- 4 Posts
- 71 Comments
a_fancy_kiwi@lemmy.worldto World News@lemmy.world•Google is lobbying the Canadian senator who introduced a bill to restrict children’s ability to access sexually explicit material onlineEnglish22·3 months agoAgreed. They’ll erode everyone else’s right to privacy in order to “protect children”
Parents are free to restrict the content their children view. If the parents choose not to learn how to set up those restrictions, that’s on them.
a_fancy_kiwi@lemmy.worldto World News@lemmy.world•China Now Faces 245% Trump TariffEnglish131·3 months agoOur government is broken. First the House of Representatives have to vote to impeach a president. Then the senate has to vote to remove the president from office.
Trump was impeached by the, at the time, left leaning house of representatives in his first term but the right leaning senate didn’t vote to impeach him so he stayed in office.
At the moment, both the house and senate lean right so they aren’t likely to do anything. The supreme court also basically said the president is above the law so they aren’t likely to do anything either.
To go along with that, Telegram doesn’t make it easy to set up an encrypted chat. First, you have to set up a regular chat, then tap on the profile image of the person you are messaging, then tap the 3 dot menu, and finally tap “secret chat”. It’s there but they clearly don’t want people using it.
a_fancy_kiwi@lemmy.worldto Linux@lemmy.ml•Is there a downside to sticking to iptables over ufw?31·4 months agoIf you know iptables, just stick with that. In my testing, docker containers seem to ignore ufw rules. Supposedly, iptable rules are respected but I haven’t learned iptables yet so I can’t verify.
a_fancy_kiwi@lemmy.worldto Technology@lemmy.world•Microsoft is killing OneNote for Windows 10English3·4 months agoI don’t know what the fuck is going on. The client app connects to all 4 servers it needs a connection to. I can create a user on the server and all clients can login using it, I just can’t get notes to sync.
Official docs here
I found this tutorial1 and this tutorial2
Tutorial2 makes this one port change to the official docker compose file but otherwise is seemingly the same as tutorial1:
notesnook-s3: image: minio/minio:RELEASE.2024-07-29T22-14-52Z ports: - 9009:9000 - 9090:9090
With that change, and setting the port of the domain to 9090, I can access minio in the browser. But I don’t know if that’s necessary or not. I’m stumped.
a_fancy_kiwi@lemmy.worldto Technology@lemmy.world•Microsoft is killing OneNote for Windows 10English9·4 months agoDid you by chance self host the sync server using docker compose? Their instructions aren’t great and I was hoping you had some tips.
For anyone else interested, if I figure it out, I’ll post what I did here.
Edit 1: I finally got it all setup but syncing isn’t working so I guess I did something wrong 🙄 . Troubleshooting now
a_fancy_kiwi@lemmy.worldto News@lemmy.world•Judge orders Trump to reinstate probationary workers let go in mass firings across multiple agencies91·4 months agoThe downward trend on the stock market is still in place 🤷♂️
a_fancy_kiwi@lemmy.worldOPto Selfhosted@lemmy.world•How do you all handle security and monitoring for your publicly accessible services?English4·5 months agohas some basic monitoring on them.
What monitoring software are you using?
I feel like the other measures you talked about (backups, condom of network traffic, etc) I’m doing ok on. Its really just the monitoring where I’m stuck. There’s so many options
a_fancy_kiwi@lemmy.worldOPto Selfhosted@lemmy.world•How do you all handle security and monitoring for your publicly accessible services?English2·5 months agoI’ll look into it, thank you
a_fancy_kiwi@lemmy.worldOPto Selfhosted@lemmy.world•How do you all handle security and monitoring for your publicly accessible services?English1·5 months agoI’ve seen a bunch of people recommend Authelia. Do you mind if I ask why you went with it over other software? I only went with authentik because I found a tutorial on it first
a_fancy_kiwi@lemmy.worldOPto Selfhosted@lemmy.world•How do you all handle security and monitoring for your publicly accessible services?English4·5 months ago-
check
-
check
-
check
-
I saw someone else recommend crowdsec. I’ll look into it, thanks
if you use one of those 5$/month VPSes, with a VPN tunnel to your backend services, that adds one layer of “if it’s compromised, they’re not in your house”.
I’ve heard this mentioned before but I don’t really understand how this works in practice. If the VPS was compromised, couldn’t they use the VPN to then connect to my home?
-
a_fancy_kiwi@lemmy.worldOPto Selfhosted@lemmy.world•How do you all handle security and monitoring for your publicly accessible services?English1·5 months agoCaddy only allows private IP ranges
Do you mind telling me more about this? How does that work; a VPN?
a_fancy_kiwi@lemmy.worldOPto Selfhosted@lemmy.world•How do you all handle security and monitoring for your publicly accessible services?English3·5 months agowill do, thanks
a_fancy_kiwi@lemmy.worldOPto Selfhosted@lemmy.world•How do you all handle security and monitoring for your publicly accessible services?English5·5 months agoIf it were only me using the apps, I’d be using a VPN. Over the years, I’ve used OpenVPN, Wireguard, and now Tailscale. In my experience, they work like 99% of the time. That last 1% though is weird connection issues; usually when switching between WiFi and cellular (or vice versa) but sometimes it’s my server or ISP and I have to turn the VPN off and back on to troubleshoot. During those rare times, my partner will either turn off the VPN and forget to turn it back on or they will forget about the VPN completely and not be able to use their phone. Ideally, I’d like to set something up that doesn’t require any potential troubleshooting on their part so I can avoid hearing “why can’t we just use Google photos?” or “what’s wrong with Google home?” 😓
a_fancy_kiwi@lemmy.worldOPto Selfhosted@lemmy.world•How do you all handle security and monitoring for your publicly accessible services?English2·5 months agothat’s awesome. thanks!
a_fancy_kiwi@lemmy.worldOPto Selfhosted@lemmy.world•How do you all handle security and monitoring for your publicly accessible services?English2·5 months agooh, my mistake. tbh, I don’t know enough about it but I’m interested. Why set up a TLS cert for AI at home? How is that benefiting you and your setup?
I’ve seen some people set up SSL certs for self hosted services and not make them publicly available but I didn’t get around to seeing why they were doing it
a_fancy_kiwi@lemmy.worldOPto Selfhosted@lemmy.world•How do you all handle security and monitoring for your publicly accessible services?English3·5 months agoHave also set it up so they get banned on Cloudflare’s side, so before another malicious request ever reaches me.
How did you end up setting that up?
a_fancy_kiwi@lemmy.worldOPto Selfhosted@lemmy.world•How do you all handle security and monitoring for your publicly accessible services?English24·5 months agoI feel weird about having those apps on the internet and basically being blind to threats. I mean yeah, I’m not a target on anyone’s list and most IPs visiting the site are bots but I would still like to know what’s going on.
I don’t work in tech for a living, this is just a hobby for me so I have limited time to work on this stuff and do research. It’s very possible I fucked something up and don’t know it. I figured if I at least got an alert that said “hey, your immich server db was dumped and sent to <insert IP>”, I could at least turn it off
Have you seen the price of McDonalds recently? I’d rather miss a meal than get scammed like that. Fuck them.