[-] Daklon@beehaw.org 5 points 2 months ago

It's technically viable, using a distributed hash table for example. But I'm not aware of any solution that does it.

[-] Daklon@beehaw.org 3 points 4 months ago

Sadly, they are doing it in spain, the judges recently stated that they can do it, and few days later almost all of the spanish newspappers had it.

[-] Daklon@beehaw.org 2 points 6 months ago

Yes, you can only use it if you where using it in the past, sadly the project seems to be abandoned.

[-] Daklon@beehaw.org 2 points 8 months ago

Yes, there are a couple of options, rfbitbanger (currently on the second batch of crowfounding) and adx (arduino digital transceiver).

[-] Daklon@beehaw.org 5 points 8 months ago

They also received a lot more complaints for not having enough trans people, just to counter that stupid complaints

More info: https://eldritch.cafe/@cassolotl/111546657870730179

[-] Daklon@beehaw.org 1 points 10 months ago

If I'm bruteforcing a server and each time that I try an username/password my IP gets banned but suddenly one combination allows me to do 4-5 test ( any bigger number than previously) you are potentially telling me that this user is different (it exists) than the previous ones. Therefore you are doing the attack easier for me because now I know which users actually exist in the machine. It doesn't matter if you are locking the attacker after the password was given.

As others told you, using public key auth, non standard ports or even port knocking will be much more useful.

[-] Daklon@beehaw.org 11 points 10 months ago

I think is better to not use an standard port and using fail2ban at the same time to avoid automated attacks. If you manage to implent what you are looking for, you are potentially telling an stacker which accounts exist and which not, allowing him to do an easier brute force attack. A typical attacker using a botnet will not be stopped by a single IP being baned, and as son as an IP is banned he will know that this account doesn't exists. Another option is enabling port knocking.

[-] Daklon@beehaw.org 1 points 1 year ago

I've been a posteo user since 4 years and it has worked perfectly for me, totally recommended

[-] Daklon@beehaw.org 19 points 1 year ago

As far as i know, they don't use the youtube api. Therefore they don't have to be compilant with any api policy or tos. They just connect to YouTube like any browser do and then show that information(with modifications) on the invidious app.

Google can try to modify the code faster than the developers try to update the app since they expect the data to be in an specific format, but that's all, they aren't using the api... There is nothing to be closed.

[-] Daklon@beehaw.org 2 points 1 year ago

As far as know there is no difference. I use the fdroid version just because I like the open source idea behind fdroid, but you can use the one that you like most

view more: next ›

Daklon

joined 1 year ago