• Activity
  • Votes
  • Comments
  • New
  • All activity
    1. Do you have an internal narrative or monologue, and if so what do you mean by that?

      This thread is inspired by an off-topic discussion in another thread that was so interesting that I wanted to make a whole post about it. I've often seen people on the net express surprise that...

      This thread is inspired by an off-topic discussion in another thread that was so interesting that I wanted to make a whole post about it. I've often seen people on the net express surprise that others have different modes of thought, typically with statements like "It was surprising to learn that others do/don't have an internal monologue!", where the do/don't choice depends on the person. I've thought for a while that a lot of this confusion might arise from people interpreting "Internal monologue" differently, and that people might actually think more similarly that it appears at first glance. My attempt to explain this in that thread was:

      For example, I certainly do not vocalize all of my thoughts and it seems like my speed of thought goes much faster than the amount of time it would take to vocalize every single thing going through my head. That being said, once I concentrate on what I am thinking about, there is definitely a vocal component. If I think about going downstairs to get a snack, my thoughts are non-vocal, but once I think about the fact I am thinking about going to get a snack, I impose a narrative that has some type of vocal quality to it - I will think, I believe in words, that my thought was "I am going to go get a snack". I suspect in discussions like this a lot of people perhaps conflate the thought with the thought about the thought, since the latter is necessary to convey what one is thinking about and (at least in my case) has some type of narrative element.

      So I am curious, Tildes - can you explain how you think, preferably both in moments where you are not actively thinking about thinking and those where you are?

      28 votes
    2. What's hard about being a man?

      I started reading Liz Plank's For the Love of Men: A New Vision for Mindful Masculinity, and it opens with the author's experiences asking men this question (emphasis mine): The more I read about...

      I started reading Liz Plank's For the Love of Men: A New Vision for Mindful Masculinity, and it opens with the author's experiences asking men this question (emphasis mine):

      The more I read about men’s relationship to directions and maps, the more it explained the absence of a substantive and open conversation about masculinity. While women are encouraged to ask questions, men are expected to pretend like they know everything even when they don’t, even when it comes to large and existential questions about their gender and their lives. As I traveled across the world, from Iceland to Zambia, I asked men the same question over and over again: What’s hard about being a man? Every single time I asked that question it was like I had just asked them if unicorns can swim.

      It was met with a pause, a smile, and then followed by another long pause followed by the words: “I’ve never actually thought of that.” When I asked women that same question about their gender—in other words, when I asked women what was hard about being a woman—it was like I had asked them to name every single thing they loved about puppies. I got nearly the same response from every woman I spoke to: “How much time do you have?” Judging from the conversations I would strike up with (half-)willing strangers, women had spent a lot of time thinking about how their gender impacts their lives, but men visibly hadn’t. While that conversation had been blossoming with women for decades, for men, accepting directions was proof that the system was broken, which goes against the natural impulses of what being a man means: not to admit confusion or ask questions.

      I thought it was a worthwhile question to consider, and I'm interested to hear how people here on Tildes would answer it.

      Also, while I'm confident in our community's ability to apply the principle of charity, I do know that discussions about gender online can often become contentious. I would very much like this to be a place for people to be able to share open and honest truths about themselves, even if those are difficult or revealing. If you are replying to someone, especially someone who has just opened up about their own personal experiences or beliefs, please make sure you are being thoughtful and considerate when doing so.

      Finally, while the question is specifically about men, I don't want to limit responses to men only. I think women and non-binary people definitely have valuable insights into masculinity as well and I welcome your voices should you choose to answer.

      49 votes
    3. Need suggestions for server email tutorial

      I usually setup debian or ubuntu servers. One of the pain areas I have avoided is email and usually just off-load the email to a 3rd party service. I currently need to setup a server with an email...

      I usually setup debian or ubuntu servers. One of the pain areas I have avoided is email and usually just off-load the email to a 3rd party service. I currently need to setup a server with an email server and need a really simple straightforward tutorial. I thought I would see if the community has any suggestions.

      10 votes
    4. Saturday Security Brief

      Saturday Security Brief Topics: Attack Surface Management, Active iMessage exploit targetting journalists, Academic research on unique EM attack vectors for air-gapped systems. Any feedback or...

      Saturday Security Brief

      Topics: Attack Surface Management, Active iMessage exploit targetting journalists, Academic research on unique EM attack vectors for air-gapped systems.

      Any feedback or thoughts on the experience of receiving and discussing news through this brief or in general are welcome. I'm curious about this form of staying informed so I want to experiment. (Thanks again for the suggestion to post the topics as comments.)


      Attack Surface Management

      This concept is about ensuring that your network is equipped to handle the many issues that arise from accommodating various "Servers, IoT devices, old VPSs, forgotten environments, misconfigured services and unknown exposed assets" with an enterprise environment. Some of the wisdom here can be applied better think about protecting our personal networks as well. Outdated phones, computers, wifi extenders, and more can be a foothold for outside attackers to retain persistant access. Consider taking steps to migigate and avoid potential harm from untamed devices.

      Consider putting certain devices on the guest network if your router supports doing so and has extra rules for devices on that network so they can't cause damage to your other devices directly.

      "A report from 2016 predicted that 30% of all data breaches by 2020 will be the result of shadow IT resources: systems, devices, software, apps and services that aren’t approved, and in use without the organization’s security team’s knowledge. But shadow IT isn’t the only area where security and IT teams face issues with tracking and visibility."

      Attack Surface Management: You Can’t Secure What You Can’t See ~ Security Trails


      Multiple Journalists Hacked with ‘Zero-Click’ iMessage Exploit

      Mobile spyware is continuing to evolve and tend towards professional solutions. Recently this technology has been abused to conduct espionage on journalists of major networks. Where once these exploits typically required some mistaken click from the user, new developments are allowing their activities without any trace or requiring interaction from the target.

      "NSO Group’s Pegasus spyware is a mobile phone surveillance solution that enables customers to remotely exploit and monitor devices. The company is a prolific seller of surveillance technology to governments around the world, and its products have been regularly linked to surveillance abuses."

      "In July and August 2020, government operatives used NSO Group’s Pegasus spyware to hack 36 personal phones belonging to journalists, producers, anchors, and executives at Al Jazeera. The personal phone of a journalist at London-based Al Araby TV was also hacked."

