NaibofTabr
@NaibofTabr@infosec.pub
- Comment on What are the best learning resources? 17 minutes ago:
Yeah, it’s one of the best reasons to actually RTFM: “How does the guy that designed this think it works? What did they intend for it to do?”
I also find it’s useful when I’m vague on the specifics, especially with network protocols. I might be expecting it to do something and then find out, oh, this doesn’t solve that problem, I’m in the wrong config file.
- Comment on used hard drive retailers 1 hour ago:
Well the “critical/irreplaceable” qualifier is kind of important - that’s why I specified it. It’s up to you to decide what that means for your data and risk tolerance.
For everything that I consider irreplaceable, I’m not comfortable with anything less than 100% duplication on the live system, and also an external offline backup. Even with enterprise-grade hardware, I don’t trust storage devices, they’re all destined to fail. Storage is the most important part of a data server, and should be treated like it is constantly trying to light itself on fire, like a library with wooden shelves lit with torches. All the other components are just as unreliable, but more expendable.
Admittedly, when you account for hot standby drives, the cost is that my storage availability is only 40%. A 16TB storage pool is in fact 5x 8TB drives: 2 mirrored pairs and 1 standby. On the plus side, thanks to ZFS and TrueNAS those drives can be whatever, no need to worry about RAID considerations for matched drives. SAS or SATA? who cares? They can even be different speeds, ZFS will compensate. Buy whatever is the right size for the pool, let the system deal with the other issues.
Can you put a price on stability? longevity? peace of mind?
The server hardware is all old repurposed stuff - a desktop build from 2013, secondhand data center surplus, refurbished/used drives, none of it’s worth much and almost all of it is well past end of life, any part of it could fail without warning at any moment. It doesn’t matter, it is highly reliable because the redundancies have redundancies, including the boot drives. Trying to squeeze every bit of value out of the hardware is a losing game because it’s basically worthless anyway, but the same would be true if it were all new top-of-the-line gear. The hardware is expendable, the data is not. Buy more cheap hardware, plan for it to explode, learn how to build stable, recoverable systems.
- Comment on used hard drive retailers 6 hours ago:
Used data center drives are great for a home lab. They’re built like tanks for hundreds of thousands of hours of constant operation. Unless you’re running a business hosting a bunch of public-facing websites out of your garage, you don’t have that kind of workload (and if you are doing that you should just be buying new drives anyway and writing them off as a business expense).
Data center drives get replaced when they hit a ceiling of operating hours, with no actual faults, or if they experience any minor faults (it’s a business expense - drives are consumables - data centers have storage rooms of spares sitting around, they just replace them).
Any competent reseller should be able to give you a SMART report, and that should tell you if there are any major issues (generally they don’t get resold if there are, nobody will buy them). If the seller won’t give you a SMART report then obviously don’t buy, they’re either a scammer or incompetent.
If your array redundancy is set up properly then there’s no reason to be “scared” or trust in “good luck”. Assume luck will be bad. Mirror every storage device that has critical/irreplaceable data on it, and have at least one hot standby drive in every pool. Don’t bother with complicated striping schemes to try and scrape a little more storage space out of your drives, that’s dumb. One-to-one mirroring for every drive. Storage drives are consumables. They will fail, not if but when, even if you only buy new. Learn to read a SMART report. Enjoy quality hardware with no real problems at low prices.
- Comment on What are the best learning resources? 4 days ago:
You say you got PEBKAC faults, I feel bad for you son.
I got 99 problems but wetware ain’t one. - Comment on What are the best learning resources? 5 days ago:
Computer networking is basically a completely different field from operating systems and programming, though obviously some of the concepts are relevant. Turns out plugging these things into each other so that they can share information in a useful way is kind of difficult. A lot of very smart people have been working on it for almost 70 years, and frankly it’s still a fucking mess, so don’t feel bad if you feel a little lost.
Starting with the basics is the right instinct, in my opinion. Start with the OSI model:
…telkomuniversity.ac.id/7-osi-layer-the-building-… geeksforgeeks.org/…/osi-model-analogy-osi-7-layer…
This helps to break down the actual functioning of the network into logical steps. It’s very helpful when you’re trying to visualize the operarion of some of the more abstract bits of the technology stack (like TCP/UDP), and when you’re trying to think through what piece of it might be causing your problem in the moment (the router is on and the cables are plugged in, why is there no connection?). It’s a map that can help you when you’re lost. It’s also a guide to how a lot of people who work on networking technology think, so it can help you understand how things are supposed to work.
Beyond that, Professor Messer is a great resource: www.professormesser.com
If you feel reasonably confident with computer hardware components and various types of cable connectors, you can probably skip the A+ part and go straight into Network+. Because you’re doing this as a home hobbyist (not for the actual certification), I recommend just listening to the courses like you would a podcast. Don’t try to memorize or fully understand everything, just use it to get a grasp of the terminology and purpose of the various pieces.
