

Security Now https://twit.tv/shows/security-now
Every week there will be news topics, sometimes there are deep dives into technical topics.


Security Now https://twit.tv/shows/security-now
Every week there will be news topics, sometimes there are deep dives into technical topics.


“Good for you” in a cheery voice
I’m considering Zulip
https://zulip.readthedocs.io/en/latest/production/install.html


Do note, because it’s using email, the recipient and sender are not private, along with the time, and probably the relative size of the messages.
The specific content of each message should be private as long as the encryption is done well. I haven’t looked at it so I don’t know if it implemnts safeguards to verify who you’re messaging with (besides using the email address) and I don’t know if it uses PFS (Perfect Forward Secrecy) to protect against a key getting compromised.


https://github.com/rsmsctr/vaultwardenGuide
It doesn’t cover backups though. It uses Caddy instead of NGINX, and it uses DuckDNS to point a subdomain to your private IP address of your Vaultwarden server, so it will only be accessible in your LAN.
I’ve been researching zero-trust for my homelab recently and I’m considering OpenZiti instead of Cloudflare since I think it can all be self-hosted. The BrowZer from OpenZiti is especially interesting to me. The fact that I’m behind CGNAT is a hurdle though.
Even as a tool it lacks predictability / reproducability. If I give instructions to download a paint program, start a new canvas of 1920x1080 and use the gradient tool to go from red to green, you’re going to get the same result every time. If I instead told a class of students to ask an AI to generate a red to green gradient on a 1920x1080 canvas, the results would not be consistent.
I use AI, but it is a tool with flaws.