Alt account of @Badabinski

Just a sweaty nerd interested in software, home automation, emotional issues, and polite discourse about all of the above.

  • 0 Posts
  • 10 Comments
Joined 10 months ago
cake
Cake day: June 9th, 2024

help-circle
  • Wireguard was written with the explicit goal of having sane, secure defaults. I totally feel you w.r.t. openvpn or ipsec, since it’s easy to do something wrong. Wireguard is much easier because it simply refuses to give you the choice to do things incorrectly.

    w.r.t. the certificate thing, you could set up a reverse proxy and do HSTS to ensure nobody can load up a rogue CA on your devices. HSTS has the issue that SSH has (trust on first use or whatever it’s called), but you just need to make sure nobody is MITM you for that first connecting and then you’ll be good to go. This would let you use a self-signed certificate if you do desired.



  • I love the thing about the bees. I remember doing the exact same thing multiple times. I eventually learned that you should leave them on the catwalk on the side of the ship and then run to grab them once the ship is leaving (since you’re safe as long as you’re on the ship somewhere, you’ll just be teleported inside with whatever you’re carrying).

    Also, the airhorn is great. I think I like the hairdryer even more because it’s louder, and I think it’s fun that you can recharge it to get more VRRRRRRRs out of it.