• 0 Posts
  • 23 Comments
Joined 1 year ago
cake
Cake day: June 7th, 2023

help-circle
  • As with most things, it gets easier with practice. After enough practice, you’ll find many of the actions and reactions of driving will become habits you do automatically. Which is one of the reasons it’s a good idea to practice good habits now, as practice makes permanent. Take your time, and try to be predictable to other drivers (use your signals, don’t make radical maneuvers). And don’t let the assholes who think the horn is an “I’m annoyed at you” button get to you. Fuck them and the camel that came on them. Take your time and make sure you are driving your car in a way you can control.

    As for learning on a manual, yes that increases the difficulty. Depending on the specific vehicle, it can make it easier or harder. Some clutches will let you get away with murder, others will murder you for being less than perfect. Many years ago, my brother owned a car with a clutch that was just brutal. It would go from “not engaging” to “fully engaged” within the slightest movement. My truck, on the other hand, the clutch was so forgiving, you damn near couldn’t stall it. Thankfully, I learned to drive a stick on my truck and when I tried my brother’s car, it took a lot less time to get used to it. As above, take your time and it will come to you with practice.





  • Have you considered just beige boxing a server yourself? My home server is a mini-ITX board from Asus running a Core i5, 32GB of RAM and a stack of SATA HDDs all stuffed in a smaller case. Nothing fancy, just hardware picked to fulfill my needs.

    Limiting yourself to bespoke systems means limiting yourself to what someone else wanted to build. The main downside to building it yourself is ensuring hardware comparability with the OS/software you want to run. If you are willing to take that on, you can tailor your server to just what you want.



  • No, but you are the target of bots scanning for known exploits. The time between an exploit being announced and threat actors adding it to commodity bot kits is incredibly short these days. I work in Incident Response and seeing wp-content in the URL of an attack is nearly a daily occurrence. Sure, for whatever random software you have running on your normal PC, it’s probably less of an issue. Once you open a system up to the internet and constant scanning and attack by commodity malware, falling out of date quickly opens your system to exploit.


  • Short answer: yes, you can self-host on any computer connected to your network.

    Longer answer:
    You can, but this is probably not the best way to go about things. The first thing to consider is what you are actually hosting. If you are talking about a website, this means that you are running some sort of web server software 24x7 on your main PC. This will be eating up resources (CPU cycles, RAM) which you may want to dedicated to other processes (e.g. gaming). Also, anything you do on that PC may have a negative impact on the server software you are hosting. Reboot and your server software is now offline. Install something new and you might have a conflict bringing your server software down. Lastly, if your website ever gets hacked, then your main PC also just got hacked, and your life may really suck. This is why you often see things like Raspberry Pis being used for self-hosting. It moves the server software on to separate hardware which can be updated/maintained outside a PC which is used for other purposes. And it gives any attacker on that box one more step to cross before owning your main PC. Granted, it’s a small step, but the goal there is to slow them down as much as possible.

    That said, the process is generally straight forward. Though, there will be some variations depending on what you are hosting (e.g. webserver, nextcloud, plex, etc.) And, your ISP can throw a massive monkey wrench in the whole thing, if they use CG-NAT. I would also warn you that, once you have a presence on the internet, you will need to consider the security implications to whatever it is you are hosting. With the most important security recommendation being “install your updates”. And not just OS updates, but keeping all software up to date. And, if you host WordPress, you need to stay on top of plugin and theme updates as well. In short, if it’s running on your system, it needs to stay up to date.

    The process generally looks something like:

    • Install your updates.
    • Install the server software.
    • Apply updates to the software (the installer may be an outdated version).
    • Apply security hardening based on guides from the software vendor.
    • Configure your firewall to forward the required ports (and only the required ports) from the WAN side to the server.
    • Figure out your external IP address.
    • Try accessing the service from the outside.

    Optionally, you may want to consider using a Dynamic DNS service (DDNS) (e.g. noip.com) to make reaching your server easier. But, this is technically optional, if you’re willing to just use an IP address and manually update things on the fly.

