Stop Trusting VPN Companies. Host Your Own (WireGuard getting started guide) 37:29


You sure you trust VPN providers? Would it not be better to make your own VPN?


::: spoiler Chapters
- 0:00- Quick overview of WireGuard
- 01:41- WireGuard VPN setup // Choosing a Linode Plan
- 02:49- SSH to the Linode server
- 03:46- Updating and upgrading server
- 04:25- Installing WireGuard
- 05:05- Hiding your WireGuard private key
- 07:03- Adding a new WireGuard interface
- 10:14- Setting up WireGuard on a Client computer
- 15:08- Disabling IPv6
- 18:35- Setting up NAT
- 21:28- WireGuard installation summary
- 22:24- Setting up persistence for WireGuard
- 26:33- Create another SSH user
- 30:11- Remove root SSH access
- 34:00- Reasons to use WireGuard
- 36:30- Conclusion
:::

in reply to RBWells

I want to make a White Russian tonight. But along with the vodka and Kahlúa, I want to add some Baileys. I usually use vanilla soy, instead of milk, because I like the taste and texture.

I started adding Baileys during the cold, dark winter months, which was a lovely evening drink. During summers, I usually go for a Tequila Sunrise, but today I'm in the mood for that softer, non-acidic feel.

EDIT: Just saw your description text, OP. Never heard of a Pas de Loupe before, but that sounds interesting. Is that Mezcal, Cynar, ancho, honey syrup and lemon juice?

Also, happy cake day!

What should I expect from someone who has just been released from prison?


My older brother is being released on parole at the end of this month after serving 11 years and 3 months of a 15-year sentence. I’m 19 now, so I was very young when he went to prison and don’t have many memories of him. He’ll be living with our parents and me after his release, and to be honest, I’m feeling a bit anxious about it.
in reply to idyllic

I know others will mention some of the personal things, so I'll instead focus on ways to help him try to reintegrate with everyday life and society socially.

You could start to try to help with some things he will interact with daily. The chances of him knowing about basically anything electronic you use now on a daily basis are slim. This is one of the biggest daily interactions that many former inmates have trouble with and betting up to speed on in modern society.

For some perspective, 11 years ago was 2014, and the launch of the iPhone 6 and 6 Plus. All the advancements since then will be new. LTE actually being widespread and usable, 5G even being a thing at all.

An offshoot of those are things like TikTok, YouTube Shorts, Instagram Reels, etc. which are massive social media hubs now, but didn't exist then. Heck, Vine was technically still around for a couple years after he went in. Educating about changes to media consumption and social media use can help with integration back into society, and suggesting some recent things to catch up on can provide recent and relevant topics of conversation for daily life.

This entry was edited (1 week ago)

Cyclocross gravel, or road?


I am a road cyclist, and I intend on getting a new bike soon. I'd like to use it to zoom around town for fun like I already do on my road bike, but I also want to be able to commute with it. As such, I'd like it to be able to handle light grass and dirt when I need to (no mud, gravel, excessive drops, etc). I've been thinking about a gravel or cross bike, but they're just not quite "zoomy" enough for me; I like more aggressive geometry and a nice, aero frame. Additionally, there has been a growing trend for thicker tires on road bikes, so a modern road bike should be able to fit cross tires. Should I just get a new road bike and throw some 33mm cross tires on it? Or should I suck it up and get a cross/gravel bike that's actually designed for dirt? On one hand I want to zoom and won't be on dirt/grass all that much, but on the other I don't want to ruin an expensive bike by taking it off-road when I shouldn't. Help a brother out.
in reply to sbf

"gravel bike" has been a widening category over the last few years. Some are basically road bikes with extra clearance (further confused by road bikes going that route too) all the way to essentially drop-bar hardtail mtbs. I'm pretty sure you would find a bike with the "gravel" label that's pretty aggressive while still being somewhat off-road capable. If you keep a second wheel set around, you can even convert it to a quasi road bike pretty easily.

How Do I Prepare My Phone for a Protest?


Shared here for public benefit.

Before going to a protest, demonstrators or observers should note that their cellphones may subject them to surveillance tactics by law enforcement. If your cellphone is on and unsecured, your location can be tracked and your unencrypted communications, such as SMS, may be intercepted. Additionally, police may retrieve your messages and the content of your phone if they take custody of your phone, or later by warrant or subpoena.
This entry was edited (1 week ago)
in reply to spaghettiwestern

>Be me
>Build new PC
>"Maybe I'll try out Linux. "
>Fairly popular 2 year old Motherboard
>Integrated WiFi Module no drivers available
>Integrated Bluetooth Module no drivers available
>No support for $170 Sound Card
>4 hours of troubleshooting later
>Linux more bloated with dependencies and packages from troubleshooting than your grandmas browser extensions
>"Fuck this"
>Nuke Partition
>Install Windows
>Shit instantly just works
>Use Linux partition drive for backups
This entry was edited (1 week ago)
in reply to spaghettiwestern

bought one of the new snapdragon x elite laptops refurbished recently. obviously it came with windows 11 and i had to briefly use it to shrink the boot partition and disable bitlocker so i could install the ubuntu concept image on it.

The amount of advertising i was subjected to in that time was infuriating. not to mention the frankly arduous setup wizard.

Even with the slight bugginess of a "concept image" OS, the user experience is SOOOO much better than shitty horrible windows.

Sent from my HP OmniBook running NOT windows

This entry was edited (1 week ago)

[Nobara] Help fixing boot situation


So I have a weird situation that I'm not sure how to fix, and it's going to require some background.

I have 4 drives in my machine:
1. A ~15 year old 128GB SATA SSD (windows, ntfs)
2. An ~8 year old 512GB SATA SSD (libraries, ntfs)
3. A ~5 year old 1TB NVMe SSD (nobara, btrfs)
4. A ~1 year old 2TB NVMe SSD (games, ntfs)

I've gone a month now without booting into windows so I figure it's time to clean up my windows install and reclaim/retire those drives, but my boot situation is kinda weird. #1 is my current default boot drive in bios, and it has both the boot loader for windows and for a previous ubuntu install I also had on the current-nobara install, and then #3 has another one (but won't boot when I select it in bios for whatever reason), so what I really need to do is clean up all these extraneous boot-loaders and set one up on drive #3 to be my main boot from now on. But I'm very nervous about messing with that sort of thing and rendering my system unbootable (I know, I still have the install USB I could use, but still.) I've tried reading guides and such on how to do bootloader stuff in general, but I am not confident in my ability to not fuck it up.

Although now that I think about it if I don't care about the windows boot drive I can just pull it, I just need to make sure I can boot off drive #3 before I do do that and I have no idea how to go about setting that up with my current situation.

NixOS printing problems


A friend and I are trying to get a machine set up to work as my school's library's printing computer instead of Windows ones. It is running NixOS. We got it bound to active directory, applications installed, etc., but the issue is that we can't get it to print. It'll say that it's printing but the print job never reaches the print server. To access the print server you're supposed to authenticate, but it doesn't ever give a prompt to. I tried turning off the firewall temporarily to see if that was the issue but it made no difference.

In configuration.nix, services.printing.enable=true and services.printing.drivers = [ pkgs.cups pkgs.hplip ]; (it is an HP printer that we're currently testing on).

I'm thinking that either SAMBA is configured incorrectly and/or the syntax that I put into CUPS for the printer is incorrect.

