[–] 6 points 9 hours ago (4 children)

Maybe somebody's asked this already but how come, in this day and age, there isn't a way to snapshot your entire phone into some sort of encrypted blob for storage in a location of your choice? You could wipe your phone and setup a throwaway profile with some basic apps before traveling, and then restore the snapshot once safely through customs.

Border issues aside, it would be very handy to be able to snapshot a phone like that anyway...

  • source
  • [–] 20 points 1 week ago (5 children)

    Mythbusters did this, taking enough cars for one lane each in rush hour traffic, plus one car that was allowed to weave.

    The weaving car was quicker by a not inconsiderable margin, so they kind of stumbled over the conclusion saying that yes, weaving is faster, but you probably shouldn't.

  • source
  • [–] 16 points 1 month ago (4 children)

    My entire card details got stolen recently, including my name, address and phone number. The first I knew of it was when an email came in with a verification code for a multi-thousand £ purchase for a hotel reservation. I was just thinking it's an odd looking phish when my phone rang. I ignored it as I always do and then it immediately rang again, so I answered it:

    Them: Hello, is this Mr Zanzibar?

    Me: Yes

    Them: This is Amex fraud dept. We've noticed some odd activity on your card, did you make a purchase at x for y in the last few minutes?

    Me: No.

    Them: OK, great. It's been flagged and declined on our end so your money's safe. Just so that I can get this closed off, can you confirm the code that was sent to you?

    Me: ......Nnnnnooooooooo?

    Them: immediately hangs up

    Obviously then had to then call the real fraud dept and cancel my card, but I was annoyed by how little of a shit they seemed to give. No curiosity of where they could've got every detail of my card, no advice of what to do next, just cancelled the card and issued a new one. Thank you, next caller please.

    Spent the rest of the day both relieved that I didn't fall for it but also furious at myself because the best response I could come up with in the moment was "no". I could've at least told them to get fucked!

  • source
  • [–] 36 points 2 months ago (2 children)

    I tried Jellyfin once about a year ago and it was... OK I guess? Certainly nowhere near as polished as the rabid fan base would have me believe, and there was something in my library that it flat out refused to play.

    If I didn't already have a lifetime Plex Pass, and it was just me hosting my own media for a user count of one, then sure, I'd use it. But none of those things are true. I need something that "just works" and Plex fits that bill.

    Like most people here, I bought a lifetime pass when it was $75 and it's paid for itself over and over again in the time since. I honestly think I've had more than $750 worth of value from my purchase. Sure they've made some odd decisions recently, but until they start actively taking away functionality or rescind existing lifetime subs then I will continue to use it.

    Meanwhile, not to belittle you personally, but the fact that every thread that mentions Plex in any way, good or bad, is guaranteed to be dominated by people circle-jerking over their beloved Jellyfin has put me completely off the project, to the point that I've had to add the word to my blocklist. Obviously that's not working too well or I wouldn't have seen this post!

  • source
  • [–] 55 points 3 months ago*

    Let me get my daily fail headline translator out real quick:

    "Came under fire" == "somebody tweeted"

    "Fury" == "a bot tweeted"

    "Outrage" == "one of our staff tweeted"

    "Slammed" == "somebody liked our tweet"

  • source
  •  

    We're currently using a traditional third party email gateway for spam/phishing scans etc, and we're using that gateway to redirect a few hundred (don't ask) email addresses to Zendesk and few other places. Now we're moving to an integrated solution that means having 365 handle incoming emails directly and we're struggling with the best approach to porting those redirects.

    As it stands, with our domains marked as Authoritative, email is bouncing before any mail flow rules are evaluated due to not having existing mailboxes or contacts. I suppose "best practice" is to create contacts or mail users for all of the support addresses we need to use, followed by either mailbox-level forwards or mail flow rules for all of those addresses (or lump them into a group where appropriate). But that way seems like a big pain in the ass to administer.

    The other option is to set the domains as Internal Relay, which will allow 365 to skip checking whether an address exists, and then just use mail flow rules to handle the redirections directly, which we can script easily enough. But that way seems unsupported at best, and raises big questions about what happens when someone emails an actual non-existent address.

    Googling didn't come up with much in the way of useful documentation so I asked a couple of AIs and they've been similarly inconclusive. Copilot thinks that misdirected email will simply bounce with a "no route found" NDR, and gave me error code 5.4.312 that appears to be made up, while ChatGPT thinks that it'll result in a mail loop and eventual 5.4.6 error, "routing loop detected".

    ChatGPT's explanation seems more plausible and its suggestion of using a catch-all rule to either redirect or bounce mis-addressed emails sounds good on the surfacce, but again, I can't find anything written by actual humans to confirm or deny.

    So I come to you, denizens of sysadmin! Is there any suggested or best practice configuration for the redirection of large amounts of email addresses? Is using Internal Relay on what is actually the final hop a supported configuration? Or is the only supported/sane option to use an Authoritative domain along with the additional overhead of mail contacts?

    Hugely appreciate any thoughts!

     

    Hey all,

    I used to build my own gaming PCs way back in the 90s/early 2000s but I fell out of the habit when I realised I'd rather kick back on the sofa with something that "just works" than constantly chasing framerates etc, and I switched to exclusively console based gaming. Now that I own a Steam Deck, and with Xbox going down the shitter, and my kids becoming of the age where having a static family PC makes a lot of sense, I've decided to move back into PC gaming.

