bear

joined 1 year ago
[–] bear 8 points 6 months ago

RETURN OF THE KING

[–] bear 7 points 7 months ago* (last edited 7 months ago)

Your response is "why are you doing X, you should do Y"

Because they're right, you shouldn't do X. I know that's not a satisfying answer for most people to hear, but it's often one people need to hear.

If the process must run as root, then giving a user direct and unauthenticated control over it is a security vulnerability. You've created a quick workaround for your issue, and to be clear it is unlikely to realistically cause you problems individually, but on a larger scale that becomes a massive issue. A better solution is required rather than recommend everybody create a hole in their security like yours in order to do this thing.

If this is something that unprivileged users reasonably want to control, then this control should be possible unprivileged, or at least with limited privilege, not by simply granting permanent total control of a root service.

This is ultimately an upstream issue more than anything else.

[–] bear 23 points 7 months ago (11 children)

Refurbished drives get their SMART data reset during the process, they absolutely had more than that originally.

[–] bear 2 points 7 months ago (1 children)

Recent NixOS convert, where has this work of art been all my life

[–] bear 6 points 7 months ago

I've got a Protectli VP2420 running OPNSense at home, which has 4x Intel i225-V 2.5gbe running on a weaker Celeron J6412, and I was able to get the expected iperf performance of ~2.35gbps from some brief testing between two directly connected machines. I didn't really do any deeper testing than that though, and I'm not currently doing any crazy threat detection stuff.

[–] bear 31 points 7 months ago

There's 102 people mentioned in that commit and two of them happen to meet in the comments of a meme thread on Lemmy of all places. I love the Internet.

[–] bear 7 points 7 months ago (1 children)

Motorola has always had some custom additions, it's not running raw AOSP. Unless it's changed in the last year, not even the Pixel can do it. Good to know Moto has apparently had this feature for a while though, wish Google would get it into Android itself so everyone can benefit.

[–] bear 21 points 7 months ago (9 children)

This feature unironically turned me from a decade long Samsung hater into a Samsung shill. The fact that it's still not in base Android is just embarrassing.

[–] bear 23 points 9 months ago (2 children)

Docker is open source, licensed under Apache-2.0. Not really sure what you're talking about.

[–] bear 5 points 9 months ago (1 children)

This is so cozy and giving me some inspiration for my own environment!

[–] bear 4 points 10 months ago (1 children)

"Because I feel like it."

So in other words, because she wants to? As in, "because it's her body and she can do whatever she wants with it"?

[–] bear 3 points 10 months ago

I don't know, that sounds like hard, thankless work that will take years of consistent effort, dealing with countless setbacks and losses but not giving up, before finally achieving our goals of making real and meaningful change. What if instead if that I just don't buy Starbucks, will that work?

view more: ‹ prev next ›