Plain old Debian always wins if you prefere a Wirkung sytem over bleeding edge features
SomeLemmyUser
- 0 Posts
- 10 Comments
- SomeLemmyUser@discuss.tchncs.detoLinux Gaming@lemmy.world•Distro RecommendationsEnglish2·23 days ago
- SomeLemmyUser@discuss.tchncs.detoCybersecurity@sh.itjust.works•GitHub user Bikini has decided to drop a bunch of POCs for unreported exploitsEnglish11·26 days ago
People in the cultural left in Europe often use this term in order to sensitively describe people who are (historically) discriminated because of their phenotypes. (E.g. Asians, latino, blacks, etc…)
I know you are satirical, but you are also kinda correct. Non-POCs would typically be “whites” (at least in Europe) who are still privileged, going back (at least) since colonialism. (E.g. Nordic, alpine or mediterranean phenotypes")
- SomeLemmyUser@discuss.tchncs.detoCybersecurity@sh.itjust.works•GitHub user Bikini has decided to drop a bunch of POCs for unreported exploitsEnglish3·26 days ago
Thanks :) “Exploitarium drops some POCs” is a quite frightening sentence in some scenarios xD
- SomeLemmyUser@discuss.tchncs.detoCybersecurity@sh.itjust.works•GitHub user Bikini has decided to drop a bunch of POCs for unreported exploitsEnglish9·27 days ago
Im from politics, where poc means person of color. I hope that differs here?
- SomeLemmyUser@discuss.tchncs.detoSelfhosted@lemmy.world•Safely exposing services to the InternetEnglish1·1 month ago
Well, i never argued against the clearly powerfull capabilities, those are obviously huge, my point was that as a hobbyist you should consider having the important stuff (finances, official documents, biometrics) in cold storage or on a separate machine as well as stuff like security cameras or doorlocks if you do stuff like this out of it until you fully understand the risks, which are not that easy to grasp for people without experience.
Ofc proxmox and qubes are incredible useful tools of technology, but their high versatility and customizability gives you a lot of tools you need understand and use properly on top of what you are already doing. (More so with proxmox as with qubes, qubes is a little less industry focused IMHO)
- SomeLemmyUser@discuss.tchncs.detoSelfhosted@lemmy.world•Safely exposing services to the InternetEnglish1·1 month ago
Valuable insight, thanks :)
- SomeLemmyUser@discuss.tchncs.detoSelfhosted@lemmy.world•Safely exposing services to the InternetEnglish1·1 month ago
Why is a hypervisor the best we got? Why would better than a dedicated bare metal server? Why would the attack surface if a hypervisor be smaller than the attack surface without one?
Honest question
- SomeLemmyUser@discuss.tchncs.detoSelfhosted@lemmy.world•Safely exposing services to the InternetEnglish1·1 month ago
Thanks for evaluating! The exploit was explained to me that an unpriviliged user/Programm could use it to get root access on the whole system, which I my mind included the hypervisor. Further reading seems to proof you right, while containers were broken VMs were not.
My point still remains, although weaker: If you know exactly what you are doing you can get a system quite secure, if you are a hobby server owner like me, its not that easy. I would have not know that the use of VMs instead of containers has sooo major security implications, that something so fundamental as ssh could be exploited in such large scales, and clustering would have been needed to avoid being unsafe.
Sure, noone would use an zero day on me targeted, the thing is: I am not working in the field, from publishing of the exploit till learned about it and had the time to patch, there were a few weeks. If in those few weeks someone deploys a tool going for mass and not for single targets, I would probably be infected and added to some botnet, cryptominer or whatever.
If I have a bare metal dedicated server, which has only access to IPs contained in my whitelist on a dedicated opnsense, I have less to wory about. Sure, someone could still find a openbsd/opnsense exploit and get me, but my point is: complex systems break in complex ways, the more complex systems you use, the more attack surface u have, need to know and understand to control and mitigate it.
Not that its impossible, but for a hobbyist who tries to self teach with man pages, tutorials and forums, you can get pwnd in unexpected ways (like because you used a container for dodgy Chinese smart home devices and expected that your production environment would be safe even if one of them was malicious, but in fact you were not, because that would have needed to be a VM. AND: before copy fail was published, users would have probably also told you that containers are safe.
- SomeLemmyUser@discuss.tchncs.detoSelfhosted@lemmy.world•Safely exposing services to the InternetEnglish6·1 month ago
I was going to build my system like that, but recently learned that host client isolation is not as strong as people make you believe.
just a few weeks ago we learned that copy fail (security vulnerability) was on major distros for years until it was fixed, it would allow containers and VMS to infect the host system. Xz utils could also lead to a broken host client separation, as proxmox uses ssh for clustering and the like.
So for really important stuff I am going to have a dedicated physical server or put it in cold storage altogether.
That said, I am by no means an expert so feel free to correct me if I got something wrong.
Isnt the sun the actual lamp and all others the forbidden ones? Like they try to orient at the sun when wanting to rise higher, that’s why they get caught by artificial light no?