Current SAMBA config:

services.samba = {
enable = true;
openfirewall = true;
settings = {
public = {
path = "/srv/public";
browseable = true;
writable = true;
"guest ok" = true;

In CUPS it shows the syntax for a Windows printer via SAMBA as follows: smb://[workgroup/]server[:port}/printer

The issue is that I don't know what it means by that. I know the print queue, domain, IP, and port (although I'm under the impression that I don't need the port for this case), but I don't know how it would fit into this. I tried looking around on the CUPS wiki but it was vague and confusing to me. Any help with this is much appreciated.

[SOLVED] Recover deleted partition table - Guys, i need help!


My disk was dos labelled (MBR). So I 'fdisk'-ed my disk and entered 'o' to convert it to GPT and wrote it to the disk. Now all the partitions are gone. I want those back. I care about the data rather than the partitions

Edit 0:

Solution:
- install testdisk
- run testdisk
- choose "Create" log
- choose target disk. Eg: /dev/sda
- Choose appropriate partition type. Mine was MBR and I chose "Intel" and select "analyze"
- Now you'll see deleted partitions. Giveem appropriate flags like "*" for boot (efi partition) and "P" any other using space or arrow keys and press enter
- choose "write" and press y on the prompt to write those found partitions to the disk.

Thanks guys for the help

This entry was edited (1 week ago)
in reply to RedWizard [he/him, comrade/them]

This article is terrible.

In less than three months' time, almost no civil servant, police officer or judge in Schleswig-Holstein will be using any of Microsoft's ubiquitous programs at work.

Instead, the northern state will turn to [an unnamed, gaping information hole] open-source software to "take back control" over data storage and ensure "digital sovereignty", its digitalisation minister, Dirk Schroedter, told AFP.

"We're done with Teams!" he said, referring to Microsoft's messaging and collaboration tool and speaking on a video call -- via an [unnamed, gaping information hole] open-source German program, of course.


What will they use instead? Who the fuck knows! The article omits this crucial piece of information.

And don't say it's TBD; they're not going to say they're "done with Teams" without knowing what they're switching to. Or, even if they haven't put the final nail in the decision, they have a short list.

This entry was edited (1 week ago)
in reply to Deceptichum

"So what you had was that the world's two major propaganda agencies, for their own quite different reasons were claiming that this destruction of socialism is socialism. And it's very hard to break out of the control of the world's two major propaganda agencies when they agree, and they agreed for different reasons, but they agreed, and then that becomes doctrine and dogma."

How do you handle image hosting?


I would like to start using floorplans/maps with various device actions on them. This means I need locally stored images, that can be seen over the network.
I managed to upload images to HA, but as they need to be accessed with a token, I either need to refresh the token every day (no), or have an image with a long-lived token (also not a good idea).

How have other people done things?
Is it worth spinning up an http image host?
Or maybe throwing files into an nginx folder inside HA?

Thoughts on a postcard 😀

What can I use for an offline, selfhosted LLM client, pref with images,charts, python code execution


I was looking back at some old lemmee posts and came across GPT4All. Didn't get much sleep last night as it's awesome, even on my old (10yo) laptop with a Compute 5.0 NVidia card.

Still, I'm after more, I'd like to be able to get image creation and view it in the conversation, if it generates python code, to be able to run it (I'm using Debian, and have a default python env set up). Local file analysis also useful. CUDA Compute 5.0 / vulkan compatibility needed too with the option to use some of the smaller models (1-3B for example)

Is there anything that can tick the boxes? Even if I have to scoot across models for some of the features? I'd prefer more of a desktop client application than a docker container running in the background.

This entry was edited (1 week ago)

I am new to Lemmy after trying to use reddit and being scared away, since most of you are former reddit users can you explain why reddit is run the way it is ?


Ok I know the title is weirdly said but I will explain more here. I tried using reddit but all of the subs and topics I wanted to speak on were gated by Karma, so I searched reddit for no karma sub so I just posted on ask reddit,nostupid questions and I made one post on r/advice which I cross posted to relationship advice after which my account glitched. Turned out I had been shadow banned and I have no clue how. My theory is I posted to much and copy and pasting a post tripped the alarm but the post was a bit different on relationship advice and I did it once, I saw reddit from like youtube videos and tiktok and people cross post to subs all the time why is that an issue ?

But to get to the main ponint of this, why is reddit run the way it is ? In the sense why do they ask so much of their users hurting both the user expirience and the site's ability to grow.
The Karma system forces you into a position where to get to the content you want you have to interact with and post content you don't care about.So you have a ton of disengaged user's just punching their time card to get to what they actually care about.
Imagine if other social media sites did this, imagine if you wanted to listen to sabrina carpenter on spotify but to do that you had to listen to 100 hours of Conway Twitty, what sense does that make ?

Reddit's karma and age gate systems resemble a mobile game and while annoying when it's done there you understand why it's designed to get you to pay to skip it, but reddit doesn't let you pay to skip it at east not directly.

Every other social media site wants to get users the content they want as easy as possible. TikTok is the best example the reason it's popular is because it's the best at getting you what you want with as little work required on your part as possible. The for you page fetches you videos your interested in, if your a creator the format of the app increases your chance of being seen and going viral.

Reddit on the other hand leaves so much of the user experience up to weather or not your post on ask reddt go gets upvotes or if you happen to know if a good sub with a karma limit since subs do not disclose their karma limit

Again for the last time, why ? Even from a selfish business standpoint this seemingly makes no sense so what am I missing

in reply to Speiser0

Wenn man bewusst einen Überblick über aktuelle Geschehnisse bekommen will, ist ein Besuch auf dw.com (weltweit) und tagesschau.de (🇩🇪) immer zu empfehlen.
This entry was edited (1 week ago)

Auch nicht mit Eltern: Alkoholverbot für Kinder unter 16 geplant


feedback on my next steps for self hosting


I'm still dipping my toes into self hosting and trying to figure out what services I would want to be always accessible from my devices vs those that could be awakened by LAN, and which services should be installed at the OS level vs as containers.

As of now, I just have an OrangePi 5 Plus running Home Assistant Supervised under Debian and nothing else. I'm hoping to expand the OPi a bit and also build out another PC (hardware unknown) as a NAS media server and NextCloud machine.

Before I start doing anything I can't undo, I'm wondering if I' on the right track with my proposed setup in the image, or if there's anything else I should consider?

Internet Blackout in Gaza as Israel Targets Last Fiber Line


Gaza (Quds News Network)- The Gaza Strip has plunged into a complete internet and communication blackout after Israeli attacks severed the last remaining fiber-optic line, the Palestinian Telecommunications Regulatory Authority announced on Thursday.

The authority confirmed that fixed-line internet and telecommunication services are now entirely cut off across Gaza, including the central and southern regions, which have now joined the digital silence already imposed on Gaza City and the north for the past two days.

“This is the result of systematic attacks on Gaza’s already fragile telecom infrastructure,” the authority said in a statement. Technicians have tried multiple times to repair and reroute damaged lines, but Israeli restrictions have blocked all efforts.

Why aren't there more nutritionists on Youtube? (and Peertube)


When looking for nutritional information, 2 ~~doctors~~ guys always show up in Youtube searches: KenDBerryMD and Dr. Eric Berg.

I don't know much about either, but a cursory search shows Berg is a quack and it looks like Ken promotes nonsense like the carnivore diet.

Why are these two so prevalent on youtube? Neither of them are actual nutritionists, but they're everywhere when searching for nutrition information.

Where are the real nutritionists? Why aren't they putting forth more effort to make sure nutrition knowledge is accessible and accurate?

Part of me is genuinely thinking it's because of money. They'd rather only share their knowledge in secret with the people paying them because if more people knew about nutrition, then they wouldn't be as necessary.

