Darkassassin07

joined 1 year ago
[–] Darkassassin07@lemmy.ca 2 points 2 days ago (1 children)

@bobslaede@feddit.dk I could kiss you. You've been invaluable my friend, thank you!

Just gave this a test: CNAME ombi.domain -> local.domain with cloudflares proxy re-enabled.

Now the HTTPS, A, and AAAA requests all receive the CNAME response and browsers are happy. I didn't even have to modify ngnix to recognize local.domain like I thought I might.

[–] Darkassassin07@lemmy.ca 2 points 2 days ago

I think I've found the problem:

It seems my issue is pihole being unable to block/modify dns requests for HTTPS records, which don't match the LAN IPs pihole handed out in A/AAAA records.

I've disabled cloudflare proxying so they don't have HTTPS records to serve, but I'll have to replace pihole with a better lan DNS solution if I want to turn that back on.

[–] Darkassassin07@lemmy.ca 3 points 2 days ago* (last edited 2 days ago) (3 children)

Thanks. That seems to be a similar, but slightly different error. I think the below may apply though.

I believe I've tracked down more of my issue, but fixing it is going to be a hassle:

When cloudflare proxying is enabled, there are 3 DNS records involved; A record with cloudflares ipv4, AAAA record with cloudflares IPV6, and the key to this puzzle: an HTTPS record with cloudflares ech/https config.

With pihole I can set DNS records for A/AAAA, but I have no way of blocking/setting the HTTPS record so it gets through from cloudflare.

The LAN A/AAAA records don't match the HTTPS record from cloudflare, so browsers freak out.

Once I disabled cloudflares proxying, I no longer get HTTPS records returned and all works as intended.

I'll either have to keep cloudflare proxying disabled, or switch pihole out for a more comprehensive DNS solution so I can set/block HTTPS records :(

Thank you @bobslaede@feddit.dk for pointing me in the right direction.

[–] Darkassassin07@lemmy.ca 2 points 2 days ago* (last edited 2 days ago) (1 children)

That unfortunately did not work. I am only getting the ipv4 address now, but I still get the same ECH error in chrome 1/5 tries.

Firefox now changed errors from 'invalid certificate' to 'connection is insecure but this site has HSTS' (true). Still wont show the cert or provide any further info. (forgot to grab a screenshot before the below 'solution')

I'm really annoyed at this point and have just disabled cloudflare proxying for this service. That seems to have sorted it for all browsers. I may look further later, I may just say fuck it and leave it like this. Gotta walk away for a bit.

[–] Darkassassin07@lemmy.ca 1 points 2 days ago

I'll look into that next if what I've done doesn't work. (see other comments)

[–] Darkassassin07@lemmy.ca 3 points 2 days ago (2 children)

Added an AAAA record to pihole:

ombi.mydomain.example 0000:0000::0000:0000

Now nslookup returns the correct ipv4 address, and '::' as the ipv6.

We'll see if that works.

[–] Darkassassin07@lemmy.ca 5 points 2 days ago

Crap, looks like that's exactly what it is.

Now how to fix that...

[–] Darkassassin07@lemmy.ca 4 points 2 days ago* (last edited 2 days ago) (7 children)

I do have external acces to Ombi via cloudflare; but the device I'm seeing this problem on is permanently connected to a VPN hosted from the same server machine as ombi/nginx with 'block all connections without VPN' enabled. And this testing has been done from within the same LAN.

It should never see/reach cloudflare for this service.

/edit; I've also disabled 'use secure DNS' in chrome. I host a local DNS within that lan/vpn network.

 

In the last couple of weeks, I've started getting this error ~1/5 times when I try to open one of my own locally hosted services.

I've never used ECH, and have always explicitly restricted nginx to TLS1.2 which doesn't support it. Why am I suddenly getting this, why is it randomly erroring, then working just fine again 2min later, and how can I prevent it altogether? Is anyone else experiencing this?

