Brad Ganley

I’m an engineer with history in reverse-engineering, logic-level troubleshooting and design, software, and whatever else.

I think of myself of more as an agroecologist/farmer type guy though no matter what the paychecks say on them

  • 7 Posts
  • 62 Comments
Joined 1 year ago
cake
Cake day: July 4th, 2023

help-circle






  • It surprises me too on some level because it does seem very obvious.

    I’ve also learned on multiple occasions over the years that I value different things and I value them much more strongly than a large swath of the selfhosting community. That may speak to whether or not people selfhost for ideological, practical, or other reasons that I am unaware of but, at the end of the day, I find myself disappointed that the version of the selfhosting community that I imagined and thought I was on the same page with is simply not the selfhosting community that exists.








  • I don’t believe FMHY was affected. For me, the timeline went:

    1. I found out about the hack pretty much immediately when it happened
    2. I immediately hopped into the Lemmy dev matrix channels to get an idea of what was going on
    3. I crossposted the news of the hack in [email protected] about 20 or 30 minutes after it happened
    4. In the dev channels, right around when I made the post, a couple of users were able to pin down the exact vulnerability and which server the user that perpetrated it originated from. A user (that I won’t name) sent test instructions (that were quickly deleted and I will not share on the off chance that there are servers that don’t know about the vuln and haven’t patched or mitigated) that verified the vulnerability.
    5. A pull request for the fix was submitted to github (and, from a cursory look at the PR, it closes the hole that was used for the hack solidly) while, simultaneously, a couple of other devs stated that 0.18.1 is not affected by the vulnerability (which I have not taken the time to verify since they’ve already PRed a patch)

    For those reasons, I don’t think FMHY was ever at risk because of how quickly it was updated to 0.18.1 coupled with the fact that I don’t think custom emojis are a thing on here. It’s very possible that I am wrong about that because I’m an idiot but I don’t believe there’s anything to worry about.



  • I gave Calibre a brief shot and was immediately put off by how big and clunky it was. I’m sure it would have been perfect if I gave it more of a shot and spent time tweaking.

    Kavita has been my solution for the last probably 7 months and I’m loving it. I don’t need anything outside of “put book in place” and then “Open Kavita, see book” and it has been perfect for that. It’s essentially plex but with books in terms of how using and maintaining it has been.