Why use immutable Linux ? And which one ?
Kid_Thunder @ Kid_Thunder @kbin.social Posts 0Comments 246Joined 2 yr. ago
Yes, though keep in mind containers aren't like VMs so the hardware isn't virtualized or anything. The root system and everything in it is still immutable as well. In usage, it doesn't matter for the container but it isn't changing the root since what is writable to the container is outside of the root.
Using containers this way is the way Silverblue was intended to be used for by the user and pretty much any other immutable distro of note.
Are you saying you can't use toolbox or distrobox for that?
You should be installing software with stuff like flatpak, toolbox or distrobox. If you treat the immutable image as a mutable one there really isn't an improvement except for less of a chance of instability of updating/changing software that's running in memory already.
Well they are placed in mostly minority communities but above that, a ShotSpotter tech admitted in court that they often change the analyst interpretations of what is and isn't a gunshot at the request of their police department customers which, keep in mind, have successfully been used in court as evidence of a crime.
There is also overwhelming data showing that the majority of their alerts lead to no arrests. The Chicago IG believes this demonstrates false positives where as ShotSpotter (who changed their name after some criticism to SoundThinking) says that people can fire a gun and leave no evidence in spite of police investigating and asking people that would have witnessed it (and there being no victim).
Furthermore, the way it works is that AI 'assists' a human who then determines if it is a gun shot and then attempts to triangulate the position it came from. From the trial I mentioned earlier, ShotSpotter determined that there was no gun shot but then changed the analysis at LEO request but in actuality was proven to be a helicopter....
Furthermore, ShotSpotter keeps the details of its methodologies and models a secret and has refused an independent audit from IPVM.
So with all of that, one could easily argue that ShotSpotter/SoundThinking is as biased as a police officer and that the evidence is purely subjective and non-transparent.
YouTube, Facebook, forums and pretty much any echo chamber. Pretty much anything that has replaced AM radio and shitty newsletters. In the 2020's also parroting politicians -- I'm sure I don't need to go over the last 4 years of examples, so how about the Bowling Green massacre that never happened?
In short, his argument in court is that the lack of evidence is evidence of criminal intent.
In a memo sent to employees Mozilla says it wants to bring “trustworthy AI into Firefox”. To help it do this sooner it’s merging its Pocket, content, and AI/Ml teams.
That's pretty concerning. It could go either way but I assume they are going to try to shove more sponsored content in an effort to further monetize Firefox in spite of getting hundreds of millions of dollars a year in donations. Maybe I'm just cynical about Mozilla though.
bi-partisan effort with democrats and MAGA fringe GOP voting for it.
Well it was 208 Democrats + 8 GOP. That's not even 4% of the GOP in the House. I guess you could call that bipartisan if you want. Then there were a bunch of failed speaker nominations before Mike Johnson.
The GOP would actually have to pass legislation for there to be a chance for anything for them to talk about. They haven't passed meaningful legislation in years that wasn't bipartisan. They've shown that even with a majority they can't get anything done themselves. They keep scapegoating their own Speakers because of it.
It pretty much shows that the GOP can't even unite to do anything in current Congress. It is supposedly so much a shitshow that some long-time Congresspeople are considering retirement after their terms are up out of frustration.
The SSH keys don't help me if I get locked out of a Domain Controller unless you're using OpenSSH (which is now a native feature you can turn on). In that case you can actually still log into the DC via command line because it authenticates based on authorizedkeys and not the LDAP of the DC. I actually do this on the enterprise, not because I may get locked out but because it is just convenient. Granted you'll have to execute powershell on the command line once in to use the AD cmdlets.
On the other hand when you create a DC now-a-days (Server 2019...I don't remember if this is asked in the wizard when in Server 2016) you can create a "Directory Services Restore Mode" password which is basically a local admin account on the DC that you can log into only when the DC is booted into safe mode. You'll be asked to create it when you promote your DC.
There's an old saying Pennsylvania, I know it's in Delaware, probably in Pennsylvania that says -- rules for me, no trees have rules wait wait no rules for...rules...uh, you follow the rules and I don't is the point.
- Dark Brandon in response as to why other government employees can't use TikTok for work but he can for his campaign, circa 1774 just before the Civil War kicked off
While you're here downvoting this (you should, it isn't very funny), it is OK to criticize government officials, even if you support them.
