• 1 Post
  • 29 Comments
Joined 1 year ago
cake
Cake day: June 6th, 2023

help-circle



  • Never heard of before and dgaf about whoever Linus Sebastion is. All this stuff I’ve been seeing about what an asshole “Linus” is thinking it must be some kerfuffle about Linus Torvalds but the bits and pieces I read made no sense. Even less now I’ve figured out it’s just some random asshole named Linus. How did I end up here? Take me back to my room, please.










  • Well, I just learned something, but what does “control” the IP mean? If they are only validating a single address via http then presumably you could just use an Amazon elastic IP as long as it resolves. I doubt that letsencrypt will support that but I would be interested to know. If they do then yeah, you could presumably set up the instance using the IP as the name, but I don’t know why you would want to. Apart from the fact that it would be hard to remember, could change at some point, screwing things up, it might work. I suggest OP do the necessary and report back accordingly.



  • Right, but Lemmy.ml is really just one of a thousand plus instances. We need something instance independent or a way to propagate info that doesn’t rely on any single failure points, or Lemmy as the communication channel. What happens when lemmy.ml is down, or if no instances are able to post due to concerted DoS?

    It’s impossible to stop anyone randomly posting stuff on Lemmy. Attackers can post misinformation as well, especially if they compromise admin accounts. Who are we gonna trust in the midst of the next incident? The account posting most prolifically about the UI exploit in progress was using a burner account that had just been created to post about it. I’m sure there were good reasons for wanting to be anonymous when discussing the work of unknown malicious actors, but it made me think twice about what was being posted at the time.


  • whilst I differ somewhat on sharing information on the exploit - knowing something about what was going on allowed some instance admins to take evasive steps - I agree with you completely that there could be a better channel for coordinating communication - I imagine a lot of the discussion went on via Matrix - under the circumstances the response wasn’t so bad given the complete lack of formal organization but yes, it definitely could be improved - you sound quite well-versed in how to handle security/critical incidents. Maybe consider contacting the devs and offering them some help in this area?





  • thanks - open source search - what a wonderful idea! Although duckduckgo is tolerable, I used google without an ad blocker a couple of days ago while setting up a new system - wow - the search results are so full of clutter and garbage that it’s practically unusable. Google search was useful once - not now.

    The main reason ChatGPT is popular is simply because it provides information quickly without a gazillion ads and SEO-driven click-chasing nonsense making the internet unusable. There’s no “intelligence” beyond a much better and more intuitive information presentation algorithm. OpenAI is just a search-engine reinvented. We need to open source LLMs next.