Skip Navigation
Pika Pika @sh.itjust.works

Just your normal everyday casual software dev. Nothing to see here.

Posts 0
Comments 502
Dev rejects CVE severity, makes his GitHub repo read-only
  • I think a good alternative is a CVE is assigned as somewhere between 1-3 unless proof of concept is able to be assigned, then and only then can the priority to increased to what it should be. these issue reports coming in as a 9 when you basically need to tell the program, "hey I'm being stupid just do it" in order for it to be vulnerable are only wasting developers time. I don't believe these issues should be ignored however I do think they should be quite a bit lower priority if no concept is provided.

  • Price will increase by $10 for v1.0 after the Steam Summer Sale
  • Yeah I do agree, it seems real sleazy blowing it under the guise of inflation, that being said it is understandable because inflation is infected quite hard with those projects, whether it's hosting costs or salary well it may not be as much as physical products I can see where they may want to raise it but in this case I do agree I think they definitely had reason to just say "yo our game is good and we know it so we're upping the price" okay maybe not exactly like that but you get the point

  • Am I the only one who missed the Owncloud rewrite in Go?
  • It all depends on your threat model, I own my Hardware as well but I'm still not going to use a software that is shown to me that they don't take security seriously but I'm also more paranoid than most

  • Pros and cons of Proxmox in a home lab?
  • I'm currently running proxmox on a 32 gig server running a ryzen 5600 G, it's going fine the containers don't actually use all that much RAM and personally I'm actually seeing a better benchmarks than I did when I just ran as a Bare Bones Ubuntu server, my biggest issue has actually been a larger IO strain than anything, because it's a lot more IO heavy now since everything's containerized. I think I easily could run it with a lower amount of ram I would just have to turn off some of the more RAM intensive items

    As for if I regret changing, no way Jose, I absolutely love the ability of having everything containerized because I can set things up how I want it when I want it and if I end up screwing something up configuration wise or decide that I no longer need that service I can just nuke the container without having to remember well what did I install on this program so I can remove it and do other programs need this dependency to work. Plus while I haven't tinkered as much in this area, you can hard set what resources you want a lot to each instance, so if you have a program like say a pi hole that you know is never going to use x amount of resources to be able to appropriately work you can restrict what it can do so if something does go wrong with it it doesn't use all of your system resources

    The biggest con out of it is probably having to figure out how to do the networking side because every container is going to have a different IP address, I found using a web dashboard is my friend because I can have heimdel tell me where all my services are and I just have to click the icon to bring me to the right IP address, it took a lot of work to figure out how it's operational and how to get it working, but the benefits I've gotten of having it is amazing. Just make sure you have a spare disk to temporarily clone partitions to because it's extremly difficult to use existing disks in the machine. I've been slowly going one at a time copying it over to an external drive nuking the and then reinitializing the disc as part of the proxmox lvm and then copying the data back over onto their appropriate image file.

  • Am I the only one who missed the Owncloud rewrite in Go?
  • I personally will never use nextcloud, it is nice interface side but while I was researching the product I came across concerns with the security of the product. Those concerns have since then been fixed but the way they resolved the issue has made me lose all respect for them as a secure Cloud solution.

    Basically when they first introduced encrypting folders, there was a bug in the encryption program, and the only thing that ever would be encrypted was The Parent Directory but any subfolder in that directory would proceed to not be encrypted. The issue with that is that unless you had server-side access to view the files you had no way of knowing that your files weren't actually being encrypted.

    All this is fine it's a beta feature right? Except for when I read the GitHub issue on the report, they gaslit the reporter who reported the issue saying that despite the fact that it is advertised as feature on their stable branch, the feature was actually in beta status so therefore should not be used in a production environment, and then on top of , the feature was never removed from their features list, and proceeded to take another 3 months before anyone even started working on the issue report.

    This might not seem like a big deal to a lot of people, but as someone who is paranoid over security features, the projects inaction over something as critical as that while trying to advertise themselves as being a business grade solution made me flee hardcore

    That being said I fully agree with you out of the different Cloud platforms that I've had, nextCloud does seem to be the most refined and even has the ability to emulate an office suite which is really nice, I just can't trust them, I just ended up using syncthing and took the hit on the feature set

  • Price will increase by $10 for v1.0 after the Steam Summer Sale
  • I mean, would you argue that the game isn't worth the price increase? I've always felt that this game with what they gave you for content is well worth a $50 price point, honestly tentatively say maybe even a $60 price point, I mean I do agree you that it's weird that they're choosing to raise the price now, considering that they honestly should have raised the price point of the game easily one or two years ago, but I definitely wouldn't go to say that the game isn't worth the price that they're asking for, I still personally believe they are under selling their game.

