Don’t stick your dinky were you wouldn’t stick your pinkie
$argon2id$v=19$m=64,t=512,p=2$DP574tIq9T8sEscj6Jvj7g$it63tsz/4vnM6CwIFtYjSA
Don’t stick your dinky were you wouldn’t stick your pinkie
Please do not fap into your coffee grinder, it’ll really increase the retention with all the stickiness. I fear you may have confused grinder with Grindr here
Fantastic grinder, got one a few months back and absolutely love it. Has a few quirks and I can never not laugh at the bellows, but produces generally tasty coffee with minimal dialling in
Turns out knives you can eat a surprising number of before it kills you
Account of a Man Who Lived Ten Years, after Having Swallowed a Number of Clasp-Knives
I don’t know if there’s any legal implications, but morally it’s pretty abhorrent. The question I’d be asking is would you even want to work for a company that engages in that type of tactic, especially since they’re likely to repeat that kind of nonsense after you’ve started the job.
I would have also put 20 down on an expired certificate
Whilst I agree on the glue records, DNSSEC is most definitely included as standard (check my domain itsg.host which is on a free account)
That I very much agree with, CloudFlare is great, but it certainly isn’t for every use case nor should it be. Thats kinda the entire point I was trying to make.
I think it’s also worth bearing in mind there that the average fedi user currently is well aware of the lack of platform level moderation, both the good and the bad that come with that.
Took 4 takes for me to finally work out what it said
Well I was expecting some form of notification for replies, but still, seen it now.
My understanding of this is limited having mostly gotten as far as you have and been satisfied.
For other bouncers, there’s actually a few decisions you can apply. By default the only decision is BAN
which as the name suggests just outright blocks the IP at whatever level your bouncer runs at (L4 for firewall and L7 for nginx). The nginx bouncer can do more thought with CAPTCHA
or CHALLENGE
decisions to allow false alerts to still access your site. I tried writing something similar for traefik but haven’t deployed anything yet to comment further.
Wih updates, I don’t have them on automated, but I do occasionally go in and run a manual update when I remember (usually when I upgrade my OPNSense firewall that’s runs it). I don’t think it’s a bad idea at all to automate them, however the attack vectors don’t change that often. One thing to note, newer scenarios only run on the latest agent, something I discovered recently when trying to upgrade. I believe it will refuse to update them if it would cause them to break in this way, but test it yourself before enabling corn
I once spent a good portion of a marquee club event sat on top of some Nexo Alpha S2 subs watching the chaos unfolding before my eyes (I distinctly remember something about a rubber horse head mask). Apart from not being able to feel my arsehole for a week afterwards, the power of the sub with the writhing mass of bodies was almost mesmerising
At least it’s still on brand, the content seems about as random
If you want a truly privacy respecting option (because self hosting), I’ve been using https://cactus.chat which is great. I specifically use it on my streaming setup as it’s real time as well to boot.
You can use a custom origin certificate, but that’s irrelevant when CloudFlare still re-encrypt everything to analyse the request in more detail. It does leave me torn when using it, I don’t use it on anything where sensitive plain text is flying around, especially authentication data (which is annoying when that’s the most valuable place to have the protection), but I do have it on my matrix homeserver as anything remotely important is E2EE anyway so there’s little they can gain, and with the amount of requests it gets some level of mitigation is desirable
Seconded, not only is CrowdSec a hell of a lot more resource efficient (Go vs Python IIRC), having it download a list of known bad actors for you in advance really slows down what it needs to process in the first place. I’ve had servers DDoSed just by fail2ban trying to process the requests.
I can assure you, that’d very much be in scope as a potential target, they’ll probably just use this as justification
I’ll preface them by saying this is me being critical of it, it is otherwise very good: