• 0 Posts
  • 100 Comments
Joined 3 years ago
cake
Cake day: July 1st, 2023

help-circle



  • Fun fact: you can actually do mitm-proof end to end encryption between a web server and a client: TLS client authentication. It’s tricky to set up, so this is more useful for e.g. small private web servers with tech savvy users. Any mitm would require cooperation of at least one party.

    In windows you manage certs with start / run / mmc, then add snap-in and pick certificates, local machine or current user. And then usually the browser requires you to whitelist the domain so it’ll be allowed to ask for a cert.

    You still have to coordinate to exchange cert identities (thumbprint ideally, CN if you really have to).




  • Like, to find the canonical DNS name of one of my home lab IPs, 209.180.104.202, you search for a PTR record for 202.104.180.209.in-addr.arpa. (You get git.mspencer.net. Note my username here.) The first A in ARPA stands for something. (That’s how you know I’m not a bot - bots don’t have 25-year-old domain names. . . . I didn’t say I was interesting, I just said I’m not a bot. :-) )

    We don’t own it though. We never should - too much concentrated wealth and corruption. Like many technology stories, big wealth (whether Cold War military spending or giant corporations using money to squeeze out more money) creates something for one purpose, but people adapt and convert it for a better purpose. Business computing tech becomes home computing or gaming tech. Military redundant communications research becomes public redundant communication infrastructure.






  • Like the American Squid Game reality show? It uses squibs and has contestants pretending to die in a lamp-shaded way (gets caught, remote controlled squib goes off, looks down disappointed, after a short reaction time and thinking delay they lay down in a safe way - or jump-fall like a stunt person). Maybe they have a bigger special effects budget and don’t interview the “dead” people after?






  • Agreed, I have one of the last “good” HP Color LaserJets from a tech recycler and last time I checked it was two model revisions old. This one still has a config option to allow unofficial toner, so I pay like $120 for a set of all four high capacity cartridges now, I think 5k pages black and 3k pages C Y and M. (It’s a MFP m477fdw I think) I think the next model was the first one that took the option away.

    You can still use third party toner with some of the later models, but those are more expensive and come with some kind of jig for transplanting an HP chip into their cartridge.

    I will never buy another HP product again (apart from replacement parts for my current printer), and will jealously guard this one and nurse this one along until it dies.

    But in a general sense, being able to completely ignore the printer for literally months, and then turn it on and get a perfect print, and then ignore it again… really nice. That’s all laser printers. Never buy HP.


  • You’re right to be frustrated. Mine is the same way. It’s ok to be passionate about that, and to value punishing greedy ISPs by not paying extra for a business account. (In many cases you could even need both, if you might worry about occasional denial of service attacks and need to be sure attackers can’t also knock out your ability to work from home, for example.)

    I think there’s a compelling argument in favor of protecting diversity of hosting and preventing a monoculture or a monopoly. It’s not super compelling, but it’s out there.


  • We also need more individuals paying for “business” Internet connections at home. We need self-hosters to be able to feel comfortable running public services from their homes. And so we need a set of practices and recipes to follow, so a self-hoster can feel confident that, if one thing gets broken into, the other few dozen things they’re hosting will stay safe.

    The “family nerd” hosting things for the family needs to be a thing again. Sorry, friends, I know family tech support sucks. It’ll suck so much more when it’s a web site down and nobody can reach their kid’s softball team page, and there’s a game next weekend, etc. But we’ve seen what happens when we abdicate our responsibilities and let for-profit companies handle it for us.

    (I wish so hard that I had a solution ready, a corporate LAN in a box, that someone can just install and use. I’m working on something, but I’m pretty sure I over-complicated it. It doesn’t need to be Fort Knox, it just needs to be pretty good. And I suck at ops stuff.)