Pika
@Pika@sh.itjust.works
- Comment on Last weekend I published Plume RC1, my side-project for a self-hosted, flat-file publishing platform built to simplify independent publishing 1 week ago:
I was originally going to add that usually different services can use the same name as long as there’s no overlap, but you can’t even use that on this one because they’re both blogging platforms.
Yeah, unless they have authorization from the original project this is likely going to require a name change.
- Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative? 2 weeks ago:
Said backdoor isn’t possible with the current day key exchange process. Without the servers in use private key, the most law agencies can do without acquiring the private key is force the CA to revoke a cert, which will disallow properly configured clients from accessing and transferring data with the server.
LE doesn’t have enough information to recreate the private key based off the public key, the only key distributed during the CSR process is the servers public key via a certificate signing request which is signed using your private key, which the CA then signs with it’s own intermediate key (which is signed by it’s root server certificate) and hands back to the private server.
The CA doesn’t have the ability to create that private key, and as such doesn’t have a way to decrypt traffic that is using that key. There is no concern for a backdoor in that process.
In order for the “backdoor” to exist, they would need to either copy the private key as part of the signing process (which it doesn’t), or somehow force the server admin to use a new private key (that the CA also holds) or somehow compromise the servers key generation process to allow for an escrow on the private key when it was generated which would allow the CA to be able to recreate the private key using the master & public key.
Now don’t take me wrong, you can still have a MiTM impersonation attack or a full impersonation bypass by the CA issuing a new certificate and having the DNS registrar have the web address go to a new server that is using the new public key but, that’s not something the CA alone has the capability of doing, and any traffic that is issued to the original server still wouldn’t be compromised, its just clients visiting your site will end up at the other site and as such will end up using keys that the other side generated instead of your own keys and additionally said new keys would also be appearing in Certificate transparency logs, or modern day clients would refuse to use them.
- Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative? 2 weeks ago:
I don’t think anyone’s going to solve the problem in general, to be honest.
Like, Let’s Encrypts goal is super novel, but also expensive as shit to actually run, and requires a lot of coordination because it needs to be a trust authority. If this ever happened, it would probably be at the backing of some government structure, because I don’t see many people wanting to jump at that at an expense.
- Comment on Letsencrypt is under US jurisdiction. Is there a free-er alternative? 2 weeks ago:
Is this accurate? Like, I know what you’re meaning, but I’m pretty sure it’s not ICANN doing it, and more so your domain registrar handing it over to the US government.
I think the most control that ICANN has over it is they could theoretically, if they wanted to, delete an entire top level domain. Since they do control the DNS root, but that is the most that they control from what I understand.
I don’t know if they have the ability to delete or transfer control over an individual domain on legal request. I think that’s outside of what their actual system allows for.
- Comment on Is this little guy AI? 5 weeks ago:
Bold of you to assume half the stuff on my desk has a purpose KEKW
- Comment on Homelab discussion 2 months ago:
I use proxmox on one server, but currently my layout is:
- docker 1:
- Authentik first network
- heimdall
- immich
- jellyfin
- NPM first network
- zipline
- docker 2:
- authentik second network
- npm second network
- blorp
- gitlab-runner
- ladder
- metube
- photon
- privatebin
- tandoor
- bar assistant
- sponsor block LXCS:
- pihole
- wireguard
- mail server (postfix/dovecot)
- zoneminder
- zabbix
- gitlab
- matrix
- xmpp/openfire
- revolt/stoat
- gamevox (temporary)
- pufferpanel - minecraft
- pufferpanel - ark
- palworld
- discord development container
- projects container VMs:
- homeassistant
- ipa server
- firewall
- Syncthing / immich storage / PXE server/ File storage
Also thank you for making this post, it helped me realize I have a few containers and services I don’t use and I don’t think have activity on them anymore so I can start a deprecation cycle on them lol
- docker 1:
- Comment on Selfhosting as a Linux newbie - Ubuntu Server LTS or Debian 13? 2 months ago:
As someone who ran Ubuntu server for a few years before moving to Debian. I would recommend Debian over Ubuntu just because I have had to do less maintenance with it. When I was on Ubuntu updating it was a constant concern of “will something change that is bad” for example they pushed the kernel live patch and the Ubuntu subscription banner as an update instead of an upgrade, so I updated as normal, and there it was.
I dislike OS’s that install new packages as part of their update procedures (an update that installs a new package instead of replacing an existing one should be reserved for upgrades), and Debian has never done that with me, so Debian is where I stay.
- Comment on I feel like Expedition 33 is overrated [minor spoilers] 2 months ago:
I believe the same for the graphics, I just couldn’t vibe with it. Everything else I didn’t mind bit the graphics I couldn’t do
- Comment on Laptop as server, how to best manage battery? 3 months ago:
As others have stated, if your model is able to have the battery removed and have it still run off power, no problem, do so.
You should be using a dedicated UPS for something like that if you’re concerned about power going out , For a power input that a laptop requires, you could very easily find a $30 or $40 one at your closest big box retail store.
If you must keep the battery in it be careful to monitor it. I ran a laptop as a server for almost four years. It does work really nice. But depending on model, they may be prone to having the battery expand if it’s on 24-7. And even if it doesn’t, that battery is going to be shot after two or three years of constant use anyway.
You can mitigate the battery health issue by making sure you have some form of battery management software running where it stops charging the battery once it hits like 80-85%. and allows it to discharge on its own. But realistically using a laptop battery as a backup power source isn’t super recommended.
Plus with a UPS, you could also hook your router and modem/ONT up to it, which means that not only is your laptop going to remain on, but usually your network will remain up as well since communication lines are quite a bit more durable and generally stay alive even if the power goes down
- Comment on Messaging apps - XMPP vs Matrix vs ??? 8 months ago:
There is also some that you just don’t want to put that type of responsibility onto either. I moved my grandfather to a password manager 5 or 6 years back. I reiterated at least 8 times do not forget this password if you do you will lose all passwords and need to do everything over again.
He lasted 3 or 4 weeks then suddenly called me saying he couldn’t remember his password period. Like he tried for a good 40 minutes to guess what he may have done and was in a pretty intense panic because he didn’t want to have to change every service he had.
Thankfully it had not been long enough for his file history backup to have deleted the file, so i just restored the last backup of his passwords.docx file and put it back where he was used to it.
I’m not about to try and have him use a password manager again, he has decent enough password management skills since he doesn’t reuse passwords period, but like, it was far too risky putting him on a password manager again.
- Comment on Messaging apps - XMPP vs Matrix vs ??? 8 months ago:
I couldn’t get into matrix, but I was a huge fan of open fire. It’s interface was stupid easy for XMPP administration and for awhile I ran it no issue with my group of friends. granted we ended up just going back to discord not due to any issue with the server or protocol but because it was tedious trying to get people to switch off a platform that works for most people.
- Comment on Need for Speed: what is the best title of the series? 1 year ago:
I loved UG and UG2, but honestly HP2 takes the cake for the best game, not because of the involvement but, because no other game in the series ever did the Cops system as well as it. The newer HP game was also good too, but I felt it branched off. HP2 you could just give a map, no reason for it, and spend the entire game dodging the cops the rest of them it felt like you were actively penalized for not pulling over. I loved the added challenge of running from the cops + racing