Oh no, you!

  • 0 Posts
  • 121 Comments
Joined 2 years ago
cake
Cake day: November 3rd, 2024

help-circle


  • Not working on anything particular, but I’m going on a road trip on Tuesday to this regional airport that is giving away two racks perfect for my use case. Deep enough for my larger machines, sound proofed and 42U tall.

    Finally my hardware can have a proper rack instead of being in a stack/pile in this harrypotteresque locker under my stairs.




  • My home servers have generally a lot smaller attack surface, as only a few ports are actually routed to them, so in theoey I could get away with a more relaxed approach. But I’m also a big believer in defense-in-depth, so I follow the same rules of thumb:

    • iptables (or equivalent) that drops anything incoming that isn’t wanted. It also rejects anything going out that isn’t planned for.
    • any public facing service (except ssh) gets its own user
    • disable root login via ssh
    • ssh login with key only on any user in sudoers


  • Well, there’s a footnote on my end: Me taking the drives home is a bit of a grey area, as the procedures say that the drives are to be mechanically destroyed when no longer needed. It doesn’t specify needed by whom. And I do attack them with my angle grinder, so it’s in accordance with company policy.

    And yes, my employer knows and is OK with it. We go through a ridiculous amount of drives due to large storage needs, so pragmatism tends to trump bureaucracy.








  • Depends if you’re hosting something public, or something private.

    For public, a webserver is a simple start. Can be anything you want it to be, but as complexity increases, so does the amount of potential attack vectors, so keep that in mind of you’re considering adding things like WordPress and the like.

    For private, a NAS and/or a simple game server is a simple and useful start.

    As for how, there’s a million ways to do it, and I’m an old stubborn BOFH that still cling to the old ways of doing it (as in, no VMs, no containers), so I’ll defer to others for that.

    While purpose built server hardware is always nice since it comes with some useful additions, the truth is that “any” machine will do. Old discarded PC will do just fine.


  • I would like to emphasize the first part of my previous comment. As I am a hillbilly occasionally cosplaying as a smart and educated person, I am incapable of exploring my statement further than just making the claim. And for that I must insist on referring to it as an hypothesis, unless someone shows me some math that it could actually work. And I hope anyone showing me said math brings the necessary crayons and puppets to explain it in a manner that I can understand.


  • neidu3@sh.itjust.workstoScience Memes@mander.xyzReferences: [1] out of his ass
    link
    fedilink
    English
    arrow-up
    26
    arrow-down
    5
    ·
    edit-2
    3 months ago

    I’m not smart enough to prove my hypothesis, nor am I smart enough to understand any proof that I am wrong, but I’m not entirely 100% convinced that dark matter exists as an attractive phenomenon inside galaxies the way it is often described.

    The way I see it, it might as well be a repulsive force between galaxies. This way it could also help explain Dark Energy.