      "The journalists were hacked by four Pegasus operators, including one operator MONARCHY that we attribute to Saudi Arabia, and one operator SNEAKY KESTREL that we attribute to the United Arab Emirates."

      "More recently, NSO Group is shifting towards zero-click exploits and network-based attacks that allow its government clients to break into phones without any interaction from the target, and without leaving any visible traces."

      The Great iPwn Journalists Hacked with Suspected NSO Group iMessage ‘Zero-Click’ Exploit ~ Citizen Lab


      Security researchers exfiltrate data from air-gapped systems by measuring the vibrations made by PC fans.

      Besides this potential exploit the article mentions past research done by Guri and his team which is worth checking out, like:

      • LED-it-Go - exfiltrate data from air-gapped systems via an HDD's activity LED

      • AirHopper - use the local GPU card to emit electromagnetic signals to a nearby mobile phone, also used to steal data

      • MAGNETO & ODINI - steal data from Faraday cage-protected systems

      • PowerHammer - steal data from air-gapped systems using power lines

      • BRIGHTNESS - steal data from air-gapped systems using screen brightness variations

      "Academics from an Israeli university have proven the feasibility of using fans installed inside a computer to create controlled vibrations that can be used to steal data from air-gapped systems."

      Academics steal data from air-gapped systems using PC fan vibrations ~ Zdnet


      Good Practices

      "Hundreds of popular websites now offer some form of multi-factor authentication (MFA), which can help users safeguard access to accounts when their password is breached or stolen. But people who don’t take advantage of these added safeguards may find it far more difficult to regain access when their account gets hacked, because increasingly thieves will enable multi-factor options and tie the account to a device they control. Here’s the story of one such incident."

      Turn on MFA Before Crooks Do It For You ~ Krebs on Security

      16 votes
    5. Friday Security Brief

      Friday Security Brief This release is trial for a weekly security brief compiled from trusted sources that encourage a general awareness of cyber security issues. I'm still not sure about how to...

      Friday Security Brief

      This release is trial for a weekly security brief compiled from trusted sources that encourage a general awareness of cyber security issues. I'm still not sure about how to do this so any thoughts or feedback will be appreciated.


      Brexit deal mandates a limit to security standards

      "In what is surely an unthinking cut-and-paste issue, page 921 of the Brexit deal mandates the use of SHA-1 and 1024-bit RSA:"

      Brexit Deal Mandates Old Insecure Crypto Algorithms ~ Schneier on Security


      FBI Warns of Hijacked Security Devices being exploited for Swatting

      "Stolen email passwords are being used to hijack smart home security systems to “swat” unsuspecting users, the Federal Bureau of Investigation warned this week. The announcement comes after concerned device manufacturers alerted law enforcement about the issue."

      FBI Warn Hackers are Using Hijacked Home Security Devices for Swatting ~ Threatpost


      A look back at some email attacks of 2020

      "In 2020, our spam folders bulged with malware-laced emails, phishing lures linking to ransomware schemes, impersonation attacks, spoofed brand and fake domain missives, and dubious requests from legit-sounding companies. So, what defined 2020 in spam?"

      Inbox Attacks: The Miserable Year (2020) That Was ~ Threatpost


      SolarWinds hackers accessed Microsoft source code

      "The hackers behind the SolarWinds supply chain attack managed to escalate access inside Microsoft's internal network and gain access to a small number of internal accounts, which they used to access Microsoft source code repositories, the company said on Thursday."

      SolarWinds hackers accessed Microsoft source code ~ Zdnet


      CISA updates SolarWinds guidance

      "The US Cybersecurity and Infrastructure Security Agency has updated its official guidance for dealing with the fallout from the SolarWinds supply chain attack.

      In an update posted late last night, CISA said that all US government agencies that still run SolarWinds Orion platforms must update to the latest 2020.2.1HF2 version by the end of the year."

      CISA updates SolarWinds guidance, tells US govt agencies to update right away


      24 votes
    6. When seeing a tag in a group, there is a link to take you back. I think a link to see that tag in all groups would also be nice?

      When you click in a tag in a tildes group, you see the topics that have been posted in that group with that tag according to your filters. There's also a link to go back to normal viewing. I think...

      When you click in a tag in a tildes group, you see the topics that have been posted in that group with that tag according to your filters. There's also a link to go back to normal viewing. I think an option to see that tag in all groups would be a neat addition, even if not particularly important. Thoughts?

      15 votes
    7. Your 2020 in review: TV highlights

      End of the year, good time as ever for a review. I started tracking my shows and movies with trakt in 2019, so i actually have a year of data to showcase. Keeping in mind that a lot of replays in...

      End of the year, good time as ever for a review.

      I started tracking my shows and movies with trakt in 2019, so i actually have a year of data to showcase. Keeping in mind that a lot of replays in this are me leaving the tv on in the background / while I sleep, here is my year:

      https://trakt.tv/users/jleclanche/year/2020

      Some highlights for me... I discovered Only Connect, what became by far my favourite game show. In general I've been enjoying game shows quite a lot and, since Trebek's diagnosis, have been going through some of Jeopardy when bored.

      New seasons: I loved the latest season of Westworld, it's sweet seeing Nolan going back to his Person of Interest roots. Archer also went back to its roots and it's been great. Sabrina got even darker, loved it. Watched the last season of stranger things and got a lot less excited about it (i do remember it getting better but this is a show that should have ended after 1, maybe two seasons).

      Reboots: Ducktales... What a revelation! And I just started the revived Animaniacs, also looking great. Finally watched the new Aladdin, very much enjoyed it! Lion King was ok, nothing special. Also, Sonic I thought was kinda funny; watched it for shits and giggles but honestly enjoyed it.

      Watched and rewatched Hamilton. Already liked it as just a playlist but as a show it truly is phenomenal.

      Some other discoveries... The Good Place. Good Girls. Ozark. All of them excellent. Started After Life but didn't get past episode 1 even though I quite want to. I finally started King of the Hill (in my watchlist for years) but I frankly can't get into it, i dislike the animation, the voices and the characters; it is witty and i can definitely see Judge's writing seeping out, but it's not smart enough to make up for the rest. And Swedish Dicks; haven't finished it as I'm watching it with a friend but loving it so far.

