loudwhisper

joined 2 years ago
[–] loudwhisper 1 points 1 month ago (1 children)

Plus, at this point why not using directly managed Nextcloud (or alternatives)... If anyway you use a managed storage, runtime and database, in a vendor lock...

[–] loudwhisper 3 points 1 month ago (3 children)

Oh yeah, I am aware. Mostly here I would question the idea to have multi-AZ redundancy and using a manage service for DB (which indeed is expensive). All of this when a 5$ VPS could host the same (maybe still using s3 for storage) and accept the few hours downtime in the rare event your VPS explodes and you need to restore it from a backup.

So from my PoV this is absolutely overkill but I concede that it depends a lot on the requirements. I can't ever imagine having requirements so tight that need such infra to run (in fact, I think not even most businesses have these requirements, I have written on the topic at https://loudwhisper.me/blog/hating-clouds/) for my personal stuff...

[–] loudwhisper 3 points 1 month ago (4 children)

There is no such thing as "neutral" in a war, but facts are facts, and lies are lies. If the position people take means people say lies, you disprove the lies.

From all this word-soup I see that you have effectively not a good example of false reporting from the Kyiv Independent, and you cast a wide net to the whole "western media".

What is an example of neutral media in your opinion that you consider factual and trustworthy?

[–] loudwhisper 23 points 1 month ago (9 children)

Everyone is free to pick their poison, but I have to ask...why? What is the target audience here? This is a massively overkill architecture IMHO. Not to talk about the fact you now need 3 managed services (fargate, s3 and aurora at least) for a single self hosted tool, and that is being generous (not counting cloudwatch, ALBs, etc.).

  • Why do you need security groups to allow egress anywhere (or, at all)?
  • I would pin the image to a digest, rather than using latest.
  • what is the average monthly cost for this infra for you?
[–] loudwhisper 1 points 1 month ago (8 children)

Did they report on those at all?

I searched their websites and I got 0 hits on the Ghost of Kyiv, and 1 hit on Snake Island (this).

[–] loudwhisper 4 points 1 month ago* (last edited 1 month ago)

Someone runs MongoDB unauthenticated, bound on 0.0.0.0 with production data, on a computer without a VPN, and the problem is the WiFi?

Like I get what you are saying, but this sounds like saying that we should ban speedbumps because imagine there is a guy with a loaded gun pointed at a kid with no safe, finger on the trigger, and high on coke, if the car hits the speedbump the toddler is gone. Yeah, but I would hardly say the speedump is the issue.

[–] loudwhisper 4 points 1 month ago

This is not really a common or easy attack, especially for any meaningful service (that is probably in preloaded HSTS lists).

It's not like this is the only shared network. In airports millions of people everyday connect to the same network.

[–] loudwhisper 2 points 1 month ago

That tracking is done in a much more effective and capillary way by tracking cell towers. I think MAC tracking is a much better option, assuming there are enough of these APs to track.

[–] loudwhisper 3 points 2 months ago

Well, windows didn't allow me to do that, so I might have to do a manual process maybe.

Anyway, I am not interested in upgrading, I am just saying that I can't upgrade (click button, couple of steps), without buying a new copy. We can argue about the semantics of what "upgrading" means, but effectively there are going to be plenty of people in my situations, which is why I brought it up.

[–] loudwhisper 4 points 2 months ago

Well, you did call it a "failed experiment", that doesn't sound right when it is the most used OS on the planet, on supercomputers, on servers, on phones.

People answered with a broad response to a broad statement.

Anyway, if this rage is medically induced and this topic seems to trigger you, why not blocking it? I think you can see how you are not going to convince anybody that your experience 20-30 years ago with Linux is applicable today, especially when people with 0 tech skills manage to daily drive a Linux dietro or use it for gaming. So why doing this to yourself?

Researching IED, avoidance for "situations that upset you" seems to be one of the few recommended prevention mechanisms. You will get banned anyway eventually from the community, why not just blocking it in advance?

[–] loudwhisper 4 points 2 months ago (2 children)

Not in all cases. My desktop PC came with windows professional (10), back in 2021. Upgrading to windows 11 is not included for free (not even to windows 11 "basic"), I need to pay a new license.

[–] loudwhisper -1 points 2 months ago

Email is almost always zero-access encryption (like live chats), considering the % of proton users and the amount of emails between them (or the even smaller % of PGP users). Drive is e2ee like chat history. Basically I see email : chats = drive : history.

Anyway, I agree it could be done better, but I don't really see the big deal. Any user unable to understand this won't get the difference between zero-access and e2e.

view more: ‹ prev next ›