8 Followers
216 Following
150 Posts

Opinion | Israel Can’t Imprison 2 Million Gazans Without Paying a Cruel Price

https://lemm.ee/post/10915513

Opinion | Israel Can’t Imprison 2 Million Gazans Without Paying a Cruel Price - lemm.ee

Full article: https://imgur.com/a/cYGW7XT [https://imgur.com/a/cYGW7XT]

I would switch to certificate based SSH authentication.

All the server keys gets signed by your CA, all clients also gets signed by your CA. Everyone implicitly trust eachother though the CA and it’s as safe as regular SSH keys.

You can also sign short lived client keys if you want to make revocations easier, the servers don’t care because now all it cares is that it’s a valid cert issues by the CA, which can be done entirely offline!

HashiCorp Vault can also help managing the above, but it’s also pretty easy to do manually.

Docker & Databases. Stack or Individual?

So I'm in the process of (re-) setting up my homelab and unsure about how to handle databases. Many images require a database, which the docker-compose usually provides inside the stack....

https://kbin.social/m/selfhosted@lemmy.world/t/226658

Docker & Databases. Stack or Individual? - selfhosted - kbin.social

So I'm in the process of (re-) setting up my homelab and unsure about how to handle databases. Many images require a database, which the docker-compose usually provides inside the stack....

Your ISP is doing it wrong, which I guess you already know. I get a /64 net via DHCPv6 for my LAN which is pretty standard.

+1 to dual stack. Too much of the internet is v4 only, missing AAAA, or various other issues. I’ve also had weird issues where a Google/Nest speaker device would fail 50% of the time and other streaming devices act slow/funky. Now I know that means the V6 net is busted and usually I have to manually release/renew. Happens once every few months, but not in a predictable interval.

Security is different, but not worse IMO. It’s just a firewall and router instead of a NAT being added in. A misconfigured firewall or enabling UPnP is still a bad idea with potentially worse consequences.

Privacy OTOH is worse. It used to be that each device included a hardware MAC as part of a statelessly generated address. They fixed that on most devices. Still, each device in your house may end up with a long lived (at least as long as your WAN lease time) unique IP that is exposed to whatever sites you visit. So instead of a unique IP per household with IPv4 and NAT, it’s per network device. Tracking sites can differentiate multiple devices in the house across sites.

This has me thinking I need to investigate more on how often my device IPv6 (or WAN lease subnet) addresses change.

RFC 7217: A Method for Generating Semantically Opaque Interface Identifiers with IPv6 Stateless Address Autoconfiguration (SLAAC)

This document specifies a method for generating IPv6 Interface Identifiers to be used with IPv6 Stateless Address Autoconfiguration (SLAAC), such that an IPv6 address configured using this method is stable within each subnet, but the corresponding Interface Identifier changes when the host moves from one network to another. This method is meant to be an alternative to generating Interface Identifiers based on hardware addresses (e.g., IEEE LAN Media Access Control (MAC) addresses), such that the benefits of stable addresses can be achieved without sacrificing the security and privacy of users. The method specified in this document applies to all prefixes a host may be employing, including link-local, global, and unique-local prefixes (and their corresponding addresses).

IETF Datatracker

Most underrated/unknown service you are hosting?

What is the service you are hosting, which in your opinion is underrated?... #selfhosted

https://kbin.social/m/selfhosted/t/192178

Most underrated/unknown service you are hosting? - Selfhosting with friends - kbin.social

What is the service you are hosting, which in your opinion is underrated?...

ELI5 Cloudflare Tunnel

So everyone is talking about cloudflare tunnels and I decided to give it a shot....

https://kbin.social/m/selfhosted@lemmy.world/t/186339

ELI5 Cloudflare Tunnel - selfhosted - kbin.social

So everyone is talking about cloudflare tunnels and I decided to give it a shot....

Flatpak Vs Snap vs Native Packages

So I know my way around Linux pretty well. However I never really got the gist of the difference between Snap, Flatpak and Native packages....

https://kbin.social/m/[email protected]/t/177834

Flatpak Vs Snap vs Native Packages - linux - kbin.social

So I know my way around Linux pretty well. However I never really got the gist of the difference between Snap, Flatpak and Native packages....

Redoing homelab and need your insights

I recently upgraded my TrueNAS server to a Synology. While TN has served me well, I don’t have the time anymore to administer it.... #homelab #selfhosted

https://kbin.social/m/selfhosted/t/161052

Redoing homelab and need your insights - Selfhosting with friends - kbin.social

I recently upgraded my TrueNAS server to a Synology. While TN has served me well, I don’t have the time anymore to administer it....

Do they still put murderous dictator's heads on spikes? Asking because I know a short dictator who is responsible for a lot of innocent people's deaths.

Showing off some of the themes for Artemis (coming soon)

Dark or light. #iOS or #Android. You’ll get theming options to personalize your #Threadiverse experience with #ArtemisApp! Shout out to our designer @lvndr! #ArtemisApp

https://tech.lgbt/@hariette/110641017887610411

🖤🇵🇷 Hariette 🌺🖤:verified: (@[email protected])

Attached: 4 images Dark or light. #iOS or #Android. You’ll get theming options to personalize your #Threadiverse experience with #ArtemisApp! Shout out to our designer @[email protected]! #ComingSoon #kbin #lemmy

LGBTQIA+ Tech Mastodon