I also recommend taking on a project to gain experience. Implenting PiHole pi-hole.net for your home network will cover routing, DHCP and DNS, plus you can do it with a Docker container.
- Comment on Medieval people had bathhouses & did not all die before 35... 5 weeks ago:
Who’s that then?
Must be a king
How d’you know ‘e’s a king eh?
He ‘asn’t got shit all o’er ‘im
Oh yeh, right
- Comment on How do we quit YouTube? 1 month ago:
There are other video sharing sites, like Odysee or BitChute or of course PeerTube, but there is no alternative to the 30 years of content that is YouTube.
- Comment on Any tips on plastic adhesives? Trying to repair headphones 1 month ago:
There is a JB Weld UV glue product that comes with a UV LED attached:
www.jbweld.com/product/superweld-light-activated
It’s a blend, not pure UV resin, that will harden quickly where the light hits it but will also slowly cure without UV exposure, so the inner parts of the joint will harden over time.
- Comment on Microsoft is overhauling the Windows 11 interface with WinUI everywhere 1 month ago:
- Comment on “Sir HMS Invincible has exploded.” 2 months ago:
- Comment on “Sir HMS Invincible has exploded.” 2 months ago:
HMS Target Practice
HMS Leaky Bucket
HMS Smoke on the Water
- Comment on Problem with receiver 2 months ago:
Yeah if you’re down to put the effort into fault tracing, you’ll need an oscope. Something like this: ebay.io/m/PDLGdu will work fine.
It will take some time, but if you’re lucky you’ll find it’s just a capacitor that you can replace cheaply. If you’re unlucky you might find that it’s a faulty IC, in which case you might have to replace an entire circuit board from a donor unit anyway.
- Comment on Problem with receiver 2 months ago:
You’re going to have a hard time pinning this down to a specific component without a circuit diagram. I did find that there’s a service manual for this unit: elektrotanya.com/…/download.html
Seems to be legitimate and has diagrams.
I would recommend starting on the output side - is the popping present on every speaker output? Both left and right? Use a very simple speaker for this, one that doesn’t require its own power source, just a red and black wire. Also, is the popping present with no input audio?
If you can narrow it to a certain output you can backtrack it to a specific section of the circuit that feeds that output. Alternatively, if it’s present on all outputs then it must be a component that is common to all, and therefore behind the area that splits to the different outputs.
An oscilloscope would be handy - you could identify the faulty signal at the speaker output, then check points along the path backward. Half-splitting is your friend. You don’t have to buy an expensive piece of lab equipment, a cheap $30-40 digital oscope will be good enough.
Another option would be to throw parts at it. I see units listed for parts on eBay for ~$80. You could try swapping out circuit boards one at a time.
- Comment on Linus Torvalds to critics of AI coding in Linux: "Fork it. Or just walk away." 2 months ago:
Copying GNU GPL code without licensing your derivative code as GNU GPL and publishing it where it’s publicly accessible, and then using your derivative code to generate profit for a corporation, is definitely theft. Just because it’s open source doesn’t mean you can just do whatever you want with it, the original programmer still has rights over the code they wrote.
- Comment on Linus Torvalds to critics of AI coding in Linux: "Fork it. Or just walk away." 2 months ago:
That’s a stretch, since we don’t know exactly how human learning works.
It is not a stretch. We may not know exactly how human learning works, but we do know exactly how machine learning works, and we know that it is not like how human learning works. It is absolutely possible to differentiate things even without complete knowledge.
I don’t know about you, but I for one have not produced anything ‘original’ my entire coding career by that metric. I feel confident in saying the vast majority of programmers have not either.
This is a bad argument. The output of a generative model is a copy-and-paste function from a library of ingested code samples with a fairly competent keyword search attached to it. Code writing bots are just script kiddie crutches.
If all you did was copy and paste from GNU GPL code, then your output would also be bound by the same license.
But I disagree with the idea that their method of learning and their actions is inherently different from what the average person does.
Then you don’t understand even the basics of the mathematics that makes them actually work. It’s a purely algorithmic process. It’s an outgrowth of multidimensional analysis and optimization, that’s all.
- Comment on Linus Torvalds to critics of AI coding in Linux: "Fork it. Or just walk away." 2 months ago:
It is actually not like a person learning at all. The only way you could believe this is if you have no grasp of the mathematics that are the basis of the multi-dimensional statistical analysis which is neural network training, and haven’t bothered to do any reading on it.
