Skip Navigation
Tempiz Tempiz @sh.itjust.works
Posts 7
Comments 44
[ Community Update ] - Community Update & Team Introduction 2023-06-23
  • Appreciate the transparency and update. This definitely eases concerns. Thanks!

  • [ Community Update ] - Regarding David's Departure 2023-06-22
  • Could we get an introduction into who the new team lead is, what their experience is, and maybe some info on the rest of the team? The current repo owner has no information and has only ever worked on Mlem with this user account. Not exactly confidence inspiring from afar.

  • [Vote] guess I gotta make a post for this over here. Do we defederate with exploding-heads.com
  • Nay

    Block them yourself. Defederation is against the principles of the fediverde. If you are looking for an instance that is more isolated, look into Beehaw.org.

  • Announcement: Embracing a New Chapter: Towards a Community-Guided Direction and Accepting Donations
  • +1 here. If growth slows and donations drop, the instance needs some savings to continue operating, or if another server upgrade is needed with a large capital expense. Not everything is OpEx.

  • The only way to win is to not play
  • Your security team sucks. Users should be encouraged to report anything sus, even if it occasionally results in a false positive.

  • I'm using Lemmy too much.
  • Yeah I never interact on Reddit but I love the idea of helping build the community here.

  • I personally use tabs
  • An absolute mad lad

  • Irl rpg
  • Would be kinda fun if you could switch between views

  • Twitter Runs Ads for Disney, Microsoft, NBA Alongside Neo-Nazi Videos
  • And then they wonder why advertises are avoiding the platform.

  • frequently
  • Constantly.

  • Reddit censoring information about kbin
  • Competing platforms are scary!!!

  • Here’s the note Reddit sent to moderators threatening them if they don’t reopen
  • “Guys this is a democracy I promise. Just do your jobs and don’t complain, speak out, or vote against anything we say. You guys totally still are stakeholders in this platform though. Please volunteer more of your time so we can monetize your free content. Thanks!” - Reddit Admins

  • Main mod of r/piracy demoded by reddit and forcing the sub to open up again
  • Reddit mods crave the “power” they get from donating their time and labor to a mega corp.

  • cache
  • Upgraded cache = bigger clothes pile.

  • Reddit CEO slams protesters, says he'll change site rules
  • I love the irony of him calling Reddit a democracy while also refusing to budge on the API issue. You can’t have it both ways.

  • *Permanently Deleted*
  • Really enjoying the feeling of a closer community of Lemmy. everyone is working together to build this platform from the ground up.

  • Beehive: an update to defederating from sh.itjust.works
  • Great to hear that there is a dialog open between the admins. Hopefully it is all sorted swiftly. Federating with all of the large instances is important for the continued growth of the platform.

  • What do you use for outgoing smtp?
  • I’m also on gmail. Haven’t had any issues with it, no real desire to change.

  • Secure and reliable
  • One sec unplugging my network for security

  • Fortinet SSL-VPN Critical Vulnerability - June 12, 2023

    A buffer overflow vulnerability was found within SSL-VPN in FortiOS leading to unauthorized code execution. Options are either to disable SSL-VPN or upgrade to a patched version.

    0

    Fortinet SSL-VPN Critical Vulnerability - June 12, 2023

    A buffer overflow vulnerability was found within SSL-VPN in FortiOS leading to unauthorized code execution. Options are either to disable SSL-VPN or upgrade to a patched version.

