Skip Navigation
Amazon Prime Video will start showing ads on January 29th unless you pay extra for ad-free
  • Worse. It went off into other conspiracy subjects like 9/11 and all sorts of crap. Theres frankly a lot of weird stuff on amazon prime for free that i would have never seen had i not dozed off.

    Most of the other apps (netflix, plex, etc) and even the streaming platform (roku) have measures to combat falling asleep. Whether its disabling auto-play (which amazon didnt have) or bandwidth saver features that will periodically ask if you are still there (which amazon appears to somehow bypass or disable, or did).

    These days though i set a sleep timer to shut off the lights and TV at midnight.

  • Any recommendations for free software backup programs that work on Windows?
  • Not free as in foss. But free as in beer.

    You can use xpenology or just a synology disk station with active backup for business. It does quite well with windows and just runs in the background.

    Before using that I use urbackup ,which is FOSS. It also worked quite well.

  • Amazon Prime Video will start showing ads on January 29th unless you pay extra for ad-free
  • I tried to use their UX. Its bad. And the worst is I fell asleep watching something like Project Bluebook once. And the Prime Reccomendations streamed a SHITLOAD of alien conspiracy content while i slept. It ruined the recs etc. And you cant delete the primary account profile....only the sub-profiles.

    Frankly i only go on it to see what I should maybe load into Sonarr/Radarr at this point. fuck em.

  • ‘Don’t worry about me. I’m fine’: Kremlin critic Navalny from Arctic jail
  • He had a dry run with the attempt on his life. He knew nothing would come of it. That the rest of the world would do nothing.

    Hell Russia has since pushed the boundaries much further with no recourse.

    I can respect that he’s principled and still recognize the total lack of forethought in the move.

  • ‘Don’t worry about me. I’m fine’: Kremlin critic Navalny from Arctic jail
  • This guy has to be one of the dimmest folks I have ever seen. Putin straight tried to kill him, failed and the world did nothing and yet he still turned himself in as some type of martyr. The world was going to do nothing and they were going to torture him and trump up any charges they felt to ensure he never sees the light of day again and for what? Nothing.

    He could have done more even in exile.

  • Today was Christmas Day. Did you leave the house? Which establishments were open today? Which were closed?
  • Frankly i find it inconsiderate to the social contract to go out on holidays, and sometimes around them.

    Its frankly why i always found Black Friday and the "scope creep" of this festival of consumerism partially so repulsive. I mean its repulsive on its own just in the way people act, but doubly so in that it runs right through a national holiday.

  • Security News @infosec.pub UselesslyBrisk @infosec.pub
    ASUS warns router customers: Patch now, or block all inbound requests
    nakedsecurity.sophos.com ASUS warns router customers: Patch now, or block all inbound requests

    “Do as we say, not as we do!” – The patches took ages to come out, but don’t let that lure you into taking ages to install them.

    ASUS warns router customers: Patch now, or block all inbound requests
    0
    Security News @infosec.pub UselesslyBrisk @infosec.pub
    Reddit hackers threaten to leak data.
    www.bleepingcomputer.com Reddit hackers threaten to leak data stolen in February breach

    The BlackCat (ALPHV) ransomware gang is behind a February cyberattack on Reddit, where the threat actors claim to have stolen 80GB of data from the company.

    Reddit hackers threaten to leak data stolen in February breach
    0
    Security News @infosec.pub UselesslyBrisk @infosec.pub
    Cost-of-Living Crisis increasing chances of Insider threats
    www.itsecurityguru.org Cost-of-Living Crisis increasing chances of Insider threats

    A new study conducted by CyberSmart has revealed that nearly half of UK SMEs (47%) believe they are at greater risk of a cyberattack since the onset of the cos

    Cost-of-Living Crisis increasing chances of Insider threats
    0
    Security News @infosec.pub UselesslyBrisk @infosec.pub
    MOVEit discloses THIRD critical vulnerability
    www.malwarebytes.com MOVEit discloses THIRD critical vulnerability

    Progress has released an advisory about yet another MOVEit Transfer vulnerability while new victims of the first one keep emerging.

    MOVEit discloses THIRD critical vulnerability
    0
    Should I host my own instance if I don't intend to run a community?
  • Yes the ansible config worked fine for me. I worked for days to get an kbin instance up. Ansible worked first go.

    I have yet to get email working but otherwise its solid. Linode will block email btw if you account is new (and frankly may be blocking mine now). You just have to put in a case and justify and it should be fine. My account should be old enough to be exempt but I will likely do it anyhow. Their support is pretty good.

    Getting federation crawled and communities added is a bit slow. Mostly because the other instances are a bit slow.

    A few pointers if you havent done admin yet.

    1. Put nothing in the federation allow list unless you want to go whitelist only. Over time as other instances hit yours and you search others, the linked list of instances will grow. Just use the blocklist if you want to block certain instances. I havent found a good way to block the growing number of instances in case they have some illegal content like CSAM. So...i may just go whitelist anyhow

    2. Searching for instances seems to be CPU heavy on mine. Its not a problem though. You just cant simply plug in a URL of a community in another instance if you havent linked. You will get a 404 if you do. So you have to go to search, looking for that community by hitting search a few times until it shows up, then you can join and it will start crawling

    3. I have no idea what "Private instance" does other than i believe it will keep your instance form starting in the future if you have it checked AND federation turned on. I saw some logs in dockers startup when i did it but nothing in the UI.,

  • Should I host my own instance if I don't intend to run a community?
  • Im currently on the 4GB dedicated. However heres an htop of it.

    https://imgur.com/a/NpEsw4t

    I am currently the only user. Im considering opening it up to limited users but not really having communities once i get a lot of the instances cached and indexable.

