• 0 Posts
  • 273 Comments
Joined 3 years ago
cake
Cake day: June 19th, 2023

help-circle

  • rekabis@lemmy.catoSelfhosted@lemmy.worldEmail ownership, I give up.
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    4 days ago

    I’ve been running my own eMail server for almost a quarter century, and I have no clue what all the fuss is about.

    Sure, providers are getting very picky about what domains that they will receive eMails from. But that’s why I have gMail, Yahoo, and Microsoft webmail accounts - so I can train their systems by exchanging emails once a quarter.

    And yes, you do have to be running whitelists and blacklists and tarpits and have a good Fail2Ban in place. And good geoIP system if you want to cut out regions that you are unlikely to ever have legitimate mail originate from. But that’s just common sense security.








    1. Actually text me the one-time passcode, rather than saying you sent it to me while instead texting it to the molten core of the earth.

    Uhhh… how about NO??

    In fact, as a casual security professional (it’s not a core part of my job, but I know a lot more than most ppl), I openly advocate making SMS and eMail illegal for transmitting one-time passcodes.

    Why? Because both are critically insecure, cannot be adequately secured outside of laboratory or highly restrictive environments, and can be trivially hijacked.

    The only one-time passcode that should be used are one-time password generators (TOTP) such as Google Authenticator or any other such method.

    Yes, this requires a little more effort on the part of the site owner, but it’s worlds better than SMS or eMail, and far more user-friendly than forcing the user to open the company’s app just to receive the code (looking at you, Canadian banks and other businesses like Telus).






  • Oh no! Forbidden

    Error: access denied: denied by administrative rule fa68ec4c0b694396d50ce50a8cf4cb6b/81a4d3ff51d16981b7d8

    Why am I seeing this?
    If you have any issues contact the site administrator and provide the following Request ID along with your browser details, specially like the User-Agent: fa68ec4c0b694396d50ce50a8cf4cb6b

    Protected by go-away :: Request Id fa68ec4c0b694396d50ce50a8cf4cb6b

    Just some basic browser protections, and I get this. Is this enshittified Cloudflare v2.0?


  • I am in IT, and personally speaking, with my own machines, I have never had these power settings not be obeyed.

    And the only time when I have seen these settings “not be obeyed” in other systems is because either,

    1. Someone or some other non-Microsoft software had dicked with power settings through the registry/GPO, or
    2. I’ve been able to trace things down to hardware malfunctions or hardware discrepancies.