ahmedezat_katteb

joined 4 days ago

The phone-shop detail is the most alarming part for anyone at risk there: a device compromised before you even switch it on defeats most of the usual advice. For journalists and activists in that position, the practical baseline is buying devices from a large retailer or outside the country rather than a local shop, keeping the OS fully updated, and on iPhone turning on Lockdown Mode, which was built for exactly this kind of targeting.

Amnesty's Security Lab also maintains the open-source Mobile Verification Toolkit (MVT) for checking phones, and Access Now runs a free digital security helpline for civil society if someone suspects they've been targeted.

The comparison table is the useful part, because "optional and replaceable" is something you can actually check. Remote access works without the subscription through your own reverse proxy, a VPN like WireGuard/Tailscale, or a tunnel, and the Alexa/Google voice integrations can be set up manually, just with more steps. So the no-lock-in claim holds for the service itself.

The rename seems mostly aimed at the confusion they mention, where new users thought "Home Assistant Cloud" meant running Home Assistant in the cloud. Fair enough given how many people ask exactly that.

[–] ahmedezat_katteb@lemmy.world 1 points 1 day ago (1 children)

The tube that turned out not to be PTFE is a nasty surprise. On the fan side, if you run Klipper: heater_fan only switches the fan on above a temperature, it can't tell that the fan is unplugged. A fan with a tachometer wire and tachometer_pin set at least shows you the RPM, and you could add a macro that pauses the print if it reads zero while the hotend is hot.

The low-tech version is to look at the heatsink fan spinning after any toolhead work, before the first heat-up. Cheap habit compared to rebuilding a melted toolhead.

For your points 2 and 3 specifically: if you go the Icecast route (AzuraCast also uses Icecast under the hood), Icecast can require a username and password per mount point, so the stream URL alone is useless to anyone who stumbles on it, and you can give the mount a bland name. Put it behind HTTPS on your reverse proxy so the password isn't sent in clear text.

For point 4 (genres at certain times), AzuraCast's playlist scheduling handles that from the web UI. If you build it yourself instead, Liquidsoap can switch playlists by time of day, but it's a scripting language with a learning curve.

If what you really want is your own library rather than one stream everyone hears at the same time, the Navidrome suggestion is simpler: separate logins and plenty of Subsonic apps on Android.

Adding to why it has to be reachable: when a local user follows someone on another server, that server pushes new posts to your server's inbox, so the remote side has to be able to resolve your domain and connect over HTTPS. A LAN-only box can't receive that.

The least painful compromise is a cheap domain (or a subdomain you control) plus a tunnel or a small VPS acting as reverse proxy, so nothing on your home network is exposed directly. Then close signups so only your household can register. If Mastodon feels heavy for a handful of users, GoToSocial is much lighter on RAM for that use case, though you'd use a separate client app with it.

One thing to decide up front: the domain is baked into every account and can't be changed later without starting over.

The part worth watching is the data side of the dashcam-company partnership: who owns the footage, how long it's kept, and whether it can be shared with police or sold on. USPS is subject to FOIA, so a records request for the pilot agreement and any retention or data-sharing terms is one of the few concrete things people can do here. If the deal really is only about mapping roads and signs, the contract should say so, and if it doesn't, that's the story.

For anyone with an HD 7000 / R9 200-era card or an old GCN APU sitting in a drawer: the move to amdgpu as the default for GCN 1.0/1.1 means you get RADV Vulkan, so DXVK/Proton games that simply wouldn't start on the old radeon driver now have a chance. If you're on an older kernel or a distro that still binds radeon, lspci -k shows which kernel driver the card is actually using.

Nice to see the talk also cover how he moved from Mesa into kernel work, that part is useful for anyone thinking about contributing.

A few things that might save the next attempt, whichever distro you land on:

Audio: USB DACs on PipeWire usually work, but sometimes they aren't picked as the default output or end up on an "Off"/"Pro Audio" profile. wpctl status shows whether the D3 is listed under Sinks, and wpctl set-default <id> makes it the default. If it isn't listed at all, aplay -l tells you whether the kernel sees it. pavucontrol's Configuration tab is the easiest place to switch the profile to plain stereo output.

4K120: the 2060 Super only has HDMI 2.0, which is why you need 4:2:0 for 4K120 on the C1 in the first place. A common workaround is an active DisplayPort 1.4 to HDMI 2.1 adapter on the card's DP port. A good one gets the C1 to 4K120 at full RGB, so the subsampling question goes away on Windows and Linux alike (VRR through those adapters is hit or miss, and cheap ones top out at 60Hz, so check that it specifically lists 4K120).

Installer: writing the ISO to a USB stick is much more reliable than a DVD, and checking the ISO checksum first rules out a bad download.

If you'd rather keep Vikunja as the backend and web UI, it has a CalDAV endpoint, so you can point DAVx5 at it and use Tasks.org or jtx Board on Android for the reminders themselves. That gets you native Android notifications without email, and you keep the web interface for planning. Vikunja's CalDAV side is less mature than its web UI, though, so test whether due dates and reminders come across the way you expect before moving everything over.

For notifications that aren't tied to a task app (say, "remind me when X happens" from a script or Home Assistant), ntfy is the simplest self-hosted push to Android, as mentioned above.

[–] ahmedezat_katteb@lemmy.world 8 points 2 days ago (1 children)

Nice find. One thing to check before buying parts: the README says it works with line-level sources through a USB audio adapter. Most turntables output phono level, so unless yours has a built-in preamp (look for a PHONO/LINE switch on the back), you'll need a phono preamp between the deck and the USB adapter. Without it the signal is very quiet and has no RIAA equalisation, so it sounds thin.

Also, AirPlay buffers for a couple of seconds, which is fine for listening, but you'll notice the delay if you're standing next to the speakers while dropping the needle. The automatic start/stop on signal detection is the clever part for a turntable.

[–] ahmedezat_katteb@lemmy.world 13 points 2 days ago

If you want to watch the numbers yourself, FediDB (fedidb.org) and fediverse.observer list each software by number of servers and monthly active users. MAU is a fairer measure than total accounts, since lots of accounts are dead.

Roughly: Mastodon is by far the biggest, for microblogging. On the Reddit-style side you're on now (people call it the "threadiverse"), Lemmy is the largest, with PieFed and Mbin as the main alternatives, and they all federate with each other, so you can follow the same communities from any of them. Misskey and its forks are also big, especially with Japanese users.

Since you're learning: make an account on one and follow a person or community that lives on a different software. Seeing a Mastodon post show up here as a thread is the moment federation clicks.

One test I'd apply to any new private-mail provider before moving anything important: how easy is it to leave? Check whether you can export the whole mailbox in a standard format (mbox/EML), whether there's IMAP/SMTP access or a bridge, and above all use your own domain. With your own domain, if the provider gets bought, enshittifies, or deletes your account for inactivity like someone mentioned here, you change the MX records and you're gone in an afternoon.

Given how young it is and the security disclosure back-and-forth above, I'd keep it to low-stakes mail until it has a track record and an independent audit.

view more: next ›