
irmadlad
@irmadlad@lemmy.world
Incessant tinkerer since the 70’s. Staunch privacy advocate. SelfHoster. Musician of mediocre talent. soundcloud.com/hood-poet-608190196
- Comment on This is the back of my 10" Mini server rack -- Custom made 3D printed power modules for each server 4 days ago:
Nice work OP. Clean and sharp. These mini servers are awesome.
- Comment on This is the back of my 10" Mini server rack -- Custom made 3D printed power modules for each server 4 days ago:
Way to head them off at the pass. Rock on with yo bad self.
- Comment on [AIP] CookTrace v1.2.0: Ingredient-Linked Steps, Wide-Screen Desktop, Cookbook Drag-and-Drop 6 days ago:
'Sup bro. It seems I need to update. Thanks for the heads up. I’ve been enjoying CookTrace so far.
- Comment on My Homelab Got Hacked - A Postmortem – Phunky Cafe 1 week ago:
About the only recent even I’ve had was when I was sitting at my desk reading an article. I noticed the mouse slightly move, but I hand no hand on the mouse. I sit there watching it, not manually moving the mouse or typing on the keyboard. It really freaked me out. Turns out, my old desk pad had a slight curl towards the edge the mouse was at, and the curl would make the mouse sense movement ever so slightly. I deployed a new desk pad, and things are back to normal. Whew!
- Comment on Expanding my laptops HDD capacity 1 week ago:
I like it. The OCD in me is screaming why you didn’t use a dremel tool to cut the slot for the USB ports instead of using a rusty, dull, steak knife from the junk drawer, but that’s just me. LOL
- Comment on Internet centralization and the original sin of NAT 2 weeks ago:
I hear a lot of chatter about CGNAT. How common is that? Anecdotally, I’ll have to say, I’ve never encountered it… ever.
- Comment on ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body 2 weeks ago:
The scripts targeted an ownCloud instance operated by a nuclear research body
Maybe it’s just me, but I think if I were running a nuclear research facility, I’d want a little something more than ownCloud, and neat as it is.
- Comment on Self-Host Weekly (28 August 2026) 2 weeks ago:
Gravity looks pretty cool, tho a bit heavy on the install. TapMap: Why are these things such a garish shade of green? Damn hard on the eyeballs.
- Comment on QubesOS workstation + homeserver, and DANE for TLS without 3rd party company 2 weeks ago:
I tried QubesOS back in the day. How has it progressed as a desktop. I was always underwhelmed visually. It just seemed rather chunky. Maybe that is intentional.
Of course, if you are going for security, that’s great, but it seemed to me that security and a visually appealing desktop could be blended.
- Comment on The hardest choices require the strongest wills 2 weeks ago:
I’m higher than a giraffe’s butthole, so I got to know: Exactly what were you staring at when you opened the picture? I kid of course, but I found that quite risible.
- Comment on [AIP] Reitti v5.3.0: Multi-Segment Trips, Spatial Coverage & FIT File Support 2 weeks ago:
Ahh ok…well, there you go. Fresh out Don Curbstickle. Maybe next time.
- Comment on [AIP] Reitti v5.3.0: Multi-Segment Trips, Spatial Coverage & FIT File Support 2 weeks ago:
I wonder if you could pair your phone with your DSLR so that you have access to GPS location tagging.
- Comment on Replacement for Docker Content Trust (DCT) 3 weeks ago:
Monitoring firewall logs would show calls to suspicious IPs and domains after you pulled the Docker container. A MiTM attack is usually conducted between two communicating parties, rather than inside the server itself. The attacker intercepts traffic as it travels across a network or service path. MiTM are not always done exterior of the server, but usually. Strong ciphers are your friend. Although MiTM and PIC events can overlap, a PIC is usually an attacker gaining unauthorized access to a system. A PIC compromise occurs outside the public facing server, through a stolen administrator password, compromised developer workstation, exposed API key, or hijacked cloud account. Securing API, devices, frequent password rotation are good practices. Again, not always exterior of the server, but usually.
- Comment on Replacement for Docker Content Trust (DCT) 3 weeks ago:
What do you (or does your org do) to ensure that you’re not using maliciously-modified containers after pulling a new docker image?
I don’t run a complex setup as it seems you do, but if I pull a new Docker container, I closely monitor my pfsense firewall logs. A lot of times, I’ll deploy a recently released container on a small test server and just observe as I run it through it’s paces. Also, I like containers that have a rather established history. I look at things like stars, how they handle bug complaints, etc. Even when updates come out, unless it’s a dire security patch, I’ll wait until all the early adopters work out the bugs and do my work for me. Early adopters are a valuable resource.
I guess you could say it all comes down to calculated risk.
- Comment on I built a tiny self-hosted corner of the internet made entirely from HTML pages 3 weeks ago:
capitalist mindset
I’m a capitalist. I run three bonafide, tax paying businesses. They allow me to live moderately comfortable. Money makes the world go 'round. I’ll never be a billionaire, but I do love me some money. Sure, the best things in life may be free, but the grocery store isn’t giving away groceries.
