• 1 Post
  • 158 Comments
Joined 3 years ago
cake
Cake day: June 22nd, 2023

help-circle



  • Those exact type of issues have existed in the past it’s why the FBI uses ad blocking and recommends that it’s used for security. There have been several browser vulnerabilities over the years that required absolutely no interaction from the user whatsoever it simply had to load the data.

    The whole reason that manifest V3 was such a big deal for unlock origin is that it prevents it from intercepting and stopping the initial connection to The domain in the first place it can only remove it after it’s been received and even that was limited. On Firefox everything is still normal it’s able to completely stop the browser from ever reaching out in the first place




  • I’m very tired of the rhetoric that Arch is only meant for tinkerers. If all you do is have plasma steam and a web browser it’s no more or less likely to break than any other distro. You could go your entire life without ever looking at the terminal.

    And while yes this malware is a problem it is specifically in the aur, the arch user repository an unofficial repository not officially supported, just don’t use it. Unless you need a weird piece of software generally related to some type of specific hobby you’re unlikely to ever even want to look at it anyway.








  • I’ve been trying but it quickly breaks for me. I’ve got 64GB of system memory and a 6800xt but after a few responses it starts to fail to generate a response. Idk if the context window is becoming too large or what but it’s unfortunate. The responses are decent but not being able to maintain a thread sucks. This is using LM studio. Maybe i need to tweak the load settings or something







  • The nginx rce relied an a series of requirements that affect almost nobody. You had to be using a very specific module and processing a specific type of data reverse proxy was not affected.

    But regardless I get your point that anything can have an RCE. However as you say at the end in principle that does not mean you should just give up and expect external projects to handle your security. VPN is a great way to access your services and it is good defense and depth, but for the sake of being a successful project to the masses? It’s basically a dead end Road