Anonymouse

joined 2 years ago
 

Google Threat Intelligence Group (GTIG) has observed increasing efforts from several Russia state-aligned threat actors to compromise Signal Messenger accounts used by individuals of interest to Russia's intelligence services. While this emerging operational interest has likely been sparked by wartime demands to gain access to sensitive government and military communications in the context of Russia's re-invasion of Ukraine, we anticipate the tactics and methods used to target Signal will grow in prevalence in the near-term and proliferate to additional threat actors and regions outside the Ukrainian theater of war.

TL;DR: keep your apps updated & don't scan QR codes that you don't trust.

[–] Anonymouse@lemmy.world 4 points 1 month ago

I've been trying to learn K8s and more recently the Gateway API. The struggles are that most Helm charts don't know Gateway (most are barely Ingressroute) and I'm trying to find a solution to one service affecting the other gateways.when a service cannot find a pod, the httproute fails and when one route fails, the ingress fails. It's a weird cascading problem.

Right now, I'm considering adding a secondary service to each gateway that resolves to a static error page. I haven't looked into it yet; it cane to me in the brief moment of clarity before I fell asleep last night.

Also, I may be doing everything wrong, but I am learning and learning is fun.

[–] Anonymouse@lemmy.world 2 points 1 month ago

I saw a documentary once that said that elephants are starting to be born without tusks. Male & female. It's evolution in action. It's sad to me, but life finds a way.

[–] Anonymouse@lemmy.world 2 points 1 month ago

There was a sea turtle at an aquarium that I visited with a 3d printed shell, so why not this?

I'd prefer to use the confiscated tusks to beat the poachers with. After that, they should give them back.

[–] Anonymouse@lemmy.world 2 points 1 month ago

I landed on Tandoor. I had a bunch of recipes on one of those web sites and they switched to a subscription model and locked me out of my recipes. I don't remember why I chose Tandoor over Mealie, but having full ownership over my recipes is freeing.

[–] Anonymouse@lemmy.world 5 points 1 month ago

What's the deal with VPNs? I noticed many instances don't work over VPN but didn't know where to ask.

[–] Anonymouse@lemmy.world 1 points 2 months ago (1 children)

Do you think this would make enough people mad enough to get their representatives to do something about it?

[–] Anonymouse@lemmy.world 2 points 4 months ago

I am interested in compression. I may give it a try when I swap out my desktop system. I did try btrfs in it's early, post alpha stage, but found that the support was not ready yet. I think I had a VM system that complained. It is older now and more mature and maybe it's worth another look.

[–] Anonymouse@lemmy.world 1 points 4 months ago

Those are some good points. I guess I was thinking about the hardware. At least where I do RAID, it's on the controller, so that offloads much of the parity checking and such to the controller and not the CPU. It's all probably negligible for the apps that I run, but my hardware is quite old, so maybe trying to squeeze all the performance I can is a worthwhile activity.

[–] Anonymouse@lemmy.world 1 points 4 months ago (4 children)

Generally, if a lower level can do a thing, I prefer to have the lower level do it. It's not really a reason, just a rule of thumb. I like to think that the lower level is more efficient to do the thing.

I use LVM snapshots to do my backups. I don't have any other reason for it.

That all being said, I'm using btrfs on one system and if I really like it, I may migrate to it. It does seem a whole lot simpler to have one thing to learn than all the layers.

[–] Anonymouse@lemmy.world 2 points 4 months ago (6 children)

I've got raid 6 at the base level and LVM for partitioning and ext4 filesystem for a k8s setup. Based on this, btrfs doesn't provide me with any advantages that I don't already have at a lower level.

Additionaly, for my system, btrfs uses more bits per file or something such that I was running out of disk space vs ext4. Yeah, I can go buy more disks, but I like to think that I'm running at peak efficiency, using all the bits, with no waste.

[–] Anonymouse@lemmy.world 20 points 4 months ago (1 children)

That is the plan. Imagine an app that can provide personalized pricing to extract just less than the amount that would cause you to go elsewhere?

It knows when you get paid and can splurge. It knows when you are drunk or high and have less self control. It's the digital pricing tags at the grocery store, but personalized to you (and not with your best interests in mind).

