Aussie living in the San Francisco Bay Area.
Coding since 1998.
.NET Foundation member. C# fan
https://d.sb/
Mastodon: @dan@d.sb

  • 12 Posts
  • 5.03K Comments
Joined 3 years ago
cake
Cake day: June 14th, 2023

help-circle
  • Whether your co-op can buy cheaper than Colesworth retail prices is a different matter.

    Some people are willing to pay a bit more if it means supporting a community store over a big corporate one.

    I’m living in the USA now, and there’s a lot more supermarkets here. In my area in California, there’s a few local chains with 3-4 stores, some co-ops, and the major stores. The biggest supermarket (Walmart/Sam’s Club) only has 20% market share, and even the top 5 companies (Walmart, Kroger, Costco, Albertsons and Ahold Delhaize) still only account for 44% market share. The top 3 in Australia (Coles, Woolworths, and Aldi) account for around 75% market share.


  • All three are defined by the license.

    Some software is “source-available”, meaning you can see the code but it’s not open-source. Microsoft uses to do this a lot with the .NET Framework (they called it “shared source”), before they created a new version that was open-source from the beginning.

    One of the issues with this type of code is that it often taints you. With the old .NET shared source for example, you weren’t allowed to redistribute the code or use it for other purposes. if you ever looked at that source code, you weren’t allowed to contribute to competing open-source projects like Mono, since they had no way to guarantee that the code you were contributing wasn’t influenced by what you saw in the shared source, or that you didn’t just copy and paste it from Microsoft’s code.

    There’s some popular self-hosted projects that are source-available rather than open-source, like n8n and Sentry.

    These days it’s more common for software to be “open core”, meaning the core functionality is open-source, but extra stuff around it is only source-visible with a proprietary license, usually requiring a paid subscription to be allowed to use it.


  • Free- and open source is not the same!

    You’re right, but in reality it usually doesn’t matter. All common licenses (GPL, LGPL, MIT, BSD, Apache, MPL) fit both definitions: free software as defined by FSF, and open-source as defined by OSI.

    It’s only really niche licenses where it differs - for example NASA’s Open Source Agreement is open-source (OSI approved) but not free (not FSF approved) because of this clause:

    Each Contributor represents that its Modification is believed to be Contributor’s original creation and does not violate any existing agreements, regulations, statutes or rules, and further that Contributor has sufficient rights to grant the rights conveyed by this Agreement.

    This is what the FSF say about it:

    The NASA Open Source Agreement, version 1.3, is not a free software license because it includes a provision requiring changes to be your “original creation”. Free software development depends on combining code from third parties, and the NASA license doesn’t permit this.

    Note that “free” refers to freedom, not price. Both definitions allow you to charge money for the software. However, you can’t restrict the user’s freedoms, so someone that buys the software could give it to someone else for free, and you wouldn’t be able to stop that while still remaining FOSS.


  • danAtoSelfhosted@lemmy.world•Anyone using 6-day certs yet?
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 days ago

    Makes sense! I didn’t realise it has a UI.

    I’ve got a bunch of snippets in /etc/nginx/snippets/, so for example I just need to add include snippets/proxy.conf to a server block to add most of the configuration needed for a reverse proxy. I’ve been using Nginx for long enough that I just write the rest of the server block by hand.



  • danAtoSelfhosted@lemmy.world•Anyone using 6-day certs yet?
    link
    fedilink
    English
    arrow-up
    5
    ·
    2 days ago

    Caddy is a good piece of software.

    I’ve been using Nginx for 20 years and don’t really have a reason to switch, so I’m still using it. I use certbot, so it’s just one command to create the certificate initially, and then it auto-renews automatically via a systemd timer.


  • danAtoSelfhosted@lemmy.world•Anyone using 6-day certs yet?
    link
    fedilink
    English
    arrow-up
    8
    arrow-down
    1
    ·
    edit-2
    2 days ago

    A private key leaking is bad, since anyone with the private key can decrypt data that was encrypted with it.

    Traditionally, the way that leaked certs were handled was via Certificate Revocation Lists (CRL). CRLs contain lists of revoked certificates - their serial number, revocation date, and the reason why they were revoked.

    However, CRLs are imperfect. Checking for revoked certificates every time you go to a site would slow things down a lot, as the lists are now too large to check and download real-time. Modern browsers and other TLS clients periodically download the lists in the background. Also, it might take a while between when the certificate is compromised and when the company notices the compromise.

    Because of this, the CA/Browser forum (a group with all the major browser and TLS certificate vendors) have started dropping the max lifetime of certificates. The idea is that even if a private key does leak, the time frame that it’s usable for will be significantly shorter and any leaks should (in theory) cause less damage.