    3

    QNAP Security Advisory | Bulletin ID: QSA-23-05

    cross-posted from: https://sh.itjust.works/post/87144

    > Received this QNAP security bulletin this morning. Update your QNAP products! > > > June 14, 2023 - QNAP® had published security enhancement against security vulnerabilities that could affect specific versions of QNAP products. Please use the following information and solutions to correct the security issues and vulnerabilities. > > >Vulnerabilities in Samba > > >Release date: June 14, 2023 Security ID: QSA-23-05 Severity: Medium CVE identifier: CVE-2022-37966 | CVE-2022-37967 | CVE-2022-38023 | CVE-2022-45141 Affected products: Certain QNAP Devices > > >Summary > > >The Samba Team has released security updates to address vulnerabilities in multiple versions of Samba, including vulnerabilities related to RC4 encryption. If exploited, some of these vulnerabilities allow an attacker to take control of an affected system. The following QNAP operating systems are affected: > > >• QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances) QES is not affected. > > >Only QNAP devices that run the affected operating systems and also act as a domain controller or AD member are affected. > > >Standalone QNAP devices are not affected by the vulnerabilities. > > >QNAP is currently fixing the vulnerabilities in QTS, QuTS hero, QuTScloud and QVP (QVR Pro appliances). > > >Please check this security advisory regularly for updates and promptly update your QNAP operating system to the latest version as soon as it is available. > > >Recommendation > > >Because RC4 encryption poses a high security risk, we strongly recommend replacing RC4 with the more secure AES algorithm when using a QNAP device as a domain controller or AD member. > > >• When the QNAP device acts as a domain controller, we strongly recommend enforcing AES encryption. > • When the QNAP device acts as an AD member, the encryption method should follow that of the domain controller. We also strongly recommend that the domain controller is configured to enforce AES encryption. Before security updates are available, depending on the AD domain role of your QNAP device, we recommend enforcing AES encryption only or at least allowing both AES and RC4 encryption to mitigate the risks posed by the vulnerabilities.

    0

    QNAP Security Advisory | Bulletin ID: QSA-23-05

    Received this QNAP security bulletin this morning. Update your QNAP products!

    > June 14, 2023 - QNAP® had published security enhancement against security vulnerabilities that could affect specific versions of QNAP products. Please use the following information and solutions to correct the security issues and vulnerabilities.

    >Vulnerabilities in Samba

    >Release date: June 14, 2023 Security ID: QSA-23-05 Severity: Medium CVE identifier: CVE-2022-37966 | CVE-2022-37967 | CVE-2022-38023 | CVE-2022-45141 Affected products: Certain QNAP Devices

    >Summary

    >The Samba Team has released security updates to address vulnerabilities in multiple versions of Samba, including vulnerabilities related to RC4 encryption. If exploited, some of these vulnerabilities allow an attacker to take control of an affected system. The following QNAP operating systems are affected:

    >• QTS, QuTS hero, QuTScloud, QVP (QVR Pro appliances) QES is not affected.

    >Only QNAP devices that run the affected operating systems and also act as a domain controller or AD member are affected.

    >Standalone QNAP devices are not affected by the vulnerabilities.

    >QNAP is currently fixing the vulnerabilities in QTS, QuTS hero, QuTScloud and QVP (QVR Pro appliances).

    >Please check this security advisory regularly for updates and promptly update your QNAP operating system to the latest version as soon as it is available.

    >Recommendation

    >Because RC4 encryption poses a high security risk, we strongly recommend replacing RC4 with the more secure AES algorithm when using a QNAP device as a domain controller or AD member.

    >• When the QNAP device acts as a domain controller, we strongly recommend enforcing AES encryption. • When the QNAP device acts as an AD member, the encryption method should follow that of the domain controller. We also strongly recommend that the domain controller is configured to enforce AES encryption. Before security updates are available, depending on the AD domain role of your QNAP device, we recommend enforcing AES encryption only or at least allowing both AES and RC4 encryption to mitigate the risks posed by the vulnerabilities.

    0

    FYI - Windows 10 21H2 Home & Pro go EoL today

    > Just a reminder that Windows 10 21H2 home and pro editions are EoL today. Make sure you get updated to 22H2. > > 22H2 will be the final release of Windows 10, with an EoL of Oct. 14, 2025. > > Enterprise 21H2 still has one year of support which will end June 11, 2024.

    3

    FYI - Windows 10 21H2 Home & Pro go EoL today

    Just a reminder that Windows 10 21H2 home and pro editions are EoL today. Make sure you get updated to 22H2.

    22H2 will be the final release of Windows 10, with an EoL of Oct. 14, 2025.

    Enterprise 21H2 still has one year of support which will end June 11, 2024.

    1

    What is your security role within your organization?

    With this new community, I figured it would be interesting to get a gauge on if there are any security professionals within the community, and what roles everyone holds?

    I personally specialize in GRC, but have also worked in network engineering in the past.

    14