434 karma · joined March 26, 2021
Microsoft should treat consumers better.
Bonus: Use these cmdlets on a offline mounted WIM image to build a custom image without bloats.
struct uptime_t u = {
.time = 0
};
ioctl(open("/proc/uptime"), GET_UPTIME, &uptime);% strace uptime 2> /tmp/strace && grep proc /tmp/strace
17:35:24 up 3 days, 7:47, 1 user, load average: 2.29, 1.85, 1.56
openat(AT_FDCWD, "/usr/lib/libprocps.so.8", O_RDONLY|O_CLOEXEC) = 3
openat(AT_FDCWD, "/proc/self/auxv", O_RDONLY) = 3
openat(AT_FDCWD, "/proc/sys/kernel/osrelease", O_RDONLY) = 3
openat(AT_FDCWD, "/proc/self/auxv", O_RDONLY) = 3
openat(AT_FDCWD, "/proc/uptime", O_RDONLY) = 3
openat(AT_FDCWD, "/proc/loadavg", O_RDONLY) = 4
It is easier to report a security issue to ntpd or chrony instead of creating a new one.
* Unified protocol to manage networking facilities
* iproute2 for FreeBSD, deprecating ifconfig(1) stuff
For hardware, I'm using Wacom 672. It has pretty good Linux drivers.
Then, if you want to use IPv4 NAT, set up SNAT and DNAT. I'm taking Linux's iptables for an example: on the VPS:
iptables -t nat -A PREROUTING -d <VPS Public IP>/32 -p tcp --dport port -j DNAT --to-destination <IP of another side of the WireGuard tunnel> iptables -t nat -A POSTROUTING -o <VPS Internet facing NIC> -j MASQUERADE
The first statement sets SNAT on IPv4 TCP (UDP is also possible) on a specified port. All packets going into this machine (dst = VPS public IP) will go into the other side of your WireGuard tunnel. -d <VPS Public IP>/32 makes sure that the packets forwarding to the VPN side won't get NATed. If you need multiple ports or protocols, just duplicate this line.
The second statement sets DNAT on the VPS. It makes the packets from your VPN side goes to the outside (sorry I'm not an expert in networking principals so that's my understanding).
On your local side, you just set up the tunnel and set your machine's default gateway to your VPS's tunnel IP address. Make sure you add a static route to your VPS's public address (WireGuard Endpoint) if you are connecting WireGuard using an IPv4 endpoint or it will get routed to your tunnel and you will disconnect.
I also sometimes setup IPv6 tunnels without NAT. On the VPS I just setup a WireGuard interface with /64 and assign each peer a /128. No NAT is needed for this case.
* Windows POSIX Subsystem: WSL has similar features, but not exact what the POSIX Subsystem is.
* Windows OS / 2 Subsystem: Killed.
* Multipoint Server: Killed in server 2016.
* Hyper-V RemoteFX
* WDS boot.wim deployment: Killed in server 2022 and Windows 11, although MDT provides a much better solution.
* TFS: MS wants you to use Azure DevOps.
* Hyper-V Server: The free ESXi alternative. MS wants you to use Azure, so it is killed with the release of server 2022.
* Microsoft Security Essentials: Killed in Jan. 2020, and its signature updates will stop in 2023.
* Windows CE: Replaced by Windows IoT
* Aero: Such a beautiful effect. Killed in Windows 8.
Disabling them requires upgrading to Enterprise or Education (basically Enterprise for schools).
Starting from a later Windows 10 feature update, Home users were forced to login their Microsoft account (for MS to steal your data by having you "cloud connected", right?) during OOBE. Now, Windows 11 Pro users were in the list.
I always recommend people to use the Enterprise edition regardless of their usage, even though you have to use illegal copies. This protects you from all these "cloud" stuff and get you back to a Windows 7 like experience.