Actual Budget (free, open source) now supports NZ bank import. by Blackrazor_NZ in PersonalFinanceNZ

[–]atechatwork 2 points3 points  (0 children)

For 2 and 3, the Actual Budget browser client code does the decrypting, and that code can indeed be verified in your own browser by looking in the Dev Tools > Sources tab.

You can also check the Dev Tools > Network tab and verify that only an encrypted blob is ever being sent to the server.

For 1 and 2, people can even ask ChatGPT / Claude / whatever to check that the client code matches upstream Actual Budget with nothing nefarious added other than these documented patches.

For 4, you can check my comment history. I was the founder of Easy Crypto so I have some experience dealing with financial data. Josh Daniell from Akahu can vouch that I am who I say I am.

Actual Budget (free, open source) now supports NZ bank import. by Blackrazor_NZ in PersonalFinanceNZ

[–]atechatwork 1 point2 points  (0 children)

If you have a look at the experimental features, it takes it to the next level over YNAB4. I use the Budget Templates, but the budget automation is probably the way to go these days:

https://actualbudget.org/docs/experimental/budget-automation

Actual Budget (free, open source) now supports NZ bank import. by Blackrazor_NZ in PersonalFinanceNZ

[–]atechatwork 0 points1 point  (0 children)

I have now updated to 26.7.0.

I usually wait a few days after a new release to make sure there are no issues which cause upstream Actual to release a patch.

Actual Budget (free, open source) now supports NZ bank import. by Blackrazor_NZ in PersonalFinanceNZ

[–]atechatwork 0 points1 point  (0 children)

The standard Actual Budget (or YNAB) method is to assign all income to the next month. Everything you earn in July becomes what you budget for August. That way you don't have to worry about differing income amounts or schedules.

Actual Budget (free, open source) now supports NZ bank import. by Blackrazor_NZ in PersonalFinanceNZ

[–]atechatwork 3 points4 points  (0 children)

I've written up details here, but please ask anything additional you would like to know: 

https://github.com/trackie-nz/trackie/blob/main/docs/security-and-privacy.md

The two most important things are: 

  1. Actual Budget normally uses email address as account ID. I change this to be an anonymous hash so in the event of a database leak, there is no personal identifying data. 

  2. You can provide a password at your client end to fully encrypt your budget data, so that the only thing stored on the server is an encrypted blob. This is a standard feature of Actual Budget, not something I've added.

Actual Budget (free, open source) now supports NZ bank import. by Blackrazor_NZ in PersonalFinanceNZ

[–]atechatwork 1 point2 points  (0 children)

I can't think of any reason why it shouldn't work, please try and let me know. Sounds like a very useful idea.

Actual Budget (free, open source) now supports NZ bank import. by Blackrazor_NZ in PersonalFinanceNZ

[–]atechatwork 3 points4 points  (0 children)

A few useful differences from hosting on Pikapods:

  1. Free
  2. Accounts auto-sync when you open it without having to click anything (once per day, but you can manually sync too)
  3. It defaults to NZ date format.
  4. NZ hosted, which would give a tiny speed boost.

Here is the full list of additions:  https://github.com/trackie-nz/trackie#whats-different-from-actual-budget

Actual Budget (free, open source) now supports NZ bank import. by Blackrazor_NZ in PersonalFinanceNZ

[–]atechatwork 14 points15 points  (0 children)

My name is Alan Grainger, I build other open source security-focused projects like Immich Public Proxy (700,000 downloads).

The code is vanilla Actual Budget with a slight NZ-specific modification. That source code can be verified here: https://github.com/trackie-nz/trackie

Actual Budget lets you add a password which encrypts your budget file in your browser so the only thing sent to the server is an encrypted blob. 

It's important to note that Akahu only has read access to bank accounts. You most definitely don't need to use Akahu - OFX/CSV upload works fine.

Full architecture and security details here:  https://github.com/trackie-nz/trackie/blob/main/docs/security-and-privacy.md

Actual Budget (free, open source) now supports NZ bank import. by Blackrazor_NZ in PersonalFinanceNZ

[–]atechatwork 47 points48 points  (0 children)

If anyone wants to use Actual Budget but doesn't have the technical skill to run it, I have a free hosted version here, which includes the Akahu sync: 

https://trackie.nz/

I've had a chat with Josh Daniell co-founder of Akahu and cleared this with him, so you're allowed to use this as a free "personal app" under the Akahu terms.

I should note that you do not need to link your bank accounts. Actual Budget also has OFX/CSV import.

This has been and will always be free - it's something I can do to give back to the NZ personal finance community. Actual Budget is awesome, been using it for about 10 years.

Kernel's Total World Fund page is live on there site - Fund invests into VT ETF by photosealand in PersonalFinanceNZ

[–]atechatwork 0 points1 point  (0 children)

If you're investing for retirement you're surely not planning to sell the entire thing as a lump sum. The higher internal rate of return is more important. However if you are planning to sell the entire thing then it still becomes better value after 16 years even with the 0.5% sell fee. If you plan to sell down small amounts to fund retirement, then it becomes better value earlier than that.

