himazawa

@himazawa@infosec.pub

This profile is from a federated server and may be incomplete. Browse more on the original instance.

A few questions about selfhosting from a newbie

Hi, I recently acquired a pretty solid VPS for a good price, and right now I use it to run Caddy for two personal sites. When I moved to Lemmy I found about this awesome community and it got me really interested in selfhosting. I won’t be asking for tips on what to selfhost (but feel free to add what you use), there’s a lot...

himazawa,

Don’t expose anything from your local network to the internet (unless you want multiple new sysadmins in your house). Try tailscale instead.

himazawa,

The difference is that you need way more interaction. Expose a webserver on the internet and check how many requests you get from just bots.

You can control what you navigate and how to interact with the outside world, but you can’t control how the outside world will interact with your services.

himazawa,

Anyone knows if there is any project for a modular NAS? Have been looked into it for a while but without success

himazawa,

Ye you are right but I was talking of 3D enclosures where you can put a zimaboard or whatever mini pc.

himazawa,

How much like the corne do you want it to be?

like a normal keyboard and not split

Also, how DIY do you want to get?

As long as no soldering is required I am up for everything

himazawa,

Row staggered but not splitted.

himazawa,

Do anyone have feedback on this?

chosfox.com/products/chosfox-l75-keyboard-kit?var…

Looks promising

himazawa,

It’s pretty funny, because from mechanicalkeyboards they suggested to post here because you have more knowledge on low profile keyboards.

himazawa, (edited )

Perhaps images, video, font etc. rendering could be compromised?

Yes, it already happen in the past. Also the Wi-Fi and Bluetooth stack got exploited, like multiple kernel drivers.

But it shouldn’t be a matter of “in the past was X exploited?” but more on having a correct security posture.

Honestly if you are arguing about wasting a “perfectly working phone” you should blame it on the vendor, especially Android devices vendors have this let’s say “defect” of dropping the support after 4/5 years.

Also not going to talk about custom ROMs (with the super rare exclusion of some) managed by god knows who, without any security team behind.

Since even the NFC and Cellular Network stack got vulnerabilities the only way you would consider an old phone “safe” to use is just turning it into the equivalent of a local ARM server.

Also pretty fun seeing the replies in the original post talking about how Google Play store shouldn’t have malware on it.

himazawa, (edited )

I believe the risk of running outdated software is super inflated and mediatic, 99% of people would be absolutely fine running a version of Android from 3 years ago or Windows 8.

That’s the same thing people running windows XP on internet were thinking in 2017.

Then WannaCry arrived and they got their data encrypted :)

himazawa, (edited )

WannaCry targeted hospitals, businesses and similar machines.

WannaCry targeted everything with SMB exposed, blindly.

Also, you should read more about security through obscurity, the fact that “no one will target you because you are a low-value target” is a false sense of security.

himazawa,

P.S. hot swappable and no soldering required.

himazawa,

I don’t know why the author of the video didn’t mention it but LockDown mode is really useful.

At least for me the default is lockdown mode on and appropriate exceptions for websites I trust.

himazawa,

Do anyone knows if it support local-only without joining the p2p network?

himazawa, (edited )

Exploited in the wild, reported in April, no fix since then?

Edit: looks like it was fixed on the 26th of April, why is tagged as 0day?

himazawa,

Ahaha I had this exact same experience. Locked out because bitwarden didn’t get the code correctly. “Luckily” the jwt token never expires so I was able to log back in without the 2FA.

With my recent de-modding and ban from the DnDMemes sub, I now have plenty of time to touch grass and help grow this community/instance. AMA I guess? (ttrpg.network)

For the record, I fully support what the remaining mod team is doing, they are a wonderful group and I trust them completely. I don’t regret the choices I made, only that my actions got a few other mods shit canned in the process.

himazawa,

So in the end you got removed… I honestly have no idea how they want to do an IPO like that

himazawa,

I was thinking about that just today, I have something like 30+ services running on a single compose file and maintenance is slowly becoming hard. Probably moving to multiple compose file.

himazawa,

I wonder if people when talking about AI just ignore the fact that it’s software and has the same issues and vulnerabilities related to that… recently I see a lot of posts talking about “AI security” and in the end are stuff known since 1995…

himazawa,

What am I looking at?

himazawa,

Thanks. I have never seen the last thing, what the numbers indicates?

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • thenastyranch
  • magazineikmin
  • cubers
  • InstantRegret
  • cisconetworking
  • Youngstown
  • vwfavf
  • slotface
  • Durango
  • rosin
  • everett
  • kavyap
  • DreamBathrooms
  • provamag3
  • mdbf
  • khanakhh
  • modclub
  • tester
  • ethstaker
  • osvaldo12
  • GTA5RPClips
  • ngwrru68w68
  • Leos
  • anitta
  • tacticalgear
  • normalnudes
  • JUstTest
  • All magazines