Remote
RSSI / CISO / BOfH • patpro.net • #FreeBSD • Compte personnel
160
Followers
152
Following
37
Posts
Joined March 19, 2025
Posts
Replying to
@muddle@infosec.exchange
@muddle@infosec.exchange @simon@fedi.simonwillison.net for years the marketing around AI is that it's too powerful, they did it twice with chatgpt.
This is the third one.
Open post
Open post
Replying to
@stefano@mastodon.bsd.cafe
@stefano@mastodon.bsd.cafe if I had this kind of person in my team, I would fire them ASAP. That’s a quite impressive level or incompetence.
0
1
0
0
Open post
What would be your fanless + headless mini PC of choice for a FreeBSD server?
1x 1Gbps Eth port, 32GB RAM minimum, 6 CPU cores minimum, 1x NVMe + 1x 2.5 SATA
#fanless #selfhosting #freebsd
0
1
1
0
Open post
Open post
Open post
Open post
Open post
J’ai commis un truc, au sujet des LLM et des mots de passe…
https://www.patpro.net/blog/index.php/2026/05/03/3867-analyse-des-mots-de-passe-generes-par-llm/
0
2
0
0
Open post
Replying to
@angiegaudion@mastodon.social
@angiegaudion L’annonce précise «Au cours de ces derniers mois, certains sites ont fait l’objet de plusieurs attaques de type DDoS.».
Alors, désolé de ce qui arrive à la LPO AURA, mais les DDoS (si on parle bien de l’activité malveillante, et pas de la conséquence du passage de robots d’aspiration mal réglés) ça ne s’évite pas avec une sécurisation de serveur.
On fait le dos rond et on attend que ça passe, avec éventuellement l’aide d’un prestataire d’infrastructure : par exemple l’hébergeur, si il propose un service de protection ou bien un opérateur tiers comme bunny.net (https://docs.bunny.net/shield/ddos)
On peut toujours optimiser le serveur au max, mettre toutes les pages en cache pour soulager le serveur et la base de données, mais au final un DDoS ça coûte tellement peu cher que n’importe qui d’un peu motivé peut envoyer plus de trafic que ne pourra jamais en traiter le serveur.
bonne chance !
1
0
0
0
Open post
Replying to
@biyokea@toot.cat
0
4
0
0
Open post
Replying to
@subnetspider@mastodon.bsd.cafe
@subnetspider anything relevant in vm-bhyve.log?
0
1
0
0
Open post
Replying to
@mwl@io.mwl.io
@mwl@io.mwl.io @encthenet@flyovercountry.social what you describe is essentially every password manager on Earth.
I got something like +400 entries in my password manager, there’s no way I know them all, so it’s basically something my computer knows.
Same goes obviously for passkeys I store in that safe, or that are inside my Yubikeys.
Still, it’s super robust, and far more safe than anything «I know».
Also, using passkey does not mean you have to share them with Apple or anyone else. If you care, use a physical key or a selfhosted password manager.
0
0
0
0
Open post
Open post
Open post
Replying to
@aaribaud@mastodon.art
@aaribaud@mastodon.art
«in countries where the GDPR applies» <- you got this wrong, GDPR applies everywhere as soon as you are an European Union citizen.
Edit: correction «European citizen» -> «European Union citizen»
@Khrys@mamot.fr
0
5
0
0
Open post
Replying to
@_elena@mastodon.social
@_elena@mastodon.social Bain Capital Crypto is involved in the European project supposed to create an alternative to GitHub. Super red flag, I think.
https://goodtech.info/tangled-levee-fonds-alternative-open-source-github/
7
1
12
0
Open post
Replying to
@_elena__dup_5049@mastodon.social
@_elena@mastodon.social let us know about the details of your mesh radio experiment, my curiosity is ON. :)
1
0
0
0
Open post
Replying to
@NanoRaptor@bitbang.social
@NanoRaptor@bitbang.social @billgoats@bitbang.social this is epic :D
0
0
0
0
Open post
Replying to
@stefano@mastodon.bsd.cafe
@stefano @ajlewis2
I often use the Advanced bash scripting guide, even though it's a bit old. I have the latest pdf on every desktop machine ;)
https://tldp.org/LDP/abs/html/
https://archive.org/details/abs-guide_202301
1
2
0
0
Open post
Replying to
@ainmosni@social.ainmosni.eu
@ainmosni @_elena
That was my first comment too: you’ll have to test your backups otherwise you don’t know if you have backups :)
It’s a Schrödinger’s cat type of problem −> you have to open the box.
And it leads me to a second aspect: automation. good backup processes (the one that brings piece of mind) are automated. And of course the backup check can be automated too.
It’s piece of cake for a backup solution that you can script (borg, restic, kopia, rsync, etc.) but frankly I don’t know about Yunohost, may be you can’t do better.
On the side, I’ll share one of my sysadmin fails: I had a finely tuned backup process with scripts/config/etc. that was running daily for years flawlessly. Someday I leveraged that backup as a source of data to do a server migration (shutdown old system, start new one, restore data from backup). That worked great. Then I tested some web apps: epic failure (missing MySQL tables). What could have gone wrong?
Answer: I had setup my backup script to ignore files named */mysql/*log* because I don’t want to backup MySQL log files. Not so much of a surprise: this element of config instructed my backup process to exclude database files named like dc_log.MYD or oc_login_address.ibd (and many others).
Of course I had another way to retrieve the missing data. But, hell, I was not comfortable.
1
0
0
0
Open post
Replying to
@schwaigbub@mastodon.social
And here we are! I’ve reinstalled Portal on my gaming rig and I hold @NanoRaptor@bitbang.social responsible for it! :D
@JuliaRez@chaos.social @schwaigbub@mastodon.social
1
0
0
0
Open post
Replying to
@NanoRaptor__dup_1737@bitbang.social
@NanoRaptor@bitbang.social @JuliaRez@chaos.social pretty sure most of them have been copied and enriched by Aperture Science Enrichment Center.
1
1
0
0
Open post
Open post
Replying to
@micahflee@infosec.exchange
@micahflee there’s a lot to say, actually: https://www.shodan.io/host/69.164.211.16
1
1
0
0
Open post
Replying to
@loadingartist@mastodon.world
@loadingartist@mastodon.world perfect modern version of Time Enough at Last, a classic Twilight Zone episode
https://en.wikipedia.org/wiki/Time_Enough_at_Last
1
2
3
0
Remote instance
social.patpro.net
Open on original server
: :
: