I’m just using regular Nginx, which I’ve been using for 20 years. What does Nginx Proxy Manager or npmplus do better?
I’ve been meaning to try Angie too, which is a fork of Nginx.
Aussie living in the San Francisco Bay Area.
Coding since 1998.
.NET Foundation member. C# fan
https://d.sb/
Mastodon: @[email protected]
I’m just using regular Nginx, which I’ve been using for 20 years. What does Nginx Proxy Manager or npmplus do better?
I’ve been meaning to try Angie too, which is a fork of Nginx.
Caddy is a good piece of software.
I’ve been using Nginx for 20 years and don’t really have a reason to switch, so I’m still using it. I use certbot, so it’s just one command to create the certificate initially, and then it auto-renews automatically via a systemd timer.
A private key leaking is bad, since anyone with the private key can decrypt data that was encrypted with it.
Traditionally, the way that leaked certs were handled was via Certificate Revocation Lists (CRL). CRLs contain lists of revoked certificates - their serial number, revocation date, and the reason why they were revoked.
However, CRLs are imperfect. Checking for revoked certificates every time you go to a site would slow things down a lot, as the lists are now too large to check and download real-time. Modern browsers and other TLS clients periodically download the lists in the background. Also, it might take a while between when the certificate is compromised and when the company notices the compromise.
Because of this, the CA/Browser forum (a group with all the major browser and TLS certificate vendors) have started dropping the max lifetime of certificates. The idea is that even if a private key does leak, the time frame that it’s usable for will be significantly shorter and any leaks should (in theory) cause less damage.
All modern deployments, regardless of if they’re using free or paid certs, should have their renewals fully-automated, so in theory the validity period shouldn’t matter as much as it did in the past. All major vendors (Let’s Encrypt, DigiCert, Sectigo, GlobalSign, AWS, SSL .com, etc) support ACME now. Reducing the validity is also a forcing function t o ensure automation is actually implemented.
somehow else in the middle and just can “ignore” certs renewals?
I’m not sure that’s possible, since an attacker in the middle shouldn’t be able to obtain a valid certificate for the domain. Certificates have a “not valid after” date encoded into them, after which the certificate is considered invalid and you get an error.

biometric, personal, behavioral and health data
What data are self checkouts collecting that regular checkouts aren’t?

Shhhhh don’t give them any ideas

Please pay attention to: Each news server talks to one or more other servers (its “newsfeeds”) and exchanges articles with them.
hmmm… it sounds like p2p.
This is describing federation and decentralization, not P2P. The servers communicate with each other. P2P is when users communicate directly.
Would you consider Lemmy or email as P2P? They’re also federated and decentralized.
It’s not p2p for the enduser, but that’s why i said it was server p2p.
Your definition of “server P2P” doesn’t really make sense. Any CDN would fit this definition for example, because CDN edge servers fill data from origin servers when it’s not cached locally, and a lot of that data would be user-uploaded, but I’m not sure anyone would describe Akamai, Fastly, or Cloudflare as P2P.
Usenet has companies running the servers, and you download from and upload to the company’s servers. Nobody would reasonably describe that as P2P, regardless of how the servers are implemented.

That’s not what P2P means though. With Usenet, the articles are stored on a server, and you download them from the server. P2P always means one peer directly connects to another. The reason P2P systems exist is that they avoid things like takedowns (since you’d need to take down every user instead of a central server), and Usenet doesn’t have that advantage.
If Usenet is P2P, then every other system that lets people upload files is P2P, including things like Rapidshare, Google Drive, forums, etc. That wouldn’t make sense.

In older versions of Soulseek, you had to have two consecutive port numbers (eg. 20000 and 20001, or 12345 and 12346, etc). AirVPN was the only VPN that let you pick the port numbers, so you could guarantee getting two consecutive ports.
I don’t think modern Soulseek clients require that any more (slskd only requires one port as far as I can tell) so it’s not important any more, but AirVPN is still the most recommended by Soulseek users.
Private Internet Access only give you a single forwarded port, so you couldn’t use it for both torrents and Soulseek at the same time (for example). AirVPN used to provide 20, but I think they reduced it to 5 for new accounts.
AirVPN’s forwarded ports are also not server-specific; you get your chosen ports regardless of which server you use.

