Kushan
@Kushan@lemmy.world
Formerly /u/neoKushan on reddit
- Comment on Password managers are less secure than promised 5 hours ago:
From the paper itself:
We had a video-conference and numerous email exchanges with Bitwarden. At the time of writing, they are well advanced in deploying mitigations for our attacks: BW01, BW03, BW11, BW12 were addressed, the minimum KDF iteration count for BW07 is now 5000, and their roadmap includes completely removing CBC-only encryption, enforcing per-item keys and changing the vault format for integrity. On 22.12.25 they shared with us a draft for a signed organisation membership scheme, which would resolve BW08 and BW09. At our request, to maintain anonymity, they have not yet credited us publicly for the disclosure, but plan to do so.
I didn’t look at the response to other Password managers, but the gist here is that the article is overblowing the paper by quite a bit and the majority of the “issues” discovered are either already fixed, or active design decisions.
- Comment on [Ubuntu] [Docker] Need help with Nvidia hardware acceleration in Jellyfin 1 day ago:
In your compose file, make sure you’ve added
runtime: nvidia.You also don’t need to deploy the resources and reserve the GPU, you can remove the entire
deploysection when using the nvidia runtime. - Comment on Overseerr & Jellyseerr to merge into Seerr 1 day ago:
I just changed my compose reference to update the volume and base image. Worked a treat.
- Comment on Overseerr & Jellyseerr to merge into Seerr 1 day ago:
Jellyfin is a fork of emby (from when it went closed source), so that makes sense. They have diverged quite a bit but seems the Auth hasn’t changed enough.
- Comment on Western Digital runs out of HDD capacity: CEO says massive AI deals secured, price surges ahead 2 days ago:
HDD prices have been creeping up for a while now. I noticed this as I was looking to add more storage to my server, checked prices late last year, figured I’d hold off a bit longer, checked again a few weeks ago and they were much higher across the board. Also a lot less stock for higher capacities. Took the plunge, bought enough storage to get me through the next few years.
Glad I did as the drives I bought have continued going up in price. This article just confirms it for me.
- Comment on MyMiniFactory has acquired Thingiverse 2 days ago:
True but thingiverse has been neglected for years now. Printables, Maker world, thangs, etc. are much better sites with a much better user experience.
Thingiverse was dying before this take over, so hopefully they’ll improve it.
If not, there’s plenty of competition out there.
- Comment on Western Digital details 14-platter 3.5-inch HAMR HDD designs with 140 TB and beyond 1 week ago:
I’m running a TrueNAS build which has just grown in time. Started off at 5x8TB drives, then added 5x16TB drives and just last week added another 5x26TB drives (that was costly ☠️). It’s all running in a very cheap case using an old threadripper machine I had (2950x), which thankfully supports ECC (128GB purchased years ago before the sillyness).
- Comment on Western Digital details 14-platter 3.5-inch HAMR HDD designs with 140 TB and beyond 1 week ago:
It’s about the storage I have in my server right now - using 15 drives ☠️
- Comment on Looking for FOSS server monitoring UI 1 week ago:
Start off simple, use something like uptime-kuma just to check your services are available - takes minutes to set up and can send you notifications when something goes down. It can plug into docker directly to check if a container is up, as well as perform HTTP checks that the service is responding, plus some other cool stuff.
(Side note, I set up ntfy to handle notifications and it’s great! Another solid recommendation but you can use discord web hooks or whatever as well)
The other options described here are good for gathering and visualising data, but it takes quite a bit to set them up and even more to configure the right kinds of alerts to notify you when something is wrong. A simple “is this docker container running” check or a “does this respond with a http 200” check gets you like 95% the way there.
- Comment on It Turns Out That When Waymos Are Stumped, They Get Intervention From Workers in the Philippines 1 week ago:
I’m guessing it’s the latter, they need to keep accidents to a minimum if they’re ever going to get broad legislation to legalise them.
Every single accident is analysed to death by the media and onlookers alike, with a large group of people wanting it to fail.
This is a prime example, we’ve known about the human intervention for a while now but period people seem surprised that those people are in another country.
- Comment on World's largest particle accelerator begins warming thousands of local French residents with waste energy from the 16-mile Large Hadron Collider 2 weeks ago:
It’s not really the same thing today as it was 15 years ago. It also hasn’t been running continuously that whole time. They regularly stop experimenting to build new extensions onto it.
I visited the LHC back in 2019 and at the time they were expanding it even then.
- Comment on Haha that's really cool, funny number man 3 weeks ago:
“I love Lemmy” mfers when they’re not self housing their own instance so they can test charges before submitting a PR to the repo.
- Comment on YSK: A real American Civil war will NOT be like Battlefield or COD. 4 weeks ago:
I’m not saying he was a good person, but the logic of “they deserve it” applies on both sides, even if one side is disproportionate to the other.