      How was your tv year?

      8 votes
    8. [SOLVED] A background process using a significant amount of CPU power stops immediately when I open task manager. Is there a way to identify what's doing thing?

      It started a day or two ago. Three threads (I think?) jump from nearly 0% to 100% and go back as soon as I open task manager to try figure out what's causing it. My first thought was a virus or...

      It started a day or two ago. Three threads (I think?) jump from nearly 0% to 100% and go back as soon as I open task manager to try figure out what's causing it. My first thought was a virus or bitcoin mining trying to hide itself (though isn't that done on GPU's?), but Windows' Defender came up empty handed.

      I know certain OS apps, like automatic VIRUS scans behave similarly, stopping when you click or type, but this culprit seems to only react to opening the task manager. It also doesn't start again until task manager has been closed for a while.

      17 votes
    9. Ask Tildes: How do you organize the files on your computer?

      I thought it'd be fun to see how some of you keep your computer organized. Do you follow some general scheme, keep it arbitrary, throw everything on the Desktop or in Downloads or just abuse the...

      I thought it'd be fun to see how some of you keep your computer organized. Do you follow some general scheme, keep it arbitrary, throw everything on the Desktop or in Downloads or just abuse the search bar?

      Feel free to go as general or as in-depth as you want.

      23 votes
    10. Surviving the winter

      When I was a child I never seemed to mind the winter, but in the past two or three years it's become exponentially harder for me to live through the cold and dark. I'm dreading the next few...

      When I was a child I never seemed to mind the winter, but in the past two or three years it's become exponentially harder for me to live through the cold and dark. I'm dreading the next few months.

      The lockdowns in March and April were pretty agonizing because I had too many responsibilities but suddenly none of the support systems I had built up in my friend groups. I got through that because it was slowly getting warmer and I could just go on a walk if I needed space. But it's started snowing this week and I don't know how well I'm going to manage for the rest of the season, with it getting dark at 4 PM and seeing so few people. I get caught up in my own head in these destructive patterns of anxiety about past friendships and relationships and obligations that are very hard to escape from around this time of year. I have a lot of hobbies but I can't do most of them right now, so I kind of just end of staring at the wall or my phone for half the day, feeling bad that I screwed up a relationship or said something weird 6 months ago or whatever. On repeat for every day. I have some friends in the area who I like a lot, but I'm a little scared to leave my house from what I hear about the virus on the internet. I've been trying to do phone calls sometimes but they kinda just burn me out and make me feel worse.

      I'm wondering if anyone else has a recurring problem with the winter like I do. I'm not sure if this is a normal thing and I'm just naive and haven't figured it out, or if most people are automatically as happy in the winter as they are in the summer. I've brought this up sometimes with people irl and they say "haha yeah I have seasonal depression too," but they mostly seem to just not like the cold (?), it's not the issue of banal-yet-existential dread and torturous self-probing that I can't avoid. I have a very sweet cat who will keep me company, and she's a good listener, but she doesn't talk a lot and she's hiding in another dimension half the time anyway. I journal and meditate every night, and that helps a little, but I really mostly rely on being able to go to pretty places to keep myself happy, and it's hard to do that when they're all closed or when it's too cold to be outside for a long time. If people have any thoughts or experiences I would love to read them.

      thank you xoxo

      19 votes
    11. Do you think that Shopify could soon rival Amazon?

      Notice: This has been cross-posted to another website, and re-worded I currently work in the eCommerce industry, and have hands-on experience building up a Shopify site from the ground up. As I...

      Notice: This has been cross-posted to another website, and re-worded

      I currently work in the eCommerce industry, and have hands-on experience building up a Shopify site from the ground up. As I watch all of the developments that Shopify makes both from a technical development standpoint and logistical standpoint, it becomes more and more clear to me that Shopify can begin to take on Amazon directly.

      The introduction of Shop app, which aggregates all shipments into a single application including those outside of Amazon, also allows users to browse products from any particular Shopify store. The app also notifies you of any shipping updates, and when packages have been delivered.

      From a technical standpoint, Shopify's main attractions come down to a few things: order management, credit card processing, customer management, and plugin integrations. This is the core of Shopify's platform for both larger and smaller businesses. Though due to Shopify's requirement of using their CMS to serve your content, enterprise users have to look elsewhere in order to build something called "headless builds", which essentially use alternate CMS mixed with Shopify's CMS to continue serving their content.

      There are a few companies that make such software in order to build out a fully custom site while still using the Shopify platform as its core, though at the moment they are a little 'hacky' but still fully functional. Given the interest in Shopify's platform at such a high level, they are very likely working on their own headless framework which could allow for 1) mainstream stores to integrate their existing platforms into a unified Shopify marketplace, and 2) to allow stores to build out fully custom websites using the Shopify platform at its core and also enroll them into a unified Shopify marketplace.

      Amazon has mostly become a front for cheap Chinese-made products, laden with review manipulation and questionable product quality. By instead bringing large brands on board with a unified Shopify marketplace, those stores can sell quality products backed by their brands which can gain trust from customers, and will give rise to smaller brands that may have been unnoticed by larger populations.
      [ For example, I recently bought a pair of shoes from a very popular Shopify store: they represent quality, comfort, and eco-friendliness. I personally find myself more willing to spend money on quality products from companies I know I can trust. ]

      What's everyone's thoughts? Are there any general problems that could come from Shopify trying to jump-start a full-blown marketplace? Do you think that companies would be willing to integrate their ERP's and CMS's with whatever API's or headless framework Shopify decides to build out?

      9 votes
    12. An honest question about gender, sexuality, and the LGBTQ+ community

      Hello! If you've clicked on this I'd like to start off by apologizing for the title! I'm in a bit of a strange headspace right this moment as I try to digest some thoughts thrown my way today. I'm...

      Hello! If you've clicked on this I'd like to start off by apologizing for the title! I'm in a bit of a strange headspace right this moment as I try to digest some thoughts thrown my way today. I'm currently coming at this from the personal lens of myself, but I think there are some larger questions/generalizations that could be made and might be helpful for others.

