SirNuke

joined 1 year ago
[–] SirNuke@kbin.social 1 points 11 months ago

Is this the one part of the night qualifies as merely mildly interesting?

[–] SirNuke@kbin.social 4 points 1 year ago

This seems highly unlikely in the age of increased polarization. The number of independents has steadily decreased and there's a reason why "making her the first Independent to win a three-way statewide race in American history" would be groundbreaking. It's not like she endearing herself to either side.

Anyone have any analysis why this would be feasible? I just can't believe someone would look at, say, the republican primary polls and think there's 25-35% of them looking for a 'centrist' independent.

[–] SirNuke@kbin.social 4 points 1 year ago

I'm not going to watch the video, but what's the procedure for switching between Linux and Windows? Usually you dedicate a GPU entirely to VFIO, with a 2nd GPU for the host OS (or run headless).

Anyway, will it work? Yes, minus some anti-cheat software. Will it be a simple solution? Well, once you get things stable, yes. The tech behind this is mature, but it can be a rabbit hole.

I would look into a non-Nvidia GPU for your 2nd PCIe x16 slot (x4, shared with the 2nd M.2 slot FYI). Good idea to check IOMMU groups before buying anything, but modern AMD motherboards are usually fine. Blacklist the Nvidia drivers and dedicate the 3070 to VFIO to make your life easier, and run Linux off the secondary GPU. Intel A380 might be a good choice. Do gaming stuff on Windows and stream via Parsec/Looking Glass/Moonlight+Sunshine; everything else on Linux.

[–] SirNuke@kbin.social 14 points 1 year ago* (last edited 1 year ago) (3 children)

Honestly, I'd be more curious what topics where the media does nail the nuances of. Are there any at all?

[–] SirNuke@kbin.social 1 points 1 year ago* (last edited 1 year ago)

If he's someone that's normally good at being funny - that is good at finding humorous observations and wording things that get people to laugh - then I'd say he's messing with you.

I would mess with him right back by acting like I'm very seriously trying to understanding the joke and ask increasingly dumb questions until he realizes that yes, I knew exactly what he was doing. Or a knowing smirk if that's too much.

(Yes this comment is very revealing about my childhood)

[–] SirNuke@kbin.social 17 points 1 year ago* (last edited 1 year ago) (4 children)

This might not be what your friend is going for, but I smirked slightly and this is how I interpret it:

I particularly like jokes that take something absurd and launder it through the structure of things that do make sense. Everything in your friend's joke is factually true. It's structured as a logically consistent argument.

And yet it is completely nonsensical. No one has ever thought that windows make something move. It invoked a slightly confused response in me, which is why I found it funny.

It's not a great joke, but I might tell it to feel out someone's sense of humor plus whether they pick up on that I'm doing so. I think the analogy to Windows makes it a weaker joke, but I would give that as an explanation just to mess with someone a little.

[–] SirNuke@kbin.social 1 points 1 year ago

It's easy* to setup Hashicorp Vault with your own CA and do automated cert generation and rotation, if you are willing to integrate everything into Vault and install your root CA everywhere. (*not really harder than any other Vault setup, but yaknow). I may go down this route eventually since I don't think a device I don't control has ever accessed anything I selfhost, or ever will.

I have a wildcard subdomain pointing to my public IP, and forward port 80 to an LXC container with certbot. Port 80 appears closed outside the brief window when certbot is renewing certs. Inside my network I have my PiHole configured to return the local IP for each service.

Nothing exposed to the internet at all. There is a record of my hostnames on Let's Encrypt but not concerned if someone will, say, deduce apollo-idrac is the iDRAC service for a Dell rackmount server called apollo and the other Greek/Roman gods are VMs on it. Seemed like a house of cards that would never work reliably, but three odd years later I only have issues if a DNS resolver insists on bypassing my PiHole. And that DNS resolver is SystemD-ResolveD which should crawl back into whatever hellhole it came out of.

[–] SirNuke@kbin.social 8 points 1 year ago (1 children)

They could hijack your site at any time, but with a copy of your live private certs they (or more likely whatever third party that will invariably breach your domain provider) can decrypt your otherwise secure traffic.

I don't think there's significant real tangible risk since who cares about your private selfhosted services and I'd be more worried about the domain being hijacked, and really any sort of network breach is probably interested in finding delicious credit card numbers and passwords and crypto private keys to munch on. If someone got into my network, spying on my Jellyfin streaming isn't what I'm going to be worried about.

But it is why CSRs are used.

[–] SirNuke@kbin.social 126 points 1 year ago

Friction between Snap and AppArmor is to be expected. The corporate sponsor of Snap, Canonical, is well known for their icy relationship with the corporate sponsor of AppArmor, Canonical.

[–] SirNuke@kbin.social 29 points 1 year ago* (last edited 1 year ago) (13 children)

The layoff includes Mary Kirby, who's been a core writer in the Dragon Age franchise since the first game. Saw takes that the layoffs are just eliminating multiplayer positions, but that's not true.

I've long suspected that Dreadwolf will make or break BioWare. Since it's following the same script as Andromeda and Anthem - endless delays, no public progress just lots of b-roll and concept art - I don't think development is going well. ME: Legacy might have bought BioWare some breathing room but I can't interpret this as anything other than death throes for the studio.

BioWare is dead, long live Larian and Spiders?

[–] SirNuke@kbin.social 4 points 1 year ago (1 children)

I've found the idea of LXC containers to be better than they are in practice. I've migrated all of my servers to Proxmox and have been trying to move various services from VMs to LXC containers and it's been such a hassle. You should be able to directly forward disk block devices, but just could not get them to mount for an MinIO array - ended up just setting their entire contents to 100000:100000 and mounting them on the host and forwarding the mount point instead. Never managed to CAP_IPC_LOCK to work correctly for a HashiCorp Vault install. Docker in LXC has some serious pain points and feels very fragile.

It's damning that every time I have a problem with LXC the first search result will be a Proxmox forum topic with a Proxmox employee replying to the effect of "we recommend VMs over LXC for this use case" - Proxmox doesn't seem to recommend LXC for anything. Proxmox + LXC is definitely better than CentOS + Podman, but my heart longs for the sheer competence of FreeBSD Jails.

[–] SirNuke@kbin.social 1 points 1 year ago (1 children)

Do you have any trouble with cooling or anything with them? Got like a billion unused PCIe lanes in my Dell R730 and can think of a few things that might benefit from a big NVMe ZFS pool.

 

What's a good, cheap, no external power GPU to buy for VMs? Want to chuck a few in my Dell R730 server to make my desktop VMs more usable. Right now have an old K620 for a Windows VM, seems like 1030s are a good bet since I have a bunch of low profile slots I otherwise have no use for.

 
view more: next ›