Consider that President Biden created the "Protecting Americans' Sensitive Data from Foreign Adversaries" Executive Order (EO 14034), President Biden's administration also threatened TikTok with a "ban" if ByteDance (TikTok's owners) via CFIUS mentioned in the article and elsewhere if they didn't sell to someone not affiliate with the CCP, the FBI and DOJ have at least investigated, if not still investigating TikTok for spying on American Journalists and that he also signed the "No TikTok on government Devices Act" seems to be a hypocritical decision regardless if an actual government device is being used to manage the account or not, doesn't it? At the very least, it sends a mixed message on to whether TikTok in its current state should be considered such a big deal in light of the bipartisan flogging that is currently being given to them.
Perhaps they deserve it but I think we also deserve an official explanation that isn't a hand wave as to why this is a reasonable decision in light of the supported political actions and allegations from the same administration that is deciding to use it anyway.
Personally I use FreeIPA for my LDAP. I like that I can create sudoers rules from one centralized place and manage ssh keys across all clients. Granted I could just use Ansible I suppose, which is how I update multiple distributions in my network and online but I like that I can just change SSH keys and sudoers from one place easily instead of changing tasks/roles. I also usually run cockpit even on my non-Red Hat distros with SSH keys just so I don't have to log into everything though it is somewhat limited outside of the Red Hat sphere.
If you don't want to use ProxMox or some other specialized HyperVisor ecosystem, you can also use Cockpit to manager your VMs along with your Pods. I wish there'd be more attention to it for features because it feels like it could do a lot more.
I also don't really worry about locking myself out for two reasons:
- I use SSH keys.
- I also have a break-glass local account on every system...with SSH keys. If its on your local network, you can use VNC/VM console/Remote Desktop with a local account while only allowing SSH with keys if you'd like. Just make sure if you're going to allow remote access outside of your network that you never forward the VNC/RDP ports. For SSH when I do this I always pick some random port -- never default and never common ones like 2222 to at least keep my logs less noisy from the botnet auto attacks.
For my online VPS' I use a firewall with geoIP from Maxmind and drop all ports but 443 from the world, except for whatever country I'm in. I drop all packets from certain countries that seem to auto-attack more often than others. I try to drop packets from all known (to me) Shodan scanners. If I'm not traveling I just restrict all other ports to my public IP's subnet though my IP hasn't changed for years. For status checking services like StatusCake, I use the "push" method instead using a simple cron job with curl instead of relying on servers around the world checking my ports. In this case, the services just check that my server has successfully hit them within X minutes to be "up".
Permanently Deleted
As much as he may have a case so long as he didn't act against store policy and actually attempted to he probably has a case, even in an at-will state.
The problem is that it will likely be difficult to get an attorney to represent him without an actual retainer because these cases usually draw out for a long, long time and are difficult to fight. Unless there's a legitimate case for a class action, then the chances are slim that anyone can afford to fight the case, even if they ultimately could win because no attorney is going to devote years to this for a 'maybe'.
The only route there may be a hope of winning here is for him to apply for unemployment and if he doesn't get it, to appeal himself. He may get that as small of a win as that is.
It is crazy that the GOP is seriously trying to impeach a person for just doing their job because they know they won't get the support to impeach President Biden but they want to ruin someone's career over political bullshit because they have nothing to show of their governance for far too long.
I was just replying tongue-in-cheek to this, though I really do have the cups.
Kristi Noem has been licking boots hard the last few years but doubled her efforts in licking boots this past year. The other day Pine Ridge -- the Oglala Sioux Tribe (Oyate) reservation banned her from entering because of her "border invasion" remarks. her response was essentially that she thinks it is bad that they brought politics into a discussion regarding federal laws...
She also started the "Meth. We're on it." marketing campaign for $1.4 million, I guess, against the meth problem in South Dakota and kept using the hashtag. She gave a GW Bush-esque response about it.
She's very divisive and definitely not diplomatic. I guess we will see if she Laura Boeberts her way out of the graces of her constituents.
Aw. I just have the older McDonald's Garfield cups with all the lead paint instead of the plutonium I guess.
I didn't say there were Miranda rights in Australia. I was referring the story I linked, which is from the US.
Your immutable OS stays stable. For example, running a sudo pacman -Syu with a bunch of stuff from AUR in your Arch container for example will not bring down your OS or otherwise make it unstable. The immutable image you first install has been tested and it is the same image as the testers -- same with the upgrades and updates, so long as you don't overlap the image with rpm-ostree in this case.
Immutability keeps your OS stable and if something does happen to go wrong, you just roll it back.
If that isn't something you need/want then that's not something you need/want.