brownmustardminion

joined 2 years ago
[–] [email protected] 1 points 2 months ago

I often wish all services could provide an opt out "I'm aware no 2fa is risky but I really don't give a damn about this account so fuck off with the constant email verifications". Or if companies insist on forcing 2fa, at least support hardware keys. Don't even get me started about banks...

[–] [email protected] 1 points 2 months ago

Good point. I'm aware of the icloud method of imessage cracking, but I often forget that I'm not always the weakest link; it's up to the people around you as well.

[–] [email protected] 1 points 2 months ago

I eventually managed to get the yubikey to work, although it is very buggy and the steps to get it working are unacceptable IMO for the "most secure phone OS". Hardware keys should be a major priority and should simply work just as easily as using passwords, but it seems to be a stale open feature request for a few years. Luckily for me, once bitwarden is authenticated with 2fa I don't need my hardware key unless I reinstall it. So that's one major hurdle behind me. Another plus is that while you need sandboxed google services to utilize hardware key auth, they don't need network permissions to work.

[–] [email protected] 2 points 2 months ago (3 children)

If iMessages are e2ee and you aren’t using iCloud, is there any evidence your messages aren’t private? As far as I’m aware iMessage is considered a very secure messaging channel. It seems like most people distrust it due to the Apple affiliation. Not that I blame them, I feel the same about Google.

[–] [email protected] 1 points 2 months ago (1 children)

Just for the sake of getting used to / transitioning to a single gos phone, does it make sense to use the insecure phone as a hotspot and utilize the pixel without a sim (so data only device). I would be using e2e encrypted apps for texts and calls so this makes sense in my head.

[–] [email protected] 4 points 2 months ago (2 children)

Appreciate the info.

It seems absurd to me that a third party online service is required for a hardware key to work in the first place. I figured it would be authenticating strictly between the locked service and the user.

[–] [email protected] 5 points 2 months ago (4 children)

Most helpful comment. Thank you. I’m heavily considering carrying two phones. My biggest hurdle is the Yubikey at this point because it locks me out of my password manager and most of my more important apps.

You mention using the usb-c connection. I tried that but it doesn’t seem to register. I guess I just need to research some more.

Thanks for giving me some hope!

[–] [email protected] 2 points 2 months ago (1 children)

When I initiate Yubikey auth via NFC in Bitwarden, it takes me to a Yubikey demo page. From what I’m reading online, for some reason I need to install google play for the key to work correctly.

Also seeing lots of chatter on the forums that a recent gos update broke most banking apps and they’re working on a fix.

Thank you for the info about the keyboard. I’ll check that one out.

[–] [email protected] 8 points 2 months ago (3 children)

I really like mostly everything about GrapheneOS on paper. The UI, user profiles, security features. It’s the inability to use it in a practical setting that’s frustrating me. Yet I see many people claiming they switched to GrapheneOS a month or a year ago and love it. So there’s got to be a solution. I can’t imagine those individuals installed gos and it was smooth sailing since day 1.

[–] [email protected] 0 points 3 months ago (4 children)

Damn I wish I would've known sooner. Isn't there a concern of not matching the same drive similar to how you can't mix and match RAM sticks?

[–] [email protected] 3 points 3 months ago

+1. Resolve is leaps and bounds ahead of Premiere and even After Effects when you consider Resolve has Fusion built in. I work on high level projects and often run into huge issues trying to work with Premiere projects. Most editors still use it simply because it was the first NLE they picked up. It lacks proper color management and its ability to export out to other software whether for post audio, color, or VFX is abysmal. I switched to Resolve about 5 years ago and while it isn’t without its faults, I’ll take it over Adobe bullshit any day. Sometimes I have to open editors premiere files to troubleshoot and I want to blow my brains out. Easily can wipe out an entire day just troubleshooting premiere projects. It’s funny because when I first got into the industry I was using Premiere and they were trying to push me to use Avid. I felt the same way about Avid as I currently feel about premiere.

[–] [email protected] 12 points 3 months ago (1 children)

For my own understanding, what potential dangers are there using a Yubikey as opposed to an open source key?

 

I self host pretty much everything, but one of the services I find makes more sense to not self host is an email server.

I’ve got a few domains I’d like to have emails for, and usually I’d go for Tutanota or protonmail. But in this instance I’m looking for something dirt cheap. These domains are for a hobby club so I’m much less concerned with privacy like I usually would be. Anybody got any recommendations?

So far namecheap seems like my best option for under $8/month. They would bundle with my domain registration and I’m assuming having both on the same service would make things pretty seamless to set up.

Not crazy concerned with privacy for these particular accounts. Namecheap or similar is reputable enough.

 

Hey guys.

Having a bit of a headache trying to get wireguard working properly through my pfsense router.

Configuration overview: VPS wireguard server set to forward all traffic from peers (it's operating as a self-hosted VPN). I have a port on my router we'll call OPT1 that I want to traffic all connections through wireguard to the VPN.

So far I have the VPS and pfsense connected successful through wireguard. They are making active handshakes and I can ping between them perfectly fine.

