-
sagaracharya
Do y'all use physical servers to host or you use remote servers or VPS providers?
-
moparisthebest
both
-
sagaracharya
moparisthebest: Which physical server?
-
moparisthebest
one in my server closet at home
-
balabol.im
> Do y'all use physical servers to host or you use remote servers or VPS providers? Single-board comp.+ssd
-
sagaracharya
Nice! :) I feel proud. All people I hear use ssh, remote servers
-
Quinn64
I'm using a RPi4 hosted through Njalla's VPN service
-
moparisthebest
My server is remote when I'm not at home :)
-
Link Mauve
I also use ssh to connect to my server, one room away. :p
-
Link Mauve
It doesn’t even have a screen plugged in. ^^
-
sagaracharya
> My server is remote when I'm not at home :) ssh is the worst thing ever wrt computer security
-
sagaracharya
ssh means anyone use my computer and destroy the meaning of malicious cracking!
-
msavoritias
can we please not have misinformation in here? sagaracharya can you please read about ssh and ipv6 or anything else before says statements like this? thank you
-
Guus
telnet ftw!
- Guus runs, hides.
-
sagaracharya
> can we please not have misinformation in here? sagaracharya can you please read about ssh and ipv6 or anything else before says statements like this? thank you Ok. You're assuming that I don't know. Please learn before speaking
-
sagaracharya
Can you keep the keys safe?
-
sagaracharya
Your private key?
-
sagaracharya
Do you know even a shred about end point security?
-
sagaracharya
That is not misinformation
-
jonas’
oh it very much is
-
jonas’
SSH-the-software and SSH-the-protocol are not the worst thing ever wrt computer security. If you cannot manage your credentials, that's a separate issue.
-
jonas’
you could for instance use a hardware security module like a yubikey if you don't trust the safety of your private key on a filesystem.
-
jonas’
The OpenSSH server is one of the most reliable pieces of software in regards to security ever made, if you take the amount of exposure it typically has into account.
-
sagaracharya
> you could for instance use a hardware security module like a yubikey if you don't trust the safety of your private key on a filesystem. Yes, but the command to fetch the key is given by the processor
-
sagaracharya
Master is the processor, not the yubikey
-
sagaracharya
> The OpenSSH server is one of the most reliable pieces of software in regards to security ever made, if you take the amount of exposure it typically has into account. I agree. But the problem lies not in OpenSSH but in other gigantic buggy softwares
-
jonas’
great, so the statement "ssh is the worst thing ever wrt computer security" is false by your own account.
-
jonas’
also note that before SSH, we had _telnet_
-
jonas’
which is oh so much worse
-
Trung
sagaracharya: you don't have to use OpenSSH or any SSH what so ever. It's your server do what you want. And on that same piece of logic, when it's not your server, it's none of your bussiness 😁
-
jonas’
sagaracharya, this is not the place for polemics or hyperboles (which that statement probably was meant to be). Please keep them elsewhere. I advise you to be careful and err on the side of caution when you write here next.
-
sagaracharya
> sagaracharya: you don't have to use OpenSSH or any SSH what so ever. It's your server do what you want. And on that same piece of logic, when it's not your server, it's none of your bussiness 😁 Oh wow. Thanks for your profound knowledge. I didn't know that. I thought your server is mine!
-
Trung
yeah i'm here: https://trung.fun
-
sagaracharya
jonas’: ok, thanks. I'll certainly keep your important advice next time or rather every time that I speak. Any more teachings, my guru?! :D
-
jonas’
sagaracharya, yes, cut the sarcasm.
-
sagaracharya
No orders please
-
Trung
yay
-
ernst.on.tour
sagaracharya: Dünnes Eis, ganz dünnes Eis ...
-
Trung
and sagaracharya is here: 49.36.111.29 "monoclesbrowser/1.0"
-
jonas’
Trung, please don't publicly post IP addresses of other people, if that's what you just did.
-
Trung
well if he comes back and confirm it we'll know
-
Menel
General and friendly reminder : https://xmpp.org/extensions/xep-0458.html#sect-idm45629458263072 ff
-
Link Mauve
And https://github.com/xsf/xeps/pull/1288 to fix that link a bit. :)
-
Guus
Thanks for turning this into something that's at least remotely constructive, Link Mauve :)
-
Link Mauve
:D
-
Licaon_Kter
PSA: https://letsencrypt.org/2023/07/10/cross-sign-expiration.html
-
Menel
^is there anything to do about it for older clients now? Without moving away from let's encrypt I mean..
-
Menel
At least it is still more then one year away..
-
Licaon_Kter
Menel: you can do this https://codeberg.org/iNPUTmice/Conversations/commit/fedd1a68d7622a9e85d3a13529c36e940b854e74
-
fatoumata
slight OT: but everyone _should_ setup pam_google_authenticator for SSH this instructions work for many systems just fine: https://wiki.archlinux.org/title/Google_Authenticator
-
Guus
That gives 2FA for SSH logins? I can see how that would be useful, yes.
-
moparisthebest
If you use passwords for authentication yes, but just don't
-
fatoumata
and reminder to set a strong password on your ssh keys, so that if they are stolen they won''t be too useful
-
fatoumata
it still has benefit with keys mopar
-
moparisthebest
It's debatable, I'm not really a fan
-
fatoumata
most people have no password at all on their keys, one firefox exploit and they're sent off somewhere along with .ssh/known_hosts reminder to also set `HashKnownHosts yes` in your .ssh/config to mitigate that and also `IdentitiesOnly yes` while you're there
-
Guus
https://tech.lgbt/@kasdeya/110688847833828258
-
moparisthebest
Now those sound like good tips that won't annoy the crap out of me :)
-
moparisthebest
Guus: haha nice
-
Licaon_Kter
Ghosts are like screen/tmux sessions.ee✎ -
Licaon_Kter
Ghosts are like screen/tmux sessions. ✏
-
Martin
> Establishing a secure connection from linkmauve.fr to mdosch.de failed. Certificate hash: (No certificate). No Link Mauve here?
-
mimi89999
Establishing a secure connection from linkmauve.fr to lebihan.pl failed. Certificate hash: (No certificate).
-
Licaon_Kter
The LE intermediate fairy came earlier?