himazawa

joined 2 years ago
MODERATOR OF
 

Used nix last year but dropped it after home-manager decided to unlink the apps from the Applications directory.

How is the current situation on usability of nix-Darwin + home-manager + brew?

Packages still fails to get indexed correctly in spotlight? I really like a fully repro environment but the fact that the usu ability was low bothered me a lot.

[–] [email protected] 2 points 2 years ago* (last edited 2 years ago)

The difference is that you need way more interaction. Expose a webserver on the internet and check how many requests you get from just bots.

You can control what you navigate and how to interact with the outside world, but you can’t control how the outside world will interact with your services.

[–] [email protected] 1 points 2 years ago (2 children)

Don’t expose anything from your local network to the internet (unless you want multiple new sysadmins in your house). Try tailscale instead.

[–] [email protected] 7 points 2 years ago* (last edited 2 years ago)

WannaCry targeted hospitals, businesses and similar machines.

WannaCry targeted everything with SMB exposed, blindly.

Also, you should read more about security through obscurity, the fact that "no one will target you because you are a low-value target" is a false sense of security.

[–] [email protected] 3 points 2 years ago* (last edited 2 years ago) (2 children)

I believe the risk of running outdated software is super inflated and mediatic, 99% of people would be absolutely fine running a version of Android from 3 years ago or Windows 8.

That's the same thing people running windows XP on internet were thinking in 2017.

Then WannaCry arrived and they got their data encrypted :)

[–] [email protected] 3 points 2 years ago* (last edited 2 years ago)

Perhaps images, video, font etc. rendering could be compromised?

Yes, it already happen in the past. Also the Wi-Fi and Bluetooth stack got exploited, like multiple kernel drivers.

But it shouldn't be a matter of "in the past was X exploited?" but more on having a correct security posture.

Honestly if you are arguing about wasting a "perfectly working phone" you should blame it on the vendor, especially Android devices vendors have this let's say "defect" of dropping the support after 4/5 years.

Also not going to talk about custom ROMs (with the super rare exclusion of some) managed by god knows who, without any security team behind.

Since even the NFC and Cellular Network stack got vulnerabilities the only way you would consider an old phone "safe" to use is just turning it into the equivalent of a local ARM server.

Also pretty fun seeing the replies in the original post talking about how Google Play store shouldn't have malware on it.

[–] [email protected] 6 points 2 years ago (3 children)

Do anyone knows if it support local-only without joining the p2p network?

[–] [email protected] 5 points 2 years ago

So in the end you got removed.. I honestly have no idea how they want to do an IPO like that

[–] [email protected] 2 points 2 years ago

I was thinking about that just today, I have something like 30+ services running on a single compose file and maintenance is slowly becoming hard. Probably moving to multiple compose file.

[–] [email protected] 5 points 2 years ago (8 children)

Thanks. I have never seen the last thing, what the numbers indicates?

[–] [email protected] 9 points 2 years ago (15 children)

What am I looking at?

[–] [email protected] 1 points 2 years ago (3 children)

I use the Inbox-Zero method

https://youtu.be/al1QXFQjq1s

So far no issues.

[–] [email protected] 9 points 2 years ago (4 children)

Soon, people will join the strange and buggy world of YouTube alternative frontends

view more: next ›