gerowen

joined 2 years ago
[–] gerowen@lemmy.world 1 points 4 hours ago

Generate a unique key for each client or device. SSH keys identify devices, not people, so I do not recommend sharing the same key between two different devices.

[–] gerowen@lemmy.world 24 points 18 hours ago* (last edited 18 hours ago) (1 children)

I generally do a few things to protect SSH:

  1. Disable password login and use keys only
  2. Install and configure Fail2Ban
  3. Disable root login via ssh altogether. Just change "permit root login" from "no password" to just "no". You can still become root via sudo or su after you're connected, but that would trigger an additional password request. I always connect as a normal user and then use sudo if/when I need it. I don't include NOPASSWD in my sudoers to make certain sudo prompts for a password. Doesn't do any good to force normal user login if sudo doesn't require a password.
  4. If connecting via the same network or IPs, restrict the SSH open port to only the IPs you trust.
  5. I don't have SSH internet visible. I have my own Wireguard server running on a separate raspberry pi and use that to access SSH when I'm away, but SSH itself is not open to the internet or forwarded in the router.
[–] gerowen@lemmy.world 4 points 1 day ago

They straight up ambushed those guys. Makes me wonder if the car accident was staged specifically to attract emergency workers.

[–] gerowen@lemmy.world 2 points 1 week ago

So far I haven't seen any attempts to change their user agents. I've seen one or two other bots poking around, but nothing to write home about so I've left them alone.

I have heard however that changing user agents is a tactic they do indeed employ, especially Claude, so it may be that I'll eventually have to adapt my defenses.

[–] gerowen@lemmy.world 5 points 1 week ago (2 children)

I've been fending off AI bots the last week or so; wrote about it here:

https://gerowen.substack.com/p/the-ai-data-scraping-is-getting-out

[–] gerowen@lemmy.world 13 points 1 week ago

Alternatively though, if an app has KDE library dependencies for example, it's kinda nice to not have to install a whole other desktop system wide.

[–] gerowen@lemmy.world 3 points 1 week ago (3 children)

I made one the other day, though I bought the music from HDTracks instead of "acquiring" it from Limewire or Kazaa. Burned it to a CD because the bus I drive has a CD player but no SD card slot or anything.

[–] gerowen@lemmy.world 33 points 1 week ago (9 children)

Why did they get removed? I feel like I'm missing a whole backstory here.

[–] gerowen@lemmy.world 1 points 2 years ago (1 children)

She straight up admitted that she was essentially a sock puppet CEO and would offer no friction to anything Musk wanted.