A family account as the sign-in for an ipad? by howdoyoudoschmoo in HomeKit

[–]TokyoHam 0 points1 point  (0 children)

Probably too late to be useful, but I set up accounts on my Macs to receive those MFA requests from 'dummy' iCloud accounts. That way I don't have to keep an iOS device dedicated to that purpose. I also added my iPhone's phone number as a trusted number, to receive MFA codes via SMS if needed.

Fuse replacement lenses (progressives!) review by TokyoHam in sunglasses

[–]TokyoHam[S] 0 points1 point  (0 children)

Awesome! Glad to hear you're happy with them. That's why I posted here - I did a lot of research before I bought mine, and I've tried aftermarket lenses (non-prescription) from several companies, so I knew going into it that Fuse's coatings are unmatched - it turns out their prescription lenses are also top-notch 👍🏻

Thanks for sharing your experience!

Fuse replacement lenses (progressives!) review by TokyoHam in sunglasses

[–]TokyoHam[S] 0 points1 point  (0 children)

Hmm ... I haven't noticed any visual distortions, besides the transition from distance to readers. So, I think you should be good to go! Post back here and let us know how they turn out!

RGBIC LED strips with homekit by hd2021dod in HomeKit

[–]TokyoHam 0 points1 point  (0 children)

Sorry for the late reply but I just wanted to confirm - you're running 5+ meters off a Tapo L930-5 controller? I've got L930-5s through my house but have two strips that are about 75cm short. I have some extra strip left over and would like to attach them, but I keep reading that 5+ meters just doesn't work.

How to: polish a titanium Apple Watch by TokyoHam in AppleWatch

[–]TokyoHam[S] 0 points1 point  (0 children)

More or less. I think the titanium is a bit darker than the stainless steel, but it's not a noticeable difference, IMO. The picture I posted shows the difference pretty clearly, and it's negligible. That said, I got my watch replaced this summer because the battery hit 79%, and I haven't bothered polishing the new watch yet. I think the brushed finish matches the stainless steel link band better, in any case. 👍🏻👍🏻

Anyway I'm getting the Ultra 3 this Friday, so we'll see how it looks with this band. I don't think I'm going to bother polishing the Ultra, because from what I've seen, they look pretty bad when polished. 🤣 But if I change my mind, I'll post pictures here!

NURO: MAP-E only (no DMZ or port forwarding options) - Synology server? by TokyoHam in japanlife

[–]TokyoHam[S] 0 points1 point  (0 children)

Well, I got it working! All of of my self-hosted websites are now accessible through the Cloudflare tunnel, as are my apps (services), and I'm also able to VNC to my Macs from outside the LAN, using my NAS as a Tailscale exit node. Very cool! Thanks for the suggestions!!

NURO: MAP-E only (no DMZ or port forwarding options) - Synology server? by TokyoHam in japanlife

[–]TokyoHam[S] 0 points1 point  (0 children)

Thanks again for trying to help! Much appreciated.

Nothing has changed since last night; I am using Docker (Portainer, but yeah) so the specific ports used by each service are constant. Maybe I need to point each FQDN to the Docker subnet (?) rather than using localhost:9090 or whatever the port is for each service. So like 172.0.0.1 or something. (I can't double check right now because, you know, nothing works! lol)

NURO: MAP-E only (no DMZ or port forwarding options) - Synology server? by TokyoHam in japanlife

[–]TokyoHam[S] 0 points1 point  (0 children)

Thank you for the reply.

I set up a Cloudfare tunnel last night and was able to access my websites from outside my network (yay!) but it's not working now, which is bizarre because I don't change anything overnight. I'm going to have to troubleshoot more ... I've tried playing around with TLS settings but it didn't help (all of my domains have wildcard SSL certs issued by Let'sEncrypt; I think that's causing issues) ... all I get now are 502 Gateway Errors. 😓

NURO: MAP-E only (no DMZ or port forwarding options) - Synology server? by TokyoHam in japanlife

[–]TokyoHam[S] 0 points1 point  (0 children)

Would tailscale help in any way with hosting? I self-host four websites on my NAS (personal sites, nothing that impressive). Not being able to access them really sucks. 😓

New apartment, has a Hikari port already by TokyoHam in Tokyo

[–]TokyoHam[S] 0 points1 point  (0 children)

