

I hear a lot of chatter about CGNAT. How common is that? Anecdotally, I’ll have to say, I’ve never encountered it… ever.
Incessant tinkerer since the 70’s. Staunch privacy advocate. SelfHoster. Musician of mediocre talent. https://soundcloud.com/hood-poet-608190196


I hear a lot of chatter about CGNAT. How common is that? Anecdotally, I’ll have to say, I’ve never encountered it… ever.


The scripts targeted an ownCloud instance operated by a nuclear research body
Maybe it’s just me, but I think if I were running a nuclear research facility, I’d want a little something more than ownCloud, and neat as it is.
Gravity looks pretty cool, tho a bit heavy on the install. TapMap: Why are these things such a garish shade of green? Damn hard on the eyeballs.
I was reading a homelab discussion about NUTs (Network UPS Tools) that left me scratching my head and wondering "…why? Is complexity for complexities sake part of homelabs? Isn’t this a huge overkill for one machine? Just…use a UPS? "
I think it’s like anything else people do. Some are quite satisfied at a moderately basic level. Others tho, implement K8 clusters, etc, a complexity level I have no interest in. Take golf for example. I used to play quite regularly. I had a raggedy old bag and some beginner level clubs I bought third hand. My buddy had every golf gadget you could possibly imagine. Thousands of dollars to whack a ball around a course and into a hole, on an amateur level. I’m thinking, ‘Dude, this isn’t the Masters Tournament at the Augusta National. We’re just whacking balls into holes and having a few beers on the weekend’ . But, every time we got together, he just had to show me his new gadget that cost him hundreds of dollars and added even more complexity to the game.


I tried QubesOS back in the day. How has it progressed as a desktop. I was always underwhelmed visually. It just seemed rather chunky. Maybe that is intentional.

Of course, if you are going for security, that’s great, but it seemed to me that security and a visually appealing desktop could be blended.


I’m higher than a giraffe’s butthole, so I got to know: Exactly what were you staring at when you opened the picture? I kid of course, but I found that quite risible.


Ahh ok…well, there you go. Fresh out Don Curbstickle. Maybe next time.


I wonder if you could pair your phone with your DSLR so that you have access to GPS location tagging.


Monitoring firewall logs would show calls to suspicious IPs and domains after you pulled the Docker container. A MiTM attack is usually conducted between two communicating parties, rather than inside the server itself. The attacker intercepts traffic as it travels across a network or service path. MiTM are not always done exterior of the server, but usually. Strong ciphers are your friend. Although MiTM and PIC events can overlap, a PIC is usually an attacker gaining unauthorized access to a system. A PIC compromise occurs outside the public facing server, through a stolen administrator password, compromised developer workstation, exposed API key, or hijacked cloud account. Securing API, devices, frequent password rotation are good practices. Again, not always exterior of the server, but usually.


What do you (or does your org do) to ensure that you’re not using maliciously-modified containers after pulling a new docker image?
I don’t run a complex setup as it seems you do, but if I pull a new Docker container, I closely monitor my pfsense firewall logs. A lot of times, I’ll deploy a recently released container on a small test server and just observe as I run it through it’s paces. Also, I like containers that have a rather established history. I look at things like stars, how they handle bug complaints, etc. Even when updates come out, unless it’s a dire security patch, I’ll wait until all the early adopters work out the bugs and do my work for me. Early adopters are a valuable resource.
I guess you could say it all comes down to calculated risk.


capitalist mindset
I’m a capitalist. I run three bonafide, tax paying businesses. They allow me to live moderately comfortable. Money makes the world go 'round. I’ll never be a billionaire, but I do love me some money. Sure, the best things in life may be free, but the grocery store isn’t giving away groceries.


Don’t take it to seriously
Too late. LOL Thank you for sharing.
Opensense is often bound by single-core operations depending on where a network packet may plumb itself through the kernel
Didn’t downvote, but when would this become an issue? Pfsense is about the same way as far as single-core operations, tho IDS/IPS like Suricata can utilize multiple threads. My standalone pfsense box sits between my modem and the rest of the network. I haven’t noticed any sluggishness or stuttering. Throughput seems quite reasonable, and supports a diverse group of devices attached to the network.
Well, there you go. I’m glad I plowed the field and saved you the embarrassment. LOL
Pay no attention to the old fart yammering on. I’m surprised I didn’t throw in a couple ‘well, back in my day’. lol I hope you get it all worked out tho.
Ahh, I missed that. So that would explain all the downvotes with no explanations why. Thank you for bringing that to my attention.
I don’t run Jellyfin, so take this as is. From what I understand tho, Jellyfin does take a fair amount of resources to run in an ideal situation. Meaning it takes some RAM for multiple simultaneous transcodes, several users, large libraries, etc. A lot of the cheaper Stick PCs come with less than stellar specs. The Stick PC I just randomly picked because it was 8 GB RAM is a MeLE Business Grade PCG02 Fanless N100 Mini Stick PC 8GB. It retails for $350 USD. For half of that price, you could opt for an SFF Optiplex, bump the DDR3 RAM to max the mobo, and DDR3 is fairly cheap, and still have resources to run other Docker containers if you wanted. For example I run an Optiplex SFF with the i7-4790 chip and 32 GB DDR3 RAM. Currently I have 53 total containers running and it really doesn’t break a sweat. Total cost of the box plus RAM was about $175 USD.
If you are going for the portability aspect, that’s where I think a Stick PC would function best. All that being said, you have options just depending on what your criteria are for running Jellyfin.


I’m an expert at nothing, but I would imagine that different VPN like WireGuard have different detectable signatures, much like different browsers have different signatures that can be detected. Also, for commercial VPNs, the IPs that the VPN company uses are easily identifiable.
I like it. The OCD in me is screaming why you didn’t use a dremel tool to cut the slot for the USB ports instead of using a rusty, dull, steak knife from the junk drawer, but that’s just me. LOL