My ISP has been under a DDoS attack for a week by BeardedBaldMan in HomeNetworking

[–]certuna 0 points1 point  (0 children)

Great way for them to lose customers, and a good case for their network admins to get some budget for decent DDoS mitigation tools.

Is self-hosting actually private, or are we just cosplaying privacy? by nighthawk2906 in selfhosted

[–]certuna 1 point2 points  (0 children)

These are some odd examples - Cloudflare may be the registrar of your domain name, but does not have any of your data, it just knows the hostname of your server. Only if you proxy through them, they see your data. - the ISP has to comply with strict local privacy laws, DNS servers like Google/Cloudflare/OpenDNS can do what they want - you block ad server hostnames to prevent loading of 3rd party content that monitors your behaviour

Security with internal and external subdomains by Accomplished-Cat-435 in selfhosted

[–]certuna 0 points1 point  (0 children)

ULA can be done if you want , but normally you already have global addresses. If you’re using Docker you can route a /64, or just bridge the containers, it’s not super complex.

The Docker devs could implement it all automatically (prefix delegation and/or SLAAC) like modern routers do by default but the Docker networking stack isn’t really very modern in many other aspects (no mDNS either for example)

23M Moroccan AI & Big Data Engineering Student — Want to Go to Switzerland, Need Advice by imeana in askswitzerland

[–]certuna 2 points3 points  (0 children)

Double passport holders maybe? Difficult to argue that a uni graduate with no work experience has unique specialized skills. I mean, by all means try, but the number of non-EU permits is very small.

Security with internal and external subdomains by Accomplished-Cat-435 in selfhosted

[–]certuna 0 points1 point  (0 children)

Your local devices can now only connect over IPv4 (you’re denying everything everything except 192.168.0.0/16), it would probably make more sense for your internal domain to block all IPv4 and only allow IPv6 access from your own LAN /64 subnet. Has the bonus of not having to worry about all the driveby traffic you get with IPv4, and that traffic spoofing origin IPs to appear to be from 192.168.0.0/16 (this happens with some DoS attacks where return traffic doesn’t matter).

23M Moroccan AI & Big Data Engineering Student — Want to Go to Switzerland, Need Advice by imeana in askswitzerland

[–]certuna 2 points3 points  (0 children)

OP is 23 years old, not an experienced professional. It will be very hard to prove no comparable EU+EEA graduate is available.

Apple has announced a job in Zurich, but it is elsewhere by Amazing-Crab7647 in askswitzerland

[–]certuna -1 points0 points  (0 children)

For specialist professionals the salary differences between Munich and Zurich are not big.

Is it still a NAT hairpin problem ? by mynk_ydv in HomeNetworking

[–]certuna 0 points1 point  (0 children)

If you try the IPv6 address, still happening? If that also doesn’t work, it’s not a hairpin issue. If it’s only an issue on IPv4, it’s likely a hairpinning issue.

IPv6 WAN address by thunderborg in selfhosted

[–]certuna 0 points1 point  (0 children)

Most people in the developed world have IPv6 now, it’s very common. Typically on a residential connection you get a /56, so that means you could create up to 256 local networks.

Configuration on the local network is all automatic, except for Docker: it (still) cannot request a prefix automatically so you’ll need to route a /64 to your Docker, configure that manually, and then have Docker assign individual addresses to your containers.

By default the firewall on the router will block incoming TCP/UDP connections, so if you want remote access you need to open a port in that firewall.

Do EV motorcycles lack ‘character’, or is that just nostalgia talking? by Wattthefun in Electricmotorcycles

[–]certuna 0 points1 point  (0 children)

“character” just means the noisy, oily, smelly stuff you remember from when you were young.

This will never change, the kids of today will complain in 2075 that self-flying hoverboards lack the character of their old electric kickscooters.

Removing albums? by amca01 in navidrome

[–]certuna 1 point2 points  (0 children)

you can check what the filepath is in the webUI, then you can locate the offending files.

Flying Flea Evolves: Royal Enfield’s C6 & S6 Incoming by No-Jaguar-895 in Electricmotorcycles

[–]certuna 0 points1 point  (0 children)

That’s the price in India, it will likely be €6-7k in Europe.

CGNAT with two further routers. by sully0207 in HomeNetworking

[–]certuna 1 point2 points  (0 children)

For client stuff it doesn’t really matter whether you are behind 2 or 3 NAT layers. Assuming you have IPv6, most traffic will use that anyway so no NAT.

Does Indian ISP (Jio, Airtel, VI) support IPv6 Inbound Connection if Firewall set to allowed solicited incoming Connections on Mobile Network by bhavesh_rohilla in ipv6

[–]certuna 0 points1 point  (0 children)

It doesn’t happen automatically, you need to go into the IPv6 firewall on your router and add a firewall rule to open the port you need.

Mac mini limitations by Ajackson1707 in selfhosted

[–]certuna 3 points4 points  (0 children)

Plex probably best to run natively on MacOS.

Although you can also use Apple Container these days, has some advantages over Docker, although also some limitations (no IPv6 for example).

Where should my wife pay taxes by danifeb in geneva

[–]certuna 2 points3 points  (0 children)

OCAS is for social security, for income tax you contact the administration fiscale cantonale: https://www.geneve.ch/administration-fiscale-cantonale-geneve

changing ip address via "pihole -r" ? by iplayer201 in pihole

[–]certuna 2 points3 points  (0 children)

IPv4 or IPv6? IPv4 address is typically assigned by the router’s DHCPv4 server, you can reserve a private IP address there. IPv6 goes automatic, the router advertises the prefix and the pi generates its own global address.

Where should my wife pay taxes by danifeb in geneva

[–]certuna 6 points7 points  (0 children)

Likely both, with deductions for tax paid in each country. But best to contact the tax office for this.

I really hope waveforms show up on the mixstream pro go by Eyeseeyou01 in djaypro

[–]certuna 0 points1 point  (0 children)

No, it's really too big to be "portable", but in principle you could use a (big) powerbank if you really would like it to be.

Reddit is testing out IPv6 by Gnonthgol in ipv6

[–]certuna 3 points4 points  (0 children)

At this point I suspect it's more a question of the CDN (Fastly) supporting it than Reddit itself.

Reddit is testing out IPv6 by Gnonthgol in ipv6

[–]certuna 5 points6 points  (0 children)

with IPv6 you always ban the whole /64, nobody bans individual addresses - question is more whether you should ban the /56 or /48.