This entry was edited (1 week ago)

Linux won't boot, looking for help


Hey there. I’m totally new to Linux. I’m not the most tech savvy, but I’m fed up with windows and want to go elsewhere. For the time being I figured I’d dual boot, and got everything set up on a usb. I plugged it in, booted up Linux Mint, and it worked smoothly. I ended the session, powered off my pc, removed the usb, booted up windows 11, freed up some disc space and did some other stuff on my computer, then turned it off for a bit. When I went to boot it up again, I got this message:

Failed to open \EFI\B00T\mmx64.efi - Not Found Failed to load image ??: Not Found Failed to start MokManager: Not Found
Something has gone seriously wrong: import mok-state() failed: Not Found

and then the computer powered off. I tried disabling fast start or whatever it’s called, as well as secure boot, and it’s still giving me that. Windows still boots up just fine. Does anyone have any advice? Like I said I don’t have much technical knowledge so a dumbed down response would be really appreciated. I’ve looked up a few forums and nothing gave me much.

Oh also, when I try to boot it and it gives me the error and turns off, if I turn it back on but boot up windows, I get a message saying something was blocked due to a security system I have to disable, but doesn’t tell me what that security system is or how to disable it. It’s getting a little frustrating. I don’t know why it worked once but not anymore.

Update: I got it working. Thanks everyone for the help.

This entry was edited (1 week ago)
in reply to BurntWits

When you freed up the disk space windows seems to have broken mints bootloader partition. You could fix it if you wanted, but at beginner level its probably best to reinstall. If you need to recover any data from you "broken" mint partition you can plug the mint USB in, boot into the live environment and look in your files mount you old mint files and backup anything you want to keep before reinstalling.

Depends on how much of a nerd you are. If the idea of rescuing your system using the terminal sounds fun then try otherwise just reinstall.

This entry was edited (1 week ago)

Why is Lemmy so toxic?


A few days ago I made an account and posted a few joke/meme comments that got a lot of engagement. Unfortunately, the replies seemed to be mostly personal attacks on me disguised as jokes, when all I was doing was trying to be funny in a harmless way. I deleted that account and this one will be temporary. You people complain about this site lacking content compared to Reddit, about communities with only one person posting regularly and there not being enough niches, but how do you expect any growth to occur if the first thing someone experiences when posting on a new account is getting dogpiled on? It wasn't my first account either, it was my latest attempt to reenter the fray after feeling like I was becoming the butt of the joke on an account before that, just engaging with the community in the way that I like to. It almost felt like on both accounts my comments were being deliberately mass upvoted just as a setup to be humiliated. Some people have horrific lives IRL that would make any reasonable person want to kill themselves, and are stuck in those soul crushing situations for years and years with no way out. It would be nice to find a place to joke around and feel even just the simulated warmth of human connection without the same kind of nastiness I encounter in everyday life, so I'll keep looking. You say Reddit is toxic? I deleted my account there a long time ago, but my experience was that Reddit is like a big metropolis and Lemmy is more like a small town. Yes Reddit has jerks, but they don't tag you with their third party app and follow you around, giving you the illusion of being accepted with (probably fake) upvotes while subtly mocking everything you say and passing it off as a joke. You can blend with the crowd there and not become a target. I really, really don't want to give Reddit and OpenAI my data, but if I want a real social media experience that isn't being gatekept by assholes who enjoy bullying on the internet because they're too scared to do it IRL I may have to. I hope Lemmy can fix itself, but my experience with small towns in real life is that those "big" (small) fish in their small, stagnant pond don't want anything to ever change because the status quo suits their mediocrity and reinforces their egos. Which would be an ironic fate for the supposed "future" of social media. Almost none of the content, all of the toxicity. Why is it so hard for people to be respectful of others?

Mandatory img:

This entry was edited (1 week ago)

I almost quit my job today but I didn't have the courage to walk into my boss' office. (Vent)


I feel so awful. I have multiple panic attacks. I want to cry. My body feels like it is not mine. I want to quit but my legs are like noodles. I can't even get up.

I know it is all in my head (perhaps) but I really think people don't trust me anymore. I don't trust myself too.

Please don't send me any self harm alert. I am not thinking about that. I just want to vent.

Danish Ministry Replaces Windows and Microsoft Office with Linux and LibreOffice


Full text due to weird cookies banner

The Danish Ministry of Digitization is to completely abandon Microsoft in the coming months and use Linux instead of Windows and switch from Office 365 to LibreOffice. Minister Caroline Stage (Moderaterne) announced this in an interview with the daily newspaper Politiken. It comes just a few days after the country's two largest municipalities initiated similar steps. This summer, half of the ministry's employees will be equipped with Linux and LibreOffice. If everything goes as expected, the entire ministry will be free of Microsoft by the fall, Politiken summarizes.

The Ministry of Digitalization's move away from Microsoft is therefore taking place against the backdrop of a new digitalization strategy in which the Kingdom's "digital sovereignty " is given priority. According to newspaper reports, the opposition is also calling for a reduction in dependence on US tech companies. Just a few days ago, the administration of the capital Copenhagen announced its intention to review the use of Microsoft software. The second-largest municipality, Aarhus, has already started to replace Microsoft services. Stage has now told Politiken that they should cooperate and that it is not a race. All municipalities should work together and strengthen open source.

When asked how her ministry would react if the changeover was not so easy, Stage replied that they would then simply return to the old system for a transitional period and seek other options: "We won't get any closer to the goal if we don't start." So far, she has only heard from employees who welcome the move. But in her ministry, which is mainly concerned with digitalization, she expects a lot of interest anyway. She also assured them that the initiative is not about Microsoft alone, as they are generally far too dependent on a few providers.

As background to the move, the article also refers to the events at the International Criminal Court, where an email account operated by Microsoft was disconnected. This caused an uproar across Europe. In Denmark, there is also the fact that the new US President Donald Trump has been announcing for weeks that his country wants to take over Greenland. The island in the North Atlantic is a self-governing part of Denmark, and the outrage at Trump's proposal is huge. The desire to reduce dependence on US companies is therefore evidently even greater there than in the rest of Europe.

This entry was edited (1 week ago)

Plex Server Replacement


Current setup is PMS running on a Synology 5-bay, and another PMS running on a Shield Pro. The NAS server is primarily used for remote streaming, while the Shield serves to my home LAN (AppleTVs mainly).

I've been seeing stuttering on larger files, either using the Plex app or Infuse, and I'm fairly certain the Synology is the weak link. Network performance in the house has pretty solid, though admittedly I could stand to test it more thoroughly. I've been looking at moving my library to a standalone system. I've been looking at the Beelink ME Mini (which happens to be on sale!). What I don't know is the best way to build this out.

I don't want to have to buy all 6 SSDs (ar at least 6x4TB ones!) at once, so I'd be looking at either a stock Linux (Ubuntu or Rocky) install w/ I guess a BTRFS pool for the SSDs (I'm guessing I can use the eMMC for OS depending on how big the install is - that or use the SSD in slot 4). Alternatively, i could possibly set up TruNAS w/ the Plex pp to manage the storage.

As for populating the media, I plan to keep the Synology as the central repo of my data. I have it replicating to another NAS at my dad's house, with movies/music/tv replicating using Syncthing. I plan to also use Syncthing to populate the Beelink.

Anyway, please poke holes in this plan and/or suggest a better one. My main goals are to get the media I'm streaming off spinning disk w/ minimal power draw (didn't mention that above) in a way that I can expand storage as necessary to accommodate the media library. Nothing's purchased yet, so I'm not married to the hardware. I would ideally like to convert the library to h.265 or even AV1 if I can make it work.

