[-] towerful@programming.dev 15 points 6 months ago

And then some kid buys a used raspberry pi or wipes an old computer and circumvents it all anyway.

[-] towerful@programming.dev 14 points 1 year ago

Imagine the debuff that blueballs would inflict because you missed the quicktime event

[-] towerful@programming.dev 15 points 1 year ago

In his Truth Social website President Donald Trump described the Smithsonian as "OUT OF CONTROL" and said museums across the United States are "WOKE."

Convicted felon says museums are woke and out of control.

In a statement sent to Newsweek the Smithsonian said: "The Smithsonian's work is grounded in a deep commitment to scholarly excellence, rigorous research, and the accurate, factual presentation of history.

The world's largest museum, education and research complex says they are grounded in accurate presentation of history.

It's pretty clear that the US government is targeting the Smithsonian and other historical archives to rewrite history.

Considering the other articles linked which talk about the removal of trump's impeachments and other pressures on historical facts and accuracy, I'd be worried about the following quote:

"It's not about whitewashing it's about full context, so while slavery is obviously a horrible aspect of our nation's history you can't really talk about slavery honestly unless you also talk about hope and progress and I think we need to be focusing on the progress that we've made then and we need to stop focusing so much on the lack of progress.

So, yeh the Nazis killed a bunch of people. But they also developed the Volkswagen, Porsche and Hugo Boss. And we have all come to appreciate fancy cars and fly shirts. So, let's not focus on what the Nazis did, but instead let's concentrate on the hope that cars bring!

And even if you argue that "things are better now". Sure, somewhat. But, imo, it's not really something to celebrate. Black people can vote, but shitty racist people in power still suppress the fuck out of them.

Germany recognises it's history. It teaches it in school, it's made memorials & museums of historically abhorrent places, and it's outlawed everything related.

US still celebrates Thanksgiving.
https://www.forbes.com/sites/maiahoskin/2022/11/24/the-real-history-behind-thanksgiving/

So yeh, here is the directive:
https://www.whitehouse.gov/fact-sheets/2025/03/fact-sheet-president-donald-j-trump-restores-truth-and-sanity-to-american-history/

to work to eliminate improper, divisive, or anti-American ideology from the Smithsonian and its museums, education and research centers, and the National Zoo.

So, eliminate some history.
But - depending on how carefully that scalpel is wielded - it could cut away the bad parts and leave the "good" parts. Cherry picking, if you will.
Leaves a generally positive vibe of slavery.
Divisive and anti-american to whip/hang/rape slaves. So, leave that part out.
But provide the American dream for a slave by impregnating them and giving them a less crowded room and easier slave labour, or elevating them to a house position, or whatever... THATS the American dream!
Slaves that behaved were treated well.
But, just leave out the thousands of slaves that were beaten for sensless reasons because they were considered barbaric and sub-human.
Just... Ignore the fact that they were kidnapped from their home, transported for weeks in horrendous conditions, then auctioned off to rich white men.

[-] towerful@programming.dev 14 points 1 year ago

Windows 11 and OSX are so outdated

[-] towerful@programming.dev 15 points 1 year ago

The cupcake was a great touch.
Like, here is the dude that is evil. But he's also normal. He's had a good day/week as far as he is concerned, and as a celebration & reward: gets himself a fancy sweet treat.
It's not some data tablet, or star wars specific thing. It's a cupcake. And a super fancy one that comes in a nice box. It's really relatable.

[-] towerful@programming.dev 15 points 1 year ago

Nonononono, that was his LAST term.
He's already clarified that was moot when he fucked with the (art of the) trade deals he negotiated then.
If you are thinking in terms of terms (4 years) or years (1 year) you are daydreaming. Get your head out of your head! Get into the here & now. Grab the here by the now! Week on week? Weak eats weak. Day at a time, hour by hour, minute by minute, second by second, trade by trade

Threaten, bully, strong-arm. That's how you business. That's how you run a casino. That's how you win. The house always wins, so it's time to double down!
We aren't looking at yesteryear or even yesterday. It's not even about the forecasts of tomorrow.
It's about the here and now.
Markets are closed? Don't care.
Markets are shut down due to a selling circuit breaker? Don't care.
Markets are open? Why aren't we buying?

It's all about line goes up. And if it doesn't go up, it's about buying.
You see, winners buy the dip. Everyone should be buying right now. And the US tariffs that. Tariff the buy, so other people pay to make the line go up.
If the US is selling, the US is being swindled. So buy the dip.

(Idk what the fuck this is. Some drunken ramblings. I hope everyone is doing well, even if we are all being fucked over financially)

[-] towerful@programming.dev 15 points 2 years ago

Geocities animated gif style "under construction", no less

[-] towerful@programming.dev 15 points 2 years ago

I've never encountered lights that don't have UV filters in them.
There's no way to control the UV filter via DMX/Artnet/sACN. It's a fixed dichroic filter in front of the discharge lamp. It's an extremely cheap filter, as well, so I doubt it would be excluded from cheapo knock-off brand lights.
Certainly on any light available in the US and EU. It just won't get certified for sale.