    Good luck, and in case I didn’t mention it, install your updates.






  • Sort of yes, sort of no. This is one of those places where the US Federal system of government would be beneficial. For the most part, Homicide is a State crime. This means that the State where the crime occurred would have jurisdiction and The US President would not have the power to pardon for that crime. So, let’s say that Biden sends a private hitman (and not Seal Team 6, the FBI or whatever fevered dream part of the US Government Trump comes up with next) to kill Trump. Said hitman would be indicted in New York under New York law for the homicide. President Biden’s power to pardon would not be able to help the hitman. By contrast, New York Governor Kathy Hochul probably could (I can’t be arsed to look up the power of pardon in New York). Where this breaks down is in DC or other Federal land (e.g. military bases). Since those are Federal lands, the Federal Government would have jurisdiction and the President probably would have the power of pardon.


  • And once you have found your specific collection of plugins that happen not to put the exact features you need behind a paywall but others, you ain’t touching those either.

    And this is why, when I’m investigating phishing links, I’ve gotten used to mumbling, “fucking WordPress”. WordPress itself is pretty secure. Many WordPress plugins, if kept up to date, are reasonably secure. But, for some god forsaken reason, people seem to be allergic to updating their WordPress plugins and end up getting pwned and turned into malware serving zombies. Please folks, if it’s going to be on the open internet, install your fucking updates!


  • The answer to that will be everyone’s favorite “it depends”. Specifically, it depends on everything you are trying to do. I have a fairly minimal setup, I host a WordPress site for my personal blog and I host a NextCloud instance for syncing my photos/documents/etc. I also have to admit that my backup situation is not good (I don’t have a remote backup). So, my costs are pretty minimal:

    • $12/year - Domain
    • $10/month - Linode/Akamai containers

    The Domain fee is obvious, I pay for my own domain. For the containers, I have 2 containers hosted by the bought up husk of Linode. The first is just a Kali container I use for remote scanning and testing (of my own stuff and for work). So, not a necessary cost, but one I like to have. The other is a Wireguard container connecting back to my home network. This is necessary as my ISP makes use of CG-NAT. The short version of that is, I don’t actually have a public IP address on my home network and so have to work around that limitation. I do this by hosting NGinx on the Wireguard container and routing all traffic over a Wireguard VPN back to my home router. The VPN terminates on the outside interface and then traffic on 443/tcp is NAT’d through the firewall to my “server”. I have an NGinx container listening on 443 and based on host headers traffic goes to either the WordPress or NextCloud container which do their magic respectively. I also have a number of services, running in containers, on that server. But, none of those are hosted on the internet. Things like PiHole and Octoprint.

    I don’t track costs for electricity, but that should be minimal for my server. The rest of the network equipment is a wash, as I would be using that anyway for home internet. So overall, I pay $11/month in fixed costs and then any upgrades/changes to my server have a one-time capital cost. For example, I just upgraded the CPU in it as it was struggling under the Enshrouded server I was running for my Wife and I.



  • Marketing is far from dead. Larian themselves used it to great effect with BG3. Does no one remember the announcement trailer released for BG3 well in advance of any gameplay footage? That’s marketing, though and through. And yes, it worked plenty well on me. A D&D game based around Mind Flayers, made by the folks behind Divinity Original Sin? Shut up and take my money. Also, when I noticed the outline of a Nautiloid ship in the background, I may have needed a change of shorts.

    The difference with BG3 was that Larian didn’t just pull an Edward Bernays style marketing as a con. They delivered a good product, worked with players to fix any issues and have gone above and beyond supporting the game after release. They have done everything right to build long term customer relationships. Maybe they don’t reach the same level of profits some other companies might, by stuffing microtransactions in every orifice. But, I suspect they are profitable and seem to be better built be continue long term and not have to tear the company up and saddle one of those pieces with insane amounts of debt.

    While I can’t promise that I’ll buy their next game, I’ll undoubtedly keep an eye out for it. Larian puts out a quality product and doesn’t fuck their customers. That’s what makes their brand of marketing work.