Spyke

Replies

Comment on

I’ve just released Gatekeeper 1.6.0. It’s a single executable that turns any Linux machine into a home gateway. Now with realtime traffic graphs, LAN autoconfiguration, full cone NAT and better looks.

Incredible amount of work, respect.

If you are lacking ideas for the super long term I could suggest you:

Any kind of ids/ips (intrusion detection system) Deep inspection packet to detect any vpn or crypto tunnel Ability to create a vpn link to another instance of the program (to link geographical disperse nodes)

And many other things that honestly I am ashamed of asking :)

Comment on

what's your experience with paperless?

Super good, it is increíble useful and the ability to find any document in almost any place in seconds in awesome.

Once this is said, you need to stick to a process and it is time consuming, and of course, you need to manually review the automatics tagging feature.

So, It is not a set and forget like most of the people expect

games

Comment on

*Permanently Deleted*

I am not going to be the one to try to stop you but you need to keep in mind that games/sw piracy comes with great risks.

You need to execute anti cheat / drm / copyrighted stuff and this is always a big door open to malware.

Be cautious out there, it is not a pleasant walk

Comment on

Software that supports your body should always respect your freedom

Reply in thread

I couldn't disagree more with you. If you are running something REAL life critical the moment there is a patch you install it and deploy as fast as possible. And if it contains any severe patch it is even the vendor who recalls all the equipment with service bulletin and advisory letters.

With life critical you don't wait the bug to appear because It maybe too late to avoid deadly consequences.

Comment on

Trying to make a phone proxy

What you need is a sip server / interface for making VoIP call through internet, there are many implementations and servers, selfhosted and paid. Pick up one you like.

Please, be aware that the quality of the voice call depends and a lot of the data rate. Keep this in mind uif you are in remote locations with poor coverage.

It is always recommended the asterisk + the freepbx for the gui. Please be aware that I don't have experience with those systems

Comment on

Internal network monitoring

Segment the network as much as feasible, forbid the communication between the segments via FW rules, and set an alert when those rules are triggered.

For example: your dmz should never initiate any type of communication with your lan segment, your lan segment should not try to access services outside ports 80/443, your dns should log all resolutions performed and it would be nice to have at least a black list.

None of them should have dns over tls, and for specific hosts and networks segments, new domains with very looong active but idle connections should trigger an alert.

My personal opinion is that for a homelab is not realistic to perform a dpi to check that there is not an active attack ongoing, neither from the raw processing power, either from the human effort side, your best chance is to alert when something unusual is happening and then adjust your rules of the are false positives

Comment on

Thoughts on cochlear implants?

I am not deaf and fortunately nobody from my family is.

But I have a friend who is a electronic technician and he activates those implants, make some checks up after a month and make sure the fine running is adapted to your needs.

He is under paid, needs to travel a lot, working on Sundays when needed and some times his working hours are long and exhausting.

He still says he has the fucking best job of the world and he is not thinking in switching in a million years.

I guess they work good and they are quite rewarding if just the technicians are this devote to the job

Comment on

*Permanently Deleted*

Reply in thread

Not good, you are going to lose a lot of stuff, from personal relations, connections to your wife and even your health.

I hope (really) your are not in a compromised financial situation and this is really temporary. If so, it is OK but you need to have a plan to reduce the hours in the foresable future.

If this is not the situation, then learn how to disconnect from the work in the spare time and spent quality time when possible, also do cardio. It helps. A lot.

When you are young you can really chew everything it is throwed at you, but it is not true anymore when you are past the 40s.

Take care of yourself, nobody else is going to do it.

Comment on

Backups: Am I doing this right?

Some clarifications :

The 3 2 1 rule applies only for the data. Not the backup, in my case I have the real/live data, then a daily snapshot in the same volume /pool and a external off-site backup

For the databases you got misleading information, you can copy the files as they are BUT you need to be sure that the database is not running (you could copy the data and n the middle of a transaction leading to some future problems) AND when you restore it, you need to restore to the exact same database version.

Using the export functionality you ensure that the data is not corrupted (the database ensure the correctness of the data) and the possibility to restore to another database version.

My suggestion, use borgbackup or any other backup system with de duplication, stop the docker to ensure no corruptions and save everything. Having a downtime of a minute every day is usually not a deal breaker for home users

Comment on

Cooling stuff does not require any energy!

No, it is not, your premise is false (in our real world. TM.) but your reasoning is good.

Energy does not vanish, you need a process to remove energy of a system.

Think in the planets orbiting the sun or the energy contained in a damm with millions liters of water. The energy is not dissipating itself, it is constant, forever.

So as long as the system is not disturbed, keeping the system in the same state is energy free because you only need energy to alter the system. Even of the energy distributions is not evenly balanced through it.

Disclaimer about the real world

Comment on

What access points do you use?

Fritzbox boxes.

They tick all the checkboxes

  • good standards support (including dect protocol if you want to have an ip phone or even iot protocols)
  • fast wifi speeds
  • cheap (at least for the second hand in ebay)
  • super stable, never had a problem with them in 5 years or more
  • fast roaming support out of the box

It is a well known brand in Germany but pretty unknown outside that country. Honestly it is the best bang for buck I was able to get.

Honestly, I would spend 10 minutes checking on them