This could be funny if it wasn’t such a sad outlook on life.
Bla bla punk bla bla vegan bla bla FOSS nerd bla bla ska, ethics and movement enthusiast
This could be funny if it wasn’t such a sad outlook on life.
Bit shocked RockBox enabled music players aren’t on the list.


What’s your concern about running it behind a reverse proxy, like caddy or nginx?


FreeBSD is BSD.


You really can’t assume your visitors are going to have static IPs.
What happens when they visit from their phone? A friend’s WiFi? Their home connection that has a regularly changing IP?


Yeah, I’d like to know too (but won’t be using proprietary stuff just to find out).
Should be: Lies / Reality
I think you’re missing historical context. There are more options now, but when Signal came out (or became Signal, after TextSecure), it was the only tool to offer such strong cryptographic properties with its then novel double ratchet algorithm. Compared to OTR and, much worse, all the other crap that was not E2E encrypted at all, it was the first really credible option on a mass scale.
The crypto was reviewed by well-considered experts, and came out looking strong.
Telegram fought for years trying to say they were just as good and in fact better, which is entirely disingenuous considering it’s not an encrypted messaging app.
These things contributed to what you call the cult following. Which wouldn’t be negative (a cult film has a cult following) if not intended to mean “a cult like Scientology”.
OMEMO is probably good enough, but i wouldn’t assume it’s the same quality as the Signal protocol it’s based on (this analysis isn’t too positive: https://soatok.blog/2024/08/04/against-xmppomemo/)
Telegram is a social network masquerading as a messaging app, not a “secure messaging” app.
Sounds like you’re in good hands. Enjoy the ride, plenty to learn and to feel good about understanding :)


It is, see https://github.com/m4tx/curl-bash-attack


No, it is different, as it adds an entire layer of indirection and unknown to the mix, increasing the risk in the process.


Yes, this is the correct approach from a security perspective.


Please tell me you are not seriously equating a highly sophisticated attack line the Solarwind compromise with piping curl to bash?


This is a bit like saying crossing the street blindfolded while juggling chainsaws and crossing the street on a pedestrian crossing while the light is red for cars both carry risk. Sure. One’s a terrible idea though.


Oh the example in the article is the nice version if this attack.
Checking the script as downloaded by wget or curl and then piping curl to bash is still a terrible idea, as you have no guarantee you’ll get the same script in both cases:


Most people don’t know how to use ftp anymore. It’s a pretty limited protocol (and requires 2 open ports to function). It’s hard to integrate with good modern auth solutions. Probably more, that’s off the top of my head.
Yeah and it’s not Mullvad itself but the cofounder with his personal money (which of course he has for being the Mullvad cofounder and handsomely paid co-CEO, I expect).
Still, nuance?