Findmysec

joined 4 months ago
[–] Findmysec@infosec.pub 2 points 3 months ago (2 children)

What's the pay like for system admins in Europe on an average? Asking for mid-level (5-7 years of experience)

[–] Findmysec@infosec.pub 2 points 3 months ago (2 children)

I have definitely read this answer before. I think we've probably already spoken on the matter. Indeed, Lemmy has a serious dearth of users interested and using secure distros over the averages. Thanks for your efforts; I do not know how to follow users on Lemmy but if I did I'd follow you. Do you have a blog/any other forum you're more active on?

Personally, I find it difficult to justify the time to learn Secureblue (especially the immutable part) or NixOS on Qubes because custom DispVMs with curated salt states work so well already. I'm interested in use-cases that will improve my security but I haven't found any dialogue on this yet. If you do have opinions on this and know where I can look, I would greatly appreciate it!

[–] Findmysec@infosec.pub 4 points 3 months ago (4 children)

I would be really interested in a comparison of Kicksecure and secureblue. I'm interested in running one of them myself

[–] Findmysec@infosec.pub 4 points 3 months ago (3 children)

Well the Star64 from Pine is pretty good, just doesn't have enough processing power and IO for my liking.

[–] Findmysec@infosec.pub 11 points 3 months ago (5 children)

Framework has a laptop in progress if you're interested

[–] Findmysec@infosec.pub 5 points 3 months ago

How would they do DPI on DNS packets routed using DoH? It looks like HTTPS traffic, it's encrypted, and other than size and frequency I don't see how they can gey anything out of it. Yeah they'll get the SNI with eCH but that's supported by FF and by a lot of providers using DoH

[–] Findmysec@infosec.pub 1 points 3 months ago

Yeah that's your situation. Some people are fine with it

[–] Findmysec@infosec.pub 2 points 3 months ago* (last edited 3 months ago) (1 children)

Ah, you mean they put the cert in a transparent proxy which logs all traffic? Neat idea, I should try it at home

[–] Findmysec@infosec.pub 3 points 3 months ago* (last edited 3 months ago)

Private CA is the only way for domains which cannot be resolved on the Internet

[–] Findmysec@infosec.pub 1 points 3 months ago
[–] Findmysec@infosec.pub 7 points 3 months ago

Now look here chap, Quadlet admittedly works fine. I personally just k3s anyway but .pod files work too.

Isn't being obedient to SELinux a good thing? You could set it to permissive if you want, but MAC systems are essential for security and I personally wouldn't go without them

[–] Findmysec@infosec.pub 4 points 3 months ago

I guess z-library needs to make a template on how to get a setup like theirs working. Unlimited subdomains lmao

view more: ‹ prev next ›