    I started looking at self builds again but everything's moved on so much since I last dipped my toes into that space that I struggle to know where to start. Then I saw an Alienware A51 in the refurb store with a decent early Black Friday discount code and very-nearly top-end specs so I pulled the trigger yesterday:

    £2525

    • Core Ultra 9 285K
    • Geforce RTX 5080
    • 64GB RAM
    • 2TB Gen5 SSD
    • 1500W platinum PSU

    Retail, this spec is currently going for £3600 so it's a sizeable saving, but now I'm getting cold feet on the basis of the Intel chip not being the best choice for gaming (and will possibly never see the BIOS fix that Intel rolled out to address this), the odd PSU that'll likely need swapping out at some point in the future, and the sheer size and weight of the thing.

    On the plus side, the reviews I've seen say that it's very cool and quiet, which is pretty important to me, and I do like the case design itself - it's very understated compared to most of the off-the-shelf options out there. On the downside what looks like a huge discount on the surface is mostly just wiping out the Dell premium, and similarly specced AMD options are available elsewhere for similar prices - albeit with the aforementioned off-the-shelf cases and a big question mark over noise levels.

    All of which is to say: Help this former DIY builder feel a bit better about dropping this much money on a Dell of all things! Odd CPU choice aside, this is still a decent system at a decent price, right?

    submitted 2 years ago* (last edited 2 years ago) by to c/smarthomes@feddit.uk
     

    We have a bunch of shutters in our living room that don't have any kind of remote control, nor a rod to operate them - you just move any of the individual slats and the rest follow suit.

    Is there anything out there that could make these smart? I'm really struggling to find the right terms to search for.

    Update: Turns out they are plantation blinds which has helped me to find the sort of thing I'm after. Cheers, Emperor!

    submitted 2 years ago* (last edited 2 years ago) by to c/selfhosted@lemmy.world
     

    Quick overview of my setup: Synology NAS running a whole bunch of Docker containers and a couple of full blown VMs, and an N100 based mini PC running Ubuntu Server for those containers that benefit from hardware acceleration.

    On the NAS I have a Linux Mint VM that I use for various desktoppy things, but performance via RDP or NoMachine and so on is just bad. I think it's ultimately due to the lack of acceleration, so I'd like to try running it from the mini PC instead but I'm struggling to find hypervisor options.

    VirtualBox can be done headless, apparently, but the package installed via Apt wants to install X/Wayland and the entire desktop experience. LXC looks like it might be a viable option with its web frontend but it appears to be conflicting with Docker atm and won't run the setup.

    Another option is to redo the machine with UnRaid or TrueNAS Scale but as they're designed to be full fledged NAS OSes I don't love that idea.

    So what would you do? Does anyone have a similar setup with advice?

    Thanks all!

    Edit: Thanks for everyone's comments. I still can't get LXC to work, which is a shame because it has a nice web frontend, so I'll give KVM a go as my next option. Failing that I might well backup my Docker volumes, blat the whole thing and see what Proxmox can do.

    Edit 2: Webtop looks to be exactly what I was looking for. Thanks again for everyone's help and suggestions.

    submitted 2 years ago* (last edited 2 years ago) by to c/selfhosted@lemmy.world
     

    Specifically from the standpoint of protecting against common and not-so-common exploits.

    I understand the concept of a reverse proxy and how works on the surface level, but do any of the common recommendations (npm, caddy, traefik) actually do anything worthwhile to protect against exploit probes and/or active attacks?

    Npm has a "block common exploits" option but I can't find anything about what that actually does, caddy has a module to add crowdsec support which looks like it could be promising but I haven't wrapped my head around it yet, and traefik looks like a massive pain to get going in the first place!

    Meanwhile Bunkerweb actually looks like it's been built with robust protections out of the box, but seems like it's just as complicated as traefik to setup, and DNS based Let's Encrypt requires a pro subscription so that's a no-go for me anyway.

    Would love to hear people's thoughts on the matter and what you're doing to adequately secure your setup.

    Edit: Thanks for all of your informative replies, everyone. I read them all and replied to as many as I could! In the end I've managed to get npm working with crowdsec, and once I get cloudflare to include the source IP with the requests I think I'll be happy enough with that solution.

     

    I work in tech and am constantly finding solutions to problems, often on other people's tech blogs, that I think "I should write that down somewhere" and, well, I want to actually start doing that, but I don't want to pay someone else to host it.

    I have a Synology NAS, a sweet domain name, and familiarity with both Docker and Cloudflare tunnels. Would I be opening myself up to a world of hurt if I hosted a publicly available website on my NAS using [insert simple blogging platform], in a Docker container and behind some sort of Cloudflare protection?

    In theory that's enough levels of protection and isolation but I don't know enough about it to not be paranoid about everything getting popped and providing access to the wider NAS as a whole.

    Update: Thanks for the replies, everyone, they've been really helpful and somewhat reassuring. I think I'm going to have a look at Github and Cloudflare's pages as my first port of call for my needs.

     

    Hey there, my local instance has had two admin posts pinned for the last 6 months-ish and they show right at the top of my Subscribed, Local, and All views. I can't imagine they're going to get un-pinned any time soon, so it would be great to get a feature where we can hide them.

    Thanks for the consideration!

    view more: next ›