Comments

This profile is from a federated server and may be incomplete. Browse more on the original instance.

noride, (edited ) to piracy in RANT: I hate the fact that my ISP can restrict access to certain sites

You are absolutely correct, I should have lead with that. Encrypted client handshake means no one can see what certificate you are trying to request from the remote end of your connection, even your ISP.

However, It’s worth noting though that if I am your ISP and I see you connecting to say public IP 8.8.8.8 over https (443) I don’t need to see the SNI flag to know you’re accessing something at Google.

First, I have a list of IP addresses of known blocked sites, I will just drop any traffic destined to that address, no other magic needed.

Second, if you target an IP that isn’t blocked outright, and I can’t see your SNI flag, I can still try to reverse lookup the IP myself and perform a block on your connection if the returned record matches a restricted pattern, say google.com.

VPN gets around all of these problems, provided you egress somewhere less restrictive.

Hope that helps clarify.

noride, to piracy in RANT: I hate the fact that my ISP can restrict access to certain sites

Yeah, even if they miss your DNS request, the ISP can still do a reverse lookup on the destination IP you’re attempting to connect to and just drop the traffic silently. That is pretty rare though, at least in US, mainly because It costs money to enforce restrictions like that at scale, which means blocking things isn’t profitable. However, slurping up your DNS requests can allow them to feed you false error pages, littered with profitable ads, all under the guies of enforcing copyright protections.

noride, to piracy in RANT: I hate the fact that my ISP can restrict access to certain sites

Most ISP blocking is pretty superficial, usually just at the DNS level, you should be fine in the vast majority of cases. While parsing for the SNI flag on the client hello is technically possible, it’s computationally expensive at scale, and generally avoided outside of enterprise networks.

With that siad, When in doubt, VPN out. ;)

noride, to pics in View from Mount Mansfield in Vermont

Is that Stowe we’re seeing in the distance?

noride, to trees in Presenting my prize nug from my latest grow!

Very nice! The biggest nug is often referred to as ‘The Crown’, wear it with pride, king! :D

noride, to fediverse in A little rant about lemmy.ml

They are individual copies of the Lemmyverse that all sync content with each other. That’s the ‘federation’ part. Some of them are weird and scary places, friend.

noride, to selfhosted in Can I attach a 10GBase-LR to QSFP-40G-LR4 (CWDM)?

QSFP and SFP are different physical connectors, they are not interoperable.

noride, to gaming in RoboCop: Rogue City gameplay trailer

Boy, I sure can’t wait for… June 2023…?

noride, to technology in Philips Hue will soon require an account to use its app — here’s what that means

You will still be able to use them completely offline after you complete the setup process, it’s in the article. Regardless, I only have a couple devices, so it’ll be pretty painless for me to rip em out.

noride, to technology in Signal chat protection against quantum computers

Yeah, they seem to put a lot of energy into esoteric features, when the app is in serious need of some quality of life improvements. I donate a tiny monthly sum to the project and honestly feel conflicted about how effectively it’s being used.

noride, to technology in Cisco buying cybersecurity company Splunk for $28B

God damnit. They ruined Viptela, absolutely fucked the licensing model for ThousandEyes, kneecapped OpenDNS, and now this shit. Stop Ciscoing good companies, Cisco!!

noride, to trees in Turned the light down to 60% was having 1300+ppfd at the canopy and was causing light stress

You caught it early. Just some light canoeing, she’s still good! :)

noride, to trees in Dry Herb Vaping vs Bong hits

As an owner of two Volcanos and an Arizer Extreme Q, I don’t really think the cost justifies the marginal improvement in vapor quality over the Q.

That said, if money really is no object, the Volcano can’t be beat in terms of quality and feature set. Replacement parts are wildly pricey too.

noride, to selfhost in Friendship ended with Debian and Docker. Now Fedora and Podman are my best friends.

This is good info, thank you for taking the time to elucidate.

noride, to selfhost in Friendship ended with Debian and Docker. Now Fedora and Podman are my best friends.

Judging by the screenshots, this looks very similar to Portainer. Are they basically the same tool set for different container architectures? Looks pretty interesting.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • uselessserver093
  • Food
  • aaaaaaacccccccce
  • test
  • CafeMeta
  • testmag
  • MUD
  • RhythmGameZone
  • RSS
  • dabs
  • KamenRider
  • Ask_kbincafe
  • TheResearchGuardian
  • KbinCafe
  • Socialism
  • oklahoma
  • SuperSentai
  • feritale
  • All magazines