• 1 Post
  • 17 Comments
Joined 1 year ago
cake
Cake day: June 9th, 2023

help-circle










  • Most welcome, and really enjoying this thread for recommendations myself. Others I’ve been to in person in the last 12 months now I’ve had to think about it:

    • Origin coffee, Cornwall - fantastic roastery café, very friendly staff.
    • Buxton coffee roasters, Peak District - generally seem to be darker roasts but have some interesting ideas. Sadly doesn’t have a café
    • Foundation coffee, Manchester - used to have a lot more in store than is currently online, not sure what’s going on. Two very nice cafés though
    • ManCoCo, Manchester - white lie, didn’t go myself in person, but friend I was with did to get me a surprise gift as we were <5 mins away. Was a tasty coffee but can’t comment further.

    Places I personally avoid from experience:

    • Chatsworth house restaurant blend - had this in a Christmas hamper for the past few years, goes straight in the bin as it is undrinkably dark for my taste
    • Pippas London - a front for a huge white label coffee distribution warehouse. Coffee was nice enough, but prefer to support small batch roasters.

    Personally I really enjoy the whole going to the roastery and seeing what they have, trying a few things out etc, so I’m heavily biased towards what’s available to me locally. I’ve got The Nocturn to try when I next run out of Kickback, but as I’ve never tried any I can’t pass any judgement.




  • Aside from SMS/email, which should be avoided anyway for other reasons, or proprietary solutions like MS’ or Steams approach, there is nothing to be gained from TOTP or WebAuthN.

    TOTP (the 6 digit code that changed every 30 seconds, usually) is just a hash of a shared secret between you and the server, and the current time rounded to the nearest 30 seconds.

    WebAuthN/FIDO2/U2F is private by design. Keys/authenticators derive a unique key for every credential pair, you can even register the same key multiple times because of this. About the only thing you gain is knowing what type of authenticator is being used, which is of questionable value at best.