• 0 posts
  • 8 comments
Joined 1 year ago
Cake day: June 4th, 2025
  • I’ll go in a slightly different direction but one that any CISO will tell you is just as important as locking down SSH, etc. Have a good backup plan

    Especially for a home server, is your biggest threat vector someone launching 0-days against it or the SD card it boots off of crapping out? Even production servers, when someone misconfigures sshd_config and locks everyone out (ask me how I know) or you get a crypto-locker run because all the configs in the world can’t save you from a supply chain attack. You’ll be glad you have backups on-site, off-site, a general DR strategy, etc.

  • In the US, I largely agree with you. Or use a website from a mobile browser. Different story in different countries where a smartphone might be the only compute the average person has, or where state services are tied to a mobile ID or bank app.

    Not saying that should be the case, but if the choice is between running niche FOSS apps and removing yourself from societal benefits structures, I know what most people will pick. That’s the real danger of allowing one company to own an entire ecosystem and have enough power that they have conversations directly with governments about their people instead of with their people.