[–] Anonymouse@lemmy.world 7 points 4 months ago (1 children)

If it helps quell any anxiety, the ring cameras are not made of quality components. A neighbor with a south facing camera said that the camera was there when they moved in, but the lens is so sun damaged that you can't see anything. It was installed maybe 2 years ago. They said that they only use it as a doorbell now.

As mentioned in another post, a malicious neighbor could blast UV light at the cameras day and night for a while to make the camera mostly ineffectve.

 

As if anybody here needs a reason to be wary of what you do online, this essay shares how a foreign adversary used back doors that were intentionally put in place to spy on Americans and how the rest of the world probably has the same back doors.

I especially appreciate the phrase "nerd harder" and the quote, "The laws of mathematics are very commendable, but the only law that applies in Australia is the law of Australia".

How can IT folk help politicans to understand?

 

While reading many of the blogs and posts here about self hosting, I notice that self hosters spend a lot of time searching for and migrating between VPS or backup hosting. Being a cheapskate, I have a raspberry pi with a large disk attached and leave it at a relative's house. I'll rsync my backup drive to it nightly. The problem is when something happens, I have to walk them through a reboot or do troubleshooting over the phone or worse, wait until a holiday when we all meet.

What would a solution look like for a bunch of random tech nerds who happen to live near each other to cross host each other's offsite backups? How would you secure it, support it or make it resilient to bad actors? Do you think it could work? What are the drawbacks?

 

I thought this group may enjoy this read about a suggestion on an option to take in the Google antitrust lawsuit. Of particular interest is that certain groups feel that the "right" approach is that everyone should be able to surveil the population, Google-style and the choice quote:

The judge repeats some of the most cherished and absurd canards of the marketing industry, like the idea that people actually like advertisements, provided that they're relevant, so spying on people is actually doing them a favor by making it easier to target the right ads to them.

 

Does anybody have any workarounds for apps that don't work due to "security"? I have a few apps that I need for work that think my phone is rooted (it is not) and refuse to run. One is Entrust Identity Guard. It just won't open ("app keeps stopping") and the other is Service Now mobile ("a rooted device is not allowed").

 

I had a super fast but small SSD and didn't know what to do with it, so I was playing with caching slow spinning LVM drives. It worked pretty good, but I got interrupted and came back a few weeks later to upgrade the OS. I forgot about the caching LVM, updated the packages in preparation for the OS upgrade, then rebooted. The LVM cache modules weren't in the initfs image and it didn't boot.

I should know better. I used to roll my own kernels since Slackware 1.0. I've had build initfs images for performance tweaks. Ugh!

Where's my rescue disk?

 

I got hung up on contractions this morning regarding the word "you've". Normally, I'd say "you've got a problem", which expands to "you have got a problem", which isn't wrong, but I normally wouldn't say. Not contracting, I'd say "you have a problem", so then should I just say "you've a problem"? That sounds weird in my head. Is this just a US English problem?

 

US Senator Edward Markey (D-Mass.) is one of the more technologically engaged of our elected lawmakers. And like many technologically engaged Ars Technica readers, he does not like what he sees in terms of automakers' approach to data privacy. On Friday, Sen. Markey wrote to 14 car companies with a variety of questions about data privacy policies, urging them to do better.

 

The EFF has a white paper with a proposal to address various online 'harms' systemically.

From the executive summary, "whatever online harms you want to alleviate, you can do it better, with a broader impact, if you do privacy first."

Slashdot also has a pretty good summary if the white paper is too long for you to read.

 

I haven't seen this posted yet here, but anybody self-hosting OwnCloud in a containerized environment may be exposing sensitive environment variables to the public internet. There may be other implications as well.

 

Other than TiVo, what options do I have for recording OTA programs? I've been playing with Plex and rip my episodal DVDs, and would like to record, too.

 

This is a long article about the US CFPB creating a new rule that may help protect your financial data. The interesting stuff is near the end where it sounds like they're putting your financial data back in your hands:

The Bureau will force banks to "share data at the person’s direction with other companies offering better products."

the businesses you connect to your account data will be "prohibited from misusing or wrongfully monetizing the sensitive personal financial data."

I'm not very knowledgeable in this area so I'm wondering what your read is on it.

view more: next ›