Yep. Firewall, routing, dhcp, dns, everything you’d expect from a gateway device. Plain Debian (or really any distro) can do it all. With a 1gbps bi-directional connection fully saturated it will run at about 10% cpu on my very crappy low power Celeron CPU.
Plus, there’s no web UI full of janky and insecure CGI scripts to exploit, and software updates are forever (well, until x64 is deprecated, so basically forever).
IPtables on Debian because I like my life to be boring and unchanging.
For about a year I was running a full out of band IPS on my network. My core switch was set up with port mirroring to spit out a copy of all traffic on one port so that my Suricata server could analyze it. Then, this was fed into ElasticSearch and a bunch of big data crap looked for anomalies.
It was cool. Basically useless because all it did was complain about the same IP crawler bots as my nginx logs. But fun to setup and ultimately good for my career lol.
It bums me out that the Ontario flag is so bad. It would take like 10 minutes to throw the trillium on the same background as the national flag and have something unique and with less monarchy ick. The current logo is a bit corporate but it would be fine.
https://i.pinimg.com/736x/4c/39/d4/4c39d441f2ff5aec306d9ce7494f2da4--ontario-norman.jpg
When they had a “housing crisis”, the USSR built a shitload of prefab concrete housing, the famous “commieblock” buildings. They were imposing, ugly, and made out of load bearing asbestos, but they succeeded in their goal of transforming an impoverished rural serf society into an urbanized industrial powerhouse. While you can and should criticize the Soviet Union, their housing project of the early/mid 20th century was the singular most successful social project in history.
I’m not saying we need “commieblocks”, but we definitely need high quality mass produced social housing in this country. We will simply never be able to solve the problem by building endless suburbs of timber and rockwoll shacks. It won’t “destroy the real estate market” because loads of people will still want their own homes eventually, but for everybody else it will be a great improvement over what we have now.
My understanding was that it was intended as an “emergency brake” - a circuit breaker that could be tripped in an urgent situation, at the cost of the user’s career. But, that requires a politically literate population that would discourage its use.
So, instead we have strongman premiers using it as a hammer to point their profoundly unpopular policies through, and an apathetic and disengaged voter base willing to look the other way.
I see it as part of the broader erosion of the “checks and balances” we were assured would prevent this type of creeping dismantling of democracy.
Exactly. The line connecting London to Kitchener-Waterloo, two cities of a half-million people, spends most of its length doing 50-60km/h because of the lousy rail lines that have been largely un maintained for forty years. What should be a 45 minute ride ends up being over two hours. We can get so much improvement to our system by just fixing the shit we already have, or had fifty years ago.
There is no benefit from this, other than buying votes from right-wing loonies.
Realistically, this is going to kill a lot of queer kids. There will be an age gap between the trans youth over 16 today, and the ones that come up after this is repealed – Not because they were somehow “converted” but simply because a lot of them won’t live to adulthood because the prospect of living through their teens in the wrong skin, with the wrong name, and wearing the wrong clothes is that torturous. This will kill kids.
Over 60 years the cost of taxes to build and maintain a transit system plus fares is an order of magnitude lower than building highway networks, ownership of personal vehicles, insurance, fuel, and rebuilding the road network after 30 years.
The idea that transit is more expensive was a mind trick by the fossil fuel and automotive industries. We’re penny wise and dollar foolish.
They’re a skilled worker that has memorized the codes for the different types of potatoes, a skill I am unlikely to learn.
We will need to drastically change our zoning rules very soon to keep up. Most sane countries allow all land use other than industrial and agricultural inside cities, and they’re better for it.
Will this be offered to refugees from Syria, Yemen, Sudan, etc?
The solution is a wealth tax. It worked for the first 10,000 years of human civilization, after the 100 year failed experiment of income/sales tax it’s time to go back.
Specifically, it’s 2012-era instagram as a federated app. It’s full of tech nerds, camera guys, birdwatchers, furries, gardening enthusiasts, railfans, and all the other quirky early adopters. It’s absolutely wonderful.
The nuclear power industry is essentially the only one that’s been mandated to be responsible for the cleanup of the entire lifecycle of their product. No other industry has to pay clean up after the mining, refining, use, recycling, long term storage, and disposal. And to be clear, that’s good – every industry should be like that. Nobody should have the “freedom” to dump without repercussions.
I think if the fossil fuel industry also had to shoulder the costs of all their externalities, they would be far less profitable than nuclear power. The entire industry is basically reliant on their ability to dump toxic garbage wherever they want, because if they couldn’t do that, there would be no industry.
Perhaps they should pay teachers enough that they don’t feel the need to take on second jobs.
Some people seem to think that you can rope off a “designated peeing area” in the swimming pool…
We all share one climate – it doesn’t matter where in the world you burn the coal or where the fires break out, we all suffer together. That’s the reality that a lot of people all over the world don’t seem to be willing to understand.
The social contract has failed in Canada. We’ve basically reverted to feudalism (with big TVs & iphones) with barely a whisper. We’re working harder than ever and getting less and less… It’s extremely demoralizing when we realize that all our work is going straight into stock buybacks & real-estate investment funds for the boomers to suck dry, leaving us with no savings, investments, homes, or really anything with value.
This was my setup from about four years ago. Other than moving suricata elsewhere, it’s largely the same. Worth a shot if it’s something you’re into!
https://nbailey.ca/post/linux-firewall-ids/
OpenBSD is also great, I’m just more familiar with the Linux tools. All the required tools are in the base image, and they have a great official guide:
https://www.openbsd.org/faq/pf/example1.html