- 6 Posts
- 115 Comments
NarrativeBear@lemmy.worldto
Privacy@lemmy.ml•To British(UK)/US: Sign the petition "Introduce an immediate ban on the sale and promotion of smart glasses"
7·12 days agoSimilarly I have no issues with people using dashcams, but I have issues with dashcams that upload to third party companies without anyones knowledge.
NarrativeBear@lemmy.worldto
Selfhosted@lemmy.world•How much do you secure a home server that's only accessible with VPN?English
10·1 month agoCould you provide some more information on how you perform a vuln scan, or what services/softwares you use to perform the scan?
NarrativeBear@lemmy.worldto
Selfhosted@lemmy.world•Setting Up OPNsense on Proxmox: Doubts regarding NIC setupEnglish
1·1 month agoLines F and E don’t exists in your diagram, all your VMs inside of Proxmox are accessible and sharing port eth3. Except Opensense, as its not bridged to eth3, but instead is assigned to the NIC card you have.
OPNSense inside Proxmox is the only VM that will see the NIC card and be the only VM that uses that NIC with those interfaces.
One interface would be for WAN in like you drew, and the other is the LAN port like on any other router. This LAN port needs to connect to a switch as this is where your OPENsence will communication with the rest of the home network and handout DHCP addresses. It’s also how you would reach your OPENsense GUI through a browser. (Outside of managing it within Proxmoxs GUI, accessible on eth3)
If your OpenSense VM goes down your home network won’t have a router which means no PCs would be able to communicate as they would have no DHCP addresses, so even if all your communication is “inside of Proxmox” your VM still would not get a DHCP addresses.
NarrativeBear@lemmy.worldto
Selfhosted@lemmy.world•Using a NAS to redirect to another NAS for streaming ?English
18·1 month agoWhat you may want to do is use something like Tailscale (or a VPN) to connect the two sites (homes) together.
Run your Tailscale setup in home A, and then in home B connected to your tailnet. You can install Tailscale on the home router of home B, or install it on any device that needs to connect to home A.
Then in home B you just connect to your Jellyfin server like you normally would if you were in home A. This could be a android box or smart tv for example or accessing it through a browser on a pc. (If those devices have Tailscale installed and are connected to your tailnet in home A)
Using a VPN like Tailscale would also mean you don’t expose your Jellyfin to the internet.
NarrativeBear@lemmy.worldto
Selfhosted@lemmy.world•Setting Up OPNsense on Proxmox: Doubts regarding NIC setupEnglish
2·1 month agoHonestly I don’t know enough to answer that question fully.
From what I understand PCI addresses (01:00.0) are dynamically assigned by the motherboard’s BIOS at boot. Adding or removing PCIe devices, enabling M.2 drives, or adjusting BIOS settings often shifts your device addresses up or down which can prevent a VM from starting up.
Reading online though, there now seems to be a workaround to this issue. I might need to give it a shot on my Proxmox machine.
“PCI ID overrides” is the term in this document to search for.
NarrativeBear@lemmy.worldto
Selfhosted@lemmy.world•Setting Up OPNsense on Proxmox: Doubts regarding NIC setupEnglish
3·1 month agoI have been running PfSense on Proxmox for ages now.
What I do is the following.
- Pass the NIC card through to PfSense.
- Your motherboards ethernet port is plugged into your network switch (think of proxmox as just another pc on your network)
- In PfSense your NIC can now be seen and all ports can be assigned as needed. Assign one as WAN and the others as LAN.
Set your pfSense /OPNsense to start at boot when you power on proxmox.
FYI, you might occasionally run into issues where the NIC “GUID” changes so your VM won’t be able to start.
When this happens your pfSense/OPNsense VM won’t start so your network will be in a “down state”. This means DHCP won’t be working either, and any PC that were not assigned a static IP won’t be able to access the Proxmox GUI to quickly fix the issue.
You might occasionally need to hook up a temporary router between a PC and your Proxmox host to access the web GUI as a result. At least this is what I do when my outrage is longer then a hour.
NarrativeBear@lemmy.worldto
Selfhosted@lemmy.world•What path does data take when connecting to a domain at my address?English
1·1 month agoWhat you are looking for is something called NAT Reflection/HairPin NAT/NAT loopback.
