[-] [email protected] 3 points 8 hours ago

Just be aware of the risks involved with running your own CA.

You’re adding a root certificate to your systems that will effectively accept any certificate issued with your CA’s key. If your PK gets stolen somehow and you don’t notice it, someone might be issuing certificates that are valid for those machines. Also real CA’s also have ways to revoke certificates that are checked by browsers (OCSP and CRLs), they may employ other techniques such as cross signing and chains of trust. All those make it so a compromised certificate is revoked and not trusted by anyone after the fact.

For what's worth, LetsEncrypt with DNS-01 challenge is way easier to deploy and maintain in your internal hosts than adding a CA and dealing with all the devices that might not like custom CAs. Also more secure.

[-] [email protected] 8 points 8 hours ago

Yes, LetsEncrypt with DNS-01 challenge is the easiest way to go. Be it a single wildcard for all hosts or not.

Running a CA is cool however, just be aware of the risks involved with running your own CA.

You’re adding a root certificate to your systems that will effectively accept any certificate issued with your CA’s key. If your PK gets stolen somehow and you don’t notice it, someone might be issuing certificates that are valid for those machines. Also real CA’s also have ways to revoke certificates that are checked by browsers (OCSP and CRLs), they may employ other techniques such as cross signing and chains of trust. All those make it so a compromised certificate is revoked and not trusted by anyone after the fact.

[-] [email protected] 0 points 20 hours ago

I want the WAN coming in from the router from the Pi’s Ethernet port, and the LAN coming out as Wi-Fi. I may also stick an additional Ethernet adapter to it in the future.

Can you try to explain this a bit more?

[-] [email protected] -2 points 1 day ago

Anything with GNOME is visually appealing but unfortunately the usability is pure garbage. KDE is the exact opposite and Xfce is quick but sits on an awkward place.

[-] [email protected] 11 points 1 day ago

Two things I've noticed about American politics: first, the most left-wing American politician would be seen as borderline far right in Europe. Second, in the US there's no left, because left would imply socialism that eventually lead to communism and that goes against the ideia of America, the American dream, the constitution etc. The entire country was built and maintained on the ideia of being against any form of communism.

[-] [email protected] -5 points 1 day ago

Define "negative way"... GNOME changes in negative ways in a weekly basis so... Notification DDoS? :P

[-] [email protected] 3 points 2 days ago

No, Matrix is just a privacy disaster that is run by a for profit company.

[-] [email protected] 1 points 2 days ago

Link wasn't there when the original post was made.

[-] [email protected] 2 points 2 days ago

You can run full GUI apps inside LXC containers and have X11 deal with the rest. Guides here and here.

[-] [email protected] 4 points 2 days ago* (last edited 2 days ago)

Well, it's a container, in most situations you would be running as root because the root inside the container is an unprivileged user outside it. So in effect the root inside the container will only be able to act as root inside that container and nowhere else. Most people simply do it that way and don't bother with it.

If you really want there are ways to specify the user... but again there's little to no point there.

lxc exec container-name --user 1000 bash 
lxc exec container-name -- su --shell /bin/bash --login user-name

For your convenience you can alias that in your host's ~/.bashrc with something like:

lxcbash() { lxc exec "$1" -- sudo --login --user "$2"; }

And then run like:

lxcbash container-name user-name
[-] [email protected] 4 points 2 days ago

When your device requests an IP it sends over a significant amount of data.

Like...?

-94
submitted 1 week ago* (last edited 1 week ago) by [email protected] to c/[email protected]

New GNOME dialog on the right:

Apple's dialog:

They say GNOME isn't a copy of macOS but with time it has been getting really close. I don't think this is a bad thing however they should just admit it and then put some real effort into cloning macOS instead of the crap they're making right now.

Here's the thing: Apple's design you'll find that they carefully included an extra margin between the "Don't Save" and "Cancel" buttons. This avoid accidental clicks on the wrong button so that people don't lose their work when they just want to click "Cancel".

So much for the GNOME, vision and their expert usability team :P

13
submitted 1 week ago by [email protected] to c/[email protected]

Hi,

Is there anyone using Amcrest IP4M-1041B with Home Assistant? I've a few questions about software and integration.

  1. From what I hear, this camera can be setup 100% offline, connected via cable to any computer and by using a built in WebUI the camera has, is this true?

  2. It offers pan, tilt or zoom. Does it work really good with HA? Can it be operated without any Amcrest software / internet connection?

  3. The features above allow you to set preset locations, can that be done on HA / WebUI / without the Amcrest app as well?

  4. Does it really operate all features offline and is it reliable? Eg. motion detection works as expected / doesn't miss events?

  5. What's your overall experience with the camera? Does it compare to let's say a TP-Link tapo?

Thank you.

44
submitted 2 months ago* (last edited 2 months ago) by [email protected] to c/[email protected]

cross-posted from: https://lemmy.world/post/14398634

Unfortunately I was proven to be right about Riley Testut. He's yet another greedy person barely batter than Apple. After bitching to Apple to remove GBA4iOS from the App Store he's now leveraging Delta to force people into his AltStore.

Delta has finally made its way to the App Store. Additionally, the Delta developer has also published their alternative marketplace, AltStore, in the EU today.

If you're in the EU you'll only be able to get Delta on the AltStore and that requires:

This is complete bullshit he could've just launched Delta on the App Store in Europe as well but he decided not to.

Thanks Riley Testut for being a dick to the people that actually forced Apple into allowing alternative app stores in the first place.


Github issue related to this dick move: https://github.com/rileytestut/Delta/issues/292

4
submitted 2 months ago* (last edited 2 months ago) by [email protected] to c/[email protected]

cross-posted from: https://lemmy.world/post/14398634

Unfortunately I was proven to be right about Riley Testut. He's yet another greedy person barely batter than Apple. After bitching to Apple to remove GBA4iOS from the App Store he's now leveraging Delta to force people into his AltStore.

Delta has finally made its way to the App Store. Additionally, the Delta developer has also published their alternative marketplace, AltStore, in the EU today.

If you're in the EU you'll only be able to get Delta on the AltStore and that requires:

This is complete bullshit he could've just launched Delta on the App Store in Europe as well but he decided not to.

Thanks Riley Testut for being a dick to the people that actually forced Apple into allowing alternative app stores in the first place.


Github issue related to this dick move: https://github.com/rileytestut/Delta/issues/292

-6
submitted 2 months ago* (last edited 2 months ago) by [email protected] to c/[email protected]

Unfortunately I was proven to be right about Riley Testut. He's yet another greedy person barely batter than Apple. After removed to Apple to remove GBA4iOS from the App Store he's now leveraging Delta to force people into his AltStore.

Delta has finally made its way to the App Store. Additionally, the Delta developer has also published their alternative marketplace, AltStore, in the EU today.

If you're in the EU you'll only be able to get Delta on the AltStore and that requires:

This is complete bullshit he could've just launched Delta on the App Store in Europe as well but he decided not to.

Thanks Riley Testut for being a dick to the people that actually forced Apple into allowing alternative app stores in the first place.


Github issue related to this dick move: https://github.com/rileytestut/Delta/issues/292

152
submitted 3 months ago by [email protected] to c/[email protected]

Here's my take:

The domain aftermarket has a big problem... it exists. This market shouldn't ever be allowed to exist in the first place. ICANN should've blocked this bullshit a long time ago and forced registrars to just let domains expire and free the space. Also add a few provisions about unused domain names and about selling them.

22
submitted 3 months ago* (last edited 3 months ago) by [email protected] to c/[email protected]

Hello,

So I have a Motorola SM56 USB Data Fax Modem (aka Apple USB Modem for some people) and according to information online this modem supports V.92, Caller ID, wake-on-ring and most importantly telephone answering (V.253).

At a place I happen to have an old telephone analog line that gets calls and unfortunately I can't get rid of. Any ideias / links / software on how can I use the modem + a low end box / ARM SBC to "digitize" the phone line into a generic SIP / VOIP that I can then connect to using MicroSIP on another computer?

Thank you.


Update on this:

I just tried the modem under Windows with a few programs such as Phone Dialer Pro and the built in dialer.exe and while the modem can detect incoming phone calls and place calls I can't pass the audio back to the operating system / phone software.

I did some research about the SM65 and it seems like it was designed to have an headset directly attached to it like on those PCI cards that also use it:

The built in COM port of the modems seems to be only usable to control the modem via AT commands and can't be used to pass audio form and to the system.

12
submitted 5 months ago* (last edited 5 months ago) by [email protected] to c/[email protected]

Hello,

My IoT/Home Automation needs are centered around custom built ESPHome devices and I currently have them all connected to a HA instance and things work fine.

Now, I like HA's interface and all the sugar candy, however I don't like the massive amounts of resources it requires and the fact that the storage usage keeps growing and it is essentially a huge, albeit successful, docker clusterfuck.

Is there any alternative dashboard that just does this:

  1. Specifically made for ESPHome devices - no other devices required;
  2. Single daemon or something PHP/Python/Node that you can setup manually with a few systemd units;
  3. Connects to the ESPHome devices, logs the data and shows a dashboard with it;
  4. Runs offline, doesn't go into 24234 GitHub repositories all the time and whatnot.

Obviously that I'm expecting more manual configuration, I'm okay with having to edit a config file somewhere to add a device, change the dashboard layout etc. I also don't need the ESPHome part that builds and deploys configurations to devices as I can do that locally on my computer.

Thank you.

23
submitted 5 months ago by [email protected] to c/[email protected]

cross-posted from: https://lemmy.world/post/11162262

Hey,

For all of you that are running proper setups and use nftables to protect your servers be aware that pvxe/nftables-geoip now has the ability to generate IP lists by country.

This can be used to, for instance, drop all traffic from specific countries or the opposite, drop everything except for your own country.

https://github.com/pvxe/nftables-geoip/commit/c137151ebc05f4562c56e6802761e0a93ed107a2

Here's how you can block / track traffic from certain countries:

Previously you had to load the entire geoip DB containing multiple GB and would end up using a LOT of RAM. Those guides aren't yet updated to use the country specific files but it's just about changing the include line to whatever you've generated with pvxe/nftables-geoip.

34
submitted 5 months ago by [email protected] to c/[email protected]

Hey,

For all of you that are running proper setups and use nftables to protect your servers be aware that pvxe/nftables-geoip now has the ability to generate IP lists by country.

This can be used to, for instance, drop all traffic from specific countries or the opposite, drop everything except for your own country.

https://github.com/pvxe/nftables-geoip/commit/c137151ebc05f4562c56e6802761e0a93ed107a2

Here's how you can block / track traffic from certain countries:

Previously you had to load the entire geoip DB containing multiple GB and would end up using a LOT of RAM. Those guides aren't yet updated to use the country specific files but it's just about changing the include line to whatever you've generated with pvxe/nftables-geoip.

161
submitted 6 months ago* (last edited 6 months ago) by [email protected] to c/[email protected]

Hey,

I found this game I used to play a very long time ago and I wanted to experience it again. Unfortunately I wasn't able to run it in Windows 10 / Windows XP SP3 VM because it would lag on modern hardware.

Here is what you need to do in order to get the game running:

  1. Search for "Midtown Madness 2 (Europe) (Rerelease)" on TPB and download it
  2. Load the disk with WinCDEmu or other solution
  3. Install the game (don't launch it)
  4. Enable DirectPlay on Windows
  5. Copy Crack\midtown2.exe to the gamefolder
  6. Download dgVoodoo2 from http://dege.freeweb.hu/dgVoodoo2/dgVoodoo2/
  7. Copy dgVoodoo2.exe to the game folder
  8. Copy all files inside MS\x86 to the game folder as well
  9. Run dgVoodoo2.exe as admin and set the following:
  • Click the button .\ to create config file to MM directory
  • In "General" > "Output API" select "Direct3D 11 MS WARP (software)"
  • Go to "DirectX" tab and change the VRAM to 128MB
  • Click "Apply" > "OK" to exit.
  1. Launch the game > Options > Graphics > select from Display drop down menu, "dgVoodoo DirectX Wrapper" > "Hardware (3D video card with T&L) from the Renderer drop menu.
  2. Click "Done" and that's it!

Note that whenever you change the resolution it won't apply any changes to the game menu - you'll only see it once you start a race.

Midtown Madness 2 should now run very smoothly under Windows 10, even on Virtual Machines. Enjoy.

24
submitted 7 months ago by [email protected] to c/[email protected]

cross-posted from: https://lemmy.world/post/8834324

I'm looking for an application (windows or maybe web) that can be used to combine images vertically and horizontally. I usually go with PhotoScape (screenshot) to for this but that's not free nor updated anymore. Important features for me are to be able to combine horizontally or vertically, set the number or rows or columns and have the ability to resize the final image.

Thank you.

view more: next ›

TCB13

joined 1 year ago