Posts
Why can't I change the terms and conditions in a pre-signed contract with a corpo?
It's common to receive a mail from some service that they're changing the terms and conditions of their service (internet provider, gmail, etc.) These changes are unilateral and can be about anything, from their privacy policy to the money they intend to charge me.
Why can't I unilaterally send them a mail and say, I am changing the terms of my patronage and will now insert my new policy (pay only xx amount, or demand a mint Chico chip ice cream every Tuesday)?
How do I survive the US immigration?
I will be entering the US in October to work for about a year and half as a visiting researcher. I will be accompanied by my partner and his two children.
I am very scared on what to expect at the border because of all the stories I hear about detentions, refusals, etc.
My concerns are:
- Do they ask everyone to unlock their phones and download EVERYTHING in there for later analysis?
- Related to point 1., refusing to unlock and give access will make you suspect and they refuse entry?
- Do they also ask you to unlock your laptop? I have stuff encrypted there as I often have to process sensitive patient data for a project I am working.
- Do they do a complete biometric data collection of you and the kids?
Also, how do we conduct ourselves at the border entry to avoid getting absolutely shafted?
P.S.: I am not in a position to call off the trip. Visa is ready and tickets are brought.
VPNs v/s TOR
I'm fairly certain this post might end up revealing my lack of knowledge on this topic rather than being a sound technical question, but here goes:
Why are most people keen on VPN services when TOR was present all along? Is it just because TOR is "slower" than VPNs or some other reason related to access?
Here are the points that confuse me:
- Many services block TOR.
True, but that's the case with VPNs too. Netflix, Spotify, or some government website (won't specify which country) will give you a tough time when they detect VPN use.
- Your ISP will know you used TOR.
Sure, but they also know that you used a VPN. Not sure why so many people use this argument. Besides, if you use TOR bridges, your ISP won't know it.
- VPNs are super helpful when trying to circumvent CG-NAT.
And you'd be right there. Accessing clearnet to serve or host a service is much easier with a VPN. But then again, most people aren't trying to circumvent their CG-NAT to host service. They're trying to use the web more generally.
This post was inspired by my utter disillusionment of Mullvad.
[Solved] Why can't I apply SPF50 sunscreen twice to get SPF100 protection?
These creams have some chemical that blocks the UV with some capacity, say a factor of 50. Why can't I apply two layers of this cream to now get a 100 factor equivalent protection?
I asked the chemist at the store and they said it's not how it works and that the highest protection factor they have is 75 (which was super expensive).
What gives?
Edit: Thank you for those super informative answers.
Are ISPs responsible for bots having residential IPs or is this a user problem?
I'm trying to understand the bot problem in the internet and finding more ways to defend myself. One thing that I can't seem to understand is why most bots, scrapers and crawlers seem to have residential IPs.
- Is it that ISPs are being paid by tech-bros to assign them these IPs?
- Is it that residential devices have been hacked /contain malware that does this?
- Is it trivial for companies to assign themselves residential IPs?
- Paid volunteers are doing this for AI companies?
Or is there is some other reason for this?
Obviously this is a problem because one can rotate / cycle through residential IPs and if I aggressively block each offender in my logs permanently, then the next person assigned this IP who may be a legitimate user will be unable to access my site.
Security considerations about hosting Immich from home
So far, my self-hosting has been limited to Pi-Hole, and a static website. I now want to try out something new, an Immich server.
I have a static IP from my ISP, so I don’t need to rent out a VPS. However, given that this IS a home internet, I want to be extra sure that it is going to be secure.
In my existing website, I use Fail2Ban + BadBotBlocker + Anubis + Nginx rate limits to protect it from scrapers, bots and malicious users, and it works well. With photos (especially family photos) at stake, I just want to know more on how to protect my server.
Add: thanks for the helpful replies. I will be sharing the photos with family, many of whom live abroad.
Grandia2, Sims3 and Cesar3 on Linux?
My wife has a windows 10 laptop that works very well (hardware). However it seems that it won't support win11. Rather than trying to tinker and make it install Win11 without the TPM support, etc., I want to install Linux Mint.
There are three games she adores and wants them to work if I installed Linux:
- Grandia 2 installed via Steam. Will proton support it?
- Sims 3 installed via Steam. Willnproton support this as well?
- Cesar 3 (which runs in a Win7 VM in windows setup by her tech savy friend). She has those files and the exe files etc. Can that be run on Linux? I'm reading about DOSBox, but not sure if that is the right tool.
I can rip out windows and go full Linux on her machine if there is support for running these three games. Any chance for me on this?
