Skip Navigation
InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)FI
Findmysec @infosec.pub
Posts 12
Comments 219
Mozilla's massive lapse in judgement causes clash with uBlock Origin developer
  • This one is completely on Mozilla. TBH I'm not very happy with their governance either. Stop spending money on bullshit and start working on the damn browser. Stop hassling devs like him who have had an immense contribution to not only open source, but your fucking browser's usage metrics.

    I wish another browser standard comes up and we can say goodbye to this google-infested shit-bucket that is mozilla.

  • Advice needed for networking/architecting
  • I'm afraid I do not follow. TrueNAS scale has support for kubernetes: install containers on top, maybe different containers for different fileshares/uses (one container for VM images, one for media etc).

    Mount said network volumes on the compute boxes.

  • What kernel version do Moto phones from 2023/2024 have?

    I'm looking at the G play/G Power editions which I'd like to root with KernelSU. Which kernel versions do these devices have?

    Thanks

    2
    Feather-Atomic atomic swap plugin for feather wallet v1.1 released
  • I do not know the specifics of how MimbleWimble works, but like XMR, transaction history and metadata is no longer public. Your trace of coins are effectively evaporated when you move coins over MW to another wallet from your "compromised" wallet, and from there you convert to XMR/move to another LTC wallet and pay merchants who accept LTC without MW. Obviously, basic OPSEC is expected but other than that the technology is supposed to work fairly well.

    You could also do a swap like LTC->XMR->LTC and spend it that way, losing some money in the process but soothing paranoia in return

  • Parental controls?
  • I found this but it's from a while back: https://h-mdm.com/advanced-web-panel-installation/

    Not too many out there TBH. If I had a daughter she'd be getting a Pixel with Grapehene and a DNS server on it (different user) if she really didn't have any self control

  • Is StormyCloud the only I2P outproxy?

    A lot many individuals run TOR exit nodes, but I never hear about people running their own I2P outproxies. Is it really hard to host, or is there some other reason? I thought that if you could run a TOR exit node I'd think you'd be just fine running an I2P outproxy.

    Running more outproxies will help in bridging torrents from the clearnet to I2P, which would be a very good move considering the crackdowns on torrents right now. Companies even want to involve civilians into their lawsuits in Sweden now, making the need for privacy/anonymity even more important when torrenting, which I2P provides.

    10

    Does Wikipedia really need my donations?

    Every now and then I'll get an email from someone higher up in Wikipedia asking for a donation. I don't really mind a tenner but I don't know if it pads the pockets of corporate management or actual contributors. Also, are they really short of money or is this tugging at emotional strings a play at something else? I wish Wikipedia survives but there's a lot of projects I need to donate to and I have a budget.

    58

    I find no motivation in working for myself

    The title is really vague, so I'll try to clarify my intentions here:

    I am an ardent supporter of FOSS. It will be greatly beneficial for my life and especially my privacy to self-host such software. Yet, I cannot find much motivation to do so.

    However, when it comes to hosting software for public use, I can usually give my utmost concentration and dedication.

    This is not how I want my life to be. I want to be motivated for myself as well as for the community. And if that's not possible, I need to trick my brain into bringing me into that kind of zone for myself.

    What do I do? What would you do in this situation?

    48

    Why do so many people use NGINX?

    I see so many posts and people who run NGINX as their reverse proxy. Why though? There's HAProxy and Apache, with Caddy being a simpler option.

    If you're starting from scratch, why did you pick/are you picking NGINX over the others?

    102

    Unable to figure out directory permissions

    cross-posted from: https://infosec.pub/post/15386345

    > Hi everyone, > > This is my CONTAINERFILE for Bind9: > > > FROM debian > > ENV LC_ALL C.UTF-8 > > # Update and upgrade system > RUN apt-get update -y && apt-get upgrade -y && apt-get dist-upgrade -y > > # Install BIND 9 and sudo (for debugging if needed) > RUN apt-get install -y bind9 bind9-dnsutils bind9-libs bind9-utils sudo > > # Configure permissions for BIND directories > RUN mkdir -p /var/cache/bind /var/lib/bind /var/log/bind > RUN chown -R bind:bind /var/cache/bind /var/lib/bind /var/log/bind > RUN chmod 664 /var/cache/bind /var/lib/bind /var/log/bind > RUN chmod -R 664 /var/cache/bind /var/lib/bind /var/log/bind > > # Create and configure log files > RUN touch /var/log/bind/default.log /var/log/bind/update_debug.log /var/log/bind/security_info.log /var/log/bind/bind.log > RUN chown -R bind:bind /var/log/bind > RUN chmod 644 /var/log/bind/*.log > > # Define volumes > VOLUME ["/etc/bind", "/var/cache/bind", "/var/lib/bind", "/var/log/bind"] > > # Set the entrypoint to the named executable > ENTRYPOINT ["/usr/sbin/named"] > > # Set the default command arguments for the named executable > CMD ["-g"] > > > I keep getting this error when I run it with podman: > > > 26-Jul-2024 03:18:21.328 loading configuration from '/etc/bind/named.conf' > 26-Jul-2024 03:18:21.328 directory '/var/cache/bind' is not writable > 26-Jul-2024 03:18:21.332 /etc/bind/named.conf.options:2: parsing failed: permission denied > > > As you can see from the CONTAINERFILE, the bind user should be able to read and write to /var/cache/bind but for some reason it doesn't. > > I have been at this for a while and I'm at my wits end. Your help is appreciated!

