Avatar
Dr. Hax
d30ea98ea65e953f91ab93f6b30ea51eb33c506f87d49f600a139aef00aa9511
Cypherpunk. Infosec veteran of about 15 years (vulnerability research, exploit development and cryptography). Cypherpunks write code. :-) Signet maintainer. Self-custody your passwords... in hardware! https://hax0rbana.org/signet Want to see wider adoption so Bitcoin can be used as digital cash and not just an investment vehicle. XMR: 44RDkTFmTeSetwAprJXnfpRBNEJWKvA5dBH5ZVXA4DofgoZ9AgjyZdSa2fo7pMD3Qe3pdKga8X22y3Lyn1xYde5kPQPzVUu

Be the rust upon their gears!

With "them" being anyone who pushes planned obsolescence and/or fights against the right to repair.

Replying to Avatar Ryan Steva

Hiding food production from the government!

https://youtu.be/wFKRu94Q6s0

#grownostr #permaculture #growyourown #thehomesteadconsultant #homesteading #freedom #betterlife #resist #agonist #gardening #food

I approve of covert food production. And if nobody can tell, I feel like it's really complying with the spirit of the rules (which is effectively: we don't want noisy, smelly farm animals).

Side note: a home owners association is not "the government" 🤣

nostr:nevent1qqsgphdula9t3mf2f3un6zzj8mekqhryp2ltem4q7he5td8dfpkculqpp4mhxue69uhkummn9ekx7mqzyqld243507y2schsen452zt6rnarjdc93d2pyt7t5p5f37kawnvuxqcyqqqqqqg2qhm80

If you are supporting protestors' right to #protest, you are fighting for free speech.

If you support #FreeSpeech, you should be supporting the protesters' right to protest. It makes no difference whether you agree with what they have to say.

1. Aviate

2. Navigate

3. Communicate

In that order

If you want to do so in an automated fashion, check out these:

https://github.com/fooock/bitcoind-ansible to set up your own full #bitcoin #node, and...

https://github.com/fooock/lnd-ansible to set up your own #lightning node.

#Lnd can run on the same machine or on a different one.

If you have ansible installed, this is like 2 commands. If not, it's 3 commands. It really is that slick.

- ☠️ Wallet of Satoshi

- ☠️ Pheonix Wallet

- ☠️ Tik Tok

...who's next?

- Alibaba

- RT

- Zeus

- Other (reply in the thread)

#AppStore #ban #censorship (sorta)

#Zeus #centralization

I hope it can come back again in the future.

I feel like that would be very appropriate.

When people who use these wallets from centralized app stores like Google and Apple need to empty their lightning wallets because it's getting pulled, is it generally cheaper to send it to another lightning address instead of closing channels?

Later, at that same URL, is a crap article on SBOMs. The author either ignores, or is oblivious to, the fact that attackers have been checking for vulnerable dependencies for decades.

If he has been pen testing for 20 years, he should certainly know this. He should also know that defenders are less likely to put in this same level of effort on tracking down libraries. I don't mean that in a disparaging way to the defenders out there. They're relying on the developers to do this work because the developers are the ones who can actually fix the issue. All the blue team (operations) can do is report it to the devs and try to mitigate it in the meantime. So it makes sense defenders wouldn't be spending their time this way. Devs should be, and if SBOMs become a requirement (de facto or otherwise), they will be.

Making it easier to make this determination with #SBOMs will benefit #attackers, but it will benefit #defenders more.

nostr:nevent1qqsr02wdr0v28m0wneu9t90du6pm3dxuucf8p3fkvt2e9mqr77psxhqpp4mhxue69uhkummn9ekx7mqzyrfsa2vw5e0f20u34wfldvcw550tx0zsd7raf8mqpgfe4mcq4223zqcyqqqqqqgaggp5c

Dark reading seems to be hit and miss, but this piece about #cloud #security is a hit (esp. #4)!

1. You don't become more secure just by going to the cloud

2. Native security controls are hard to manage in a hybrid world

3. Identity won't save your cloud

4. Too many firms don't know what they're trying to protect

5. Cloud-native development incentives are out of whack

https://www.darkreading.com/cybersecurity-operations/ciso-corner-evil-sboms-zero-trust-cloud-security-mitre-ivanti

For the Pi part of your setup, are you using a pico like is listed on the mashtasic site, or have you found some way to get meshtastic to run on Linux (e.g. a Raspberry Pi 0/1/2/3/4)?

I ask because I'd like to use my LoStik to act as a receiver with a Pi Zero 2 W board but I can't find and existing software to make that happen.

Replying to Avatar Ava

🎯

Honest question, albeit slightly off topic: If you could buy a very expensive laptop with an open source CPU, would you be interested?

MNT's FPGA-based CPU caught my attention a while back, and I don't have any income, so $1600-2600 for just the CPU is steep for my blood, but I'm curious to get your take.

More info here: https://mntre.com/media/reform_md/2022-09-29-rkx7-showcase.html

Followed. Delighted to get hooked up with fellow gardeners here on nostr!

Replying to Avatar Fern

👋

Followed the friendly fern fanatic. 🙃

To any bystanders who might find this note, if you have not seen how fern leaves grow, you are missing out!

I don't know what Ludis is or who Bad Sector Labs are, but open source, self-hosted things, deployed with Ansible... I'll give that a 👍.

A recent MIT study indicated that "the cloud" now has a larger carbon footprint than the airline industry.

https://www.internetsociety.org/blog/2024/04/the-internet-and-climate-change

The article also has good news about what is being done to make the internet more efficient and more resilliant.

#EarthDay