atzanteol
@atzanteol@sh.itjust.works
- Comment on The great silence or why haven’t we found any aliens yet? 1 week ago:
The replies to this story are making me lose faith in humanity.
- Comment on I measured the idle RAM of 19 self-hosted apps on identical hardware so you can size a VPS without guessing 1 week ago:
Is this useful? They’re started but doing absolutely nothing. Who cares? You need to plan for max usage not idle.
My forgejo instance running right now is using 1070MiB. That’s way off your 173MB.
- Comment on White House plan for a ‘golden age’ of science ignores the structures that made the US a scientific superpower 1 week ago:
Trump-branded lysenkoism.
- Comment on Sample 25 might contain proof of microbial life having existed on Mars 2 weeks ago:
Also, it might not.
- Comment on Could objects like stars be considered living? 4 weeks ago:
No.
- Comment on Codeberg bans vibe coded projects 4 weeks ago:
At the very least it’s a mistake to say the law is “settled” at all. It’s barely been tested.
- Comment on Codeberg bans vibe coded projects 4 weeks ago:
Huh. I mostly read people moralizing the use of AI and wanting to slap a scarlet AI on anyone who uses it while derisively using the terms “slop” and “vibe” to poison the well.
- Comment on Keeping Backup Costs Down with B2? 4 weeks ago:
Restic will compress as well.
- Comment on E-mail archive browser for gmail takeout files (.mbox) 4 weeks ago:
You could just install dovecot and search over imap or pop3 from any email client.
- Comment on Google pays $250K for Linux vulnerability allowing guest VM escapes 5 weeks ago:
OMG.
en.wikipedia.org/wiki/Security_through_obscurity
In security engineering, security through obscurity is the practice of concealing the details or mechanisms of a system to enhance its security. This approach relies on the principle of hiding something in plain sight, akin to a magician’s sleight of hand or the use of camouflage. It diverges from traditional security methods, such as physical locks, and is more about obscuring information or characteristics to deter potential threats. Examples of this practice include disguising sensitive information within commonplace items, like a piece of paper in a book, or altering digital footprints, such as spoofing a web browser’s version number. While not a standalone solution, security through obscurity can complement other security measures in certain scenarios.
You don’t know what you’re talking about - please stop. It’s embarrassing. It’s a long-standing industry term not some weird phrase I just made up. Nobody is saying “Linux is obscure”.
- Comment on Google pays $250K for Linux vulnerability allowing guest VM escapes 5 weeks ago:
Enjoy your “security”. 🙄
- Comment on Google pays $250K for Linux vulnerability allowing guest VM escapes 5 weeks ago:
Sorry - which part of your comment added anything of value? “can help to minimize the attack surface”? 99% of the time a proxy just passes traffic through. Unless you’re talking about a WAF which is a) a different thing and b) NOT what any home gamers are talking about when they recommend nginx, traefic, etc. to newbs.
- Comment on Google pays $250K for Linux vulnerability allowing guest VM escapes 5 weeks ago:
Just google the term next time rather than embarrassing yourself.
- Comment on Google pays $250K for Linux vulnerability allowing guest VM escapes 5 weeks ago:
See what I mean?
As if a proxy blindly passing traffic directly to a backend server “reduces attack surface” in any meaningful way. 🙄
- Comment on Google pays $250K for Linux vulnerability allowing guest VM escapes 5 weeks ago:
The self-hosted crowd thinks reverse proxies protect you from the Internet. Don’t expect too much of them.
- Comment on Google pays $250K for Linux vulnerability allowing guest VM escapes 5 weeks ago:
You could have just said that you don’t know what “security through obscurity” is.
- Comment on Google pays $250K for Linux vulnerability allowing guest VM escapes 5 weeks ago:
It goes right to the top!
- Comment on Help choosing a good HDD for my home server? 1 month ago:
2.5’ hdd but besides running tight on space
No wonder - that’s huge! (sorry - couldn’t resist)
While I don’t exactly intend to run RAID
At these sizes you may want to consider it - at least a mirror. That’s a lot of data to lose and/or have to fetch from backups. Being able to limp along until you get a replacement is an enormous time-saver.
- Comment on "Ultimate" guide for literal beginners 1 month ago:
Underrated comment.
A “howto” that just gives you scripts and commands to run is pointless. You need to understand the technology, and networking in particular.
- Comment on Homepage - Selfhosting Dashboard 1 month ago:
No?
- Comment on Help! I need a really simple image hosting solution 1 month ago:
2Gig on S3 (in us-east-1) is like $0.05/mo. and is enough for either Nextcloud or Immich. Your data is going to be the largest consumer of space.
- Comment on Help! I need a really simple image hosting solution 1 month ago:
Things like Immich or Nextcloud are far too much for what I need, I basically just need a password-protected upload interface and the ability to grab the direct links to the images to embed them.
Why do you care that they do things you don’t need if they also do what you need?
Because these do just what you need and do it well.
- Comment on Using a NAS to redirect to another NAS for streaming ? 1 month ago:
Reverse proxies do not give you security.
- Comment on Setting Up OPNsense on Proxmox: Doubts regarding NIC setup 1 month ago:
Agree - critical infrastructure should have as few dependencies as possible.
- Comment on What path does data take when connecting to a domain at my address? 1 month ago:
It’s called “traceroute” on Linux and Mac because there was never a 8.3 filename limitation on them.
- Comment on How my AI Agent views and maintains "our" homelab 1 month ago:
Does… It matter?
Energy use is energy use no?
The energy required to do inference (i.e. amount it questions and the like) is no worse than doing some gaming for a short period of time.
That said it’s probably less efficient to run locally since anthropic and openai have been getting more efficient data center hardware from nvidia compared to consumer desktop gpus.
- Comment on Recommendations for next steps for my setup and order of operations (primarily as it relates to reverse proxies)? 1 month ago:
Unless you have a specific need there is no reason. So long as the domain resolves then you’re probably good. I use AWS so I can easily update the IP since I have a dynamic IP address. Some may use Cloudflare because it’s necessary to use other services or because there’s a ‘free’ option or something? I’m really not sure - I’m not familiar with Cloudflare but I see lots of people using their low-end free services for things.
- Comment on Recommendations for next steps for my setup and order of operations (primarily as it relates to reverse proxies)? 1 month ago:
The tutorials I’d been looking at were showing them overriding the DNS servers at the domain registrar with servers from Cloudflare or elsewhere. Is that just because there may not be an automated way to update the IP dynamically with the domain registrar, but there is for Cloudflare?
Probably because those tutorials are using Cloudflare for DNS services. I actually use Amazon AWS Route53 for my domain (purchased through 123cheapdomains (yes - really)) and I update it through the AWS APIs with a small script.
- Comment on Recommendations for next steps for my setup and order of operations (primarily as it relates to reverse proxies)? 1 month ago:
I was curious what distro you folks might recommend for this purpose.
This is a bit like going to an automotive forum and asking “what’s the best car to buy”. You’re going to get a lot of “I’m running <blank>” and people telling you their preferences, which is NOT the answer to your question. The answer to your question is that literally any of them would be fine for your purposes. If you’re happy with Bazzite then stick with Bazzite. There’s no reason to switch.
If I have to manage it entirely by command line, it will take 10 times longer for me to do anything I want to do, and I’d really prefer a GUI.
Then use a GUI. The extra memory used is trivial and your system will be way over-powered for a reverse proxy to a home network anyway. In Linux land there’s really no such thing as a “server distro” and a “desktop distro” for the most part. I use Ubuntu, Debian and Fedora as servers. They can all have desktops on them too.
You may find, however, that as you manage more than one system it becomes tiresome/tedious to have to use RDP for remote administration and may start learning the CLI over time. Especially since it’s often a lot easier to give somebody a list of commands to run on a forum than to say “open your network manager, which is different on Gnome from KDE, click the button that says…”.
I need something that can sit there without updating until I tell it to
Are you going to update frequently? You want to be sure you’re keeping security patches up-to-date. Auto-patching can be very good unless you have the discipline to keep up with it.
I need a domain for that, and a lot of tutorials just skip on past this step in the domain configuration screens where you “enter your DNS servers” as though I know why I’d need other DNS servers,
You’ve got a bit of reading on how DNS works. But basically there are “root DNS servers” that everybody knows by IP address that then know about other DNS servers by IP and forward traffic to them to resolve names. When you register a domain you are asking one of those DNS providers to resolve your hostname to your IP address. You can see this a bit by running
dig +trace some.host.nameand it will show the requests made. Your DNS servers would be the ones where you register your domain.BUT your IP address may change. So you generally need a way to update it if it does. There are providers like dyndns.org and others (search for dynamic domain service or something) that will give you a sub-domain for free/cheap and tools to auto-update it. Something like “mysite.dyndns.org”.
- Comment on [Jeff Foust] Astronomers fear orbital data centers will interfere with observations 2 months ago:
What problem is this solving? It’s expensive to launch, hard to power, hard to cool, and unserviceable.
Also - no mention of the speed running Kessler syndrome?