Skip Navigation

Posts
1
Comments
192
Joined
2 yr. ago

  • Security through obscurity never works, so changing you SSH port does barely anything

    ... for security that is.

    What it does is keep a lot of automated bots from spamming your server. No, they don't have any chances to get access when key authentification is used (and they won't try either... most go for the incredible low hanging fruits like admin/admin user/password sets), but they can become a strain on your own ressources.

    What actually helps (and is usually configurable with any firewall) is rate limiting access. Just blocking someone's access for 10 seconds after a failed attempt will make absolutely no difference for you but a big one for those spammers. Now add some incremental increase after multiple fails and you are perfectly set.

    PS: 53 is the standard port for DNS when your server operates as such.

    PPS: Don't use it. People should really let that stuff die and exclusively run encrypted DNS (via TLS, HTTPS or Quic...)

  • Mainly my normal phone app. But for a long time it's not sync'd to some google cloud (which would be the default) but a Radicale instance.

    I used Nextcloud before but honestly it's a mess to maintain. So much that I would not suggest it without planning to extensively use a lot of the different available addon functions.

    Just for file sharing and caldav/carddav I will pick some simple solutions (like Radicale and Syncthing) over Nextcloud any day.

  • And to give you a reference to some of the details glossed over...

    The anubis instance listening to a socket doesn't work as described there. Because the systemd service is running as root by default but your web server would need access to the socket. So you first need to harmonise the user the anubis service runs as with the one from your web server with the permissions of the /run/anubis directory.

    (see Discussion here for example)

    Also having one single setup example in the docs with unix sockets when that isn't even the default is strange in the first place...

    Half the Environmental Variables are just vaguely describing what they do without actual context. It probably makes perfect sense when you know it all and are writing a description. But as documentation for third-person use that's not sufficient.

    Oh, and the example setup for caddy is nonsensical. It shows you how to route traffic to Anubis and then stops... and references Apache and Nginx setups to get an idea how to continue (read: understand that you then need a second caddy instance to receive the traffic....).

    PS: All that criticsm reads harsher than it is meant to be. Good documentation needs user input and multiple view points to realize where the gaps are. That's simply not going to happen with mostly one person.

  • More than once. But -not actually surprsing by a work in progress by mostly one single person- it's not actually what I would call well-structured or even coherent. 😅

    More than once googled for a detail I didn't understand and ended up on the issue tracker realizing I'm not alone and some behavior is indeed illogical or erratic.

    And then some of it is of course referencing forwarding- and header-information, how it's handled, where it's flattened... and as my question should have told you, I don't even much clue how it is handled normally.

  • It isn't webdav per se. It's the website presented by a webdav server. So there should be no functional difference between this and yet another webserver in a decentralized setup.

    Yes I know that I can easily change things around to have the reverse proxy run ignored. I was more interested in the "why it happens" than a practical solution (for that I could just move the reverse proxy one block up...).

  • Logs of what exactly? I don't even know where to look. Neither is nginx logging an error, nor is a request ending on an unavailable port and just timing out logged anywhere. How would I set up extensive logging of anything but errors and accesses?

    As far as I'm concerned this is not some error but something regarding the details how proxy_pass works, that I don't understand.

    In fact it isn't even an actual problem per se. I can easily move the reverse proxy up one block so only the actual pages are protected. But the point is that I want to understand why a request that should be routed internally (and is without Anubis in the mix) ends up there. I would suspect some way the default headers are transmitted screwing things up.

  • I have tried localhost and 127.0.0.1 after initially using the internal 192.168.x.x IP and the behavior is always identical.

  • Also even then it's no reason at all to take a step back and reevaluate how much of the original talking points were bullshit, too.

  • "To my surprise, I found that I agreed with conservatives and libertarians on [...]"

    ...totally imaginary issues that only existed in right-wing hallucinations.

    🤣

  • Even if maintainers wouldn't just package stuff themselves. How many formats do you need to cover 95% of the eco system? More than 3?

  • Deleted

    Permanently Deleted

    Jump
  • Lemmy UI:

    So I would guess that it's not a client but an OS or browser issue regarding encoding.

  • Deleted

    Permanently Deleted

    Jump
  • Shhh! Don't let Big Clock know that we are on to them.

  • Because the candidate doesn't matter anymore. You will get some shit propaganda narrative hammered into your brain anyway (see: "vote for Trump so there will be no genocidal war in the middle east").

    So why would democrats care about anything else than their own internal power dynamics? It's not like they can get a good candidate when collective brain-damage will make sure that it's a totally useless candidate anyway once the screeching morons on (social) media tell you what your new reality is.

  • "Option A is really, really bad for me. But I'm not sure if option B wouldn't be somewhat bad, too. So I will just watch and let option A happen."

    --- You, and millions of other propaganda victims helping fascists win

  • Deleted

    Permanently Deleted

    Jump
  • Most people are not that observant and really self-centered.

    From there just a little variance in the spectrum ranging from "I think as highly about others as I think about me" to "they are all inferior to me" can make a massive difference on how someone sees and interacts with the world. And barely anything of it is based on the actual reality of other people.

  • Every one of these articles about disillusioned trumpers never seems to have a basis in more than one or two anecdotal examples.

    That's entirely a matter of perspective, or more precise here: timing.

    That wide outrage really exists. But it is very short-lived and just a case of "waiting on new instruction how to think".

  • Deleted

    Permanently Deleted

    Jump
  • One recent... many, many more throughout history. Terror against the population does not work, never did and never will.

  • No, it's not.

    This is just the 100th iteration of "this time they will really start to criticise Trump". And then the cult gets new orders and instantly they will fall silent and shift their opinion as instructed to match their new reality.

    These people really took 1984 as an instruction manual.

  • Don't be rediculous. By then Debian will be on 258 at best...