No, I rarely read the code of software I use, especially crypto code since thant’s not my thing. But good to know that you did. Thanks for your opinion.
- 5 Posts
- 17 Comments
Please tell us more about the actual security problems!
Emacs with LSP and magit rules!
callcc@lemmy.worldto Woodworking@lemmy.ca•The Best Food-Safe Finish May Be None At All - Fine Woodworking Article2·3 months agoWho found this out? The CIA? Seems clear to me.
callcc@lemmy.worldto Woodworking@lemmy.ca•The Best Food-Safe Finish May Be None At All - Fine Woodworking Article41·3 months agoMicrobes are usually totally fine. You are full of them, the world is full of them. Don’t panic.
callcc@lemmy.worldto Technology@lemmy.world•Europe’s GDPR privacy law is headed for red tape bonfire within ‘weeks’English1·3 months agoCookie banners are not mandated by GDPR. It’s an unrelated piece of law.
Welcome to the internet. You will be probed. Just as your immune system, or rather your body, is being probed.
Just don’t run broken software. The attackers will not be able to exploit you then. If they have zero day exploits, the WAF will most of the time not save you since they are often pretty easy to circumvent. WAFs are only effective against old and shitty exploits that should be patched anyways since ages.
Attack surface is made of the amount of code that is running when an attacker speaks to your machine. Imagine a freshly installed GNU/Linux distro with no services. The attack surface is minimal. All packages sent to your machine will only ever be touched by relatively limited parts of the linux TCP/IP stack and NIC driver. If you now run a web server, the package coes through the NIC driver, TCP/IP stack and web server. The surface is increased. Each of these parts of your machine’s code could have bugs. The more code your attacker’s packet runs through, the more opportunity to make your machine do things you don’t like.
If you want your machine to do what you like but not what random attackers like, it is therefore mandatory to have the least amount of attack surface, not adding code in contact with your attacker like a WAF or “antivirus”. Both these kind of softwares will inspect the packages coming in an take decisions (potentially bad ones) based on the content.
WAFs will mostly not help you since on a well configured and patched system, little known bugs are exposed. They might help you occasionally but usually patching the system is more effective. Of you want this to happen automatically, it’s entirely possible. Most os’s allow automatic unattended upgrades.
Wafs don’t make you safer but create unnecessary attack surface. Just keep your machine and services up to date.
callcc@lemmy.worldto Right to Repair@discuss.tchncs.de•Liberating manuals from the many jails of manuals into InternetArchive1·5 months agoVery nice! I’ll try not to forget next time I liberate a mabaul.
callcc@lemmy.worldto Green Energy@slrpnk.net•Negative electricity prices registered in nearly all European energy markets1·1 year agoI’m afraid that’s not how it works. You’ll have enormous amounts of really salty water that you need to get rid of. Usually you’ll just put back from where you took it thereby increasing salinity which is not good™ for ecosystems.https://www.wired.com/story/desalination-is-booming-but-what-about-all-that-toxic-brine/
callcc@lemmy.worldto Green Energy@slrpnk.net•Negative electricity prices registered in nearly all European energy markets2·1 year agoApparently dealing with the brine is a big issue though. Source: heresay
Please watch out to orient your light in a way that it wont point into your fellow cyclists eyes. That can be very unsettling.
Bike lights often have optics that try to prevent this from happening off course only when properly oriented.
Busch Müllers are great such as IXXON Core. Also, I’ve noticed more and more people having very bright bike headlights that don’t point downwards enough. They blind the hell out of me during my commute. Please do me the favor of orienting your light downwards and not pointing it into my eyes.
callcc@lemmy.worldto Technology@lemmy.world•TIL there is an fediverse alternative to DiscordEnglish1·2 years agoSnicket is pretty good
Just came here to say that the guy looks like a creep!