• 2 Posts
  • 688 Comments
Joined 1 year ago
cake
Cake day: April 30th, 2024

help-circle

  • Society norms have to be bilateral, and convenient for every member of the society.

    One member of society cannot fuck around not expecting to, eventually, find out.

    This is why we have laws, norms and social customs. So we can live in a society.

    If members of society feel that they cannot longer live next to other members is when society breaks, and, you like it or not, the social pact gets broken.

    You cannot force members of a society to live en the minimum common suffering denominator. To lower everyone standards of living to the one provided by the most annoying member of the society. That’s a highway to the society giving the big F to that member.

    It should be the contrary, society should try to live to the standard of the less annoyance. To avoid bother the most sensible member of the group.

    It’s a everyone loses vs everyone wins situation. We should aim for the later.




  • Is you homelab getting ddosed constantly?

    I had had it for years and never ever got ddosed.

    Are you sure it’s actually ddos and not just the typical bots scanning for vulnerabilities? Which are easy defended for by keeping updated.

    It’s weird as a DDOS is not something that’s just happens, it’s a targeted attack. It’s a rare occurrence that someone decided to attack a homelab.









  • daniskarma@lemmy.dbzer0.comtoTechnology@lemmy.worldPlex got hacked.
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    1
    ·
    8 days ago

    Have to point a dns to the ip, buy a domain, stablish ddns. I don’t see it happening often. If you know all that you are ought to know about getting hitm

    Bot hits are not a problem for jellyfin. The main problem right now is unauthorized access to endpoints for people who know the hash that is being used in that endpoint.

    It’s a targeted attack that hampers availability of the services (making it more available than it should be). It doesn’t make internet more insecure or anything.

    As I said previously I haven’t actually known of any of these attacks happening on the wild. As they are kinda hard of pull of. You need to know the precisely hash used for the endpoint, the most normal way of knowing that without being an authorized user is because you used to be an authorized user and you are not anymore. That’s weird in jellyfin current ecosystem. People say that the hash could be calculated by a complete outsider, but I have never seen anyone pulling it off on the wild. You need to know a lot of things about the service you are attacking to be able to do it.

    So, yes is a security vulnerability, all software have those. But I think it gets blown out of proportion often.


  • daniskarma@lemmy.dbzer0.comtoTechnology@lemmy.worldPlex got hacked.
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    5
    ·
    9 days ago

    Not techie people are not going to be able to open it for internet access. If you have the knowledge to set a internet available service you should have the knowledge to be able to provide basic security.

    Most security issues with jellyfin are an issue only for a specific type of user. The one who is selling access to their server. The worst Jellyfin security issue makes selling access to your server a higher risk situation.

    I hope someday those issues would get patched, but I get why there are other priorities for the dev team right now, about issues that bother to a bigger majority of jellyfin users.



  • While I whish access were secured at some point. I’m still yet to see one of those guessed hash attacks on the wild.

    A good thing about Jellyfin is that we KNOW its insecurities because it’s open source.

    Other software may be insecure like that but you would only know after an incident happens because you cannot audit the source code.



  • I know of a guy that went to a shelter for a dog, and they refused because he works with animals, in a farm. And they just hated him for it, excusing the refusal in “he is just going to use the dog as a dog guard”, when this is not true at all, he already had a dog who is incredibly well treated and loved. But this shelter just hated farms, even this traditional farm which consisted in a 2-3 cows in a natural pasture, and refused to give this guy a dog.

    I don’t know what’s going on with shelters.