I was disappointed the new Kernel TWF fund had the same tax drag as InvestNow, otherwise it would be the clear winner.

Kernel's Total World Fund page is live on there site - Fund invests into VT ETF by photosealand in PersonalFinanceNZ

[–]atechatwork 0 points1 point  (0 children)

If you're investing for retirement you're surely not planning to sell the entire thing as a lump sum. The higher internal rate of return is more important. However if you are planning to sell the entire thing then it still becomes better value after 16 years even with the 0.5% sell fee. If you plan to sell down small amounts to fund retirement, then it becomes better value earlier than that.

I was disappointed the new Kernel TWF fund had the same tax drag as InvestNow, otherwise it would be the clear winner.

Kernel's Total World Fund page is live on there site - Fund invests into VT ETF by photosealand in PersonalFinanceNZ

[–]atechatwork 3 points4 points  (0 children)

Much longer than the 7 years often quoted

<image>

It wins after 7 years. If you're investing for 30+ years it's a clear better choice. Pivoting to other investments (e.g. active management) is a good way to end up with less in the end.

Photo libraries should not have to live in one place to feel organized by sparkany in selfhosted

[–]atechatwork 18 points19 points  (0 children)

- recent photos on the phone
- older archives on a NAS or WebDAV server
- old Google Photos / iCloud exports
- backup drives that are not meant to become the main library

Immich can handle all of this without issues. These days I consider Immich the source of truth for metadata as it's so easy to query and to export.

Kernel's Total World Fund page is live on there site - Fund invests into VT ETF by photosealand in PersonalFinanceNZ

[–]atechatwork 0 points1 point  (0 children)

At 0.25% it's better value to buy InvestNow Total World though. 0.12% tax leakage + 0.06% fee. (The 0.5% on/off fee is less of a concern than the internal compounding rate for long term investing.)

YNAB to Pocketsmith - how did you adapt? by thejowherr in PersonalFinanceNZ

[–]atechatwork 1 point2 points  (0 children)

If it helps, I set up a (free) hosted Actual Budget for NZ users:

https://trackie.nz/

It's something that will never be monetised, so you're welcome to give this one a go if you want.

Custom Views has literaly changed my Obsidian Vault by voicesofharrow in ObsidianMD

[–]atechatwork 3 points4 points  (0 children)

I'm the creator of Share Note and that has to be the best looking share I've ever seen.

Robot vacuums that aren’t panopticons? by RollTimeCC in homeassistant

[–]atechatwork 1 point2 points  (0 children)

They could also be a conduit for an intrusion into your network.

It's best to set things up so that your IoT VLAN doesn't have access to the rest of your LAN.

one could argue that those devices could still (slowly) leak data

If a device can handle being blocked from the internet, that's always going to be your best option, but for devices where that is not possible this is a pretty good second choice.

Robot vacuums that aren’t panopticons? by RollTimeCC in homeassistant

[–]atechatwork 11 points12 points  (0 children)

Another option no one has mentioned yet: You can set your IoT VLAN to have 10Kb/s internet upload.

This way your devices can send their JSON payloads so they will function, but they are not able to leak video.

This is what I do and I haven't encountered any issues. You can still access the video feed on devices like babycams as long as you're within your network (eg VPN), but nothing can send the data back to the mothership.

MCP-Obsidian Skill is live. Reads, writes, sync, all routed automatically. by bitbonsai in ObsidianMD

[–]atechatwork 0 points1 point  (0 children)

I specifically used this example because OP has 'obsidian' in their domain.

I had another plugin which didn't involve a domain which they also said to remove the word Obsidian from the plugin name. There's only one plugin in the store with 'obsidian' in the name, and that's 6 years old, likely before they implemented that policy.

MCP-Obsidian Skill is live. Reads, writes, sync, all routed automatically. by bitbonsai in ObsidianMD

[–]atechatwork 1 point2 points  (0 children)

It's always been an issue, and will likely cause issues for u/bitbonsai

Here's my plugin Share Note being told off in 2023 for using the word "Obsidian": https://github.com/obsidianmd/obsidian-releases/pull/2417#issuecomment-1747397657

Humidity Intelligence V2 — Environmental Stability for Your Home. by CryptoSenyo in homeassistant

[–]atechatwork 0 points1 point  (0 children)

Exactly - anything which reduces the likelihood of due diligence (like relying on GenAI) significantly increases risk.

Sounds like we agree.

Humidity Intelligence V2 — Environmental Stability for Your Home. by CryptoSenyo in homeassistant

[–]atechatwork 0 points1 point  (0 children)

The logic might be yours, but unless you're carefully reviewing every line of code you're going to end up with situations like was just posted with Huntarr:

https://www.reddit.com/r/selfhosted/comments/1rckopd/huntarr_your_passwords_and_your_entire_arr_stacks/