[–] 17 points 2 days ago

I used to work for an MSP (Managed Service Provider), can confirm. Security is something I had to redirect attention to on a day-to-day basis. Even then, the company was more concerned with appearance and audit compliance than security.

I have worked at IT companies that really did care about security, but those companies were driven by management and staff that personally cared about IT security. One of them was a certificate authority.

Here's a story about physical security from before that time.

I once had equipment in a Data Center that was embedded in the 4th floor of an office building. There was a mantrap at the entrance, designed to prevent you from walking away with the main DC door open, or letting people tailgate in to it. One of the doors of the mantrap was a sliding door, disguised as a bit of the hallway.

The sliding door was locked with a maglock on the thin end, so when it fully closed, it locked and you couldn't slide it open without a key card, from inside or out.

...unless you bumped in to it with your shoulder, which separated the lock and opened the door. Which, after it was figured out (about 1 month), happened all the time. People would get let in to the DC without a card that opened that specific door. (DC security control provisioned the main door was separate from building control, which managed the sliding door).

When they tried to get out later, they'd get stuck in the mantrap, then they'd wait for someone to let them out (pre-cellphones). That person would then show them the trick. This was so common they turned off the forced-lock alarm. This lead to the mantrap being useless, and people propping the DC door open for ease of access when moving stuff in and out.

This was put in place in 2001, and I visited the building last year in 2025, it's still in place today.

It's worth noting that this DC was shared by multiple competitive reinsurers, ISPs and financial agencies. The were no cameras outside or inside, and you could poke most server reset buttons through the rack cages with the ink cartridge of a ball point pen. Not everyone was shown that trick.

  • source
  • parent
  • context
  • [–] 7 points 1 week ago (1 child)

    To stave off water damage and rusting when shipping to humid areas.

    One dock strike or lost piece of paperwork and it could sit in an unair-conditioned container long enough for the cardboard to disintegrate.

    It is an awful waste of plastic, but I expect the return rate for rusted tools 'damaging' fasteners is high enough that financially it makes sense for the company

  • source
  • parent
  • context
  • [–] 1 point 1 week ago*

    If you want to approach 200Hz, then it's probably still good advice to go for the XTX, especially if high framerate is a strong feel-good improvement for you.

    I've got a 2k 240Hz monitor, I can drop it to 1080p for testing if you want me to try any specific games out. If I've got it, I can give you some rough FPS numbers - just let me know! I'm running steam on Linux with proton, but the numbers should be pretty comparable to Windows these days.

    Love an ITX build - I'm cheating with the XTIA XProto L because it's an open build. I was lucky the 7900XT fit on mine - it's almost too long. The MERC 310 XFX 7900XT and XTX are both 344mm. It dwarfs my old RTX2070.

    They are technically PCIe 4.0 cards. My i7-10700K CPU is only 3.0 capable, but it runs just fine. Some people reported problems using 4.0 cards in 3.0 slots. I haven't seen issues. I'm told I'm leaving some power on the table, but with the price of RAM, I'm not upgrading any time soon.

    One other note, the additional power supply connections required for the GPUs are 2x8 pin connectors for the 7900XT and 3x8 pin connectors for the 7900XTX, so you may need to buy a new power supply or double check your power supply came with enough ports and cables if it's modular.

  • source
  • parent
  • context
  • [–] 2 points 1 week ago (2 children)

    I got a 7900xt and I'm very happy with it!

    I wish I'd spent $100 more at the time and got the XTX. I just want that little bit extra in some games, where it might make 4k (medium) hit 80fps stable instead of 60fps. Or 2k (high) hit 120fps instead of 100.

    I will say, I got an XFX card and man are they long. Deffo check your case!

  • source
  • [–] 0 points 2 weeks ago

    I've seen the recommendations of software raid0. The answers are all technically correct.

    Don't do this. Especially with real hardware. If you lose one drive, you will lose both the drives.

    Could you give us more info on how your other encrypted drive is mounted and meant to be used?

