• 2 Posts
  • 41 Comments
Joined 9 months ago
cake
Cake day: January 25th, 2024

help-circle


  • Y’all need to get a word in with your representatives that what’s needed is legislation preventing budget bills from containing anything other than budgets.

    That would solve this problem real quick. It’s been sounding stupider and stupider using the budget meeting to force unpopular agendas down throats or else the government is held hostage.

    I think it would fit the bill if budgeting was held up over allocations, one side wants more border spending, one side wants more educational spending, etc, that would make sense but “allow us to attach this whole other unrelated law to declare the sky is actually green(which also contains a tag along that I get to be emperor), or nobody gets paid” is just ridiculous.




  • Since you mention setup instead of any manual install screwery, I’d say root(uid 0) is still very real, you just didn’t setup any login for it. Every time you sudo (substitute-user-do), you(probably uid 1000) are running that command as root instead of you. In fact, just sudo -i and you are now “logged in” as root.

    Edit: Missed the context. Should still be useful info but you probably are not accidentally remoting into an account you never setup the login for.


  • Raspbian is sometimes a compromise between security and usability, because it is designed to go into the hands of new users. It also used to ship with a default “pi/rasberry” login hardcoded and IIRC permitted root password login over ssh. Things experience users change or turn off, but needs to start friendly for the rest, you know?

    By doing this, they can take a step in the right direction by separating the root and login user, without becoming annoying asking for a password frequently as a newbie copies and pastes tutorial commands all week.

    And as I said it’s unlikely, even very unlikely, but just not impossible. Everything comes with a risk, I just believe it’s up to you, not me, what risks mean in your environment. Might be you’d like to have the convenience on the home dev server, but rather have as much security as possible on a public facing one.

    Or maybe you’d like to get really dialed in and only allow specific commands to be run without a password, so you can be quick and convenient about rebooting but lock down the rest. Up to you, really, that’s the power of Linux.


  • In Debian, you will want to modify your /etc/sudoers file to have the NOPASSWD directive.

    So where you find something like this in that file:

    %sudo ALL=(ALL:ALL) ALL

    Make it like this:

    %sudo ALL=(ALL:ALL) NOPASSWD:ALL

    In this example, powers are given to the sudo %group, yours might just say pi or something else the user fits into.

    Also, please note that while this is convenient, it does mean anyone with access to your shell has a quick escalation to root privileges. Some program you run has a shell escape vulnerability and gets a shell without a password, this means they also get root without one too. Unlikely to happen, sure, but I believe one should make informed decisions.





  • Now would be a good time to look for a .com you like, or one of the more common TLDs. And register it at Namecheap, Porkbun, or Cloudflare. (Cloudflare is cheapest but all-eggs-in-one-basket is a concern for some.)

    Sadly, all the cheap or fun TLDs have a habit of being blocked wholesale, either because the cheap ones are overused by bad actors or because corporate IT just blacklists “abnormal” TLDs (or only whitelists the old ones?) because it’s “easy security”.

    Notably, XYZ also does that 1.111B initiative, selling numbered domains for 99¢, further feeding the affordability for bad actors and justifying a flat out sinkhole of the entire TLD.

    I got a three character XYZ to use as a personal link shortener. Half the people I used it with said it was blocked at school or work. My longer COM poses no issue.


  • Some would think this is horrible, but to me, it would be wholly dependent on the title/what was bought and sold.

    Nothing in this world is free. Development, servers, character licensing, it all costs money and if those costs aren’t passed down, you’ll never afford to continue. So for a game, especially one with online content or continuing content, to be free to play, money has to come from somewhere.

    Where the road splits is what is being sold. Things that give an edge in the game, pay-to-win? Uninstalled. Time limited FOMO triggers? Disgusting. Random loot boxes? Begone foul spirit.

    On the other end, if all that is for sale is shiny baubles and trinkets, things no one needs but can have as a reward for “supporting development”? I’m cool with that. If I feel no requirement to pay up, it’s being handled right, and if I like they game, sure, I can part with a fiver to look like I’m dipped in gold or whatever the supporter pack adds to help them keep the lights on(at least until I get bored of it in a week or two and switch back :P).

    I’d be curious what the divide is between the two kinds of purchases are. I’m sure I’ll be disappointed to find it was mostly P2W scum, though.



  • Y’know, that does put a thought in my head.

    How do you know the President is calling? If I saw a caller ID saying anything like that I’m going to assume spam. Unknown DC number, also spam.

    Does an aide come to my door and hand me a phone, or warn me that the next call is official?

    Otherwise of course I missed the call, guess the President gets to leave a voicemail! And we can play telephone tag with his staff until there’s another moment in his day…?


  • Is there a list anywhere of this and other settings and features that could/should certainly be changed to better Firefox privacy?

    Other than that I’m not sure I’m really going to jump ship. I think I’m getting too old for the “clunkiness” that comes with trying to use third party/self hosted alternatives to replace features that ultimately break the privacy angle, or to add them to barebones privacy focused browsers. Containers and profile/bookmark syncing, for example. But if there’s a list of switches I can flip to turn off the most egregious things, that would be good for today.



  • I think the polls are close because only a certain subset of voters are in them.

    Did you participate in the poll?

    I ask because I didn’t. I’m not even sure how I could but can’t be bothered to figure it out, and it doesn’t seem like it means much.

    I also asked my coworkers if they were in any of these polls. Out of the whole lunchroom, one old guy said he used to do them, years ago when they would call him and ask questions. But they haven’t in a long while.

    So that’s a whole lunchroom not represented in the polls, and I doubt we’re the exception. But we will all be voting come November.


  • I mean, given my work schedule it was late for me too. But it was an OK time for the other coast I suppose. Good thing I have a DVR.

    Old age aside, that’s the curse of campaigning while actively President I think. Biden’s been up since god knows when hearing reports, making tactical decisions, worrying about multiple wars, working the reporters, navigating security concerns and doing his job, while also having to rehearse what he can anticipate, get to the studio and get all made up and go on TV. I’d be fried at the tail end of such a day too.

    Trump probably threw a party, napped, popped some strong pills, printed another copy of his same old rally speech and came out of a hotel across the street ready to blame some immigrants for the sun going down.

    Maybe we should get the VP to run the country on important days like debates so the active president can get the same treatment as the guy with nothing better to do?


  • On the one hand, it’s a tradition at this point to always run the incumbent. In most cases, it’s a slam dunk win unless things went really wrong. (say a pandemic)

    The difference now is that I don’t think we’ve ever had presidents get this old. I think Reagan ended this old but no one has ever run for office this old. And I can’t blame a guy for getting old like I can blame a guy for spouting lies and vitriol. I do think it’s time for an upper age limit for office though. If people can be too young, they can be too old. And it seems like people are living long enough to get to test it.

    But on the other hand, there just aren’t any democrats that came close to winning the primary, wether because of the first hand tradition or because they just didn’t have anything good to bring to the table I’m not sure.

    And when the opposition is as sturdy as Trump, it’s not the time to play games with untested newbies, you know? So you try to bring up your battle hardened best, even if he might be getting up there in years.

    That said, before the debate, I felt like he had the ability. He’s been strong at previous public appearances. I truly hope this is a fluke, and he wipes the floor with Trump at the next debate. Because otherwise we are screwed, either because Biden fades out on us or Trump gets to try for his racist autocracy.