Sign in

Savely Krasovsky

@krasovs.ky
97 followers 182 following 196 posts

Software and Security engineer, pentester, gopher, enthusiast. krasovs.ky

PostsRepliesMedia
Savely Krasovsky @krasovs.ky · 17/12/2025
This is the finished build btw!
010
Savely Krasovsky @krasovs.ky · 17/12/2025
And I run 250W version with i9-14900K, 7 SSD disks and Arc Pro B50! Never had a problem, but ofc i9 is power limited, though still impressive IMO.
000
Savely Krasovsky @krasovs.ky · 17/12/2025
Yep, but I a little bit regret that I didn't pull a trigger on another 96 GB kit! I thought "well, 700 is 100 euros more than I paid a year ago, will wait until prices calm down" 💀
010
Savely Krasovsky @krasovs.ky · 16/11/2025
Yep, I talked with ASRock Rack support and they basically told me that no one tests MB under those conditions so it's most likely Intel firmware or even a hardware issue which no one wants to fix.
000
Savely Krasovsky @krasovs.ky · 16/11/2025
@notthebe.ee hi! I was tinkering hella a lot with Raptor Lake W680 server board with pretty powerful BIOS, but without a lot of success unfortunately. I managed to get C10 only without GPU. Here is my full journey, feel free to ask!
forum.level1techs.com
ASRock Rack W680D4ID-2T/G5/X550 C-states / ASPM problem
Hi, recenly got this board, but cannot figure out how to go below pkg C2 (pc2). My setup: CPU: i9-14900K RAM: two 48 GB ECC UDIMM sticks from Kingston Motherboard: ASRock Rack W680D4ID-2T/G5/X550 (...
110
Savely Krasovsky @krasovs.ky · 19/10/2025
But I have to add that the entire stack of 10 containers added 10W to the server's power consumption. For "doing nothing" that's quite a lot.
010
Savely Krasovsky @krasovs.ky · 19/10/2025
It turned out MAS basically replaced the legacy SSO integration, so I had to migrate. I would clarify that point in the docs better. Also, it seems that standalone Element Call doesn't support MAS for some reason. But overall, it works better than alternative servers.
100
Savely Krasovsky @krasovs.ky · 19/10/2025
I've decided to give it a second spin and picked Synapse this time; hopefully I have a more powerful machine. It worked better that time, with fewer annoying bugs. But I found the documentation unhelpful for OIDC/SSO.
100
Savely Krasovsky @krasovs.ky · 18/10/2025
Do you see the light at the end of the tunnel? Because for now I do not. Panther Lake doesn't really impress me. I don't think Windows/Linux laptops will magically last much longer after switching to a new node process. AMDs next mobile chip will probably be incremental. Qualcomm? Too many problems.
000
Savely Krasovsky @krasovs.ky · 18/10/2025
How did we end up in this situation? I don't like Apple products because of their walled-garden nature, but I have to admit that we're at the point where the MacBook is light years ahead in technological terms.
100
Savely Krasovsky @krasovs.ky · 18/10/2025
Hell, even those heavy-duty workstations are not matching Apple's single-core performance. Memory bandwidth with SODIMM DDR5 is at least two times smaller. Maybe in some cases a discrete (!) GPU can win the graphics battle, but that's it, lol.
100
Savely Krasovsky @krasovs.ky · 18/10/2025
There are no Windows or Linux laptops that will last a full day. None. There are no laptops that come even close to the M4 Pro/Max-maybe only those with a basically desktop-class chip inside a laptop-like chassis and abysmally small battery life.
100
Savely Krasovsky @krasovs.ky · 18/10/2025
I really want to buy a good Linux laptop like a ThinkPad or Framework, but I just cannot ignore how much further Apple is in terms of performance and efficiency.
100
Savely Krasovsky @krasovs.ky · 18/10/2025
The situation around Windows/Linux laptops is bizarre. While AMD clearly has a lead in the Intel vs AMD race, Apple is just smashing both of them.
200
Savely Krasovsky @krasovs.ky · 13/09/2025
And most probably this is the only thing he hosts on that Raspberry.
010
Savely Krasovsky @krasovs.ky · 13/09/2025
So we are stuck forever with Synapse which is like to use a sledgehammer to crack a nut. I just cannot host it on a small server like Raspberry Pi.
110
Savely Krasovsky @krasovs.ky · 13/09/2025
And I again faced all those bugs, slowness and everything I remembered about Matrix. But now I am pissed even more, because the protocol became SO bloated and complex that it's seemingly impossible to write a new implementation from scratch.
110
Savely Krasovsky @krasovs.ky · 13/09/2025
...and since I don't have very powerful server, I was shocked to know that Dendrite is basically abandonware now. Synapse requires a ton of resources so it's a no-go for me. So I went with Tuwunel.
110
Savely Krasovsky @krasovs.ky · 13/09/2025
Well, I've decided to give a second chance, but since I don't want to use your server (because sorry, but what is the point of your fancy protocol then if it cannot be relatively easily implemented and work properly in the federation?)
110
Savely Krasovsky @krasovs.ky · 13/07/2025
This explains a lot, I didn't know it personally. In my opinion desktop should be a priority for you, I don't use mobile app a lot, most of chats in Matrix are hobby/work related for me.
110
Savely Krasovsky @krasovs.ky · 13/07/2025
Latest Element for Desktop, use it rarely from time to time when there are no other options, my account is on envs.net instance, they use Synapse with sliding sync support.
envs.net
envs.net | environments
envs.net | environments for linux lovers - since 9/2019
100
Savely Krasovsky @krasovs.ky · 13/07/2025
In my case I almost never could join the big conference without pain. Missed messages, missed order of messages, missed decryption, etc. It just doesn't freaking work. And they call it a day!
210
Savely Krasovsky @krasovs.ky · 13/07/2025
I assume that "fast loading times" only applies if you are a user of matrix.org instance. In my experience if you are trying use anything else than their flagship instance, you will instantly notice that their federation works good only on paper.
110
Savely Krasovsky @krasovs.ky · 11/07/2025
Unironically big thanks for using Discord instead of Element/Matrix. I genuinely doesn't understand how open source community uses that mess. Literally almost anything is better.
110
Savely Krasovsky @krasovs.ky · 20/06/2025
Tried, but got an error. Probably did:web thing again.
000
Savely Krasovsky @krasovs.ky · 16/06/2025
Got it, makes sense, thank you for your response!
000
Savely Krasovsky @krasovs.ky · 16/06/2025
I understand that it will undermine your goal to force Google extend their program and allow to certify custom ROMs, but I am not sure what is more important here: potentially larger userbase or priciple prevailing.
000
Savely Krasovsky @krasovs.ky · 16/06/2025
Probably dumb question, but in case you will end up selling your own device, isn't it will be also possible to certify the device, pass all Google tests and receive their approval to pass Play Integrity checks?
200
Savely Krasovsky @krasovs.ky · 20/05/2025
This is basically what "Year N Pass" pass is.
020
Savely Krasovsky @krasovs.ky · 20/05/2025
Their Snowrunners DLCs are pretty simple. Every year they release 3 minor updates (usually it's relatively small region with 2 maps) and 1 major (with big region and 3-4 maps inside it). Each DLC (minor/major) has its transport. Any other DLC you can easily skip, they are usually junk.
110
Savely Krasovsky @krasovs.ky · 13/05/2025
Problem is solved using this 3rd party provider: codeberg.org/s1m/hw-fido2... Seemingly it implements Android Credential Provider by reusing code of microG FIDO2 service implementation. It works, not sure how secure this provider though.
codeberg.org
hw-fido2-provider
hw-fido2-provider
110
Savely Krasovsky @krasovs.ky · 13/05/2025
I have no problem in using sandboxed Google Play Services. Bitwarden as Passkey provider works fine. My question is about Security Keys. They work in case of non-residential device bound credentials, but I am not able to register or login using residential credentials.
000
Savely Krasovsky @krasovs.ky · 13/05/2025
Sure, I know. I use Google Pixel 8 with GrapheneOS, though AFAIK entire FIDO2 functionality provided using Play Services which are of course installed. I tested with stock Pixel 6 and yep, I see the option now, strange. @grapheneos.org do you have any ideas?
100
Savely Krasovsky @krasovs.ky · 13/05/2025
Did you test Discoverable Credentials? If I choose `Preferred` or `Required` it asks to save Passkeys only in Bitwarden. Only if I set `Discouraged` it prompts with Security Key options, but in that case it creates Non-residential Passkey.
100
Savely Krasovsky @krasovs.ky · 13/05/2025
@passkeys.dev could you please somehow highlight that even the latest Android 15 doesn't allow to create Resident Keys (aka discoverable credentials) using even newer FIDO2.1 Security Keys?
100
Savely Krasovsky @krasovs.ky · 26/04/2025
Oh, you meant that. I thought something is wrong with my PDS migration and my account is in limbo.
110
Savely Krasovsky @krasovs.ky · 26/04/2025
@cred.blue hey! What does "Profile State: Incomplete" mean?
110
Savely Krasovsky @krasovs.ky · 13/04/2025
Still waiting for did:web support 😶‍🌫️
000
Savely Krasovsky @krasovs.ky · 10/04/2025
Official PDS implementation hasn't any Bluesky branding.
010
Savely Krasovsky @krasovs.ky · 10/04/2025
You don't need to write "Sign in with OAuth2". Just make a single input field for handle and "Next" button. It will redirect user to their PDS and they will see usual form with password backed by their PDS. It's pretty common approach.
130
Savely Krasovsky @krasovs.ky · 10/04/2025
Why not OAuth2? Works well with both official and third-party PDS.
100
Savely Krasovsky @krasovs.ky · 07/04/2025
tbh i even checked the font to use it in my projects because i like the current font a lot. though i wouldn't protest over change
130
Savely Krasovsky @krasovs.ky · 04/04/2025
As someone who escaped from totalitarian regime I can say that you heavily underestimate banhammer power, unfortunately.
050
Savely Krasovsky @krasovs.ky · 27/03/2025
Got it, thanks!
000
Savely Krasovsky @krasovs.ky · 27/03/2025
Okay, PDS supports OAuth2. But how I can view to which apps I provided access and revoke it?
100
Savely Krasovsky @krasovs.ky · 26/03/2025
found another problem:
000
Savely Krasovsky @krasovs.ky · 25/03/2025
New comment interface needs to be fixed! Overall looks great.
100
Savely Krasovsky @krasovs.ky · 25/03/2025
@tangled.sh I have finally finished my knot dockerization, it includes everything. You need to only mount volumes and publish ports (5555 and 22): tangled.sh/@tangled.sh/...
tangled.sh
Docker support · pull #14 · @tangled.sh/core · tangled
010
Savely Krasovsky @krasovs.ky · 24/03/2025
I am dumb. Knotserver should also run under git, problem resolved! 🤦‍♂️
010
Savely Krasovsky @krasovs.ky · 24/03/2025
@tangled.sh could you clarify please, which user should own repositories? When I create repository it's owned by root:root and I cannot push to it, but if I manually chown -R git:git it starts to work. It could be error at my side, since I am trying to run it under rootless Podman.
100