ETA: For clarity: I'm not transcoding AFAIK. My Shield mounts the Synology over SMB and mostly works fine, until I try to play anything 4k - then I get stuttering. On the surface, this sounded like a network issue, but I can't find a problem w/ the LAN. My thought was to move the PMS to a single location w/ local storage, and use the Synology just as an archive.

ETA2: FWIW, I have not expanded the memory on the Synology or installed any cache drives.

This entry was edited (1 week ago)

Debian (12/13): Wireguard VPN-client


So, I imported my connection-configuration provided from OPNsense Wireguard VPN.

The connection is working on an old (<10 years) Android Phone. But from within Linux (same config) I am unable to resolve subnet ip addresses.
I can still access the internet though.

So; Am I using my origin connection to resolve foreign ips or am I using my VPN DNS?
Why am I unable to access my subnet ip addresses on my linux machine?

The Linux machine is 6.13.30-arm64 with /etc/debian_version pointing to 13.0.

I have installed wireguard-tools and network-manager only. I have also wireguard installed but it doesn't make a difference and its usage is for hosting a endpoint.

Again: It works for other machines like intended.
If of concern: I am running XFCE.

Apple’s Craig Federighi on the long road to the iPad’s Mac-like multitasking


Personally, I was shocked that they did the thing that people have been asking them to do for years. I expected them to continue to dig their heels in and ship another halfstep / half-assed measure.

First ever upgrade issue - lost zwave controller


I've been running Home Assistant for about a year now and always installed every update as soon as it's released and never had any issues at all.

Yesterday some time in either the zwave js 15.6.0 or core 2025.6.0 update (I am too complacent and did them both in quick succession without testing anything) I lost my Zooz 800 zwave controller. Reloading HA didn't bring it back. I had unplug and replug the Zooz USB stick and then reload again.

Not a big deal, just sharing FYI.

in reply to KittenBiscuits

Thank you for caring. If you need to or just feel it's best, there are all sorts of safe live animal traps out there, if you need it or any more coons relocated..

youtube.com/watch?v=xCZprBPFDV…

San Francisco based XRobotics pizza making robots, lease for $1,300 a month and can make 100 pizzas per hour.


Interesting that they are going the subscription route and not selling these outright. It works because the comparison with the cost of a human looks so favorable. I'd expect to see this with humanoid robots too as they take over more and more human jobs.

XRobotics’ countertop robots are cooking up 25,000 pizzas a month

YouTube Music Downloader


Hey guys i have been using Navidrome to stream my music from my server and its been amazing. I primarily use YT Music because of discoverability so I have all of my "primary" playlists (about 8 of them really, but supporting a somewhat arbitrary limit would be nice) in YouTube.

Im looking for an automated way to download the music and keep my navidrome instance updated with a couple playlists. I started working on some Python script to handle it, but its just not working super well so i would prefer to use someone elses solution haha.

Anyone have any good recommendations? I tried this one but I couldn't actually find the music and it seems to only support one playlist at a time. It would also be nice to download the album art and set some ID3 tags too

This entry was edited (1 week ago)
in reply to Lv_InSaNe_vL

Just to throw out an easy option: if the music is well-labeled on Youtube, you can get pretty close to that full suite with just yt-dlp by using --embed-thumbnail as a stand-in for album art, dumping your files with an “Artist - track - album” naming structure using the --output-template flag — then using an awk or python script as a second pass to add the artist/track/album names to each file as tags.

E: and in case it isn’t self-evident, you don’t have to give yt-dlp a URL for each track; it’ll work fine with a playlist URL.

This entry was edited (1 week ago)

Your username is your prompt, what does it look like?


Rerunning an idea, I'm curious how image generators have improved/changed.

Feel free to break up the words in your username, and let us know if you added anything like "a logo for..." Or "an avatar for..."

Let's run it through as many different generators as you have access to, and see what happens. You might just find your new avatar picture!

Does the share button on pixeled do nothing?


I created a secondary Pixelfed account to test the share functionality, but none of the posts I've shared from my main account are showing up in the new account’s feed.
This entry was edited (1 week ago)
in reply to rumimevlevi

if your two accounts are on a different instance, federation takes a while, your follow signals to your instance to synchronize the content from the other account, and it's not instantaneous, it's queued along the requests of everyone else on your instance.
This entry was edited (1 week ago)
in reply to CosmoNova

I never even played fortnite, but i watched some videos on it, and it's pretty weird. I can just assume it's for children who don't care because they don't know and actually have a chance playing and winning. Marvel rivals put you in pity matches after you lost a game or two and it's ridiculous. It's just a waste of time. But even if the bots are so obvious, there are still teammates that go: let's go guys, we got this.
They have a combined 3 kills and we have like 30 each. There is no reason playing this.

How to screen record regions while showing the region boundary?


I want to see either a persistent rectangle box on the edges of the region being recorded (anything outside the box isn't recorded), or dim the parts of the screen that aren't being recorded. I looked for screen recorders for hyprland & wlroots and didn't find any with this functionality. wf-recorder + slurp works for me but I want a boundary visual.
This entry was edited (1 week ago)
in reply to return2ozma

In case you want to know if you need to start backing a local primary challenger:

Based on GovTrack, which documents Congress' legislative activities, the following 75 Democrats voted in favor of the first resolution expressing "gratitude" to ICE:

Adams, Alma (NC-12)
Auchincloss, Jake (MA-4)
Beatty, Joyce (OH-3)
Bell, Wesley (MO-1)
Bishop, Sanford (GA-2)
Brown, Shontel (OH-11)
Budzinski, Nicole (Nikki) (IL-13)
Bynum, Janelle (OR-5)
Cherfilus-McCormick, Sheila (FL-20)
Cohen, Steve (TN-9)
Courtney, Joe (CT-2)
Craig, Angie (MN-2)
Cuellar, Henry (TX-28)
Davids, Sharice (KS-3)
Davis, Donald (NC-1)
Elfreth, Sarah (MD-3)
Frankel, Lois (FL-22)
Gillen, Laura (NY-4)
Gluesenkamp Perez, Marie (WA-3)
Golden, Jared (ME-2)
Gonzalez, Vicente (TX-34)
Goodlander, Maggie (NH-2)
Gray, Adam (CA-13)
Harder, Josh (CA-9)
Hayes, Jahana (CT-5)
Horsford, Steven (NV-4)
Hoyer, Steny (MD-5)
Kaptur, Marcy (OH-9)
Keating, William R. (MA-9)
Kennedy, Timothy (NY-26)
Krishnamoorthi, Raja (IL-8)
Landsman, Greg (OH-1)
Lee, Susie (NV-3)
Lynch, Stephen (MA-8)
Magaziner, Seth (RI-2)
Mannion, John (NY-22)
McBath, Lucy (GA-6)
McClain Delaney, April (MD-6)
McDonald Rivet, Kristen (MI-8)
Meng, Grace (NY-6)
Min, Dave (CA-47)
Morelle, Joseph (NY-25)
Moskowitz, Jared (FL-23)
Moulton, Seth (MA-6)
Mrvan, Frank (IN-1)
Neal, Richard (MA-1)
Neguse, Joe (CO-2)
Pallone, Frank (NJ-6)
Panetta, Jimmy (CA-19)
Pappas, Chris (NH-1)
Pettersen, Brittany (CO-7)
Riley, Josh (NY-19)
Ruiz, Raul (CA-25)
Ryan, Patrick (NY-18)
Schneider, Brad (IL-10)
Schrier, Kim (WA-8)
Scott, David (GA-13)
Sewell, Terri (AL-7)
Sorensen, Eric (IL-17)
Soto, Darren (FL-9)
Stanton, Greg (AZ-4)
Stevens, Haley (MI-11)
Subramanyam, Suhas (VA-10)
Suozzi, Thomas (NY-3)
Swalwell, Eric (CA-14)
Sykes, Emilia (OH-13)
Thanedar, Shri (MI-13)
Torres, Norma (CA-35)
Torres, Ritchie (NY-15)
Tran, Derek (CA-45)
Vasquez, Gabriel (Gabe) (NM-2)
Vindman, Eugene (VA-7)
Wasserman Schultz, Debbie (FL-25)
Whitesides, George (CA-27)
Wilson, Frederica (FL-24)

Ghostty in review: how's the new terminal emulator?


