNS.
I live in a very small country and work in IT. The NOC for all three ISPs and I have met. It would surprise me if they were competent enough to do this intentionally for malicious purposes.
If you can get access out to the internet via ping, see if you can do other things - get on a VPS and test with tcpdump at both ends. There’s a few free ones or trials great for disposable purposes like this. Set it up in advance…
You won’t know what it is til you troubleshoot.
I’ve had huawei firewalls reaching some simultaneous connection limit and fail, reversing their ruleset - blocking everything except ICMP, tr069 and ssh (concerning) outbound…
I’ve had problems with specific DNS servers, through the ISP’s network.
I’ve seen regular BGP changes causing outages all over the place (the ISPs locally don’t peer with each other…)
Post your findings, would love to help/hear!


An interesting argument would be to require the training data to be shared to prove it was never exposed to the original source it’s ripping off.
It might help set a precedent that would make this sort of thing less attractive


Do you subscribe to karakeep lists? Are they of infinite length?


That matches my experience too. I’d still recommend switching to vibrate to prevent the next call from embarrassing the user further
Not ideal for the PC but I can offer a solid phone solution.
ArchiveTune has all the power of YouTube music, none of the ads or subscriptions.
Not sure how you’re going to import that playlist, but it can sync playlists from YouTube, which might work for you.
And if all they care about is their playlist, playlists can be downloaded, so even if it breaks later, you’d still have it.