• 0 Posts
  • 33 Comments
Joined 3 years ago
cake
Cake day: June 23rd, 2023

help-circle

  • 99% of people who can read code are only going to catch obvious things like cryptominers. Most aren’t going to catch something like the XZ malware that was an entirely serendipitous finding from timing how long a certain part of the process took and noticing it was off. True malware is using unique loopholes and malformed requests that will get past nearly everyone.

    There really needs to be a concentrated effort put into vetting code, but of course, funding for that is non-existent. 60% of code in the wild is maintained by hobbyists getting paid almost nothing. We’re screwed.


  • I think if it had happened anywhere except Ottawa, where the local authorities recognized this had political implications, it would have been smacked down in normal disturbance of the peace actions. But the local twits weren’t about to get involved in what probably had national impact, so they just left it to the feds to clean up. I’m not sure what other avenues the feds had than the one they used, but they should probably come up with something.

    You’d have figured they could order the Ottawa police to deal with it and took responsibility before they starting using things like bank account seizures and other pretty heavy handed bullshit that you’d never see in a regular action for a problem like this. That’s where I was a little taken aback during the process. By all means, deal with assholes blowing their horns and shitting on people’s lawns like you would normally. But using devices reserved for terrorism gave these jackasses way too much credibility.












  • There’s a pile of reverse proxies out there, NPM is one that’s built on nginx’s reverse proxy mechanism that’s a little opaque to configure if you aren’t much for text configuration files. I do like it for quick and easy LetsEncrypt SSL cert management, and it’s integration with Certbot, especially when you have LE moving to very short SSL lifetimes. This can all be done manually with cronjobs etc, but NPM is pretty low effort and works well.

    Other reverse proxies that use their own engines are Traefik, Caddy and HAProxy. They each have their use cases, such as docker integration or high availability. None are as easy to use as NPM in my opinion.