maus

joined 1 year ago
[–] maus@sh.itjust.works -1 points 1 year ago (2 children)

Tankie gonna tank

[–] maus@sh.itjust.works 2 points 1 year ago (1 children)

Tell me you're a tankie who doesn't know what communism is without saying it directly holy fucking shit

Why are there so many brain dead takes in this thread? Who the fuck can possibly believe that communism can't be communism if it's "invited"?

[–] maus@sh.itjust.works 4 points 1 year ago (1 children)

We can hold someone responsible for their own actions while still acknowledging that people are a product of their own environment and try to study and address the underlying societal/economic conditions that led to these situations occurring in the first place.

[–] maus@sh.itjust.works -4 points 1 year ago

Tanker gonna tank

[–] maus@sh.itjust.works 1 points 1 year ago* (last edited 1 year ago) (1 children)

Does skip intro not require everyone to have pass? Yes it does, https://support.plex.tv/articles/skip-content/

Also app installs requiring either a 1time unlock per user or the end user to have plex pass? Yes it does

[–] maus@sh.itjust.works 0 points 1 year ago (4 children)

Most benefits require both the server user and the end user to have Plex Pass.

Personally I prefer Emby or even Jellyfin over Plex.

[–] maus@sh.itjust.works 1 points 1 year ago (1 children)

Just use Cloudflared then, no need to port forward. Or use a VPN with port forwarding and a dynamic dns

[–] maus@sh.itjust.works 5 points 1 year ago

Personally I trust Bitwarden more than myself to keep all my passwords secure AND available. They've got a good track record as far as I'm aware.

For general security hardening though...

I use Shodan to help me identify if anything is misconfigured and what is visible from the web. You can pick up an account for usually $1 for life when they run a deal, then you can just monitor your DDNS, domain, and IP address and have it email you when any new services are detected.

Cloudflare Tunnels, to remove the need for a nginx reverse proxy (with the added benefit of easy failover as well as simplifying your stack). Then I'm utilizing Cloudflare's WAF to handle filtering out known malicious, foreign IP addresses, and other malicious traffic.

Another route you can go is a Nginx/haproxy reverse proxy behind something like Suricata. Then you can utilize something like fail2ban or crowdsec.

Authentik. Get everything behind a SSO experience and don't expose your backend services to unauthenticated local traffic (utilize http basic auth with header passthrough in authentik). So many people setup auth wrong and then have something like auth.domain.com going through auth but then mistakenly have their external IP address setup to allow traffic in authenticated.

[–] maus@sh.itjust.works 3 points 1 year ago

Pretty scummy overall, but average user probably doesn't understand the drives could fail at any moment and that the older the drives age the more likely it will fail.

Regardless though, it would better serve to warn users to have a backup of their data than just a blanket age-shaming.

view more: ‹ prev next ›