IsoKiero
@IsoKiero@sopuli.xyz
- Comment on MAGA has been swooning over an Army soldier and her pro-Trump message. She is AI 2 weeks ago:
So creating an onlyfans account using Grok is profitable?
- Comment on I am an American. I used to be proud of my country. Now it feels like a turd circling the drain. Is there anything going on behind the scene that America is actually doing good in? 2 weeks ago:
the joke was that in the USA you can be multi millionaire+ wealthy and pay 0% tax
That is the actual joke here, agreed. If, and that’s a pretty damn big if, there was any sense on USA government they could just take our progressive steps and leave everything above 35% away from it and still have a crapload of budget to actually make their country great again.
But spending 100 million bucks per hour to demolish schools half way across the world is cool too I guess.
- Comment on I am an American. I used to be proud of my country. Now it feels like a turd circling the drain. Is there anything going on behind the scene that America is actually doing good in? 2 weeks ago:
You don’t need to be Elon-wealthy to get those percentages. Over 500 000€/year salary gives you nice 50% tax bracket. You absolutely are not poor if your taxes are that high, but you don’t need to be CEO of Google either.
- Comment on This is Android's new 'advanced flow' for sideloading apps without verification, includes one-day waiting period 2 weeks ago:
This does not apply to “installing software”.
So it doesn’t apply when I click the big button which says ‘Install’ on F-Droid app on my phone?
And it does come with risk,
Just like installing software from the ‘secure’ Google Play store.
Installing software is installing software, no matter where you get that software from. That’s it. You can try to twist that with nuances on terminology or invent new ones, the end result is that an piece of software is installed on the system and nothing more. It doesn’t matter if the software came from play store, f-droid, steam, windows store, shady google drive link or the pirate bay. It doesn’t matter if you’re a power user or never seen a smartphone before in your life.
Sure, there might differences in potential security, compatibility, licensing and whatever, but it is still a piece of software being installed.
- Comment on This is Android's new 'advanced flow' for sideloading apps without verification, includes one-day waiting period 2 weeks ago:
“installing apps from outside the Google Play Store”
To me that implies it’s somehow different than just installing software. You could say ‘install from play store’ or ‘install from f-droid’ if you need to specify which app repository you should use, as that what it is. Sideloading might be an appropriate term if you need to upload apk to your device via USB-cable from your PC, which the term originally meant.
to make it sound somehow dangerous or complicated in order to justify
[Citation needed]
From the article:
This “advanced flow” is for power users and enthusiasts who “want to take educated risks to install software from unverified developers.” Google says it was “designed carefully to prevent those in the midst of a scam attempt from being coerced by high pressure tactics to install malicious software.”
Sure, the term itself comes from 1990s, but lately specially Google tries to twist that to mean something only ‘power users’ do and it comes with a ‘educated risk’.
- Comment on This is Android's new 'advanced flow' for sideloading apps without verification, includes one-day waiting period 2 weeks ago:
Do you consider installing games to you PC from Steam sideloading too? What about downloading Firefox installer? It is installing software on your computer, no matter if that computer happens to be in a cellphone form factor, and always has been. Sideloading is a made up term to make it sound somehow dangerous or complicated in order to justify even bigger walls on the ecosystem garden and control how people use their own devices.
- Comment on This is Android's new 'advanced flow' for sideloading apps without verification, includes one-day waiting period 2 weeks ago:
“This is Android’s new ‘advanced flow’ for INSTALLING apps without verification”. Sideloading is such a bullshit term made only to confuse consumers. They can wrap that in sparkling wrapper, but it’s still security theater at best and definetly misleading. Apps from F-Droid or any other app ‘store’ are not any less safe than the ones at googles own offering.
- Comment on Agent based backup server? 2 weeks ago:
No deduplication, encryption nor support for non-linux operating systems for a start.
- Comment on Agent based backup server? 2 weeks ago:
Not from my wife if I lose our photo collection which has been building up since we got our first digital camera 20ish years ago.
- Comment on Is it possible to have a usable domain without a VPS or a static IP address? 2 weeks ago:
I have dynamic dns address and a handful of CNAME records on my domains pointing on that dyndns-address so I can use ‘proper’ names with my services. When my public IP changes it takes a few minutes for the records to update, but it usually happens only when my router reboots so it’s been good enough for me.
