UselesslyBrisk

joined 1 year ago
[–] UselesslyBrisk@infosec.pub 2 points 1 year ago* (last edited 1 year ago) (2 children)

As someone that has spent the better part of the week mucking with it.... the kbin build docs have multiple gaps in the documentation and are functionally broken unless you have some better understanding of the setup. I WAS able to get the system built, but could never get it online. Best i got was 500 errors where the UI was up but there was a break somewhere in Redis, Postgres, Nginx etc. All the logs were clean though. This was with the docker method and build from source method on both Ubuntu 22.04 and Debian 11 (which are what he specifically referenced)

Lemmy was much easier to setup using the ansible method. I have an instance online. Though im still working out the federation thing and some other kinks. I figured it would just reach out to Activity pub and federate with everyone but now it seems I have to build a static list...If if search for an instance i know exists I get a

404: couldnt_find_community

So there are some gaps but it seems much more mature. For example you cant mark your instance private AND have federation enabled. If you do that and restart the instance will fail to come up, but theres no warning or error in the UI.

I like the kbin dev better as people. But the lemmy code is definately more polished, even if the devs are turd sammiches.

[–] UselesslyBrisk@infosec.pub 3 points 1 year ago* (last edited 1 year ago)

Browser.feddit doesnt include kbin right? Also it got removed from the main page....couldnt find the link...lol

[–] UselesslyBrisk@infosec.pub 1 points 1 year ago* (last edited 1 year ago)
[–] UselesslyBrisk@infosec.pub 4 points 1 year ago (3 children)

And a single place to find communities.

[–] UselesslyBrisk@infosec.pub 2 points 1 year ago

My truck is white because it’s hot AF outside and it there is a LOAD of difference between dark colors and white in the sun.

[–] UselesslyBrisk@infosec.pub 6 points 1 year ago

Kbins build docs are a nightmare. I have experience with Linux and docker. Can’t get them to work at all. Closest I get are 500 errors and one can’t find a log tossing errors to explain it to save my life.

Maybe I’m not as well familiarized with the parts and pieces as I thought, though I’ve built plenty of Drupal stacks and the like, even using docker and Ansible etc.

Then I look at PRs showing sql injection fixes and XSS fixes and I’m like…oh

[–] UselesslyBrisk@infosec.pub 1 points 1 year ago (1 children)

I haven’t. But now I’ve seen a couple. I believe they did /r/tumbler or something dirty too.

It’s a shame. Totally antithetical to their culture they (Reddit) started and grew with as a freedom of speech platform.

[–] UselesslyBrisk@infosec.pub 5 points 1 year ago (1 children)

mmm. thats debateable.

If theres vulnerabilities in the software, like RCE's or SQL Injections that can lead to access...Cloudflare wont do much for you. For example Kbin has already have PRs for SQL injections and even XSS vulns.

These will get flushed out with time and more people maintaining them of course. But I dont know if I would want that on my personal network even if on a DMZ. If for no other reason than if your instance starts spamming outbound traffic and you get flagged by your ISP.

Heck I had one of my domains flagged by my works Cisco Umbrella instance and the dang thing wasnt even in prod yet.

[–] UselesslyBrisk@infosec.pub 1 points 1 year ago (6 children)

Im surprised they havent just performed takovers of the private subreddits and installed new mods.

Maybe they have but are doing it at a slow pacing, either because its manual or because it may attract less attention.

[–] UselesslyBrisk@infosec.pub 1 points 1 year ago

At this point, considering all the tomfoolery that’s occurred. It’s probably the best after we have painted our selves into a corner.

[–] UselesslyBrisk@infosec.pub 0 points 1 year ago (1 children)

I stopped running my own a while ago. Its no longer really decentralized and the big players (google/microsoft) will often just blacklist you for little reason.

That said I DO maintain my own domain and backups. So i can take my email to whatever hosting provider I want.

I also noticed, during the migration, that if you simply register your domain with one of the big players (ie: Google Workspace or M365) you will often get whitelisted and email will flow easier. This was easier when they had a free tier though.

view more: ‹ prev next ›