• 7 Posts
  • 29 Comments
Joined 3 years ago
cake
Cake day: June 27th, 2023

help-circle
  • The implication is that sending links to encrypted files with the decryption key added to the URL (eg Thunderbird Send, Mega etc) is not zero-trust. Decryption may take place locally and the key part of the URL may not be sent to the file hosting service, but when the recipient clicks on the link and is served one-off code by the web site, that code may be compromised.

    As we know, the best way to be sure is to do your own separate encryption but without secure-by-design most people will think you are very odd demanding that decryption is done separately and keys are shared through a different channel. Speaking from experience, no matter how much training they are given at work, most people, including HR, would rather you sent them sensitive documents (like passport scans) in the clear as email attachments or at least in a way that involves a single click (Wetransfer etc).





  • A policy I saw coming out of an NHS (UK) department mandated ‘human-in-the-loop’ which is essentially what the article mentions in the end. The risk is that over time clinicians may become complacent with ‘good enough’ and don’t bother to review thoroughly. And it may be easy to spot mistakes, but not necessarily omissions unless you keep your own notes. More so after a long session, although medical appointments are typically short and focused.

    On a positive note, in my experience clinicians using LLMs do indeed spend more time engaging with service users. In an ideal world, they would be given time to engage and take notes, but this is not going to happen.








  • Windows refugee here. I installed Debian 13 with KDE Plasma on my main machine four months ago and I am still ironing out issues. Eg CUPS was asking me to login all the time and didn’t accept my credentials. After some days researching I discovered I had to log in as root. Then, I discovered I didn’t have root credentials for some reason. I had to create them and then add my local user to a group! Just to be able to use my home printer.

    Or suddenly my clock was 62 minutes off. I discovered the NTP service was never set up properly and I had to install chrony.

    I don’t see how I could have avoided using the terminal. These are only a couple of examples. No deal-breakers and on this occasion I had the time and determination to resolve them. I could have easily given up.



  • I am on Debian 13 KDE Plasma with Wayland. I tried kdotool as @Erwan suggests but as expected xprop doesn’t return anything. Apparently, I will also have to use kwindowprop which will take a while to appear on Debian Stable.

    There used to be a thing in KDE where you could execute actions and macros based on window titles

    Now, that would be nice but unless there is another way it looks like I will have to wait.

    Thanks for the help.




  • I share your concerns about trust. With flatpaks we can still read the source and commits, but not many will or can do this every time they install and update software anyway. In this sense, we have little choice but to trust the verified developer and the community, who may of course be compromised too, regardless of distribution method. I suppose with flatpaks we have to check permissions and make them as restrictive as possible.


  • This ranking is very close to how I see this. Anything after Docker/Podman is out unless I absolutely need an application in which case keeping a record of dependencies is a good idea. But I want to know the work system will absolutely start in the morning hours from a deadline. Avoiding single points of failure is another way of course (ie multiple systems, OSes, backups, password managers etc).


  • I remember the time applications came on floppies, 640kb of RAM was indeed enough for anyone, and people competed in writing games in one line of BASIC (yes, that was 255 characters code max). Containers feel horribly wasteful to me, but I came to accept there aren’t many realistic alternatives for the average users who need reliability with zero effort. Making a note of dependencies in case you need to backtrack is not a realistic proposition for most. But I can understand why some users will want full control and a lean setup.


  • I agree with the popular view that Debian Stable + KDE Plasma + Flatpaks (or Appimage, Docker) strikes a balance between system reliability and freshness in selected applications when that counts. I may be missing updates for KDE Plasma but v6 is quite mature so I don’t mind. I know storage is cheap but I am instinctively uneasy with containerisation as it’s done by Flatpaks etc because of the duplication you get with all-in. But if that’s the price of reliability, so be it. It’s just that sometimes there is only a PPA or a .deb, which is why I asked.

    EDIT: I just tried distrobox for the first time. It is amazing how efficient it is. I ran Firefox on Arch and I couldn’t tell the difference in resources. Amazing really.



  • I have been preparing the move to Linux for years, switching to FOSS cross-platform applications on Windows and installing Linux on my secondary machines. A few weeks ago I made my work machine dual boot with the intention to remove Windows completely. I find that I never log into Windows at all already, and my Debian Trixie + KDE Plasma experience is the same in many areas (mainly because I use the same applications as before) and vastly better in others.

    There were issues I had to solve but nothing major. It is true that Windows has been very stable and efficient for me, but people forget that when this happens it is the result of many years of learning, fine-tuning, decluttering and getting used to Windows. You get to that stage with Linux very quickly, and it feels much better.