Lettuce eat lettuce

Always eat your greens!

  • 6 Posts
  • 372 Comments
Joined 3 years ago
cake
Cake day: July 12th, 2023

help-circle

  • Well, we all know how this ends…

    It’s a really sad day for me, I love Bitwarden, it’s easily the best password manager I’ve used, and I’m in IT, I’ve used a bunch.

    Fuck private equity, fuck it to death. But until then, I’ll be moving my test setup for KeyPassXC into production over the coming weeks and months.

    I was happily subscribed to Bitwarden for years for my personal account, I moved several people and a whole company onto it’s platform. We had a good run, time to move on.





  • Mixed for us, some of the new hires are quite experienced, some are kids straight out of school. Overall a younger crowd, (mid 20’s - early 30’s)

    It does require a lot skills-wise though, and it’s the most intense team in our department IMO. They are always on-call and constantly dealing with high priority threats. I wouldn’t want that kind of pressure all the time personally, but they make a good chunk more money than I do as a sysadmin, so there’s positives and negatives.


  • From their own documentation:

    opening and re-saving a document renders the same for 307 of the 309 files in the psd-tools test set and 169 of 170 in our mixed ag-psd/psd-tools set

    Just what I want in my editing software, the assurance that my saved files will mostly render properly when reopened in the same program…

    This is exactly what will sink any attempts to do similar things, it’s not the broad functionality of the software, it’s all the billions of edge cases.

    The LLMs will be able to get all the general requirements mostly right, and that’s where it will stop. The subtle errors and bugs will pile up steadily as the codebase grows too large and complex for even frontier models to accurately summarize, and the people who vibed it to begin with don’t actually understand what is happening, so they can’t troubleshoot effectively.

    Automated bug reports will pile up, agents will be dispatched in greater numbers, leading to cost issues and further complicating and compounding the errors in a bloated and convoluted codebase. The leads of the project will get burned out and abandon the project, leaving a giant, rotting, husk behind. Software that was forever, “almost working properly.”







  • There are different reasons to run different things. Some apps are not able to be run as containers, or don’t make sense to run containerized.

    VMs offer better isolation between systems, which is important for high-security applications.

    Traditional Hypervisors also allow you to easily run fleets of completely different OSes on the same hardware, which you can’t do with containers.

    On the other hand, if you want/need high scalability, extremely efficient resource usage, and you don’t need to run radically different OS environments simultaneously, containers, especially Docker containers or Podman containers are a great choice.

    Incus containers are a great middle ground that I’m a fan of more than Docker/podman containers or traditional VMs. They are system containers, vs application containers like Docker/Podman.

    That means they are actually full-fledged Linux distros by default, but are still much smaller than a traditional VM.

    Also, for any of these solutions, if you’re constantly doing admin tasks manually, you’re doing it wrong. All modern platforms have APIs or other ways to interact with them via code.

    For my own setup, I have everything. My main server runs XCP-ng for the hypervisor, and I have several traditional VMs on it, including my primary NAS. I also run a virtual Incus host that I have my Minecraft server running in, and some random other system containers. I have a Docker host VM, but I don’t really use it.

    I also have my home media server which is a standalone system running TrueNAS on bare metal with Tailscale and Jellyfin running as Docker containers within TrueNAS.

    My setup is messy because it has been built slowly over several years, and I don’t have enough time or energy to rip it all down and put it back together in a more optimal way.



  • If you’ve already got Qubes and Xen Hypervisor running, your technical level is high enough for sure. And honestly, your security is already probably good enough.

    Qubes has very secure defaults, I don’t think you need to do anything else, honestly what you have already might be overkill, but idk your use case.

    Make sure you can’t see your torrent/download machine VM from any other devices on your network. Use Nmap as long as it’s your network. Don’t use it on a corporate or university network, it will likely get your device totally locked out and you in big trouble.



  • Idk what software you’re using, but most VM software has an easy way to take a snapshot of the VM state. If you’re about to download something risky, take a quick VM snapshot, so if it ends up being some kind of malware, you can just roll the VM back to its earlier state without issue, takes like 2 minutes.

    If you’re worried about malware spreading through your network, you need to isolate your devices. The most common way to do this is with VLANs, but I don’t know what your home network looks like, and if you just have a typical home setup with your ISP’s modem/router and all your devices plugged into it or on the default wireless network, you won’t be able to do that.

    You could also use something like UFW on Linux to only allow internet traffic and block any traffic inbound or outbound to your LAN network, isolating your PC from all other devices on your LAN. This isn’t great, because if your host is compromised, then your host-based firewall could also be compromised and the malware could then get out to the rest of your network.

    You could invert this and have all your other devices on LAN set to block all traffic from your specific PC, which would be more secure, but also a pain to configure, plus it assumes all the other devices are able to be configured in that way on your LAN.

    There are a bunch of other solutions, but it depends on your setup, your technical skill level, and your threat profile. If you’re just torrenting cracked games and random software, that’s somewhat risky, but not really that crazy if you are running it in a VM with rollback snapshots.


  • My understanding is that this is just a sort of open forum/presentation on this as an idea. That being said, it’s a stupid-ass idea.

    I don’t want my computer to “love me back” it’s a fucking machine that I built to do my work on and play my games on. I am the only form of agency I want having access to it.

    If I ever want an AI agent running all the time in the background doing shit for me, I’ll fucking install and configure one myself! I want my OS to be an OS, not some “smart”, interactive fake person that will hallucinate random Bash commands, fuck my partitions up randomly, and bork my system.

    I alone am the only thing that I want destroying my system, if that’s going to happen, it will happen by my own hands, my own shitty commands, my own piss-poor scripts.

    This AI delusion and hype cycle is more infuriating than the NFT craze, and that’s really saying something.


  • Man, I really hate this economy. This AI bubble cannot pop fast enough, but I fear we have at least till the end of this year, possible Q2 of next year to see it happen. Even then, it’s not like it will be instant, and capacity won’t just instantly switch over to normal consumer components. Assuming even more tech idiocy doesn’t happen, we’re still years away from a ramp up to “normal” capacity.

    I’m even more scared that the era of personal computing is in it’s last days. The combination of drastic cost increases, and the dominance of corpo-tech working 24/7 to destroy ownership completely, might be too much to overcome.

    We’ll see a return to the era of computing similar to the 80’s and early 90’s. Building your own PC will require lots of money and technical skills. Pre-builts will be a distant memory. PC builders will be spoken of in similar terms as HAM radio people are now, hermitic nerds who are hardcore into their ancient, dark, tech wizardry.