    Honestly, they could increase the game after the sale, launch the 1.0 release and raise the price again saying that okay now it's no longer Early Access and I think that would be 100% Fair, I've gotten exponentially more hours out of this game than I have out of games that I've paid $70 for

  • Price will increase by $10 for v1.0 after the Steam Summer Sale
  • Honestly as much as I dislike it raising in price, if this is a price increase for the initial release that's completely fine due to the fact that the game is definitely worth more than they're selling it anyway, plus I give them props alone for releasing the fact that they are going to raise the price because most Studios would just have this really good deal and then raise the base price after the sale never letting anyone know ahead of time

  • People doing the 30 days linux Challenge are having several problems because of Mint's old packages and technology. Why people still recommend it when there is Fedora and Opensuse with KDE and Gnome?
  • I'm not sure but, I always recommended Mint for it's ease of use, I tried fedora, didn't like it, will likely never use it again. First impressions are a pain cause if you fail the first impression you lose before you begin. It could be an amazing system but, it was a bigger pain to setup and get going plus had less resources for me to get started while using more lesser known tools that wern't easily transferrable from the previous systems I has tried.

  • Photographers Push Back on Facebook's 'Made with AI' Labels Triggered by Adobe Metadata. Do you agree “‘AI was used in this image’ is completely different than ‘Made with AI’”?
  • I'm not sure of the complaint, is the tag not accurate? If you use AI to make something are you not making it with ai? Like if I use strawberry to make a cake would the tag made with strawberries be inaccurate?

    Like I failed to see the argument, if you don't want to be labeled as something accurate don't use it otherwise deal with it.

  • China's commercial 'artificial sun' achieves first discharge
  • I would check that page out but damn it gives you a full screen subscription prompt when you open the page.

    edit apperently there is an almost invisible x on the top right that closed it, but it only worked after I reloaded the page

  • JFK Airport. I'm not taking their advice.
  • I mean it gets the point across, regardless of the service dog or a pet(which shouldn't be in the TSA security line in the first place cuz generally airports will have a designated drop off or require Kennels) , in this case it doesn't matter how dense you are, it's clear: do not pet the dogs, if the reader wants to say that it means no petting dogs on the entire trip, the airport doesn't care as long as you're not petting the dogs at the airport, and therefor not getting in the way of procedure or causing a potential safety issue for the port

  • X will soon limit the ability to livestream to Premium subscribers
  • Yeah I get that, but the primary one that I use it for has stated that he doesn't want to have to learn a new platform and that if his Twitter ever died he's not going to learn another platform. I would rather have updates on a shitty platform then no updates at all. Of course that's also under the assumption that everybody left the platform as well because me alone leaving wouldn't do anything

  • List of versions (stable, LTS, unstable etc) of major distributions from fastest to slowest updates?
  • If you open up the host instance, you'll only see one other commenter anyway so I think they are down voting due to it seeming like a demand, but since no one's messaging why I'm just guessing

  • X will soon limit the ability to livestream to Premium subscribers
  • I really thought they got rid of that future, you know after the absolute dumpster fire it's launch was, like it doesn't look good when your launch stream is buggy and barely runs

  • X will soon limit the ability to livestream to Premium subscribers
  • I exclusively use it because content creators I follow are stubborn and won't leave the platform. I regret every time I'm forced to open it because it's mostly spam now, but they won't go elsewhere

  • Never know til you go.
  • I was moreso referring to the do not wash in the sun, do not use hot water, do not use car washes that use pre-cleaners, and the fact that apperently having tree resin or dead insects on the vehicle is enough to cause corrosion of it.

    I agree the carwash mode sounds logical, I've just never heard of it or needed it for any of my vehicles, I just don't open the doors or windows in the wash.

  • Never know til you go.
  • I just read the how to clean your Cyber truck article from Tesla and holy cow you might as well have written purchase vehicle, store directly in garage indefinitely, cause just about anything damages it lol

    the link if anyone else was curious

  • Advice wanted: Combining current solutions into one home server
  • Seconding this, I took the plunge a month or two back myself using proxmox for my home lab. Fair warning if you have never operated anything virtualized outside of using virtualbox or Docker like I was you are in for an ice Plunge so if you do go this route prepare for a shock, it is so nice once everything is up and running properly though and it's real nice being able to delegate what resource uses what and how much, but getting used to the entire system is a very big jump, and it's definitely going to be a backup existing Drive migrate data over to a new Drive style migration, it is not a fun project to try to do without having a spare drive to be able to use as a transfer Drive

  • Never know til you go.
  • The fact that I can't tell if you are joking or if there's actually a car wash mode scares me lmao

  • Google clamps down on VPN workarounds for cheaper YouTube Premium subscriptions
  • To add information on that the other person didn't, YouTube was purchased by alphabet in 2006, it was purchased in a very unstable state, it was bleeding money, but they wanted it because they saw potential in the platform for Data Tracking and video analytics along with the fact that it had a very high traffic ratio.

    When they purchased it one of the first things they started working on was trying to turn it to be green instead of red, but despite this they still didn't start seeing any real decent change until about 2009, and it wasn't until 2015 that the platform itself started running in the green.

    All this happened with YouTube being one of the most popular video platform sites out there. YouTube doesn't have to do anything to actively block competitors from doing it, with their established market dominance, search engine self promotion tendancies(there was an ongoing lawsuit in Australia regarding this) and the amount of sheer money they have, no company is going to try to compete, the closest arguably is likely twitch but they are pushing the reverse direction with streaming instead of video hosting