SeriousBug
@SeriousBug@infosec.pub
- Comment on NYPD faces backlash as it prepares to encrypt radio communications | New York | The Guardian 10 months ago:
Agreed. But I think the right to monitor the police doesn’t have to mean real-time access to police radio. The radio could be recorded, like body cam footage, and released on demand with FOIA. FOIA allows redactions when needed, so sensitive information like victims names and addresses could be redacted.
- Comment on Those who are self hosting at home, what case are you using? (Looking for recommendations) 10 months ago:
I can vouch for the node 804, although I haven’t used the others so I can’t say which is the best.
- Comment on Should I use Restic, Borg, or Kopia for container backups? 10 months ago:
No.
- Comment on Should I use Restic, Borg, or Kopia for container backups? 10 months ago:
I’ve been using Kopia for all my backups for a couple years, both backing up my desktop and containers. It’s been very reliable, and it has nice features like being able to mount a backup.
- Comment on Commercial Flights Are Experiencing 'Unthinkable' GPS Attacks and Nobody Knows What to Do 11 months ago:
Nope. And more importantly, it looks like nobody considered what might happen if the signal gets spoofed. The backup systems that are supposed to keep working if GPS breaks also break due to these spoofed signals.
- Comment on 8GB RAM on M3 MacBook Pro 'Analogous to 16GB' on PCs, Claims Apple 1 year ago:
Have you ever actually seen a laptop lid just break off because the epoxy failed, or is this just a hypothetical? I used my last laptop for around 8 years, I took it with me to college every day in a backpack, on public transit. It got thrown around, scratched up, but the hinges didn’t break lol
- Comment on Chrome not proceeding with Web Integrity API deemed by many to be DRM 1 year ago:
This is worse. Let’s go with an example: on an Android phone, you visit a website. The website asks for an integrity check, the browser works with Google Play Services to complete the check.
What if you have a de-Googled phone without Play Services, or if you made modifications to restrict Google’s tracking? Then Google can refuse to verify you. What if you installed an ad blocker in your browser? Google can refuse to verify you.
If you fail verification, the website could ask you to complete a captcha, or just refuse to show you anything.
- Comment on New homeowner lots of questions 1 year ago:
One advice I haven’t seen mentioned: there are tool libraries in many cities where home owners can borrow tools for a low membership cost. This can save you from spending a lot on tools, especially for ones you won’t need often.
- Comment on Roblox tells employees they have to come to office three days a week or take severance package 1 year ago:
Severence pay is not mandatory everywhere. So you might get nothing if you are laid off.
- Comment on The World’s Oldest Active Torrent Turns 20 Years Old 1 year ago:
Fines. And say you seeded a movie to 1000 people and a DVD of the movie costs $20, they sue you for $20000, treating it like you broke into a warehouse and stole 1000 DVDs of the movie.
- Comment on Will you be willing to pay for using Twitter? 1 year ago:
I already donate to Mastodon development, and to the Mastodon server I’m on. It’s a good reminder to donate to the Lemmy server I’m on too.
- Comment on I moved to Seattle for a high-paying tech job. It turned out to be the loneliest time of my life. 1 year ago:
Men will literally write a Business Insider article instead of going to therapy. No really, I feel like this guy could benefit from some therapy.
It wasn’t until I met a few women on dating apps that I realized being a software engineer in a tech hub is far from special. Working at companies like Amazon or Microsoft just isn’t interesting; it’s the norm here.
It’s weird to expect that you’d get dates just for being an engineer. What? Like if someone did date you just because you are an engineer, that would be such a shallow relationship.
I think one big reason for that is software engineering doesn’t require socially demanding skills like in product management or UX design.
Strongly disagree, software engineering is mostly social skills. It’s all about communicating problems, learning your users pain points, explaining your solutions, and coordinating work. Coding the actual solutions is typically the easy part unless you are doing cutting edge computer science research.
- Comment on What would it take for you to move away from Github? 1 year ago:
I’m not OP but I use Woodpecker CI, also self hosted. Gitea is also working on Gitea Actions which are supposed to be compatible with Github Actions, but I think it’s still on beta.
- Comment on FTC judge rules Intuit broke law, must stop advertising TurboTax as “free” 1 year ago:
You could keep using it and just ignore all the credit card ads they show you. That’s how they make their money.
- Comment on Is bit rot really a threat that I should worry about? 1 year ago:
For any family photos and documents you can’t afford to lose, make sure you have backups of it. A RAID array does not mean you don’t need backups: you want at least 3 copies, at least one offsite.
The copy in your RAID array is one copy. You can back that up to an external hard drive or something as a second copy. Then have an offsite backup on something like Backblaze as your third copy.
- Comment on nginx reverse proxy using subpaths help 1 year ago:
You’ll need to check the documentation of every app, they usually have an option to set a base path so the app will add that base path to every link and resource.
If some of the apps don’t have support for that, the next option would be to build from source and patch all the links yourself.
- Comment on Is there a way to run old bare metal hardware on LAN for a dedicated computing task like AI? 1 year ago:
"AI compute module"s exist, they are called GPUs. All the matrix calculations that go into neural networks are highly parallelizable, which means GPUs are optimal for them. A cheap used GPU will beat anything you can cook up yourself.
- Comment on Garagefs selfhosed s3 compatible storage. 1 year ago:
I don’t like that garage requires manual intervention to upgrade, so I went with minio which can upgrade automatically. I have it deployed with docker, and I use watchtower to pull in upgrades automatically without intervention.
I do love minio. I have backups going into it, and I use it to host my static website blog too.
- Comment on Period tracking app options? 1 year ago:
The police can confiscate your servers. Considering some states are treating abortion as murder, I don’t think it’s unrealistic to say the police could raid your home and confiscate your devices just on suspicion.
The only thing safe against that is an encrypted device locked with a password, no biometrics like fingerprints or face ID. As far as I know, you can refuse to give a password under the 5th amendment, but you can’t refuse to unlock a device with a fingerprint reader or face ID.