- 0 Posts
- 41 Comments
ironsoap@lemmy.oneto Ask Lemmy@lemmy.world•How to get away from owning a smartphoneEnglish16·8 months agoAddiction is a tough thing… Hard just to out it down.
Indeed, I’m feeling lazy and need a non-ai translator please… ?
ironsoap@lemmy.oneto Technology@lemmy.world•Sysadmins slam Apple’s SSL/TLS cert lifespan cutsEnglish18·9 months agoIf approved, it will affect all Safari certificates, which follows a similar push by Google, that plans to reduce the max-validity period on Chrome for these digital trust files down to 90 days.
Max lifespans of certs have been gradually decreasing over the years in an ongoing effort to boost internet security. Prior to 2011, they could last up to about eight years. As of 2020, it’s about 13 months.
Apple’s proposal would shorten the max certificate lifespan to 200 days after September 2025, then down to 100 days a year later and 45 days after April 2027. The ballot measure also reduces domain control validation (DCV), phasing that down to 10 days after September 2027.
And while it’s generally agreed that shorter lifespans improve internet security overall — longer certificate terms mean criminals have more time to exploit vulnerabilities and old website certificates — the burden of managing these expired certs will fall squarely on the shoulders of systems administrators.
Over the past couple of days, these unsung heroes who keep the internet up and running flocked to Reddit to bemoan their soon-to-be increasing workload. As one noted, while the proposal “may not pass the CABF ballot, but then Google or Apple will just make it policy anyway…”
…
However, as another sysadmin pointed out, automation isn’t always the answer. “I’ve got network appliances that require SSL certs and can’t be automated,” they wrote. “Some of them work with systems that only support public CAs.”
Another added: “This is somewhat nightmarish. I have about 20 appliance like services that have no support for automation. Almost everything in my environment is automated to the extent that is practical. SSL renewal is the lone achilles heel that I have to deal with once every 365 days.”
Until next year, anyway.
ironsoap@lemmy.oneto Mildly Infuriating@lemmy.world•A conversation with a school teacher in the state of FloridaEnglish5·9 months agoCross posting to facepalm, extremelyinfuriating, or rage does seem more appropriate.
ironsoap@lemmy.oneto Mildly Infuriating@lemmy.world•This means I close the tab, regardless of what is on the site.English1·9 months agoIncredibly hostile design. I generally avoid, but like Reddit they have hostage to some info I desire sometime so wipe my way through it… Close the browser, rm -rf /, and wash my hands.
ironsoap@lemmy.oneto Mildly Infuriating@lemmy.world•This means I close the tab, regardless of what is on the site.English18·9 months agoSounds like fandom.com
Even when disabled at a high level, their sub checks are still there and there are hundred of them. Deceptive BS.
ironsoap@lemmy.oneto Technology@lemmy.world•Youtube has fully blocked InvidiousEnglish2·10 months agoAgreed, now the fun part of coming up with a legal basis to do so and convincing regulators.
ironsoap@lemmy.oneto Technology@lemmy.world•Youtube has fully blocked InvidiousEnglish31·10 months agoI don’t think this requires an act of congress. I think you might see more consumer advocation on the part of FTC (although it doesn’t currently regulate online broadcast), or potentially the CFPB.
Admittedly it’s more likely to see the EU do some regulations, but it all depends on the election.
ironsoap@lemmy.oneto Technology@lemmy.world•Youtube has fully blocked InvidiousEnglish1·10 months ago
ironsoap@lemmy.oneto Ask Lemmy@lemmy.world•Do you take out expandable in your phone?English4·10 months agoI miss it all the time. I wish Pixels would get off their internal storage racket, or at least give you extremely large options.
ironsoap@lemmy.oneto Technology@lemmy.world•Youtube has fully blocked InvidiousEnglish11·10 months agoWhile I agree, I have a hard time seeing how people will stop using it until the field changes. Maybe in 10 years it will the the MySpace of the sitcom era, but right now it’s still growing. That growth is giving it carte blanche to manipulate the users as it sees fit. Regulation might impact it, but it’s still a bit of a Goliath.
- Compared to 2023, YouTube’s user base has grown by 20 million this year, representing a 0.74% increase. From Global media insights
Also the active user base is 2.7 billion people in 2024 from the same source above.
The alternatives are out there, but just not in the same league.
ironsoap@lemmy.oneto Technology@lemmy.world•YouTube confirms your pause screen is now fair game for adsEnglish26·10 months agoYt-DLP and it’s variation (Seal, YTDLnis, etc.), newpipe and it’s variation (Tubular, Newpipe Sponsorblock, etc) already allow you to do this without having to get manual.
What’s the privacy criteria you are thinking about?
ironsoap@lemmy.oneto Technology@lemmy.world•USPS Text Scammers Duped His Wife, So He Hacked Their OperationEnglish18·11 months ago[# Systematic Destruction (Hacking the Scammers pt. 2)
Taking on the “Smishing Triad”](https://blog.smithsecurity.biz/systematic-destruction-hacking-the-scammers-pt.-2) g
His blog on the topic if you don’t want the wired summary.
ironsoap@lemmy.oneto Piracy: ꜱᴀɪʟ ᴛʜᴇ ʜɪɢʜ ꜱᴇᴀꜱ@lemmy.dbzer0.com•ISPs Hijack Cloudflare/Google DNS Requests, Ending Site-Blocking Workarounds * TorrentFreakEnglish31·11 months agoA brief technical summary from iMAP reveals what happens when users attempt to access sites using Cloudflare and Google DNS.
• On Maxis, DNS queries to Google Public DNS (8.8.8.8) servers are being automatically redirected to Maxis ISP DNS Servers;
**
• On Time, DNS queries to both Google Public DNS (8.8.8.8) and Cloudflare Public DNS (1.1.1.1) are being automatically redirected to Time ISP DNS servers.
“Instead of the intended Google and Cloudflare servers, users are being served results from ISP DNS servers. In addition to MCMC blocked websites, other addresses returned from ISP DNS servers can also differ from those returned by Google and Cloudflare,” iMAP warns.
…
"Users that are affected, can configure their browser settings to enable DNS over HTTPS to secure their DNS lookups by using direct encrypted connection to private or public trusted DNS servers. This will also bypass transparent DNS proxy interference and provide warning of interference,” iMAP concludes.
Essentially Malaysia law required ISP to drop DNS entries for some sites, local users started using public DNS. ISP started redirecting public DNS requests, and local users started using DNS over HTTPS.
The pirate wars continue in their arms races.
ironsoap@lemmy.oneto Privacy@lemmy.ml•Can a website access my local network/learn about the existence of other devices without installing malware?English24·1 year agoWhat in the world are they digging for?
I did a quick search and they don’t make it easy. Peter Lowe’s ad and tracking server blocklist is the only one I found. EasyList doesn’t seem to have a donation link, nor Dan Pollock at someonewhocares.org. Also worth noting that UBO doesn’t take donations. You could always subscribe to AdGuard, but that’s mixed.
ironsoap@lemmy.oneto Technology@lemmy.world•Apple to ‘Pay’ OpenAI for ChatGPT Through Distribution, Not CashEnglish2·1 year agoAlternative link non paywalled
Good thing they found some in Montana. Not that it’ll be online for a while.
I think the market is going to struggle with this for a while yet, in the mist of this brewing trade war.