    • It is possible to get the second encrypted drive to decrypt and mount automatically, without logging in.
    • It's possible to do it without leaving a key for your second drive on your primary hard drive using a TPM
    • It is possible to get both drives to decrypt automatically and mount

    It all depends how the encryption is being done, and where the mount points are.

    Could you give us:

    • The rough dimensions of the drive partitions (fdisk -l)
    • Your current mount points after mounting the second drive (df -h)
  • source
  • [–] 9 points 2 weeks ago*

    In my experience, those apps don't detect immediately, sometimes only alarming beyond 5 mins after contact. I have to assume by default to save power the scans are rate limited, like with WiFi scans.

    Those apps have to be allowed to scan when the glasses are transmitting to detect them, providing limited success.

  • source
  • parent
  • context
  • [–] 1 point 2 weeks ago (1 child)

    Lovers in a dangerous space time has been suggested already, so I'll just mention it as a second vote!

    Magicka and Magicka 2 are excellent, and hilarious. Might be a bit hectic later on, but early on both are pretty low stakes and paced slowly.

    My other recommendation is Octodad. You control independent limbs of an octopus, pretending to be a man. Multiplayer is couch co-op. Remote play would be tougher, but still very funny!

  • source
  • [–] 3 points 1 month ago* (3 children)

    Concrete strategies are pervertable. Values are less so. If you know what you're aiming for, you should be able to evaluate any strategies you encounter to see if they align. It's also not possible to build one strategy for everyone. How could you make it right for all communities? How could you force everyone to follow it? You'd need a state...

    Reading more about anarchism in general should expose you to concrete examples of what has been tried, how it worked, and how it was destroyed. I'd start with Orwell in Spain and the Anarcho-Syndicalysts.

    Based on my understanding, the method by which we get from the world today to the an anarchist society is often conflated with the social revolution of socialism. Maybe it will, maybe it won't. I doubt it. What I do know, is that anarchism isn't just a theory - it's a practice. We are meant to live it, not just talk about it.

    Start with anarchism as a spice. Any time you're in a position to influence the governance of something, a project, club, society or council, insist on making sure that all use of authority is justified.

    Get involved in everything you can, be the person that brings the anarchist perspective. You don't need to call yourself an anarchist and proclaim your actions for the cause. This isn't a crusade, you're not killing in the name of. It's about making sure that use of authority is justified. Offer the anarchist options, show others how to live a different way.

    Finally, always be aware someone will recognize what you are and what you're about. Anarchism is about making power justify itself, and if it can't, abolishing that power. This means that those that seek power will always notice you're the problem to them acquiring more power. They will seek to eliminate or neuter your ability to interfere.

    If you're making small waves in a small community, the response will likely be similarly small. If you've succeeded in making a whole region change to a different way of life, maybe it's a national guard with guns that comes knocking. Both can be devastating.

    If that sounds like a lot of effort, it is. That's why the world hasn't switched overnight. I would say however, that it's no more effort than is required anyway. Every strategy picked must be checked for suitability - the ends cannot justify the means.

  • source
  • parent
  • context
  • [–] 5 points 1 month ago

    I mean, they're 100% correct to do this. Forgejo is definitionally a SaaS application thanks to https://codeberg.org/. Specifically because of the affero clause, you can't relicense AGPLv3 code as GPLv3, so you can't include it in the project.

    Moving it to some sort of pluggable module would be good, rather than just dropping it though. There's nothing stopping them shipping code that downloads and sets up exif-terminator. I think working with the AGPL would send a good message and set a good example here.

    PR

    PR commit

    Reopened issue to resolve the problem

  • source
  • parent
  • context
  • Locking the bootloader (sh.itjust.works)
     

    I've been looking through the documentation and installation guides for PostmarketOS, and I've noticed there seems to be no mention of locking the bootloader after flashing.

    Is that because there's no issue with doing so, or because you can't?

    I'm looking at installing on a Fairphone 5, but anyone with any device that's able to share their experience would be appreciated.

    view more: next ›