- Comment on Self Hosting- Security recommendations 2 months ago:
Your first concern should be your boundary firewall. You should have all ports closed except the ones that you are definitely using for external services. You should know which ports you have open and why, and what traffic, how much and how often you expect to see on those ports (8080 will have regular Internet use traffic, but your reverse proxy port should only have traffic when you’re away from home and actively using it), and you should monitor that traffic at the firewall every so often, and especially when you make changes to your network. Closed ports should be configured to drop packets rather than respond that the port is closed (stealth mode). On a home network, preventing unwanted incoming connections will protect you from the majority of malicious activity. It’s the most effective single thing you can focus on.
The next thing would be to separate untrusted devices onto dedicated VLANs. This would be for IoT devices, gaming consoles, “smart” appliances, anything that connects to the Internet whose software you don’t have control over. They get isolated on a VLAN that only connects to the Internet and doesn’t allow local connections to devices on other VLANs, so the rest of your network doesn’t exist as far as they’re concerned. This should cut down on things like “smart” appliances taking inventory of your home network and reporting it back to the manufacturer’s servers.
If you do these two things, and you’ve got your reverse proxy configured properly so that other people can’t break into it, you should minimize unwanted connections to your network and your server/containers should be fine with default internal firewall policies. The only reason you would need to do more is if you expect a direct/intentional attack by a motivated hacker, but in that case there’s not much you can do unless you’re an expert.
If you want to go further, try implementing the community version of runZero:
www.runzero.com/platform/community-edition/
help.runzero.com/docs/self-hosting/
www.cisa.gov/…/runzero-community-edition
This is a network visibility tool that will discover and identify devices. To get a really complete look, you would run it from inside your network and deal with anything that you don’t think should be accessible, then run it again from outside your network to see what a potential attacker would see.
- Comment on Linus Torvalds to critics of AI coding in Linux: "Fork it. Or just walk away." 2 months ago:
Digital reproduction is digital reproduction no matter how many extra steps are added to the reproduction process. It’s just an algorithm that sorts through a collection of stored data to find specific pieces of data which best fit the keywords supplied by the user, then regurgitates the results that are the best match based on correlation.
In spite of common meaning overlap and popular metaphors, the human brain is not a computer. Ask any neurologist.
- Comment on Linus Torvalds to critics of AI coding in Linux: "Fork it. Or just walk away." 2 months ago:
This is a misunderstanding based on confusion between technical and colloquial terminology.
A machine learning model “learns” information in the same way that a curve fitting algorithm “learns” the shape of a data set.
This is not the same as the colloquial meaning of human learning. It is a mathematical process.
- Comment on Linus Torvalds to critics of AI coding in Linux: "Fork it. Or just walk away." 2 months ago:
This comparison is invalid. Training a neural network algorithm is not equivalent to human learning. We are talking about data stored in machine learning models owned and controlled by multi-billion dollar corporations.
It has already been demonstrated multiple times that original training data can be reproduced completely from models, so yes, they are data storage systems. When they reproduce code which they have previously stored, even only in part, that is a derivative work. Adding extra steps to the transcribing process doesn’t make it any less a copy of the original.
- Comment on Linus Torvalds to critics of AI coding in Linux: "Fork it. Or just walk away." 2 months ago:
Every single generative tool is built on theft. No one has a training database that only contains code they were given legal permission to use for that purpose. Moreover, if these tools were trained on any GNU GPL code, then the tool and all of its output should also be GNU GPL:
if you distribute a derivative work or modification, you must provide the source code to those recipients under the same or equivalent license terms
en.wikipedia.org/wiki/GNU_General_Public_License
None of the companies developing these tools are obeying the terms of the licenses. The trained models are the product of theft.
You cannot be a moral person and approve of the use of these tools, they are diametrically opposed.
- Comment on Imagine if those works survived 2 months ago:
I mean… We do have the Wayback Machine
You can see what the Internet was like in 1996:
- Comment on Roblox announce plans to let people AI generate basic games using text prompts stuck into a mobile app, but claim that won't fill their homepage with AI slop 2 months ago:
Ooh… so Roblox uses Luau internally for user-developed game logic, which means that you could probably get the AI to write you a complete application and execute it within the Roblox environment. This seems ripe for exploitation.
- Comment on [Support] HDD diing or something else? 2 months ago:
More specifics are needed for a support request. Provide the baseline specifications please.
What OS are you using? What is the make and model of the drive? Is it internal or external? USB? SATA? SAS? NVMe? A PCIe adapter? Is this a desktop, laptop, NAS, server, NUC, Raspberry Pi with an expansion board?
Are you familiar with SMART? Have you done any diagnostics?
- Comment on How it goes everytime 3 months ago:
I thought we were an autonomous collective.
- Comment on What's your contingency plan for the apocalypse? 3 months ago:
- Comment on Revisiting Rule #3 Hey everyone, as I previously mentioned the rules here are 3 months ago:
- Comment on My country's police just busted a dangerous 3d printed weapons manufacturer. 8 months ago:
What if I want to cut my spaghetti?