• 0 Posts
  • 7 Comments
Joined 2 months ago
cake
Cake day: March 10th, 2025

help-circle
  • And then you critize the government, get a sham trial and are marked for your crime as some kind of “garbage person” without rights. Afterwards, execution or locking away and maybe throw in some torture for the fun of it. This is reality already. It just hasn’t been done to you.

    You can feel about it however you want, I may even feel the same with some people, but as an adult, we have to use logic.

    The point is, there must never be an official group of people without rights you can just “get rid of” im some way. This limit is not for the punished, it exists to shield the innocent.



  • These are the occasions I wish death penalty was a thing, especially for those cases where the idiots have been caught in the act - there are better things to do with my tax money than making sure they have a place to live in and some nice good meals to go with it.

    I do understand how you feel about that and I do kinda feel the same, BUT … you always have to assure that every last person has rights and gets acceptable treatment, even the ones who seemingly have no soul. Because if there’s ever a category of people without rights, any government would have an easy way to get rid of eveyone critizing them.





  • Set OPNSense default policy

    As far as I remember, OPNSense has a default policy rule of “deny all incoming, allow all outgoing”. If not, this should be one of the first steps to take.

    Get your own VPN

    If you can, you could use your own VPN service. I run a VPS for 6 € / month. If you can get your hands on something like this and install an openvpn server, you could always use that VPN for every connection.

    So even if an attacker highjacks your connection somehow, he would only be able to see encrypted content and all content will be encrypted by a server you own and can verify / trust. You could also integrate this VPN into your OPNSense, so you’ll be connected as soon as OPNSense starts up and has internet.

    Regarding MITM attacks

    Please someone correct me if I am wrong, but MITM attacks should generally be impossible when connecting to SSL backed connections, right?

    These certificates (or rather the certificate authority the HTTPS certificates have been issued by) are generally trusted by your own operating system. Therefore, if someone wanted to highjack your connection without you getting some kind of certificate error, he would have needed to get his hands on a certificate issued by a worldwide trusted certificate authority and the address name matching the certificate.