• 0 Posts
  • 40 Comments
Joined 3 years ago
cake
Cake day: November 16th, 2023

help-circle
  • It’s better than that.

    Ford has been in power since 2018. In his first two years, his admin advocated for and pushed through legislation specifically to allow speed cameras to be installed in municipalities. This may have been leftover legislative planning from the previous party, but in either case it rode through with conservative favour.

    Political interests have since shifted, and with his most recent term as Premier, he’s been loudly admonishing any municipality that installs speed cameras, bike lanes or other traffic calming measures because he’s parroting nonsense about how it restricts traffic in high density areas and is making a stink about how it all just increases congestion.

    It’s dangerous, stupid and frustrating. He’s made threats to municipalities thay don’t agree with his declarations, attempting to deny typical grants allocated to improving infrastructure in smaller regions.





  • Darknet used to be good, but there’s been a shift in the content recently in which it feels like Rhysider doesn’t feel like he’s interviewing someone as much as he’s trying to be that annoying guy at the party who keeps butting in to try and tell your story for you.

    I can’t quite tell what changed, or when, but I feel like he used to give his subjects a lot more room to breathe instead of imposing his own personality over everything.


  • I don’t feel bad for Microsoft, but responsible disclosure is about more than that.

    It’s ethical. It gives the developer time to correct an error before it has the potential to affect anyone using their products. When you don’t follow that process, whether one set out by the developer, or a best effort on your part, you are now contributing to the potential harm caused by that vulnerability.

    This isn’t universal, and I have no doubt that Microsoft is also partly to blame, but there’s a significant element of attention seeking in the mix here. They could have reached out to other security researchers, validated the findings in private and found another channel to work through. Maybe he tried, but largely it seems like his actions are retaliatory and broadly harmful to anyone who has to administer these products.

    I have a lot of respect for security researchers. My job relies on the work they do and the skill it takes to do it. But part of that relies on doing things in a way that minimizes potential harm.


  • I was mostly making the comment in jest. I do rename, but my folder structures, as someone who downloads everything manually based on what I want to watch rather than doing the automated *arr stuff leaves it in directories only I consider sensible.

    I have Jellyfin behind a reverse proxy that lives in a DMZ and a WAF to go with it. I’m sure there’s still room for watching an unauthenticated stream because I forgot to rename a folder somewhere, but it’s not exactly an attack vector I care about. I’m more concerned about DDoS or impersonation attacks, which I also attempt to mitigate via an LDAP implementation behind the scenes.

    It’s not perfect, but it’s the best effort I can make at the moment.