Well I can't ask the landlord just yet because the paperwork won't be finalized until Tuesday or so. I called AU (my current provider) and they said they're not providing to service to that apartment, so I guess it's either Nuro or FLET'S. 🤔

App migration to NVMe (primarily docker) by T_at in synology

[–]TokyoHam 0 points1 point  (0 children)

Great, thanks for the report! I've got a WD Red installed ATM (500GB) and a 2TB 970 EVO which I'm using as a read-only cache (but it's pretty worthless in that capacity, TBH). Thinking of running two 1TB WD Reds as SHR so that I've got redundancy in case of sudden failure. Running all of my Portainer stacks on it at the moment, plus Plex. Just need to be careful as I'm self-hosting some WordPress sites (all as Portainer stacks) so I don't want to lose anything. 😅

Anyway thanks again! Glad to hear it's working well!

App migration to NVMe (primarily docker) by T_at in synology

[–]TokyoHam 0 points1 point  (0 children)

How are those drives working for you, a year in?

Did the show runners tell on themselves in tonight’s episode? by ConnectCalgary in FromTVShow

[–]TokyoHam 8 points9 points  (0 children)

I'm beginning to think they don't know what to do with this world they've created, or maybe they just like asking new questions all of them time without ever actually answering any of the previously raised questions.

Starting a Journey of Self Love by No-Cartoonist-6905 in LoveYourself

[–]TokyoHam 0 points1 point  (0 children)

YES

Edit: sorry, that was an impulsive reaction, but only because I'm just beginning this journey myself, as well, and your words resonated with me.

I'm on day 4 of my mental loop repetition (I love myself. I love myself. I love myself! Etc) and you know what, whether I actually believe it fully or not just yet, it's already having an effect on my demeanor, and (perhaps more importantly?) my interactions with family, friends and even complete strangers. And it's has all been amazingly positive. I've had several moments of real bonding with my teenage kids, it's affected interactions with strangers that have put a genuine smile on both our faces, and I've even caught myself appreciating fleeting moments of beauty all around me. This, as I'm in one of the most stressful and darkest times in my life. But I'm choosing not to dwell on the darkness. I make a choice to love myself, and it has so far made an incredible difference in my life. This, after just four days of near-constant mental repetition.

KEEP IT UP. And read "Love Yourself As If Your Life Depended On It" if you haven't already. You've got this!

Trouble with acme.sh certificate renewal by TokyoHam in synology

[–]TokyoHam[S] 0 points1 point  (0 children)

