36
submitted 4 weeks ago by [email protected] to c/[email protected]

I noticed while updating my system just how many packages I have installed that I don't recognize.

I tend to think that minimalism is better for security, so I'd like to remove any packages that I'm not using, but this is a bit of a scary task.

Does anybody have a safe method for reviewing and purging unused or bloat packages while obviously making sure not to accidentally remove important dependencies?

I'm on arch btw.

[-] [email protected] 20 points 1 month ago

I recommend it every time this question pops up and I'm surprised more people aren't privy to it:

Rent a VPS as your public gateway. Connect the VPS to your server with a simple wireguard tunnel.

The only thing on the VPS should be a reverse proxy with SSL/TLS pass through.

Send the traffic at the VPS reverse proxy to a reverse proxy on the main server. Configure this proxy to use letsencrypt certs.

The benefit and importance of the SSL pass through reverse proxy, is that it allows all data in transit to remain encrypted until it reaches your physical server. Traditionally, most would suggest the one and only reverse proxy exist on the VPS but all traffic would then be decrypted on the VPS. This could obviously compromise your traffic if the VPS provider snoops or your VPS is compromised.

Cloudflare tunnels decrypt on their hardware as well, which is why I always recommend avoiding their services.

14
submitted 1 month ago by [email protected] to c/[email protected]

I updated my nvidia driver to 570 and now some games that worked fine previously present the error: direct x 12 is unsupported on this computer.

I see lots of others having this same issue but no solutions.

Has anybody figured out a fix?

I'm on Fedora so there doesn't seem to be any straightforward way to rollback the driver.

12
submitted 1 month ago by [email protected] to c/[email protected]

I'm making my own white oak door jambs. So far I did one set. I milled some rough cut oak, made two passes through the table saw to roughly remove a rabbet for the integrated door stop.

Then I ran it through the table saw again with a dado stack to get the rabbet to the final dimensions. The problem is, it's difficult to apply even pressure as the wood passes over the dado stack. I already have a featherboard pushing against the fence, but I'm thinking I could use another pushing against the saw top.

I know I can put one on my fence, but that would apply pressure to the part of the board closest to the fence only. Do they make any contraptions that can apply even pressure downwards, but over a larger surface area? Like multiple featherboards extended out over the work piece.

[-] [email protected] 18 points 2 months ago

I've used Tuta for years, paid account with multiple custom domains.

I prefer them for their principles, but their clients are extremely frustrating. Emails load very slowly and their email search is basically unusable.

I've resorted to downloading old emails and using other clients to import and search through them. I really wish they would improve their email search.

35
submitted 3 months ago by [email protected] to c/[email protected]

Anybody got any suggestions for a good print-screen / screenshot app?

I'm using the default of Swappy right now and it doesn't really suit my needs.

The MacOS screenshot app is my ideal.

[-] [email protected] 15 points 3 months ago

SDR is Standard Dynamic Range. This is how most media is viewed and has been viewed for decades, typically in the Rec709 color space. 99% of consumer devices display in SDR.

HDR is a newer technology that expands the dynamic range passed Rec709 color space. It requires an HDR capable screen to display HDR content and most content is not distributed in this format, although this has been changing in the last few years.

I personally find HDR kind of a gimmick, but my point is that HDR != HD. SDR/HDR describe contrast ratios and how many colors are rendered. SD/HD describe resolution.

The chart does show them downgrading the plans from 4K/UHD to HD though.

[-] [email protected] 20 points 3 months ago

The wiki entry has a chart which shows all plans have access to HD content. Is the chart wrong or did the contributor confuse SD with SDR?

Either way fuck HBO.

24
submitted 3 months ago by [email protected] to c/[email protected]

Call me paranoid but why do the staff on a lot of private trackers seem so interested in what other trackers you have accounts with?

Most of the time when you apply with a new tracker or have to re-apply due to inactivity it feels like you're being interrogated by the feds.

From the perspective of a private tracker, why are they so pushy about that? And can they know if you're lying?

The implication seems like, "we all talk to each other and if you lie to me you lose all of your accounts".

82
submitted 3 months ago by [email protected] to c/[email protected]

I realize this is a really silly request, but I absolutely refuse to watch YouTube videos without a proxy frontend let alone logging into a google account.

I've been wanting to watch dnsl's "Fallout RP is serious business" but it's age restricted.

Does anybody know either of a way to bypass the age restriction or can just send me the video? I've tried everything I know short of giving in and signing into YouTube.

8
submitted 3 months ago by [email protected] to c/[email protected]

I'm looking for a simple way to make my contact form functional. So far it seems like emailjs would do the trick.

I'm curious if there are any other recommendations? What would you use and why?

Realistically I can't see the form getting more than a dozen submissions per month.

6
submitted 4 months ago by [email protected] to c/[email protected]

I'm looking to automate/script my pfsense wireguard tunnels so that each wireguard tunnel only goes up if there are one or more clients connected to the subnet associated with that tunnel and goes down once all clients have disconnected. I was wondering if there is already a plugin that accomplishes this or can be adapted, otherwise what is best practice for running scripts on the pfsense box?