A few months ago, a new terminal emulator was released. It's called ghostty, and it has been a highly anticipated terminal emulator for a while, especially due to the coverage that it received from ThePrimeagen, who had been using for a while, while it was in private beta.
This entry was edited (1 week ago)

Airlines Don't Want You to Know They Sold Your Flight Data to DHS


Full text to bypass paywall:

A data broker owned by the country’s major airlines, including Delta, American Airlines, and United, collected U.S. travellers’ domestic flight records, sold access to them to Customs and Border Protection (CBP), and then as part of the contract told CBP to not reveal where the data came from, according to internal CBP documents obtained by 404 Media. The data includes passenger names, their full flight itineraries, and financial details.

CBP, a part of the Department of Homeland Security (DHS), says it needs this data to support state and local police to track people of interest’s air travel across the country, in a purchase that has alarmed civil liberties experts.

The documents reveal for the first time in detail why at least one part of DHS purchased such information, and comes after Immigration and Customs Enforcement (ICE) detailed its own purchase of the data. The documents also show for the first time that the data broker, called the Airlines Reporting Corporation (ARC), tells government agencies not to mention where it sourced the flight data from.

“The big airlines—through a shady data broker that they own called ARC—are selling the government bulk access to Americans' sensitive information, revealing where they fly and the credit card they used,” Senator Ron Wyden said in a statement.

ARC is owned and operated by at least eight major U.S. airlines, other publicly released documents show. The company’s board of directors include representatives from Delta, Southwest, United, American Airlines, Alaska Airlines, JetBlue, and European airlines Lufthansa and Air France, and Canada’s Air Canada. More than 240 airlines depend on ARC for ticket settlement services.

****Do you work at ARC or an agency that uses ARC data? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.****

ARC’s other lines of business include being the conduit between airlines and travel agencies, finding travel trends in data with other firms like Expedia, and fraud prevention, according to material on ARC’s YouTube channel and website. The sale of U.S. flyers’ travel information to the government is part of ARC’s Travel Intelligence Program (TIP).

A Statement of Work included in the newly obtained documents, which describes why an agency is buying a particular tool or capability, says CBP needs access to ARC’s TIP product “to support federal, state, and local law enforcement agencies to identify persons of interest’s U.S. domestic air travel ticketing information.” 404 Media obtained the documents through a Freedom of Information Act (FOIA) request.

A screenshot of the Statement of Work. Image: 404 Media.

The new documents obtained by 404 Media also show ARC asking CBP to “not publicly identify vendor, or its employees, individually or collectively, as the source of the Reports unless the Customer is compelled to do so by a valid court order or subpoena and gives ARC immediate notice of same.”

The Statement of Work says that TIP can show a person’s paid intent to travel and tickets purchased through travel agencies in the U.S. and its territories. The data from the Travel Intelligence Program (TIP) will provide “visibility on a subject’s or person of interest’s domestic air travel ticketing information as well as tickets acquired through travel agencies in the U.S. and its territories,” the documents say. They add this data will be “crucial” in both administrative and criminal cases.

A DHS Privacy Impact Assessment (PIA) available online says that TIP data is updated daily with the previous day’s ticket sales, and contains more than one billion records spanning 39 months of past and future travel. The document says TIP can be searched by name, credit card, or airline, but ARC contains data from ARC-accredited travel agencies, such as Expedia, and not flights booked directly with an airline. “[I]f the passenger buys a ticket directly from the airline, then the search done by ICE will not show up in an ARC report,” that PIA says. The PIA notes the data impacts both U.S. and non-U.S. persons, meaning it does include information on U.S. citizens.

“While obtaining domestic airline data—like many other transaction and purchase records—generally doesn't require a warrant, there's still supposed to go through a legal process that ensures independent oversight and limits data collection to records that will support an investigation,” Jake Laperruque, deputy director of the Center for Democracy & Technology's Security and Surveillance Project, told 404 Media in an email. “As with many other types of sensitive and revealing data, the government seems intent on using data brokers to buy their way around important guardrails and limits.”

CBP’s contract with ARC started in June 2024 and may extend to 2029, according to the documents. The CBP contract 404 Media obtained documents for was an $11,025 transaction. Last Tuesday, a public procurement database added a $6,847.50 update to that contract, which said it was exercising “Option Year 1,” meaning it was extending the contract. The documents are redacted but briefly mention CBP’s OPR, or Office of Professional Responsibility, which in part investigates corruption by CBP employees.

“CBP is committed to protecting individuals’ privacy during the execution of its mission to protect the American people, safeguard our borders, and enhance the nation’s economic prosperity. CBP follows a robust privacy policy as we protect the homeland through the air, land and maritime environments against illegal entry, illicit activity or other threats to national sovereignty and economic security,” a CBP spokesperson said in a statement. CBP added that the data is only used when an OPR investigation is open and the agency needs to locate someone related to that investigation. The agency said the data can act as a good starting point to identify a relevant flight record before then getting more information through legal processes.

On May 1, ICE published details about its own ARC data purchase. In response, on May 2, 404 Media filed FOIA requests with ICE and a range of other agencies that 404 Media found had bought ARC’s services, including CBP, the Secret Service, SEC, DEA, the Air Force, U.S. Marshals Service, TSA, and ATF. 404 Media found these by searching U.S. procurement databases. Around a week later, The Lever covered the ICE contract.

A screenshot of the Statement of Work. Image: 404 Media.

Airlines contacted by 404 Media declined to comment, didn’t respond, or deferred to either ARC or DHS instead. ARC declined to comment. The company previously told The Lever that TIP “was established after the Sept. 11 terrorist attacks to provide certain data to law enforcement… for the purpose of national security matters” and criminal investigations.

“ARC has refused to answer oversight questions from Congress, so I have already contacted the major airlines that own ARC—like Delta, American Airlines and United—to find out why they gave the green light to sell their customers' data to the government,” Wyden’s statement added.

U.S. law enforcement agencies have repeatedly turned to private companies to buy data rather than obtain it through legal processes such as search warrants or subpoenas. That includes location data harvested from smartphones, utility data, and internet backbone data.

“Overall it strikes me as yet another alarming example of how the ‘Big Data Surveillance Complex’ is becoming the digital age version of the Military-Industrial Complex,” Laperruque says, referring to the purchase of airline data.

“It's clear the Data Broker Loophole is pushing the government back towards a pernicious ‘collect it all’ mentality, gobbling up as much sensitive data as it can about all Americans by default. A decade ago the public rejected that approach, and Congress passed surveillance reform legislation that banned domestic bulk collection. Clearly it's time for Congress to step in again, and stop the Data Broker Loophole from being used to circumvent that ban,” he added.

According to ARC’s website, the company only introduced multifactor authentication on May 15.

This entry was edited (1 week ago)

Github- I don't get it!


I feel super dumb asking this. But what actually is and how does github (or similar sites) work? Are they all just source files one needs to manually compile? I am always confused when I look at a github page. I know some have directions but they still go way over my head sometimes. Im not a total noob but some of this stuff seems like you need to be in programming and have an IDE just to run a program.

