Goofed Home

Conversation

$$5179
https://lemmy.world/u/thedoginthewok posted on Feb 28, 2026 00:44
In reply to: https://sh.itjust.works/comment/5548402

I know I’m replying to a two year old comment, but who cares.

I’ve had a Motorola Milestone (Motorola Droid in the US) in 2009 and I got an internet enabled plan immediately.

It was very expensive and capped at 200 Megabytes per month, so I only really used it for basic web browsing. Fucking loved that phone, though. I played through a few GBA games on an emulator, with the keyboard it worked great.

I’ve had spotify back then, but I never streamed anything, because of the data cap.

https://lemmy.world/comment/22387335

Silicon Valley Rallies Behind Anthropic in A.I. Clash With Trump

$$5177
https://infosec.pub/u/cm0002 posted on Feb 28, 2026 00:38

Actions by the president and the Pentagon appeared to drive a wedge between Washington and the tech industry, whose leaders and workers spoke out for the start-up.

Feb. 27, 2026

https://archive.ph/hwHbe

Sam Altman, the chief executive of OpenAI, said in a memo to employees this week that “we have long believed that A.I. should not be used for mass surveillance or autonomous lethal weapons.”

More than 100 employees at Google signed a petition calling on the tech giant to “refuse to comply” with the Pentagon on some uses of artificial intelligence in military operations.

And employees at Amazon, Google and Microsoft urged their leaders in a separate open letter on Thursday to “hold the line” against the Pentagon.

Silicon Valley has rallied behind the A.I. start-up Anthropic, which has been embroiled in a dispute with President Trump and the Pentagon over how its technology may be used for military purposes. Dario Amodei, Anthropic’s chief executive, has said he does not want the company’s A.I. to be used to surveil Americans or in autonomous weapons, saying this could “undermine, rather than defend, democratic values.”

https://infosec.pub/post/42713307

An open source, off-grid, decentralized mesh network built to run on affordable, low-power devices. No cell towers. No internet. Just pure peer-to-peer connectivity.

$$5176
https://infosec.pub/u/cm0002 posted on Feb 28, 2026 00:33

Also see !meshtastic@mander.xyz

https://infosec.pub/post/42712940

Conversation

$$5175
https://piefed.social/u/rimu posted on Feb 28, 2026 00:31
In reply to: https://activitypub.space/post/1407

It looks like this - https://piefed.social/c/adultswim@lemm.ee

https://piefed.social/comment/10324532

I'm bored, here's a photo.

$$5171
https://lemmy.world/u/over_clox posted on Feb 28, 2026 00:10

You wanna argue about it? It’s a spoon..

https://lemmy.world/post/43658385

Connect NetBird server to a peer?

$$4985
https://slrpnk.net/u/statelesz posted on Feb 27, 2026 15:41

I just installed NetBird on a VPS using the Self-Hosting Quickstart Guide. Now I want to connect the VPS using Netbird to another client. When I also use Docker to register the VPS as a Netbird peer the whole network gets messed up because now the server and the client try to manage the network. So how am I supposed to register the VPS as a netbird peer to connect it to other peers?

https://slrpnk.net/post/34658520

$$5023
https://lemmy.world/u/Hominine posted on Feb 27, 2026 17:07
In reply to: https://slrpnk.net/post/34658520

I’m not quite sure what you are asking but I run the Netbird management containers containers on a server and also run a native client alongside them to have the server itself also perform as a peer. Is that what you are looking to do above?

https://lemmy.world/comment/22380232
$$5127
https://slrpnk.net/u/statelesz posted on Feb 27, 2026 21:33
In reply to: https://lemmy.world/comment/22380232

Yes, but I also want to run the client in a container and the docs recommend to run the container using network_mode: host. And I suspect this creates a conflict in networks. So I want to have Netbird server, Netbird client and Nginx Proxy Manager all in containers share the same network.

https://slrpnk.net/comment/20973719

‘God of War’ First Look: Ryan Hurst Is Kratos and Callum Vinson Is Atreus in Prime Video’s Live-Action Series

$$5001
https://piefed.social/u/Skavau posted on Feb 27, 2026 16:21
https://piefed.social/c/television/p/1824369/god-of-war-first-look-ryan-hurst-is-kratos-and-callum-vinson-is-atreus-in-prime-videos

8 posts in conversation

$$5111
https://lemmy.zip/u/IWW4 posted on Feb 27, 2026 21:00
In reply to: https://piefed.social/c/television/p/1824369/god-of-war-first-look-ryan-hurst-is-kratos-and-callum-vinson-is-atreus-in-prime-videos

Kratos looks awesome, all the casting news about the show has been great. I am cautiously optimistic.

https://lemmy.zip/comment/24923258
$$5113
https://sh.itjust.works/u/Sineljora posted on Feb 27, 2026 21:02
In reply to: https://piefed.social/c/television/p/1824369/god-of-war-first-look-ryan-hurst-is-kratos-and-callum-vinson-is-atreus-in-prime-videos

