Skip Navigation
InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)HI
Posts
7
Comments
30
Joined
2 yr. ago
NixOS @infosec.pub
himazawa @infosec.pub

How is the situation of nix/nix-darwin/home-manager on macOS?

Used nix last year but dropped it after home-manager decided to unlink the apps from the Applications directory.

How is the current situation on usability of nix-Darwin + home-manager + brew?

Packages still fails to get indexed correctly in spotlight? I really like a fully repro environment but the fact that the usu ability was low bothered me a lot.

  • A raspberry with Adguard + unbound, a zimaboard with truenas scale running the -arr suite, nextcloud, homeassistan, homarr, headscale and caddy 2x2TB nvme and 3x 4tb HDD I recently got a new PC and I think I will convert it to being part of the homelab, it has a ryzen 7 3xxx and a 2070 super.

  • The difference is that you need way more interaction. Expose a webserver on the internet and check how many requests you get from just bots.

    You can control what you navigate and how to interact with the outside world, but you can’t control how the outside world will interact with your services.

  • ErgoMechKeyboards @lemmy.world
    himazawa @infosec.pub

    Low profile keyboard compatible with choc switches

    I am looking for a low profile keyboard compatible with the choc switches. I plan to put the choc sunset on it. I was looking for something similar to the Corne, just without the ergo-split thing. A standard 65-75% would work.

    Bonus for hot swappable and no soldering required.

  • WannaCry targeted hospitals, businesses and similar machines.

    WannaCry targeted everything with SMB exposed, blindly.

    Also, you should read more about security through obscurity, the fact that "no one will target you because you are a low-value target" is a false sense of security.

  • I believe the risk of running outdated software is super inflated and mediatic, 99% of people would be absolutely fine running a version of Android from 3 years ago or Windows 8.

    That's the same thing people running windows XP on internet were thinking in 2017.

    Then WannaCry arrived and they got their data encrypted :)

  • Perhaps images, video, font etc. rendering could be compromised?

    Yes, it already happen in the past. Also the Wi-Fi and Bluetooth stack got exploited, like multiple kernel drivers.

    But it shouldn't be a matter of "in the past was X exploited?" but more on having a correct security posture.

    Honestly if you are arguing about wasting a "perfectly working phone" you should blame it on the vendor, especially Android devices vendors have this let's say "defect" of dropping the support after 4/5 years.

    Also not going to talk about custom ROMs (with the super rare exclusion of some) managed by god knows who, without any security team behind.

    Since even the NFC and Cellular Network stack got vulnerabilities the only way you would consider an old phone "safe" to use is just turning it into the equivalent of a local ARM server.

    Also pretty fun seeing the replies in the original post talking about how Google Play store shouldn't have malware on it.

  • Ahaha I had this exact same experience. Locked out because bitwarden didn’t get the code correctly. “Luckily” the jwt token never expires so I was able to log back in without the 2FA.

  • Honestly curious, why? I live in a country that doesn’t have it but I don’t see downsides if the crimes committed are way too bad. For example, why keeping alive (with contributors money) a serial killer?

  • I wonder if people when talking about AI just ignore the fact that it’s software and has the same issues and vulnerabilities related to that.. recently I see a lot of posts talking about “AI security” and in the end are stuff known since 1995…

  • Exploit Development @infosec.pub
    himazawa @infosec.pub

    Manjaro 0day LPE via pamac

    ignore me @infosec.pub
    himazawa @infosec.pub

    This is a test from memmy

    Test

    Discussions related to Infosec.pub @infosec.pub
    himazawa @infosec.pub

    Set default language to English

    What about setting the new language of a post to English? There are people that don’t know how lemmy works that keep on opening new posts and leaving the language to “Undetermined” by mistake so no one can answer them.

    Research @infosec.pub
    himazawa @infosec.pub

    RowPress: Amplifying Read Disturbance in Modern DRAM Chips

    ignore me @infosec.pub
    himazawa @infosec.pub

    Lemmy doesn't like '