Also I use two separate dyndns providers so there’s likely at least one working DNS entry to my network.
- Submitted 2 weeks ago to selfhosted@lemmy.world | 12 comments
- Comment on Self Hosting for Privacy - Importance of Owning your own Modem/Router? 2 weeks ago:
I’ve always liked the way slashdot handles comment rating. It’s a bit complicated, so maybe that’s why it’s not adopted elsewhere, but it gives a much more fine grained options instead of just up/downvote.
- Comment on Self Hosting for Privacy - Importance of Owning your own Modem/Router? 2 weeks ago:
ISP obviously don’t see the traffic inside your own network, regardless of the router used. But as soon as you open any kind of connection over the internet, incoming or outgoing, your ISP has to have some information about it to route the traffic. DNS over TLS doesn’t hide that your browser opens connections to servers, they can see if you use wireguard to access your services (not which ones, just in general that there’s traffic coming and going) and even if you use VPN for everything they can still see the encrypted VPN traffic and, at least technically, apply pattern recognitions on that to figure out what you’re doing. And if you use VPN then your VPN provider can do the same than your last-mile internet provider, so you’ll just move the goal by doing that.
Last-mile ISP is going to be a middleman on your network usage no matter what you use and they’ll always have at least some information about your usage patterns.
- Comment on Self Hosting for Privacy - Importance of Owning your own Modem/Router? 2 weeks ago:
ISP can see your traffic anyways regardless if their router is at your end or not. In here any kind of ‘user behavior monitoring’ or whatever they call it is illegal, but the routers ISPs generally give out are as cheap as you can get so they are generally not too reliable and they tend to have pretty limited features.
Also, depending on ISP, they might roll out updates on your device which may or may not reset the configuration. That’s usually (at least around here) made with ISPs account on the router and if you disable/remove that their automation can’t access your router anymore.
So, as a rule of thumb, your own router is likely better for any kind of self hosting or other tinkering, but there’s exceptions too.
- Comment on YouTube ads are about to get even longer and they’ll be unskippable 3 weeks ago:
We need to pick our battles. I don’t see much difference in paying Google for a service than having a Spotify family plan like I do. I know spotify has its own problems and my money would be more ethically spent on some other service, but with everything else going on life I can’t be arsed to switch to anything right now. For me it gives enough value for the money spent and that’s good enough for now.
- Comment on What to selfhost if you have a lot of bandwidth 4 weeks ago:
I’d guess there’s some tools which rely on RSS feeds or something to update seeds automatically, but that’s just a gut feeling. Also it shouldn’t be too difficult to write your own, but I don’t know if anything ‘production ready’ is out there.
- Comment on What to selfhost if you have a lot of bandwidth 4 weeks ago:
Discoverability is one issue and trust for longevity is another. No bigger distribution is going to rely their official download links on an individual home lab which can disappear overnight. Also I guess there’s also guestion if images are provided as is without adding/removing your own ‘extensions’, but that’s what cheksums are for.
And this is obviously on a general level, I’m not trying to suggest that xana is not trustworthy :) But torrent seeding is a helpful thing for community, and easy/safe to set up.
- Comment on I'm struggling to think of any online services for which I'd be willing to verify my identity or age 4 weeks ago:
Age verification is one thing, but I routinely verify my id online. Banking, insurance, taxes, various other government things, car registrations, some of the kids school stuff and so on. We have pretty decent infrastructure in place here in Finland and the entities I identify myself online already has my info anyways. I can use either my banking app or mobile verification to securely prove I am who I claim to be and the systems have roughly the same user experience than MFA tokens.
Each of those are roughly zero-knowledge, the website I log in receives just “User with login token xxx is IsoKiero with SSN 123456789” and the tokens expire after a while. Also there’s restrictions in place that my insurance company can’t just sell my data to whomever unless I opt-in for their “marketing” program (not going to happen) and even then there’s some limitations on how they can use the data.
The same system could be adopted to age verification, but that’s a whole another can of worms.
- Comment on Simple inexpensive cloud backup? 5 weeks ago:
I’m using proxmox backup server to make copies of full virtual machines, it takes care of encryption and verification of the data, so it’s not exactly the same than your scenario. Borg Backup is commonly recommended, but restic and dejadup are worth checking out too.
- Comment on Simple inexpensive cloud backup? 5 weeks ago:
I use hetzner storagebox for similar needs. It’s not encrypted, so you need to manage that by yourself, but they support a ton of protocols and pricing is decent, even if they’re increasing the price shortly.
- Comment on UK fines Reddit $19 million for using children’s data unlawfully 5 weeks ago:
Leaked data doesn’t even need to be dangerous to life. I, like many others, don’t have “nothing to hide”, but I don’t still want my real name next to a list of content I’ve watched from streaming sites. Also I don’t really want my identity tied to this pseudonym, or any other accounts on any platform. There’s a crapload of problems and it would be a heaven for scammers if there was no way to stay at least relatively anonymous around the net.
- Comment on Android will become a locked-down platform in 194 day 1 month ago:
In theory Canonical could lock down Ubuntu like that, but it would be the end of Ubuntu. Switching over to Mint or Debian is not a big deal for majority of the linux-users and also Ubuntu would lose all the advantages they can currently pull off from Debian package maintainers. Also I suppose it would bring a ton of headaches with licenses, but IANAL, so don’t quote me on that. And, obviously, that would kill snapcraft too as I don’t see any incentives for developers to support walled gardens for free, so it wouldn’t be all bad.
- Comment on Instagram boss: 16 hours of daily use is not addiction 1 month ago:
Philip Morris: 1 pack of cigarettes per day is not addiction.
- Comment on New nickel-iron battery charges in seconds, survives 12,000 cycles 1 month ago:
Team expects, may be useful, could be used, prototype, are currently investigating and so on. Cool piece of technolgy, but no even mention when they’d expect that to be commercially available, if it’s even possible to manufacture in commercial scale. Like many other new battery chemistries and technologies, it shows promise and makes a good headline, but at this point that’s pretty much it.
- Comment on Is the Raspberry Pi Still an Affordable SBC? I Don't Think So 1 month ago:
Armbian works on most, if not all, raspberry pi compatible boards. I meant that support from vendor is often a lot shorter than from raspberry and it can cause problems/bugs with bootloaders and drivers unless vendor is actively working with armbian/kernel development for their chipset.
- Comment on Is the Raspberry Pi Still an Affordable SBC? I Don't Think So 1 month ago:
Orangepi and other “clones” often use rockchip on their boards which isn’t as well supported as Raspberry equivalent so it’s not direct replacement. Also their supported lifespan is often much less than rpi.
- Comment on Tor calls for more Snowflake proxies! 1 month ago:
It is, but the sad reality is that while you contribute your capacity for good cause it’ll be abused by bad actors as well. Obviously with snowflake node you don’t get to see what’s excactly going trough, but some time ago I had exit node running and I got several calls from my ISP that there’s malicious traffic coming from my IP address. ISP managed it pretty well when I explained what’s going on but eventually they got so many complaints from other peers on the network that they took ‘hard route’ and told that they’ll take my connection down unless I shut down the node. No hard feelings for the ISP, they took all the abuse mails and other annoyance for me and I absolutely understand their decision. But it’s good to at least acknowledge that tor isn’t just to get around oppressive policies.
- Comment on AI Didn't Break Copyright Law, It Just Exposed How Broken It Already Was 1 month ago:
I wouldn’t compare Swartz with the AI scrapers. Aaron pulled mostly public domain documents from JSTOR and caused minor issues with the servers which is “a bit” different than pulling everything from the internet to a database over a practically global DDOS-attack. But when companies do it it’s apparently somehow different and Swartz was pretty much publicly lynched and eventually bullied to suicide.
- Comment on Finland's Ministry of Justice is considering halting its plans to start using US-hosted cloud services 1 month ago:
It’s a government thing. I’m not sure when they’ve started to consider alternatives, but that renewal process (as old systems are on EOL) has most likely been on the table for years.
- Comment on Frigate NVR Critical RCE Vulnerability 2 months ago:
That’s my use case. But my frigate-box is strictly behind firewall and I access it over wireguard when I’m away.