Tesla customers in France sue over brand becoming 'extreme right'


Around 10 French clients with leases on Teslas are suing the US carmaker, run by Elon Musk, because they consider the vehicles to be "extreme-right" symbols, the law firm representing them said on Wednesday.
in reply to cm0002

I found one pretty cheap on Craigslist..

tinyurl.com/missingf35

If you don't trust tinyurl, I totally don't blame you. It links to this archived page, funny as hell actually...

web.archive.org/web/2023091900…

Edit: Listing Text...

Supersonic VTOL - like new PRICE DROP - $75,000,000 (Charleston)

cryptocurrency ok

Used F-35 Stealth Fighter. No damage to landing gear as came in belly-up, engine ingested an eensy weensy bit of mud in non-piloted landing. Nothing to worry about, already pressure-washed it. Retains full stealth capabilities.

Air conditioner works just needs some Freon.

Will require new canopy and Martin-Baker. Includes half box of Crayons left by former occupant. (64 Color)

General Characteristics

Primary Function: Multirole fighter
Prime Contractor: Lockheed Martin
Power Plant: One Pratt & Whitney F135-PW-100 turbofan engine
Thrust: 43,000 pounds
Wingspan: 35 feet (10.7 meters)
Length: 51 feet (15.7 meters)
Height: 14 feet (4.38 meters)
Maximum Takeoff Weight: 70,000 pound class
Fuel Capacity: Internal: 18,498 pounds
Payload: 18,000 pounds (8,160 kilograms)
Speed: Mach 1.6 (~1,200 mph)
Range: More than 1,350 miles with internal fuel (1,200+ nautical miles), unlimited with aerial refueling
Ceiling: Above 50,000 feet (15 kilometers)
Armament: Internal and external capability. Munitions carried vary based on mission requirements.
Crew: One

If the ad is still up the plane is still available. Delivery available.

Absolutely NO joyrides without check in hand, F-35 endorsement and $10,000 fuel deposit.

No trades, MRAPS, Apaches, HIMARS, Javelins. Bring A Trailer --- and Cash!

No lowballs, I know what I've got.

This entry was edited (1 week ago)
in reply to MaggiWuerze

Since the right wing stuff still gets pushed to the front page


I find this hard to believe since it goes against my decades long personal experience using YouTube. The moment I click on a “Ben Shapiro destroys” video, sure - I get plenty more in my feed. But they also go away when I stop engaging. In my experience, YouTube does a great job of recommending me the kind of content I actually like to watch.

Ghostty in review: how's the new terminal emulator?


A few months ago, a new terminal emulator was released. It's called ghostty, and it has been a highly anticipated terminal emulator for a while, especially due to the coverage that it received from ThePrimeagen, who had been using for a while, while it was in private beta.
This entry was edited (1 week ago)
in reply to Pro

I give it a spin every month or so to see how it’s getting on. I’m on macOS.

Every time I walk away unimpressed, despite its maker’s very deserved esteemed reputation.

I’m probably not seeing something. What I do see, however, is that I can’t search my scrollback history, nor can I select text without a mouse.

Also, pressing cmd+, on macOS opens the config inside TextEditor (yes, a separate GUI app) rather than in $EDITOR. It’s a small thing but I couldn’t figure out how to change it. Coming from Kitty, this drove me mad.

I’m not sure who Ghostty is for. My feeling is it’s aiming to be an excellent, polished experience for casual terminal users. But I didn’t see anything that Kitty or just tmux anywhere can’t do.

This entry was edited (1 week ago)

Facebook advertised a professional child kidnapping service to me


Pretty sure they blocked me after I commented, so no screenshot.

The US essentially has no restrictions on what parents can do to their children, or pay to have done to them. These companies will show up at night, and take a child out of their bed at night. They explicitly tell parents not to warn the kid what will happen.

Imagine being woken up in the middle of the night, maybe forced to quickly pack, and then be loaded in a van. You have no idea where you are going or why or who or what is going on. You get taken to a facility which is basically a cult. You might be dumped out in rural Utah, with people that have zero training in wilderness safety, who might punish you by denying you food and water.

Children die in these places all the fucking time. There generally is no state or federal oversight of these facilities - so there aren’t really investigations. These places are havens for child predators.

When I was sexually abused at a similar facility and tried to report it - I was placed on heavy doses of antipsychotics in retaliation. They drugged me unconscious, and then punished me for sleeping during “class.” As an adult, I have involuntary shakes and movements associated with the medical malpractice enacted on me.

These places don’t get investigated, they don’t get shut down. I think Utah is one of the only states with any form of agency that watches over these places. Child protective services won’t go in, health care agencies won’t go in.

Children have no rights in the US. They are the property of their parents, to be disposed of as they wish. And fuckers like this agency are delighted to kidnap children that their parents can’t be assed to parent.

in reply to LandedGentry

Thank you for sharing this. Probably one of the hardest reads of my life, it's incredibly powerful and well written so it conveys the horrors of the experience in an almost visceral way.

It also really helped me understand at a much more personal level how these addiction/reeducation camps and cults break people mentally and emotionally.

Sure, you read about these kinds of things happening in the news, but it never hit home for me what that experience is like until reading this.

Thank you.

Menstrual tracking app data is a ‘gold mine’ for advertisers that risks women’s safety


Cambridge researchers urge public health bodies like the NHS to provide trustworthy, research-driven alternatives to platforms driven by profit.

Women deserve better than to have their menstrual tracking data treated as consumer data - Prof Gina Neff

Smartphone apps that track menstrual cycles are a “gold mine” for consumer profiling, collecting information on everything from exercise, diet and medication to sexual preferences, hormone levels and contraception use.

This is according to a new report from the University of Cambridge’s Minderoo Centre for Technology and Democracy, which argues that the financial worth of this data is “vastly underestimated” by users who supply profit-driven companies with highly intimate details in a market lacking in regulation.

The report’s authors caution that cycle tracking app (CTA) data in the wrong hands could result in risks to job prospects, workplace monitoring, health insurance discrimination and cyberstalking – and limit access to abortion.

They call for better governance of the booming ‘femtech’ industry to protect users when their data is sold at scale, arguing that apps must provide clear consent options rather than all-or-nothing data collection, and urge public health bodies to launch alternatives to commercial CTAs.

This entry was edited (1 week ago)
in reply to Lka1988

Well on iOS there’s the Apple health app. To my knowledge it stores health data locally. I’ll double check now.

Edit: it does store health data in iCloud by default, but according to Apple its end to end encrypted

By default, iCloud automatically keeps your Health app data, including health records, up to date across your devices. To disable this feature, open iCloud settings and turn off Health. iCloud protects your health records data by encrypting it both in storage and during transmission. If you're using iOS 12 or later and have turned on two-factor authentication for your Apple Account, health records are encrypted using end-to-end encryption through iCloud. This means only you can access this information, and only on devices where you’re signed in to iCloud. No one else, not even Apple, can access end-to-end encrypted information.
This entry was edited (1 week ago)
in reply to Pro

The humans in my family who experience menstrual cycles have been pretty happy with Clue who have an explicit promise to never give up your data. YMMV and of course you should evaluate what a promise from this organization means to you.

propitiouspanda doesn't like this.

Why does bitdefender let me download Brave so easily but not Librewold?


So i downloaded Brave on windows 10 a few months ago and i remember that it was pretty easy without any hiccups but last week when i tried to download librewolf a message poped up saying that it may be harmful for your computer even tho i downloaded it from the official source

Is it just me or is microsoft getting more and more desperate to collect our data?

