markstos

joined 1 year ago
[–] markstos@lemmy.world 2 points 15 hours ago

At one time there were browser extensions that allowed you to comment on any web page and allowed other extension users to see your comments.

The comments were hosted through the extension and not on the pages themselves.

Something like that would be possible but I don’t know anyone offering it now. I presume no one wants to moderate that.

[–] markstos@lemmy.world 20 points 2 days ago (1 children)

I had a friend who liked to sulk around in a trench coat. He bought a grocery store donut and promptly tossed the receipt.

He was soon stopped by grocery security for theft. After some hassle they tracked down his receipt and let him go, but yeah that’s what donut receipts are for.

[–] markstos@lemmy.world 4 points 3 days ago

This coverage provides an example of what is sent, and it includes neither MACs nor HDD serial numbers.

https://ostechnix.com/manjaro-data-donor/

[–] markstos@lemmy.world 2 points 3 days ago

After Ubuntu for many years I switched to Arch because they packaged a number of things I wanted that Ubuntu did not.

If you are happy with Ubuntu stick with that. I have friends and family that use it and it’s fine.

[–] markstos@lemmy.world 2 points 4 days ago

Good example. It’s true that an even a GET request not designed to mutate data might still fail to validate input, allowing a SQL injection attack or other attack that escalates to the privileges that the running app has.

[–] markstos@lemmy.world 3 points 4 days ago

This has to be the cheapest coiled split-keyboard cable option. Creative !

[–] markstos@lemmy.world 4 points 5 days ago (1 children)

Immich has a whole set of end-to-end automated tests to ensure they don't accidentally make public any URLs they went to be private:

https://github.com/immich-app/immich/tree/main/e2e/src/api/specs

As a popular open source project, that would be e glaring security hole.

Using this proxy puts the trust in a far less popular project with fewer eyeballs on it, and introduces new risks that the author's Github account is hacked or there's vulnerability in he supply chain of this docker container.

It's also not true that you "never need to touch it again" . It's based on Node whose security update expire every two years. New image should be built at least every two years to keep to update with the latest Node security updates, which have often been in their HTTP/HTTPS protocol implementations, so they affect a range of Node apps directly exposed to the internet.

[–] markstos@lemmy.world 1 points 5 days ago

Yes, there are broken uses of the HTTP protocol verbs where filtering to GET won’t work.

[–] markstos@lemmy.world 8 points 6 days ago (11 children)

A simpler way to protect a private service with a reverse proxy is to only forward HTTP GET requests and only for specific paths.

It’s extremely difficult to attack a service with only GET requests.

The security of which URLS are accessible without authentication would be up to immich.

[–] markstos@lemmy.world 3 points 6 days ago (1 children)

Some kind of horizontal deflection — a curve to the side can still be used to slow bikes near an intersection. But here the original design practically required getting off the bike to go through it, while the path around it will hardly slow bikes at all. So both attempts were failures.

Here’s example of a newly constructed protected bike lane which curves as it approaches an intersection to slow bike traffic.

[–] markstos@lemmy.world 2 points 1 week ago

I think you may be looking for a programmable keyboard.

With one, you can have arrow keys on the home row like vim, and make other universally recognized keys easy to reach including Home, End, PgUp, PgDn, App (right click), and all the modifiers. Some also build pointing devices into the keyboard as well.

I primarily use the Unicorne by Boardsource.

[–] markstos@lemmy.world 2 points 1 week ago

That’s something! But it doesn’t raise any money from people with other VPN providers or who don’t want to buy a VPN service.

 

It is reportedly plug-n-play for basic features, but for more advanced features, something like this project would need to be patched to add support for the camera.

https://github.com/samliddicott/guvciew-meet4k

 

If you have been using an ergonomic mechanical keyboard for more than year, let us know which keyboard it is, and whether you plan to keep to keep using it for at least another year or if there's another keyboard you are considering trying instead.

 

I have a Logitech C920 and am looking to upgrade. Something suitable for streaming.

Some annoyances with the Logitech: sometimes autofocus fails and poor reproduction of blacks. Ex: Lack of detail when a black cat is on screen.

I already have a nice mic-- the webcam doesn't need one.

 

I'm looking for a simple sendmail replacement to receive local mail, such as from cron and service failures and forward it to on to a real SMTP server.

I have used msmtpd successfully but thought I'd ask if folks have other solutions they like.

 

And then I moved colon and semicolon to layers and re-assigned that outer pinky key to my rarely used AltGr key.

view more: next ›