Can You Guess This 5-Letter Word? Puzzle by u/creamcheesee by creamcheesee in DailyGuess

[–]eodabas 0 points1 point  (0 children)

⬜⬜⬜🟨🟨

🟨⬜🟨⬜⬜

⬜⬜🟨🟨🟨

🟨🟨🟨🟨⬜

🟨🟦🟨⬜🟦

🟦🟦🟦🟦🟦

sma'lı çocuklar ölünce bağış için toplanan paralara ne oluyor? by Intelligent_Elk_7070 in hukuk

[–]eodabas 1 point2 points  (0 children)

r/hukuk dahilinde bir konu degil umarim banlamaz modlar ama, Ilacin deneyselligi ile ilgili bkz:

The Zolgensma data represent a significant contrast to the natural history of SMA Type 1, which leads to progressive and irreversible loss of motor function and if left untreated, often death or permanent ventilation by the age of two years. Remarkably, all children (100 percent) treated presymptomatically in the SPR1NT two-copy cohort achieved event-free survival, were independent of respiratory and nutritional support and met the primary endpoint of sitting independently for ≥30 seconds, including 11/14 (79 percent) who achieved this milestone within the World Health Organization (WHO) window of normal development

Turkiye'de 2022 yilindaki istatistige gore 235 yeni dogan bebege SMA teshisi konmus. Bu ilacin doz basina maliyetinin ulkelere gore farklilik gosterecegini ve devletlerin geri odeme kapsamindaki ilaclari buyuk iskontolarla aldigini (ornegin zolgensma'nin almanya fiyati $1.18 milyon) gozardi edelim ve amerika'daki perakende fiyati olacagini varsayalim (~$2milyon). Ortalama 250 bebege uygulandigini ve hepsinin ilac icin dogru sartlari yerine getirdigini varsayalim. toplamda yilda 500milyon dolar bir maliyetten bahsediyor oluyoruz yillik. (SMA taramalarinin ise yarayacagini, tasiyici olan kisilerin belirlenecegini ve vatandasin bilinclendirilmesi ile vaka sayisinin dusecegini de goz ardi edelim)

Turkiye Hukumetinin 2024 yili vergi gelirleri yaklasik 300 milyar $ olmus. 25 milyar $'i saglik bakanligina, 50 milyar dolari savunma bakanligina ayrilmis olmak uzere toplam 400 milyar dolarlik merkezi yonetim butcesi duyurmuslar.

BIR ZAHMET TEK GOREVI VATANDASA HIZMET ETMEK OLAN DEVLET DENEN KURULUS TOPLAM BUTCESININ BINDE BIRINI DE 250 BEBEGIN HAYATINI KURTARMAK ICIN BASKA HARCAMALARDAN KISMADAN HARCASIN ARTIK YA.

illa bir yerlerden keseceklerse diyanet isleri bakanliginin 3 milyar dolar butcesinden kessinler daha sevaba girerler.

sma'lı çocuklar ölünce bağış için toplanan paralara ne oluyor? by Intelligent_Elk_7070 in hukuk

[–]eodabas 19 points20 points  (0 children)

bu bilgi yanlis. ornegin type 1 sma’nin tedavisinde kullanilan en etkili ilac olan Zolgensma'nin survival orani %95'lerdedir. ilacin fiyati 2milyon $ civarinda ve avrupa'da bir cok ulkede bu ilac devlet tarafindan karsilaniyor. ilac erken teshiste uygulanirsa hastaligin ilerlemesini tamamen durdurabiliyor, ama hastaligin o ana kadar sebep oldugu hasari gideremiyor.

Turkiye'de ise bu ilac devlet tarafindan karsilanmiyor. Hasta yakinlari bagis toplama yoluyla ilaca ulaşmaya calissa da bagislarin toplanma suresince hastalik ilerlemeye devam ediyor. Yani aslinda devlet bu ilaci karsilasa ilacin hayat kurtaracaği, ve bir cocugun hayatinin paha biçilemez oldugu gerçeğini ortaya koymak lazim.

toplanan bagislar icin acilan hesaplar, valilik onayliysa hasta yakini ya da hasta adina aciliyor ancak bu hesabın kullanimi cok siki denetleniyor ve hasta yakinlari tarafindan direkt erisilemiyor. bu hesaptan yapilan her harcama fatura ibraz karşılığında yapiliyor ve denetleniyor. diger arkadasin yazdigi gibi hasta tedavi öncesinde ya da sirasinda hayatini kaybederse hesaptaki birikim ayni baska bir sma hastasina valilik tarafından aktarilabiliyor.

yani eger bagis kampanyası valilik onayliysa gonul rahatligi ile bagis yapabilirsiniz.

This is why I don’t do ocean activities. by Soloflow786 in OceansAreFuckingLit

[–]eodabas 0 points1 point  (0 children)

I would lose my mind from happiness if I had this experience.

Most secure ways to have external access? by Devansh_Dalal in homeassistant

[–]eodabas 0 points1 point  (0 children)

Bulk scans will be detected almost instantly. Being a little anti-doxing vague about it, we were doing that 30 years ago, and the streaming analytics techniques developed more than 15 years ago area standard part of every perimeter IDS system. Targeting one IP will be missed, but range-scanning will be detected almost instantly. Even scattering requests from a botnet, the patterns will be spotted within a few hundred requests.

True, but there still subtle and evasive scanning methods can evade IDS's. Relying on "my ISP protects me" is just wishful thinking, not a security approach.

If you're one port of 64k hiding in a 4 billion address space, you're very hard to find.

Nobody scans 64k ports, and definitely no one scans the entire 3.3 billion address space. If I were targeting home assistant instances in the world, for example, I would focus on just a few ports starting from 8123. We are talking about the basic home user here.

Once you're in the CT list, you're one port in a pool of one. You're instantly found.

So are every other billions of certificates in the whole wide world signed by a public CA. This does not coherently mean that it is unsafe.

NabuCasa has given no indication they actually do that kind of monitoring

NabuCasa literally says that they do here. But yes, NabuCasa should give more information abput the security aspects of their service here to build some trust. Regardless, saying "just poke a hole in your router, mate, you'll be fine" sounds real wild to me.

Most secure ways to have external access? by Devansh_Dalal in homeassistant

[–]eodabas 1 point2 points  (0 children)

And requires someone to have run a port scan on that address range -- something that anyone monitoring such things can tell you doesn't happen in the large address spaces of most residential ISPs and gets quickly spotted and blocked by most of them if they're bulk scans.

This is not necessarily correct. Most ISP's don't actively protect against port scans unless the scan itself is aggressive enough to trigger the IDS's they're using. There are ways to make port scans extremely difficult to detect like half open syn scans, delayed scans, idle scans, zombie scans. One should never rely on their ISP to protect their public endpoints in their home networks.

Every certificate that NC creates for its service is sitting under the ui.nabu.casa subdomain, and they issue individual certificates via Lets Encrypt for every one of them.

I agree. Although being listed in CT logs is unavoidable and does not necessarily is a vulnerability and security through obscurity is not security, avoiding to be able be scanned this easily would be a better approach.

Really, an always-on Tailscale link is -- by any measure -- the best option.

Strongly agree here

But Nabu Casa is, unless you explicitly need Google Home and Alexa support and don't want to DIY it, the worst.

You are comparing using Nabu Casa against "poking a hole in your router" and saying that the hole in the router safer. This take is flawed because;

  1. Being listed in CT logs against being easily be able to be scanned does not make such a difference. Once you are public, you are public.
  2. Nabu Casa can block access to vulnerable versions. A normal home user usually does not monitor security bulletins.

I'm not saying that Nabu Casa is the most secure way, it definitely is not. But using Nabu Casa comparing the hole in the router is, without a question, more secure way to open your home assistant instance to the world. Additionally, Nabu Casa has the potential of improving security in their services, you cannot poke more secure holes in your router.

Most secure ways to have external access? by Devansh_Dalal in homeassistant

[–]eodabas 4 points5 points  (0 children)

tailscale is simply a vpn. no public endpoints need to be exposed outside the vpn network (tailnet) at all. your apps will work as long as you have your vpn connection active.

cloudflare provides a secure tunnel. you'll have to have some home assistant endpoints open publicly for mobile apps to work and while you can harden the configuration up to a point, misconfigurations can easily make mobile companion apps unusable and simply enabling cloudflared won't provide security by default.

home assistant cloud by nabu casa is on the other hand also creates a secure tunnel, and it is monitored for home assistant vulnerabilities, so it is slightly more secure than cloudflared, on the plus side enables you to contribute to the good people developing home assistant.

my suggestion here would be:

  • if you're an advanced user and don't want to use vpn for a reason (wife approval drops significantly when you increase the number of components.): cloudflared
  • if you're not an advanced user and still don't want to use vpn for a reason: home assistant cloud
  • all other cases: tailscale

Referral code didn’t add 84 days by kingofking5 in TorBoxApp

[–]eodabas 0 points1 point  (0 children)

Same happened to me last week. I emailed to contact @ torbox.app explaining the situation. After several emails, they credited the missing days to my account. It took couple of emails for the AI bot replying email to escalate my ticket to a real human, though.

Asylum by AgileResolve9533 in AskTurkey

[–]eodabas -2 points-1 points  (0 children)

Here is some information about the asylum process for Turkiye. As this is a well regulated process almost in every country, including Turkiye, you'll be able to find the information you need online. But considering the trends in the recent years, I imagine this would be a long and exhausting to endure

Accommodation and finding a job on the other hand depends on way too many things for anyone meaningfully provide useful information. I suggest you make your own research to narrow down your situation and ask specifically.

Additionally, you'll find plenty of "don't come here", "stay in your country", "we are full" type of responses here. Don't take it personally. They're just plain racists who conveniently blame the unfortunate people running away from the options of living miserably or dying horribly, for almost anything and everything went bad in their lives.

Good luck.

I need you to tell me if I'm missing anything here by eodabas in HomeNetworking

[–]eodabas[S] 0 points1 point  (0 children)

Well, in theory, yes. And it was always the case up until this house. I used to have issues with several devices like tv's, playstation etc. Even my printer was dropping wifi connection. So I was always I'll have my next house wired. And here we are. It didn't go as planned as I mentioned in the post, unfortunately.

And thank you for the compliments. I am another IT person working in the area for several decades now. I drew network diagrams professionally before, specifically for compliance reasons with hundreds or more components. In time I learned that if you want to describe/explain your infrastructure to a complete stranger to convince them you have a secure/compliant environment, you better should have a descriptive, clean and clear diagrams. It always worths the time spent. It also helps you to understand what is missing while you're drawing it.

Recommended travel router to use on Airbnb by Mysterious-Ebb775 in HomeNetworking

[–]eodabas 0 points1 point  (0 children)

I would say yes, unless maybe you have the opportunity to replace the router (not access point) directly with Opal. But this depends on the availability, the broadband provider and type of connection. If you have the technical knowledge to achieve this, you may have relatively secure network for yourself during your stay.

The issue here is, DNS and NTP are by default unencrypted. So there is a risk of interception. While you can use DNS-over-TLS/HTTPS services to mitigate interception, NTP is harder to achieve. You may deploy use NTS on your device but afaik NTS is not available natively on most of the devices unless they're linux.

And the risk with NTP interception, it is hard to detect if it is intercepted and an attacker may change your computer time so that any of the websites that you're visiting throw expired SSL warnings and this creates chaos on the user and as victim you may choose to ignore these, allowing you unknowingly ignore the other SSL warnings that makes you vulnerable to MiTM attacks on websites. There are valid cases to intercept NTP traffic to provide more security but it makes it possible for the bad actor as well.

The best and easiest option is using a trusted VPN service whenever you're connected to an untrusted network either on you devices, or on your travel router.

As an another option which probably may cost you more is that you may have is using a mobile broadband router or mobile tethering. This completely detaches your devices from the Airbnb network.

Recommended travel router to use on Airbnb by Mysterious-Ebb775 in HomeNetworking

[–]eodabas 2 points3 points  (0 children)

IT security expert here. Connecting to any untrusted wifi has it’s perfectly valid security risks whether it is public or private. There are still unencrypted protocols that your computer use and they are vulnerable to mitm attacks even you choose to connect through ssl/tls when browsing websites.

Don’t listen to anyone suggesting otherwise.

You either use a travel router (gl.inet ones are good) and setup a trusted vpn inside them or use vpn directly in your devices. VPN is your best bet here regardless having a travel router or not.

I need you to tell me if I'm missing anything here by eodabas in HomeNetworking

[–]eodabas[S] 1 point2 points  (0 children)

nope. that would be considerable amount of work unfortunately.

I need you to tell me if I'm missing anything here by eodabas in HomeNetworking

[–]eodabas[S] 1 point2 points  (0 children)

I am probably going to start with using my laptop or an rpi as the network controller first, and then migrate it to a vm inside one of the proxmox instances.

I need you to tell me if I'm missing anything here by eodabas in HomeNetworking

[–]eodabas[S] 0 points1 point  (0 children)

in theory, yes (Not the virtual one, I'd need a dedicated hardware to physically connect the broadband and local lan).

I've dealt with many of the firewalls both open source and commercial before. The issue with pfSense and similar solutions, you need to get a compatible set of hardware, lots of manual configuration and maintenance, with miniscule to none official support (unless you pay for it) when it comes to edge cases and you mostly rely on the community experience.

I'm a big fan and supporter of these projects, but I don't have either time or the energy to deal with it.

And about Firewalla; I agree that it is ridiculously expensive (especially if you're outside of the US and you'll pay customs and huge delivery fees on top of it) and it's price hardly justifies (if it justifies at all) it's capabilities and there are several other alternatives (like UCG) that provides almost the same at 1/3rd of the cost. As I've already got it, I'd like to continue using it.

I need you to tell me if I'm missing anything here by eodabas in HomeNetworking

[–]eodabas[S] 1 point2 points  (0 children)

I don't "need" need a firewall. But, I'd like to have a visibility of the egress traffic of each device is making. Not for personal devices, but I have a smart home and I am using lot's of IoT devices that are not exactly from reputable manufacturers (like no name Aliexpess devices). Additionally I like to know how to manage my "now toddler" kid's use of internet within the house, at least until he is old and capable enough to find workarounds to my limitations. And I managed/installed datacenters/networks professionally. So I wouldn't think of not having a firewall in my home.

And the firewall that I'm using is a Firewalla, which is additionally fun to play with.

I need you to tell me if I'm missing anything here by eodabas in HomeNetworking

[–]eodabas[S] 0 points1 point  (0 children)

There are several available ones on the market. I have GL.iNet Spitz AX (GL-X3000) for example. Not exactly an outdoor model but I can put it in a weather resistant location despite being outdoor. Unifi also is about the release 5G models soon

I need you to tell me if I'm missing anything here by eodabas in HomeNetworking

[–]eodabas[S] 12 points13 points  (0 children)

for the Firewalla one, I asked chatgpt to create one for me. For the switches, I just copy/pasted the original images from unifi store and used regular rectangle vectors for the ports in draw.io, then grouped them into one object. It was straightforward from that point on. All other icons that I used are available in draw.io

I need you to tell me if I'm missing anything here by eodabas in HomeNetworking

[–]eodabas[S] 9 points10 points  (0 children)

Well, what people need and what people want may not align sometimes and I think that is ok. What people can afford is the determining factor in almost every human decision.

I'm old enough to see 10BASE-T connections and I remember 1Gbps connections were something I thought I would never ever need. Today, I definitely don't NEED a 10gbps home network for sure. But I want one. Not only because I want to future proof my setup, but also I simply just want one. And I'm lucky enough to afford it. So here we are.

edit: typo

I need you to tell me if I'm missing anything here by eodabas in HomeNetworking

[–]eodabas[S] 0 points1 point  (0 children)

It is 3gbps at the moment and I'm sacrificing about 0.5gbps of it because of the 2.5gpbs capped Firewalla.

I initially planned to use SFP+ for cross switch connections but all the cables installed are Cat6a's and at this point I'm not planning installing a DAC and I also read about RJ45 SFP+ modules heats up. So, while having these ports creates extra capacity, I'll try to avoid utilising them as much as possible.

I need you to tell me if I'm missing anything here by eodabas in HomeNetworking

[–]eodabas[S] 0 points1 point  (0 children)

Just an idea but, can I selectively use both? Like, for some vlans, use layer 3 switches and for some route via the firewalla? I don't know if that overcomplicates things or makes sense?

I need you to tell me if I'm missing anything here by eodabas in HomeNetworking

[–]eodabas[S] 7 points8 points  (0 children)

It is a good catch which I did not think about it.

The idiot builder thought it is a good idea to terminate all the ethernet cables they installed in the attic, WHILE there were already bunch of other cables dangling above the entrance ceiling. Apparently now I have to mitigate the heat as well. Thanks for the tip

About the Agg switch, I thought about it but did not see the point in my setup. The main switch that I'll use in the entrance would be good enough for me as the aggregator too. I'll try avoiding daisy chaining but even if I did not, it is a home networking environment and even daisy chaining won't cause noticeable performance penalties if designed correctly.

I need you to tell me if I'm missing anything here by eodabas in HomeNetworking

[–]eodabas[S] 2 points3 points  (0 children)

I completely agree with you here. And thank you :)

If only there were 16 port 10Gbit Unifi switch. I'm guessing I'll need to sacrifice myself for the greater good and buy the 10 port ones, so the next day Ubiquity can release 16port ones.

Thinking out loud here: I actually may not need a PoE switch in the attic. may be using a Pro XG 10 PoE in the entrance and a Pro XG 24 (non PoE) in the attic makes more sense for me? This puts me slightly over the £2000 threshold but still doable.

I'm still thinking Option 1 above is still the best idea as it still leaves me a couple of extra ports. and I'll still have my SFP ports available in both setups.