      Ok, so for some background I am a "straight" man. My previous partners have all been women, with the exception of one who identified as female when we were dating, and my current partner is non-binary but female-presenting and has identified as such the entirety of the time we have been dating. I have previously viewed myself as straight and an ally to my partner and the lgbtq+ community. Today, I was having a long conversation with my cousin about his experiences coming out of the closet and with homophobia in our family. I mentioned at one point that I didn't feel comfortable making some assumptions/statements since I am straight and not a member of the community. He (very politely) brought up that, at least strictly technically speaking, the fact that I am dating someone who is non-binary means we are not in a heterosexual relationship and that I am not technically straight, more likely being bi or pan (if we could lets not turn this into the bi vs pan debate which I know is a controversial topic but not really what I'd like to focus on). He also made a point to stress that these are all technical definitions and that gender and sexual identity are very personal and if I don't feel that it describes me then it isn't for him to decide I'm wrong. This made me a bit uncomfortable. It made me uncomfortable because while he's right, it feels wrong. I feel like if I began identifying as pan/bi, it would come off as a straight white male looking for a way to put himself in the position of being oppressed or marginalized for woke points. I don't know if it is because the college I went to was full of dudes like this, constantly looking for ways to be the victim, but its just something I feel deep in my bones. I don't really know though. I feel like if someone came up to me and described my life as their own and told me they identified as pan/bi I would agree and support them, but I won't extend that to myself. I don't know if its just a lifetime of assuming I was straight is why this is or if the term is actually wrong.

      I guess to summarize/generalize, I'll put some reallly fucking loaded questions where I know the 'real' answer is "It is a deeply personal thing and will vary by person to person because the LGBTQ+ community isn't a monolith with all the same ideas" but I'm hoping maybe writing all this out and reading some of the results will help me color, process and digest my thoughts.

      1. What/where would you put the line between straight and not straight (if anywhere). I know personally while I like to keep an open mind, I do heavily preference female-presenting people, whether they be trans, nb, or identify as a woman. But is that openness to dating someone who doesn't identify as a woman enough for me to be not-straight? I want to say yes, I don't think you need to date someone of a different gender to be not-straight. My cousin is bi but has exclusively dated men. I wouldn't tell him he isn't bi.

      2. I am very uncomfortable with this question but do you feel there is a degree of "not-straight" you need to be to be an active part of the queer community. To kind of explain my thoughts on that: From an outside perspective, no one that hasn't been told my partner is nb would question if we said we were a straight couple. I've never and probably will never feel fear or be oppressed based on my sexuality. I dunno. I just feel really weird. like I'm inserting myself into a community I've always identified as an ally of but been an outsider to.

      Anyway, sorry for this rant. I know the two questions are really loaded and I honestly feel like I know the answer to both of them. But just because i know the answer doesn't change how conflicted I feel and so I guess I'm just trying to work through some of the thoughts and conflicts.

      I also want to take a second to note: I am actively talking with my partner about these thoughts and feelings. This is an ongoing discussion in our household, I am just looking for more perspectives and views to help me see things from different angles and work through my thoughts and feelings. Helping me through this is absolutely not the responsibility of anyone on Tildes and I don't want it to seem like I am putting that pressure on the community.

      18 votes
    13. BOTI Science: Best of interval compilations, suggestions? Supporting trends identification

      Discussions of progress or collapse often get mired in the question of significant discoveries and inventions. After wrestling with several organisational cencepts for various catalogues, and...

      Discussions of progress or collapse often get mired in the question of significant discoveries and inventions. After wrestling with several organisational cencepts for various catalogues, and running into the Ever Growing List dilemma, I hit on what I call BOTI, or Best of the Interval (day, week, month, year, decade, century, etc.). It's similar to the tickler file 43 folder perpetual filing system of GTD. For technical types, a round-robin database or circular buffer.

      (As with my bullet journal experiments, the effort is uneven but recoverable, which is its core strength.)

      By setting up a cascade of buffers --- day of month, (optionally week or weekdays), month of year, year of decade, decade of century, century of millennium, millennium of 10kyr, a progressively larger scale record (roughly order-of-magnitude based), with a resolution of day but a maximum retention of (here) 10,000 years but only 83 record bins. How much you choose to put in each bin is up to you, but the idea is that only to most significant information is carried forward. Yes, some information is lost but total data storage requirements are known once the bin size and count are established.

      Another problem BOTI addresses is finite attention. If you limit yourself to a finite set of items per year, say ten to one hundred (about what a moderately motivated individual could be aware of), BOTI is a form of noise-filtering. Items which seemed urgent or captivating in the moment often fade in significance with time, and often overlooked element rise in significance with time and context. 'Let it settle with time" is a good cure to FOMO.

      There's the question of revisiting context. I'd argue that significance might be substantially revised years, decades, possibly centuries after a discovery or inventiion. So an end-of-period purge of all but the top items isn't what we're looking for. Gut a gradual forgetting / pruning seems the general idea.

      Back to science and technology: It's hard to assess significance in the moment, and day-to-day reports of science and technology advances are noisy. I've been looking for possible sources to use and am finding little that's satisfactory. I'd like suggestions.

      There is a goal here: trends over time. I've a few senses of directions of research and progress, possibly also of biases in awards. Looking at, for example, Nobels in physics, chemistry, and medicine from, say, 1901--1960 vs. 1961--2020, there seems to be a marked shift, though categorising that might be difficult. The breakpoint isn't necessarily 1960 either --- 1950 or 1940 might be argued for.

      There is the question of how to measure significance of scientific discoveries or technological inventions. I'm not going to get into that though several standard measures (e.g., counting patents issued) strike me as highly problematic, despite being common in research. Discussion might be interesting.

      Mostly, though, I'm looking for data sources.

      5 votes
    14. Vimeo is not very good

      (This is kind of a rant about Vimeo's website. It might be better in ~tech, or ~comp. Feel free to move it.) I've always preferred using Vimeo to YouTube for finding interesting videos because...

      (This is kind of a rant about Vimeo's website. It might be better in ~tech, or ~comp. Feel free to move it.)

      I've always preferred using Vimeo to YouTube for finding interesting videos because it's more oriented towards artists than people just uploading random stuff. As mentioned in the recent What Creative Projects Have You Been Working On? thread, I had some nature videos I shot of hummingbirds and wanted to upload them somewhere. My spouse had uploaded videos to Vimeo before, so I thought I'd put them there rather than YouTube because I don't like dealing with Google.

