• 1 Post
  • 548 Comments
Joined 3 years ago
cake
Cake day: June 17th, 2023

help-circle
  • Not the answer to your question, but just something to note with Amazon. They stock many high order generic products, and individual store sellers can list a product as their own, amazon will then part pick from the bin to fulfill the order.
    This often means the brand of the store front is irrelevant to the product you receive. It can also mean stock rotates and the next order you have is almost identical but not quite.

    It can also occasional mean amazon part picker grabs the wrong part when you order a well known brand, as they either just eyeballed the grab or somebody dumped the wrong stock parts in the bin.








  • I have openSUSE on my main machine, with SELinux. They are more security focused by default than some other distros.

    Firewall on by default, SELinux enforcing by default, sudo needs root password-not just passwordless or same user password like some distros. There’s a YAST GUI hardening App so you can see what passes best security practise and what needs attention. Zypper has various patch commands so you see a list of what patches are available, their critical/recommended status, and weather they are installed or unneeded for your setup. Also ability to apply patches by CVE numbers.

    SELinux can be frustrating initially, until you get used to how it works. I.e. I setup shared network folders but couldn’t see data in some folders, it was because copying files into the folder to be served doesn’t automatically give access over the share, there needs to be SEL policy assigned to the files which you establish the policy and then can apply to all files in the folder.



  • BCsven@lemmy.catoSelfhosted@lemmy.worldRaspberry Pi 4B
    link
    fedilink
    English
    arrow-up
    2
    ·
    14 days ago

    Yes, I bought a rocketfish drive enclosure years back, so dropped a drive in that, and attached vias USB. Never had issues with it.

    Assign as data drive in Openmediavault.

    Openmediavault had some plugins and settings to set folders2ram so that the initial SDcard OS is writting to RAM instead of constant writes to the SDcard.



  • BCsven@lemmy.catoSelfhosted@lemmy.worldRaspberry Pi 4B
    link
    fedilink
    English
    arrow-up
    9
    ·
    15 days ago

    There are some sites dedicated to suggestions, or if you download the pi image burner tool it has a bunch of OS suggestions in the menu, like Pihole, Kodi media box, home assistant, etc.

    I have a few running. One was setup as NAS and dlna music server using OpenMediaVault, one is a Volumio music player, my other one is Home assistant.

    If you like old 80s-90s games there is RetroPi.

    Too many choices really :)


  • I recognize its not a firewall like an iron door on your house blocking intruders, its more like the intruders don’t know your address. But it is a layer of security help as per this quote from CISCO

    "NAT is a networking feature that can help reduce organizational security risk by hiding internal networks from public networks. By default, outside public IPs cannot communicate to an internal private IP host if there is no pre-existing NAT translation. So, NAT separates public and private networks.

    Additionally, organizations that use NAT can implement and maintain multilayer security to block threats and protect against malicious activity. Your edge platform may be able to perform these essential security services."







  • BCsven@lemmy.catoSelfhosted@lemmy.worldPassword managers...
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    17 days ago

    The solution to that is you purchase a backup key and enroll both when presented with the QR image for new OTP links, or add a secondary FIDO key on some accounts. Then you store the other one in a fireproof box.

    Or you use a cryptographic key and print it out using shard tool. The shard tool lets you specify how many splits and how many required for a tebuild. It prints out the shards and you distribute to safe places or people. They are useless by themselves but if you scan in the required amount of pieces the tool will rebuild your cryptographic key