• 1 Post
  • 30 Comments
Joined 23 days ago
cake
Cake day: February 14th, 2025

help-circle
  • I would think very carefully before contacting the police. I am not suggesting that you should provide a safe harbor for people sharing CSAM, or obfuscate their crime. You absolutely should take action, but carefully weigh your options before calling the police.

    While it may (possibly!) be true in your jurisdiction that platform operators are not liable for user content, police aren’t on “your side”. Even if you assume the highest standards of professionalism from them, they need to represent the interests of the victims (not you) and need to diligently investigate the crime. That means they need to confirm beyond reasonable doubt that you are not involved beyond operating the host.

    Just because you self-disclose does not mean that you are innocent. You could’ve been actively participating and when threatened with blackmail you’ve decided to self-disclose to avert guilt.

    Another consideration is what else I have on my server. I’m catch and release for pirate movies and TV these days so there’s only 100gb or so. I do have several hundred pirate audiobooks though. Deleting all that before handing my server over will look very suspicious.

    With all of this in mind, the only course of action is to talk to a lawyer. A lawyer will know exactly what laws are relevant, and can guide you through the process of self-disclosure while minimising the imposition on you.


  • ok so don’t hate me but h001, h002, h003, and so on.

    That’s h for host. I also use n to number networks, and k to number physical keys.

    I list them all in my keepassxc password database, where I can include any additional information.

    With the prevalence of vms, docker containers, and docker networks, there’s just too many things to name. By numbering them I can just side step that whole game.










  • Is it weird that I’ve never heard this term “mutual aid” before this thread but apparently everyone here knows all about it?

    Anyway. There’s just no way I’d give real money to someone asking for it like this because for every real person there must be a dozen scammers at least. It honestly seems crazy to me that this could work and people could send money.

    If people are giving money away like this then they’re part of the problem IMO. You’re encouraging scammers, and perpetuating the practice, diverting money away from the people who actually need it.





  • I don’t think the SPF / DKIM / DMARC stuff is overly complex nor the core of the problem.

    In my case it was recipients with bonkers microsoft exchange servers that just had weird ideas about who should be sending them emails.

    For example, one thing that tripped me up forever ago was grey listing. Apparently the receiving server just wouldn’t acknowledge the sending server for an arbitrary period of time, say 12 hours or so. Spam senders would usually give up long before then, while a legit server would keep trying because it’s legitimately trying to deliver an actual email.

    So my email-in-a-box type self hosted set up was fine really. Compliant you might say. But to send emails to this one in a thousand recipient I had to investigate what was going on and reconfigure things to ensure their server would interact with mine.

    Another thing that can happen is that spammers just put your email address in the “from” field and fire off a few million emails. Obviously the DKIM signatures and SPF won’t match but it still just makes your future legitimate emails look spammy. Having the credibility of a larger organisation goes a long way in this type of instance.


  • I’m absolutely in the “don’t self-host email” camp. That said, I think it could be done reliably if you wanted to use someone else’s SMTP server and let them worry about deliverability. As in, have your mx records on your domain route to your MTA and dovecot, but set your DKIM and SPF records to match a third party SMTP server. You could use mxroute as an SMTP server very cheaply. There are others like the email API type services. I still can’t think of why I’d want to self host with all this drama but just an idea I’ve heard.





  • For sure there are plenty of people that don’t produce any real value in their work, but that’s been the case since forever and they’re hard to weed out because in some ways their full time job is to ensure their ongoing employment.

    As in most things, it’s a question of extent.

    The most accurate statement you can make is that AI will make “most” office employees “more” efficient.

    The thing is, this has been happening with every technological advance for hundreds of years.