      The site is a hot mess. I've hit the following problems after lightly using it for 2 days. I uploaded a single video and set it to be public:

      • No way to enter keywords or tags. Searching will only find your video if you mention the search terms in your title (and maybe your description).
      • Some of their own pages are broken or missing. If I go to "categories" and click on "documentary" it shows me an error message saying the page doesn't exist. If I click on "arts" or "music" I go to that category and see videos available.
      • No information on how to add your video to a given category. Is it done automatically? Is it done by someone on the staff noticing and adding it? I have no idea!
      • My video has gotten a few views from people here, so it is uploaded and available for anyone to see. But if I search for "hummingbird" and limit the search to videos uploaded in the last 7 days, my video is not displayed. Why not? Who knows?
      • I ran the iOS app without logging in and it showed my account but said I had no videos, even though others were able to see them. Logging in shows the videos and confirms that they are set to allow anyone to view them. WTF?
      • I attempted to send them a message telling them about the broken links. When you go to the help section and click on "Contact Us," you get a fake chat window that's just a bot that will pick keywords out of your question and reply with articles that don't answer your question. In fact, they even ask below each one, "Does this answer your question?" with a button for yes and nothing else. There's no way to say, "No, this was unhelpful." If you scroll to the bottom of the list of articles they recommend, there's a button to send a message to their tech support.
      • I'm on the free tier, so I wasn't expecting any sort of answer to my help question, but still wanted to let them know so they could fix it. But that didn't work either. They have enough sense to copy your question from the chat bot into the tech support form (nice!) but it strips out any URLs. (Thanks! Very useful since I was trying to report a broken URL!) But it doesn't matter anyway because after you choose a category (none of which are correct) and attempt to submit your form, nothing happens. You press "Next" and the button turns into a spinner for a few seconds, and then stops and turns back into the "Next" button. Nothing appears to have been submitted, but no error is presented.
      • The site is full of dark patterns. I get that they want upgrade revenue coming in, and I have no problem with that. But they do things like have a blinking icon in your video's settings for "interaction tools." These are things you can do to monetize your video, or whatever. Stuff I will never need. All the options in this section require a paid upgrade and there's no way to turn off the blinking beacon (except, I assume, by upgrading).

      I was considering upgrading to their bottom-tier paid account, but after seeing how much is broken, I have to wonder if they're circling the drain? I get using chat bots and forms to make it easier for their support people, and making sure users know about ways to upgrade, but this is ridiculous. Anyone else run into this?

      26 votes
    15. Share a link to good singing in a language that you don't understand

      I thought maybe we'd play this game again? This time the "iron chef" ingredient is good singing, but in a language that you don't understand. Ground rules: One song per comment, so we can vote for...

      I thought maybe we'd play this game again? This time the "iron chef" ingredient is good singing, but in a language that you don't understand.

      Ground rules:

      • One song per comment, so we can vote for them individually.
      • One top-level comment per user, so pick your favorite song.
      • If you want to post more than one song, reply to yourself to add more comments.

      Previously in this series:

      19 votes
    16. What is/are your favorite quote/s?

      (This is a self-repost, hence the "duplicate question" tag.) A guy named Adolf Hitler won an election in 1932. He won an election, and 50 million people died as a result of that election in World...

      (This is a self-repost, hence the "duplicate question" tag.)


      A guy named Adolf Hitler won an election in 1932. He won an election, and 50 million people died as a result of that election in World War II, including six million Jews. So what I learned as a little kid is that politics is, in fact, very important.

      -Bernie Sanders

      Good satire raises questions about reality.
      (IDK the source, but I first heard it here)

      The old world is dying, and the new world struggles to be born: now is the time of monsters.
      -Antonio Gramsci, 1930

      When I was a kid my parents warned me about the mind-numbing effect TV would have on me if I watched too much of it. They were referring to fluff entertainment, which I've consumed plenty of over the years. Meanwhile, my parents used the TV to watch important and meaningful shows like the news. Eventually Fox News. In the end, they were right— but not in the way they expected.

      -@balooga, here

      If God has made us in his image, we have returned him the favor.

      -Voltaire

      All tyrannies rule through fraud and force. When fraud is exposed, they must rule exclusively by force.

      -George Orwell

      If you do not use the person you are, you will lose the person you are and instead become the mask that you wear.
      -Greg Guevara/Jreg

      What do you need from your parents?

      encouragement
      -u/DeSteph-DeCurry

      This (very long) quote from "They thought they were free"

      Each act, each occasion, is worse than the last, but only a little worse. You wait for the next and the next. You wait for one great shocking occasion, thinking that others, when such a shock comes, will join with you in resisting somehow. You don't want to act, or even talk, alone; you don't want to 'go out of your way to make trouble.' Why not?-Well, you are not in the habit of doing it. And it is not just fear, fear of standing alone, that restrains you; it is also genuine uncertainty. Uncertainty is a very important factor, and, instead of decreasing as time goes on, it grows. Outside, in the streets, in the general community, 'everyone' is happy. One hears no protest, and certainly sees none. You know, in France or Italy there would be slogans against the government painted on walls and fences; in Germany, outside the great cities, perhaps, there is not even this. In the university community, in your own community, you speak privately to your colleagues, some of whom certainly feel as you do; but what do they say? They say, 'It's not so bad' or 'You're seeing things' or 'You're an alarmist.'

      And you are an alarmist. You are saying that this must lead to this, and you can't prove it. These are the beginnings, yes; but how do you know for sure when you don't know the end, and how do you know, or even surmise, the end? On the one hand, your enemies, the law, the regime, the Party, intimidate you. On the other, your colleagues pooh-pooh you as pessimistic or even neurotic. You are left with your close friends, who are, naturally, people who have always thought as you have....

      But the one great shocking occasion, when tens or hundreds or thousands will join with you, never comes. That's the difficulty. If the last and worst act of the whole regime had come immediately after the first and smallest, thousands, yes, millions would have been sufficiently shocked-if, let us say, the gassing of the Jews in '43 had come immediately after the 'German Firm' stickers on the windows of non-Jewish shops in '33. But of course this isn't the way it happens. In between come all the hundreds of little steps, some of them imperceptible, each of them preparing you not to be shocked by the next. Step C is not so much worse than Step B, and, if you did not make a stand at Step B, why should you at Step C? And so on to Step D.

