Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)N

nickwitha_k (he/him)

@ nickwitha_k @lemmy.sdf.org

Posts
5
Comments
442
Joined
3 yr. ago

  • Eh. It's a fine distro (I use it as one of my boots) but I really would steer new folks away from Arch as a first distro. The wiki is phenomenal but it's not very ergonomic for people who don't live in the terminal (like me), even with Discover.

  • Yeah... But then it sucks for anyone not running Arch (btw) or derivative distros. I really don't have a dog in this merge conflict but really would feel bad for any packager maintainers.

  • My two meow at each other, humans, and the dog.

  • Would have to go back to before the license change in September 2024. The current license basically forbids forks, from my reading.

  • Yeah. That's a pretty shitty license to move to for endusers and others. Disallowing derivatives, etc. is within their rights but, really a dick move but, considering this commit message, not surprising.

  • As I mentioned in other comments, I am a noob when it comes to web-sec; please forgive what may be dumb questions.

    There's nothing to forgive. Asking questions and being curious is how you learn this stuff.

    Is it really just permission rights "over-exposure" issue?

    From what I've read, it's more fundamental than that. It's a basic architecture issue. The datastore was publicly accessible, which it should never be. If they had it setup according to best practices, with an API to proxy access and auth, the datastore's permissions would be of minimal consequence, unless their network was compromised (still best practice to secure it and approach with a zero-trust mindset).

    Or does one need to also encrypt and then decrypt the data itself that must be sent to a database?

    Generally, cloud datastores handle encryption/decryption transparently, as long as the account accessing data has authorization to use the key. They probably also didn't have encryption setup.

    Also, if you have time, recommend any links to web/cloud/SaaS security best practices "for dummies"?

    Here are some more resources:

  • I'd argue that it should not even be done in Dev. Dev, staging/testing, and prod environments should all be as close to one another as possible, especially for infra like datastores.

  • I agree. Some sort of solution is necessary but this probably isn't it.

  • On one hand, yes. On the other, women have, based upon crime statistics, legitimate reasons to avoid putting themselves in a situation where they may be assaulted or murdered for reporting problematic and/or worrisome behavior.

  • Yup. It sounds like they were following security worst practices.

  • Yeah. You also landed on a correct thought process for security. Cloud providers will let you make datastores public but that's like handing over a revolver with an unknown number of live chambers and saying "Have fun playing Russian roulette! I hope you win." Making any datastore public facing, without an API abstraction to control authN and authZ is not just a bad practice, it's a stupid practice.

  • You've got the right ideas. Noone should ever be storing any password in plaintext. It should always be hashed and only the hash stored. That's like WEBDEV99 (remedial course, not even 101).

    Really. Despite your stated "noobishness", you basically landed in the territory of best practices right of the bat.

    If you're looking for a good source of best practices, the CIS benchmarks are great. https://www.cisecurity.org/

  • I like type F for the symmetry. However, type K is smiling.

  • No. Conservatism has always only been about conserving aristocratic/oligarchic socio-economic power structures and establishing them where absent. Those are the only ideals they've ever had. All of the test was just a facade to pretend that their ideology has any place in a free, open, and equitable society.

  • He has too much slaver (for-profit prison) support to even come close to that.

  • Beat me to it.

  • They could be extensions of the scapula. This would make the renditions where pegasus appears to be galloping while flying more accurate.

  • As others have stated, it's general advice. I think that it is worth stating anyway because there is still stigma around mental health conditions and treatments.

    As for curing depression, it really depends on the type and cause of depression. Some people have differences in their brains that cause chemical imbalances that need medication and therapy to address. Some people come down with the mental health equivalent of the flu and need support to get through it. A mental health professional like a therapist or psychiatrist is trained to diagnose and formulate a treatment plan based upon what is observed.

    Depression can be fatal and I've known too many people who've succumbed to it. So, I will always recommend therapy to anyone going through depression, if they can afford it - sometimes sliding scales are available.

  • COBRA is a fucking joke so that they can claim that you have the "option" to get health insurance while being completely unaffordable.