458 karma · joined October 10, 2014
For a home network simple multi-port knocking should be enough (combined with --ctstate NEW even better). If port knocking or SPA is too cumbersome then at least consider limiting access based on GeoIP, block tor exit nodes, etc (ipset is pretty amazing).
This can be applied to any service on your network btw, including Wireguard. I like knowing that a portscan of my network shows nothing open. I don’t end up on a list that gets used in the next ‘spray and pray’ attack.
Disclaimer: I’m not advocating this for serious use due to replay attacks and IP spoofing via a VPS. This is for home network protection (a boring Class C non target).
https://www.pbs.org/wnet/nature/the-serengeti-rules-41dfru/2...
the guy = John Lansing
USA organization for external propaganda = USAGM (U.S. Agency for Global Media).
I’ve only helped recover from ransomware once about 2 years ago. When we ran the decryption program provided after paying it decrypted ~97% of the data. Some files were just permanently corrupted. Windows Server with ECC memory fwiw.
Fun note but the owner wanted to reboot after decryption and I yelled “No!” across the room, wanting to clone the known good data first. Good thing too, a reboot started the encryption all over again… good times.
I heard they were hit again but took my advice and setup Backblaze.
You’ve identified issues with whitelisting but blacklisting isn’t perfect either. For example, many don’t trust NIST and may want to prevent the use of any of their future curves. Blacklisting fails here.
When updating to a newer version of SSH I think it’s good practice to ‘man ssh_config’ and at least look at KexAlgorithms, HostKeyAlgorithms and Ciphers.
Would you please elaborate on your distrust of Cloudflare? I’m not looking to call you out. Quite the opposite, I appreciate your candor. I just feel like I’m missing some context.
Another benefit to using a user.js file is that your changes are persistent. If Mozilla changes a setting via an upgrade, like they did with experiments and plan to do with DoH, your changes aren’t overridden.
The only downside is if you decide to undo a setting in user.js you’ll also have to make the same change in about:config.
I’ve since left the Bay Area and now have SMUD. They come out every year to check brush and trees. This past summer they cut down a dying tree on the property at no cost. The arborist they sent out was extremely knowledgeable and didn’t mind that I took his time to ask about native replacements, etc.
There’s no doubt that Trump is capitalizing on it and why wouldn’t he?
What makes you think this is fear-mongering? As in fake. The Hong Kong events, South Park, NBA, etc… this is as organic a shit storm as I’ve ever seen.
I’ll start by saying I’ve setup DoH on my home router just for fun.
> Whilst seemingly not having the skills to block all public DoH providers in their network.
Now with my admin hat on - maintaining a list is an unnecessary burden. It’s a matter of sensibility not skill. Time is money after all.
DoT (DNS-over-TLS) probably should have won since it uses it’s own port (853) which makes it easily manageable, does the same thing and is more mature. The “but privacy” argument for DoH looks like a red herring.
> The dnscrypt-proxy file is quite large, but can be compressed for a massive reduction of its size, from ~12 Mb down to ~2 Mb.
Routers typically have 8-16 Mb of storage. Even 2 Mb is a bit much but even if the size doesn’t bother you the memory usage is still relatively extreme when compared to the link I shared.
[1] https://github.com/dnscrypt/dnscrypt-proxy/wiki/Installation...
If you’re interested in something lightweight for OpenWrt give this a try:
https://openwrt.org/docs/guide-user/services/dns/doh_dnsmasq...
Maybe if we had a universal battery and simple swap out solution. Something like a car wash where you drive onto a track and a machine swaps out the battery?
I’m not yet ready to crucify Apple for not issuing a press release listing sites and services affected. Same with the Google “deep dive” with it’s vague insinuations.
I suspect this is a big international incident like - “China bought hacks from Mossad to target Hong Kong” kind of big. For all we know there are gag orders in place and an ongoing investigation.
I will still use iOS devices too. They are still the most secure consumer available/friendly computing devices available imo. That said, I want to know more.
I can’t find it now but it wasn’t long ago that the NextCloud (or was it OwnCloud) FAQ had a note about security that read something like “we’re busy adding features we’ll get to security later”. It left me feeling uneasy. I would have hoped security would have been part of the design. Maybe I’m just getting old...
Or is this just another ploy to get better pricing?
Thanks team for keeping some of us sane!!
So, maintenance seems like a must. Especially on rooftops or structures that will naturally “settle” over time. If I had to guess, these tolerances weren’t properly maintained or the buildings/roofs themselves weren’t solid enough to begin with.
If anyone can shed more light on this (pun intended)…
I’ve known many people who perceive stuttering, slow page loads and game lag as a result of a slow connection. The ISP’s could solve this but I’d imagine it works in their favor. While I’m more than capable of tweaking SQM/Cake (OpenWrt) values and testing (keeping ping times below 40ms), I believe a simple consumer friendly (read: automatic) solution is sorely needed.
I bought an iPhone 7 from Net10 about 5 months ago for $220 shipped. It requires a minimum $20 a month plan for 12 months before I can unlock it. About 2 years ago I got my mom an iPhone SE for $140 with similar plan/unlock. Both brand new.
They’re not everyday prices and not the newest model but it is possible to go iOS without breaking the bank.
There has got to be a better way. I mean Sonic just lost a potential customer because I won't "Try Again Later".
Ubuntu + Firefox FWIW
Reasons I chose to go with a shaved head:
My dad wore a toupee and nobody was allowed over after dad took it off (he’d take it off immediately after work, apparently they’re not very comfortable). My uncle tried every new cream/lotion that came on the market and was obsessed (he died of brain cancer at age 62 btw). My grandfather, was just bald. Of the three my grandfather was the most confident and comfortable in his on skin.
I’m not telling you to just get over it, it’s demoralizing when you’re young. I just hope that with time you’ll become more comfortable with yourself. My wife and previous girlfriends never had a problem with it as many women don’t. At this point she tells me what length I should keep it and I just go with that.
https://act.eff.org/action/prevent-copyright-trolling-tell-t...
https://www.techdirt.com/articles/20190711/00001742562/congr...
Calibrating my monitors took them from having piercing bluish whites to more softer pinkish whites and reduced daytime eye strain significantly.
I then use Redshift at night with the undocumented "preserve" switch to combine my icc profile with the Redshift changes.