*Edit: Sorry it wasn't bitdefender it was something like Antimalware service executable or something like that which i think is a microsoft product

This entry was edited (1 week ago)

Autonomous User doesn't like this.

Over a month of Linux, my thoughts compiled


edit: I'm using Fedora Workstation 42!

I really like the ability to just search "sleep", "shutdown", "restart", etc. Switching between windows and opening search using either the super key or a three finger swipe up is super handy, on Windows the button opens the start menu (where the search is horrible) and a three finger swipe up can open app switcher, where you have to hold your three fingers to go to another app.

Using GNOME extensions to see power usage, CPU usage, memory usage, etc. is very useful. Weird that the "extension list" addon isn't a thing that's on by default. Feel like being able to see all your extensions is a really important part of having extensions. Being able to see the clock at the top took a bit getting used to but makes so much more sense than having it tucked in a corner. I also like the integrated calendar, much better than Window's version where you are unable to see any of your events, not even as a dot!

Using dnf and flatpak to install programs is very smooth and I like being able to update all my programs at once with just "sudo dnf update && flatpak update"! Being able to see the dependencies and progress bars and download speeds is really helpful too. I don't need to search for programs anymore because of a thing called "fuzzy search". It's like magic!

GNOME's UI looks much cleaner than Windows, everything is actually cohesive. It's not a mix of flat and glass and clear and ancient. It's all adwaita. (that's what you call it, right?)

Something weird was not having the minimise and maximise buttons. I had to enable those myself, which is a bit odd. Now that it is enabled it works fine.

I also really like being able to easily customise themes (everforest) and icons (Papirus!). And if GNOME is considered "not very customisable" in the linux world, KDE, Cinnamon, etc. must be even more customisable! I'm happy with GNOME though, so I probably won't switch DE anytime soon. Maybe when I get a new computer I could try out KDE.

App compatibility was no problem. All the apps I used before (thunderbird, obsidian, joplin, vscodium, godot, etc.) all have linux versions, and the ones that don't (like SumatraPDF and AIMP) have linux alternatives. Okular and Gapless has been working great!

There were very few issues, but there were some nonetheless. OBS Studio footage was very choppy as hardware decoding wasn't working, and I had to dig deep into forums to install drivers for my intel igpu. Now it works fine, so that's good! I also had an issue with a VPN app, but they support an app called "Clash Verge". They only note the Windows and Mac versions on their site, but clash verge has a linux app too, and it works quite well!

I don't play many games, mostly Minecraft and some retro titles. mGBA works fine on linux, and Minecraft java edition supports linux. I've also tried a bunch of linux games like SuperTuxKart and Xonotic and, considering they were made around a decade ago or so (I think) they were really fun! My other games ran fine with Steam installed, Proton and Wine makes them run fine!

I'll be sticking with the penguin as it's fun, playful, and is much cuter than both the window and the apple. 😁

This entry was edited (1 week ago)

Browsers are complicit in browser fingerprinting.


Everyone talks about how evil browser fingerprinting is, and it is, but I don't get why people are only blaming the companies doing it and not putting equal blame on browsers for letting it happen.

Go to Am I Unique and look at the kind of data browsers let JavaScript access unconditionally with no user prompting. Here's a selection of ridiculous ones that pretty much no website needs:

  • Your operating system (Isn't the whole damn point of the internet that it's platform independent?)
  • Your CPU architecture (JS runs on the most virtual of virtual environments why the hell does it need to know what processor you have?)
  • Your JS interpreter's version and build ID
  • List of plugins you have installed
  • List of extensions you have installed
  • Your accelerometer and gyroscope (so any website can figure out what you're doing by analyzing how you move your phone, i.e. running vs walking vs driving vs standing still)
  • Your magnetic field sensor AKA the phone's compass (so websites can figure out which direction you're facing)
  • Your proximity sensor
  • Your keyboard layout
  • How your mouse moves every moment it's in the webpage window, including how far you scroll, what bit of text you hovered on or selected, both left and right clicks, etc.
  • Everything you type on your keyboard when the window is active. You don't need to be typing into a text box or anything, you can set a general event listener for keystrokes like you can for the mouse.

If you're wondering how sensors are used to fingerprint you, I think it has to do with manufacturing imperfections that skew their readings in unique ways for each device, but websites could just as easily straight up record those sensors without you knowing. It's not a lot of data all things considered so you likely wouldn't notice.

Also, canvas and webGL rendering differences are each more than enough to 100% identify your browser instance. Not a bit of effort put into making their results more consistent I guess.

All of these are accessible to any website by default. Actually, there's not even a way to turn most of these off. WHY?! All of these are niche features that only a tiny fraction of websites need. Browser companies know that fingerprinting is a problem and have done nothing about it. Not even Firefox.

Why is the web, where you're by far the most likely to execute malicious code, not built on zero trust policies? Let me allow the functionality I need on a per site basis.

Fuck everything about modern websites.

This entry was edited (1 week ago)

Simple Blog options?


Anyone have any recommendations for Blog software?

I was considering for a while just using a mastodon instance as my blog because I just kinda wanna sign in and upload my papers that I've written. I was pretty close with Hugo. I'd rather not have to build the site everytime I upload and I want to self host and not use Github actions. I think I still could do it since I like using Cloudflared tunnels.

What is all out there?

Why should I continue to financially support the development of Lemmy when the developers operate .ml, an instance that is a prime example of arbitrary censorship?


Please convince me that I should continue my support or advice what I can do. I'm prepared to do my part, but I can only do so if I can be sure that my support is not going to people who think arbitrary Censorship is alright (needs to be based on objective community rules and not on the political agenda of mods).
This entry was edited (1 week ago)
in reply to LandedGentry

I didn't realize that I was banned from .ml. Am I? Anyway, that's not the point. My point is to support technology that allows free expression, especially since that's not the case with mainstream platforms. And by free expression of opinion, I mean what is commonly understood by that term – not baseless insults, accusations, conspiracy theories, or anything else that lacks any factual basis. I mean the free expression of legitimate, debatable opinions. That should be the most natural thing in the world.

Got any security advice for setting up a locally hosted website/external service?


Setting up a personal site on local hardware has been on my bucket list for along time. I finally bit he bullet and got a basic website running with apache on a Ubuntu based linux distro. I bought a domain name, linked it up to my l ip got SSL via lets encrypt for https and added some header rules until security headers and Mozilla observatory gave it a perfect score.

Am I basically in the clear? What more do I need to do to protect my site and local network? I'm so scared of hackers and shit I do not want to be an easy target.

I would like to make a page about the hardware its running on since I intend to have it be entirely ran off solar power like solar.lowtechmagazine and wanted to share technical specifics. But I heard somewhere that revealing the internal state of your server is a bad idea since it can make exploits easier to find. Am I being stupid for wanting to share details like computer model and software running it?

This entry was edited (1 week ago)
in reply to monogram

Please tell me more, which firewall would you recommend that plays nice with Docker?


Firewalld

No NAT?


Another user in this thread suggested DMZing, so combine your advice with theirs and boom. It’s not uncommon, and it’s fine if you firewall the box yourself. Most people don’t knowingly choose to use a firewall that they don’t intend to work, like you would.

why would you copy paste a docker compose without reading it?


There’s more than one way to use docker. Spinning up an official mysql image using the official docker run OR docker compose calls suggested by the docs would start up a server wide open to the entire internet if DMZ’d.

This entry was edited (1 week ago)

[Combat] Failed attempt by a Russian Pantsir-S1 air defense system to shoot down a Ukrainian AN-196 Liutyi UAV over the Tatarstan region this morning.


