• 1 Post
  • 78 Comments
Joined 1 year ago
cake
Cake day: June 18th, 2023

help-circle
  • I self-hosted it few months ago, and it’s actually surprisingly easy! Someone has made an Ansible script for Matrix with Element and some bridges, that (at least a month ago, IaaC tends to be pretty fragile) worked out of the box on a first try. I just set up some config values (mostly about enabling bridges I want) based on their amazing documentation, and then ran it once and everything is working so far. I even updated it several times already, and every time it was smooth, and it was basically just running a single ansible command. Their documentation is pretty well written, and with my basic cloud, IT and Linux knowledge I had no issues with following it. All you need to know is how to set up cloud VM, get a domain and set DNS, and set up SSH keys to access the server.

    In total it took me about two hours in total, from when I decided “I’m setting up Matrix tonight” without any prior knowledge, looking up my options and finding the ansible script, setting up cloud and getting Matrix up and running.

    I’m renting a VM on Hetzner for like 6$ per month, and it worked without issues so far. I use it for Discord and Messenger, although the Meta bridge does have some problems, for example I didn’t figure out how to message someone with whom I haven’t had a conversation since I set up the bridge, since only then it creates the room for it. But that can be solved by keeping the Messenger app or usign the browser to send a first message, and it immediately shows in your Matrix bridge (and stays there forever).


  • Ever since I played watchdogs and shadowrun, I wanted to work in cybersecurity, especially as a Red Teamer, which is literally Shadowrun - you run complex ops that have to break in, and steal stuff from largre banks without anyone but the management knowing about the test, with almost nothing being off-limits, as long as it doesn’t cause some kind of damage.

    Five years later, I do work as a Red Team Lead. Hpwever, our company was just scrambling to start doing RT since thats the buzzword now, and while we did have amazing pentesters, unfortunately pentesting and Red Teaming requires vastly different skills. Ypu never need to avoid EDRs, write malware with obscure low-level winapi, or even know what kind of IoC ajd detections will a command you run create, when you are doing a pentest.

    But since no one knew better, and I love learning and researching new stuff, while also having Red Teaming romabticized, my interrest in it eventually led to me getting a Lead position for the barely scrambling team.

    Mind you, I was barely out of being a junipr, with only three years of part time pentesting experience. It was NOT a good idea.

    I quickly found out that RT is waaay harder and requires the best of the best from cybersec and maleare development. We didnt have that. Also, turns out that I love to learn now stuff and take on a challenge, but being a Lead also means you are drowning in paperwork and discussions with client, while also everyone from the team doesn’t know what to do and turns to me about what should we do. Which I didn’t know, and barely managed to keep learning it on my own. Our conpany didnt want to give us much time for learning outside of delivery, I was only working parttime, and I was slowly realizing that we don’t have almost any of the skills we need.

    We were doing kind of a good job, most of our engagement turned out pretty well, but it was atrocious.

    Turns out, I’m not good at managing and planning projects, or leading people. I’m better just as a line member.



  • For anyone considering the game, there’s a relevant quote from the developer in one of their blog posts, that I think could help them decide whether it’s a game for them or not:

    Although Pal World is a very interesting game, I would like to add one point: it is not at all suitable for players who prefer single-player games and want to enjoy the story, so please be aware of that. There’s almost no story, so those people won’t enjoy it. Fans of survival craft genres such as Minecraft and Valheim will enjoy this game.


  • Ooh, you are right, I can actually file bug reports or try to fix it myself now that I switched to FOSS from Windows. Tbh that didn’t really occur to me, since I was switching only like a month ago. I’ll look into it, so far I suspect that it’s actually covered by one of those troubleshooting cases mentioned in their FAQ, and I’m not really confident enough to start recompiling libraries with additional flags. Especially since I’m on Nobara and don’t want to break anything, AFAIK that OS is pretty customised from the start and figuring out what I can safely touch isn’t something I have the guts for yet.


  • I was using LibreWolf before, but I really like the idea of bundling VPN + Browser, and also the way they handle payments - not only is Mullvad VPN kind of cheap, I can just pay with crypto and don’t need any account (kind of - you just generate username that also serves as an password, without any other contact information required).

    But what I like the most about it is the idea of making a browser with the goal of having the same fingerprint between users (as much as possible), and offering it with a VPN - becuase that means that most of other users of the VPN will probably also have the same fingerprint from the browser, so you will blend in with them. I wasn’t really sold on the idea of VPN before that and didn’t use one, but this was what convinced me.

    But tbh I haven’t done much research into the company, or into the effectivness of their implementation. I’m kind of betting on their cooperation with Tor Browser, which should have most of this stuff already figured out. But it’s possible that other browsers are just better at it, I never checked.

    I do however still use LibreWolf for the occasional site that breaks with Mullvad, but it’s not something that happens too often.

    I use(d) the VPN alongside it and found the add-on “hints” regarding the correct DNS settings more frustrating than helpful, too.

    Hmm, I don’t think I’ve ever noticed anything about DNS. I think I’ve actually never click on the browser vpn extension, though :D Is it the encrypted DNS hint?

    EDIT: Found this, apparently it’s doing pretty well https://privacytests.org/




  • But then you are risking an actual reprecussion for your actions, and would have to deal with consequences of several really pissed of corporations with a recipe about how much money did your actions costed them in damages, that would be pretty hard to wriggle yourself out of.

