Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)N
Posts
1
Comments
143
Joined
2 yr. ago

  • If client certificates and basic auth is not supported by jellyfin:

    • reverse proxy
    • strong random subdomain
    • wildcard certificate
    • tls1.3 only
    • doh/dot only

    1-3 make random scanners unable to find your service, 4&5 even hide it from your ISP. Dot/doh service will still know your subdomain, so be your own dot/doh ! :D

  • Ports are closed by firewalls, and if you need to port forward on your home router this is a non-issue anyway

  • meh, how can that be :-( I'm still in the process of setting things up with jellyfin, didnt know...

  • Just put it behind a proxy and require a user cert? Bit of a burdon on the client side, admittedly

  • How comes you don't have a baby? Was it eaten by fascists, maybe?

  • Traffic is still gonna be e2e encrypted, not too much to gain

  • Push means: if your Server gets compromised, your backup is, too.

    So I prefer pull. To not have the same effect I use a restricted ssh account that can only call rrsync.

  • ipfwadm ftw

  • I have to admit it widens the attack surface. Not immensely, but every bit counts.

  • host key veryfication, right, good point! non-root attacker won't have your servers key. but thats just on top. so even if you ack the new host key, what could they gain? give you a shell with their permission and wait for you to sudo-tell them their password maybe. until then trying to mimic the system they might not know too much about (whats in /root?)

  • I run a small it company. Each month I have to sort all tax relevant documents and hand them to my tax office.

    So I download the tx CSV from my accounts. Those get parsed and the relevant invoices get searched in paperless, so I see if something is missing etc with a few minutes of manual work.

  • I have an paperless account and shared it with my user, but you can also just integrate 2 accounts in one email client.

    Guess I should create a sieve filter to look for relevant mails and auto-copy

  • so everyone can open them... so what? attacker who already gained local access can crash your original sshd and spin up his own one? admittedly a thinkable scenario... but can this even be abused in a pubkey auth scenario?

  • Old school

  • Introducing pay-per-slice in 2026, to assure customer satisfaction!

  • Removed Locked

    Why does Lemmy.ML admire authoritarian regimes ?

    Jump
  • Whenever I come across a post like OP describes, and I check the instance, it's ml (with a bit of hex in the mix). It seems fair to me to ask this question.

    But then I guess the discrepancy is: "90% of a specific kind of users are on this instance", which is absolutely not the same as "90% of this instances users are of this kind"

  • I learned from a friend how to dial in with some terminal to create an account like that manually. There were some magic numbers/strings involved, but I can't remember details. I just remember the com port had to be set to 7n1, not 8n1 like for all other stuff I did

  • Very interesting read and deep insights into sabotage operations!

  • git init /