Usenet is client-server, not P2P.
The issue with “good performance” on P2P systems is that you’re reliant on other users’ bandwidth, and there’s a lot of people in the world that have slow upload speeds. Some users use a seedbox with a fast datacenter-grade 10Gbps or 40Gbps connection, but it’s not common.
The obvious approach if you want to download something from people with slow connections is to download parts of the same files from a lot of them in parallel, which is exactly what BitTorrent does. That’s good enough for plenty of use cases, which is why BitTorrent has been around for so long. The protocol is designed pretty well for this use case.
It’s got plenty of legit use cases too, especially in research (where it’s common to have data files that are tens or hundreds of gigabytes and need to be shared with other researchers) and in gaming (where it was common to use BitTorrent to download updates, at least outside of Steam).

It’s like Napster or Limewire if you ever used them. You download files directly from individual users. You can also browse all of a user’s shared files.
It requires inbound connectivity to work well, so you’ll have to ensure your VPN supports port forwarding. The VPN that’s usually recommended for Soulseek (and torrenting) is AirVPN.

I’m surprised they let you dual boot a managed machine, since the Linux installation likely isn’t running any of their management software. At my work, we’re not allowed to dual-boot, but at least they support Fedora. (their production servers use CentOS and Fedora is close enough that they can reuse a lot of management infrastructure like Chef recipes across both)
See if there’s a setting in the BIOS to always use the Nvidia graphics. It’ll use more power but should be more reliable.
Hybrid graphics is notoriously buggy on Linux, especially reverse PRIME. Reverse PRIME is used when the video output port on the laptop (DisplayPort, HDMI, whatever) is physically wired to the discrete GPU, but the system is the integrated GPU. There’s a well-known bug with reverse PRIME where the screen only updates at 1fps when only using an external monitor (laptop screen is disabled).

Nvidia isn’t too bad these days, especially for 20 series and newer since they switched to using the “open-source” driver by default. It’s mainly PRIME that’s the problem (where you have both onboard graphics and a discrete GPU and the system has to switch between them), and the problems aren’t exclusive to Nvidia.

CEOs and CTOs really need to start caring about their products this much again. These days I’d be surprised if any big tech CEOs even go through the new user setup and onboarding experience and provide detailed feedback like this.
People don’t realise that there’s more to AI than LLMs and chat bots, and that plenty of software has been using AI (machine learning, neutral networks, forecast modeling, etc) for at least a decade or two.

At work we’re migrating from Google Chat to Slack, and there’s a bunch of things I already miss. There’s a lot of strange UI issues in Slack that aren’t an issue in any other competing products.

The thing with age verification is that it’s a legal requirement, so they’re all going to have to do it.
Running an online service with a lot of users is very expensive, too. All these proprietary services eventually realise that they need revenue in order to continue operating. That’s one of the reasons why decentralized, federated services are the way to go - everyone runs their own small community, so there’s no one company or person that has to cover an enormous bill.

I really don’t understand how a chat app for gamers became so big in the software development community. It’s such a poor choice, especially for support. Nothing is indexed in search engines, and people can’t see messages unless they join. I’ve even seen some projects use Discord for bug tracking. It’s woefully inadequate for that.

Open source is the way. It always amuses me when people move from one proprietary system to a different one, since the new one always ends up having the same issues.
This just sounds like using the same password on every site. Am I missing something?
Passkeys have to be unique per site so that you can revoke one without having to change something on every other site.
Makes sense! I didn’t realise it has a UI.
I’ve got a bunch of snippets in
/etc/nginx/snippets/, so for example I just need to addinclude snippets/proxy.confto a server block to add most of the configuration needed for a reverse proxy. I’ve been using Nginx for long enough that I just write the rest of the server block by hand.