
Ooops
@Ooops@feddit.org
- Comment on Trump Keeps Wind Farms Waiting Despite Court Ruling 1 week ago:
“new analytical methodology”
faeceomancy?
- Comment on How "secure" is your setup? 2 weeks ago:
Wait… IT isn’t informations technology?
- Comment on Is Authelia enough without fail2ban or crowdsec? 2 weeks ago:
It’s basically two-way TLS. It’s not only your server providing a certificate to prove it’s the real thing and not just some men-in-the-middle device or your connection for redirected, but the other side of the connection using the certificate, too, to show they are actually the devices allowed to communicate.
So this basically revert the security. You are no longer trying to filter out access attempts when they show questionable behavior, but completely reject anything unless it’s explicitly authorized. Which of course only works when you or (a small number you can manually manage of) others access that stuff from fixed devices that you can set up properly.
PS: For me fail2ban does basically something similiar. I have several web interfaces exposed via reverse proxy. But I barely ever use those interfaces manually; normally it’s via apps that access the services via that web interface. So things like failed authentifications or misstyped passwords don’t happen (unless when setting up something new maybe and then I’m there to unban a device manually if I screwed up). So fail2ban is set up to aggressively bans IPs for hours just for a single failed attempt.
That’s keeping all those spammy bots looking for easy targets away very effectively, yet completely invisible for my legitimate use. After all that’s always the core issue: security vs. convenience. You build the best possible security that also doesn’t overly interferes with your normal use. Also the reason there is no on-size-fits-all solution because it’s about your use-case.
- Comment on QBittorrent breaks out of sandbox to commit crimes 3 weeks ago:
it will bring value to […] the community.
I’m inclined to find this more believable than similiar statements of all the usual AI suspects.
- Comment on Expanding my laptops HDD capacity 4 weeks ago:
I’m more irritated than I’d like to admit by the fact that there is no 16V to 6x SATA power converter going with that M.2 to 6x SATA adapter.
- Comment on Solar Has Crossed a Critical Economic Tipping Point | Solar now requires no more upfront capital than coal or gas to produce the same annual electricity 4 weeks ago:
But you are not scalable.
The companies that in my country have already applied for grid connections of more solar and battery capacity than would be needed in the next few years yet waiting and waiting and at some point just giving up would be.
Oh, and now law changes will also kill all future plans as no one will build any more solar with their own money (or get loans from banks) after the decision if they can actually feed in their produced electricity is shifted to the control of grid providers all-well connected or subsidiaries with fossil-fuel focused energy companies.
- Comment on Solar Has Crossed a Critical Economic Tipping Point | Solar now requires no more upfront capital than coal or gas to produce the same annual electricity 4 weeks ago:
I think the more active people are in countering propaganda
Oh, so you never actually tried to talk to those lost propaganda victims conditioned to reject facts (because otherwise they wouldn’t fall obvious bullshit anyway) and can’t be convinced of reality anymore?
- Comment on Solar Has Crossed a Critical Economic Tipping Point | Solar now requires no more upfront capital than coal or gas to produce the same annual electricity 4 weeks ago:
Propagandists spend so much time and money on propaganda
Your mistake is believing that they are spending much money. It’s actually a small fraction of the money they makew from burning the planet, miniscule if compared to the amounts accumulated over decades, and i’s also the easiest option. They could also just buy politicians who are incredible cheap but still more expensive than the ongoing media desinformation campaign.
- Comment on Solar Has Crossed a Critical Economic Tipping Point | Solar now requires no more upfront capital than coal or gas to produce the same annual electricity 4 weeks ago:
They already moved on to different tactics like restricting the ability to connect solar to the grid or simply burying all applications in red tape for years.
- Comment on UK/EU homelabbers: would you host a hardened Pi so I can watch baseball I already pay for? 5 weeks ago:
That’s the probably most unhelpful and stupid thing I saw in quite some time. The AI or Not Quiz right at the beginning regularly links the exact same things to human or to AI (404 links are a sign or AI hallucination or just natural link decay that show it’s from a human; wonky grammar is a sign for AI unless the text is human-written where it’s just bad english that LLMs would not produce intentionally…).
- Comment on Google pays $250K for Linux vulnerability allowing guest VM escapes 2 months ago:
Nobody is saying “Linux is obscure”
How about scrolling up to the exact comment I anwered to? Or -as you seem to be on the exceptional dense side- let me do it for you…
Linux’s “security through obscurity” was never going to last.
As already explained above I did not expect that statement to use the common “long-standing industry term” because -again- it would be utterly insane to claim security through obscurity for something open source.
- Comment on Google pays $250K for Linux vulnerability allowing guest VM escapes 2 months ago:
Yes, please do.
The actual notion of “security through obscurity” (that will surely come up on Google if their AI bullshittery hasn’t screwed up completely…) for Linux is insane because open source is the polar opposite. The often more unprecise and colloquial usage I thus assumed you were using doesn’t apply either, for the reasons I summarised.
So which imaginary definition of “security through obscurity” are you using when none of the real ones makes any sense?
- Comment on Google pays $250K for Linux vulnerability allowing guest VM escapes 2 months ago:
You are right. I don’t know what your personal definition of “security through obscurity” is as it’s very obviously not matching actual reality.
- Comment on Google pays $250K for Linux vulnerability allowing guest VM escapes 2 months ago:
There was never an actual notion of “security through obscurity”. LInux runs the complete Internet and most coporate server infrastructure. That’s where the actual money is.
People hallucinating that Linux is something obscure simply have no clue and confused their home desktop for real computing. Windows desktops are constantly targeted not because they are -unlike Linux- so wide-spread but because they are already insanely insecure. They are the low hanging fruit where you can cobble together some cheap shit and will still find million of PCs vulnerable. If you want to find a Linux comparison it’s definitely not server or desktops but cheap IoT devices not having seen an update (or any security to speak of) for many years.
- Comment on Keep Android Open (Stop Google from limiting APK file usage) 2 months ago:
Petitions are useless
Protests are useless
Governments and corporations conspire to implement surveilance knowing what comes next
<-- we are here
Actual resistence
- Comment on 18% of people running Nextcloud don't know what database they are using 1 year ago:
So one in five doesn’t do proper backups. That’s much better than expected… 😅
- Comment on 18% of people running Nextcloud don't know what database they are using 1 year ago:
Isn’t that the whole point of containerised solutions? Having some pre-setup, auto-updating solution with very little requirement to dive into the details like what your database is and which dependencies you need to manage…