Besides which, I haven't used a discharge lamp in years. It's all LED now, even the cheap stuff.

There is no way "set channel 4 to full" would disable any safety features in a moving light that would allow it to output damaging UV light. And the only other way it would hurt someone is if it was focussed on them, and they actively stared into it. Like, staring at the sun kind of level of staring at a light.

So, get rid of that "ordinary stage lights" pish.


This is absolutely a case of "we should get UV lights". And instead of getting safe UV cannons for fun florescent paints, they got UV disinfectant lights. Probably still makes florescent paints glow, but it's the wider band UV stuff designed to kill biological cells (ie disinfect). Which is exactly what it did to people's skin and retina.

[-] towerful@programming.dev 14 points 2 years ago

The server was now too full of data to do anything,

This reminds me of something that I always mean to do but totally forget to.
Allocate 1gb of space for a blank/dummy file on every VM I run.
When you run into a VM that locks up due to disk space, delete (or resize) the file, get to work fixing the VM, then put the empty file back

[-] towerful@programming.dev 15 points 3 years ago

Newsthump is a satire site.
I think this is a parody on The Onions classic "'No way to prevent this' says only country where this regularly happens" article they release after mass shootings in the US.

[-] towerful@programming.dev 14 points 3 years ago

What you are doing is exposing ports to the internet and advertising you home IP.
Which is fine, mostly.

A better way has been mentioned with cloudflare tunnels. This means your server connects out to cloudflares servers, instead of cloudflare forwarding to your IP.
It would then leverage all the protections that cloudflare offers (ddos protection, client filtering etc).
However, cloudflare then has access to everything that goes through it.
It's very secure, chances are cloudflare doesn't care about your traffic, and as long as everything is legal you will be fine.

If you don't want cloudflare knowing all of your servers served traffic, then you either need to run your own reverse-proxy-over-vpn style endpoint on a VPS (that you trust), or accept the additional risk of leaking your home network public IP.

If you accept the additional risk of leaking your home IP, then it's worth making sure your firewall/router is up to scratch.
Make sure it has active development (which is why most people use something like opnsense), and is always up to date (to ensure any vulnerabilities are patched).
Beyond that, the system is as secure as you want it to be. The more secure, the more maintenance and upkeep it needs.
There are many things you can do.

The easiest is to firewall on your devices. So the reverse proxy will only accept inbound from WAN, cannot establish its own connections to WAN, and whatever connections are required for forwarding to the pi.
And the pi would be firewalled to only allow incoming connections from the reverse proxy, cannot establish connections to wan, and whatever else is needed for it to function.
Where these rules are established is up to you. They could be on the router/firewall with each device on its own vlan (or pvlan if you are fancy). This is the most secure, but harder to implement.
Or they could be on the device itself, as long as the processes that are "doing the thing" cannot change the firewall rules (ie, don't run them as root or as a privileged user). Correctly configured, this is as secure as doing it on the router/firewall.

The idea here is to prevent any hacker moving sideways (ie from the device they own to another device).
If they own a device, then they can't do anything with it - even if they extract all keys, passwords and secrets from it.

Another interesting thing is to run an (outbound) proxy on your firewall. Force all outbound 80/443 through the proxy (via dnat rules), and have your servers trust the proxy's root CA.
What this means is that the firewall can then decrypt all outbound http connections, allowing for easy packet inspection.
If a server is downloading dodgy scripts, then hopefully your Deep Packet Inspection tool will catch them and shut it down.
You can do the same for DNS resolution (dnat redirect to a DNS resolving service), and whitelist only the DNS entries your services require.

Most basic attack would be easily caught it completely shut down by these kinds of things.

There is also crowdsec.
It can do a bunch of things.
It can run on things like opnsense, or the servers themselves.
It can then detect malicious traffic according to crowd sourced detection/metrics (which, I believe, you contribute to by using it) and block it.
But, honestly, might as well just use Cloudflare Tunnels.

Security is about layers.
What if someone manages to get Remote Code Execution on this service? How do I detect it? How to I prevent it? How do I limit it to that device?
And have regular offline backups. So if something gets hacked and bitlocked, you can wipe the server and restore from a backup (and practice this. No point having a backup strategy if it ends up not working when you need it).

But honestly? Do you need to expose this to the internet?
Would it be easier to run a VPN, so only trusted devices can connect to it in the first place? (Wireguard would be my recommendation here)

[-] towerful@programming.dev 14 points 3 years ago

Ctrl+backspace to delete previous word.
Ctrl+delete to delete next work.

view more: ‹ prev next ›

towerful

0 post score
0 comment score
joined 3 years ago