    4

    Unable to figure out directory permissions

    cross-posted from: https://infosec.pub/post/15386345

    > Hi everyone, > > This is my CONTAINERFILE for Bind9: > > > FROM debian > > ENV LC_ALL C.UTF-8 > > # Update and upgrade system > RUN apt-get update -y && apt-get upgrade -y && apt-get dist-upgrade -y > > # Install BIND 9 and sudo (for debugging if needed) > RUN apt-get install -y bind9 bind9-dnsutils bind9-libs bind9-utils sudo > > # Configure permissions for BIND directories > RUN mkdir -p /var/cache/bind /var/lib/bind /var/log/bind > RUN chown -R bind:bind /var/cache/bind /var/lib/bind /var/log/bind > RUN chmod 664 /var/cache/bind /var/lib/bind /var/log/bind > RUN chmod -R 664 /var/cache/bind /var/lib/bind /var/log/bind > > # Create and configure log files > RUN touch /var/log/bind/default.log /var/log/bind/update_debug.log /var/log/bind/security_info.log /var/log/bind/bind.log > RUN chown -R bind:bind /var/log/bind > RUN chmod 644 /var/log/bind/*.log > > # Define volumes > VOLUME ["/etc/bind", "/var/cache/bind", "/var/lib/bind", "/var/log/bind"] > > # Set the entrypoint to the named executable > ENTRYPOINT ["/usr/sbin/named"] > > # Set the default command arguments for the named executable > CMD ["-g"] > > > I keep getting this error when I run it with podman: > > > 26-Jul-2024 03:18:21.328 loading configuration from '/etc/bind/named.conf' > 26-Jul-2024 03:18:21.328 directory '/var/cache/bind' is not writable > 26-Jul-2024 03:18:21.332 /etc/bind/named.conf.options:2: parsing failed: permission denied > > > As you can see from the CONTAINERFILE, the bind user should be able to read and write to /var/cache/bind but for some reason it doesn't. > > I have been at this for a while and I'm at my wits end. Your help is appreciated!

    2

    Unable to figure out directory permissions

    Hi everyone,

    This is my CONTAINERFILE for Bind9:

    ``` FROM debian

    ENV LC_ALL C.UTF-8

    Update and upgrade system

    RUN apt-get update -y && apt-get upgrade -y && apt-get dist-upgrade -y

    Install BIND 9 and sudo (for debugging if needed)

    RUN apt-get install -y bind9 bind9-dnsutils bind9-libs bind9-utils sudo

    Configure permissions for BIND directories

    RUN mkdir -p /var/cache/bind /var/lib/bind /var/log/bind RUN chown -R bind:bind /var/cache/bind /var/lib/bind /var/log/bind RUN chmod 664 /var/cache/bind /var/lib/bind /var/log/bind RUN chmod -R 664 /var/cache/bind /var/lib/bind /var/log/bind

    Create and configure log files

    RUN touch /var/log/bind/default.log /var/log/bind/update_debug.log /var/log/bind/security_info.log /var/log/bind/bind.log RUN chown -R bind:bind /var/log/bind RUN chmod 644 /var/log/bind/*.log

    Define volumes

    VOLUME ["/etc/bind", "/var/cache/bind", "/var/lib/bind", "/var/log/bind"]

    Set the entrypoint to the named executable

    ENTRYPOINT ["/usr/sbin/named"]

    Set the default command arguments for the named executable

    CMD ["-g"] ```

    I keep getting this error when I run it with podman:

    26-Jul-2024 03:18:21.328 loading configuration from '/etc/bind/named.conf' 26-Jul-2024 03:18:21.328 directory '/var/cache/bind' is not writable 26-Jul-2024 03:18:21.332 /etc/bind/named.conf.options:2: parsing failed: permission denied

    As you can see from the CONTAINERFILE, the bind user should be able to read and write to /var/cache/bind but for some reason it doesn't.

    I have been at this for a while and I'm at my wits end. Your help is appreciated!

    8

    Somebody please explain PROXYv2 to me and the myriad of ways to do DoH?

    I've been looking to implement DoH

    1. The first idea was to simply follow this - I do not understand the configuration fully but it looked fine.
    2. Then, I decided to use a proxy/Load balancer in front of BIND to deal with HTTPS.

    However, I came across PROXYv2 (which is not even mentioned in the docs, just in a blog post) and the likes of DNSdist.

    My questions:

    1. I can't find a detailed explanation of what I need to do about PROXYv2 - does my Reverse-proxy absolutely need to have it to be able to communicate with my DNS server?
    2. Why can't I just have any reverse-proxy that can handle HTTPS and put it in front of my DNS resolver? Does my proxy need to have a specific protocol to be able to talk DNS queries?

    I am still confused, would really appreciate some help :)

    0

    Is Backblaze a reliable provider?

    Hi everyone,

    I've started pushing backups of media important to me (family pictures, video etc) to backblaze with client-side encryption.

    However, are they a reliable storage provider? I can't help but compare them to something like Amazon who likely has a better chance of maintaining my files but they are so expensive that I don't even bother.

    What do you think? Yes, I've heard of 3-2-1, however for now I only have backblaze and a local backup. I'm trying not to spend too much on this.

    Thanks!

    67