    • The original maximum duration was 39 months: Three years plus an extra three months leeway for obtaining and deploying new certificates.
    • March 2018: Reduced to 825 days
    • September 2020: Reduced to 398 days
    • March 2026: Reduced to 200 days
    • March 2027: Planned to reduce to 100 days
    • March 2028: Planned to reduce to 47 days

    All modern deployments, regardless of if they’re using free or paid certs, should have their renewals fully-automated, so in theory the validity period shouldn’t matter as much as it did in the past. All major vendors (Let’s Encrypt, DigiCert, Sectigo, GlobalSign, AWS, SSL .com, etc) support ACME now. Reducing the validity is also a forcing function t o ensure automation is actually implemented.

    somehow else in the middle and just can “ignore” certs renewals?

    I’m not sure that’s possible, since an attacker in the middle shouldn’t be able to obtain a valid certificate for the domain. Certificates have a “not valid after” date encoded into them, after which the certificate is considered invalid and you get an error.




  • danAtolinuxmemes@lemmy.world•Linux tips
    link
    fedilink
    arrow-up
    6
    ·
    3 days ago

    The Debian version of Mint. :D

    Most Linux distros have live DVDs that let you try it out without installing it… Try a few of the major distros and see what you like best? You could also install a few and dual-boot (multi-boot I guess?)


  • danAtolinuxmemes@lemmy.world•Linux tips
    link
    fedilink
    arrow-up
    10
    ·
    3 days ago

    causing instability and tons of graphical glitches especially in video playback

    Flashbacks to me struggling to get the fglrx drivers working.

    If you never got to experience the “joy” of that… There was a time long ago when getting graphics acceleration working with ATI/AMD GPUs on Linux needed proprietary drivers. It was a struggle, significantly worse than dealing with the Nvidia drivers today. Things improved so much when AMD released and upstreamed their modern open-source driver, around 10 years ago now.



  • Please pay attention to: Each news server talks to one or more other servers (its “newsfeeds”) and exchanges articles with them.

    hmmm… it sounds like p2p.

    This is describing federation and decentralization, not P2P. The servers communicate with each other. P2P is when users communicate directly.

    Would you consider Lemmy or email as P2P? They’re also federated and decentralized.

    It’s not p2p for the enduser, but that’s why i said it was server p2p.

    Your definition of “server P2P” doesn’t really make sense. Any CDN would fit this definition for example, because CDN edge servers fill data from origin servers when it’s not cached locally, and a lot of that data would be user-uploaded, but I’m not sure anyone would describe Akamai, Fastly, or Cloudflare as P2P.

    Usenet has companies running the servers, and you download from and upload to the company’s servers. Nobody would reasonably describe that as P2P, regardless of how the servers are implemented.


  • That’s not what P2P means though. With Usenet, the articles are stored on a server, and you download them from the server. P2P always means one peer directly connects to another. The reason P2P systems exist is that they avoid things like takedowns (since you’d need to take down every user instead of a central server), and Usenet doesn’t have that advantage.

    If Usenet is P2P, then every other system that lets people upload files is P2P, including things like Rapidshare, Google Drive, forums, etc. That wouldn’t make sense.


  • In older versions of Soulseek, you had to have two consecutive port numbers (eg. 20000 and 20001, or 12345 and 12346, etc). AirVPN was the only VPN that let you pick the port numbers, so you could guarantee getting two consecutive ports.

    I don’t think modern Soulseek clients require that any more (slskd only requires one port as far as I can tell) so it’s not important any more, but AirVPN is still the most recommended by Soulseek users.

    Private Internet Access only give you a single forwarded port, so you couldn’t use it for both torrents and Soulseek at the same time (for example). AirVPN used to provide 20, but I think they reduced it to 5 for new accounts.

    AirVPN’s forwarded ports are also not server-specific; you get your chosen ports regardless of which server you use.



  • If I remember correctly, around 5 or 6 years ago, Google Search leadership changed such that the ads org started running it. The focus since then has been on advertisers rather than regular users.

    This is literally the definition of enshittification: the company first focuses on gaining users, then switches the focus to business customers, then squeezes both of them.



  • Usenet is client-server, not P2P.

    The issue with “good performance” on P2P systems is that you’re reliant on other users’ bandwidth, and there’s a lot of people in the world that have slow upload speeds. Some users use a seedbox with a fast datacenter-grade 10Gbps or 40Gbps connection, but it’s not common.

    The obvious approach if you want to download something from people with slow connections is to download parts of the same files from a lot of them in parallel, which is exactly what BitTorrent does. That’s good enough for plenty of use cases, which is why BitTorrent has been around for so long. The protocol is designed pretty well for this use case.

    It’s got plenty of legit use cases too, especially in research (where it’s common to have data files that are tens or hundreds of gigabytes and need to be shared with other researchers) and in gaming (where it was common to use BitTorrent to download updates, at least outside of Steam).















Moderates