pHr34kY
@pHr34kY@lemmy.world
- Comment on How is everyone dealing with Android 17's "Nearby Devices" change? 3 days ago:
Nope. I don’t use them.
- Comment on How is everyone dealing with Android 17's "Nearby Devices" change? 3 days ago:
It’s because people keep finding ways around them and they evolve in nonsensical ways.
- Comment on How is everyone dealing with Android 17's "Nearby Devices" change? 4 days ago:
I’ve been on IPv6 years before Google turned it on. My ISP gave me a /48 and I’ve got different subnets for my WAN, LAN and guest LAN. I have a 4-port NIC so I could put a different subnet on each port.
I didn’t mention it in my first post, but I only made AAAA DNS entries for my internal stuff. I just enable IPv4 for the few services that actually need it.
- Comment on How is everyone dealing with Android 17's "Nearby Devices" change? 4 days ago:
Nope. SSL certs are pinned to the hostname, not the IP address. I can change the IP address in DNS and it will still work.
- Comment on How is everyone dealing with Android 17's "Nearby Devices" change? 4 days ago:
That’s exactly what I’m doing.
- Comment on How is everyone dealing with Android 17's "Nearby Devices" change? 4 days ago:
I’ve also got a completely different DNS config for WAN and LAN traffic. WAN devices can only resolve PTR records for my mail server. My LAN devices have DDNS so internally they a get allocated DNS entries by hostname. Even my guest network has a different config for isolation.
They definitely all need to be kept separate.
- Comment on How is everyone dealing with Android 17's "Nearby Devices" change? 4 days ago:
Routing between two interfaces on the same NIC takes nanoseconds. You wouldn’t notice a performance difference.
When I first set it up, I didn’t have a static IP address, so it would not be great when it changed. I also want my server to remain reachable locally if my internet goes down. I had different firewall/ACL rules for wifi too. For example, some of my internal websites only prompt for a login if you’re outside the network.
IPv6 has been awesome here. I have my server and clients on different /64 subnets in the same /48 block. The nearby devices on Android assumes only the same /64 is local.
- Comment on How is everyone dealing with Android 17's "Nearby Devices" change? 4 days ago:
Native apps all have a backwards-compatible setting so it’s allowed by default. That will surely get dropped when Google bumps the minimum Android target API so newly published apps need to explicitly configure it.
I actually went through my apps list and disabled nearby devices for all the apps that don’t need it. It’s a good security measure. I just don’t like how it was rolled out.
- Comment on How is everyone dealing with Android 17's "Nearby Devices" change? 4 days ago:
I self-host a DoH/DoT server and my local DHCP advertises it to local clients. It’s kinda cool because android phones on my wifi will use DoT when private DNS is set to “automatic”.
Private DNS sort-of broke while I was tinkering with internal/external IP addresses for nearby devices. It wouldn’t always connect when I specified my external IP (despite being available externally). I made it IPv6-only too. It wouldn’t be the first time something couldn’t handle it.
- Comment on How is everyone dealing with Android 17's "Nearby Devices" change? 4 days ago:
I’m actually on GrapheneOS.
I’ve found that you can deny “Network” permissions and permit “Nearby devices”. The app becomes LAN-only this way.
- Comment on How is everyone dealing with Android 17's "Nearby Devices" change? 4 days ago:
I’m actually using GrapheneOS.
- Comment on How is everyone dealing with Android 17's "Nearby Devices" change? 4 days ago:
It would be annoying to do that for everyone who uses my wifi.
I found that “Conversations” (XMPP) was blocking a connections even when the permission was enabled. I suspect Android no longer allows connections on port 5xxx on a local network. It works fine when the IP is external.
- Submitted 4 days ago to selfhosted@lemmy.world | 69 comments
- Comment on DC UPS for router? 6 days ago:
I did this once with a router. I just bought a 12V SLA battery (a UPS battery) and a trickle charger. The charger was always connected to the battery, so it was pumping about 13V into the router. The router could withstand it. It’s easy enough to get a voltage regulator if it’s an issue, but most hardware already does it to an extent. It was DC all the way.
- Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative? 1 week ago:
I don’t think anyone is gonna solve that problem until it’s actually a problem.
- Comment on We need a list of products we can buy without worrying about telemetry or advertising. 1 week ago:
Mozilla has their Nothing Personal online magazine with product reviews. It’s only a small handful of product at this point. This started out as “Privacy Not Included”, which is now defunct.
- Comment on nftables: Can't ping my own server 2 weeks ago:
Run
nft list rulesetand make sure that the final result matches your config. Maybe it’s misinterpreting or discarding something? - Comment on nftables: Can't ping my own server 2 weeks ago:
My server has this to allow ICMP in nftables:
ip protocol icmp accept meta l4proto ipv6-icmp accept
There’s a hundred ways to do the same thing, and I haven’t found online guides to be consistent.
- Comment on Is this a good first homeserver? 1 month ago:
I’m using bcache, and I’m using btrfs as the filesystem on top of it. I’m not sure that the way I’ve done it is considered best practice anymore. The discourse online is a mess because the landscape keeps evolving.
- Comment on Is this a good first homeserver? 1 month ago:
2 of my 4x 4TB spinning drives are portable. 2 in mirrored raid, and on-site backup, and an off-site backup. If you don’t have it on 3 drives across two sites, you don’t have it.
The other specs seems fine, but I personally upgrade my desktop then take the old CPU, RAM and motherboard to use for my server.
- Comment on What do you do with your old iPad mini? 2 months ago:
My 6th gen iPad is the only Apple product I own. It’s also the only device that refuses to connect to my WiFi. I was going to make it a wall panel, but it’s shit.
My wife bought the $100 digital wall calendar from KMart and it hooked up to my CalDav server. I was surprised that it showed zero dark patterns. No vendor lock-in. No ads. No spying.
- Comment on Self hosted photo options for the family? 2 months ago:
There’s Nexcloud and the “Memories” plugin. It’s not as good as Immich though, especially if you don’t need the rest of NextCloud.
- Comment on What actual damage do you secure your servers against? Whats the attack vector? 2 months ago:
The worst I had was a credential-stuffer bot that used a set of leaked credentials to get on my mail server and send spam. I changed the password within 5 minutes and it stopped. That was the end of it.
Once I had someone deface a website because wordpress wasn’t patched. I just restored the site from backup and moved on with life.
I would think that most of the time, you just join a botnet.
BUT someone getting into your email can let them do password resets to all your accounts. Then again, I self-host my email because all mail providers are reading your email by default. I’d still rather self-host it.
- Comment on Is they're an easy way to make my Jellyfin accessible outside of my home network 2 months ago:
You can still just open it to the internet. Just do it on IPv6 instead.
- Comment on What us the best way to add remote access to my servers? 6 months ago:
Make it a subdomain on a wildcard cert if you’re concerned about that.
- Comment on What us the best way to add remote access to my servers? 6 months ago:
Just expose it on single-stack IPv6. Nobody ever knocks. The address space is not scannable.