• 0 Posts
  • 116 Comments
Joined 3 years ago
cake
Cake day: June 7th, 2023

help-circle
  • As excited as I am for this, it’ll be a while before I can get back to Valheim. My wife and I finished our last run, defeating The Emerald Flame in Ashlands, a couple months back and we’re not ready to deal with the Mistlands and Ashlands again quite yet. We also just enjoy the early game enough that we’d usually rather re-roll to experience the new content than continue an old world.

    I’m also going to be curious to see what, if any changes and tweaks happen to the game with it officially released. In our last playthrough, the Mistlands still suffered from issues dealing with enemies which were slightly off-plane. A situation you cannot avoid in Mistalnds. Also, the particle effects and screen shake for magic were way over-done. Casters basically blind everyone else, but the magic is so incredibly invaluable that someone needs to do it, especially in Ashlands. I don’t know how you’re supposed to deal with the forts without it. Between spawn rates turned up to “yes” and melee weapons which have all the stopping power of a limp dick, the only reliable solution we found was yeeting a couple trolls into the fort with a batch of vines setup to hold the breach.

    I’m also curious about support for mods. It makes sense that they didn’t want to put time into support during early access, but that’s now over. We basically don’t play without the Mass Farming mod and the Better Wisps mod. The former is just a tedium reduction mod and the later strikes a nice balance (for us) between keeping the mists and actually being able to find anything in the mists. The hunt for black cores is tedious enough without being able to see any further than my own feet.




  • I’ve been on several sides of this. As a sysadmin supporting a Windows dominated environment integrating Linux, as a user who wants to use Linux in a Windows dominated environment and in security trying to secure an environment with both Windows and Linux. In short, it depends on the use case, environment and the users’ tolerance for problems.

    The first question which will come up is, “why?”. If you don’t have a good business use case, you should expect to be basically told to go get fucked. I realize that this seems like IT sticking their head in the sand, and it kinda is. But, also realize that you are asking them to take on extra work for nothing more than your own self edification. I have yet to meet an IT department which is so overflowing with time and resources that they want to take on new work which isn’t required. Even with the most basic use cases for Linux, IT is going to need to have resources dedicated to support, maintenance and oversight. Things like asset management, patching and license management don’t go away on Linux systems. Sure, the OS may not have a license to worry about (unless it’s RHEL or Ubuntu Pro), but there may be other software installed which is licenses and that license may be a different SKU on Linux. Then there are issues with ensuring IdM works on that flavor of Linux and supporting it when it breaks.

    Along side that “why” question, be ready to answer the “why not” questions. Why not a Windows based alternative? Why not Cygwin/WSL? Why not a Linux based server that you SSH into from your main Windows desktop? Especially with a lot of workloads moving to the cloud, I’ve seen the mainframe model start to return, just with Linux instead of Unix/AIX this time. This sort of thing centralizes a lot of the IT headaches into a single host (or handful) which can much more easily be centrally managed. And that’s a theme to keep in mind, IT departments love centralized management. This is one of those places where Linux kinda lags Windows. Centralized management does work on Linux. It’s one of the reasons RHEL is all over the place, Satellite is like crack for IT departments dealing with Linux. But, a lot of centralized management looks like a folder full of Ansible scripts. With proper code management, it can work quite well. Keep in mind that many folks in IT are not coders and for a handful of Linux systems, dedicated resources which can handle that may not be in the budget (in the end, everything is about money).

    Ok, so you have your “why” and are ready for “why not”. Let’s talk about the security stack. No, just because it’s Linux doesn’t mean you can ignore security. I’ve personally worked cases where Linux boxes got popped. And from the user side, things like ClickFix attacks are starting to crop up targeting Linux desktops. So, does your company’s software stack support Linux? This has, thankfully, started to be more common. Go back a decade and the answer was almost certainly, “no”. Partly because Linux wasn’t that common and partly because idiots believed Linux was fully secure by design. Anyone who believes that today shouldn’t be allowed to work on anything more advanced than an Etch-a-Sketch. With the dominance of Linux in the cloud, attackers are targeting Linux and your system will need to be ready for it. If your company’s security stack doesn’t support Linux, and/or your security department doesn’t have the expertise to monitor and respond to issues on Linux systems, you might find them resistant. Thankfully, that whole “Linux dominating the cloud” thing has started pushing security teams towards supporting Linux. And more advanced security teams often utilize Linux themselves in some capacity. So, that could ease your path a bit.

