dentacle

joined 20 hours ago
[–] dentacle@bookwyr.me 10 points 8 hours ago* (last edited 8 hours ago)

The Russian Playbook? I think that's what it's called. Or "Russian Presidential Roulette".

Edit: I think I have to explain, not everyone is old enough to remember who Medvedev is and what kind of a tool he was for Putins domination.

[–] dentacle@bookwyr.me 4 points 8 hours ago* (last edited 8 hours ago)

Sorry you went through that.

Me? Who said that was me? I never said that. How rude. Nothing like that could ever happen to a brilliant guy like me. No, you shut up!

I still haven’t put anything of consequence on the VPS

Maybe keep it that way? It's just not worth it in the end. If you just want to play with new tech on a VPS, have at it. But maybe without important data, and make sure to tell every user of your services about the risks. Because in the end, you are responsible. You are not Microsoft, a company that was never held accountable for billions in corporate damages through cyber-securitty bullshit.

[–] dentacle@bookwyr.me 1 points 9 hours ago (2 children)

Blue teaming is hard.

After 20 years in the field I'd say it's an impossible job. We are always 5 steps behind. Now with AI, 27 steps. I quit IT to keep my sanity.

And don't listen to the promises of big companies with billion-funds, they cook with water like the rest of us. See " Amazon infiltrated by North-Korea ".

[–] dentacle@bookwyr.me 7 points 10 hours ago (6 children)

I like what you are doing, but I want to tell a little story for educational purposes:

Once there was an IT pro (like in "it's their job to do stuff like that for money, but with a team and funds") who thought he's smarter than the internet and started selfhosting on a VPS for the family. Nothing dramatic, just some nextcloud stuff and games for the kids. Everything was secure and always up-to-date, backups to multiple locations, the works.

This worked for years, but one night Mr. Smartypants made a tiny config change that needed to be reversed for full security. But he forgot about it. And it took only 3 hours for a bad actor to exfil all data and burn the VPS to the ground. And that was before AI started to roam the web...

You get the idea: you can do everything right, but then you will make that one tiny mistake or forget an update. With the internet at its actual state you can asume all your data will be compromised or gone at some point. Just make sure that's ok for you.