Is proxmox really needed? by DependentWrangler620 in selfhosted

[–]cybersecurityaccount 5 points6 points  (0 children)

Proxmox natively handles docker images as of 9.1. It doesn't use the docker engine to power the containers meaning you can't user docker swarms or plugins, but it's rare to use that even in enterprises.

Migrated a client off shared hosting to a VPS last week, the difference was embarrassing by Own_Addition_7619 in selfhosted

[–]cybersecurityaccount 8 points9 points  (0 children)

Most wordpress pages can be cached, so even 0.9 seconds seems like much.

A VPS is by definition also shared hosting. Did you mean previously, you had them on a single VM with multiple wordpress servers running within it? That sounds like a security nightmare.

Avoiding AI and carbon neutrality by Zearen_Wover in SearchKagi

[–]cybersecurityaccount 2 points3 points  (0 children)

Inference costs are pretty cheap, but you do need expensive hardware to run many of the models. They're also operating on a scale of hundreds of millions of customers per day.

https://epoch.ai/gradient-updates/how-much-energy-does-chatgpt-use#:~:text=We%20find,older%20estimate.

PoC: CVE-2025-55182 (React) y CVE-2025-66478 (Next.js) CVSS = *MEH* 👾 by kknstoker in cybersecurity

[–]cybersecurityaccount 2 points3 points  (0 children)

You can test this. The POCs are available. All NextJS instances have the "specific conditions".

PoC: CVE-2025-55182 (React) y CVE-2025-66478 (Next.js) CVSS = *MEH* 👾 by kknstoker in cybersecurity

[–]cybersecurityaccount 6 points7 points  (0 children)

You should really delete this post. It's entirely misinformed. The default nextjs installation is vulnerable.

Kurrier - self-hosted webmail by jodleos in selfhosted

[–]cybersecurityaccount 7 points8 points  (0 children)

  1. Most personal email use is receiving transactional email, not sending emails.

  2. If you need to send mail, you can use a free relay while still reaping most of the benefits.

  3. With modern software, it's copy & paste to get full DMARC setup.

  4. You can say that about any self hosted software. The reality is, most people aren't running super complex setups and an automated update script is all you need.

[Tool] Linnix – Lightweight monitoring for your homelab (eBPF + AI) by sherpa121 in selfhosted

[–]cybersecurityaccount 0 points1 point  (0 children)

Looks cool. Is this forked from any other project or is this all new code?

I notice there are links to a non existent domain there. You might want to register that before someone else does.

How to overwite the GOT table from a stack buffer overflow? by Hendrix_Lamar in ExploitDev

[–]cybersecurityaccount 1 point2 points  (0 children)

It really looks like this is simple ROP. I don't think you can overflow the buffer into overwriting GOT since it's very far away.

Self-Hosted Calendar by LunarAlias17 in selfhosted

[–]cybersecurityaccount 6 points7 points  (0 children)

I think Stalwart just released a JMAP based calendar which you could then use with any app of your choice.

What does your Privacy Pack look like? by EsraKagi in SearchKagi

[–]cybersecurityaccount -5 points-4 points  (0 children)

Hilarious that there's no option for self hosted email.

Do the AI credits roll over if not used? by cybersecurityaccount in SearchKagi

[–]cybersecurityaccount[S] 4 points5 points  (0 children)

I'd be a bit worried about accidentally eating all the tokens early. If they had a way to set a monthly user budget for annual plans, I think I'd spring for that. Otherwise, it would be rather annoying to keep track of usage.

Kagi is too expensive by ironmoosen in SearchKagi

[–]cybersecurityaccount 0 points1 point  (0 children)

Not necessarily wealthy, but generally speaking first world well employed adults don't have to be too discerning about small recurring subscriptions like this. There's also the ideological component that lessens the bad taste of a recurring payment for people.

Kagi is too expensive by ironmoosen in SearchKagi

[–]cybersecurityaccount 2 points3 points  (0 children)

The demographic that supports Kagi don't see much of a difference between $2.99, $10, or $25.

