Just your normal everyday casual software dev. Nothing to see here.

  • 0 Posts
  • 166 Comments
Joined 3 years ago
cake
Cake day: August 15th, 2023

help-circle


  • Said backdoor isn’t possible with the current day key exchange process. Without the servers in use private key, the most law agencies can do without acquiring the private key is force the CA to revoke a cert, which will disallow properly configured clients from accessing and transferring data with the server.

    LE doesn’t have enough information to recreate the private key based off the public key, the only key distributed during the CSR process is the servers public key via a certificate signing request which is signed using your private key, which the CA then signs with it’s own intermediate key (which is signed by it’s root server certificate) and hands back to the private server.

    The CA doesn’t have the ability to create that private key, and as such doesn’t have a way to decrypt traffic that is using that key. There is no concern for a backdoor in that process.

    In order for the “backdoor” to exist, they would need to either copy the private key as part of the signing process (which it doesn’t), or somehow force the server admin to use a new private key (that the CA also holds) or somehow compromise the servers key generation process to allow for an escrow on the private key when it was generated which would allow the CA to be able to recreate the private key using the master & public key.

    Now don’t take me wrong, you can still have a MiTM impersonation attack or a full impersonation bypass by the CA issuing a new certificate and having the DNS registrar have the web address go to a new server that is using the new key but, that’s not something the CA alone has the capability of doing, and any traffic that is issued to the original server still wouldn’t be compromised, its just clients visiting your site will end up at the other site and as such will end up using keys that the other side generated instead of your own keys and additionally said new keys would also be appearing in Certificate transparency logs, or modern day clients would refuse to use them.



  • Is this accurate? Like, I know what you’re meaning, but I’m pretty sure it’s not ICANN doing it, and more so your domain registrar handing it over to the US government.

    I think the most control that ICANN has over it is they could theoretically, if they wanted to, delete an entire top level domain. Since they do control the DNS root, but that is the most that they control from what I understand.

    I don’t know if they have the ability to delete or transfer control over an individual domain on legal request. I think that’s outside of what their actual system allows for.




  • That is an interesting concept, I would argue that it wouldn’t tackle the root cause of why most would want to federate due to rules just being universally applied to both the user instance and the community instance for the mega instances, and it still wouldn’t do anything with it being against the spirit of the fediverse in terms of needing to spread or web out, but I agree it would be nice.


  • I tend to agree that the majority of communities are hosted on 3 major instance’s its a concern that makes it difficult remove any of the 3 or 4 mega instances regardless of policies or practices.

    I see many saying just boycott or block .world but, a decent source of communities im in are listed there. I know it’s against the spirit of fediverse but I don’t see that changing any time soon.


  • Pika@sh.itjust.workstoSelfhosted@lemmy.world•Homelab discussion
    link
    fedilink
    English
    arrow-up
    7
    ·
    edit-2
    2 months ago

    I use proxmox on one server, but currently my layout is:

    • docker 1:
      • Authentik first network
      • heimdall
      • immich
      • jellyfin
      • NPM first network
      • zipline
    • docker 2:
      • authentik second network
      • npm second network
      • blorp
      • gitlab-runner
      • ladder
      • metube
      • photon
      • privatebin
      • tandoor
      • bar assistant
      • sponsor block

    LXCS:

    • database server
    • pihole
    • wireguard
    • mail server (postfix/dovecot)
    • zoneminder
    • zabbix
    • gitlab
    • matrix
    • xmpp/openfire
    • revolt/stoat
    • gamevox (temporary)
    • pufferpanel - minecraft
    • pufferpanel - ark
    • palworld
    • discord development container
    • projects container

    VMs:

    • homeassistant
    • ipa server
    • firewall
    • Syncthing / immich storage / PXE server/ File storage

    Also thank you for making this post, it helped me realize I have a few containers and services I don’t use and I don’t think have activity on them anymore so I can start a deprecation cycle on them lol


  • I use proxmox on one server, but currently my layout is:

    • docker 1:
      • Authentik first network
      • heimdall
      • immich
      • jellyfin
      • NPM first network
      • zipline
    • docker 2:
      • authentik second network
      • npm second network
      • blorp
      • gitlab-runner
      • ladder
      • metube
      • photon
      • privatebin
      • tandoor
      • bar assistant
      • sponsor block

    LXCS:

    • pihole
    • wireguard
    • mail server (postfix/dovecot)
    • zoneminder
    • zabbix
    • gitlab
    • matrix
    • xmpp/openfire
    • revolt/stoat
    • gamevox (temporary)
    • pufferpanel - minecraft
    • pufferpanel - ark
    • palworld
    • discord development container
    • projects container VMs:
    • homeassistant
    • ipa server
    • firewall
    • Syncthing / immich storage / PXE server/ File storage

    Also thank you for making this post, it helped me realize I have a few containers and services I don’t use and I don’t think have activity on them anymore so I can start a deprecation cycle on them lol


  • As someone who ran Ubuntu server for a few years before moving to Debian. I would recommend Debian over Ubuntu just because I have had to do less maintenance with it. When I was on Ubuntu updating it was a constant concern of “will something change that is bad” for example they pushed the kernel live patch and the Ubuntu subscription banner as an update instead of an upgrade, so I updated as normal, and there it was.

    I dislike OS’s that install new packages as part of their update procedures (an update that installs a new package instead of replacing an existing one should be reserved for upgrades), and Debian has never done that with me, so Debian is where I stay.


  • I noticed this myself by complete coincidence when itjust.works updated and I could click on my own comments and they wouldn’t pull anything.

    I had thought that it might have been a bug with the server so I switched over to the standard Lemmy instance and it would load fine.

    Then I dug through the settings more and I found the toxic mode hidden in the advanced settings. and realized that when I enabled toxic mode I could see the comment tree.

    Weirdly enough, I did a deep dive into all the black lists that it has hard-coded when I saw and I couldn’t for the life of me find out what was flagging that post from being able to be seen. None of the instances of anyone in the comment train were in the black list, I guess it’s possible that the instance itself was in a blacklist, but I forgot to check that.



  • I’m not sure, I was running 2.7.5 myself but i am not sure what version of immich I started with. I didn’t think this would effect fully docker setups much. I think this would mostly effected people who had configured with a preexisting database. I believe the docker edition with postgres built in upgraded for you awhile back unless you supplied an environment variable telling it to do otherwise.