Mirror

https://t.me/karymat/11143

in reply to k_rol

According to Wikipedia, the Pantsir shoots small missiles with radar or optical guidance. No idea why it missed.

I watch this one history yt channel that goes through the moment to moment details of various battles. One thing I learned from that is that things just go wrong all the time in wars. Missiles fail to launch, radars malfunction or aren't properly calibrated, a manufacturing defect turns a potent weapon into a dud, etc.

White House responds to California city terminating contract with ICE


DHS Assistant Secretary Tricia McLaughlin told Newsweek that the City of Glendale's decision was "deeply disturbing," and accused state officials of siding with criminals over public safety after unrest in Los Angeles.


Just so people are aware, this is the same rhetoric/same regurgitated talking points being used against "progressive" policies in blue cities within red states all over the country.

They are banking on an escalation of physical violence and confrontation that they will use as an excuse to establish a permanent federal and military force in California that will not be subject to any California state laws.

Why do I believe that? Because its how it happened in my own city to establish a permanent state police force that can't be regulated by any city or local ordinance.

They instigate and then argue that progressive policies have resulted in an emergency and chaos, that leaves them no choice but to step in and fix things by taking control.

They have been using takeovers of blue cities within red states as a testing ground for this kind of thing since Trump's first term.

This entry was edited (1 week ago)
in reply to dinren

it’s just an example of state overreach in a violent manner. one of many. none are appropriate when one truly considers things like “rights” etc.

the civil war was probably the last time the state was able to “legit” use violence because it was to quell an actual secession by a formal militia of more than a million traitors and terrorists.

This entry was edited (1 week ago)
in reply to flandish

Asserting that the state has no legitimate interest in using limited violence (i.e. tear gas) to execute lawful search and arrest warrants against heavily-armed, recalcitrant pedophiles is truly one of the takes of all time.

The Bundy standoff, the SLA, and the Waco Siege are categorically different from the firebombing of Philly or the Tulsa Massacre to anyone with a brain.

This entry was edited (1 week ago)
in reply to DominusOfMegadeus

I'm pretty happy with Downie (and Permute to directly convert media to whatever format I like). So far it downloads everything I throw at it. And you can create custom download handlers (using JavaScript) to make it work (without interaction) with sites that are currently not supported and would spawn the user-interactive downloader.

If you just want to download and don't care about a nice GUI, yt-dlp probably has similar features.

Russia’s tech company VK unveils WeChat clone built on Putin’s orders: the app has mic and camera access, gathers user data, and shares it with the state


cross-posted from: lemmy.sdf.org/post/36376926

Archived

On June 4, during a meeting with government officials, Vladimir Putin stated that all public services must be moved to the national messenger app called Max. According to Minister of Digital Development Maksut Shadayev, the multiplatform system is already operational.

[...]

The Max app — a Russian equivalent of China’s WeChat — was unveiled by the tech giant VK in late March. At present, it features a messenger, a chatbot builder, a payment system, and mini-apps. On June 5, VTB’s digital bank launched on the platform.

To register, a Belarusian or Russian SIM card is required — which, as The Insider noted, foreigners can no longer obtain without submitting biometric data.

As stated in the Max app’s privacy policy, the platform will collect data on:

  • user devices
  • IP address
  • operating system
  • browser
  • location
  • internet provider
  • contacts from the address book
  • all user activity within the service
  • information obtained through the camera or microphone, if the user grants the app access (most users will, for example, in order to record voice messages)

Other messaging apps collect such data as well, but there's a catch. The Max app's privacy policy explicitly states that it may share this data with the “company's partners” as well as with “any government or local authority.”

[...]

Drama on Fedi. Framasoft vs Firesidefedi.


Source: peer.madiator.cloud/w/wuqKuurL…


Episode 20 - Booteille - Framasoft - Livestream 2025-05-27


Welcome Fedi Friends to the episode 20 of Fireside Fedi! I'm your host ozoned. Fireside Fedi is a show about folks within the Fediverse. If you're seeing this, you are a part of the Fediverse.

With me today is Booteille! Booteille was a volunteer to Framasoft for 3 years, then became a co-president, a volunteer position as well, and then got hired by Framasoft and stepped down from his volunteer position . Booteille seems to wear many different hats around Framasoft. From interviews, conventions, building donation campaigns, to sysadmin tasks, website tweaks, etc.

Booteille describes their goal with Framasoft is "to help as much as I can the organisation in our goals: raising awareness about digital issues and helping to build a society fitting our values."

I'm very excited to finally have this show as we've had to reschedule numerous times. Schedule conflicts, then I was sick for weeks, and booteille is finally getting over being sick as well.

framasoft.org
Donation Link - support.framasoft.org
Framasoft Mastodon - framapiaf.org/@Framasoft
numerethique.fr/
blog.dreads-unlock.fr/
Mastodon - framapiaf.org/@booteille
degooglisons-internet.org/en/
support.joinpeertube.org/en/


This entry was edited (1 week ago)

Lemmy.zip 2nd Birthday Giveaway! 🍰


Hello all!

To celebrate Lemmy.zip turning 2 years old, we are once again hosting a small giveaway to say thank you for being here ❤️

We're giving away 3 prizes to 3 lucky winners. This will be 1 x £25 Steam gifts, and 2 x £10 Steam gifts.

The giveaway will be open for 48 hours from 12:00 UTC on the 10th June 2025, to 12:00 UTC on the 12th June

You can enter by making a comment in this very thread! Your comment can say or be absolutely anything you want (within reason!)

Once you've made a comment, you should get a message back from ZippyBot confirming you've entered and a ticket number. For transparency, at the end of this we'll publish the entry list and ticket numbers.

You must be a Lemmy.zip user to enter (comments from anyone else will be ignored!) and you will need a Steam account and be happy to send me your username so I can gift you the value via Steam. Your Lemmy.zip account must have been created before the 9th June 2025.

At the end of the giveaway, I'll lock the thread and Zippy will pull three random entries. The first username pulled will win the first prize (£25), and the other two users will win the other prizes (£10).

I've put a few FAQs in this spoiler tag if you want to know more:


FAQs - PLEASE READ!

::: spoiler FAQs
- Q) Can anyone enter?
- A) You must be a lemmy.zip user, have a steam account, and your lemmy.zip account must have been created before 9th June 2025


  • Q) Can I have a giftcard for a different platform, i.e. xbox or playstation?
  • A) Unfortunately not. Those platforms (to my knowledge) don't allow me to purchase a giftcard in the UK and you activate it anywhere in the world. Steam allows currency conversion on gifts.

  • Q) How quickly will I get my prize?
  • A) Steam requires that someone must be on a user's friend list for 3 days before giftcards can be sent, therefore I will share my Steam profile with the winners (or vice versa) and after 3 days of being friends on Steam, I will send the gift over. (Unless you live in the UK, in which case I can send you a code within 24 hours)

  • Q) I think my entry was valid, but I didn't get a reply from Zippybot with my ticket number. What do I do?
  • A) Send me a message asap! You can try commenting again too.

  • Q) Are Lemmy.zip user donations funding this?
  • A) No, just making it clear here that the donations to Lemmy.zip only ever go towards the server and Lemmy.zip infrastructure. The funds for this are coming from my wallet 😀

  • Q) How does Zippy select the winners?
  • A) Zippy randomly shuffles the list of entrants in the DB. It then randomly shuffles the list again in Python. Then it randomly selects 3 winners from that double shuffled list. You can see the code for this here.

  • Q) What if something goes wrong?
  • A) If for any reason something goes wrong during the giveaway, it will be paused until it can be resumed. If too much time lapses, the giveaway will be restarted.

:::

This entry was edited (1 week ago)