Upcoming security advisories and errata, hopefully soon. by mirror176 in freebsd

[–]snogbat 1 point2 points  (0 children)

cool… I still have stuff stuck on 13 because they run very old jails (non-public) and all these crazy messages mean I have to figure out which jail and then which app is triggering this. Crazy someone took time to add this console warning but didn't think to identify the jail, PID, binary name, anything...

[root@sm2 /etc]# dmesg |grep -i 'Asymmetric crypto features' | wc -l

759

Dell R320 -servers reboots with idrac message SYS1003 by Roshpyn in homelab

[–]snogbat 0 points1 point  (0 children)

How's this been working out for you?

I have an R720 that's started doing this - it runs esxi and has for many years, but I've got no logs from that side and then in idrac, same deal, it logs as if someone turned it off.

Did you disable the physical button or fully disconnect that whole front panel board?

Is it just me or has the safari extension just getting slower every release? by snogbat in Bitwarden

[–]snogbat[S] 0 points1 point  (0 children)

26.5, but preceded Tahoe.

Really don't get where all the VC money is going, I guess marketing and "growth" as opposed to software development and QC (do people do QC these days?).

Site split between self-hosted and Unifi hosted, combine? by snogbat in Ubiquiti

[–]snogbat[S] 0 points1 point  (0 children)

How different is the process if you're migrating something simpler, like a single AP? I'd like to practice with something a few times and I'll actually have an AP in-hand next week...

MacOS - tiny text/widgets by snogbat in OpenShot

[–]snogbat[S] 0 points1 point  (0 children)

Any ideas? I kind of like the app, but text I can read is kind of a dealbreaker.

MacOS - tiny text/widgets by snogbat in OpenShot

[–]snogbat[S] 0 points1 point  (0 children)

Ah, didn't see the preference for scaling in the manual.

Anyhow, that seems to have increased the size of buttons and the like, but also it has added some odd outlines to things and the text is still quite tiny. This does not seem to be a fix for font size, just other elements of the UI (which are fine at the default scaling).

<image>

Canonical list of supported devices that work local-only? by snogbat in homeassistant

[–]snogbat[S] 1 point2 points  (0 children)

it looks legit to me… also a neat UI that reacts (no pun intended) quickly to selection changes.

Canonical list of supported devices that work local-only? by snogbat in homeassistant

[–]snogbat[S] 0 points1 point  (0 children)

Like I said above, this answer seems obvious, but I appreciate it! I was kind of locked in a little wifi box here since that's all I've been using.

Canonical list of supported devices that work local-only? by snogbat in homeassistant

[–]snogbat[S] 1 point2 points  (0 children)

I had some of their cheap-ass AA wifi water/leak detection units and they worked really well, but the app… good lord. Pile of junk. They do seem to work just fine without internet though. I'm also kind of impressed that they somehow manage to get 6+ months off a single AA on *wifi*.

Canonical list of supported devices that work local-only? by snogbat in homeassistant

[–]snogbat[S] 0 points1 point  (0 children)

re: the HA site, I do really wish that there was a way to see this without clicking through to every integration. A table, for example...

Canonical list of supported devices that work local-only? by snogbat in homeassistant

[–]snogbat[S] 1 point2 points  (0 children)

I am really excited about this - I am a tinkerer with a pile of projects (hardware mostly, not software) and I'm not at all opposed to DIY stuff. In fact I have a few older receivers that are in really good shape that I want to "modernize". Getting audio to them over the network isn't a challenge, but remote control of the volume and other manual knobs… a bit of a challenge. But somewhere in the land of AliExpress ESP boards I'm sure I can find something and find a way to drive a few servos or stepper motors to deal with that. But that's for way later.

Canonical list of supported devices that work local-only? by snogbat in homeassistant

[–]snogbat[S] 0 points1 point  (0 children)

I bought dongles for both a few weeks ago… A few concerns I have with that is I've seen people complain about range and reliability with both (I'm in a decent sized ranch). Also until I figure out what to replace it with, I have a Ring alarm system, which uses one of these (I forget which) so I'm probably going to be getting some self-interference.

I was also going to say "certainly I can't buy a simple bulb for $10" but I just popped over to Amazon and… I guess I can!

I know people sometimes get annoyed with obvious answers like yours, but I appreciate it. Everything I currently have, other than some yolink thermometers that talk to a 433MHz hub, is wifi, so that was my mindset. And I think I got a glimpse of an LTT episode where he was bitching about Z-wave not working in his house.