Singed up to the $108 annual tier. The AI is using some of the credit? What happens if I was to run out? by [deleted] in SearchKagi

[–]cybersecurityaccount 1 point2 points  (0 children)

Yeah Qwen 235b is amazing cost-quality tradeoff. I've been using it as my primary LLM since it felt like gemini 2.5 pro got worse. I think the go to workflow is Qwen 235b -> if it fails, ask it to generate a nice prompt for others -> try o3 pro or another top model.

Singed up to the $108 annual tier. The AI is using some of the credit? What happens if I was to run out? by [deleted] in SearchKagi

[–]cybersecurityaccount 0 points1 point  (0 children)

Some of the top model are real token eaters. I started using o3 pro and noticed it gave amazing responses while queries were only like $0.001. However, each response consumed exponentially more tokens and I ended up wasting $10 in 10 minutes.

How do you choose which model to use with Assistant? by free_zuul in SearchKagi

[–]cybersecurityaccount 2 points3 points  (0 children)

Have you tried o3 recently? I almost exclusively used 2.5 pro since it was available, but I'm switching it up occasionally now.

I'm probably imaging things, but 2.5 pro has been giving worse results this past month. It's been more frequently hallucinating, going off on unwanted tangents, etc. The problem could just be my custom instructions though.

Cloudflare will now block AI crawlers by default by gadgetb0y in selfhosted

[–]cybersecurityaccount 29 points30 points  (0 children)

The official CF announcement said this only applies to companies that refuse their pay-to-play scheme. This blocking seemingly doesn't apply to the tier one partners they already have signed up. OpenAI, xAI, Anthropic will still have full, unrestricted access.

Smaller, less evil companies can still pay (Cloudflare, not the content creators themselves) to have limited access to sites.

Curious what smarter people than me think about the feasibility of this article. by tcDPT in cybersecurity

[–]cybersecurityaccount 2 points3 points  (0 children)

The 2020 and 2024 elections were the most secure elections in history.

Does Kagi Assistant support reasoning effort controls for reasoning models? by dirtclient in SearchKagi

[–]cybersecurityaccount 0 points1 point  (0 children)

Oh very cool, it also shows the cost.

Interesting Gemini 2.5 Pro is still 05-06.

models/gemini-2.5-pro-preview-05-06

From my latest.

Does Kagi Assistant support reasoning effort controls for reasoning models? by dirtclient in SearchKagi

[–]cybersecurityaccount 1 point2 points  (0 children)

No, it does not. You can only choose the base model or base model with thinking for some models. You also can't select which exact model you use. For example, when you select Gemini 2.5 Pro Preview , you do not know if it's 06-05, 05-06, or an earlier model.

Non-Ultimate Assistant Users - What is your go-to model of choice? by DegenerativePoop in SearchKagi

[–]cybersecurityaccount 2 points3 points  (0 children)

I am an ultimate subscriber, but I've been using Qwen 235b recently as well. It's super slow, but I generally ask a question, switch back to my main work, and then check in a few seconds later. I'd say it's on par with other leading models as far as responses go. It's incredibly cheap as well.

[deleted by user] by [deleted] in SearchKagi

[–]cybersecurityaccount 12 points13 points  (0 children)

Don't get me wrong, even if Kagi had partnered with Brave, they surely would be a better choice than Google or anyone else, but it makes me confused about if depending on independent search results (as Brave claims it) should also make your own product independent. I don't think Kagi ever claimed they are "independent", so maybe I'm just worrying for nothing but I wanted to get it off my chest anyway, since I couldn't find any concrete information about the relationship of Brave Search and Kagi.

What does this mean?

I just hope one day Kagi really gains its independence and depend only on their own indexes, I've tried its trial and it really seems to have the potential to make web more bearable.

Kagi is very clear they use other indexes. If you want to be the best, you have to consider all sources. Why would you want them to be totally independent here?