• 1 Post
  • 156 Comments
Joined 3 years ago
cake
Cake day: June 22nd, 2023

help-circle

  • Those exact type of issues have existed in the past it’s why the FBI uses ad blocking and recommends that it’s used for security. There have been several browser vulnerabilities over the years that required absolutely no interaction from the user whatsoever it simply had to load the data.

    The whole reason that manifest V3 was such a big deal for unlock origin is that it prevents it from intercepting and stopping the initial connection to The domain in the first place it can only remove it after it’s been received and even that was limited. On Firefox everything is still normal it’s able to completely stop the browser from ever reaching out in the first place




  • I’m very tired of the rhetoric that Arch is only meant for tinkerers. If all you do is have plasma steam and a web browser it’s no more or less likely to break than any other distro. You could go your entire life without ever looking at the terminal.

    And while yes this malware is a problem it is specifically in the aur, the arch user repository an unofficial repository not officially supported, just don’t use it. Unless you need a weird piece of software generally related to some type of specific hobby you’re unlikely to ever even want to look at it anyway.








  • I’ve been trying but it quickly breaks for me. I’ve got 64GB of system memory and a 6800xt but after a few responses it starts to fail to generate a response. Idk if the context window is becoming too large or what but it’s unfortunate. The responses are decent but not being able to maintain a thread sucks. This is using LM studio. Maybe i need to tweak the load settings or something







  • The nginx rce relied an a series of requirements that affect almost nobody. You had to be using a very specific module and processing a specific type of data reverse proxy was not affected.

    But regardless I get your point that anything can have an RCE. However as you say at the end in principle that does not mean you should just give up and expect external projects to handle your security. VPN is a great way to access your services and it is good defense and depth, but for the sake of being a successful project to the masses? It’s basically a dead end Road


  • Actually, i mentioned the memory leaks as it’s been a consistent issue for years now. Again normal people cant and won’t setup special containers with memory limits as a crappy work around.

    You may not like that i don’t blindly glaze jellyfin because it’s open source. However I’m just being realistic about what it needs to actually be a viable replacement for plex for the masses.

    It needs to be able to match media properly, it still struggles with this even when you go out of your way to make sure the media is named in the exact manner the documentation dictates. It needs to be able to be used remotely simply through the web, having to set up a VPN is not a viable approach, it needs to be able to function long-term without eating up all the system’s memory and requiring regular restarts to prevent it from going out of control. Subtitles need to work on all clients, as it stands right now Roku subtitles are non-functional like 80% of the time no matter what you do, some TV browsers struggle with it as well.

    I am sorry that that upsets you, but it is the reality and it is the reason the projects like these tend to mostly be used by the technically inclined. Including myself, I was able to put it in an unprivileged secured lxc container, so that I could use it through the web and set memory limits, but most people cannot and will not do that. I would prefer to see it be successful and be able to tell everyone never touch Plex again, but I know that telling people it’s ready to go while it has a myriad of basic issues is not helpful.