• 0 Posts
  • 42 Comments
Joined 1 year ago
cake
Cake day: July 23rd, 2025

help-circle
    1. Why not both? Packaging multiple releases, documenting, and support is lessened with a single release. Officially supporting more ways to install is extra time and effort that is considerably worse with PHP than applications written in most (maybe all?) other popular languages due to the variety of ways people can configure PHP and how the web server executes it is huge and trying to support all of that is considerable. Even if you just narrow down to a single http server, there’s a lot of variations just how the http server executes the scripts and that’s ignoring the PHP/PHP extension level differences. I can’t think of any popular languages that are worse or even in the same ballpark as PHP on execution environment inconsistencies.

    2. The existence of the docker release doesn’t prevent you from running it outside of docker and the Dockerfile/image serves as a reference implementation. It provides you the exact steps and working configuration to deploy it outside of docker.

    Consider a PHP application with install instructions, you follow them and it doesn’t work due to some non obvious configuration difference. With the docker image you have a reference of what should work and can use that to narrow down what is different between your PHP install/configuration and a working system.

    If you’ve not run in to these kinds of situations, consider yourself lucky. It was a nightmare back in early 7.x releases and older.


  • Years ago I’d have one PHP app that required version X of PHP and another that required version Y and my distro often only had one of them (or you couldn’t install both simultaneously), so I’d have to either compile myself (or later use a 3rd party repo). All solvable of course, but then throw in MySQL version requirements and PHP extensions and it’s just extra crap that containers just take care of for you. I’ve had this kind of inter app requirements conflicts with stuff other than PHP, but I’ve had by far more of it with PHP. For a while I used FreeBSD jails to help, but jails was kind of a pain. I enthusiastically embraced docker for PHP stuff early on.

    A benefit for application developers, particularly PHP is there’s a lot of differences between distros and how people install and configure PHP. Even like which PHP extensions are available and their settings. Other languages things tend to be more consistent at the system level and customizations are app are usually application level (contrast with PHP extensions and system level configurations). It really helps reduce support issues due to distro/user differences if a developer just provides a working dockerfile as a reference implementation and in my experience this is far more likely with PHP than other languages. I realize this is mostly applicable outside of PHP, but I actually personally see more benefit with PHP based on my past experiences.


  • While most (maybe all?) TVs actively prevent this, there have ben security flaws that allow you to gain root and go from there. A few years ago I saw my TV+firmware combo was rootable, but newer firmwares patch it. My point is that while you probably can’t just install on your TV model, there may be a security flaw that allows for root access that can be used. It’s also possible that it’s not rootable now, but someone will find a way to jail break in the future. No one can really offer specific guidance without knowing the model and firmware version as whether it’s possible is most likley going to depend on both.

    Example of one that worked for my TV (and other older LGs): https://github.com/throwaway96/dejavuln-autoroot It worked by exploiting a bug in the LG media player (I don’t know more specifics).




  • There’s fetchmail and some other options to move mail from one IMAP sever to another. This can be used to sort of hybrid self host. Gmail would receive your inbound mail, but it would be moved to your self hosted IMAP server, freeing up space on gmail. You’d point your mail client to your server. You could still use gmail for SMTP.

    As far as actually self hosting IMAP, you can have multiple receiving servers set up with different priorities (via DNS MX record). Even with just 1, the normal practice is for a sending mailserver to retry for a few days, so you’re unlikely to lose mail with normal self hosting down time (although I guess this can vary a lot for some).



  • I can reply yo emails. It’s what jaybone said – I use a 3rd party outbound (SMTP).

    I use Thunderbird as my mail client. In there you can define multiple IMAP/pop accounts (inbound) and multiple SMTP (outbound). So when I click reply, the SMTP I have set for that email address is a 3rd party service that sends emails using my domain.

    This does have a privacy implication, so whether that’s appropriate for you is for you to decide. The 3rd party can read and save a copy of your outbound email inclusive of any content included with it (like the email you’re replying to if you include it).


  • I’ve run a mail server since the late 90s. I gave up running my own outbound years ago. Whether it gets received is too inconsistent. Primarily, make sure the IP you use isn’t on any spam lists. If it is, get a new IP or try to submit appeals. Make sure you have the standard anti spam/authenticity measures implemented (they’re listed in the OP).

    These are the minimum. Years ago it was enough to have reasonable delivery. Unfortunately these aren’t that helpful anymore because spammers also set them up (often with seemingly randomly generated domain names). I assume because not having them was a fairly strong signal for being a spammer, so now they also set them up, which also means there’s not really any configuration / setup you can do to seem legitimate (aside from mail volume and the content itself which will be analyzed).

    Anyway running your own SMTP itself is easy. The problem is getting your mail to the inbox or at least spam/junk folder (your mail may get blackholed and not even show up in spam). At least when you get a rejection, you know something is wrong, but many times the receiving server will indicate a success code and simply not deliver it to the user (not even to their spam).




  • Lee@retrolemmy.comto3DPrinting@lemmy.world•What 3D printer should I buy?
    link
    fedilink
    English
    arrow-up
    3
    arrow-down
    1
    ·
    4 months ago

    That mindset is part of why I bought a Prusa originally, but felt betrayed by the MMU2S. That was an expensive and crap product that they never fixed. They basically stole from their customers with that one and I wish the community wouldn’t let them get away with it without them making it right, which at this point would be difficult to do.