- Comment on I built a tiny self-hosted corner of the internet made entirely from HTML pages 3 weeks ago:
Don’t take it to seriously
Too late. LOL Thank you for sharing.
- Comment on VyOS or Opnsense 3 weeks ago:
Opensense is often bound by single-core operations depending on where a network packet may plumb itself through the kernel
When would this become an issue? Pfsense is about the same way as far as single-core operations, tho IDS/IPS like Suricata can utilize multiple threads. My standalone pfsense box sits between my modem and the rest of the network. I haven’t noticed any sluggishness or stuttering. Throughput seems quite reasonable, and supports a diverse group of devices attached to the network.
- Comment on Stick PC for a media client? 3 weeks ago:
Well, there you go. I’m glad I plowed the field and saved you the embarrassment. LOL
- Comment on Stick PC for a media client? 3 weeks ago:
Pay no attention to the old fart yammering on. I’m surprised I didn’t throw in a couple ‘well, back in my day’. lol I hope you get it all worked out tho.
- Comment on Stick PC for a media client? 3 weeks ago:
Ahh, I missed that. So that would explain all the downvotes with no explanations why. Thank you for bringing that to my attention.
- Comment on Stick PC for a media client? 3 weeks ago:
I don’t run Jellyfin, so take this as is. From what I understand tho, Jellyfin does take a fair amount of resources to run in an ideal situation. Meaning it takes some RAM for multiple simultaneous transcodes, several users, large libraries, etc. A lot of the cheaper Stick PCs come with less than stellar specs. The Stick PC I just randomly picked because it was 8 GB RAM is a MeLE Business Grade PCG02 Fanless N100 Mini Stick PC 8GB. IT retails for $350 USD. For half of that price, you could opt for an SFF Optiplex, bump the DDR3 RAM to max the mobo, and DDR3 is fairly cheap, and still have resources to run other Docker containers if you wanted. For example I run an Optiplex SFF with the i7-4790 chip and 32 GB DDR3 RAM. Currently I have 53 total containers running and it really doesn’t break a sweat. Total cost of the box plus RAM was about $175 USD.
If you are going for the portability aspect, that’s where I think a Stick PC would function best. All that being said, you have options just depending on what your criteria are for running Jellyfin.
- Comment on Means to privately connect to my home server other than Tailscale? 3 weeks ago:
- Comment on Means to privately connect to my home server other than Tailscale? 3 weeks ago:
I’m an expert at nothing, but I would imagine that different VPN like WireGuard have different detectable signatures, much like different browsers have different signatures that can be detected. Also, for commercial VPNs, the IPs that the VPN company uses are easily identifiable.
- Comment on My self-hosted experience - and my favorite container 3 weeks ago:
I’m just yanking your chain bro. Glad you are enjoying your self hosting journey. Rock on wid yo’ bad self.
- Comment on My self-hosted experience - and my favorite container 3 weeks ago:
Congrats on the improved lifestyle now. I wouldn’t say you have wasted hours. More so that you have invested in your privacy and data retention.
firefox: image: jlesage/firefox container_name: firefox ports: - “5808:5800” environment: - TZ=America/Chicago - PUID=1000 - PGID=1000 #- VNC_PASSWORD=${VNC_PASSWORD} - DARK_MODE=1 - WEB_AUDIO=1 - WEB_FILE_MANAGER=1 - WEB_FILE_MANAGER_ALLOWED_PATHS=ALL - WEB_HOST_CLIPBOARD_SYNC=1 volumes: - ./firefox/config:/config:rw - /SWAP:/downloads shm_size: “2gb” restart: unless-stopped networks: - web
My Dick Tracy decoder ring is on the fritz. I think it says ‘My hovercraft is full of eels’.
- Comment on Self-Host Weekly (21 August 2026) 3 weeks ago:
Some guy hid a prompt injection in his legal filing that encouraged the court’s AI to rule in his favor (fortunately, the court confirmed it does not use AI for these reviews)
‘E’ for effort nonetheless. That’s pretty funny.
- Comment on [AIP] WebPrint a self-hosted webUI for your printer 3 weeks ago:
I don’t care if you don’t like it.
I like your style bro. If you don’t like it, you can go the way you came. Pretty damn refreshing. ^5
Damn the torpedoes, full steam ahead!
- Comment on Is there any tape media backup system that works through USB? 3 weeks ago:
No shit. I still have a 5090 still stuck in my throat. $8k for a tape drive, hell, I could have got two 5090s.
- Comment on Selfhosting payment processing 3 weeks ago:
That sucks. Personally, I wouldn’t selfhost financial applications. I don’t need that headache with my money or someone else’s either. I hope you find a solution.
- Comment on Selfhosting payment processing 3 weeks ago:
No worries. I use Square for my businesses, but they are not self hosted. They do take their skim off the top, but that’s a cost of doing business.