freedinosaur | 3 years ago | on: CVE-2022-41924 – tailscaled can be used to remotely execute code on Windows
freedinosaur's comments
freedinosaur | 3 years ago | on: CVE-2022-41924 – tailscaled can be used to remotely execute code on Windows
Now I feel less crazy for not using Tailscale SSH for similar reasons.
I'd like to see a security evaluation of Tailscale, on a per feature basis.
I'd like to see tailscaled run with far fewer privileges.
Is there a Tailscale alternative that just does Wireguard + NAT traversal and doesn't try to do key management?
freedinosaur | 3 years ago | on: Linux boot partitions and how to set them up
TIL! My NixOS configuration just got a little bit simpler, and more uniform between machines.
freedinosaur | 3 years ago | on: Linux boot partitions and how to set them up
freedinosaur | 3 years ago | on: Hard User Separation with NixOS
freedinosaur | 3 years ago | on: Hard User Separation with NixOS
Typos:
Specialisations will allow me to run a stable and canary track, one per generation.
freedinosaur | 3 years ago | on: Hard User Separation with NixOS
In theory I could manage this with git rebasing and/or tagging, but in practice I lose confidence in whether I've accurately tracked.
With specialisations, I'd comfortably commit an experimental change to my canary track, even though it might break, safe in the knowledge that the stable track continues to boot.
freedinosaur | 3 years ago | on: Hard User Separation with NixOS
I plan to use this for testing changes to my boot units.
In theory, plain old generations allow you to safely test changes to boot units, by allowing you to jump to the previous generation. In practice, this involves remembering which generations have known-good boots.
Specialisations will allow me to run a stable and candy track, on per generation.
What other usecases do specialisations improve?
freedinosaur | 3 years ago | on: GitHub: High-impact package maintainers now require 2FA
A high-impact package on another forge wouldn't be subject to the same constraint.
freedinosaur | 3 years ago | on: A configuration management system for computers that are pets, not cattle
https://discourse.nixos.org/t/documentation-team-flattening-... aims to flatten the learning curve for NixOS.
freedinosaur | 3 years ago | on: SourceHut terms of service updates, cryptocurrency projects to be removed
Sourcehut is open first, so all is not lost: those excluded could host their own.
On balance, I'm looking at alternatives, but might stay.
freedinosaur | 3 years ago | on: Ask HN: How many are switching to Mastodon?
The bailey: Twitter censoring NY Post during election time.
Disclaimer: I don't follow US politics, but do follow online censorship.
freedinosaur | 3 years ago | on: Ask HN: How many are switching to Mastodon?
Facebook Messenger < Signal < XMPP. I have a few stragglers on FB Messenger, but don't have the app installed.
Facebook Marketplace < Gumtree. Gumtree at least is searchable without an account.
I subscribe to Mastodon and Twitter accounts via RSS.
Github < Sourcehut: I only use Github for contributing to other repos.
Mobile Linux > Open app stores > closed app store: WIP. :)
I don't think it offers authn/authz, but that's fine: neither does my ISP. I just want SSH reachability.