  • Lee@retrolemmy.comto3DPrinting@lemmy.world•What 3D printer should I buy?
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    4 months ago

    I don’t know current best options, but last I was looking, the Voron design was where I was leaning. I’d suggest avoiding companies that violate open source licenses.

    I used to be a Prusa evangelist, but I don’t forgive them for the MMU2S. Huge amount of people never could get it to work. I’m curious as to the actual percentage working. I couldn’t ever get it to work even with multiple complete rebuilds. That product should have been recalled or a free fix offered. Years later they released a new version that supposedly fixed the issues and you still had to pay to upgrade to it. Discounted if they had a support record for you. If not, full price.

    From time to time I see a new Prusa printer and think “that looks good, I should buy it”, and then remember the insane amount of time I wasted trying to get the MMU2S to work. Never buying Prusa again until they provide me the working MMU I paid for at no additional cost. As there’s basically zero chance of that, my boycott continues and I suggest not supporting a company that fucked over their customers with an expensive poorly designed product that they then want them to pay to fix.



  • Please actually compare the certificate when connecting to your server directly (bypassing Cloudflare) and connecting via Cloudflare. An easy way to do this is with openssl CLI:

    openssl s_client -servername your-domain-here.org -connect your-ip-here:443 < /dev/null 2>/dev/null | openssl x509 -text -noout
    

    Replace your-domain-here.org with your domain and your-ip-here with your actual server IP, but also do it with the Cloudflare IP.

    The section about the “Full (strict)” / “Full” is referring to how Cloudflare verifies the certificate (or not in the case of Flexible and off) between your origin server and Cloudflare – this is not with respect to the client and Cloudflare. The Custom origin certificates are also with respect to Cloudflare and your server (has no impact on certificate used between the client and Cloudflare). Cloudflare still uses a separate certificate that they have issued to themselves and hold the private key to use for the client.

    If you pay extra for their “Advanced Certificate Manager”, this allows you to upload a custom certificate to be used between the client and Cloudflare, but you have to provide the private key to Cloudflare because they still terminate SSL/TLS at their servers. Even their “Total TLS” service (part of ACM and the word “Total” could be mistaken to be “total” as in from client all the way to your origin server) does not provide E2EE.

    I may be unaware of a newer service offering, but the only way that I’m aware of to get true E2EE is on their Enterprise plan (Keyless TLS). I have a lot of experience with Cloudflare for both personal and Enterprise plan (I was the technical person in charge of the account and configuring and such). Granted, I’ve not been dealing with CF enterprise for a few years now and they may have a new service offering outside of enterprise that I’m not familiar with, but my quick look around still looks like everything aside from Keyless TLS requires either giving them the key (in the case of ACM custom certificates) or they use their own certificate for client <-> Cloudflare. When I did manage the enterprise plan, we actually didn’t use Keyless TLS because we used features that required them to terminate TLS anyway, so I can’t speak to the specifics of it.

    I hope I’m wrong though. I’d love to have true E2EE while still getting the DDoS protection on my personal stuff.




  • I’m in very early stages of a similar project (platform fighter) and a similar issue (I can’t do everything and was having trouble finding reliable people). I don’t know if our project goals are similar enough to warrant working together, but I think it may be worth talking about a possible collaboration. Perhaps even just to make the game multi platform (I’m targeting a retro game console) given that we’ll both need a lot of the same things even if the code itself has a lot of differences. Art, sound, music, story/text, but even things like defining character lists, abilities, and game balance related things is important and duplicative.

    By very early stages I mean I don’t have any game logic written yet. I’m targeting retro game console hardware and so far I’ve mostly been writing code (primarily C) to test my understanding of how the hardware functions/limitations (already found some bugs between emulator and real hardware that impacts some home brew games from other developers), and then writing functions that will become a game building library (I don’t know that it’s right to call it an “engine”). Granted, I’m making a lot of assumptions at this point about what I’ll need in terms of features, but also in terms of how much system resources are safe to allocate to different pieces, so when I get things a little more understood and have some core library functions I’m happy with, I’ll start writing game logic to see what more I need / what changes I need to make.

    I’ve not worked on it for a few months as I’ve been busy with contract work that I was just informed this week is ending prematurely due to budgetary changes. As such, I expect to have time to pick it up again starting next week.


  • Could you explain more? Is this just an experiment to see if you can line up and fuse 2 separately printed objects? Are the 2 parts different materials? I feel like I’m misunderstanding.

    What I think you’ve done is print 1 object in TPU and then print a 2nd object, also in TPU, close enough to the 1st object such they fuse. Maybe your future plans would help me understand. I’m interested in learning about different techniques.

    I had considered doing something like object fusing to create foldable objects, like print the first couple layers in TPU (for both objects as well as a connecting piece between them) and then print 2 separate objects on top of the TPU base – think like a foldable phone case where rather than use a normal hinge, it would be an edge in TPU and the rest is PLA/PETG/whatever. Reason to do the whole base in TPU is that I thought just printing the part that connects the other 2 parts in TPU wouldn’t fuse well enough and would separate with use. I’ve not actually done this.