truthfultemporarily

joined 7 months ago
[–] truthfultemporarily@feddit.org 21 points 1 week ago (1 children)

The threat model is that all communication is recorded and will be decrypted once the technology becomes available. The question then becomes for how long you want your data to be secure. If its for example 40 years, you need to chose an algorithm today that is still secure in 40 years.

[–] truthfultemporarily@feddit.org 7 points 1 week ago* (last edited 1 week ago)

I would recommend something like stalwart, which is just a single binary and works. Gives you a web interface and a zonefile you can just copy paste into your DNS including all correct DMARC DKIM SPF and autodiscovery records.

Setting postfix, dovecot etc. up from scratch can be a bit time consuming and annoying.

Deliverability depends on where it is hosted, many VPC providers IP space is completely blocked in spam filters.

[–] truthfultemporarily@feddit.org 36 points 1 week ago (6 children)

You only go to Valhalla if you died in battle or hang yourself from an ash tree.

I understand this, but this is inconsistent behavior. You now use 22 inside your network and something else outside. Whenever you create inconsistent behavior, everyone using it has to have an awareness of all these inconsistent behaviors.

Also, it is hard to troubleshoot because the tool most admins would want to use (netstat) will not give you useful information to understand the situation.

[–] truthfultemporarily@feddit.org 1 points 1 month ago (1 children)

If you have a drink that creates a nice tingling sensation in some people and make other people go crazy, the only sane thing to do is to take that drink off the market.

I'm not sure LLMs can do this. The reason is context poisoning. There would need to be an overseer system of some kind.

[–] truthfultemporarily@feddit.org 0 points 1 month ago (2 children)

If you change it, definitely change it on the server so it shows up in netstat and is consistent.

The idea behind keys is always, that keys can be rotated. Vast majority of websites to that, you send the password once, then you get a rotating token for auth.

Most people don't do that, but you can sign ssh keys with pki and use that as auth.

Cryptographically speaking, getting your PW onto a system means you have to copy the hash over. Hashing is not encryption. With keys, you are copying over the public key, which is not secret. Especially managing many SSH keys, you can just store them in a repo no problem, really shouldn't do that with password hashes.

[–] truthfultemporarily@feddit.org 45 points 1 month ago (6 children)

This is mostly nonsense.

  • Why block outgoing? Its just going to cause issues for most people. If you're going to do that, do it centrally (hw firewall)
  • Why allow http and NTP incoming, when there is no http / NTP server running.
  • If there is http server running no mention of https://ssl-config.mozilla.org/ and modsecurity
  • If you're using ufw anyway why not go with applications instead of ports?
  • In a modern distro, the defaults are usually sane (maybe except TCP), most of the stuff in the SSH config is already default.
  • Why change the SSH port of a home server, which most likely is not reachable from the outside anyway?
  • Actually potentially impactful stuff like disabling services you don't need, such as cups, is not mentioned
  • unattended-upgrades not mentioned
  • SELinux / AppArmor not mentioned
  • LKRG not mentioned https://lkrg.org/
  • Fail2ban not mentioned

Don't just copy random config from the internet, as annoying as it is, read the docs.

[–] truthfultemporarily@feddit.org 34 points 1 month ago (5 children)

It's not better than nothing - it's worse than nothing. It is actively harmful, feeding psychosis, and your chat history will be sold at some point.

Try this, instead of asking "I am thinking xyz", ask " my friend thinks xyz, and I believe it to be wrong". And marvel at how it will tell you the exact opposite.

Its probably talking about the UK stratospheric aerosol injection research. Like all conspiracy theories, just enough of a grain of truth.

[–] truthfultemporarily@feddit.org 3 points 1 month ago (4 children)

Could use mullvad DNS.

 

I just tried for 10 minutes to edit a date in a spreadsheet in nextcloud mobile and it didn't let me.

I just need an online office suite that works so I am not forced to use GSuite.

view more: next ›