    Others like @leopardboy@netmonkey.tech are running on a 2GB shared just fine. I will likely move to that if i choose to keep it solo for sure, or under 100 users and no communities.

    I dont have the time to really moderate others or content on the instance. So i dont think I plan to host any communities at all. I do wish you could federate/sync specific communities to your instance to make searching/subscribing easier.

  • Should I host my own instance if I don't intend to run a community?
  • I’ve run linodes for years. My blog runs on them. I still host a variety of other services on them. They are good for everything from gaming servers to a blog etc.

    They did get bought out by akamai a while back. And have raised their prices but they are still solid.

    Nanodes are awesome deals frankly.

  • Should I host my own instance if I don't intend to run a community?
  • I have a lab at home and do host some stuff for myself from there in a small DMZ (ie: Miniflux RSS readers, Plex through Reverse proxy etc).

    But I used a linode for my lemmy/kbin stuff. Reason being is that the code is fairly new and there may be exploits bugs and

    1. I dont want to deal with my ISP made an instance is exploited and becomes some type of C2 box or spews out spam. Kbin specifically already has PRs to fix XSS and Sql injection stuff, the former of which is usually avoidable if you just follow some pretty basic principles. So its a concern.

    2. Linode has better bandwidth than my non-symmetrical ISP uplink and is on its own quota.

  • Discussions related to Infosec.pub @infosec.pub UselesslyBrisk @infosec.pub
    Have been seeing this 404 error for external instance communities here and there.
    imgur.com imgur.com

    Discover the magic of the internet at Imgur, a community powered entertainment destination. Lift your spirits with funny jokes, trending memes, entertaining gifs, inspiring stories, viral videos, and so much more from users.

    imgur.com

    What am I doing wrong. I know that community exists. Just cant sub to it through my account.

    0
    [Question] Does anyone run their own email server?
  • I stopped running my own a while ago. Its no longer really decentralized and the big players (google/microsoft) will often just blacklist you for little reason.

    That said I DO maintain my own domain and backups. So i can take my email to whatever hosting provider I want.

    I also noticed, during the migration, that if you simply register your domain with one of the big players (ie: Google Workspace or M365) you will often get whitelisted and email will flow easier. This was easier when they had a free tier though.

  • Former TikTok exec: Chinese Communist Party had "God mode" entry to US data
  • Yeah definately a "water is wet" kinda revelation.

    Also, given that I am not Chinese, I dont really see much of a risk for foriegn citizens. I would be more concerned with my own governments spying (and most all of them do in the western world).

  • Former TikTok exec: Chinese Communist Party had "God mode" entry to US data
    web.archive.org Former TikTok exec: Chinese Communist Party had "God mode" entry to US data

    A former executive at TikTok’s parent company ByteDance has claimed in court documents that the Chinese Community Party (CCP) had access to TikTok data, despite the data being stored in the US.

    A former executive at TikTok’s parent company ByteDance has claimed in court documents that the Chinese Communist Party (CCP) had access to TikTok data, despite the data being stored in the US. The allegations were made in a wrongful dismissal lawsuit which was filed in May in the San Francisco Superior Court.

    4
    Security News @infosec.pub UselesslyBrisk @infosec.pub
    Paragon Solutions Spyware: Graphite - Schneier on Security

    Paragon Solutions is yet another Israeli spyware company. Their product is called “Graphite,” and is a lot like NSO Group’s Pegasus. And Paragon is working with what seems to be US approval :

    American approval, even if indirect, has been at the heart of Paragon’s strategy. The company sought a list of allied nations that the US wouldn’t object to seeing deploy Graphite. People with knowledge of the matter suggested 35 countries are on that list, though the exact nations involved could not be determined. Most were in the EU and some in Asia, the people said.

    Remember when NSO Group was banned in the US a year and a half ago? The Drug Enforcement Agency [uses] (https://www.nytimes.com/2022/12/08/us/politics/spyware-nso-pegasus-paragon.htm ) Graphite.

    We’re never going to reduce the power of these cyberweapons arms merchants by going after them one by one. We need to deal with the whole industry. And we’re not going to do it as long as the democracies of the world use their products as well.

    0
    10 years after Snowden's first leak, what have we learned?

    Also a good conversation here: https://news.ycombinator.com/item?id=36227166

    EDIT: Changed the link to an archive.org version.

    0
    Security News @infosec.pub UselesslyBrisk @infosec.pub
    Service Rents Email Addresses for Account Signups – Krebs on Security

    One of the most expensive aspects of any cybercriminal operation is the time and effort it takes to constantly create large numbers of new throwaway email accounts. Now a new service offers to help dramatically cut costs associated with large-scale spam and account creation campaigns, by paying people to sell their email account credentials and letting customers temporarily rent access to a vast pool of established accounts at major providers.

    Full details on link.

    0
    Security News @infosec.pub UselesslyBrisk @infosec.pub
    Chrome zero-day: “This exploit is in the wild”, so check your version now
    0
    InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)US
    UselesslyBrisk @infosec.pub
    Posts 10
    Comments 16