It looks pretty well cited to me. The fact that it was written anonymously doesn’t really take away from that.
It looks pretty well cited to me. The fact that it was written anonymously doesn’t really take away from that.
90% sure wireguard (the VPN server) is going to need an open port if you want to connect from the outside.
FWIW: I’m running jellyfin and a whole host of other services on a Beelink with an Intel n95 and 8gb of ram. Runs like a champ.
Using Firefox mobile, everything works and is mostly performance 🤷♂️
im a big fan of the nas device being single purpose. its life should only exist in fileserving. i have several redundant nas devices and then a big ol app server.
This is the way. Except my “big ol’ app server” is an n95 mini pc that sips power.
Because even if an attacker could gain access even as root he cannot modify system files.
Your comment was already from the position of if an attacker could gain root access. My responses were to that directly, and nothing else.
Your comment also contained
The filesystem itself is also read-only.
Which is what led to the further discussion of root making that not so.
I don’t believe that to be the intent of the OP’s comment, given their second sentence, but they are welcome to state otherwise. I just don’t want them thinking that an immutable distribution gives them some kind of bulletproof security that it doesn’t.
While you are correct, any system is compromised if you have root, so isn’t that irrelevant at that point?
The original context for the comment chain was:
Because even if an attacker could gain access even as root he cannot modify system files.
So no, it’s completely relevant.
Someone with root can run ostree admin unlock --hotfix to make /usr writable. Someone with root can also delete all restore points.
It would be strange for them to call it that if it actually means “completely irrelevant from a security perspective”.
See the comment by superkret.
An attacker escaping from a container can’t be system root as Podman runs rootless (without some other exploit or weak password).
That would be true of podman running anywhere, and is not unique to an immutable distribution.
The filesystem itself is also read-only.
You can change that real quick if you have root access.
Because even if an attacker could gain access even as root he cannot modify system files.
They 100% can.
The GitHub says they plan on adding other fediverse connections in the future.
They are for sure talking about the ARM servers from Oracle. You get 24gb of memory and 4 cpu cores that you can carve into virtual machines.
Issue is that the free stock is very limited, and there have been some claims of people having their free service resources reclaimed by Oracle.
Still, if you can get one, it is probably the best you can get for free.
If you’re happy with Racknerd, they have deals on LEB all the time. Right now, even
What makes Debian a pain to use on servers?
I personally combine lower end NAS boxes with 4x4 mini PC’s. I like the separation of concerns, as well as the tiny footprint.
I use a VPS from RackNerd for all kinds of things (my personal Lemmy, for one). Have had it for two and a half years or so with no complaints.
Ditto. You could also leave Jellyfin as your back end, and link it to Kodi for your front end (if it is just the UI you are bored of)
Here it is. Mostly the sunk cost of VST products with miserable DRM. It seems like it can be done, but I have zero interest in mixing that headache into a creative space.
You can say that speaks volumes about the character of the author (though you are the one assigning said “shame”). You were asking why this report deserves credence. The points raised in the report have citations such that you can decide where you fall on the presented issues.