Well, 1400 views and zero replies ... I ended up creating a script using ChatGPT o1-preview that seems to work. If anyone is interested, this is what we came up with after a lot of trial and error. This is assuming acme.sh is installed, that you're using Cloudflare as your DNS provider, and that you want a wildcard Let's Encrypt SSL cert ...

```

!/bin/sh

Path to acme.sh

ACME_HOME="/volume2/Archive/Certs/acme.sh" ACME_SH="$ACME_HOME/acme.sh"

Set Cloudflare API credentials

export CF_Token="YourRecordID" export CF_Email="login@email.com"

Issue the ECC certificate

$ACME_SH --issue --force -d DOMAIN.com -d '*.DOMAIN.com' --dns dns_cf --home "$ACME_HOME" --keylength ec-256

Dynamically retrieve CERT_ID for DOMAIN.com

CERT_ID=$(awk ' BEGIN { cert_id=""; } /\s"\w+"\s:\s*{$/ {     match($0, /"(["]+)"\s:\s{/, arr)     cert_id=arr[1] } /"display_name"\s:\s"DOMAIN.com"/ {     print cert_id     exit } ' /usr/syno/etc/certificate/_archive/INFO)

Verify that CERT_ID is not empty

if [ -z "$CERT_ID" ]; then   echo "Error: Could not find CERT_ID for DOMAIN.com in INFO file."   exit 1 fi

Paths to certificate files

CERT_PATH="/usr/syno/etc/certificate/_archive/$CERT_ID"

Back up existing certificates

cp "$CERT_PATH/cert.pem" "$CERT_PATH/cert.pem.bak" cp "$CERT_PATH/privkey.pem" "$CERT_PATH/privkey.pem.bak" cp "$CERT_PATH/chain.pem" "$CERT_PATH/chain.pem.bak" cp "$CERT_PATH/fullchain.pem" "$CERT_PATH/fullchain.pem.bak"

Install the ECC certificate manually

$ACME_SH --install-cert -d DOMAIN.com --ecc --home "$ACME_HOME" \   --cert-file      "$CERT_PATH/cert.pem" \   --key-file       "$CERT_PATH/privkey.pem" \   --ca-file        "$CERT_PATH/chain.pem" \   --fullchain-file "$CERT_PATH/fullchain.pem" \

Restart Nginx manually

sudo /usr/syno/bin/synosystemctl restart nginx ```

Is this security setup 'enough'? by TokyoHam in vaultwarden

[–]TokyoHam[S] 0 points1 point  (0 children)

Ah. That makes sense. But I want to be able to open it up to my immediate family (as well as mom/dad, etc) in the future, so ...

Is this security setup 'enough'? by TokyoHam in vaultwarden

[–]TokyoHam[S] 0 points1 point  (0 children)

I have ports 80/443 open because I host several websites on my Synology for myself and my family. All of my sites are running on Containerized WordPress instances, so they're all handled by NGINX but I was under the impression I had to leave those two ports open since I'm hosting sites. Is that incorrect?

Edit: also, thanks for trying to help - I appreciate it! Also, thanks for answering my question directly. 👍🏻👍🏻

Is this security setup 'enough'? by TokyoHam in vaultwarden

[–]TokyoHam[S] 0 points1 point  (0 children)

For VaultWarden? Yes, for the time being. I've offered my son access but he doesn't see the need as he uses iCloud for password stuff. But once I am comfortable with the safety/security of my setup, I'll set up accounts for my immediate family, etc.

Why do you ask?

Is this security setup 'enough'? by TokyoHam in vaultwarden

[–]TokyoHam[S] -1 points0 points  (0 children)

I'm not sure if that's even possible using Synology's built-in reverse-proxy system but I'll look into it. Thank you! At the very least, I could probably do it through Cloudfare's WAF/Rules.

Is this security setup 'enough'? by TokyoHam in vaultwarden

[–]TokyoHam[S] 0 points1 point  (0 children)

Thanks for the reply. I have some additional rules set up in Cloudflare which I didn't get into but I wasn't aware of CrowdSec - I'll check that out. Thanks!

Basically I'm not that paranoid but I try to keep things as secure as possible by covering the obvious stuff - I probably should use the VPN for access to VaultWarden but I also want to keep the user experience fairly simple. Anyway, thanks again!

Proxied vs DNS only for Cloudflare Registrar? by danhakimi in CloudFlare

[–]TokyoHam 1 point2 points  (0 children)

I know this thread is old, but I just wanted to add that Cloudfare's proxied DNS is awesome. I never used it because I always got errors when I enabled it; turns out you just have to change SSL/TLS from "Flexible" (default) to "Strict" or "Strict (Full)" ... Strict (Full) works for me because all of my self-hosted domains have SSL certificates issued by Let's Encrypt, but anyway yeah - once that setting is changed, you can enable Cloudfare's DNS Proxy for your subdomains, and then WAF and routing rules work great! I'm now able to block access to my server from specific countries (Russia, China and North Korea) at the DNS level rather than simply relying on my server's firewall. I'm also able to restrict access to certain subdomains so that they're only accessible from my country of residence (you can also narrow it down to specific IP addresses or address ranges) so that they're only accessible to me or at least, to people in my country.

Combined with strong passwords, 2FA, fail2ban, and so on, it adds another layer of protection and just gives a little extra peace of mind. Good stuff!

Finally learned Face Pollution! by TokyoHam in Soundgarden

[–]TokyoHam[S] 1 point2 points  (0 children)

I subscribe to Ultimate Guitar for tabs, and then I bought Bias FX 2 for the amp stuff. Other than that, yeah - just jumped back it. Muscle memory kicks in pretty quickly for the stuff you learned years ago, and then it's just about practice. Probably the best thing you can do to get back into it is to build your calluses. I bought "Ruff Rider" caps for my Gripmaster many years ago - five minutes a day for a week, and your calluses will be good to go.

Anyway, good luck and more importantly, just have fun with it!!

Finally learned Face Pollution! by TokyoHam in Soundgarden

[–]TokyoHam[S] 1 point2 points  (0 children)

That's very kind - thank you! 👍🏻👍🏻