(They/Them)

This is my main lemmy account.

Admin of lemmy.cloudhub.social

I can also be found elsewhere on the fediverse at @jax@cloudhub.social

  • 9 Posts
  • 70 Comments
Joined 1 year ago
cake
Cake day: June 2nd, 2023

help-circle


  • Just because it’s not public facing doesn’t mean that it’s not an issue. It might be less of an issue, but it is still a massive vulnerability.

    All it takes is one misconfiguration or other vulnerable system to use this as a jumping off point to burrow into other systems. Especially if this system has elevated access to sensitive locations within your network.



  • Your best bet is going to be a 4U chassis. You can get 2U chassis with consumer PSUs, but they are going to be more expensive and very limited in terms of parts that will work. You can easily find 4U chassis that support regular ATX internals with proper mounting holes for the PSU and mobo standoffs.

    There are some small SuperMicro servers that use Xeon-D (I think? Very low power Xeons that are passively cooled), but you’re pretty vendor locked in with those.

    Do not use external drives for this. TrueNAS doesn’t support it, and you’ll be limiting your speeds to that of the USB bus, which is not nearly as fast. Pointless going SSDs if you are using external drives.



  • I don’t think it’s worth the devs’ time to implement e2ee for DMs, there are lot of other things that need to be fixed first. Not only that, but if it’s implemented in Lemmy, it’d make Lemmy non-interoperable to DM users from other federated platforms such as Mastodon or KBin. Which, I’m not sure works right now, but in theory would be possible.

    Also, yes, that is generally the case.


  • I highly doubt it will, there are many much better solutions available, and as it says when DM’ing someone, you can you Matrix for e2ee. In fact, there is even an option in the profile settings to provide your Matrix username.

    Implanting e2ee within DMs is massive scope creep and also really difficult to do properly.

    The general rule is basically “never implement your own encryption/security, just use what’s already been implemented by people who actually know encryption/security”.