[-] fishynoob@infosec.pub 6 points 3 weeks ago

I don't do this, but I would set up oAuth like Authelia or something behind a reverse-proxy and authenticate Jellyfin clients through that.

[-] fishynoob@infosec.pub 5 points 3 weeks ago

Hey, it's nice to talk to you. I've seen you around this community and I like your comments.

I said K8S because I work with it, but if OP doesn't need HA I guess Podman is fine too. I don't like Docker anymore after what they pulled a year or so back

[-] fishynoob@infosec.pub 9 points 3 weeks ago

I came to know about this from another post and so far it seems like an awesome idea

[-] fishynoob@infosec.pub 7 points 3 weeks ago

Your blog is awesome. I have always wanted someone to break down RF homelabbing for me and I think as your blog progresses I will find such content.

I'm also looking for blogs/material on OS hardening (Linux/*nix), do you plan to write on that (and any recommendations)?

[-] fishynoob@infosec.pub 8 points 3 weeks ago

Using a SIM has never been private. Cell phone coverage has always been an instrument of surveillance.

[-] fishynoob@infosec.pub 7 points 3 weeks ago

Coming back to this thread, I do think some of your comments were inflammatory. If you were to receive a ban, it should have been for trying to bring fights in the comments (but even that is ambiguous at best). I agree that the ban for a comment was too much. An admin shouldn't be conflating one such action with overall behaviour. As for "repeated bad-faith behaviour", it is not so far out to ban you I think. People should be responsible for their own actions.

[-] fishynoob@infosec.pub 4 points 3 weeks ago* (last edited 3 weeks ago)

I went through the list. Google and FairPhone should definitely be moved to "Safe for now" whilst OnePlus should be moved to "Requires an online account/sacrifice" as they limited their unbrick utility which means no more custom ROMs for new OnePlus phones.

I honestly don't understand why Chinese companies do this. They would fare much better against their American counterparts (including Samsung) if they allowed for more open hardware. Goes to show that MBAs at the top of these companies have utter dung between their ears

7

I have been looking at hardening *nix servers for my lab and maybe carry some of that over to work. CIS benchmarks are something I like doing but that's barely scratching the surface. What do you do for your servers?

I have Lynis, systemd-analyze, Kernel self protection in mind but I'd love to hear your thoughts. Bonus points for the most paranoid setups!

[-] fishynoob@infosec.pub 5 points 4 weeks ago

I don't think OP made two A records here. He simply configured the reverse proxy to point to the VM and the A record to point to the reverse proxy. In my mind, if NGINX is terminating SSL then the only problem could be ports.

[-] fishynoob@infosec.pub 8 points 4 weeks ago

OP you NEED to tell me how you did this. I want this. I want to host something like character.ai on my own hardware. If you have a guide on this I'd love it.

[-] fishynoob@infosec.pub 4 points 4 weeks ago

Are there guides on this?

[-] fishynoob@infosec.pub 13 points 4 weeks ago

I'll take it. Reality isn't very fun and hasn't been good for a while for me. This is a very good escape. I'll take this over drugs

view more: next โ€บ

fishynoob

joined 4 weeks ago