Nextcloud
melroy
- 0 Posts
- 50 Comments
melroy@kbin.melroy.orgto Piracy: ꜱᴀɪʟ ᴛʜᴇ ʜɪɢʜ ꜱᴇᴀꜱ@lemmy.dbzer0.com•Just found this 2,64TB Playstation 2 Collection. What a madman.4·3 days agoThanks! I just was planning to install my chip mod modbo v5.0.
Thanks for saying mbin is good software 👋😊
melroy@kbin.melroy.orgto Technology@lemmy.world•Google quietly released an app that lets you download and run AI models locally21·7 days agoI won’t gonna use my smartphone as a local llm machine.
Pocket just works. And now Mozilla is killing it. It’s a shame. There are even companies asking them to take over the software and support. So pocket will stay… Not sure how far that is.
melroy@kbin.melroy.orgto Technology@lemmy.world•Google quietly released an app that lets you download and run AI models locally131·8 days agonever go online again - they won’t be able to monitor anything, even if there’s code for that included.
Sounds counter-intuitive on a smart phone where you most likely want to be online again at some point in time.
melroy@kbin.melroy.orgto Technology@lemmy.world•FBI Wants Access To Encrypted iPhone And Android Data—So Does Europe1·8 days agoAnd you also don’t know if they are doing this already. So who knows it might be happening already.
melroy@kbin.melroy.orgto Piracy: ꜱᴀɪʟ ᴛʜᴇ ʜɪɢʜ ꜱᴇᴀꜱ@lemmy.dbzer0.com•Amazon Fire Sticks enable “billions of dollars” worth of streaming piracy51·8 days agoThe more piracy the better imo. And I don’t need to explain why anymore, that is obvious
melroy@kbin.melroy.orgto Selfhosted@lemmy.world•Do you actually audit open source projects you download?7·9 days agoYes. It’s important to verify the dependencies and perform audits like automated scans on the source code and packages from repositories like PyPi and npm. Which is done on my day job.
Also before mirroring data, I look at the source code level if I see anything suspicious. Like phoning home or for example obfuscated code. Or other red flags.
Even at home, working on ‘hobby projects’, I might not have the advantage of the advance scanning source code tools, but I’m still suspicious, since I know there is also a lot of sh*t out there.
Even for home projects I limit the amount of packages I use. I tent to only use large (in terms of users), proven (lot of stars and already out for a long time) and well maintained packages (regular security updates, etc.). Then again, without any advance code scanning tool it’s impossible to fully scan it all. Since you still have dependencies on dependencies with dependencies that might have a vurnability. Or even things as simple as openssl heartbleed bug or repository take overs by evil maintainers. It’s inevitable, but you can take precautions.
Tldr: I try my best with the tools I have. I can’t do more then that. Simple and small projects in C is easier to audit then for example a huge framework or packages with tons of new dependencies. Especially in languages like Python, Go and Javascript/typescript. You have been warned.
Edit: this also means you will need to update your packages often. Not only on your distro. But also when using these packages with npm and PyPi, go or php composer. Just writing your code once and deploy is not sufficient anymore. The chances you are using some packages that are vulnerable is very high and you will need to regularly update your packages. I think updating is just as important as auditing.
melroy@kbin.melroy.orgto Technology@lemmy.world•FBI Wants Access To Encrypted iPhone And Android Data—So Does Europe32·9 days agoDepends on how good the e2e application is written. But yea, since android is still in the middle of data transfer, as well as IO of storage. Meaning both iOS and android can be the man the in the middle software that is tapping off the data even before it’s getting encrypted.
Hopefully nobody is reading this from apple or Google, before I give them ideas. 😔
melroy@kbin.melroy.orgto Technology@lemmy.world•Telegram partners with xAI to bring Grok to over a billion users11·10 days agodeleted by creator
melroy@kbin.melroy.orgto Technology@lemmy.world•Forced E-Waste PCs And The Case Of Windows 11’s Trusted Platform6·10 days agoTry winegui as well…
melroy@kbin.melroy.orgto Technology@lemmy.world•Forced E-Waste PCs And The Case Of Windows 11’s Trusted Platform213·10 days agoInstall Linux already
melroy@kbin.melroy.orgto Technology@lemmy.world•German court sends Volkswagen execs to prison over Dieselgate scandal51·13 days agoIts finally happening
melroy@kbin.melroy.orgto Technology@lemmy.world•Most of us will leave behind a large ‘digital legacy’ when we die. Here’s how to plan what happens to it1·14 days agoI at least hope I will been remembered.
melroy@kbin.melroy.orgto Technology@lemmy.world•Valve CEO Gabe Newell’s Neuralink competitor is expecting its first brain chip this year3·14 days agoTinnitus is something very hard to ignore.
What happened? Why is it down 😭