

Agree, this is exactly what I went with recently in the same situation.
HW/FW security researcher & Demoscene elder.
I started having arguments online back on Fidonet and Usenet. I’m too tired to care now.


Agree, this is exactly what I went with recently in the same situation.


All services are dockerized, updated nightly.
Server OS runs a kernel-patch service for real time exploit patching.
All other updates as soon as they appear.
Yeah, sometimes I’ll need to go in a repair - but that’s way better than having to clean up after having been exploited due to not keeping up on security patches.


Yeah it seems nobody understands this.
Bunch of different zigbee ones. Zigbee-only means they’re guaranteed to be local and I’ve had no issues with my Deconz-based zigbee network for many years.


Will Nextcloud run apps not marked as compatible with that version?


nycjournals.com seems to be an influence operation. The domain is a month old and the about section contains nothing that actually tells you anything about what’s behind the site.
edit: That means this is likely a false story unless corroborated by another source.
Epstein probably would have intentionally avoided making such a list, which would also incriminate himself and could possibly get him killed
Exactly. If such a list existed he would surely not survive long in jai … oh
So? Pubkey login only and fail2ban to take care of resource abuse.


Volkswagen is doing really well. No idea why the headline would point out Chinese EVs specifically.
/switched to VW ID.7 from Tesla Model 3


Yeah, I mean, are we sure he’s really born in the USA?


I went from Seafile to Nextcloud with family file sharing as the primary usage. I’m using the AIO docker installation without issues.
This might not help, but I never experienced the issues you had.
(I moved away from Seafile due to - in my opinion - it dying a slow death with less and less support)
Still no. Here’s the reasoning: A well known SSHd is the most secure codebase you’ll find out there. With key-based login only, it’s not possible to brute force entry. Thus, changing port or running fail2ban doesn’t add anything to the security of your system, it just gets rid of bot login log entries and some - very minimal - resource usage.
If there’s a public SSHd exploit out, attackers will portscan and and find your SSHd anyway. If there’s a 0-day out it’s the same.
(your points 4 and 5 are outside the scope of the SSH discussion)
Feel free to argue with facts. Hardening systems is my job.
This is not “the correct answer”. There’s absolutely nothing wrong with “exposing” SSH.
A few replies here give the correct advice. Others are just way off.
To those of you who wrote anything else than “disable passwords, use key based login only and you’re good” - please spend more time learning the subject before offering up advice to others.
(fail2ban is nice to run in addition, I do so myself, but it’s more for to stop wasting resources than having to do with security since no one is bruteforcing keys)


If they indeed used personal phones of regular consumer brands then … yeah, I assume zero day exploits would indeed have been used to gain persistent access. It’s at least in the realm of the possible.


I went from Emby to Jellyfin as they started their enshittification journey. I don’t really notice it being less polished.


So what was the effect of their non-vote with regards to “racists and billionaires”. Did they do better or worse than they would’ve under Harris?
No one in the us ever looks at how things work in other countries, right?
While we don’t have the exact same mortgages setup in the EU, it’s not in any way uncommon for our house loans to not be realistically paid down during one’s life time. Yeah, we indeed refer to it as renting from the banks.