Produced by fascists interested in your subscription. Do not support financially!

https://sh.itjust.works/comment/24012798

Bobby J. Brown, Actor on ‘The Wire,’ Dies at 62

$$5003
https://piefed.social/u/Skavau posted on Feb 27, 2026 16:25
https://piefed.social/c/television/p/1824381/bobby-j-brown-actor-on-the-wire-dies-at-62

$$5100
https://lemmy.dbzer0.com/u/tlekiteki posted on Feb 27, 2026 20:10
In reply to: https://piefed.social/c/television/p/1824381/bobby-j-brown-actor-on-the-wire-dies-at-62

SLOP

https://lemmy.dbzer0.com/comment/24664436
$$5110
https://lemmy.zip/u/IWW4 posted on Feb 27, 2026 20:58
In reply to: https://piefed.social/c/television/p/1824381/bobby-j-brown-actor-on-the-wire-dies-at-62

I don’t remember him in The Wire, RIP.

https://lemmy.zip/comment/24923212

Virtual Machines vs LXC vs Docker: What’s the Real Difference?

$$4618
https://lemmy.world/u/InternetCitizen2 posted on Feb 26, 2026 16:49

An informative YT channel I found. I’m sure many people here might already know, but I found it helpful and it makes the comm a good resource for newer folks looking to get a handle on what all these tools do and how they will use them in their selfhosting.

https://lemmy.world/post/43606507

8 posts in conversation

Word Count Linux: 3

$$4992
https://lemmy.world/u/non_burglar posted on Feb 27, 2026 16:02
In reply to: https://lemmy.blahaj.zone/comment/19388429

Cgroups is not a really a security feature (from what I understand). It is about controlling process priority, hierarchy, and resources limiting (among other things).

With respect, I think you misunderstand what gvisor does and containerization in general. cgroups2 is the isolation mechanism used by most modern Linux containers, including docker and lxc both. It is similar to the jail concept in BSD, and loosely to chroot. It limits child process access to files, devices, memory, and is the basis for how subprocesses are secured against accessing host resources without the permission to do so.

Gvisor adds more layers of control over this system by adding a syscall control plane to prevent a container from accessing functions in the host’s kernel that might not be protected by cgroups2 policy. This lessens the security risk of the host running a cutting-edge or custom kernel with more predictable results, but it comes with caveats.

Gvisor is not a universally “better” option, especially for homelab, where environment workloads vary a lot. Gvisor comes with an IO performance penalty, incompatibility with selinux, and its very strength can prevent containers from accessing newer syscalls on a cutting edge host kernel.

My original comment was that ultimately, there is no blanket answer for “how secure is my virtualization stack”, because such a decision should be made on a case-by-case basis. And any choice made by a homelabber or anyone else should involve some understanding of the differences between each type.

https://lemmy.world/comment/22379040
$$5109
https://lemmy.blahaj.zone/u/Neptr posted on Feb 27, 2026 20:33
In reply to: https://lemmy.world/comment/22379040

Yes, I understand what GVisor does. Cgroups2 are for isolation of system resources, bit arent even the main sandbox feature used for isolation by Docker. I am pretty sure namespaces significantly more important for these containers’ security.

GVisor helps with one of the main risks in a container setup which is the shared kernel by hosts and guests. I understand it comes with a performance penalty (and I didnt know it was incompatible with SELinux), but that does change my original point that GVisor is a security improvement to default Docker. I understand there is more nuance, even when I wrote my original comment I understood (just like any other security feature) it cant be used in every scenario. I was being intentionally general, and in my second comment I was pretty specific about what it protects against: Kernel vulnerabilities and privilege escalation.

I researched cgroups2 more and I still dont understand why you brought it up in the first place. Cgroups2 and gvisor provide very different security benefits. Cgroups help to keep a system available (lessening the risk DoS attacks) by controlling access to some system resources (io, devices, cpu, memory) and grouping processes of a similar type. It seems rather optimized to solve resource control on a container host. I mentioned gvisor because it is mostly just a drop-in replacement container runtime which doesnt need setup to be used.s

Now for a different container runtime which provides significantly more features (than gvisor) with less downsides (if configured correctly for a specific workload), Sydbox provides syd-oci which id an application kernel runtime which uses a permission config file to create a sandbox, isolating using namespaces, seccomp, landlock, and more. It can sandbox in many different categories (often times leveraging multiple features to provide a multilayer sandbox), you can see the categories at the syd manpage. The biggest downside is that you must really understand what your container application needs otherwise it will prevent it from running. It is a “secure by-default” sandbox which can be softened through config.

https://lemmy.blahaj.zone/comment/19397243

The Dexterity Deadlock

$$5108
https://infosec.pub/u/cm0002 posted on Feb 27, 2026 20:27
https://infosec.pub/post/42703555

Create New Post