I'm primarily noticing it with Ombi. I'm also mainly using Chrome Android for this. But, checking just now; DuckDuckGo loads the page just fine everytime, and Firefox is flat out refusing to load it at all.

Firefox refuses to show the cert it claims is invalid, and 'accept and continue' just re-loads this error page. Chrome will show the cert; and it's the correct, valid cert from LE.

There's 20+ services going through the same nginx proxy, all using the same wildcard cert and identical ssl configurations; but Ombi is the only one suddenly giving me this issue regularly.

The vast majority of my services are accessed via lan/vpn; I don't need or want ECH, though I'd like to keep a basic https setup at least.

Solution: replace local A/AAAA records with a CNAME record pointing to a local only domain with its own local A/AAAA records. See below comments for clarification.

[–] Darkassassin07@lemmy.ca 2 points 3 days ago

You've done enough, keeping it behind your routers firewall.

You could block LAN access and require a VPN connection to that specific machine if you really wanted more, but I'm not that concerned about it.

[–] Darkassassin07@lemmy.ca 2 points 3 days ago* (last edited 3 days ago) (2 children)

Yup. Point is; if you're not depending on just its login page to keep it secure, there's not a whole lot needing 'security patches', so I wouldn't be all that concerned about slow updates. As long as it remains bug free, I'm happy.

[–] Darkassassin07@lemmy.ca 4 points 3 days ago (4 children)

And security patches

Something with the power of dockge should be behind a seprate form of authentication imo.

I only access it via VPN, it's not exposed to WAN.

[–] Darkassassin07@lemmy.ca 46 points 4 days ago (18 children)

Considering how old Facebook is, you'd think they would have their shit together when it comes to password security...

 

I've been using paperless-ngx to consume mail from outlook/hotmail for a while now, but recently had the mail server refuse connections while mail was being processed. (Not sure why, consuming is working now with no changes and no errors besides 'connection refused', while retrieving that mail. Temporary outage I guess?)

This left me with a couple pieces of mail not imported. However, now everytime the mail consume task runs, it recognizes that those pieces of mail are there but refuses to process them with the message:

Skipping mail '421' '<email subject>' from '<sender email>', already processed.

How can I get it to recognize those mails HAVE NOT been processed?

 

Aug 13 (Reuters) - General Motors (GM.N), has been sued by the state of Texas, which accused the automaker of installing technology on more than 14 million vehicles to collect data about drivers, which it then sold to insurers and other companies without drivers' consent.

15
submitted 3 months ago* (last edited 2 months ago) by Darkassassin07@lemmy.ca to c/jerboa@lemmy.ml
 

I've noticed with the last 2-3 versions of the app (currently 0.0.69, nice); the app crashes 2/3rds of the time when returning to it from being in the background.

Open the app, switch to another app, switch back a couple min later and it closes then reopens as if you'd just started it for the first time today (losing whatever post you had open).

Curious if others are experiencing this?

Android 14, One UI 6.1

 

CPU/GPU/RAM/Disk usage, logs, errors, network usage, overall status, etc

What do you use/prefer?

Mainly looking for self-hosted web based tools, stuff I can view from a browser; but desktop and CLI apps are welcome too :)

 

I have what may be a stupid question...

How is it your master password is both used to decrypt your vault and used to authenticate with bitwardens public servers to acquire a copy of your vault/view it in the web app, but bitwarden can't use that password entry to decrypt the vault themselves?

(please correct me if I'm misunderstanding, as I use self-hosted vaultwarden for my server instead of the public ones)

75
submitted 8 months ago* (last edited 8 months ago) by Darkassassin07@lemmy.ca to c/selfhosted@lemmy.world
 

After almost a year of repeated emails stating the transition from Google Domains will have no effect on customers, no action is required; I just got this email:

Update Dynamic DNS records Hi there, As previously communicated, Squarespace has purchased all domain name registrations and related customer accounts from Google Domains. Customers are in the process of being moved to Squarespace Domains, but before we migrate your domain [redacted] we wanted to inform you that a feature you use, Dynamic DNS (DDNS), will not be supported by Squarespace.