    The final bit might be your tolerance for pain. If you’re out there on the bleeding edge, trying to be the first Linux system in an all Windows environment, expect things to break. No matter how well planned the rollout, the fact that the IT department hasn’t done this before means that they are going to miss stuff. It happens. If your system becomes a common source of trouble tickets, IT leadership may try to pull the plug. If you turn out to be a high maintenance user, you might find IT slow to respond and unwilling or unable to help with things aren’t working quite right. Some level of self-help and patience with a help desk which doesn’t have Linux expertise are going to be necessary. You really don’t want to become the phone number which pops up on the Help Desk queue and all the analysts scramble to avoid taking the call.

    To conclude this long ramble. Linux systems in a Windows dominated environment is getting easier. That “the cloud” basically runs on Linux has gone a long way into getting Linux integrated into Windows environments. Microsoft has been forced to make their tools actually work with Linux, rather than the abomination which was setting up POSIX uids in a Windows 2000/2003 Active Directory domain. But, a lot of IT departments will still want to treat Linux as a server OS and not a desktop OS. MS Office, Teams and the rest of their communications and collaboration software still treats Linux as a pariah. Integrating and supporting Linux alternatives means budget and resources which aren’t dedicated to the core business. And that’s really what IT is going to care about.


  • Along side what you mention, I work for a company with a lot of engineers from multiple disciplines. Linux is everywhere in our environment and has been growing. Most of our engineers either have a Linux laptop, use Linux virtual machines or submit jobs through Linux backed software stacks. Our products have tools built on Linux to the point that we used to maintain our own Linux distribution to make having all those tools on a system easy, though we’ve just moved to having scripts to install and setup everything. Almost all of those engineers also have a Windows laptop as their daily driver. The few who don’t have Macs.

    I don’t doubt that organizations can move to all non-Windows, but the Windows Ecosystem of Exchange, Office and Active Directory/Entra is very hard to replace. Yes, you can absolutely cobble together alternatives. But, you then have a special snowflake of an IT infrastructure. Maintenance may be eased by the use of tools like Ansible, but even that will likely result in organization specific playbooks and scripts. But centralized management of a Linux environment isn’t quite as standardized yet and so requires more planning and effort. And then there is the challenge of security.

    Folks like to tout the inherent better security of Linux. As someone who works in Cybersecurity daily, I fully agree with that assessment. However, “better” isn’t “perfect”. You still need vulnerability management, monitoring and response tools. And this is an area where Linux lags behind Windows, mostly because of the effort put into it. Something as basic as Endpoint Detection and Response (EDR) on Linux is still a foreign concept to a lot of folks. And yes, it’s absolutely necessary. I’ve personally worked cases involving compromise of Linux systems and Linux specific malware. And more than just XMRig clone #5374. It may be harder to move from user to root on Linux than moving to local admin on Windows (unless some jack-off decided that Linux doesn’t need updates and DirtyCow still worked); but, there is still a lot of damage which can be done without root.

    Overall, I’d say that the Linux ecosystem is evolving. It’s already embedded in a lot of environments of all sizes, but it’s usually a smaller part of a much larger Windows network. Hopefully, if enough large organizations start pushing away from Windows and towards Linux, there will be more investment and standardization. And, we’ve already seen some of that. Red Hat is a common distro of choice for large organizations because of that higher level of centralized control and standardization. Of course, a lot of the tools engineers want to use aren’t on Red Hat, specifically because of that centralization (read: everything AI). So, it will be interesting to see where we land.




  • All of the above.

    Is it that ISPs are being paid by tech-bros to assign them these IPs?

    Bullet Proof Hosting is a thing. Some ISPs basically advertise to criminals about their ability to evade take down orders and unwillingness to work with law enforcement. So, some infrastructure ends up on these devices. However, the IP ranges from these services often get discovered and are added to public reputation and block lists.

    Along side this, cloud providers are pretty bad about policing their networks. On my own home server, I have blocked much of the Digital Ocean IP space, as it’s home to a lot of scanners, bots and other malicious traffic.

    Is it that residential devices have been hacked /contain malware that does this?

    This happens, a lot. The Mirai Botnet thrived on compromised home routers. People are pretty bad at updating their devices and many SOHO routers ship with some pretty bad vulnerabilities. It’s only a matter of time until someone finds an unpatched or misconfigured router and adds it to a botnet. People also get phished or install trojans all the time, adding to botnets. Darknet Diaries just had a fantastic episode on the Bayrob malware, part of which was turning infected machines into a custom botnet.

    Is it trivial for companies to assign themselves residential IPs?

    Some ISPs just look the other way when they get reports of malicious activity on their network. Also, attackers can force a DHCP refresh and just get a new IP when the old one seems blocked. Getting one in the first place is often as simple as signing up for service and/or compromising someone’s home PC and using it as a relay.

    Paid volunteers are doing this for AI companies?

