Skip Navigation

Posts
8
Comments
325
Joined
3 yr. ago

HW/FW security researcher & Demoscene elder.

I started having arguments online back on Fidonet and Usenet. I'm too tired to care now.

  • No, the difference in the replication crisis between the soft "sciences" and the hard is enormous. The soft are basically producing results equal to making coin tosses.

  • I don't consider Psychology to be a scientific discipline - I belong to the hard sciences crowd.

    My wife is a psychologist.

  • 50% of all published papers in Psychology are not reproducible ...

    ssssh

  • 100% correct. There's a whole field of mobile cybersecurity researchers who would be able to name names and show code if this was true.

    The rest of the comment field here saddens me immensely.

  • I went from Seafile to Nextcloud with family file sharing as the primary usage. I'm using the AIO docker installation without issues.

    This might not help, but I never experienced the issues you had.

    (I moved away from Seafile due to - in my opinion - it dying a slow death with less and less support)

  • Had a Tesla Model 3 before, have a VW ID.7 now. They're driven the same and it looks like they both agree about the distances driven.

    FWIW

  • ... and those same men wonder why women find them repulsive.

    Sit and pee.

  • They're very efficient at spreading piss all over the place, yes.

  • Sit and pee.

    Urinals are disgusting.

    /European man

  • Still no. Here's the reasoning: A well known SSHd is the most secure codebase you'll find out there. With key-based login only, it's not possible to brute force entry. Thus, changing port or running fail2ban doesn't add anything to the security of your system, it just gets rid of bot login log entries and some - very minimal - resource usage.

    If there's a public SSHd exploit out, attackers will portscan and and find your SSHd anyway. If there's a 0-day out it's the same.

    (your points 4 and 5 are outside the scope of the SSH discussion)

  • Feel free to argue with facts. Hardening systems is my job.

  • This is not "the correct answer". There's absolutely nothing wrong with "exposing" SSH.

  • A few replies here give the correct advice. Others are just way off.

    To those of you who wrote anything else than "disable passwords, use key based login only and you're good" - please spend more time learning the subject before offering up advice to others.

    (fail2ban is nice to run in addition, I do so myself, but it's more for to stop wasting resources than having to do with security since no one is bruteforcing keys)

  • Breakfast is coffee and toast.

    /Swede

  • There are still server softwares our there that are going to be exposing people's private Mastodon posts.

    You could've saved yourself a lot of typing there by just admitting to claiming things you actually didn't know.

  • If you know of other ActivityPub servers that expose private posts the same way I suggest you make a responsible disclosure to the developers.

    I don't know of any, but you claim they exist so ...

  • You have absolutely no idea what "responsible" in "responsible disclosure" means :) It's completely irrelevant how Mastodon has implemented private posts when it comes to how Dansup handled the issue, knowing what the effects were.

    You don't, when told of a vulnerability, handle it in a way that cause harm if it can be avoided.