      And one day, too late, your principles, if you were ever sensible of them, all rush in upon you. The burden of self-deception has grown too heavy, and some minor incident, in my case my little boy, hardly more than a baby, saying 'Jewish swine,' collapses it all at once, and you see that everything, everything, has changed and changed completely under your nose. The world you live in-your nation, your people-is not the world you were born in at all. The forms are all there, all untouched, all reassuring, the houses, the shops, the jobs, the mealtimes, the visits, the concerts, the cinema, the holidays. But the spirit, which you never noticed because you made the lifelong mistake of identifying it with the forms, is changed. Now you live in a world of hate and fear, and the people who hate and fear do not even know it themselves; when everyone is transformed, no one is transformed. Now you live in a system which rules without responsibility even to God. The system itself could not have intended this in the beginning, but in order to sustain itself it was compelled to go all the way."

      and this shorter quote from a 1950 report, along with some extras from an article that features it

      Back in 1950, when both major parties were broad and moderate with overlapping appeals, many of America’s leading political scientists wrote a report in which they bemoaned this state of affairs.

      In a report, “Toward a More Responsible Two-Party System,” they saw two national parties that were but loose confederations of state and local parties, incapable of bringing forward coherent programs to the voters and carrying them out when they got into power.

      If the American political parties failed to heed their advice, the authors issued a dire warning:

      If the two parties do not develop alternative programs that can be executed, the voter’s frustration and the mounting ambiguities of national policy might also set in motion more extreme tendencies to the political left and the political right. This, again, would represent a condition to which neither our political institutions nor our civic habits are adapted. Once a deep political cleavage develops between opposing groups, each group naturally works to keep it deep. Such groups may gravitate beyond the confines of the American system of government and its democratic institutions.

      Assuming a survival of the two-party system in form though not in spirit, even if only one of the diametrically opposite parties comes to flirt with unconstitutional means and ends, the consequences would be serious. For then the constitution-minded electorate would be virtually reduced to a one-party system with no practical alternative to holding to the “safe” party at all cost.

      (That being said, this quote does show some age, as we now know that this "constitution-minded electorate" doesn't really exist. And "moderate" is extremely relative)

      19 votes
    17. 2020 US Presidential Election Results - Discussion Thread

      This will be a noisy thread. Please use the ignore feature if you do not want to see it in your feed. This is a continuation of the original thread from election day, which was here. These threads...

      This will be a noisy thread. Please use the ignore feature if you do not want to see it in your feed.


      This is a continuation of the original thread from election day, which was here.

      These threads are intended as more conversational spaces to process the day and results. Consider this an open forum for your own thoughts and feelings.


      There is also a thread here in ~news that's more focused on articles and events.

      30 votes
    18. 2020 US Presidential Election Day - Discussion Thread

      This will be a noisy thread. Please use the ignore feature if you do not want to see it in your feed. We have a thread here in ~news that's more focused on articles and events, but I also want us...

      This will be a noisy thread. Please use the ignore feature if you do not want to see it in your feed.


      We have a thread here in ~news that's more focused on articles and events, but I also want us to have a more conversational space to process the day. Consider this an open forum for your own thoughts and feelings.

      50 votes
    19. Rate my homepage!

      Inspired by this post on lobste.rs, I thought it'd be fun for us all to post our homepages and talk about them. I'm posting this in ~creative because I think of a homepage as a creative endeavor,...

      Inspired by this post on lobste.rs, I thought it'd be fun for us all to post our homepages and talk about them. I'm posting this in ~creative because I think of a homepage as a creative endeavor, but feel free to move this to ~design or ~tech or wherever, mods.

      Just post your homepage as a top-level comment, and we'll workshop in replies!

      42 votes
    20. Tracking down an old guitar riff

      Yesterday, I was talking with my dad about western swing and similar country music in a conversation about my grandfather who was a mandolin player in a red dirt/western swing band on old timey...

      Yesterday, I was talking with my dad about western swing and similar country music in a conversation about my grandfather who was a mandolin player in a red dirt/western swing band on old timey radio in Texas during the post-war years. Unfortunately, I was never able to connect with my grandfather through music because I was still fairly young when he passed away, but I put on his favorite band, Bob Wills and the Texas Playboys, while I was thinking about him and getting some work done.

      The Spotify top tracks led me to Steel Guitar Rag from 1936. Shortly after the 40 second mark, you will hear a guitar riff that sent me on a scavenger hunt, texting a couple different friends for help and skipping around songs for half an hour. The riff felt really familiar but more uptempo in my head than in the Bob Wills track. My first thought was the band WOLF!, maybe a track like Humdinger. Good song but not it. A friend of mine suggested Folsom Prison Blues, but that has a distinctly different riff in it.

      Eventually, it struck me that I knew the riff from a King Curtis live album from 1966, I just needed to skip around until I found it in one of the tracks. The track is titled Medley: Peter Gunn / Get Long Cindy, and the riff starts after the 3:25 mark. Pretty similar don't you think?

      10 votes
    21. In which a foolish developer tries DevOps: critique my VPS provisioning script!

      I'm attempting to provision two mirror staging and production environments for a future SaaS application that we're close to launching as a company, and I'd like to get some feedback on the...

      I'm attempting to provision two mirror staging and production environments for a future SaaS application that we're close to launching as a company, and I'd like to get some feedback on the provisioning script I've created that takes a default VPS from our hosting provider, DigitalOcean, and readies it for being a secure hosting environment for our application instance (which runs inside Docker, and persists data to an unrelated managed database).

      I'm sticking with a simple infrastructure architecture at the moment: A single VPS which runs both nginx and the application instance inside a containerised docker service as mentioned earlier. There's no load balancers or server duplication at this point. @Emerald_Knight very kindly provided me in the Tildes Discord with some overall guidance about what to aim for when configuring a server (limit damage as best as possible, limit access when an attack occurs)—so I've tried to be thoughtful and integrate that paradigm where possible (disabling root login, etc).