When you search for a “domain.example.com” your router loops you back at your reverse proxy and all the traffic remains “internal”. Your website will still be externally accessible (the ones you setup to be).
Here’s a example of how to set this up on PfSense router.
NarrativeBear@lemmy.worldto
DeGoogle Yourself@lemmy.ml•Poison Google's data collection profiles by generating decoy signals.
0·1 month agoGreat app, I have been using this for a few weeks now on my home network and have noticed a difference in the ads popping up.
NarrativeBear@lemmy.worldto
Privacy@lemmy.ml•Would OS age verification laws affect a Google account on GrapheneOS?
3·1 month agoNot sure why you are being downvoted, you are correct in saying this is mass surveillance, branded as age verification, and marketed as protecting the children.
NarrativeBear@lemmy.worldOPto
Privacy@lemmy.ml•Canada is about to end private digital conversation — Bill C-22
2·3 months agoSimplex, Quiet, Keet, & Sessions are some different apps that I have come across.
Also Nextcloud chat is something that you could self-host. Though if this bill does pass I guess hosting this would make you a criminal as soon as it does.
NarrativeBear@lemmy.worldto
Selfhosted@lemmy.world•How would you expose Jellyfin securely without a vpn?English
23·2 months agoI too would like to know more. Jellyfin has been something that I am still hesitating to expose online without a VPN.
I have Plex behind a reverse proxy (HAproxy) with Crowdsec and firewall rules all behind Cloudflare. My firewall rules in HAproxy block access a few different ways, like if request are higher then 60 requests a second, or if there is strange path traversal. Used the following guide as a start.
https://www.archy.net/building-a-native-fail2ban-with-haproxy-stick-tables/
NarrativeBear@lemmy.worldto
Privacy@lemmy.ml•Major VPN provider says it could leave Canada over lawful access bill
45·3 months agoCanada post and other mail providers will now be opening all envelopes and packages sent. All contents will be scanned or photographed and held on file for 2 years time, and released to relevant authorities upon request of investigation. To make things easier please do not seal packages or envelopes for easier and more convenient access.
All photos and scanned documents will be held in a highly secured database with easy backdoors access!
Pretty much the equivalent in terms of what Canada wants to implement with access to VPN logs and asking ISPs to keep logs for 1-2 years minimum.
Your link in the post appears to be pointing to Reddit.
Here is the link for everyone on mobile.
NarrativeBear@lemmy.worldto
Privacy@lemmy.ml•New 3D printing regulations: "Additive in America: Regulating 3D Printing" by 3D Printing Nerd
38·4 months agoSo… could I not just disconnect my pc from the internet, or have a desktop or virtual machine without internet access, keep my 3d printer offline, and use a software or 3d modeling software that’s open-source, and profit?
This bill has also just classified my ice tray as a 3D printer, and don’t tell anyone but a trip to my local Home Depot with 10 bucks in my hand could potentially make something more dangerous.
NarrativeBear@lemmy.worldto
Selfhosted@lemmy.world•Asset Management RecommendationsEnglish
3·4 months agoHonebox a simple home inventory management software
NarrativeBear@lemmy.worldto
Selfhosted@lemmy.world•What are some TrueNAS alternatives?English
1·4 months agoOne option is to use a older version of TrueNAS until some alternatives start to show up.
I would probably keep my NAS offline so it does not phone home.
NarrativeBear@lemmy.worldto
Selfhosted@lemmy.world•GitHub - damontecres/Wholphin: An OSS Android TV client for JellyfinEnglish
3·4 months agoThat can be installed on any hardware, as opposed to just a TV directly. That I could get behind.
NarrativeBear@lemmy.worldto
Privacy@lemmy.ml•Meta discontinues end-to-end encryption on Instagram
5·5 months agoMy local post office did the same. All letters and packages are now sent open so staff can read and see the contents. /s
NarrativeBear@lemmy.worldto
Privacy@lemmy.ml•Historic Chat Control Vote in the EU Parliament: MEPs Vote to End Untargeted Mass Scanning of Private Chats
5·5 months agoThank fucking god, someone finally realized opening everyone’s private messages would be similar to opening everyone’s written leters at the post office before they get sent.
Also people need to continue to stay vigilant, in case this does come back “rebrand” as something new.



I wouldn’t touch that shit with a 10ft pole