Mikina

joined 1 year ago
[–] Mikina@programming.dev 10 points 3 months ago

A good reminder to always set your password manager to auto-lock (with PIN for convenience) after 3-5 minutes. The PIN makes it easy to re-log, while not being bruteforceable (AFAIK after few failed attempts it reverts to password), and if someone would get to your PC, either physically or remotely, they won't be able to get all your passwords.

One of the best jackpots I've ever found during Red Teaming engagements was when I RDPd to a server through pass-the-hash, only to find an unlocked password manager with passwords for most of the other servers, service and admin accounts.

[–] Mikina@programming.dev 2 points 3 months ago

You are right, calling it a contradiction was not exactly accurate. Or rather - it did contradict some of the narrative that is pushed by Delta, about CS not providing any support in the first few days, which it sounds like isn't exactly true. But most of the case will indeed still need more receipts, that's true.

[–] Mikina@programming.dev 3 points 3 months ago* (last edited 3 months ago) (3 children)

A Delta spokesperson said the airline "will decline to comment further." ®

Huh, did they really register that sentence? :D

Also, the CS response to the accusations should have been at the beginning, not near the end of the article, because it does provide some pretty important context, including links to LinkedIn posts from Delta board members that directly contradict most of the article:

When asked about this August 8 letter from Delta, a CrowdStrike spokesperson told The Register:

Delta continues to push a misleading narrative. CrowdStrike CEO George Kurtz called Delta board member David DeWalt within four hours of the incident on July 19th. CrowdStrike's Chief Security Officer was in direct contact with Delta's CISO within hours of the incident, providing information and offering support.

CrowdStrike's and Delta's teams worked closely together within hours of the incident, with CrowdStrike providing technical support beyond what was available on the website.

This level of customer support led Delta board member David DeWalt to publicly state on LinkedIn: "George and his team have done an incredible job, working through the night in difficult circumstances to deliver a fix. It is a huge credit to the Crowdstrike team and their leadership that many woke up to a fix already available."

I'm all for CS having consequences for what happened, but Delta so obviously lying here with literal Linkedin posts from their board members that directly contradict what they are claiming, that's just scummy.

[–] Mikina@programming.dev 2 points 3 months ago

I've been mostly using Mullvad, and so far it worked pretty well out of the box. Few sites break, and for that I have LibreWolf, but other than that, I'm enjoying Mullvad more.

[–] Mikina@programming.dev 1 points 3 months ago

One thing I forgot to mention - last time I recommended cloudflared, I was told that the TOS for cloudflared forbid use for high-volume streaming of data, such as movie/audio streaming, or sharing of large files for download.

I never had an issue with it, but I didn't use it for streaming, only to share/download a small to medium sized file once per few weeks. I suppose that if you were to publicly post a link to a few Gb large file, and had hundreds of people download it through the cloudflared, they may take an issue with it. Maybe even if you were regurally watching streamed movies from your server through it. So just a heads up, make sure to check the ToS first.

[–] Mikina@programming.dev 12 points 3 months ago (4 children)

I'm using GrapheneOS, and suprising amount of apps (including my bank app) works without Google Services. And if there's something I need for work that doesn't work without them, I have another profile with sandboxed Google play (which isn't enabled on my main profile), and use the app there, where it's separated from all of my data. No need to root my phone, and so far it worked great.

As for sharing your Nextcloud stuff, what I did was for services that need to be public, I just got a cheap (like, few dollars per year) domain and use Cloudflare Tunnel (Cloudflared). It handles all port forwarding for you, and you don't have to make anything public on your router - just install cloudflared on the server and have it forward the port you want to your domain. You can also set up geoblocking and ACL pretty easily, so it's perfect for that.

I've however recently moved to using ZeroTier, because it has a nice mobile VPN app, so I just run zerotier (it's literally two commands to install and join a network) on my server, and if I need to access something there I just launch it on my phone and connect through ZeroTier. This, however, won't help if you want to share stuff from your server with others, since they'd have to install a ZeroTier client and also join your network. For Jellyfin, Nextcloud and Sunshine, though, it's amazing.

And if that still feels like too much hassle for you, I'd recommend looking into Proton Drive. I'd consider that one of the best hassle-free alternatives to GDrive, which launched recently.

[–] Mikina@programming.dev 1 points 3 months ago

I see. So, you having shares basically means you own part of the company assets, and if it were to for example shut down or get into huge trouble (so no one sensible would want to buy their shares), you'll still get kind of compensated from the value of their remaining assets being sold? That kind of makes sense, and is the difference I was looking for.

It's still weird, but a little bit more understandable than crypto, which is only literally stealing and scamming money from others (who will eventually in the end end up left with all the literally valueless crypto, and whose money basically paid for all your profit from it)

[–] Mikina@programming.dev 5 points 3 months ago

What exactly would the collapse cause? Article mention polar ice creeping up to northern England, and temperatures dropping. Would it mean that you'd basically get ice age in half of Europe? How I understand it, you'd gat extreme cold in the north, and extreme (not survivable) hot around the equinox. So, mass migration from both into the central eruope, where the weather would be extreme hot but survivable in summer, and super cold in winter? More storms, typhoons, and in general a really bad time, due to drought and crops gerting fucked?

[–] Mikina@programming.dev 4 points 3 months ago (8 children)

I see, stonks are way more bullshit than I thought. Is there anything else you can do with your stock, other than sell it to someone else? I always thought that crypto is such a scam especially because in the end, it has no value in itself, and the only thing you can do with it is sell it to someone else. If noone wants to buy it, well, you are fucked. Does it mean that stocks are exactly the same concept? I always thought it has something to do with the vaule of the company and the profits it earns, but if there is no way how to cash them out other than selling your piece of paper to someone, then it's really the same? I suppose that unlike crypto, the stock price increases if the company is turning profit, but you still have to find someone to sell it to, right, so the price is increasing only because the demand from people willing to buy it is increasing due to it turning profit, but it's not really tied to the actual value of the company, so it's exactly like crypto? Or is the price set by some different mechanism than crypto is - pure demand from people willing to buy?

[–] Mikina@programming.dev 1 points 3 months ago (1 children)

I was just about to update my Nobara after some time, thanks for the heads up. It's a shame, I really loke Nobara and I switched to it because I couldn't get lot of game related stuff working properly on Fedora and I'd like to stick to Fedora-based distros since I'm used the most to that. I guess PopOS would be my next choice if I couldn't get something working, Mint after that.

[–] Mikina@programming.dev 15 points 3 months ago (17 children)

I've always thought that stocks have to pay dividents, like that's the whole point of having it? I.e you get paid by the company regularly some of their profit, based on how much stock you have.

Does this mean that the only way how to make money from their stock now is to sell them to someone else? But then, it has nothing to do with the actual company and money they make, but you are paid by someone totally unrelated - the guy who buys the stock from you. I don't get it, I suppose I'm missing something.

[–] Mikina@programming.dev 2 points 3 months ago (3 children)

I vaguely remember seeing something about this in Nobara news, does anyone knows if Nobara is also rollbackable like this, or am I out of luck?

view more: ‹ prev next ›