mike

joined 1 year ago
MODERATOR OF
 

I stopped at level 24, but it was super funny!

 

Nein das ist kein Passwort-Tester. Besser! Wer schaffts alle Passwortbedingungen zu erfüllen?

 

cross-posted from: https://lemm.ee/post/3809973

Action by regulator follows £12.7m fine by UK for illegally processing data of 1.4m children under 13

 

Die überwältigende Mehrheit der erfolgreichen Hacks in freier Wildbahn setzen auf menschliche Faktoren. Wie können wir Systeme und Interfaces gestalten, um diese Schwachstellen zu mindern?

Ob Ransomware oder Phishing, APT-Angriffe oder Stalking: Die am häufigsten ausgenutzte Schwachstelle ist der Mensch.

Ein Problem, das nur wenig Forschung tatsächlich angehen will. Stattdessen begnügen wir uns damit, den Usern Dummheit zu unterstellen und menschliche Faktoren der IT-Sicherheit "out of scope" zu sehen.

Zeit, anders über das Problem nachzudenken, denn es gibt einige Interessante Erkenntnisse zu entdecken.

Vortrag von Linus Neumann

1
Lemmy Update 0.18.4 (postit.quantentoast.de)
 

🇩🇪 Wir updaten gleich auf Lemmy 0.18.4. Es kommt zu einem kurzen Neustart.

🇬🇧 We update to Lemmy 0.18.4 and will reboot for it right away

 

Beispiel robots.txt um ChatGPT auszuschließen:

User-agent: GPTBot
Disallow: /
[–] [email protected] 5 points 1 year ago* (last edited 1 year ago) (3 children)

Since your question is quite basic and general, I'll try to answer equally.

  1. Hardware: For a single user instance a Pi 3B+ is sufficient. Still, Lemmy can take up some storage space over time because of the images. So make sure you don't take the smallest SD card you have lying around. I assume you know how install an OS and get basic things running.

  2. Get a domain; there are many providers out there. Consider using a TLD of your country (e.g. .de, .fr). Domains are usually relatively cheap. You're most likely running your Pi at home, so check if you have a static IP address or if you have a dynamic one. First one? Great, go ahead. Second one: Check if your domain provider offers an API to automatically update the DNS record; example provider api.

  3. Have a look at the Lemmy administration docs. Depending on your experience, it is relatively easy to setup. Make sure you understand what you're doing, i.e. first get to know Docker for example, then follow the commands. If you don't understand something, just ask or search online. Lemmy is not very complex to operate, so for every part of the deployment you should be able to find information online.

  4. Set up port forwarding in your router for ports 80 (HTTP) and 443 (HTTPS). You can find information for your specific router online, but for some routers this cannot be done.

  5. Get a SSL certificate for your domain. You can get one for free with Let's Encrypt.

  6. Once you have your instance up and running, I would recommend setting it to "private" first. This way you can play around with your instance or reinstall if something goes wrong without having to worry about federation. Once you've federated (communicated with other instances, e.g. by subscribing to communities of other instances), you really shouldn't reinstall!

I hope this helps you with the first steps. Decide for yourself if you want to deal with maintenance and administration "long term". It's perfectly fine to use other instances and not host Lemmy yourself if you don't feel up to it. After all, there is also a security aspect to consider. If you do: have fun with self-hosting!

 

cross-posted from: https://postit.quantentoast.de/post/23088

🧅 Ihr steht auf Zwiebeln?

Unsere Lemmy Instanz hat ab sofort einen Tor-Mirror! 🥳

Ob er genutzt wird und ob sich der Wartungsaufwand lohnt, werden wir sehen. Aber fürs erste: viel Spaß beim anonymen posten! 🕵️

http://postitlx2byjec2lq3haowhx6x6aa7cwoo4hdplg7vw3meuzxmsh5yyd.onion

 

🧅 Ihr steht auf Zwiebeln?

Unsere Lemmy Instanz hat ab sofort einen Tor-Mirror! 🥳

Ob er genutzt wird und ob sich der Wartungsaufwand lohnt, werden wir sehen. Aber fürs erste: viel Spaß beim anonymen posten! 🕵️

http://postitlx2byjec2lq3haowhx6x6aa7cwoo4hdplg7vw3meuzxmsh5yyd.onion

[–] [email protected] 5 points 1 year ago

That's an interesting question. At the time being, I think the only way is to do regular backups and store them at a friends for example. That way an instance can be restored after the server has been taken.

Really the only way is to not save anything, or perhaps some sort of blockchain for all the comments and posts?

Blockchain is an interesting thought - or maybe something similar to Matrix. All instances have their own copy of a post and sync with each other. That way it doesn't matter if one instance disappears. Though, that would probably not comply with the Fediverse idea? Interesting thought experiment non the less!

[–] [email protected] 8 points 1 year ago (2 children)

I get your point. Then, why not start your own instance with rules that you approve? I know, easier said than done, but that's the nice thing about the Fediverse. Next to the general purpose instances, there are many "themed" ones with focus groups such as musicians, journalists and so on.

[–] [email protected] 7 points 1 year ago* (last edited 1 year ago) (5 children)

You lying to yourself or have unfounded expectations.

Nobody mentioned any expectations hm...

Everything on Mastodon is in plain text, there is no encryption, and servers get mirrored.

That's 100% correct, and I think it's important to explain that to non-techy users.

It’s only the login info that stays with the instance [...]

Technically yes, but I'd cut the "only" because login info includes the users email. So in case of a raid or data breach, I'd like to know about it.

The entire point of why Mastodon was ever started was censor evertbody that has the wrong opinion. Twitter wouldn’t delete people because of what they believe, so Mastodon was developed to ban IP address so only approved speech could exist on the internet as far as they are concerned and can avoid ackniwledging the real world. A high number of people on there, especially the admins, live in cult

I don't know what places on Mastodon you've visited, but that's not the point of Mastodon or the Fediverse in general at all. But we don't have to start a discussion about that since you seem to already have made up your mind about it.

[–] [email protected] 10 points 1 year ago* (last edited 1 year ago)

As far as I know they seize everything if there's a warrant. No matter whether it's relevant for said warrant.

Edit: Sorry, misunderstood your comment; Don't know what the reason for the warrant was.

[–] [email protected] 1 points 1 year ago

Hab dein Post eben erst entdeckt. Für den Fall das es hier noch jemanden interessiert: Ich persönlich kann Ionos empfehlen. Domain und Mail haben über Jahre nie Probleme gemacht. Auch vServer haben mir die beste Erfahrung geboten. Hatte viele Anbieter über die Jahre ausprobiert (darunter Contabo, Strato, ...), aber keiner kam an die Performance und Uptime von Ionos ran.

view more: ‹ prev next ›