• 0 Posts
  • 15 Comments
Joined 3 days ago
cake
Cake day: October 1st, 2026

help-circle
  • The phone-shop detail is the most alarming part for anyone at risk there: a device compromised before you even switch it on defeats most of the usual advice. For journalists and activists in that position, the practical baseline is buying devices from a large retailer or outside the country rather than a local shop, keeping the OS fully updated, and on iPhone turning on Lockdown Mode, which was built for exactly this kind of targeting.

    Amnesty’s Security Lab also maintains the open-source Mobile Verification Toolkit (MVT) for checking phones, and Access Now runs a free digital security helpline for civil society if someone suspects they’ve been targeted.


  • For your points 2 and 3 specifically: if you go the Icecast route (AzuraCast also uses Icecast under the hood), Icecast can require a username and password per mount point, so the stream URL alone is useless to anyone who stumbles on it, and you can give the mount a bland name. Put it behind HTTPS on your reverse proxy so the password isn’t sent in clear text.

    For point 4 (genres at certain times), AzuraCast’s playlist scheduling handles that from the web UI. If you build it yourself instead, Liquidsoap can switch playlists by time of day, but it’s a scripting language with a learning curve.

    If what you really want is your own library rather than one stream everyone hears at the same time, the Navidrome suggestion is simpler: separate logins and plenty of Subsonic apps on Android.




  • If you’d rather keep Vikunja as the backend and web UI, it has a CalDAV endpoint, so you can point DAVx5 at it and use Tasks.org or jtx Board on Android for the reminders themselves. That gets you native Android notifications without email, and you keep the web interface for planning. Vikunja’s CalDAV side is less mature than its web UI, though, so test whether due dates and reminders come across the way you expect before moving everything over.

    For notifications that aren’t tied to a task app (say, “remind me when X happens” from a script or Home Assistant), ntfy is the simplest self-hosted push to Android, as mentioned above.


  • Nice find. One thing to check before buying parts: the README says it works with line-level sources through a USB audio adapter. Most turntables output phono level, so unless yours has a built-in preamp (look for a PHONO/LINE switch on the back), you’ll need a phono preamp between the deck and the USB adapter. Without it the signal is very quiet and has no RIAA equalisation, so it sounds thin.

    Also, AirPlay buffers for a couple of seconds, which is fine for listening, but you’ll notice the delay if you’re standing next to the speakers while dropping the needle. The automatic start/stop on signal detection is the clever part for a turntable.


  • One test I’d apply to any new private-mail provider before moving anything important: how easy is it to leave? Check whether you can export the whole mailbox in a standard format (mbox/EML), whether there’s IMAP/SMTP access or a bridge, and above all use your own domain. With your own domain, if the provider gets bought, enshittifies, or deletes your account for inactivity like someone mentioned here, you change the MX records and you’re gone in an afternoon.

    Given how young it is and the security disclosure back-and-forth above, I’d keep it to low-stakes mail until it has a track record and an independent audit.


  • The difference for me is control. On a phone you get per-app permissions, you can switch location off, and you can leave it at home. The car’s telematics modem is always on, there’s no permission screen for it, and you usually can’t opt out without losing features you paid for.

    It’s also not hypothetical: in 2024 GM was reported to have shared drivers’ trip and hard-braking data with data brokers that fed insurers’ risk scores, and the FTC later took action over it. People saw premiums go up without ever knowingly agreeing to it. That’s why folks pull fuses: the phone at least gives you a switch.


  • Two things specific to the RX 6400 worth knowing:

    • It’s a PCIe 4.0 x4 card. On a PCIe 3.0 board the link is half as fast, and that hurts most exactly when a game spills past the 4 GB and starts moving textures over the bus. So on a 3.0 board, keeping texture quality low enough to stay inside VRAM matters even more than usual. MangoHud can show VRAM use live, so you can see when you hit the ceiling.
    • For emulation, VRAM mostly goes on internal resolution and texture packs. In Dolphin, PCSX2 and the like, 2x-3x internal res is usually comfortable on 4 GB; 4x+ with high-res texture packs is where you’d start running out.

    It also has no hardware video encoder, so don’t count on it for recording or streaming, but for older games and emulation it’s a perfectly decent card.


