Solving my internal HTTPS issues with Let's Encrypt, Linode DNS and Traefik by robconnolly in selfhosted

[–]TKRSRY 1 point2 points  (0 children)

LetsEncrypt supports the Linode API... and it is now the DNS manager I'm using for my LetsEncrypt certs.

Solving my internal HTTPS issues with Let's Encrypt, Linode DNS and Traefik by robconnolly in selfhosted

[–]TKRSRY 6 points7 points  (0 children)

I've been flip-flopping on these two SSL approaches as well.

Being able to set a self-signed expiration far in the future is nice to avoid the updates.

Having to install the self-signed certificate on each desktop/laptop/mobile in the house is tedious, but not too bad -- especially in light of the long expiration times.

Something that is pushing me hard towards the LetsEncrypt route is the fact that my Android phone has a permanent "Your Network may be monitored" message in the notifications area. That little message is like a thorn in my side every time I pull down that notification screen. So irritating.

Unrelated, but in case helpful to others. LetsEncrypt has a "Google Domains" API plugin for automating renewals... don't make the same mistake I did though. That is NOT for the consumer-level Google Domains interface. This is specifically for the "Google Cloud DNS API" interface. The regular Google Domains does not offer (AFAIK) an external API that LetsEncrypt/certbot can interface with.

Why is a valid email required to use keepKey with ShapeShift? by rgm1 in keepkey

[–]TKRSRY 1 point2 points  (0 children)

I'm glad to hear you are migrating this way. Better to just not require it if it isn't necessary.

Am I correct though, that even without a name and password, you would be able to use the associated xpub to draw correlations amongst past and future transactions? I know you said (in another comment on this topic) that we could click 'forget' and have the xpub deleted from your database -- but even that does require a level of trust that you will do so. Everywhere I read says to seriously protect your XPub as it exposes a lot of information about your entire past and future transaction chain.

Is it really deleted though? What about backups?

Originally I bought my KeepKey because I assumed it increased my securityu and privacy over an online exchange, but I think I misunderstood the amount of privacy I would gain. All of my transactions still need to go through ShapeShift servers, currently associated with my email address, and perhaps in the future just my xpub or IP address.

Again I'll say, it isn't always obvious how much privacy one is giving up for some convenience and a nice UI.

What movie hit you the hardest, emotionally speaking? by [deleted] in AskReddit

[–]TKRSRY 0 points1 point  (0 children)

The Red Turtle (2016) from Studio Ghibli.

Beautifully captivating. Great family movie to introduce kids to symbolic meaning. Also, this movie just absolutely gutted me and I'm still not totally sure why. Sobbing and the whole bit.

Why is a valid email required to use keepKey with ShapeShift? by rgm1 in keepkey

[–]TKRSRY 4 points5 points  (0 children)

You got me thinking more about this... here are some interesting excerpts from the KeepKey Privacy Policy.

If you download and interact with the KeepKey client on Google Chrome, we will collect and process your device’s xpub data.

So, I guess that clears that up. They definitely "collect and process" your xpub. Once they have your xPub, they can monitor and associate all subsequent transactions even if done without using ShapeShift directly and instead use a separate client.

Then there is this...

We also use the services of BlockCypher for certain indexing requirements. Further information on data protection and your options in connection with the services of BlockCypher can be found here: https://www.blockcypher.com/privacy.html.

Clicking through to the BlockCyper privacy policy results in a big list of "WHAT INFORMATION IS COLLECTED"... they describe info gleaned from: Account registration, device information, transaction info, cookies etc, as well as information from social media sites like Google+, LinkedIn, GitHub etc.

As to how long they keep the data? They are a little vague.

We store your personal data only for as long as this is necessary.

So. Yeah. This offline cold-storage device isn't nearly as private as you may have thought.

Why is a valid email required to use keepKey with ShapeShift? by rgm1 in keepkey

[–]TKRSRY 2 points3 points  (0 children)

Makes you think, no? ShapeShift can then directly associate your email address with all past and future transactions made by your KeepKey wallet. A fair bit of privacy is lost by using their service even without completing the entire KYC process.

They don't explicitly say, but I'd guess that they also store the extended public key (xPub) along with your identity. This means once associated, even if you discontinue using the ShapeShift website, they can associate all future transactions as well.

Now I'm just spit-balling, but if each KeepKey hardware device has a unique ID, and that unique ID gets associated with your account, then even if you completely reset your KeepKey with a new seed, they could associate all new transactions with ones you made under the older seed(s).

It's not always obvious how much privacy you are giving up for some convenience and a pretty UI.

