hayalci

@hayalci@fstab.sh
3 Post – 45 Comments
Joined 11 months ago

BBC has just started doing that at https://social.bbc

What is FUTO?

FUTO is an organization dedicated to developing, both through in-house engineering and investment, technologies that frustrate centralization and industry consolidation.

https://futo.org/

No need for using sensational/clickbait headlines like this.

1 more...

The thing you want is "glue records" the upper level server would serve ns1.example.com (this is an approved domain for example use, better to use example.com than making your own example up) as the authoritative name server. Then provide the glue record which says "ns1.example.com is at IP address X".

It should ask for IP addresses as well as hostname. Otherwise they only assumed people will "host" their domain in another hosted, as opposed to self-hosting.

In that case (and in any other case) change your registrar to someone else who supports glue records.

5 more...

Lots of people contributed really good answers, so I don't have anything valuable to add to their answers. But I wanted to point out for your detailed question, you include what you have done, what is your understanding and what are your shortcomings clearly. As opposed to a lot of posts with vague, detail-challenged narratives, that's a top notch post.

And the community delivered by giving good answers, so go community!

Also, you didn't just ghost after the initial post and interacted.with the people who graciously donated their time, so another bonus point there, as well.

I use porkbun.com for my domains, which is excellent, and also has glue record support.

https://kb.porkbun.com/article/112-how-to-host-your-own-nameservers-with-glue-records

1 more...

A good answer to a "why?" question is "why not?" This can be a great learning or practice opportunity for redundant network links and other interface challenges.

Same here.

https://longhorn.io/ for the curious

CRISPR to the rescue!

+1 on not using containers.for Network routing stuff That way lies pain and misery.

Yeah, that's the key point. They weren't trawling all the servers, they probably had a wiretap order for one specific server. As a legal business, you can't just say no to police because you don't like mitm.

There are STEREO and Osiris rex already in L4 and 5

https://en.m.wikipedia.org/wiki/List_of_objects_at_Lagrange_points

3 more...

Ah true. Companies are great at hiding the open web that they (ab)use.

1 more...

in addition to "dedicated Nas + compute node" and "just use a desktop" suggestions, there's the microserver option in between. Small, but has enough power to run stuff other than storage.

Hp proliant microserver is what I use, you can try getting a previous generation from second hand market.

https://www.hpe.com/us/en/product-catalog/compute/proliant-servers/pip.proliant-microserver.1014673551.html

VPN software usually is built strong to begin with, and any vulnerabilities discovered will be promptly fixed as well, so updating frequently should suffice. (Why not automate it with unattended-upgrades package?

Using a random high port number will probably hide it well enough for Internet-wide port scanners as well.

if you want to be extra paranoid, you can hide the VPN service behind a port knocker as well.

3 more...

Good point, kernel updates should be paired with reboots to get kernel patches applied quickly.

Yes wireguard would only accept connections clfrom clients with known certificates, but this is "belt and suspenders" approach. What happens if there's a bug in wireguards packet parsing or certificate processing? Using port knocking would protect against this —very remote— possibility.

1 more...

6GB is more than enough for many desktop environments. Plus, a server wouldn't have any anyway. not booting the Ubuntu installer seems like a bug, or other non-resource problem. if you try with a newer installer, or some other distro, that computer can host many things.

Yeah porkbun is good.

To see how the glue records work, you can run dig +trace example.com

This answer goes into detail how it works behind the scenes.

https://superuser.com/questions/715632/how-does-dig-trace-actually-work

Random idea, continuously ping the router from the laptop so it doesn't "forget" that the laptop exists on the WLAN?

(I know you mention the laptop can still reach out when you try, but maybe the trick is to keep having traffic to-from the laptop continuously)

Google Podcasts also supported entering RSS feeds manually.

4 more...

Otoh, Spotify (and probably apple and other big corps) don't even allow you to add RSS URLs, so I wanted to point out they Google was one of the big players which was more open.

Nope, not realistic for "mirroring". Federated could be possible, but I wouldn't have high hopes about (good) latency and coverage.

You got an excellent short answer here, but for a more extensive article check out https://itsfoss.com/compile-linux-kernel/

keepass2android is worth a try as well.

"underpowered" routers are usually underpowered for multiple high bandwidth wireless connections. if you disable the wireless, shoving bits over copper would -usually- be efficient enough to not be the bottleneck.

Did you consider keeping the services closed to the outside world and using tailscale to access them? Doesn't work well if you want to give access to a bunch of people, though.

You can use Snikket with other servers too, there is no restriction or special sauce. It's mostly a fork of Conversations.

Lots of relevant comments in this post https://aussie.zone/post/4286731

I have been using porkbun.com as a domain registrar.

For email hosting, self-hosting is a lot of effort. If you just want the damned thing to work. I've heard good things about Fastmail, and personally I'm using migadu.com. it's $19/year for micro.

Use any imap client, or if you want to keep using what you're using Gmail and Outlook and Apple mail apps w all support your new personal account over imap as well

Their own doc, sure why not.

Any other context where there's a giant with the same name. No, please at least write it out expanded once.

RFC 2606 is your friend ;⁠-⁠)

https://datatracker.ietf.org/doc/html/rfc2606

You do you.

ZFS has a "copies=N" setting, but documentation and discussion I can find say there's no guarantee that the copies will end up on different devices (vdevs in ZFS parlance)

Check out this previous comment

https://lemmy.ml/comment/9168742

i also think that it's overkill, especially for a minimalistic tool like wireguard. That's why I mentioned "if you want to be extra paranoid". This forum is for learning, and this question is an open ended learning question, hence, an opportunity to learn about port knocking, even if the actual real life benefit of that would be minuscule.

I recommend https://migadu.com. not free, but the lowest price tier has lots of features, unlimited mailboxes etc.

Use https://combine.fm paste in a tidal link and share the resulting page, people can click on the service they have to listen to the same song.

Use https://combine.fm paste in a tidal link and share the resulting page, people can click on the service they have to listen to the same song.

Huh, I wasn't so sure about Osiris-Rex but I totally remembered STEREO A & B as stationary at L4 and L5.

Note to self: re-read the sources you quote.