Salamander

  • 452 Posts
  • 953 Comments
Joined 4 年前
cake
Cake day: 2021年12月19日

help-circle


  • Thanks a lot for the examples! I have been looking through these, and, as far as I can tell:

    1. In SSL stripping, the site would appear to your client as HTTP, not HTTPS. If that’s the case, I think SSL stripping is blocked when using ‘HTTPS-Only’ mode
    2. For DNS spoofing, the visited site would show up as insecure because they would not be able to generate a valid certificate for the target website

    I still have not had the chance to look into leaky metadata. But, generally, I think metadata issues can in part be addressed by not generating much metadata.

    Probably the biggest vulnerability is the captive portal. There is no way to verify you’re connecting to an official Starbucks router. I think that when connecting to a public router it is wise to assume that it is malicious.







  • 868 MHz is right

    For dBi and directionality, it depends on terrain and goals. In MeshCore you can ask the signal to follow specific router paths, and so you may or may not want an omnidirectional antenna depending on how you want the signal to travel.

    Most common antennas that you will find use wither SMA or N connectors. For outdoor use, N connectors are allegedly better in terms of water resistance. If you are making your own enclosure, you can find both SMA-IPEX and N-IPEX connectors with an O-ring which prevent water from entering the hole through which the connector threads come out. The inside of the enclosure is protected equally well for SMA and N, it is just the connector portion which remains exposed, so over months/years the connector may corrode and N-type may last longer. The Heltec T114 is probably shipped out with an SMA-IPEX cable with no O-ring.

    I use this one: N-type connector, 8 dBi, omidirectional:

    https://nl.aliexpress.com/item/1005007463706065.html




  • It depends. In my experience: in an academic laboratory I have been able to use common sense.

    For example, gloves go on when working with strong acids/bases. The statement:

    gloves apparently only give researchers a false sense of security that can dull the sense of touch and prevent you from recognizing chemical exposure

    Does not apply as much when you are working with such corrosive agents, because you really should never be in a position where spilling 4 M HCl into your hands would go unnoticed.

    When working with large quantitites of oils, even if non-hazardous, gloves go on and they will probably get oil in them.

    When working with cell cultures, the goal is often to not contaminate the cultures. Some people prefer to wash their hands thoroughly and not use gloves, and they have been working at it for many years and they seem to do just fine. It’s a risk mitigation strategy - if the cultures have antibiotics and fungicides, risk is already not too high.

    In an industry setting it is different. Companies often comply with specific standards and health and safety regulations. While the individual can use common sense, the people in charge of ascertaining compliance (sometimes ‘EHS’, Environment, health and safety personnel) aren’t necessarily chemists themselves, nor should they need to be aware of the identity of the transparent liquid in the flask that you are holding. So, generic rules are often set in place not only because of their practical utility but also to simplify enforcement. In some cases external auditors can come in (announced or not) and verify compliance - this, again is much simpler when the rule is ‘lab coat behind yellow line, gloves always on when touching a container with a liquid’ than having to interview each person to understand what they were touching without gloves and to understand their philosophy of why they chose to do so.


  • I have experienced issues both over tor and over clearnet. The tor front-end exists on its own server, but it connects to the mander server. So, the server that hosts the front-end via Tor will see the exit node connecting to it, and then the mander server gets the requests via that Tor server. Ultimately some bandwidth is used for both servers because the data travels from mander, to the tor front-end, and then to the exit node. There is also another server that hosts and serves the images.

    What I see is not a bandwidth problem, though. It seems like the database queries are the bottleneck. There is a limited number of connections to the database, and some of the queries are complex and use a lot of CPU. It is the intense searching through the database what appears to throttle the website.









  • I do have a wall with similar boxes. From the image, I am not sure if they are the same size. I just measured one of my small drawers and it is 14 cm x 5.5 cm x 5 cm. Since I have many different tiny components, I quickly ran out of space when I tried to give each component its own drawer.

    But I think that I might be able to do a better job with these if I take everything out and start organizing again. I set the rules for how to place things before I started buying SMD components, and many of the through-hole components I can combine without problem. An improvement would be if I can find something like this but with many more and much smaller boxes.