Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Privacy
  3. Trump cuts funding to FOSS projects.

Trump cuts funding to FOSS projects.

Scheduled Pinned Locked Moved Privacy
privacy
66 Posts 38 Posters 194 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • engineergaming@feddit.nlE [email protected]

    http://longeepsiteaddress.i2p. Bonus points for having an option for a human-readable domain as well.

    S This user is from outside of this forum
    S This user is from outside of this forum
    [email protected]
    wrote on last edited by
    #36

    But i2p doesnt have PoW DDOS protection. Trust me, that shit helps a fuckton for limiting ddos. I witnessed firsthand nine onion services that upgraded from not having DDOS protection to having DDOS protection while under attack and the attack completely stopped.

    L engineergaming@feddit.nlE 2 Replies Last reply
    1
    0
    • zerush@lemmy.mlZ [email protected]

      Don't confuse TOR with security, you can get exposed to use the Onion without an additional encrytion layer or VPN. TOR cannot encrypt the traffic between an exit relay and the destination server.

      S This user is from outside of this forum
      S This user is from outside of this forum
      [email protected]
      wrote on last edited by
      #37

      Sure, like any security it operates in layers

      Totally disagree that Tor does not address security. The loophole you mention is indeed well known, but again it's an exploit like anything

      And like any security thing, you stack a few layers to get the real world security

      zerush@lemmy.mlZ 1 Reply Last reply
      1
      0
      • G [email protected]

        cross-posted from: https://programming.dev/post/28204065

        rexios@lemm.eeR This user is from outside of this forum
        rexios@lemm.eeR This user is from outside of this forum
        [email protected]
        wrote on last edited by
        #38

        Wait you guys were getting paid to work on open source?

        1 Reply Last reply
        1
        0
        • V [email protected]

          the guy is literally a political front for techbros, it's not like he would do something else.

          driving_crooner@lemmy.eco.brD This user is from outside of this forum
          driving_crooner@lemmy.eco.brD This user is from outside of this forum
          [email protected]
          wrote on last edited by
          #39

          Those mf build their empires on the back of open source.

          1 Reply Last reply
          1
          0
          • S [email protected]

            Sure, like any security it operates in layers

            Totally disagree that Tor does not address security. The loophole you mention is indeed well known, but again it's an exploit like anything

            And like any security thing, you stack a few layers to get the real world security

            zerush@lemmy.mlZ This user is from outside of this forum
            zerush@lemmy.mlZ This user is from outside of this forum
            [email protected]
            wrote on last edited by
            #40

            The TOR network is certainly pretty secure, but it's always advisible to use it in the Onion not without an additional layer, at least with a good VPN. Anyway I think that the future is in a descentralized web (I2P, Hyphanet, Snowflake, Shadowsocks and similar), the normal Internet is to heavy controlled by big companies and govs.

            1 Reply Last reply
            1
            0
            • G [email protected]

              cross-posted from: https://programming.dev/post/28204065

              zerush@lemmy.mlZ This user is from outside of this forum
              zerush@lemmy.mlZ This user is from outside of this forum
              [email protected]
              wrote on last edited by
              #41

              Make America great again

              1 Reply Last reply
              1
              0
              • S [email protected]

                the enemy is both weak and strong

                G This user is from outside of this forum
                G This user is from outside of this forum
                [email protected]
                wrote on last edited by
                #42

                The appropriate sequence of events would be:

                Trump starts tariffs > People switch to FOSS > Trump cuts funding to FOSS

                This really isn't double-speak and, if anything, clearly shows the hostility of the admin. They are just incompetent, short-sighted, and overall an enemy of the people.

                1 Reply Last reply
                1
                0
                • ? Guest

                  I did not knew that Tor was getting funded by the american state. Thats giving me some spooky vibes.

                  K This user is from outside of this forum
                  K This user is from outside of this forum
                  [email protected]
                  wrote on last edited by
                  #43

                  One theory is that Tor was opened to the public by the United States Naval Research Laboratory only to create a crowd of users for their agents to hide in.

                  1 Reply Last reply
                  1
                  0
                  • S [email protected]

                    .gov is using let's encrypt? That's pathetic.

                    krolden@lemmy.mlK This user is from outside of this forum
                    krolden@lemmy.mlK This user is from outside of this forum
                    [email protected]
                    wrote on last edited by
                    #44

                    Theyre more likely paying godaddy thousands a year for each cert on domains that go back decades.

                    1 Reply Last reply
                    1
                    0
                    • S [email protected]

                      But i2p doesnt have PoW DDOS protection. Trust me, that shit helps a fuckton for limiting ddos. I witnessed firsthand nine onion services that upgraded from not having DDOS protection to having DDOS protection while under attack and the attack completely stopped.

                      L This user is from outside of this forum
                      L This user is from outside of this forum
                      [email protected]
                      wrote on last edited by
                      #45

                      Edit: ...a decentralized Monero exchange

                      There's the Monero shilling I expect in every comment

                      S 1 Reply Last reply
                      1
                      0
                      • S [email protected]

                        As far as Let's Encrypt goes, the easy way to solve that is self-signed SSL certificates and Tofu. Just make it stupid obvious if an SSL certificate changes on a site that you go to. Like, turn your browser into a giant red screen that says that the security of the website has changed and may be broken obvious. Maybe you could have search engines also index SSL certificates so you could see if Google and Bing and DuckDuckGo and whoever else all say that this website has the same SSL certificate that it has had for X amount of time and if the search engines start showing different results you get suspicious

                        M This user is from outside of this forum
                        M This user is from outside of this forum
                        [email protected]
                        wrote on last edited by
                        #46

                        Never heard of tofu before (the software). What is it?

                        I had heard about DANE and how that would help in scaling back the need for big CAs but I could never grasp how one would do that. Do you know about it? I'm looking for someone to explain it to me.

                        S 1 Reply Last reply
                        1
                        0
                        • V [email protected]

                          the guy is literally a political front for techbros, it's not like he would do something else.

                          P This user is from outside of this forum
                          P This user is from outside of this forum
                          [email protected]
                          wrote on last edited by
                          #47

                          Tech bros are only interested in getting the results from open source. They want the free software from their slaves, they aren't interested in paying anything.

                          Tech companies, for a while, added a bit to open source as it was in their own self interest, but they still shut out everything that wasn't them, they still make the internet in the horrible stonewalled garden that it is today. No account? Half the internet isn't accessible to you anymore

                          Fuck all the big tech and social media companies

                          andromxda@lemmy.dbzer0.comA 1 Reply Last reply
                          1
                          0
                          • M [email protected]

                            Never heard of tofu before (the software). What is it?

                            I had heard about DANE and how that would help in scaling back the need for big CAs but I could never grasp how one would do that. Do you know about it? I'm looking for someone to explain it to me.

                            S This user is from outside of this forum
                            S This user is from outside of this forum
                            [email protected]
                            wrote on last edited by
                            #48

                            Tofu stands for Trust on First Use. So basically, you would get an SSL certificate from the website the very first time you connected to it, instead of trusting a certificate authority. Then, if the SSL certificate changed, you would then be warned that the certificate had changed and would have to decide whether to trust the new certificate or not trust the new certificate. That's why I said perhaps search engines could index certificates and tell you how long the certificate has been active and you could check several engines quickly to determine whether each engine has the same certificate indexed for the same website and if they did not then you would know something might be up.

                            M thorned_rose@sh.itjust.worksT 2 Replies Last reply
                            1
                            0
                            • L [email protected]

                              Edit: ...a decentralized Monero exchange

                              There's the Monero shilling I expect in every comment

                              S This user is from outside of this forum
                              S This user is from outside of this forum
                              [email protected]
                              wrote on last edited by
                              #49

                              Your welcome

                              1 Reply Last reply
                              1
                              0
                              • S [email protected]

                                Tofu stands for Trust on First Use. So basically, you would get an SSL certificate from the website the very first time you connected to it, instead of trusting a certificate authority. Then, if the SSL certificate changed, you would then be warned that the certificate had changed and would have to decide whether to trust the new certificate or not trust the new certificate. That's why I said perhaps search engines could index certificates and tell you how long the certificate has been active and you could check several engines quickly to determine whether each engine has the same certificate indexed for the same website and if they did not then you would know something might be up.