    This probably happens. Afterall, we’ve already seen a company selling an AI product which was just workers in India.

    Obviously this is a problem because one can rotate / cycle through residential IPs and if I aggressively block each offender in my logs permanently, then the next person assigned this IP who may be a legitimate user will be unable to access my site.

    Look into Fail2Ban. This program monitors your logs and will ban IPs automatically based on criteria you set. This can include specific HTTP requests in your web logs. The ban can be permanent or can be time limited. For example, I have a container running in a cloud provider which I use to proxy requests through my ISP’s CGNAT setup. There is an NGinx reverse proxy running there and I have fail2ban watching the access log. If certain request strings are seen, the sending IP gets dumped in a permanent jail. I also have it scanning the sshd logs and banning IPs which fail to login 3 times within a short period.

    It’s far from a silver bullet, but it’s something which should be running on any web facing system. Attackers will always be rattling the door knobs. There is no reason to let them keep rattling away.




  • Thanks for sharing.

    But, please stop using the curl command piped into a terminal pattern. Malicious actors have been abusing the fuck out of this pattern ever since the idiots at Anthropic decided that would be the official install pattern for Claude. I’ve been cleaning up infections based on people just blindly running shit like that constantly over the last couple months.

    Folks, never run a random script from the internet, without being sure what you are actually about to run. If using AUR packages is considered risky. Random scripts being piped into a terminal ranks right up there with sticking your dick in a blender.


  • One of the traditional ways to do this is to stand up a reverse proxy (e.g. NGinx) That then sits on ports 80 and 443 (you’ll want TLS for NextCloud) and forwards traffic to those applications. If you are using docker for everything, you can have a back-end docker network where the NGinx container forwards traffic to the PiHole and NextCloud containers. And since each container is its own entity, you don’t need to worry about mucking about with the ports for the different services, they can each have ports 80/443 on their own container and you don’t need to worry about forwarding those ports from the host. Though, if PiHole is running on the hardware and not in a container, this can complicate things.




  • The just stopped working was the client stopped syncing?

    The client doesn’t seem to detect new photos as they are created/taken. If I manually upload an image from my photos folder, it syncs just fine. Files in other folders seem to sync just fine. But, photos and videos just never even try to sync.

    NextCloud decided to stop allow private made certificates with its client in 2025 and its what made me switch.

    This hasn’t been an issue for me. I pay for a domain and have a certificate issued by Let’s Encrypt. The only certificate errors I get are when I refresh the certificate every 6 months, and that’s just the client asking me if I want to trust the new certificate.

    Syncthing

    I had looked into this a while back, but it seemed to be more of a point to point solution and not a client-server system. I was aiming to have an authoritative server with everything and clients (both phone and desktop) able to pull the needed/request files. I also like the ability to share via a web link when needed. Am I wrong in that understanding?


  • I currently use NextCloud, but I have been looking to move away from it. My main use case is for syncing photos and videos to the cloud from my phone (Android) and this used to work flawlessly. But, some time in early 2025, it just stopped working. I can still manually upload files and sync still works for other folders (e.g. Documents) just fine. But, photos and videos just won’t sync automatically. Not sure if there are other options which would work better, but NextCloud on Android just seems to be broke.


  • LinkedIn is basically a public resume. Using it for anything more demonstrates that you do not have a basic grasp of privacy or security. As such, there shouldn’t be anything up there which is all that bad to have leaked. Sure, if the password database gets dumped, rotate your LinkedIn password (it should already be unique, so no worries about it being reused elsewhere). And having an email address get added to every spam list everywhere kinda sucks. But, what else is the attacker going to get, my name and work history, which are already public on the site?

    I mean, yes LinkedIn should be raked over the coals for shit security practices. And we really need something like the GDPR here in the US to actually do that. But, I’m also not going to get terribly worked up about my public CV being leaked. The leak is kinda redundant.



  • Microsoft’s partner portal website mysteriously said his account had been deactivated, without specifying why.

    My money is on Microsoft’s AI based detections causing false positives again. I spend way too much time chasing ghosts from Defender. Their machine learning based signatures are especially egregious. You get an alert with a name like “Win32/Wacatac.b!ml”. That last “ml” bit denotes that it’s machine learning based. And then you get fuck all to help you determine why the alert fired. Sure, it might actually be a trojan. More likely, it’s a false positive. But who knows, because Microsoft won’t provide enough information to perform a reasonable analysis of the binary.

    And MS has been pushing CoPilot hard. It’s in everything and it’s happy to slop up answers for you. The accuracy of those answers though can be a bit spotty. I’d certainly never turn it loose on tools which can have business impact. But, I doubt Microsoft has any such reservations about letting CoPilot slop all over third party devs.