• 0 Posts
  • 216 Comments
Joined 3 years ago
cake
Cake day: July 11th, 2023

help-circle
  • Thanks. I have spent the day reading about M-disc and optical formats. Lemmy is great for starting rabbit holes! I think I may swap a blu-ray burner into one of my machines and I am actually thinking dual layer blu ray is a decent trade-off: simmiliar chemistry to m-disc (unlike the clear superiority of m disc over DVDs -which I was literally burned on the other week with some yellowed DVDs), and yet still cheap, reasonable amount of disc shuffling, and in the future, nearly any blu ray drive will work with the 50gb discs (unlike 100gb disks). Still might grab a blu ray m disc burner if I see a good deal but they seem rarer than a hens tooth. Lol.

    I have less than a TB of truly irreplacable stuff, so 20 discs isnt bad to suffle, and aiming for maybe 20 years of electrically safe cold storage* zero maintenance off-site seems pretty reasonable for a $50 drive and about that in discs.

    *This is overkill anyway - already have zfs snapshots going to an external drive in another room and restic backups to b2. But the threat model is some combination of losing b2 (credit card fail or my own incompetence) plus housefire/robbery/electrical surge taking out everything. Also, if I get hit by a bus and my CC is cancelled, a box of transparrently readable discs are significantly safer bet for my survivors than my note about how to get the data off the NAS/backup drive. They could leave it 5+ years and come back to it no problem.


  • I have wondered about how to manage a 100 spool of DVDs as long term cold storage of the most important data. Would need some way of splitting the data up automatically and building a straightforward burning workflow, with redundancy incase a disk is destroyed, and a way to find a given file.

    Seems like a lot of work for 400-ish Gb, but 1. Its very cheap, 2. Archival disks could last a lot longer in cold storage than anything else affordable, and 3. Anyone could recover it in the future because DVD drives have been manufactured by the billion and are still being put in some office PCs. 100gb blurays are also an option but that means sourcing a burner and at least a few drives capable of reading them to store alongside.

    Edit: at first blush, plain files to make recouvery easier plus par2 files scattered across enough disks to be able to lose a whole disk or have many damaged disks seems like the right format. Some sort of index would need to be built and left on every/most disks or maybe printed on paper. Its mainly the workflow to do it that would be a PITA.




  • Security by obscurity is when the design or archetecture of the system is obscure enough to supposedly styme attackers (it doesnt), and as soon as people understand the design, your security is broken.

    A hard to guess unpublished subdomain is a transparent and standard archetecture - nothing obscure about it and publishing that you use such a scheme doesnt break the security.

    The subdomain is a bearer token that serves as an access control and just like a key or passphrase, has a security value proportional to the bits of information an attacker has to guess.

    The real limitation is that browsers and humans are not great at not leaking domain names, so its very possible it will get leaked eventually and hard to rotate. Thats the reason they are weak. Still, they can be usefull to stop scanners just trolling for unpatched services.




  • There are constant scanners on any site and scrapers on websites, but it is far less of a problem than you would imagine unless you have a big wiki or software forge with hundreds of nested commit history pages for them to spider into.

    I also run private servers on hidden subdomains (with wildcard certs and DNS entries), so the low effort scanners never bother them.

    DDOS attacks take money, so they aren’t typically going to go after some random homelabber. If it did happen, I would either just shut it off for a while or change the VPs IP. Ovh also has some of its own ddos protection.


  • Keep in mind that you wouldn’t route local traffic through it, so everything watched at home would be direct and not count.

    I have a $5/mo VPS with OVH and they allow unlimited bandwidth within reason. Unless you have multiple households streaming from your server all the time, likely totally fine. If you do end up with one relative streaming 24x7, then I would look at installing the tailscale app on their TV and configuring things to connect that one user direct to your home server.

    A VPS takes some learning, but IMHO, it is the “correct” answer and worthile learning.



  • Really a long time coming pain point is comfortably sharing between family. I think the new workflows will be the way eventually. I plan on using it to auto add pictures with the recognised faces of family members to a “Family Photos” album as they are uploaded, and allow everything else to stay unshared by default for each user.


  • Your idea works in theory, but in practice, using a ZigBee plug as a power sensor -even if you managed to program a way of detecting its online/offline status, will probably have too many issues.

    The protocol is designed for low power and so has to be robust to temporary connectivity issues from interference. You would either have too much latency between the switch and the light turning on/off, or you would have phantom switching of the light whenever some other device in your house desides to do its thing.

    It is a genuinely neat idea you had though.



  • Yeah, I bind mount the config inside a config directory just below the compose file, and the state (databases, files, etc) to a seperate storage location that makes sense. The compose and config gets added to git and pushed to a forge, while the storage directories are backed up like normal (in my case, zfs snapshots pushed to another computer and then restic backs up those cold files to b2.







  • Jason2357@lemmy.catoSelfhosted@lemmy.worldI finally bought a domain! Now what
    link
    fedilink
    English
    arrow-up
    2
    arrow-down
    2
    ·
    2 months ago

    I absolutely agree, to the point where I thought you were agreeing with a different post I made. This is the way!

    There are lots of free or nearly free ways to host a static site with your domain, and basically walk away from it for years at a time just fine. I wouldn’t use Cloudflare just on principal for just static site hosting, but its fine I guess. All the software forges host pages for free, and a bunch of smaller outfits like Neocities. Even a static site on a VPS is nearly zero maintenance. When was the last time there was a CVE for remote code execution that would effect a Linux VPS hosting only a static webpage via Caddy or Ngnix and key-based SSH? (I don’t actually think there has been one).

    Absolutely, I use a VPN for self hosted services I can’t be bothered to secure properly and don’t need exposed to all that mess. Wireguard is amazing. I used OpenVPN for years and it was such a pain in the ass mobile. I remember when it first came out, I set it up and made a SIP VoIP call with my phone. I could toggle between WiFi and cellular networks without the audio even glitching, let alone a call dropping. That was honestly like black magic back then.