525 karma · joined April 1, 2007
[ my public key: https://keybase.io/ingenium; my proof: https://keybase.io/ingenium/sigs/WM9U5ulI4enLEK2fWt2WjGTk0-u1mnsJ7T_v7HLSHMc ]
Self hosted was a nice middle ground. No one else has a copy of my password database, and it's always in sync between devices. Stick nginx as a proxy in front of it for https and easy let's encrypt certificate management. The downside is that Keepass by default allowed me to have copies in multiple locations. Bitwarden is only on the server, but since the database is encrypted it's easy enough to have regularly scheduled backups of it. It just is an added step to find another docker host for it if my home server goes down, during which time I may not have access to my passwords.
The best/easiest way to run it is to use Docker. They have a script that will set it up for you. After that, the container can basically self update and self manage. Any addons that you want to use are installed as separate docker containers that talk to the main home assistant container. It's super seamless and easy.
In my case, I just setup a barebones Debian VM and ran their setup script. It took care of all the Docker stuff and got it up and running.
Basically pick a subdomain on a domain you own and have that and only that forward to HA. So the only way to connect to the HA instance from the internet is to know the exact subdomain you've picked for it. Set the proxy to not pass any port 443 traffic unless the subdomain matches one that you've set.
Anything of importance, I have broad directories under Documents, and then sub folders. Or sometimes I'll put them on my fileserver with similar directory structure. The Documents folder is backed up with Spideroak.
That being said, it seems the networks have a lot of congestion at the neighborhood level (equivalent to oversubscribed DOCSIS nodes), at least in my experience in several neighborhoods in Barcelona. This became much more visible when COVID hit and Netflix and such had to limit quality in Europe as a result.
I only have experience with Movistar and Vodafone fiber, I Haven't used Orange's so I'm not sure if they're any better.
On AT&T (technically a tablet plan) it gets deprioritized after 22 GB, but that's never been an issue for them, even the one month they did 500 GB. I've never seen their speeds affected. Costs about $20 or $25 / month. This is a riskier plan, in that AT&T could check the IMEI and shut it off at any time if it doesn't match (as they've done in the past).
The Sprint plan (hotspot plan with a public routable IP, $41/month effectively, but prepaid for a year at a time) does not get deprioritized, but it's probably not worth it unless you can get band 41. If you do get band 41 you'll see some very nice speeds though, at least download. But T-Mobile is beginning to shut down Sprint's band 41, and to my knowledge this plan is not permitted to roam onto T-Mobile yet. It's keyed in their system as a mobile broadband plan with a 20 or 25 GB bucket of data, however it has unlimited overage. I done hundreds of GB on it no problem. It exists only because of the licensing arrangement for Sprint to use the EBS band 41 spectrum.
The solution was to set it as the default printer, then add a new printer with the same CUPS URL. For some reason, setting it as the default allowed Windows to see it again. Then delete the new copy, and the original began working and allowed its settings to be edited. Incredibly frustrating.
Mercury works better than Readability usually, but the downside is that Mercury uses a third party to process it, whereas Readability is all local. So some sites will block Mercury from accessing it, because it's seen as a bot (Forbes does this, as do a few other sites).
This combo works great for reading entirely in your RSS reader. I use my phone to download my feeds for offline before flights, so I can read the actual content as well without an Internet connection (assuming it doesn't have formatting errors).
The default is:
adb settings put global airplane_mode_radios cell,bluetooth,wifi,nfc,wimax
I have mine set to:
adb settings put global airplane_mode_radios cell,wifi,wimax
That's why it's important for people taking PrEP to be screened regularly, and put on a proper cocktail if they test positive.
I've been fighting a similar issue. I woke up one morning to an email that my account was permanently suspended, along with several family members' accounts that don't live with me. All of our accounts were shut down at the same time, with no reason given. None of us had used Paypal in months, and I haven't received money on Paypal in years. We can't get a hold of anyone to find out what happened.
Current rumor is "there is a RF transmission issue that burns up the modem, quite literally, so then it won't read anymore. Can happen on any band. The software releases are supposed to prevent this from happening. But if your device has succumbed to this already, you're hosed." https://s4gru.com/forums/topic/7899-galaxy-s10-family-discus...
For a full local resolver, you can configure it to use and serve expired records, with a 0 TTL. In the background it will then lookup all records used, so that it's refreshed for next time. Cloudflare does this. Likewise, you can configure it to prefetch frequently requested records before they expire.
In my experience, Google's DNS has so many servers that even on subsequent requests, you hit a different server and it has to do the full lookup again (likely querying a root unless it's a popular domain). It's not really decreasing the load on the root servers that much, if at all. It might actually increase the load.
One trick you can do to speed up your local recursive resolver is allowing it to serve expired records. Unbound in pfsense allows for this. If the record has been previously retrieved but is expired, it returns the record with a 0 TTL (to force the client to look it up again next time). This includes internally using expired NS records, for example to lookup a different subdomain. Meanwhile, in the background, it looks up all the records used to refresh the TTL, and serves/uses this next time. Generally speaking, expired records still work fine. I noticed that Cloudflare DNS does this as well, and regularly serves 0 TTL records.
I've found that this consistently makes my local resolver faster than any public DNS server, except sometimes the very first time it looks up a domain. The slowest DNS queries are records which use lots of nested CNAMES on different domains with short TTLs, such as www.microsoft.com / most sites using akamai, which takes 500ms for the first lookup. There was a domain I saw the other day which had 4 or 5 layers of CNAMES which took 1-1.5 seconds to resolve initially.