Having trouble with OnePlus5T wifi drivers
I am trying to get my OnePlus 5T to work as a headless server to host AdGuardHome, a static site, and a couple of other small stuff. However, I am having a lot of trouble with establishing a stable internet connection because I seem to lose the wireless wlan0 interface completely after reboot.
Basic details
- Device: OnePlus5T (codename: dumpling)
- Method of flashing: pmbootstrap (version: 3.10.1) on a Linux machine.
- PostmarketOS kernel used: linux-postmarketos-qcom-msm8998
- Repositories used: 25.12 (mainline)
- Init system: OpenRC
- WiFi backend: wpa_supplicant (default)
- GUI: Console (no keyboard)
Problem faced
I ssh into the device with USB and give wireless connection successfully with nmcli as shown here (https://wiki.postmarketos.org/wiki/Using_a_phone_as_a_server). After a set a static IP (with nmcli modify), installing AdGuardHome, etc. everything works for a while. Then when I reboot the phone (or keep it off for more than 2 h and start), I seem to completely lose the wlan0 interface.
Diagnoses
-
I tried
ip aand found thewlan0completely missing. -
I tested to see if the drivers were indeed present:
$ apk info | grep firmware
device-oneplus-dumpling-nonfree-firmware
firmware-oneplus-msm8998
firmware-oneplus-msm8998-openrc
firmware-qcom-adreno-a530
linux-firmware-qca soc-qcom-msm8998-nonfree-firmware
soc-qcom-msm8998-nonfree-firmware-openrc
- I tried to look at the logs with
dmseg | tail -20:
[ 17.116168] qcom,apr 17300000.remoteproc:glink-edge.apr_audio_svc.-1.-1: Adding APR/GPR dev: aprsvc:apr-service:4:3
[ 17.116239] qcom,apr 17300000.remoteproc:glink-edge.apr_audio_svc.-1.-1: Adding APR/GPR dev: aprsvc:apr-service:4:4
[ 17.116262] qcom,apr 17300000.remoteproc:glink-edge.apr_audio_svc.-1.-1: Adding APR/GPR dev: aprsvc:apr-service:4:7
[ 17.116284] qcom,apr 17300000.remoteproc:glink-edge.apr_audio_svc.-1.-1: Adding APR/GPR dev: aprsvc:apr-service:4:8
[ 17.186076] q6asm-dai 17300000.remoteproc:glink-edge:apr:apr-service@7:dais: No dais found in DT
[ 17.186084] q6asm-dai: probe of 17300000.remoteproc:glink-edge:apr:apr-service@7:dais failed with error -22
[ 1830.969129] ath10k_snoc 18800000.wifi: supply vdd-3.3-ch1 not found, using dummy regulator
- I tried
cat /sys/devices/platform/soc/18800000.wifi/power/runtime_status
and got the output: unsupported.
I tried
sudo nmcli con up MyHomeWifi
Request
- Help get the wifi drivers working properly
- I have a “Portronics” USB-to-Ethernet adapter, but it seems the OS doesn’t recognise that either. So using it as an alternate route for internet is not possible. Please help with that as well (or alternatively) if possible.
Can Anubis and Iocane be linked?
This may sound like a weird thing to do, but I realised that many crawlers and bots are somehow still able to get past my Anubis. I presume they have gotten smarter and are capable of using JavaScript.
To counter this, I want to link my Anubis to an Iocane setup such that:
Internet > nginx reverse proxy > Anubis > Iocane > my site/app
My hope is that two different filtering mechanisms (one of which will actively poison and waste the bot's resourced) will protect my system better.
I thought I'd ask before actually trying out something like this.
What's up with expired domains being unavailable?
A domain name I was interested in expired in January this year. It was previously registered at Squarespace.com.
Why is it still unavailable to purchase despite being more than a month since its expiry?
Not sure if relevant but I checked the expiry date at: whatsmydns.net/domain-expiration
Help making sense of IPs and A records
I am trying to host my first website + service.
#My server setup
I have a static webpage in server 1. A gotosocial installation in server 2. They are connected to a reverse proxy (server 3). This has a public IP of (not exact) 204.230.30.104.
#My router setup
I can open ports 80 and 443. I just don't know to which IP (I'll explain why down).
#My registrar
In have a domain, say 'newexample.com'. The @ has an A record for the IP (not exact) 208.145.80.33
#My confusion
- If I want to make a subdomin for GoToSocial like 'gts.social.new example.com', do I use CNAME or A record?
- If I want to serve the static website to be served at 'www.newexample.com' , do I remake an A record for www.newexample.com ?
- There appears to be a CNAME in my DNS record already by the registrar for www that goes to some "redirect" link. What's up with that?
- How do I make the domain connect to my server and how to make the server connect to my domain properly?