

While checking checksums is important, it you’re getting them from the same place as the download you might as well ignore the checksum. If someone can replace the download they can very likely also replace the checksum file download.
Migrated to https://piefed.social/u/SMillerNL


While checking checksums is important, it you’re getting them from the same place as the download you might as well ignore the checksum. If someone can replace the download they can very likely also replace the checksum file download.


Senator Hanson mocked and vilified an entire faith, a faith observed by nearly a million Australians … I’ve never seen someone be so disrespectful to (the parliament).
Maybe not updating bot mitigation fast enough would cause an even bigger outage. We don’t know from the outside.
It wasn’t an unintentional update though, it was an intentional update with a bug.
5 minutes of uninterrupted DDoS traffic from a bot farm would be pretty bad.


I’m thinking of the Apache project, and all the important projects it covers that are under an Apache license and I’m not sure where the sudden worry comes from.
HTTPD and Nginx have had very permissive licensing for years and seem to do fine.


Why are they pushover licenses? Because they don’t force people to contribute back? Because a lot of companies aren’t doing that for GPL licensed software either.
Also not really sure how this would allow a takeover, because control of the project is not related to the license.


Wasn’t the issue there that there are no drivers for the specific Apple silicon hardware, so someone needs to invent them? Because we’ve had raspberry pi for ages. Software for ARM is a solved problem AFAIK.
The link I posted focuses on security, what you post focuses on privacy. Wire is a very secure protocol but WhatsApp being owned by Meta still makes it a privacy nightmare.
Signal is probably a better choice in that case.
I don’t, since I read https://www.latacora.com/blog/2019/07/16/the-pgp-problem/
Af an attack can escape a container a lot of companies worldwide are going to need to patch a 0-day. I do not expect that to be part of my threat model for self-hosted services.
Probably because they only represent 1% of the people. As is tradition over there