• 0 Posts
  • 40 Comments
Joined 3 years ago
cake
Cake day: June 20th, 2023

help-circle

  • Fail2ban is just another tool in your toolbox. Defense in depth, as others mentioned.

    Fail2ban is primarily a tool to prevent brute force attacks, especially useful for services that don’t do their own throttling. For example I usually put ssh in fail2ban, but if Authelia’s built-in protection is good enough, then use that.

    Outside ssh, anything that could be used to brute force credentials should be in fail2ban if they’re exposed: web sites with simple auth, mail, etc.



  • I installed CacyOS on my MSI laptop with Nvidia m2060 + igpu and Intel CPU a couple of months ago. I can play genres through Steam just fine. It performs better than it did on Windows 11.

    I’ll be honest, I was amazed I had no issues getting it running. CachyOS has sone great tools to set things up and their wiki is excellent. I just followed the steps in there to set up GPU switching. I disabled secure boot, since that can get in the way of drivers loading, but they have instructions for that as well.

    Wi-Fi worked out of the box. I even have a luks encrypted root.

    The main issue I had was MSI specific hardware, like battery charging control, normally managed by the Dragon Center. I found an open source replacement for that.

    I can’t speak to the battery performance since I always use it plugged in. It’s a few years old so it’s probably not great anyway.

    Your mileage may vary. It’s probably going to be more off a struggle with hardware specific to the model of laptop rather than Nvidia.



  • My guess is that it changed from open source to a proprietary license. From Wikipedia:

    Initially, Paint.NET was released under a modified version of the MIT License, with the exclusion of the installer, text, and graphics.[9] However, citing issues with the open source code being plagiarized by others that had rebranded the software as their own and bundled user content without their permission, the availability of the source code was restricted, in December 2007 Brewster announced his intent to restrict access to components of the program (including its installer, resources, and user interface).[10] In November 2009, the software was made proprietary, restricting the sale or creation of derivative works of the software.[10][11]




  • Depends on what in using it for. There is no way to fully avoid the Internet anymore. You can’t interact with businesses or government without it. So, for that, we’re stuck with it.

    I work in IT so I’ll be stuck with it there. I already have no expectation of privacy at work, though.

    For entertainment and engaging with communities like Lemmy, I think losing anonymity through mandatory online id would be the nail in the coffin.

    I already moderate myself on social media, but I have an outlet in these communities. I would simply stop using them if I lost that.

    I would guess underground networks would rise up to replace them, but I would not want to put myself at risk. I don’t trust VPNs enough for that.


  • I think it’s fair to want a more helpful error message, but that’s not necessarily the purpose for path. There is a real cost to every entry in your $PATH. Not as much as in the world of spinning rust, but some.

    There are some completion modules for shells that will suggest misspelled or even installable packages if it can’t find the command. Those are arguably better options.

    As for traditional systems, I remember a time where running arbitrary commands, even with an --help argument could be dangerous and we had to set least try ‘man command’ first.



  • My guess is not just traditional developers, but anyone doing any amount of coding, like data scientists, business analysts, etc.

    Especially if they’re using AI, those tools work better on Linux, or as is the case most places, wsl2 inside Windows.

    I believe Windows is kept because of the Office tools. However, Windows needs 12 layers of security tools that constantly get in your way, so the path of least resistance is to just stay in your wsl2 sandbox.

    The knee jerk reaction to this from enterprise IT is often to restrict access to WSL. This solves the problem, but creates disgruntled users who will continue to try and work around it.

    What they should consider, in my opinion, is giving these people real Linux workstations that can be enrolled in group policies, SSO, and all that good stuff. Commercial vendors of Linux will support these use cases.

    Some places roll out Macs, which work almost as well, but the hardware is more expensive. Hardware and commercial software support may be better, though, I don’t know.

    I think either is a superior alternative to Windows.



  • In no particular order:

    • The Rest Is Science (podcast)
    • Technology Connections/Connextras
    • Jeff Geerling / Level 2 Jeff – Edit: see replies below
    • Techmoan
    • Gamers Nexus / GNCA
    • LGR
    • Switch and Click
    • The Linux Experiment
    • Tasting History with Max Miller
    • Ben Eater (breadboard computers)
    • Stuff Made Here (engineering)
    • Up and Atom (science)
    • Simon d’Entremont (photography)
    • Words Unravelled and Rob’s Words (English language)
    • Kurzgesagt – Edit: see replies below
    • Veritasium – Edit: see replies below
    • Tom Scott (the returned)
    • Asianometry (tech history)
    • Clabretro (retro networking and server hardware)

    Edit: A few bonus channels that may be of interest but didn’t all fit the criteria for me:

    • Action Retro - doing silly stuff with old computers - more recent discovery for me
    • Dr Geoff Lindsey - Linguistics - I only watch occasionally - can be a bit heavy on the linguistic science for an amateur like me.
    • Lftkryo - Linus Åkesson - an absolute wizard coding on the C64
    • RetroBytes - computer history. Most of his content is mainly him just talking, so I can just listen while I’m doing something else
    • Tech Tangents - more of a recently discovered channel for me. Vintage hardware. Underrated channel.
    • Serial Port and Parallel port - vintage computers and networking. Brings back memories from my days working for an ISP.
    • Honorary mention to Veronica Explains. She keeps things pretty basic so I don’t get a lot out of her videos, but I like her stance on open source and not selling out. She posts everything on Peertube as well.