      I’m not a DevOps or sysadmin-oriented person by trade—I stick to programming most of the time—but this role falls to me as the technical person in this business; so the last few days has been a lot of reading and readying. I’ll run through the provisioning flow step by step. Oh, and for reference, Ubuntu 20.04 LTS.

      First step is self-explanatory.

      #!/bin/sh
      
      # Name of the user to create and grant privileges to.
      USERNAME_OF_ACCOUNT=
      
      sudo apt-get -qq update
      sudo apt install -qq --yes nginx
      sudo systemctl restart nginx
      

      Next, create my sudo user, add them to the groups needed, require a password change on first login, then copy across any provided authorised keys from the root user which you can configure to be seeded to the VPS in the DigitalOcean management console.

      useradd --create-home --shell "/bin/bash" --groups sudo,www-data "${USERNAME_OF_ACCOUNT}"
      passwd --delete $USERNAME_OF_ACCOUNT
      chage --lastday 0 $USERNAME_OF_ACCOUNT
      
      HOME_DIR="$(eval echo ~${USERNAME_OF_ACCOUNT})"
      mkdir --parents "${HOME_DIR}/.ssh"
      cp /root/.ssh/authorized_keys "${HOME_DIR}/.ssh"
      
      chmod 700 ~/.ssh
      chmod 600 ~/.ssh/authorized_keys
      chown --recursive "${USERNAME_OF_ACCOUNT}":"${USERNAME_OF_ACCOUNT}" "${HOME_DIR}/.ssh"

sudo chmod 775 -R /var/www
      sudo chown -R $USERNAME_OF_ACCOUNT /var/www
      rm -rf /var/www/html
      

      Installation of docker, and run it as a service, ensure the created user is added to the docker group.

      sudo apt-get install -qq --yes \
          apt-transport-https \
          ca-certificates \
          curl \
          gnupg-agent \
          software-properties-common
      
      curl -fsSL https://download.docker.com/linux/ubuntu/gpg | sudo apt-key add -
      sudo apt-key fingerprint 0EBFCD88
      
      sudo add-apt-repository --yes \
         "deb [arch=amd64] https://download.docker.com/linux/ubuntu \
         $(lsb_release -cs) \
         stable"
      
      sudo apt-get -qq update
      sudo apt install -qq --yes docker-ce docker-ce-cli containerd.io
      
      # Only add a group if it does not exist
      sudo getent group docker || sudo groupadd docker
      sudo usermod -aG docker $USERNAME_OF_ACCOUNT
      
      # Enable docker
      sudo systemctl enable docker
      
      sudo curl -L "https://github.com/docker/compose/releases/download/1.27.4/docker-compose-$(uname -s)-$(uname -m)" -o /usr/local/bin/docker-compose
      sudo chmod +x /usr/local/bin/docker-compose
      sudo ln -s /usr/local/bin/docker-compose /usr/bin/docker-compose
      docker-compose --version
      

      Disable root logins and any form of password-based authentication by altering sshd_config.

      sed -i '/^PermitRootLogin/s/yes/no/' /etc/ssh/sshd_config
      sed -i '/^PasswordAuthentication/s/yes/no/' /etc/ssh/sshd_config
      sed -i '/^ChallengeResponseAuthentication/s/yes/no/' /etc/ssh/sshd_config
      

      Configure the firewall and fail2ban.

      sudo ufw default deny incoming
      sudo ufw default allow outgoing
      sudo ufw allow ssh
      sudo ufw allow http
      sudo ufw allow https
      sudo ufw reload
      sudo ufw --force enable && sudo ufw status verbose
      
      sudo apt-get -qq install --yes fail2ban
      sudo systemctl enable fail2ban
      sudo systemctl start fail2ban
      

      Swapfiles.

      sudo fallocate -l 1G /swapfile && ls -lh /swapfile
      sudo chmod 0600 /swapfile && ls -lh /swapfile
      sudo mkswap /swapfile
      sudo swapon /swapfile && sudo swapon --show
      echo '/swapfile none swap sw 0 0' | sudo tee -a /etc/fstab
      

      Unattended updates, and restart the ssh daemon.

      sudo apt install -qq unattended-upgrades
      sudo systemctl restart ssh
      

      Some questions

      You can assume these questions are cost-benefit focused, i.e. is it worth my time to investigate this, versus something else that may have better gains given my limited time.

      1. Obviously, any critiques of the above provisioning process are appreciated—both on the micro level of criticising particular lines, or zooming out and saying “well why don’t you do this instead…”. I can’t know what I don’t know.

      2. Is it worth investigating tools such as ss or lynis (https://github.com/CISOfy/lynis) to perform server auditing? I don’t have to meet any compliance requirements at this point.

      3. Do I get any meaningful increase in security by implementing 2FA on login here using google authenticator? As far as I can see, as long as I'm using best practices to actually ssh into our boxes, then the likeliest risk profile for unwanted access probably isn’t via the authentication mechanism I use personally to access my servers.

      4. Am I missing anything here? Beyond the provisioning script itself, I adhere to best practices around storing and generating passwords and ssh keys.

      Some notes and comments

      1. Eventually I'll use the hosting provider's API to spin up and spin down VPS's on the fly via a custom management application, which gives me an opportunity to programmatically execute the provisioning script above and run some over pre- and post-provisioning things, like deployment of the application and so forth.

      2. Usage alerts and monitoring is configured within DigitalOcean's console, and alerts are sent to our business' Slack for me to action as needed. Currently, I’m settling on the following alerts:
        1. Server CPU utilisation greater than 80% for 5 minutes.
        2. Server memory usage greater than 80% for 5 minutes.
        3. I’m also looking at setting up daily fail2ban status alerts if needed.
      9 votes
    22. Trump/Biden 2020 Presidential Debate #2 Discussion Thread

      This will be a noisy thread. Please use the ignore feature if you do not want to see it in your feed. Watch on YouTube Other viewing options Debate starts ~90 minutes from the time of this...

      This will be a noisy thread. Please use the ignore feature if you do not want to see it in your feed.


      Watch on YouTube
      Other viewing options

      Debate starts ~90 minutes from the time of this posting.