I followed the documentation, but my windows PC connected directly to OPT1 can't access the internet. From the PC I can ping the DHCP server of OPT1 as well as the wireguard tunnel, but I can't ping anything outside of that. I'm passing all traffic from OPT1 subnet to the wireguard interface in both OPT1 firewall rules and the wireguard interface rules.

I'm sure many of you have dealt with this configuration before. Does this issue sound familiar?

 

Twitch has gotten insufferable with ads lately. Sometimes I'm getting 3mins straight of ads.

To add insult to injury, twitch is buggy as hell and I often need to refresh and usually it loads new ads.

I used to have a special config in ublock specifically for twitch but that doesn't seem to work anymore.

Any tips?

 

I'm dangerously close to running out of space for my VMs on local-lvm, but noticed I have a lot of free space in my local storage where I only have a dozen ISOs stored.

Can anybody help me figure out how I'd go about shrinking the local storage so I can extend my local-lvm?

1
submitted 7 months ago* (last edited 7 months ago) by [email protected] to c/[email protected]
 

So I’ve been putting off upgrading the fence on my trusty Rigid 4512 for a few years.

I’ve got a big cabinet project coming up and of course my fence of choice, the Vega 40 Pro is no longer available.

Anybody have experience upgrading the 4512 and have any recommendations?

EDIT: Considering Delta T30 and Shop Fox W2005.

 

I’m looking for a small 7” or 8” computer monitor to keep on my desk to display Discord and other things without taking up real estate on my main monitor. Ideally something cheap and therefore not a touchscreen. There’s tons of options online but I’d like to get some recommendations from people who have a similar product and enjoy it.

Something similar in shape and size as the StreamDeck XL would be great. Obviously just a screen though.

 

After a very enlightening discussion in a previous thread, I decided to plunge into a mesh type network to connect my various servers and devices.

Nebula has been fairly straight forward to set up so far, but I’m having some trouble with the details and am curious if anybody has successfully got Nebula up and running for their network.

Installation on Linux platforms has been a breeze. Windows I can’t seem to get working. I was able to install but the service refuses to start. Can’t find any documentation besides random GitHub issue threads. MacOS was easy to install but having issues due to a VPN that’s running already.

I use a VPN because I travel a lot. I also use my MacBook to SSH into my servers or access remote file storage. My previous network configuration was connecting via wireguard to my network. I was able to do this while maintaining an always on VPN with the mullvad app. With Nebula that VPN seems to muck things up.

I’m also curious if anybody has had experience setting up a dual config for Nextcloud. Essentially accessing a Nextcloud server from nebula with a trusted device while still allowing public access for things list public shared links.

 

I had sound working fine with one problem: the center and rear right channel were swapped.

I generated an /etc/asound.conf to work on the channel swap and reloaded and now I can see the audio in pulse audio monitor, but nothing from the speakers. I deleted asound.conf and rebooted and it's now back to the previous settings but still having an issue with no sound from the speakers.

Any help is appreciated. I'm still also trying to figure out how to rearrange the surround channels so they are assigned to the correct speakers. Changing them from the hardware isn't an option unfortunately.

 

Hey folks. I’m fairly new to web dev but was wondering if you all could give me some quick advice.

I’m looking to make and selfhost some fairly simple but visually interesting portfolio static websites. I’ll be posting some creative projects I’ve worked on as well as contact info and such. I’m trying to keep a minimalist design but visually interesting and artistic.

My current research led me towards ReactJS and Tailwind CSS to accomplish this task.

Is this a good framework or do you recommend an alternative?

 

So I selfhost a number of servers in various locations and utilize a DigitalOcean VPS as a hub/gateway to transmit data between these nodes.

I have a consistent issue when running large backups or transfers in which DigitalOcean flags my server for a DDOS attack and sends traffic to a black hole for 3-4 hours.

Customer support has been the absolute worst and does fuck all to help remedy the situation in any way. These events have been consistent over the past 8 months.

Does anybody have recommendations for a solid VPS provider?

Price isn’t too much of a factor. I was running a $8/month server but I don’t mind something more expensive if the company has a good reputation for reliability and privacy.

As mentioned, I primarily use a VPS as a gateway/hub for file transfer services. I’m also hoping to spin up another VPS for static websites.

 

Some background:

  • have a poweredge r320 on battery backup (basic APC unit)
  • have unifi dream machine
  • poweredge powers down automatically if power goes out

What's the safest way to allow myself to power on the server in the event it shuts down while I'm not home?

I figure since I have remote access to my UDM, perhaps there's a command I can execute from there to power it on?

My fear is using a method that provides more than just poweron commands remotely. I want to keep the server attack vectors down.

 

Can anybody lead me down the right path on this...?

I run a jellyfin server and I'd like to utilize a raspberry pi as the equivalent of a roku box / fire stick but for my jellyfin server.

I'm setting this up for a friend as a gift. He isn't very tech savvy so I wanted to make it user-friendly. I'm looking into buying a usb remote control as well.

I love the jellyin UI so it would be cool to stick with that.

What are my options? It would be ideal if the pi boots up right into the browser/player app and can be accessed/controlled via the remote like roku or similar.

EDIT: I wanted to specify that I already have a media server. This pi would serve as a client for viewing only. It will stream from the main server.

view more: ‹ prev next ›