  • No problem. I just spent a few minutes prompting Gemini and requested that it provided sources. I think it’s about right, because it matches what I remember (LTT had a YT privilege to replace videos in situ, where as GN did not), but the usual AI caveats apply. Sorry if that seems low-effort, but I don’t see a rule against quoting AI, and I’m not that invested in this either. (Mods: please take this down if it’s against any rules).

    The response it gave me at first was a bit too long for this post so I asked it to summarize, and I’ve added the other sources it gave me to the bottom.

    Here is a condensed summary of the controversy:

    • The Core Issue: In August 2023, the YouTube channel Gamers Nexus (GN) published a massive 44-minute exposé criticizing Linus Tech Tips (LTT) for rushing content, which led to significant data and testing errors in their hardware reviews.
    • The “VIP” Privilege: GN revealed that instead of taking down flawed videos and losing their algorithmic momentum, LTT was using a backdoor YouTube privilege—available only to massive creators through a partner manager—to silently replace the source video file on the backend after publication.
    • The Proof: GN proved this by comparing the YouTube versions of LTT’s videos to versions syndicated on the Chinese platform Bilibili. Because LTT didn’t have the same VIP privilege on Bilibili, the original uncorrected videos containing glaring data errors were still live there, while the YouTube versions had been magically fixed.
    • The Fallout: GN argued this was an unfair advantage that allowed LTT to prioritize quantity over quality without facing the massive financial and algorithmic penalties that regular creators face when forced to re-upload. Following the intense community backlash, LTT paused their entire production schedule to overhaul their quality control labs and promised full transparency regarding future video corrections.

    Why GamersNexus Hates LinusTechTips

    This video essay provides a comprehensive retrospective and breakdown of the entire Gamers Nexus and Linus > Tech Tips controversy, providing further context on the claims and the resulting fallout.

    Sources:





  • Your diagram is almost right, but I think it will help to understand more of the details. It’s important to understand the difference between DNS (domain name lookup) and IP routing.

    To break your diagram down more, this is what happens when any computer looks up your website:

    1. The device does a DNS lookup of “example.com” using their name server, which may forward it to another DNS server (most home routers do this). I won’t go into the multiple levels of DNS lookups and caching here.
    2. Through looking it up by DNS, the device now has the final IP. DNS is now out of the picture and we’re doing IP routing.
    3. The device tries to make an HTTP connection to your external IP. HTTP is a protocol that runs over TCP/IP (UDP is used for QUIC/HTTP3). To keep things simple I’ll stick with old fashioned HTTP over TCP without SSL. I am also skipping over NAT.
    4. For TCP, it performs a handshake, which the reverse proxy will negotiate. Once the connection is established, the browser speaks HTTP to the reverse proxy. It looks something like:
    GET / HTTP/1.1
    Host: example.com
    ...lots more headers...
    <blank line>
    
    1. The reverse proxy then takes that request, maps it to an upstream (if any), and makes another request to it via the configured transport. If that part falls down, you will see a 503 error. Otherwise, you will see the response from the upstream, possibly with some modifications made by the reverse proxy (some will rewrite links and cookie paths, for example)
    2. The reverse proxy sends that response back to the client.

    That’s all very simplified, of course.

    As others pointed out, things may seem to work differently from the “inside”, if hairpinning is not available or enabled. This is not related to DNS, but to IP routing. The firewall doing NAT can get confused and not know what to do when an internal request goes to an external IP that it itself has. When it turns that around and routes it back to the internal network, that’s called hairpinning.

    One “fix” for this, often used in enterprises, is to use so-called split DNS. All that means is that if you’re asking your internal DNS server for an internal name, it will give you the internal address (192.168.1.123 for example), but an external client would get an external IP.

    TL;DR: DNS and IP routing are separate concerns and happen at different parts of the TCP/IP stack.


  • AC in the US aren’t (usually) heat pumps. The most common setup here is a furnace for heating (usually natural gas) plus AC, connected to the same central air unit. Heat pumps are pretty common, but not nearly as universal.

    Just mentioning it because “AC” isn’t usually used to refer to heat pumps here.