  • The most useful number you can get is from your own stack: put your actual app on the box and hit it with k6 or wrk using a realistic mix of pages, and watch memory rather than CPU. On 2 GB the failure mode is almost always RAM: too many PHP-FPM/worker processes plus a database on default buffers, then swap thrashing and the OOM killer, long before the single core is the limit.

    What buys the most headroom on boxes this size:

    • cap the worker count (pm.max_children or the equivalent) to what actually fits in RAM
    • size the DB buffer pool deliberately instead of leaving defaults
    • zram for bursts
    • serve anything static or cacheable straight from nginx so it never touches the app

    And rate-limit or block the obvious scrapers. As someone said above, bot traffic is often the real load.


  • If you end up running it headless (game streaming host, Jellyfin/Immich worker, whatever), two small things save a lot of hassle:

    • Get an HDMI dummy plug (a “display emulator”, a few euros). With no internal panel detected and nothing on HDMI, the GPU often has no proper display to render to, and Sunshine/Steam streaming in particular wants a “real” display to capture at the resolution you pick.
    • Check the BIOS for a “power on after AC loss” / “auto power on” option. Plenty of laptops don’t have it, but if yours does, it comes back on its own after an outage like a proper server. Otherwise Wake-on-LAN from one of your mini PCs is the fallback.

    And since storage is your bottleneck right now, open it up and see if there’s a second M.2 slot. Some of these chassis have one, and then it could hold some data while also taking the Immich/Paperless ML jobs on the 3050Ti.


  • In the US it’s any electronic device, not just phones. CBP’s own rules (Directive 3340-049A, from 2018) define it broadly: laptops, tablets, cameras, hard drives, game consoles, anything that stores data.

    The directive splits searches into two kinds:

    • Basic search: an officer manually looks through the device. No suspicion needed.
    • Advanced search: they connect external equipment to copy or analyze the contents. That officially requires reasonable suspicion or a national security concern, plus supervisor approval.

    One detail that’s useful for planning: the directive says officers are only supposed to search what’s stored on the device itself, not data that lives only in the cloud, and they’re meant to ask you to disable network connectivity first. So something that just syncs from a server once you’re home (and isn’t cached locally) is in a different position from files on the disk. Courts in different circuits have also ruled differently on how much suspicion is needed, so it’s not entirely settled.


  • The problem with a static list in a sidebar is exactly what you said: public instances come and go, and in six months half the links are dead and someone has to keep pruning them.

    A lower-maintenance option might be to link to the things that track health instead of the instances themselves, e.g. the official Invidious instance list that shows uptime, plus a one-line mention of LibRedirect (browser extension that rewrites YouTube links to a working Invidious/Piped instance and rotates when one is down) and FreeTube for desktop, which doesn’t depend on any public instance at all. That way the sidebar stays correct even when instances disappear, and people sharing videos here can keep posting the plain YouTube link without it being a problem.


  • Nice, this is one of those automations that pays for itself the first winter. Two small things that might make it nicer to live with:

    The loop with the namespace can be a one-liner, and you can limit it to the next couple of days so a cold snap six days out doesn’t nag you every morning all week:

    {{ (daily['weather.forecast_home'].forecast[:2]
        | map(attribute='templow') | min) < minTemp }}
    

    And to stop repeat alerts once you’ve actually done the work, pair it with an input_boolean like outdoor_water_winterized: add it as a condition (only notify when off), send the notification with an actionable button (“Done”) from the companion app, and have the button event flip the boolean on. Then a second automation turns it back off when the forecast lows climb above, say, 8 °C for a few days in spring. That also covers curbstickle’s point if you ever add more taps, one boolean per tap.


  • I do, but with a few tweaks that cut most of the junk the other comments mention:

    • Point Contact: at a dedicated alias, not your main inbox, and filter it hard. If the noise gets bad you can drop the alias without touching anything else.
    • Add a Policy: line linking to a short page that says plainly there is no bug bounty and no payment for reports. Most beg-bounty mails are mass-sent with a payment ask, so this gives you something to point them at and lets you bin them without guilt.
    • Don’t forget Expires:, it’s actually required by RFC 9116 and a lot of hand-written files leave it out. Set a calendar reminder to bump it.
    • Serve it at /.well-known/security.txt; the root path is only a legacy fallback.

    Whether it’s worth it for a homelab is debatable, but if you host anything other people rely on (a Matrix/Lemmy instance, a shared Nextcloud), having one real contact path beats someone finding a hole and having nowhere to send it.