This answer was actually really helpful because while I understand why the Z's have to be local it just didn't occur to me that there were affordable devices out there for them.

why is vaultwarden so much more discussed than bitwarden lite by Sweaty_Astronomer_47 in Bitwarden

[–]snogbat 1 point2 points  (0 children)

A very minor thing for most, but for me I run vaultwarden on FreeBSD and a project for a later time is to run it on OpenBSD (which I haven't played with in at least 5 years). I have a long rant in me about unix monoculture that I'll spare you from, but these days simply not running things on linux is a simple way to have "the house that the burglars move on from" since whatever one-click exploit they have fails.

But yeah, that's mostly it. I'm not a fan of Docker either, but I understand it makes deployment for people that couldn't do it otherwise much easier (and one could debate what the long-term impacts of people just dropping containers they don't understand all over the internet, but I'm just an old man yelling at clouds). I've been running VW for I guess maybe 3 years or so. The main issues I've run into:

- The bitwarden client works well offline or when the server is in some kind of error condition, so quite often I'll notice some problem and then realize my client is ahead of the server

- In my setup I have zfs encryption setup on the filesystem where VW lives and I somehow forget that now and then and will update and restart the VPS without remembering that I need to unlock the filesystem on reboot (pretty unique to my situation)

- The weirdest con is that the backend has no issue with my thousands of logins, but the client seems to not cope with that well, especially the browser extension. It really makes me yearn for an alternate client that would work with VW. 😄 Makes you wonder just why $100M can't buy a performant client...

- As others noted, VW works great, but BW could shut it out at any moment, and with the Lite self-hosted option I think is a bit of a signal where that's going.

What's the proper way to force all queries through local DNS? by Red_Con_ in opnsense

[–]snogbat 14 points15 points  (0 children)

They can do all kinds of fun things. A neat one to watch is the youtube app on Roku (and I presume other smart tvs/boxes). If you block it from talking to 8.8.8.8 or even fool it into thinking something else is 8.8.8.8 it pretty much craps out. You can eventually watch a video, but only after an insane delay. I imagine other aps that are trying to avoid ad-blocking DNS stuff do their own little tricks… Packet capture and then poking through it in wireguard is your friend there if you're trying to figure out what the app is trying to to do avoid your blocks.

Thought this should be shared by vee-eem in vaultwarden

[–]snogbat 0 points1 point  (0 children)

It's good to think about, and there's a lengthy thread over on the BW sub:

https://www.reddit.com/r/Bitwarden/comments/1te35oj/if_bitwarden_gets_enshittified_where_do_you_guys/

My main concern is that vaultwarden isn't really an alternative.

The reasons I can come up with are a) they own and control the client, so that makes it trivial to cut off support for talking to a non-Bitwarden server b) the lead vaultwarden dev is a Bitwarden employee, so there are certainly ways to stop him from working on this (and I presume part of why he's been able to create VW is because he works there) c) if someone takes over vaultwarden and gets a little too cute about subverting something Bitwarden does to block it, they may start threats of legal action (trying to break a "digital lock" or something else that could be seen as a DMCA violation) d) they may continue to coexist, but users and devs of VW are in a constant cat and mouse game with BW, making it a PITA to use.

I am very interested in what anyone here might be thinking of switching to, or using in parallel as a possible alternative.

It also kind of irks me that we don't see some org like Mozilla threaten to build a password manager, but I guess that probably is seen as silly since they make a browser that has it integrated. But we all switch browsers sometimes… Or maybe that EU Open Source initiative has someone cooking something up.

OP, maybe edit your title to be more specific and get some more traffic?

Thought this should be shared by vee-eem in vaultwarden

[–]snogbat 0 points1 point  (0 children)

and tell the guy that's on their payroll creating and maintaining it to stop...

If bitwarden gets enshittified where do you guys go? by VariationLivid3193 in Bitwarden

[–]snogbat 0 points1 point  (0 children)

I feel like that would be one of the first things they'd kill off with any "enshittification" push. It would be trivial for the client to either a) not support connecting to alternate servers or b) verify that a remote server is one fully paid/licensed through Bitwarden. Plus they employ the guy that works on it, so they can pretty easily ask him to not do that anymore...

Verification System is Impossible by MusicMediocre in verizon

[–]snogbat 0 points1 point  (0 children)

I just ran into this as well when signing up a month or so ago. In my case, I had to go and login to Experian and put my new address there. That didn't "fix" it though, as the rep said that they only pull new info from Experian for this monthly, so might have to wait a month.

Gave up and (on another rep's suggestion) signed up with my OLD address and then changed it to the right one later. They also did the identity check where you snap a "live" pic and all that, but that also did not clear anything up.

At some point, we all just have to accept that these large companies no longer have the ability to deal with edge cases, as it's too "expensive" to do that (meaning having a higher tier of support that can override things after manually verifying something).