      Info from The Washington Post:

      Location: Belmont University in Nashville

      Moderator: Kristen Welker, NBC News White House correspondent and co-anchor of “Weekend Today”

      Details: The debate will be 90 minutes long and have no commercial breaks. It will be divided into six 15-minute segments that the moderator has chosen. They are: fighting covid-19, American families, race in America, climate change, national security and leadership.

      Trump’s campaign has criticized the topics, saying they thought this was supposed to be a foreign policy debate. The head of the Commission on Presidential Debates said that’s not true.

      Trump has criticized the moderator, Welker, as being biased, as he has other moderators. The commission and even a Fox News host have defended Welker’s integrity.

      The commission also announced days before the debate that in light of Trump’s frequent interruptions during the first one, it will silence the microphone of the candidate who is not speaking during the two-minute opening segment for each candidate. After each candidate has two minutes, there will be an open discussion where both microphones will be on, but the commission urged civility in a statement: “It is the hope of the Commission that the candidates will be respectful of each other’s time.” The Trump campaign said it still will participate, despite the president criticizing a potential virtual debate as a forum where it would be too easy to silence his microphone.

      21 votes
    23. Proving the Earth is round at home

      I am looking for practical ways to prove the Earth is round using materials accessible to the average person. I have zero interest in disproving Flat Earth folks. I am inspired by Dan Olson's...

      I am looking for practical ways to prove the Earth is round using materials accessible to the average person. I have zero interest in disproving Flat Earth folks.

      I am inspired by Dan Olson's (Folding Ideas) excellent video where he is able to do this measuring the curvature of a lake near his home that has a very specific geography that lends itself to this sort of experiment. I've seen all sorts of ways to prove this measuring shadows and poles, using gyroscopes, etc. and wanted to know if there are any practical guides for proving once and for all that the Earth is round for yourself relying on nothing more than experimentation.


      What I'm not looking for:

      • Math relying on flight times/charts
      • Video/picture evidence
      • Deductive proofs built on agreed upon premises
      • Expensive tests
      • Extremely time consuming projects
      • Underwhelming results (relying on a probabilistic argument for a round Earth from the evidence.)

      What I am looking for:

      • Practical experiments
      • Things I could potentially do without spending much money
      • Tests that aren't largely comprised of accepting someone else's research
      • Potentially math-heavy evidence
      • Results that are strong and conclusive

      I've thought of finding some easy to test version of Eratosthenes' proof using two poles. I've also thought about using a balloon and sending something to space like what is done in this Tom Scott video. Nothing seems well documented in such a way as for me to be able to follow it at home.

      TL;DR: I think it would be a meaningful experience to have the power to prove the Earth is round by myself, for myself. I can only compare this desire to the desire a child with a telescope has when wishing to observe Saturn or Mars themselves for the first time. It's not to prove anything or to settle doubts, but for the personal value of independently observing this astronomical fact oneself.

      17 votes
    24. How to get a "Reddit Experience" for Twitter?

      Hey folks, I hate Twitter with a passion and find it very hard to follow discussions because they are so terribly displayed in the official App/Website. Unfortunately I have to use it for job...

      Hey folks,

      I hate Twitter with a passion and find it very hard to follow discussions because they are so terribly displayed in the official App/Website. Unfortunately I have to use it for job reasons and therefore I am looking for less headaches.

      Is there an app which can show me Twitter content and discussion tree views like Reddit does?

      I am totally willing to pay.

      Thanks in advance for your thoughts.

      8 votes
    25. How do you know whether a back-and-forth conversation is productive and/or appreciated?

      Sometimes I get into a back-and-forth... heated interaction with someone, and it goes on for a while, and then they stop responding. Afterwords, I might wonder if it was worthwhile. Maybe they got...

      Sometimes I get into a back-and-forth... heated interaction with someone, and it goes on for a while, and then they stop responding. Afterwords, I might wonder if it was worthwhile. Maybe they got tired of arguing with me, or maybe they just thought the conversation reached its natural endpoint? Rarely, the conversation might end with us explicitly agreeing it was a good discussion, but that's kind of formal and not the usual case online.

      Just stopping is my habit as well. If I don't want to talk anymore, I upvote the last comment (if I thought it was good) but don't reply.

      In the case of repeated interactions like this with the same person, sometimes I wonder if I'm annoying them by replying to their comments too much, particularly if we disagree often. I've never been explicitly told to go away, but people are often reluctant to say things like that, for good reason since you never know how people will react.

      It seems to me that upvotes don't tell me this. Upvotes tell you whether your comments make sense to the crowd. They don't tell you whether the person you're talking to liked your reply. Which seems like it would be good to know. It would be valuable feedback if the goal is to be a better conversationalist. That seems like a good goal to aim for?

      I guess we could get in the habit of saying "good point" and all that, and sometimes things can be inferred from what people say if you're good at taking hints, but not all of us are. But we are all trained to upvote things we like already, and it seems like it would be nice to take advantage of that.

      To the extent that people like to gather internet points, I wonder what sort of conversation would be encouraged if you got them by writing a good reply from the perspective of the person being replied to? But I guess it could be gamed pretty easily if two people cooperate, so we probably shouldn't keep a total.

      Also, think about how this looks from the outside: if you are reading a conversation by two other people in a heated back-and-forth, how do you know whether they're having a good time or not? Maybe it seems obvious, but in some cases a heated discussion might look worse to outsiders than participants. If you could see that they liked each other's comments then it would seem friendlier.

      Note that Facebook does tell you who upvoted a comment, but since it tells you everyone who upvoted it, it's even more information, maybe too much.

      (This is a followup to @NaraVara's previous topic, focusing on a particular aspect of it.)

      13 votes
    26. What are you following this week? Weekly sports round-up thread

      OK, let's give this a shot. Feel free to share your thoughts about anything going on this week in the world of sports - an event you're looking forward to, a great game you watched that you...

      OK, let's give this a shot.

      Feel free to share your thoughts about anything going on this week in the world of sports - an event you're looking forward to, a great game you watched that you recommend, a story that you're keeping tabs on, whatever tickles your fancy. Also, if you have any ideas/suggestions about this thread itself, feel free to chime in. My one suggestion is to please keep spoilers out of top-level comments.

      Edit: We don't have a theme tune (yet) but just imagine this is the intro (other brands are available).

      14 votes