Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)C
Posts
32
Comments
186
Joined
2 yr. ago

  • I heard he already lost interest in this project.

  • I did it only once (yet) because i needed a specific addon for the software.

    In my case, I wanted to use caddy webserver with a specific plugin. It was quite easy to create a new image exactly the way i wanted it.

  • I'm not a mbin user, but the combined frontpage looks interesting.

  • The maintainers of the big web browsers have pretty strict rules for CAs in this list. If any one of them gets caught issuing only one certificate maliciously, they are out of business.

    And all CAs are required to publish each certificate in multiple public, cryptographically signed ledgers.

    Sure, there is a history of CAs issuing certificates to people that shouldn't have them (e.g. for espionage), but that is almost impossible now.

  • For 3 more months or so, you can't buy them in april 2026 anymore

  • Short lifespans are also great when domains change their owner. With a 3 year lifespan, the old owner could possibly still read traffic for a few more years.

    When the lifespan ist just 30-90 days, that risk is significatly reduced.

  • No, these are completely separate issues.

    • CRL: protect against certificates that have their private key compromised
    • CT: protect against incompetent or malicious Certificate Authorities.

    This is just one example why we have certificate transparency. Revocation wouldn't be useful if it isn't even known which certificates need revocation.

    The National Informatics Centre (NIC) of India, a subordinate CA of the Indian Controller of Certifying Authorities (India CCA), issues rogue certificates for Google and Yahoo domains. NIC claims that their issuance process was compromised and that only four certificates were misissued. However, Google is aware of misissued certificates not reported by NIC, so it can only be assumed that the scope of the breach is unknown.

    Source

  • There are some nameserver providers that have an API.

    When you register a domain, you can choose which nameserver you like. There are nameservers that work with certbot, choose one that does.

  • The only disadvantage I see is that all my personal subdomains (e.g. immich.name.com and jellyfin) are forever stored in a public location. I wouldn't call it a privacy nightmare, yet it isn't optimal.

    There are two workarounds:

    • do not use public certificates
    • use wildcard certificates only

  • The best approach for securing our CA system is the "certificate transparency log". All issued certificates must be stored in separate, public location. Browsers do not accept certificates that are not there.

    This makes it impossible for malicious actors to silently create certificates. They would leave traces.

  • The "accepted anwer" feature seems very nice, i would love to see this implemented in other fediverse projects too.

  • I think its a completely different use case. MobaXterm is a fancy ssh/rdp tool with some extra features, while rustdesk is an alternative to teamviewer or anydesk - tools for remote support.

    Disclaimer: I haven't used rustdesk yet, I have no need for this use case.

  • Yes, that is exactly what I meant.

  • Personally, I would try to avoid publishing nginx proxy manager's management web ui to the general public.

  • Please don't confuse the nginx proxy manager (npm) with the node.js packet manager (npm). The latter is frequently in the news regarding security vulnerabilities.

  • NSFW Removed

    fireTv

    Jump
  • There is no content in this post.

    @taher12@lemdro.id I see this is your first post, welcome here :) If you need help, feel free to ask.

  • For selfhosting, I would advise against installing a desktop environment and rather suggest to install a server version without GUI.

  • Only downside I see is how long it took for version 2.0 to get released. The previous stable release (1.23.16) was released almost one year ago.

  • I've been using this new version a few weeks now (since beta 3). The most significant advantage is the performance improvement. With 100+ monitors, the "old" version was very sluggish and took a long time to start.

    Edit: I migrated my existing install to mariadb following this thread on github.

  • Cybersecurity - Memes @lemmy.world

    Responsible Disclosure (other perspective)

  • Cybersecurity - Memes @lemmy.world

    Responsible disclosure

  • Cybersecurity - Memes @lemmy.world

    No backup, no mercy

  • Cybersecurity - Memes @lemmy.world

    Your password has expired

  • Cybersecurity - Memes @lemmy.world

    Does your company do phishing simulations?

  • Cybersecurity - Memes @lemmy.world

    Password length requirement

  • Cybersecurity - Memes @lemmy.world

    Website security

  • Cybersecurity - Memes @lemmy.world

    We're probably not the only ones running outdated software

  • Selfhosted @lemmy.world

    Immich v1.109.1 released with optional paid license

    github.com /immich-app/immich/releases/tag/v1.109.0
  • Cybersecurity - Memes @lemmy.world

    Security is a process

  • Cybersecurity - Memes @lemmy.world

    Phishing

  • Cybersecurity - Memes @lemmy.world

    Phishing