                                M This user is from outside of this forum
                                M This user is from outside of this forum
                                [email protected]
                                wrote on last edited by
                                #50

                                Oh, this is certainly complex logic (for the search engine I mean).

                                S 1 Reply Last reply
                                1
                                0
                                • M [email protected]

                                  Oh, this is certainly complex logic (for the search engine I mean).

                                  S This user is from outside of this forum
                                  S This user is from outside of this forum
                                  [email protected]
                                  wrote on last edited by
                                  #51

                                  Well, it really depends on if you want somebody to trust or not. If you don't want to trust anybody except yourself, then you can just use Tofu and be good with it. The only reason I brought up using search engines as an index is just to give people a place to look.

                                  If I want to visit CNBC and I've never visited them before, I could just go straight to CNBC and trust their certificate right away. Or, if I wanted to confirm that the CNBC certificate was likely valid, I could ask DuckDuckGo, Google, and Quant. And if they all agreed that they had the same certificate that I was getting, I'd be more likely to think that it's valid.

                                  M 1 Reply Last reply
                                  1
                                  0
                                  • S [email protected]

                                    Well, it really depends on if you want somebody to trust or not. If you don't want to trust anybody except yourself, then you can just use Tofu and be good with it. The only reason I brought up using search engines as an index is just to give people a place to look.

                                    If I want to visit CNBC and I've never visited them before, I could just go straight to CNBC and trust their certificate right away. Or, if I wanted to confirm that the CNBC certificate was likely valid, I could ask DuckDuckGo, Google, and Quant. And if they all agreed that they had the same certificate that I was getting, I'd be more likely to think that it's valid.

                                    M This user is from outside of this forum
                                    M This user is from outside of this forum
                                    [email protected]
                                    wrote on last edited by
                                    #52

                                    This is actually a great idea. Is there an opensource implementation of it?

                                    S 1 Reply Last reply
                                    1
                                    0
                                    • M [email protected]

                                      This is actually a great idea. Is there an opensource implementation of it?

                                      S This user is from outside of this forum
                                      S This user is from outside of this forum
                                      [email protected]
                                      wrote on last edited by
                                      #53

                                      Well, you can just generate your own SSL certificate on your machine, locally. I believe you can probably do it with OpenSSL. I've only done it with my Monero node, and they offer a binary, which will generate a certificate for you. I would just look up how to create a self-signed SSL certificate. My guess is it's just a few commands in the terminal.

                                      M 1 Reply Last reply
                                      1
                                      0
                                      • S [email protected]

                                        Well, you can just generate your own SSL certificate on your machine, locally. I believe you can probably do it with OpenSSL. I've only done it with my Monero node, and they offer a binary, which will generate a certificate for you. I would just look up how to create a self-signed SSL certificate. My guess is it's just a few commands in the terminal.

                                        M This user is from outside of this forum
                                        M This user is from outside of this forum
                                        [email protected]
                                        wrote on last edited by
                                        #54

                                        No, I meant the logic where the browser would prompt the user to review and verify the cert for a particular website without consulting a CA. I run some self-signed certs already but I'd love to implement this in my homelab.

                                        S 1 Reply Last reply
                                        1
                                        0
                                        • M [email protected]

                                          No, I meant the logic where the browser would prompt the user to review and verify the cert for a particular website without consulting a CA. I run some self-signed certs already but I'd love to implement this in my homelab.

                                          S This user is from outside of this forum
                                          S This user is from outside of this forum
                                          [email protected]
                                          wrote on last edited by
                                          #55

                                          Oh, that was an idea for a way to do it. Not anything that's been implemented, or at least not to my knowledge.

                                          1 Reply Last reply
                                          1
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups