mike

joined 1 year ago
[–] [email protected] 7 points 1 year ago (2 children)

I figured I could simply upload them on our webserver, so here you go:

[–] [email protected] 6 points 1 year ago

I can't imagine the sound of a room with like 20 pupils, each hammering on such a keyboard.

[–] [email protected] 2 points 1 year ago (4 children)

I'll do that! Question is where to post it. Lemmy doesn't support videos.

 

When 4 IBM Model M keyboards showed up during a cleanup at work (university) and I was asked if I wanted one, I of course said yes!

It's an IBM model M 1394540 from 1992 with the PS2 connector and the detachable cable. The keyboard and cable are in very good condition, even the manufacturing sticker on the back looks pretty good! All keycaps present, all keys work. It just needed "some" cleaning which ended in a 3h long process haha.

It will definitely be my daily driver for the next few weeks. I haven't decided yet if I will use it long term. I'm actually very happy with my modded Keychron Q6. Maybe I'll try some lube on the stabilizers and perhaps a little tape mod.

The best part was that I got to take a second Model M with me, which I will give to a good friend. This one is also in great condition.

It was an incredible day!

 

GDPR Compliance Check

For those who haven't heard of it before, Gumb is

A platform for managing meetings, gatherings, and events for communities of any size. - gump.app/en

I have investigated this app because it is used by a club where I am occasionally active.

Landing Page / Homepage

Fonts: The landing page is using google fonts, so those fonts are loaded (8 requests) from fonts.gstatic.com when opening the website. The first issue here is that google fonts are not listed in the privacy policy at all. Second, by a German court ruling google fonts are not compliant with the GDPR:

The use of external font services cannot be based on Art. 6 § 1 p.1 f GDPR, as the use of the fonts is also possible without having to establish a connection from visitors to external servers. - LG München Az. 3 O 17493/20

Images: Furthermore the website is loading images from firebasestorage.googleapis.com (105 requests). Following the argumentation of the previously mentioned court ruling, using firebase for images could also be considered non-compliant because images could easily be served without having to establish a connection from visitors to external servers.

Youtube Embed: The website includes a youtube iframe (13 requests to www.youtube.com) with an introduction video. While youtube themself offer an iframe option called "Enable privacy-enhanced mode", the Gumb homepage embeds the »normal« iframe that places tracking cookies which again violates the GDPR. The iframe furthermore sends

  • 6 requests to play.google.com/log,
  • 4 requests to https://googleads.g.doubleclick.net
  • 1 request to https://static.doubleclick.net
  • 4 request to https://jnn-pa.googleapis.com

Tracking: The website uses, as stated in their privacy policy, Google Analytics (GA) which results in a request to https://region1.analytics.google.com/g/collect... and https://www.googletagmanager.com. However, writing "we use GA" in the privacy policy is not sufficient. GA requires consent from the website visitor.

There are a few more unnecessary requests, but I think the point is clear.

All of that is happening without any consent from the visitor!

Mobile App

Gumb offers mobile Apps for Android and iOS, of which I only checked the Android version. While I can't say for sure that the app violates the GDPR because it immediately asks for credentials, the Exodus Privacy Report (of the latest version 1.0.84) still looks rather bad:

  • Amazon Analytics
  • Amazon Mobile Analytics
  • Google Analytics
  • Google CrashLytics
  • Google Firebase Analytics
  • Google Tag Manager

Web App

Next to mobile apps, Gumb offers a web app too. Well, what can I say - there are requests to

  • https://fonts.googleapis.com
  • https://www.googletagmanager.com
  • https://region1.analytics.google.com/g/collect...
  • https://www.google.de/ads/...
  • https://stats.g.doubleclick.net/g/collect...
  • https://ipgeolocation.io/

even without being logged in or any given consent.

Conclusion

For a tool from Switzerland with paid subscription plans and the purpose of managing events/meetings etc. it uses a lot of google (tracking) services... Very sad to see as the app looks otherwise really modern and useful. Do today's developers know that applications like Gumb can be implemented without selling their users' soul to google?

[–] [email protected] 1 points 1 year ago

I thought this would be visible with my link. Specifically shared the "show changes" Link but that doesn't seem to work.

 

In case you need a quick laugh, have a look at this CVE report.

For context: quote DVWA Repo:

Damn Vulnerable Web Application (DVWA) is a PHP/MySQL web application that is damn vulnerable. Its main goal is to be an aid for security professionals to test their skills and tools in a legal environment, [...].

[–] [email protected] 1 points 1 year ago (1 children)

That one was really difficult and IMO the solution wasn't the best possible move...

 

I stopped at level 24, but it was super funny!

[–] [email protected] 6 points 1 year ago

Nice, thanks for sharing! Mine looks like this atm:

  • HS: Mainly Docker containers and VMs
  • VPS: Wireguard to relay traffic (NAT) to the HS (SSL termination on HS)
  • UPS in case of power outage
  • Pi4 for backups within the local network. It also has a disk station for regular air gapped backup.
  • Pi3 for off site backup
  • Fire extinguisher nearby in case of emergency ^^

image of my Homelab

[–] [email protected] 5 points 1 year ago (2 children)

Die spannende Frage ist: Bekommt er das Bier erstattet?

[–] [email protected] 3 points 1 year ago

Been there, done that. Volatility is something you learn pretty early, yes. ^^

[–] [email protected] 4 points 1 year ago (2 children)

First: Good for you, enjoy the journey! Second: Just as others already pointed out, Mastodon is not really a beginner project. You want to understand what you are doing, not just make everything work no matter what. Some reasons why I'd not start with Mastodon:

  • Complex deployment stack (for beginners)
  • Needs regular maintenance
  • Security considerations (if you haven't managed/hardened a server before)
  • Long term project

So instead: Have a look at awesome-selfhosted for ideas. A personal dashboard, photo gallery or a PiHole/AdGuard is a good start.

About Docker; it's a bit more than just dependency separation. It's a kind of virtualization, but without each container running it's own kernel. Advantage is: Docker images run (with some configuration) relatively lightweight out of the box. So there's no need to install the applications natively. While I'm a great fan of Docker, you'd probably learn more installing things natively in the beginning. Or maybe do both, it's up to you. However, if you decide to use Docker, be sure to understand what's going on under the hood. That's where the fun begins. Everyone can pull and start images, but not everyone knows how to customize or build them themselves.

No matter what you decide to do, have fun. And if you've any questions, there's plenty of documentation online or just ask. The selfhosting community is very welcoming towards new members ;)

[–] [email protected] 1 points 1 year ago (1 children)

Don't worry, nothing is easy in the beginning and yes, some docs are not up to date because Lemmy has such a steep development curve and therefore frequent changes.

[...] i think i might try to do it again tomorrow after the frustration of failure of today is gone and i have some more motivation.

Do have any other self hosting experience? Maybe a software that is a bit more easy to handle would be a good starter. With that, you can experiment and learn a bit, before starting a (long term) project that requires proxy, database, frontend, backend and configs to make them work together. Not to speak from the maintenance.

Is it okay if i just ask my questions to you directly in this thread?

Sure thing. I can recommend the Lemmy admin matrix chat as well (if you're a matrix user).

Do you mean DynDNS with the automatic updates?

What I mean is: best case is your provider offers an api which allows you to update the DNS records by running a simple script. What I would not recommend is using something like mylemmy.dyndns.org (or similar services) for a Lemmy instance.

[–] [email protected] 3 points 1 year ago* (last edited 1 year ago) (3 children)

Since your question is quite basic and general, I'll try to answer equally.

  1. Hardware: For a single user instance a Pi 3B+ is sufficient. Still, Lemmy can take up some storage space over time because of the images. So make sure you don't take the smallest SD card you have lying around. I assume you know how install an OS and get basic things running.

  2. Get a domain; there are many providers out there. Consider using a TLD of your country (e.g. .de, .fr). Domains are usually relatively cheap. You're probably running your Pi at home, so check if you have a static IP address or if you have a dynamic one. First one? Great, go ahead. Second one: Check if your domain provider offers an API to automatically update the DNS record; example provider api.

  3. Have a look at the Lemmy administration docs. Depending on your experience, it is relatively easy to setup. Make sure you understand what you're doing, i.e. first get to know Docker for example, then follow the commands. If you don't understand something, just ask or search online. Lemmy is not very complex to operate, so for every part of the deployment you should be able to find information online.

  4. Set up port forwarding in your router for ports 80 (HTTP) and 443 (HTTPS). You can find information for your specific router online, but for some routers this cannot be done.

  5. Get a SSL certificate for your domain. You can get one for free with Let's Encrypt.

  6. Once you have your instance up and running, I would recommend setting it to "private" first. This way you can play around with your instance or reinstall if something goes wrong without having to worry about federation. Once you've federated (communicated with other instances, e.g. by subscribing to communities of other instances), you really shouldn't reinstall!

I hope this helps you with the first steps. Have fun with self-hosting!

 

cross-posted from: https://postit.quantentoast.de/post/18942

I thought this might be of interest to other users as well as admins.

 

I thought this might be of interest to other users as well as admins.

view more: next ›