My initial thought was to have a cronjob monitor the various DHCP servers for each subnet, then initiate a script to connect the associated wireguard tunnel if it detects any active DHCP leases on that subnet.

I have multiple subnets on this box, each with it's own wireguard gateway. I like the idea of only making the VPN connection if there is a client calling for it.

[-] [email protected] 25 points 6 months ago

FBI, open up!

Jk. Thank you for your service

[-] [email protected] 21 points 6 months ago

Did you use compressed air to clean out the fans?

It's possible to fry circuitry if you artificially rotate the fans too fast, as this generates an electric field more powerful than the fans and their attached components are rated for.

Probably rare to cause damage with modern computers but an old PC might be more susceptible to this type of damage.

14
submitted 7 months ago by [email protected] to c/[email protected]

I run a qemu/KVM setup in which I have different VMs for different use cases/profiles. Very similar in theory to something like Qubes OS. So far when I want to swap to another VM I have to first un-fullscreen, then click the other VM display window and fullscreen that. I was beginning to work on hotkeys and scripts to allow switching between VMs by assigning Ctrl+NumPad# to specific VMs and then having the triggered VM appear in full screen. But I'm imagining there's probably already a VM display manager that streamlines this.

Does anybody have any suggestions?

The biggest factor is that the display needs to be responsive as I'm using these VMs for daily tasks.

Bonus points if the display manager can output a variable for the currently focused VM so I can script the keyboard backlight to change to an assigned color as well as change the power profile of the base operating system to match the currently highlighted VM better.

[-] [email protected] 15 points 7 months ago

Yeah pimeyes absolutely needs to be shut down and laws need to be in place to protect private citizens from having their information sharable and searchable without their explicit consent. "Publicly available information" is always the line people use to defend these services. I'm arguing that our modern capabilities needs to be adjusted for. Things shouldn't be so publicly accessable in the first place and personal data aggregation should be a much more vetted and potentially licensed business. Can we talk about what other purpose these facial recognition databases serve other than to stalk, expose, or extort people? If they required proof of identity and only allowed searches of your own face then I could understand the value.

144
submitted 8 months ago* (last edited 8 months ago) by [email protected] to c/[email protected]

I accidentally attempted to SSH into one of my servers from a device that did not contain my ssh key. I configure all of my servers to only allow authentication via cryptographic keys. Root ssh as well as password auth are disabled.

To my surprise, I was able to log in to my server with a password despite this. Baffled, I first tried some other servers. 2 of the 5 other servers I tried were accessabke via password.

After some swift investigation the culprit was found, a cloud-init ssh config in sshd_config.d/ with one line: password_authentication Yes.

So TLDR PSA....if you run a server in any type of virtualized environment, including a VPS, check your /etc/ssh/sshd_config.d/ folder. And more broadly, actually thoroughly test your ssh access to confirm everything is working as you intend it to.

104
submitted 8 months ago by [email protected] to c/[email protected]

I'm curious what the benefits are of paying for SSL certificates vs using a free provider such as letsencrypt.

What exactly are you trusting a cert provider with and what are the security implications? What attack vectors do you open yourself up to when trusting a certificate authority with your websites' certificates?

In what way could it benefit security and/or privacy to utilize a paid service?

And finally, which paid SSL providers are considered trustworthy?

I know Digicert is a big player, but their prices are insane. Comodo seems like a good affordable option, but is it a trustworthy company?

16
submitted 8 months ago by [email protected] to c/[email protected]

For those of you that know, I'm trying to find a niche community, forum, chat room, whatever of individuals that could give me some pointers on cracking an OFX plugin. My knowledge ends at simple standalone exes and the communities I know of seem largely focused on game cracking.

If you know of a community that you think would help me on my journey, feel free to share. You can also send me a private message if you need to be discrete.

[-] [email protected] 46 points 9 months ago

I operate an invidious instance. Google has really cracked down the past two weeks on YouTube front ends. Its extremely frustrating.

Invidious devs are finalizing a workaround so hopefully things will be working again in the next week or two.

[-] [email protected] 22 points 11 months ago

ELI5 please. What are the benefits over unbound?

[-] [email protected] 15 points 1 year ago

Got an alternative that isn't youtube?

[-] [email protected] 15 points 1 year ago

Your question is a good one. I'm not the one who downvoted you fyi. To answer your question, it is absolutely a personal anecdote based on my own experimentation. I'm sure others will add their own experiences. Based on my experiences there's no doubt about twitch shadowbanning based on VPN use. I'll admit I don't have a basis for Linux and adblockers being a part of the equation, but I made it clear in my original post that those were assumptions.

To further speculate, I have an idea that the shadowban may actually be triggered by somebody using the same VPN server doing something that triggers it, affecting anybody else on that server. I can't possibly provide evidence for that theory, but it would explain the seemingly random nature of the shadowbans.

[-] [email protected] 13 points 1 year ago

I prefer to shy away from those companies, especially Google, for moral/privacy reasons.

view more: next ›

brownmustardminion

0 post score
0 comment score
joined 3 years ago