• 19 Posts
  • 748 Comments
Joined 2 years ago
cake
Cake day: March 19th, 2024

help-circle


  • communism@lemmy.mltoTechnology@lemmy.worldBitwarden 100% price increase
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    1
    ·
    2 days ago

    I’ve had my VPS exposed to the internet for a while and never been pwned. No professional experience. Use SSH keys, not password authentication. Use FDE if physical access is in your threat model. Use a firewall to prevent connection on internal-only ports.

    Vaultwarden will store your passwords encrypted (obviously) so even if your database does get stolen, the attacker shouldn’t be able to read your passwords without your master password.


  • It’s great. I also self-host my own Forgejo (that’s the software Codeberg runs on) instance for private repos, to avoid using up space on Codeberg’s servers.

    Main problem is the lack of federation, leading to splintering across Codeberg/GitLab/sourcehut/self-hosted forges. I know there’s Radicle, and Forgejo is working on ActivityPub integration, but it’s slow-moving to get what should be inherently federated by design (git) to actually be federated. In practice you need accounts on a dozen different websites if you want to regularly contribute to foss.






  • Signal is fine for normal/social chatting. It is centralised which makes it much harder to obscure identifying conversation metadata, and I wouldn’t recommend it for comms with a state threat model. I like SimpleX for addressing those issues.

    If you just want to chat to friends and nothing else, I probably would recommend Signal for the most polished experience and most widely adopted open-source private messenger.






  • The point schnurrito was making is that even if you know what an IP address is and what are valid or invalid IP addresses, a lot of people won’t read the IP address. They’ll just see numbers and skim over them. Even if you’re keeping eyes peeled for scams, most people don’t have their IP address memorised off the top of their heads so they wouldn’t be looking to check if the IP address looks right or not.




  • Most people who build software from source do it for reasons other than trust. Could be for fun (I imagine the main reason why people do Linux From Scratch), could be for the same reason that compels some people to use Gentoo lol. OP didn’t say what their motivation was.

    edit: nvm, in other comments OP has said they’re concerned about an xz style of backdoor. In any case, I would still be interested to read about someone trying what OP is suggesting.



  • My favourite unusual one is sichuan pepper powder on garlic bread. Originated in me rummaging through my spices for stuff to add to my garlic bread and I really liked this. I now add it to garlic bread, pizzas, that sort of thing.

    Cumin is also a great all purpose spice I put on many things. Cumin+turmeric for curry-flavoured things, but also cumin+salt+pepper+rosemary+garlic granules for anything roasted.