Local timeline
Interestingly, Claude Code can draw more power than my MacBook Air power adapter can provide (25W).
I know what I'll be recommending to all friends and family from now on.
I was already deep into writing a custom data migration script because the original script doesn't include attachments. All of a sudden, the "what the hell am I doing for ~30USD/year" moment hit.
Spent a few hours researching alternatives to #1password, due to their cost increase. For me, it boils down to three scenarios.
a) Migrate to Bitwarden Cloud, save ~25 USD/year, but deal with migration hell
b) Migrate to Bitwarden self-hosted through Vaultwarden, accept community risk, and lie awake at night about server hardening
c) Stay with 1Password and live a worry-free life for the cost of a cup of coffee per month per user
I'll be going with C. Thank you for coming to my TED talk.
Zo zie je: beide kan waar zijn. Zijn er plaintext wachtwoorden gelekt? Waarschijnlijk niet. Zijn er plaintext verificatiewoorden gelekt? Waarschijnlijk wel. Dat is nog steeds niet best, maar het is een wezenlijk ander risico dan je accountwachtwoord dat op straat ligt.
Odido heeft ervoor gekozen dit verificatiewoord leesbaar op te slaan in hun CRM. Technisch had dit anders gekund, maar het verklaart wél waarom de hackers "wachtwoorden" in plaintext aantreffen terwijl Odido zegt dat er geen inlogwachtwoorden gelekt zijn.
Maar: je kan bij Odido telefonisch een "verificatiewoord" afspreken. Dit is geen inlogwachtwoord. Het doel is dat de klantenservice kan controleren dat ze met de juiste persoon spreken vóór ze wijzigingen doorvoeren.
Voor accountauthenticatie gebruiken bedrijven op deze schaal eenrichtingshashing. Dat betekent dat zelfs Odido zelf je wachtwoord niet kan uitlezen, ze kunnen alleen controleren of wat je invoert overeenkomt. Plaintext wachtwoorden voor miljoenen accounts? Dat is uiterst onwaarschijnlijk.
De gestolen data komt uit een klantcontactsysteem (CRM), niet uit een authenticatiedatabase. Dat zijn twee compleet gescheiden systemen met een ander doel.
#1password hasn't been heading in a direction I really like, and that's a shame because I've been a paying customer since 2012. It's time to start looking elsewhere.
Just finished the last milestone before taking a new web server in production: The full recovery test after wiping the filesystem.
Went without a hitch. ReaR is a very cool tool. Highly recommend for backing up & restoring bare-metal machines. It even fully restores software RAID configurations.
Ran my first half-marathon this morning. Feeling very grateful. The training through winter, despite rain, cold, and snow, is really paying off. At this point, the mid-March race feels like a victory lap.
Am craving a nap right now, though.
Does anyone have experience with Hostkey? Their prices are interesting.
(follow-up)
The printer finished the order of business cards this week, and I quite like how they turned out. Going to leave these at entrepreneur-heavy hotspots like the post office soon.
For the past year I've been building out my website to better showcase my services, something I'd always avoided because most work came through word-of-mouth.
The hardest part? Reaching out to former colleagues and clients to ask for testimonials. It felt uncomfortable, honestly.
But seeing their words come together on the page makes me genuinely grateful for the projects I've been part of: https://jorijn.com/en/work-and-results/
Also, I ate everything in my fridge and am now very tired.