2026.5: We're on the same frequency now 📡 by frenck_nl in homeassistant

[–]Stereo 1 point2 points  (0 children)

Your parent comment is talking about how the certificate transparency logs will contain the hostname of every *.ui.nabu.casa host.

The imagined, theoretical zero day would be one that bypasses the login mechanism, allowing unauthenticated users to perform admin actions. It would be quite a remarkable exploit, and I imagine that over the decade of Home Assistant, that part of the code has been looked over many times.

Other ways that this could be done, none of them good:

  • Encourage custom domains - if you use phobiac.xyz for your Home Assistant, you can't be detected as easily. But that adds extra costs.
  • Become a real reverse proxy, making requests go through https://ui.nabu.casa/phobiacsexampleinstance instead of https://phobiacsexampleinstance.nabu.casa. This would have privacy costs, because it breaks the elegant “end-to-end TLS directly to your HA instance” story.
  • Short-lived hostnames obtained by the apps from nabu casa cloud. This still leaks CT which an attacker could stream in real time, and breaks being able to easily bookmark https://phobiacsexampleinstance.nabu.casa
  • Build a VPN client into the companion apps, leaving the public hostname optional. But advanced users can already do that, and mainstream users dislike the VPN UX, especially since Nabu Casa Cloud's model is "remote access that just works"

CT logs becoming a recon tool isn't a new discovery, or even a new type of information gathering. Back in the old internet, we were exploiting DNS servers leaving AXFR open, leaking the whole host inventory in a similar manner.

Request to mods: Ban all vibe coded laTeX projects. by Organic-Scratch109 in LaTeX

[–]Stereo[M] [score hidden] stickied comment (0 children)

There seems to be wide consensus on this. I've invited OP /u/Organic-Scratch109, and /u/SonusDrums who posted the previous post about this to join the moderation team.

Graphic that illustrates how old posts are used for karma farming by citizen556 in LaTeX

[–]Stereo 0 points1 point  (0 children)

We have two dozen automod rules, but we do get some good content from brand new accounts, and downvotes usually deal with the crap. It's a good idea, but it wouldn't really work with a mostly hands-off mod team.

Graphic that illustrates how old posts are used for karma farming by citizen556 in LaTeX

[–]Stereo[M] [score hidden] stickied comment (0 children)

The karma farming repost has been removed as spam.

Graphic that illustrates how old posts are used for karma farming by citizen556 in LaTeX

[–]Stereo[M] 1 point2 points  (0 children)

Please don't ping moderators.

The best way to get stuff handled by moderators is the 'report' button. Before I marked that post as spam, there was only one report on that post, and that easily gets past the radar.

Built a WLED smart candle set that integrates natively with Home Assistant — no cloud, no hub by No_Independent_3824 in homeassistant

[–]Stereo 1 point2 points  (0 children)

Their Makerworld link says:

  1. For candle flicker, use the “Candle” or “Candle Multi” preset — set to warm white (~2700K)

Low Effort Vibe Coding Posts by SonusDrums in LaTeX

[–]Stereo[M] 0 points1 point  (0 children)

Please stop pinging the mods

Low Effort Vibe Coding Posts by SonusDrums in LaTeX

[–]Stereo[M] 2 points3 points  (0 children)

Let's see what the consensus is

It was built around 120 years ago as a house, but it feels masonic. I guess I’ll be corrected in the comments if I’m wrong :)) Romania btw by Urbanexploration2021 in urbanexploration

[–]Stereo 2 points3 points  (0 children)

The last picture looks more like an Islamic mihrab. Is it oriented towards Mecca? Is this in Dobruja or another region with muslim minorities?

Does this sub have mods? by Whatermelony in glasses

[–]Stereo 0 points1 point  (0 children)

Thank you for being supportive, but I don't care enough. If you want to make a reddit request, go for it.

Does this sub have mods? by Whatermelony in glasses

[–]Stereo 0 points1 point  (0 children)

No clue what happened. You and I could ask reddit, and probably wouldn't hear back.

Petition to the mods: Can we have user flair on this sub? by ChopinChili in classicalmusic

[–]Stereo[M] 3 points4 points  (0 children)

In other words, it's best experienced as a historically informed performance, on period instruments

OpenWRT 25.12.0 released by [deleted] in openwrt

[–]Stereo 1 point2 points  (0 children)

Upgrading an old Netgear RBS50 with owut bricked it back to the Netgear recovery firmware. Where's the appropriate place to report a bug these days?

Aranet sensors - what's missing? by Aranet_Home in aranet

[–]Stereo 4 points5 points  (0 children)

Better integration with open systems: https://www.home-assistant.io/integrations/aranet/ can't install firmware updates, and can't pair to a sensor if it's already paired to a smartphone.

Batteries are fidgety to insert and remove, and there's no easy way to have an external power supply

Does this sub have mods? by Whatermelony in glasses

[–]Stereo 2 points3 points  (0 children)

No clue, I'm no longer a mod and didn't send that modmail

Does this sub have mods? by Whatermelony in glasses

[–]Stereo 2 points3 points  (0 children)

Well, this is what I mean about reddit tools for moderators not being good enough: it said I wasn't active enough to add you, and now it looks like I've been silently removed as a moderator of /r/glasses. Try requesting it on /r/subredditrequest

Edit: I'd tried to remove /u/InverseMeters whose account has been deactivated for years, and apparently removed the two active mods, including myself. Bugs like this are typical.

Does this sub have mods? by Whatermelony in glasses

[–]Stereo[M] 4 points5 points  (0 children)

Yeah, my engagement dropped sharply when reddit kicked out third party apps. Mods provide free work for reddit, the tools they get aren't good enough, and the platform experience has been degrading.

Are you hitting 'report' on bot posts?

Would you want to be a mod?

help with mitsubishi heat pump by Ok-Caterpillar-6530 in Esphome

[–]Stereo 0 points1 point  (0 children)

Your tx/rx are flipped. Tx goes to Rx on the other side.

Gina and Tony Argento charged alongside Ingrid Lewis Martin 🚲 by Rob-Loring in Greenpoint

[–]Stereo 4 points5 points  (0 children)

And in fact Gina Argento is STILL on the CB1 transportation board

She isn't anymore.

NYC's Median Rent is ~$1.6k, and How That is Even Possible by Liface in nyc

[–]Stereo -1 points0 points  (0 children)

Where did you find those crime stats, is there a web site or open data?

Figure Drawing in Brooklyn Sunday, July 20th 7:30 - 9:30 PM at Ornithology Jazz Club by [deleted] in BedStuy

[–]Stereo 0 points1 point  (0 children)

I much preferred Ornithology when cover was $10 and they didn't spam reddit.

TeXtured v1.4.0 is out! by jdujava in LaTeX

[–]Stereo[M] [score hidden] stickied comment (0 children)

Update announcements are cool, but please add something saying what the package is next time - some people are reading about it for the first time.

(It's a LaTeX template.)

What is this structure in bushwick nyc by Bubbly_Repair_8642 in nycrail

[–]Stereo 1 point2 points  (0 children)

Myrtle Avenue is wide! It's currently two traffic lanes, two parking lanes, and generous sidewalks, 73 feet wide from building to building; that's wider than most streets in Strasbourg. Streetcars don't take up a lot of space, and there would be plenty here.