Avatar
Skhron - VPS for Bitcoin, Lightning and Monero
2641c5060e4eec82089fdb2c9eb84714660fddf7c23a01d731311481983f0175
Privacy-first VPS hosting provider. Servers in Poland, Warsaw and Sweden, Stockholm. We use only own colocated equipment and operate own network behind AS215467. Check us out: - http://skhroneuxrnchfz3wifchkju6spd3nx4krqe6zbx65hsax7qsbubb4qd.onion/ - https://skhron.eu/ - https://skhron.com.ua/ is our old website We accept Bitcoin, Lightning and Monero using self-hosted BTCPayServer and bitcart.ai instances We also operate our own lightning node (CLN): https://amboss.space/node/02f16437c2b9bf9f38bc4a57d7f32d7c36633725392cebf1faadea11b4ea855a7b

When outside, almost always I prefer light theme to save on screen brightness

#asknostr Anyone has personal nostr #relay for multiplexation purposes / saving websockets on a mobile?

So far I have found a few projects but they seem to not be actively maintained or widely used:

- https://github.com/bndw/nostr-relay-proxy

- https://github.com/Dolu89/nostr-proxy

I would like to hear your opinion on this idea in general, do you know any implementations or what do you think about these specific ones.

I am not sure if it ia good idea given that there can be issues with reaching web server / CORS misconfiguration / temporary DNS issue

I am somewhat biased towards certificates - I see them more as vendor's confirmation of yours' proficiency in using specific software/hardware in a way they expect you to.

As for Linux kernel and it's wide and extremely diverse ecosystem, there is no single entity, who are in charge of judging what is OK and what's not. IMO, closest to this position are Red Hat due to their contributions and enterprise services (Red Hat Enterpise Linux distro, it's components they've developed exclusively for it, testing environment like Fedora and CentOS Stream, OpenStack, Ansible...).

Can't recommend you any certification, but did you ever use Gentoo or NixOS? You can learn much while using them.

As for professional recognition, I think only Red Hat certification programmes are worthy.

There is no need to restart nginx to update certificates, you can ask nginx to reload TLS certificates (`-s reload`, it actually reloads entire configuration): https://nginx.org/en/docs/switches.html

You can even reload nginx binary on-the-fly and revert this change if necessary: https://nginx.org/en/docs/control.html

Replying to Avatar crrdlx

Got the email below, haven't had time to check if it's real or scam. Says Google Play needs KYC. If true, that's sad. #kyc #plebchain

Critical message Your developer profile and all apps will be removed from Google Play if you do not complete account verifications by Oct 11, 2024 (in 28 days)

Your developer profile 'crrdlx' and all apps will be removed from Google Play on Oct 11, 2024 (in 28 days) if you do not complete account verifications in Play Console.

Your deadline to complete verification

Oct 11, 2024

Complete verification in Play Console

Now

What you need to provide to verify

When you verify, you'll be asked to confirm whether your developer account is for an organization, or whether it's for personal use. The information you need to provide depends on your account type.

a D-U-N-S number (organizations only)

If you're an organization and you don't have a D-U-N-S number, request one at no cost from Dun & Bradstreet now. This process can take up to 30 days, so we recommend requesting a D-U-N-S number immediately. Learn more about requesting a D-U-N-S number

a phone number for Google Play users to contact you (organizations only)

an email address for Google Play users to contact you

a phone number and email address for Google to contact you

an official document to verify your identity

an official document to verify your organization (organizations only)

If you earn money on Google Play using Google Play billing, you'll also need to verify your merchant payment details.

All developers must complete account verification to comply with the updated Play Console Requirements policy. To learn more about account verification, visit the Help Centre.

I am not familiar with Google Play from developers' POV, but after quick search I found this one year old article: https://android-developers.googleblog.com/2023/11/ensuring-high-quality-apps-on-google-play.html?m=1

So mandatory KYC for devs seem to be true.

Replying to Avatar Dr. Hax

A bug in #GitLab that, according to GitLab's write up, "allows an attacker to trigger a pipeline as an arbitrary user".

Does this mean an attacker could create a pipeline job to extract secrets and then run it as another user?

GitLab won't say. They just say the attacker can #exploit this #vulnerability "under certain circumstances". Not much #transparency for something they consider a "critical" vulnerability.

Source: https://about.gitlab.com/releases/2024/09/11/patch-release-gitlab-17-3-2-released/#execute-environment-stop-actions-as-the-owner-of-the-stop-action-job

Before someone tells me thay it's open source and I can just read the source code, just stop. You're missing the point. The point is that people who write up announcements like this should be communitating to other server operators what the actual risk is. Do I need to shut down the CI runner until I can get someone out of bed to patch this? How can I find exploitation in the logs or be completely confident my server wasn't exploited?

#security #infosec #cyber #cybersecurity

In similar cases I always expect the worst