Skip Navigation
Jump
Revy (by Speedl00Ver)
  • imo we should launch our boat off the exposed hull of yonder upturned schooner, and whilst in midair, fire our torpedoes into a helicopter.

    3
  • Jump
    The Accelerationists’ App: How Telegram Became the “Center of Gravity” for a New Breed of Domestic Terrorists
  • Durov gets arrested in france and suddenly the telegram slander kicks into high gear. It gets a hit piece every once in a while for sure, but the last few days have been on a different level.

    You know who else uses telegram? My family, to send vacation pics to each other.

    You know what other technology bad guys use? Email.

    6
  • Jump
    Studios are cracking down on some of the internet’s most popular pirating sites
  • Private trackers disgust me. What kind of pirate turns away from the world, to re-seeding fragments of files they don’t care about to other cowards with slightly slower rss feeds; all for a chance at enough ratio to get the show you want? It’s a country club, with self-validating assholes, dry hot dogs, and tall fences.

    The Mainline DHT is the way forward. There is no social credit here. The kids in Africa are starving, and I will throw them as much as I can, kilobyte by kilobyte, for no reason at all, for I too was a leecher once.

    53
  • Jump
    Drivers Hate The Tech In Their Cars
  • 2014 impreza. No screen at all. I bought a phone mount that shows waze and charges my phone.

    I have cruise control and heated seats. And I can operate both with gloves on!

    Don’t need a backup cam because my windows and mirrors are good.

    I will drive this car until it dies, and then I’ll replace the head gaskets and drive it until it dies again. And then I will replace the cvt and drive it until it dies a third time.

    Unfortunately there’s nothing you can do about the NY road salt. The frame will be left, flake by flake, in the gutters of 490. It’s the only thing that can take this car from me, and it is its inevitable fate.

    22
  • Jump
    A Guessing Game
  • Did you know that in the first version of php, each function name would be hashed to lookup the code to run it? And the hashing algorithm was: the first letter. So all the functions started with a different letter.

    19
  • Jump
    Why does my treadmill want my email address?
  • I wanted a countertop dishwasher. Home depot doesn’t have them in stores, it was online only. I figured it would probably make me make an account in order to check out. I said nah.

    5
  • Jump
    Mesa 24.3 Lands "The Juiciest Refactor Ever" [Mike Blumenkrantz from Valve :"I'm gonna go full doomguy across the whole DRI frontend and everything it touches"]
  • It’s an open source linux graphics driver.

    It is very widespread, despite being quite slow, because it works. It ships by default with almost everything, and is the fallback when card-specific drivers fail

    Edit: what Max_P said

    1
  • Jump
    Complexity
  • I have declared war on notifications. My immediate family, two closest friends, and my boss can call me. In no other circumstances will my phone make a noise or vibrate. I will check my texts when I feel like it.

    Other than a few exceptions, no apps may show the notification badge either. Discord will show DMs and mentions from one or two servers. Everything else is blocked. My work email may show unread email. I’ve even turned off banners on my work chat app. I don’t think I’ve checked my personal email in months.

    All my recurring charges are paperless + autopay. That’s another notification badge I forgot about - I have a budgeting app that can show transactions. I categorize them, make sure their categories are covered, and I’m done.

    On the first of the month, I pay rent and set the budgeting app categories. Then I have nothing to worry about, and near-zero distractions. My biggest pain point in life is deciding what to eat for dinner.

    16
  • Jump
    Good guides for the security you need to set up for self hosting?
  • Anything exposed to the internet will be found by the scanners. Moving ssh off of port 22 doesn’t do anything except make it less convenient for you to use. The scanners will find it, and when they do, they will try to log in.

    (It’s actually pretty easy to write a little script to listen on port 20 (telnet) and collect the default login creds that the worms so kindly share)

    The thing that protects you is strong authentication. Turn off password auth entirely, and generate a long keypair. Disable root login entirely.

    Most self-hosted software is built by hobbyists with some goal, and rock solid authentication is generally not that goal. You should, if you can, put most things behind some reverse-proxy with a strong auth layer, like Teleport.

    You will get lots of advice to hide things behind a vpn. A vpn provides centralized strong authentication. It’s a good idea, but decreases accessibility (which is part of security) - so there’s a value judgement here between the strength of a vpn and your accessibility goals.

    Some of my services (ssh, wg, nginx) are open to the internet. Some are behind a reverse proxy. Some require a vpn connection, even within my own house. It depends on who it’s for - just me, technical friends, the world, or my technically-challenged parents trying to type something with a roku remote.

    After strong auth, you want to think about software vulnerabilities - and you don’t have to think much, because there’s only one answer: keep your stuff up to date.

    All of the above covers the P in PICERL (pick-uh-rel) for Prepare. I stands for Identify, and this is tricky. In an ideal world, you get a real-time notification (on your phone if possible) when any of these things happen:

    • Any successful ssh login
    • Any successful root login
    • If a port starts listening that you didn’t expect
    • If the system watching for these things goes down (have two systems that watch each other)

    That list could be much longer, but that’s a good start.

    After Identification, there’s Contain + Eradicate. In a homelab context, that’s probably a fresh re-install of the OS. Attacker persistence mechanisms are insane - once they’re in, they’re in. Reformat the disk.

    R is for recover or remediate depending on who you ask. If you reformatted your disks, it stands for “rebuild”. Combine this with L (lessons learned) to rebuild differently than before.

    To close out this essay though, I want to reiterate Strong Auth. If you’ve got strong auth and keep things up to date, a breach should never happen. A lot of people work very hard every day to keep the strong auth strong ;)

    35
  • Jump
    Microsoft points finger at the EU for not being able to lock down Windows
  • For the Nth time, crowdstrike circumvented the testing process

    Edit: this is not to say that cs didn’t have to in order to provide their services, nor is this to say that ms didn’t know about the circumvention and/or delegate testing of config files to CS. I’ll take any opportunity to rag on MS, but in this case it is entirely on CS.

    6
  • Jump
    The Microsoft/CrowdStrike outage shows the danger of monopolization
  • Crowdstrike is big, but not that big.

    About half of my clients use them; and of those, about a third are halfway through ripping them out in favor of MS defender.

    (MS is definitely “that big”)

    8
  • Jump
    Slow recovery from IT outage begins as experts warn of future risks
  • I want to spin up a separate thread here if that’s okay.

    Please give me an example of any EDR solution produced through “public ownership structures”. I don’t think such a thing exists, but I welcome being proven wrong.

    1
  • Jump
    Slow recovery from IT outage begins as experts warn of future risks
  • Private ownership and investment of capital created Crowdstrike as a profit-seeking venture. It also created MS Defender, SentinelOne, trellix, carbon black, etc. Competition in the marketplace (and there was/is lots of competition) forced these products to be as good as they could, and or self-stratify into pricing tiers. Crowdstrike, being the best (and most expensive) is the most widely-used. Note that not every enterprise requires that level of security, and so while CS is widely used, it is not ubiquitous. This outage could have been significantly worse.

    1