dan

joined 3 years ago
[–] dan@upvote.au 7 points 4 days ago

Caddy is a good piece of software.

I've been using Nginx for 20 years and don't really have a reason to switch, so I'm still using it. I use certbot, so it's just one command to create the certificate initially, and then it auto-renews automatically via a systemd timer.

[–] dan@upvote.au 7 points 4 days ago* (last edited 4 days ago)

A private key leaking is bad, since anyone with the private key can decrypt data that was encrypted with it.

Traditionally, the way that leaked certs were handled was via Certificate Revocation Lists (CRL). CRLs contain lists of revoked certificates - their serial number, revocation date, and the reason why they were revoked.

However, CRLs are imperfect. Checking for revoked certificates every time you go to a site would slow things down a lot, as the lists are now too large to check and download real-time. Modern browsers and other TLS clients periodically download the lists in the background. Also, it might take a while between when the certificate is compromised and when the company notices the compromise.

Because of this, the CA/Browser forum (a group with all the major browser and TLS certificate vendors) have started dropping the max lifetime of certificates. The idea is that even if a private key does leak, the time frame that it's usable for will be significantly shorter and any leaks should (in theory) cause less damage.

  • The original maximum duration was 39 months: Three years plus an extra three months leeway for obtaining and deploying new certificates.
  • March 2018: Reduced to 825 days
  • September 2020: Reduced to 398 days
  • March 2026: Reduced to 200 days
  • March 2027: Planned to reduce to 100 days
  • March 2028: Planned to reduce to 47 days

All modern deployments, regardless of if they're using free or paid certs, should have their renewals fully-automated, so in theory the validity period shouldn't matter as much as it did in the past. All major vendors (Let's Encrypt, DigiCert, Sectigo, GlobalSign, AWS, SSL .com, etc) support ACME now. Reducing the validity is also a forcing function t o ensure automation is actually implemented.

somehow else in the middle and just can “ignore” certs renewals?

I'm not sure that's possible, since an attacker in the middle shouldn't be able to obtain a valid certificate for the domain. Certificates have a "not valid after" date encoded into them, after which the certificate is considered invalid and you get an error.

[–] dan@upvote.au 3 points 4 days ago

biometric, personal, behavioral and health data

What data are self checkouts collecting that regular checkouts aren't?

[–] dan@upvote.au 8 points 4 days ago (2 children)

Shhhhh don't give them any ideas

[–] dan@upvote.au 6 points 5 days ago

The Debian version of Mint. :D

Most Linux distros have live DVDs that let you try it out without installing it... Try a few of the major distros and see what you like best? You could also install a few and dual-boot (multi-boot I guess?)

[–] dan@upvote.au 10 points 5 days ago* (last edited 5 days ago) (3 children)

causing instability and tons of graphical glitches especially in video playback

Flashbacks to me struggling to get the fglrx drivers working.

If you never got to experience the "joy" of that... There was a time long ago when getting graphics acceleration working with ATI/AMD GPUs on Linux needed proprietary drivers. It was a struggle, significantly worse than dealing with the Nvidia drivers today. Things improved so much when AMD released and upstreamed their modern open-source driver, around 10 years ago now.

[–] dan@upvote.au 8 points 5 days ago* (last edited 5 days ago) (3 children)

Why not a co-op instead? Owned by members rather than a corporation/shareholders.

On the other hand, if government subsidisation works well for medication (with the PBS) and university (with CSP places), maybe it'd work well for other necessities like food too.

[–] dan@upvote.au 4 points 6 days ago* (last edited 6 days ago) (3 children)

Please pay attention to: Each news server talks to one or more other servers (its "newsfeeds") and exchanges articles with them.

hmmm... it sounds like p2p.

This is describing federation and decentralization, not P2P. The servers communicate with each other. P2P is when users communicate directly.

Would you consider Lemmy or email as P2P? They're also federated and decentralized.

It's not p2p for the enduser, but that's why i said it was server p2p.

Your definition of "server P2P" doesn't really make sense. Any CDN would fit this definition for example, because CDN edge servers fill data from origin servers when it's not cached locally, and a lot of that data would be user-uploaded, but I'm not sure anyone would describe Akamai, Fastly, or Cloudflare as P2P.

Usenet has companies running the servers, and you download from and upload to the company's servers. Nobody would reasonably describe that as P2P, regardless of how the servers are implemented.

[–] dan@upvote.au 4 points 6 days ago (5 children)

That's not what P2P means though. With Usenet, the articles are stored on a server, and you download them from the server. P2P always means one peer directly connects to another. The reason P2P systems exist is that they avoid things like takedowns (since you'd need to take down every user instead of a central server), and Usenet doesn't have that advantage.

If Usenet is P2P, then every other system that lets people upload files is P2P, including things like Rapidshare, Google Drive, forums, etc. That wouldn't make sense.

[–] dan@upvote.au 4 points 1 week ago* (last edited 1 week ago)

In older versions of Soulseek, you had to have two consecutive port numbers (eg. 20000 and 20001, or 12345 and 12346, etc). AirVPN was the only VPN that let you pick the port numbers, so you could guarantee getting two consecutive ports.

I don't think modern Soulseek clients require that any more (slskd only requires one port as far as I can tell) so it's not important any more, but AirVPN is still the most recommended by Soulseek users.

Private Internet Access only give you a single forwarded port, so you couldn't use it for both torrents and Soulseek at the same time (for example). AirVPN used to provide 20, but I think they reduced it to 5 for new accounts.

AirVPN's forwarded ports are also not server-specific; you get your chosen ports regardless of which server you use.

[–] dan@upvote.au 3 points 1 week ago

Thanks! This is what I was thinking of, but ironically I couldn't find the links/articles lol

[–] dan@upvote.au 49 points 1 week ago (5 children)

If I remember correctly, around 5 or 6 years ago, Google Search leadership changed such that the ads org started running it. The focus since then has been on advertisers rather than regular users.

This is literally the definition of enshittification: the company first focuses on gaining users, then switches the focus to business customers, then squeezes both of them.

view more: ‹ prev next ›