HN user

Caboose8685

168 karma
Posts1
Comments34
View on HN

Shelly also has static analysis for AUR packages that looks for all the common, shifty ways a pkgbuild might try to give you something bad.

To clarify, the packages in the CachyOS repo from the AUR are manually reviewed by a team member before inclusion and updates.

CachyOS takes the default arch repos and re-builds packages targeting CPU generations and their instruction sets. There are no proprietary repos. Cachy has their own personal repo where some packages not in arch repos are built.

Gaming stuff is NOT installed by default, but there is a button in the Hello app new users can click that installs 2 meta packages that install almost everything one might want for gaming. Take a look at it in a VM and see for yourself.

The performance increases from their kernel + optimized packages are small but noticeable to me. Give their wiki a read-through: https://wiki.cachyos.org/

TV: Now What? 3 years ago

I mean just read through the link above. You'll find no exemption for personal use when it involves bypassing DRM. Which I don't think any DVD or blu-ray anymore lacks.

I'm also reasonably sure that "3. Proposed Class 6: Audiovisual Works—Space-Shifting" in the above link would cover personal archival and that was explicitly rejected.

Don't get me wrong, I'm still all for it, but it's not permitted anymore like it used to be.

TV: Now What? 3 years ago

Personal archival isn't exempt anymore, that dropped some years ago. The only archival exemption now is for "qualifying institutions".

FWIW, I've been using an Omada switch and 2 APs for over a year with the controller in a docker container without any issues. I have preferred OPNSense as my router/firewall for years and it works well for me with omada gear.

Bitwarden is fantastic IMO, vaultwarden if you like to self host.

Out of an abundance of caution, it would be prudent to change the passwords for the most critical accounts in your life initially. Things like your bank, email, Google. Accounts that losing control of would immediately make you go "oh shit, I can't do X that I need for daily life". Then slowly over time change the less critical ones.

I highly recommend Neo Store. It's a drop-in replacement for f-droid that leverages the newer Android API for seamless updates. Been using it for months happily.

SMB signing is only on by default for servers. I've done quite a few pentests where that's been leveraged to dump the SAM hashes of workstations that happen to have the Domain admin stored.

I moved from lastpass to bitwarden about 2 years ago, then to self hosting vaultwarden about 6 months ago. Bitwarden wasn't as feature-full as lastpass at the time, but I liked it a lot. My father was using lastpass in the meantime and I saw it devolve into an unpleasant mess UX wise and these days, ignoring the elephant of the hack, am confident bitwarden is a much better experience overall compared to lastpass.

Not only phishing, but too many people have the terrible habit of using the same password everywhere. So with public breach data, it's not a stretch to think bad actors would try, and probably be successful way too often, to use said credentials on bank sites.

Graphene certainly looks impressive by all accounts, but are there any 3rd party audits? I can't find any.

I've learned to expect that from FOSS software that has any kind of security claims and purports to help me be more private or secure. Particularly since I don't have the necessary skills/knowledge to do so myself.

On the flip side, this process can be abused by people who don't actually intend on leaving to get better rates/prices. I've done it a few times over the years to deal with rising costs of an ISP when I don't have any good competitor to actually switch to.

Where is this stated in their rules or whatever? Something I can reference if I need to try this and the person pushes back.