SayCyberOnceMore

  • 16 Posts
  • 646 Comments
Joined 3 years ago
cake
Cake day: June 17th, 2023

help-circle

  • It’s not about AV. It’s about vulnerabilities.

    AV just uses (often multiple) vulns to do something, and with closed-source systems you can’t fix it yourself, so you need an application to do it for you.

    AV is a block-list approach… always needs updating, even for things you don’t have. Linux can operate with allow-lists, so only the apps you have can execute.

    Plus firewalls (outbound as well as inbound), SSH, secure package repos, etc.

    You don’t need AV, but, you can have it if you want it (maybe file-less memoey resident stuff)

    But, yeah, that other post was just mayhem.










  • I have multiple zones: home and almost-home (same center coordinates, just larger diameter)

    This allows the house to “get ready” before someone is actually home, ie trigger lights to come on earlier.

    It also helps with random GPS jumps.

    Then, when the wifi connection is slow (maybe low phone battery) and people are literally outside the door, there’s no awkward pauses before someone actually “arrives”.

    I also have zones for our work places, intending to be used as a double-check, ie not-home isn’t usually good enough, I want the house to know we’re all at work and then the internal house cameras come on, etc.

    I also have a “visitors” flag, so that if friends / family are in and we leave, then the TV and lights don’t turn off and they’re not attacked by the laser robots…

    Also, (from memory) the person entity can be a combo of GPS and ping sensors to ensure it’s a correct reading






  • SayCyberOnceMore@feddit.ukOPtoSelfhosted@lemmy.worldSystem Redundancy
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    9 days ago

    That (2 FWs) was what I was considering initially.

    But, looking at some other posts, I’m starting to rethink my design as I only have 1 WAN connection, then I only need 1 FW (maybe). SIM would be rarely used, I’m not sure the overall cost would be worth it

    So separating FW from DHCP & DNS might be a better solution.