Kirk deserved it for the horrid shit he said and the vitriol he spread, I can absolutely see some right winger saying someone else deserves it for living in the dem part of town or looking a bit gay.
- Comment on YSK: A real American Civil war will NOT be like Battlefield or COD. 4 weeks ago:
It’s too late, it’s already starting to happen. People are already having to dodge ice just while going to work, Charlie Kirk literal got sniped while at work.
It’s going to get worse before it gets better.
- Comment on who's gonna tell him? 4 weeks ago:
I looked and couldn’t see it.
- Comment on Digg launches its new Reddit rival to the public 4 weeks ago:
Superior technology does not necessarily mean a superior product. History has plenty of examples where the inferior technology won out because the majority of people don’t care about having the best or most advanced technology, they want the easiest, cheapest and (most importantly) lowest effort.
To be clear, I don’t think digg is a superior product either, I’m just saying that how good the tech is matters far less than people want to believe. What truly matters is the implementation.
- Comment on Bill Gates, Jeff Bezos and Sam Altman among billionaires investing in 'Freedom City' to be built on Greenland 5 weeks ago:
He’s a means to an end for those that want to do whatever the fuck they like. Can him the smartest man you’ve ever met, throw him some pocket change and give him a fake trophy, he’ll do whatever you tell him.
- Comment on I love science 1 month ago:
We’re gatekeeping science now?
This is just the equivalent of “oh you like <band>, name all their albums”. It’s dumb and you don’t need to be an expert to appreciate something.
- Comment on PS5 ROM Keys Leaked: Sony’s Unpatchable Security Nightmare (2026) | The CyberSec Guru 1 month ago:
My dude, have you tried not being a cunt for no reason lately?
- Comment on PS5 ROM Keys Leaked: Sony’s Unpatchable Security Nightmare (2026) | The CyberSec Guru 1 month ago:
Yeah I checked the twitter profiles of the two people mentioned, one doesnt talk about it at all and the other says it’s not what people think and it won’t enable CFW.
AI nonsense.
- Comment on PS5 ROM Keys Leaked: Sony’s Unpatchable Security Nightmare (2026) | The CyberSec Guru 1 month ago:
It’s really not. Literally the same thing happened with the PS3, arguably that was much worse and it didn’t cook Sony at all.
- Comment on Taiwan chipmaker TSMC begins 2nm chip volume production 1 month ago:
No because apple bought up almost the entire 2026 allocation.
- Comment on Plex’s crackdown on free remote streaming access starts this week - Ars Technica 2 months ago:
It’s entirely hypothetical. Jellyfin could also close source tomorrow, hypothetically (It happened with Emby so there’s precedent).
- Comment on Plex’s crackdown on free remote streaming access starts this week - Ars Technica 2 months ago:
This is a "slippery slope’ argument and thus a fallacy.
Let users decide how they want to run their own stuff. Right now if you have Plex pass this isn’t an issue. If it becomes an issue, then you’re in the exact same position you’d be in today if you decided to move away from Plex now.
I moved away from Plex years ago, but I don’t blame users for sticking with it, it still has a lot of advantages over jellyfin.
- Comment on flock + ring = ice 2 months ago:
Sure, the effort to set up an actual working thing will always be more than setting up a broken thing.
- Comment on flock + ring = ice 2 months ago:
The only drawbacks to having actual security cameras is when you trust your data to a 3rd party known to use your data for evil.
If you record things locally, there’s really zero drawbacks.
- Comment on Hard drives on backorder for two years as AI data centers trigger HDD shortage — delays forcing rapid transition to QLC SSDs 3 months ago:
The explosion of scam coins was basically inevitable, it’s what you get with zero regulation.
- Comment on PRUSA releases the OpenPrintTag, open source standard for filament spool identification and data tracking 3 months ago:
I have to admit I gave in and bought one, despite my misgivings about their approach and at this stage I have no regrets. It really does “just work” in a wonderful way.
At first I was annoyed they used non standard nozzles, but AliExpress sorted that out in no time. The nozzles they use on newer machines are pretty great too, no more burning myself trying to unscrew a nozzle to swap it.
There’s no doubt that some of their decisions have been questionable, but some I really do agree with.
- Comment on PRUSA releases the OpenPrintTag, open source standard for filament spool identification and data tracking 3 months ago:
I’m still sore after Bambu’s whole slicer locking down bullshit, but you can’t deny that Bambu also got the entire 3D printing industry to pull their collective fingers out and start actually making great printers that “just work” - including prusa, who were very clearly caught off guard as well. Before Bambu came along people were still recommending Ender’s as a good “first printer”, which is all you need to know. Now there’s a ton of good options (including prusa).
- Comment on PRUSA releases the OpenPrintTag, open source standard for filament spool identification and data tracking 3 months ago:
“a” setting?
Do you have any idea how many settings there actually are for a proper print profile? Never mind usage amounts which are tedious to track.
You can also just not use it.