- End Times Fascism, And the Fight for the Living World (Naomi Klein and Astra Taylor)
- The Age of Extraction: How Tech Platforms Conquered the Economy and Threaten Our Future Prosperity (Tim Wu)
2,457 karma · joined April 7, 2013
- End Times Fascism, And the Fight for the Living World (Naomi Klein and Astra Taylor)
- The Age of Extraction: How Tech Platforms Conquered the Economy and Threaten Our Future Prosperity (Tim Wu)
It's far from perfect, but it was a quick way to get rid of bots, while not completely blocking people from countries such as Vietnam.
However, on a Gitlab instance I manage (500 users), we have to restrict viewing of git logs and pretty much everything except issues. The bots were too aggressive. Chinese crawlers have access to a huge range of IPs and they often do only 10-20 requests per day, while generating in total over 50k requests per day. Our server load went from 99% down to 0.1% after that (and it's a fairly big server).
I know sudo-rs will likely not allow viewing the password in the short term, but the benefit to being able to have some visual feedback, is that it lets me use a more complex password.
Other example: if I'm on a ssh link with very high latency (ex: on a phone), I might type one character at the time, make sure they register correctly, and continue. If I can't do that, then I'll type the password in a text editor, then copy-paste it into the password prompt.
Some clients use Jitsi, but I find it more complicated to run Jitsi in-house. BBB was really easy to setup.
I see finances for a few free software projects, and many of them really struggle to get donations year after year, in a way that helps make the project predictable and sustainable.
For the US, people want you to be a 501c3, and then you need a EU equivalent. Canadians are unlikely to give to a US org (especially these days), but the market is too small to setup a local charity. So you need partners. All that has many compliance requirements and paperwork, so you need non-tech employees for the fundraising and accounting.
Eventually your big donors start blackmailing the project if you don't do what they want, and often their interests are not aligned with most users. You need various income sources.
Their documentation is excellent, the improvements and roadmap for Thunderbird made me finally adopt it, and I appreciate their privacy-friendlier translation services. uBO works great in Firefox, and I can't stand using a browser without its full features.
About MBA types: the free software project I work for has an MBA type, which I initially resented as being an outsider. However, they manage the finances, think about team and project growth long-term (with heavy financial consequences), and ignore the daily technical debates (which are left to the lead devs), and listen to users, big and small. Some loud users like to complain that we don't listen to them, and sometimes we kick them out, because we do listen to users.
I don't know much about Mozilla internals, if I am to judge from the results: Mozilla is still here, despite everyone saying for 10+ years that they are going to die. They are still competitive. They are still holding big tech accountable, despite having a fraction of their power. I can imagine that they make a lot of people here very uncomfortable.
With Syncthing, I sync to a directory that my Nextcloud user can access (a read-only mount), so I can still easily share photos using Nextcloud, for example.
(although it's unfortunate that the Android syncthing app is being retired. h/t for the heads up and the recommended alternatives)
I used Nextcloud sync in the past, but found it unreliable.
And CloudFlare went to court. Most companies would not be able to afford it.
Looking at my non-nerd 17 year old, they meet maybe once a month, and it's to cook food together during the day. Nobody drinks. They just see it as a waste of money. Maybe not the most normal sample. They love biking and also go to circus school together (Montreal).
I find it easier to write custom checks for things where I don't control the application. My custom checks often do API calls for the applications they monitor (using curl locally against their own API).
There are also lots of existing scripts I can re-use, either from the Icinga or from Nagios community, so that I don't write my own.
For example, recently I added systemd monitoring. There is a package for the check (monitoring-plugins-systemd). So I used Ansible to install everywhere, and then "apply" a conf to all my Debian servers. Helped me find a bunch of failing services or timers, which previously went un-noticed, including things like backups, where my backup monitoring said everything was OK, but the systemd service for borgmatic was running a "check" a found some corruption.
For logs I use promtail/loki. Also very much worth the investment. Useful to detect elevated error rates, and also for finding slow http queries (again, I don't fully control the code of applications I manage).
My teenager never had any issues with using Linux since the age of 10 (old laptop with Firefox and Minecraft), and never used Windows (school uses Chromebooks). Hopefully this works with just a standard editor too, although the Crunchlabs IDE looks nicer for learning.
China is authoritarian, but also has a huge political system, somewhat strong institutions. That can't be said of many authoritarian regimes, which tend to be more fragile. It takes a really long time to build civil institutions. For example, Russia has the money and an authoritarian regime, but repeatedly fails to innovate, and we can't predict what will happen when Putin leaves.
(Feeld also lets you skip a profile, and get back to it later)
Most of my git usage on the CLI is nothing fancy, just a few commands, but I keep a text file for some tips/tricks I don't use regularly.
People are definitely less risk-taking, workaholics, despite having a social safety net, or maybe because of it. It's just maybe less in our culture to "go big or go home". Having a cabin in the woods and free time to live your life is nice.
Maybe because I live in Quebec, and language is definitely a barrier (requires immigrants to be trilingual), but I haven't met many shady people from China or India, on the contrary. My ancestors came here by accident from different countries, taking a random boat in a port, worked hard and made it. I hope we can give that opportunity to others too.
Many things don't matter at a small scale, but they do at 15M-scale.
Trello users are about to get bombarded by phishing attempts and spam.
We have a web app that does QR scanning for event badges, using a JS library, but it's painfully slow compared to the camera app.
In some systems, a password reset lets you bypass MFA. On Gitlab, however, you might be able to reset the password, but it will not let you bypass MFA (which was a nice mitigation for this CVE).
I often wonder about this, because people's email should have fairly good security (MFA, detect new devices, suspicious IPs, alerts, etc), and MFA on the other service lets them have similar protections. Both services might not be bullet-proof, but an attacker will likely generate alerts in one or the other.
Most of my users are very non-technical, and might not have access to their MFA (MFA reset requests are fairly frequent), so to be able to access using a one-time-secret sent by email seems like an acceptable compromise, especially if it means that more users will enable MFA. In systems I administer, less than 20% of users tend to enable MFA (it depends on org policy, and it's often optional).
Speaking of, I wish services would do auth by: login -> MFA -> pass, instead of login -> reCaptcha -> pass -> MFA. Especially for scenarios where MFA is mandatory. Having reCaptcha is really annoying considering I went the extra step of enabling MFA (ex: Stripe, Quickbooks).
However, my actual Mastodon feed only has content from people I follow, without any recommendations, and that works great.
Divorce date can be pretty random, since it's rarely done live by a judge/official.