• 28 Posts
  • 1.66K Comments
Joined 3 years ago
cake
Cake day: July 13th, 2023

help-circle


  • I’m afraid of security bugs in the software I’m using, so that containers don’t contain, read-only doesn’t prevent writing, mounting directories doesn’t restrict access to those directories, etc.

    I’m a nobody, I can’t imagine anyone targeting me or my random domain, but I can imagine getting swept up in a net of attacks of opportunities targeting hosted software with known vulnerabilities, or injected supply chain vulnerabilities, so I want to reduce my attack surface as much as I can (while still actually letting the people I want to access it actually access it)


  • I’m kinda disappointed with this thread, I’m in a similar position to OP, but all the responses are just like “use a reverse proxy and make your URL hard to guess” and other measures which are not very secure. \

    It seems like that’s about as good as you can get at the moment, because the mobile apps barf if you try to add in auth in front of the reverse proxy, but a lot of people seem to be providing this advice like it’s good enough rather than as good as you can get.












  • One of the big controversies is that these companies do have access to cameras on private property, using things like ring doorbell cameras.
    And depending on conditions, you can still track the movement of something smaller than a pixel. Smaller than a pixel doesn’t mean invisible, it affects the color of that pixel and you can track the movement of the disrupted pixel.
    And you have to actually get close enough you the camera lens to damage it, so there is continuity; they’re not just looking at a strange color pixel and leaping to the conclusion that it is a drone, they see the drone flying off into the distance (in reverse) and cross reference it with other cameras to track the movement at a distance.

    It’s a lot of effort, but protecting the investments of the wealthy is one of the only things that will mobilize both the finances of the wealthy and the actual effort of the police.






  • Idk, I think they can probably do a reasonable job tracing a drone back to it’s takeoff location, and then tracking the person who brought it there back to their home, with decent coverage.

    That said I don’t know if I’m overestimating their ability regarding machine learning and AI - this is probably fairly labour intensive unless they’ve done a good job preparing all their data and they have plenty of compute.