deleted by creator
- 0 Posts
- 36 Comments
Yeah, I’m confused by this video (which is from nearly a year ago, btw). It looks like a gnome shell overview more than anything.
vector_zero@lemmy.worldto
Linux@lemmy.ml•Mozilla Might Finally Enable Firefox's Wayland Backend Soon
251·3 years agoWell good thing I finally realized it wasn’t enabled and set my environment variables to enable it.
vector_zero@lemmy.worldto
Linux@lemmy.ml•What is your favourite floating window manager?
2·3 years agoI’ve run plain ol’ openbox without a desktop environment on top of it, and it’s quite nice. IIRC I also had a standalone status bar application, but I can’t remember which one I used.
There are a couple utility programs (obconf and obkey?) that help to configure everything comfortably.
Based, mostly
vector_zero@lemmy.worldto
Linux@lemmy.ml•Do you need to have a firewall on a linux desktop?
3·3 years agoAnd even then, a properly configured SSHD instance wouldn’t really benefit from a firewall, unless you wanted to block all countries besides your own or something.
vector_zero@lemmy.worldto
Linux@lemmy.ml•Do you need to have a firewall on a linux desktop?
7·3 years agoEvery computer has a bunch of ports (1-65535 if I recall correctly), each of which is a unique entity to which a single service can bind. In layman’s terms, a port is a door that one service is able to answer when someone knocks. By convention, some ports have a specific associated service (80 = HTTP, 443 = HTTPS, 22 = SSH), but there are a lot that you can just use as you deem appropriate.
If you want a service (e.g. a web server) to be accessible, you have to run a service that binds to a known port (e.g. 80), and a client has to reach out to your server on that same port. A firewall sits between your service(s) and any potential clients, much like those steel security screen doors. If that’s closed, nobody gets through on that port, even if a service is bound to that port and is listening for a connection.
As a general rule of thumb, you want your firewall to block as much traffic as possible without breaking something (I.e. blocking one of your public-facing services). If you don’t run any services on your computer (web services, media servers, etc.), you can probably get away with blocking all inbound traffic. without any discernable impact.
Khal looks promising:
vector_zero@lemmy.worldto
Technology@lemmy.world•San Francisco says tiny sleeping 'pods,' which cost $700 a month and became a big hit with tech workers, are not up to codeEnglish
1·3 years agoIt’s expensive because of the concentration of wealth, not the quality of the area. There’s a ton of crime, homelessness, car break ins, etc.
People often leave their car doors unlocked or their windows down to prevent their windows from being broken, but instead they find random people sleeping in their cars.
On the plus side, the weather there is quite nice.
I’m going to cast another vote for a reverse proxy, such as NginxProxyManager. It’s really easy to set everything up, and they’re usually very easy to run in Docker/Podman.
One thing to note: if you end up with a domain with mandatory HSTS, you’ll have to use DNS-based certificate generation rather than HTTP based, since unencrypted HTTP is blocked (chicken/egg problem to get HTTPS working). It’s not hard, but you have to be aware of that limitation.
vector_zero@lemmy.worldto
Linux@lemmy.ml•[solved] How to unfocus a frozen application that grabbed the pointer/keyboard in Xorg?
2·3 years agoAh, I’ve almost always used a single monitor setup, so my use case wasn’t weird enough to break X11. That said. Even Wayland is wonky on my multi monitor setup at work, though that’s probably more a GNOME thing than a Wayland thing.
I do still think the approach they took with Wayland is a tad odd, in that everyone has to implement it themselves. But hey, if it works, it works.
vector_zero@lemmy.worldto
Linux@lemmy.ml•[solved] How to unfocus a frozen application that grabbed the pointer/keyboard in Xorg?
2·3 years agoold
Old doesn’t mean bad
broken
Is it?
unmaintained
Is it?
I use Wayland personally, but I’ve had almost zero issues with X in the last decade, maybe with the exception of minor screen tearing several years back.
The build approval process actually stripped out all comments via a script.
Thanks, Satan.
vector_zero@lemmy.worldto
Linux@lemmy.ml•Run Shell Script without sudo and with special bit permission using suid-wrapper
3·3 years agoOr create a service running with limited access to specific resources, and create an API for users to make requests to that service.
vector_zero@lemmy.worldto
Linux@lemmy.ml•Question: is systemd-homed ready for everyday use yet?
1·3 years agoActually, thinking more about this…
Can you give an example of this grub cmdline bypass? If what you're saying is true, this would be a huge issue. I'd switch bootloaders over something like this.
vector_zero@lemmy.worldto
Linux@lemmy.ml•Question: is systemd-homed ready for everyday use yet?
2·3 years agoThough after a point rubber hose cryptanalysis will become the more pragmatic option for an attacker.
vector_zero@lemmy.worldto
Linux@lemmy.ml•Question: is systemd-homed ready for everyday use yet?
42·3 years agoThat doesn't sound trivial at all.
vector_zero@lemmy.worldto
Linux@lemmy.ml•Question: is systemd-homed ready for everyday use yet?
71·3 years agoOnce that key is loaded in memory anyone with 10 minutes and access to google could trivially unlock your computer in several different ways. It is virtually exactly like having no security whatsoever.
I highly doubt it.
If you have any tips for how I can personally bypass my computer's encryption in 10 minutes without being able to login, I'd love to try my hand at it.
vector_zero@lemmy.worldto
Linux@lemmy.ml•Question: is systemd-homed ready for everyday use yet?
1·3 years agoVery true, which is why it's important to run as few services and have a locked down firewall. Maintaining a minimal attack surface is everything.


Bonus when you disable software flow control: In addition to Ctrl+r to reverse search through commands, you can search forward via Ctrl+s