Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)L
Posts
4
Comments
167
Joined
3 yr. ago

  • I'm not an expert so take this with a grain of salt, but it seemed to me that the driver approach is the more useful abstraction and also the more modern, and that the old one will get eventually phased out (or stay there under the hood, out of the way).

    I did see that some tutorials started out with "figure out if you have a hardware switch" but this way I didn't have to care.

  • I did initially do it with the firewall alone. I created a "br-nvr" device, moved lan1 from br-lan to it, and used br-nvr as the device for the NVR interface and firewall zone, then selectively let my phone and the NVR app from the LAN zone access the camera ports with traffic rules.

    Everything else about the interface and zone stayed the same as they are now. That's what's great about the OpenWRT abstractions. I really appreciated how easy it was to get things working with the firewall zones alone, don't get me wrong.

    The one major issue with that approach was that the NVR app is outside the NVR zone and I wanted it in there.

    • It makes broadcasting a non-issue, (I really don't want to have to learn how to do cross-network broadcasts and I understand they're fraught with problems anyway).
    • Better security with less complexity. A single camera can have like 3 ports that need to be made accessible, and different cameras will have different ports. Making and maintaining traffic rules for multiple cameras would rapidly turn into a nightmare.

    With the NVR app in the same isolated network as the cameras they can do whatever they want in there without needing explicit rules.

    But I couldn't put the NVR docker container into the NVR network, because it lives on a machine on the LAN network, and you can't have the host machine on one network and a app on it in another network, with a single physical cable... unless you use tagged VLANs.

    There are also some potential annoyances in the future if I ever want to move cables around the ports or make more complex setups, the VLAN abstraction makes things easier.

  • In this particular case it wasn't Docker that gave me the headaches, it was OpenWRT and wrapping my head around tagged VLANs.

    Once you have the VLANs working on the router and the tagged interfaces up on the server, pointing a Docker network or an LXC at the eth0.100 interface is equally easy.

    Now, when I first got the camera I was considering adding a secondary network card to the server and plugging the camera into that, so it would be directly hardwired into the machine running the NVR. If I had done that I was given to understand that taking ownership of a physical NIC would have been much easier with LXC than with Docker.

    (We'll never know because I couldn't find the PCI network card.)

  • Selfhosted @lemmy.world

    How to physically isolate a camera with OpenWRT, tagged VLANs and Docker

  • It's virtually unknown in the Linux world too. It's literally something they made up overnight and are trying to astroturf.

    I'd say "what a time to be alive" to see the day someone considers it worth astroturfing a Linux distro, except there's probably some nefarious shit behind it.

  • I'm not OP but yeah, basically. People who are passionate about a specific topic will know what's up in that area.

    I can name half a dozen of the most popular Arch-based distros off the top of my head because... they're actually well-known. Meaning they've been around for years, I've used several personally and can argue their pros and cons, and they feature prominently in objective lineups like the Steam Hardware Survey. Omarchy is none of these things.

  • Paywall.

  • Which is why, hopefully, this union will progress to being a national IT union and not remain a strictly one-time Microsoft thing.

  • They'd have to effectively close down the Czech branch of the company.

    There used to be shenanigans where an owner would shut down one company and continue as another but goverment labor watchdogs have gotten wise to such methods. And it would be ridiculously overt for a corporation like Microsoft especially under these circumstances when they're in the full spotlight.

    No, they'll try to "lobby" the politicians as usual and push for union-unfriendly legislation, try to limit union applicability to certain industry branches, and if all else fails pull out of Czech Republic and hope the rest of Eastern Europe doesn't follow suit.

  • Hetzner + a HDD backup would basically get you to 3-2-1.

    As a rule of thumb I'd keep the SSDs for live data and HDDs for backup.

    Hetzner supports multiple good backup tools so you have options, and their prices are decent.

    But please stick to Restic (or Borg) because they're actually designed for backup and have built-in encryption, compression, deduplication, integrity, recovery etc. Don't use "sync" tools like rsync.

    Please, please, please assume that any of the SSDs and HDDs and cloud storage can dissapear at any time. Sit down and run some scenarios on paper, see what you'd do in each case.

    Also a good idea is to sit down and categorize all your data on a scale of "how much my life would be over if I lost this".

    Sometimes super-essential data can be very small. For example a list of things to do in case of untimely demies (a "digital will") can be a single text file that can be easily stored (encrypted) with family members. EncryptPad is a cross-platform text editor that uses open, standard encryption and can use a simple password.

    If you need an extra form of backup media for ultra-essential data, Blu Ray optical discs are still an option. They are specifically designed for this and an USB optical writer is cheap.

    Last but not least, store your "cold" backups in proper storage enclosures. For HDDs I like Orico padded boxes, for Blu Ray's use a "CD wallet".

  • Who wants to bet we'll see attempts to nullify votes that don't fit the declared affiliation before the next elections are over?

  • They're saying Graphene without MTE is less secure, which isn't something they want.

    Well they're inevitably backing into a dead-end. MTE is obviously off the table now which means eventually they'll have no hardware fitting to their super-exacting demands. Motorola might come through, or not.

    I hate being a conspiracy theorist but honestly sometimes the way Graphene clings to Pixels feels like a Google scheme to boost their pathetic Pixel market share.

  • Not as such, but there are models that will be crippled in various ways by the lack of a connection.

    I saw one that would frantically try to connect (to what, I don't know) for several minutes out of every hour and while that was going on (because it was offline) the UI would slow down.

  • There are models that will try out unencrypted wifi AP just to phone home. No extra equipment needed and unfortunately the chances of finding an open AP are pretty good in the middle of the city.

  • Have you tried using it as a DLNA renderer? For example using BubbleUPnP on a mobile device as DLNA controller to cast content from Jellyfin+DLNA plugin as DLNA server.

  • Is the cleaning lady also a company founder?

  • useful data

    The extent of which is "Proton good, others bad".

  • Graphene choosing to die on the hardware MTE hill has always seemed weird to me. It's one feature but it excludes 99% of the phones except the Pixel. GrapheneOS has so much to offer besides it, and nowadays they could use Rust as a workaround anyway.

  • if someone went to a phone store with a stock graphene on display and anything else next to it, which one do you think they'll choose?

    People consider the phone features too. For example Huawei has built a really solid following due to their phones' quality and that following didn't go away when Google started sabotaging their phones. Eventually banking apps started releasing versions for Huawei AppGallery (the Huawei Android app store).

    So the Google monopoly can be bent if there's sufficient demand.

  • We don't have proof of Microsoft doing that with Edge specifically. But that's academic because we already know that Microsoft uses GDID to track website visits:

    Microsoft’s records showed that at that exact same minute, a Windows device carrying GDID g:6755467234350028 had visited the ngrok signup page.

    Whether it does it with Edge or the system HTTP libraries or whatever it really doesn't matter, what matters is that they do.

  • Selfhosted @lemmy.world

    How do you guys use Tailscale (or other VPN) with containers

  • Selfhosted @lemmy.world

    Migrating away from Gandi, 9 months later

  • Selfhosted @lemmy.world

    Upgrading a self-hosted server (episode 3)