xlash123

joined 1 year ago
[–] xlash123 9 points 9 months ago

The best you can do is use OSS software that has been battle tested. Stuff like OpenSSH and OpenVPN are very unlikely to have backdoors or major vulnerabilities currently being exploited. If you don't trust something to not be vulnerable, you're best to put it behind a more robust layer of authentication and access it only by those means.

[–] xlash123 37 points 9 months ago (1 children)

I understand that software directly and silently changing the default software can be a security issue. But it's only because it happens silently. Does Windows allow for showing a system prompt that confirms the change to the user? If not, then that's just plain ol' anti-competitive. Especially with how pushy Edge and Bing can be.

[–] xlash123 7 points 9 months ago

I think NLPs have been less helpful for me. Like I'll go to work and it'll think I'm in another state (our internet uses the same IP as our headquarters, and the SSID is the same for all locations). Not sure why it can't reject the bad guess when it sees how off it is from my GPS coordinate.

[–] xlash123 5 points 9 months ago (1 children)

I wanna use Rust to build mobile apps so bad. I don't really know what I want to build, but I want to use Rust to do it

[–] xlash123 22 points 9 months ago (5 children)

The text isn't loading for me

[–] xlash123 5 points 9 months ago (1 children)

I just started using Backblaze B2, switching from AWS S3. I use it through Rclone to encrypt everything before I upload it. Only $6/TB/mo and it only charges what you use. You can download up to 3x your data stored per month for free, so if you ever decide to move or you need to restore a backup, you don't have to pay egress costs. It was the cheapest service I could find, but there may be others.

You can set price limits on your account to ensure you don't go over too. It will alert you when you approach the limit. There are some minor costs, like pinging the API, but they are free up to a reasonable amount.

[–] xlash123 14 points 9 months ago

You need to swipe harder for it to work

[–] xlash123 19 points 9 months ago* (last edited 9 months ago)

A backdoor is very distinct from a vanilla vulnerability. Heartbleed was a vulnerability, meaning the devs made a mistake in the code, introducing a method of attack. XZ was backdoored, meaning a malicious actor intentionally introduced a method by which he could exploit systems.

Both are pretty serious vulnerabilities, but a backdoor, especially introduced so high in the supply chain, would have been devastating had it not been caught so early.

[–] xlash123 2 points 9 months ago (1 children)

Man, I wish more businesses operated like Dick's. They sound like they legitimately care about their workers and community. What good is the "free" market when it comes at the expense of peoples' happiness and wellbeing?

[–] xlash123 39 points 9 months ago (2 children)

Too complicated. Just enter a negative number.

[–] xlash123 7 points 9 months ago (3 children)

While you definitely should be able to get a full night's sleep, sleeping all day (at least consistently) could lead to physical and mental problems. So a humane prison should get the prisoners out of bed and doing something productive.

[–] xlash123 31 points 9 months ago

RIP that one guy who relied on this bug. He's gonna have to create a bookmark now, which will ruin his whole workflow.

view more: ‹ prev next ›