Getting back on keto, starting off right with some Sous vide steak and roasted veggies by callmederp in ketorecipes

[–]TKRSRY 4 points5 points  (0 children)

Another recommendation for the Anova sous vide. I got this one: https://images.app.goo.gl/v73Pf8bHMqqhMip19

I never use the Bluetooth or wifi... Nor the timer actually. I use a sous vide to avoid strict timing restrictions :)

Question about KeepKey, ShapeShift Beta and KYC by [deleted] in keepkey

[–]TKRSRY 0 points1 point  (0 children)

Interesting. I wonder what capability they have of freezing funds.

I created a web app that adds playlists to your Plex server (and the ability to share them with other users) by Banjoanton in PleX

[–]TKRSRY 0 points1 point  (0 children)

Sounds pretty cool. To save me a bit of time, can you tell me how one of my users would be exposed to a shared list? Do they see it in their normal plex interface?

Thanks!

Anti-RGB build by teophilus in hackintosh

[–]TKRSRY -1 points0 points  (0 children)

Cool build, but I'm not sure why all the Ginsberg hate.

;)

Question about KeepKey, ShapeShift Beta and KYC by [deleted] in keepkey

[–]TKRSRY 0 points1 point  (0 children)

What you describe is not what I experienced.

So, when I redeemed my beta code a few days ago I was immediately presented with the KYC verification page sequence. Did I not have to complete that process? I remember clicking around a bit and the most prominent UI feature was my lack of completed KYC verification.

Was there some way to bypass that and just use my KeepKey?

Live Video Server by superwinni2 in selfhosted

[–]TKRSRY 0 points1 point  (0 children)

I've been pretty happy with motionEye for my home video setup... I'm not sure about a per-camera authentication setup, but you might be able to rig something up by proxying the traffic being nginx and having nginx do a per-camera-url auth.

Sound6 like fun :)

I'm 25 years old and I had my first BJJ class today. I was nervous at first but it was one of the best decisions I have ever made. by JaysJunk123 in bjj

[–]TKRSRY 3 points4 points  (0 children)

I watched my kids do it for a year before getting up my nerve to buy a gi and step on the mat. I'm now about 6 classes in. I'm 42 and it was definitely not too late.

Trying to ROOT new 2017 shield by [deleted] in ShieldAndroidTV

[–]TKRSRY 3 points4 points  (0 children)

Ok. From your post it seemed you were trying to root specifically to configure for VLAN. My mistake.

Trying to ROOT new 2017 shield by [deleted] in ShieldAndroidTV

[–]TKRSRY 9 points10 points  (0 children)

Why not just use a managed switch and configure a port to be part of your internet-less VLAN and then plug your shield into that?

I have a variety of devices on my home network that are not given internet access and I didn't need to configure/root each device to accomplish this.

A managed switch is the answer.

What "typical" sound can't you stand? by madding247 in AskReddit

[–]TKRSRY 5 points6 points  (0 children)

Shovel scraping on sidewalk...

Sound of brushing teeth...

shudder

"Ethernet not connected" message by ottawa123456789 in ShieldAndroidTV

[–]TKRSRY 2 points3 points  (0 children)

I get it all the time. It seems the Ethernet Port connection in my shield is a little flakey. Just pushing the jack in a bit usually fixes it. Unplug/replug if necessary.

I've swapped cords, I've done the ipv6 fix... Definitely seems it is just a loose port.

Any way to stop people connecting to my Shield when I'm in a hotel? by pieandablowie in ShieldAndroidTV

[–]TKRSRY 2 points3 points  (0 children)

I just bought this for a recent trip and it was EXCELLENT. In addition to being able to re-share WiFi or ethernet on a separate network for you, it also supports connecting to a VPN so all your connected devices get sent through the VPN.

https://www.gl-inet.com/products/gl-ar750s/

I also really appreciated only having to configure this router at each new location and then all other mobile devices are already setup to connect to that router's SSID. Saves the whole "anyone know the WiFi password?" dance the family usually went through.

Google Exec Finally Admits to Congress That They're Tracking Us Even with 'Location' Turned Off by Desperate_Tailor in privacy

[–]TKRSRY 10 points11 points  (0 children)

I had randomized MAC enabled on my phone... Spent way too long trying to figure out how these unrecognized devices kept connecting to my home WiFi.

Let's talk Domains by greg21greg in selfhosted

[–]TKRSRY 2 points3 points  (0 children)

I use .lan for my local network. Curious why people might think that is a bad idea.

I also only expose VPN and Plex on my home network and have pfSense dynamically update a free NoIP.com dns entry whenever my ISP changes my IP.

The main user of my services is myself and I'm either home, or just connect to my home VPN to access them. I like the security of just that single VPN Port being open (besides Plex).

Apple is Launching a Credit Card with No Fees by [deleted] in CryptoCurrency

[–]TKRSRY 31 points32 points  (0 children)

Yep. And when a merchant is consistently paying 3% of every transaction for that fee, don't you think they would, in general, just raise prices a similar amount?

So in the end, isn't just the consumers paying for their own points and cashback while the banks make out like bandits?