Global namespace extremist. Defragment your communities!

  • 0 Posts
  • 38 Comments
Joined 1 year ago
cake
Cake day: June 12th, 2023

help-circle
  • IKEA devices apparently work very well with Aqara

    When it comes to zigbee devices, don’t combine the aqara wall switches with large (4 buttons) ikea remotes.

    The wall switches tend to execute the commands from the remotes instead of just routing them to the coordinator.

    My Zigbee network also improved a lot when I set up some IKEA plugs in the loft.

    I have similar experience with the ikea bulbs. More of them I connect, more stable the whole network gets.


  • Gmail offers imap amd smtp access. You have to enable 2FA, and then it will allow you to create account for so called “less secure apps”.

    In your place, I’d either continue using gmail directly, or finish the configuration of the self hosted mail server and just use that with any smtp/imap client. I suggest getting a separate domain for testing first, before moving your primary inbox there.





  • you still need good security configuration of the exposed service.

    In a sense that security comes in layers, yes. But in practice, this setup will prevent 100% of bots scanning the internet for exposed services, and absolute majority of possible targeted attacks as well. It’s like using any other 3rd party VPN, except there’s not a central point for the traffic to flow through.

    From the attackers point of view, nothing is listening there.

    I’ve used a similar setup in the past to access a device behind a NAT (possibly multiple NATs) and a dynamic IPv4. Looking back, that ISP was a pure nightmare.







  • Of course security comes with layers, and if you’re not comfortable hosting services publically, use a VPN.

    However, 3 simple rules go a long way:

    1. Treat any machine or service on a local network as if they were publically accesible. That will prevent you from accidentally leaving the auth off, or leaving the weak/default passwords in place.

    2. Install services in a way that they are easy to patch. For example, prefer phpmyadmin from debian repo instead of just copy pasting the latest official release in the www folder. If you absolutely need the latest release, try a container maintained by a reasonable adult. (No offense to the handful of kids I’ve known providing a solid code, knowledge and bugreports for the general public!)

    3. Use unattended-upgrades, or an alternative auto update mechanism on rhel based distros, if you don’t want to become a fulltime sysadmin. The increased security is absolutely worth the very occasional breakage.

    4. You and your hardware are your worst enemies. There are tons of giudes on what a proper backup should look like, but don’t let that discourage you. Some backup is always better than NO backup. Even if it’s just a copy of critical files on an external usb drive. You can always go crazy later, and use snapshotting abilities of your filesystem (btrfs, zfs), build a separate backupserver, move it to a different physical location… sky really is the limit here.






  • Yes, on the outside meter. It comes with a magnet with a double sided tape which you place around the LED, and the sensor itself just hangs on the magnet. But I’m not sure if american meters provide such interface.

    I’ve asked the utility provider for some kind of official, approved, solution, but all they have to offer was to replace the entire meter, and even that would only report a 15 minute average via some proprietary API. The frient device is clearly a better solution. No wonder they were sold out for months.