So apparently SquareSpace will be entirely useless to me and I've got "as soon as 30 days" to move.

Got any suggestions for good registrars to migrate to?

(it's a .pw domain if that matters)

/edit. I'm a moron.

I already use cloudflare as my name server, Google/SquareSpace only handles the registration.

I'll be fine. Thanks for the help everyone!

10
2FA (lemmy.ca)
submitted 1 year ago* (last edited 1 year ago) by Darkassassin07@lemmy.ca to c/boostforlemmy@lemmy.world
 

Does boost support 2 factor auth?

I can't login: If i use the incorrect user+pass I get 'incorrect login' if I use the correct ones I get 'login failed'.

There is no option to enter my required 2fa code...

/edit switched apps then switched back and the 2fa field showed up but refused my code. Force stopped the app and got the same 'login failed' message switched apps again and back; now it shows all fields and finally logged me in correctly.

Seems buggy af.

 

I've only ever had my domain registered via Google Domains (~7 years), mostly because it was cheap+convenient, and google already had my billing info. Google has however sold its domain registration services to SquareSpace and will soon be transitioning customers there.

Not upset to be removing one more bit of google from my life, but I don't know much about SquareSpace and I'm not sure if I should just go with the transition to them or perhaps move to a different registrar... If I was to move, where too?

Curious what others think about the situation and company.

Are you a Google domains customer? What's your plan? Why?

 

Using Chrome, Firefox, Brave, Samsungs 'Internet' app, and every other browser I've used/tried on Android:

I'll go to select some text on a page by long-pressing on it and it'll select the word I'm touching as well as expand that selection to a somewhat random amount of additional text (usually not following any structure such as selecting a whole sentence for example).

I'll then go to adjust that selection by grabbing one of the two tabs on either end of it and the moment I do, the opposite tab jumps to a completely random spot on the page vastly expanding the selection, then the whole page scrolls to an entirely different section; Leaving me holding one end of the selection unable to see what was originally selected. I can't scroll to where I was, and If I let go and just click copy I've now copied 90%of the page to my clipboard.... Attempting to modify the selection any further yields the same lack of control and just makes things worse.

This doesn't happen everywhere, but I get these results far far more often than a successful copy+paste. Like just now trying to copy an address from a local transit guide.

I end up having to drop the paste into a notepad app, reselect the bit I actually wanted (if it even made it into the pile of garbage I was forced to grab) then delete the note once I'm done.

This is fucking stupid and I hate it. Rant over. Thank you for listening.

/edit: I don't have the power to pin a comment, but d3Xt3r@lemmy.world has a great solution: Use the rectangle select tool in androids 'Edge Panel' (must be enabled in settings), then press the 'T' button to copy text from the area you've selected.

 

I'm not talking about an extra 10-15sec, but easily 2-3 full minutes (I've sat here with a timer checking) to load pages, sometimes not loading them at all. Particularly with login pages, but even just homepages.

Dropbox, Cloudflare, Various companies forums, My bank, Google; each of these sites and more I've had firefox either not load at all, or take so long I've been able to copy the link into Chrome, do what I need there, then come back to Firefox still 'loading' a blank white page.

I just don't understand. I want to migrate away from Chrome and use Firefox, but it's been unusably slow when it even loads anything at all.

P.S. In the time I've taken to write this (~5min) plus the time to decide to post and find this community firefox has still not loaded my cloudflare dash... (typed in the address, waited a while, gave up and came here but left it open)

/edit: I should note I have ublock installed, but I get the same results with it disabled most of the time.

 

When viewing individual comment trees, usually by opening a comment from my own history that has replies on it, or just clicking view context: the original comment is the furthest indented, with the replies indented one less, and further replies to those less indented still until the lowest level comment appears as the oc, but at the bottom of the list.

Here's an example:

view more: next ›