    Which is exactly why (proper) protesting isn’t easy to do in the slightest, and you have to really believe in the cause to resort to such things. And that is how it should be. It’s also why you only end up with with random people blocking inconsequantial roads or ruining glass-protected paintings. Because they want attention, they want to feel good that they’re doing something, and protesting is the edgy thing to do that nobody understands. But at the end of the day, they want to go back to their instagram so they can post about it, instead of dealing with the consequences.

    If you resort to such a drastic action, and protesting definitely is a drastic action, at least the kind the post is talking about, you should sacrifice something other than your free time and a pocket change in fees, otherwise it has no value. That’s why demonstrations held at a weekend or holidays feel so cheap, if you aren’t even willing to take your time off for it, whats the point?

    I wouldn’t for most of them. So I don’t attend. But all these “feel-good” demonstrations and protests are only succeeding in undermining the grave nature of protests and demonstrations, to the point where no-one really needs to take them seriously.


  • Unfortunately, NVIDIA. I was buying a new PC half a year ago, and only started even considering to make the switch to Linux few months after that, so I am at a pretty unlucky point where I just had recently spent a lot of money for new-gen PC, but without knowing that I should really go for AMD.

    I will make the switch to AMD as soon as it’s justifiable, but I’m too lazy to deal with second-hand resale and it’s hard to justify a new GPU when I still have the current gen, but from wrong manufacturer.



  • I haven’t really looked into it too much, but… Aren’t they actually right in this case?

    Sure, reading “we can’t protect your privacy because you’re using privacy-centric extension…” feels like bullshit, but from how I understand it based on the screenshot, the issue is that you have blocked the cookie permissions pop-up, whose main reason is to give you an option to opt-out of any tracking cookies, thus protecting your privacy. While also being required by law.

    However, this depends on how exactly is the law formulated. How does it deals with a case where you don’t accept, nor decline any cookies, and just ignore it? Are they not allowed to save any cookie until you accept it and specify what exactly can they save? Or should they not let you use the site until you accept it?

    I vaguely remember that it used to be enough to just have a OK-able warning that this site is using cookies, but then it changed to include a choice to opt-out. Which could indicate that unless you opt-out, which they are required to give you a chance to, they can use whatever tracking cookies they want. And if that is the case, this message is actually correct.


  • I’m actually glad for it. It made me switch to Linux, discover Mullvad Browser and their VPN combo, get a GrapheneOS phone, find an amazing Freetube YT desktop client, and dabble with Home Assistant and PIHole. Plus I migrated to Protonmail and Kagi as my search, and Lemmy instead of reddit is also an amazing change, the discussions I’ve seen so far feel better and more in depth, and I’m enjoying my time here so far. The lack of endless content is also great, to help with implementing Digital Minimalism.

    So, while I hate any large corporation and their greed with more and more passion, it has lead me to a nice privacy journey, for which I’m glad.



  • I’ve just blocked YT in my browser, and use https://freetubeapp.io/ instead. It’s a desktop app, so I don’t have to deal with cookies and storage being deleted after every session, just as i can do subscriptions to channels without requiring an account.

    So far, it has been an amazing experience, I totally recommend it. And I second the point about Nano AdBlcoker, since I’ve also been one of the victims, since at the time Nano Defender was one of the alternatives pretty well recommended on Reddit, that was better at avoiding anti-adblock scripts. Plus, any extension you have only makes you easier to fingerprint, thus defeating the point of VPN or privacy focused browser. Especially with Mullvad browser + VPN, which is especially build on the idea of sharing the exact same fingerprint with every other Mullvad VPN user.


  • You are right I shouldn’t have equaled bitcoin with the rest of the crypto ecosystem. While most crypto is utter scam, it’s true that there have been some slight advances here and there, and there are coins that may be actually useful for some cases, mostly Monero and I suppose Ethereum. I’d still say that crypto has done more harm than good in the world, and I say that as someone who’s really focused at privacy, care about it a lot and have invested significant amount of time and effort into staying as private as possible.

    But it’s great that Ethereum managed to solve most of the issues with Bitcoin - unless I’m mistaken, it’s not really used for investment speculation, and if it managed to keep the energy requirements low, that’s good. But last time I remember researching about blockchain (it was few months, so feel free to correct me), isn’t it running into serious issues with ledger size, that makes it infeasible for long-term (decades) of use, without sacrificing some of it’s guarantees? Which is one of the main issues with blockchain tech in general, that I don’t think has been solved so far.





  • After several of my favorite songs disappeared from Spotify, I’ve adopted a different approach to music.

    If I see on on a band show merch stand, I buy a cassette. It’s more of a novelty item and a way to slightly support the band. While I do have a portable tape player, I only rarely take it out. I switched from LPs to tapes because of the costs and huge effort associated with playing or storing them (that is, if you do it right are are not OK with fucking up your LPs), but tapes are cool and don’t have that many storage or playing problems.

    Other than that, I’ve stopped paying for any kind of streaming services, and save the 10$ per month to just buy one or two (new or old) albums from my favourite artists on Bandcamp, that I’ve spend the last month listening to the most. The albums I buy I add to my NAS library, which usually replaces stolen copies of said albums that I’ve previously got from Redacted.

    This allows me to keep a pretty expansive library, by just stealing what I need, but with a promise that I’ll eventually buy the album (using the money I saved on streaming services), if it’s something that I’ve listened to extensively. I’m also not at mercy of streaming services, that can take away my music whenever they decide to.

    So far I’ve been doing this for a few years, and even increased my budget for just buying albums if I can’t immediately find them on Redacted.