Authentik has done the opposite of enshittification. As they’ve gotten more successful, they’ve taken enterprise features and moved them into the community edition. I’ve been extremely happy with Authentik so far and the dev has been nothing short of fantastic every time I’ve seen them interacting with the community.
Solar Bear
- 0 Posts
- 94 Comments
Something you might want to look into is using mTLS, or client certificate authentication, on any external facing services that aren’t intended for anybody but yourself or close friends/family. Basically, it means nobody can even connect to your server without having a certificate that was pre-generated by you. On the server end, you just create the certificate, and on the client end, you install it to the device and select it when asked.
The viability of this depends on what applications you use, as support for it must be implemented by its developers. For anything only accessed via web browser, it’s perfect. All web browsers (except Firefox on mobile…) can handle mTLS certs. Lots of Android apps also support it. I use it for Nextcloud on Android (so Files, Tasks, Notes, Photos, RSS, and DAVx5 apps all work) and support works across the board there. It also works for Home Assistant and Gotify apps. It looks like Immich does indeed support it too. In my configuration, I only require it on external connections by having 443 on the router be forwarded to 444 on the server, so I can apply different settings easily without having to do any filtering.
As far as security and privacy goes, mTLS is virtually impenetrable so long as you protect the certificate and configure the proxy correctly, and similar in concept to using Wireguard. Nearly everything I publicly expose is protected via mTLS, with very rare exceptions like Navidrome due to lack of support in subsonic clients, and a couple other things that I actually want to be universally reachable.
A direct case was not reported in the UK in recent years, but evidence of very likely polio transmission was found in sewage samples two years ago:
https://nationalpost.com/news/world/polio-virus-found-in-uk-sewage-samples-risk-to-public-low
A similar situation happened in New York where an actual case was found a month later:
The short of it is, when vaccination rates fall, Polio can be reintroduced via transmission of the live virus found in the oral vaccine, usually taken in poorer countries. If someone were to take the oral vaccine and then immediately travel to a country with lessening vaccination rates, like is currently happening in the west due to the spread of right-wing conspiracy mongering, the live virus still in the vaccinated individual has a low but not zero chance of propagating to the unvaccinated or immune-compromised population there. Samples containing these vaccine-derived viruses are found a few times per year in most places, and it’s a weaker virus so often it leads to no symptoms, but in very rare instances it does take hold with the expected effect:
https://www.who.int/emergencies/disease-outbreak-news/item/2022-DON366
Despite individual cases of polio turning up, either via direct reporting or evidence found elsewhere, it would still be correct to describe polio as being “eradicated” in these countries, at least currently. Nobody is confused by this or demands reclassification of the status of polio.
I don’t follow. We regularly refer to polio as being “eradicated”, even though there have still been documented (but exceptionally rare) cases of polio transmission even in western countries over the last couple decades. That actually sounds like a perfectly apt comparison for the goals of prison abolition, just not in the way you intended.
In short, prison abolition isn’t about abolishing prisons?
Bad name choice in my opinion, as it immediately makes me think: what a dumb idea.
This is kind of like saying being anti-war is a dumb idea because there will surely always be wars fought in defense. Being anti-war isn’t necessarily being an absolute pacifist. It’s about opposing war and striving towards a future where war is a relic of the past. Everybody understands this, but struggles to apply the same logic to other topics.
Striving for intentionally utopian and impossible ideals is a great idea, actually, as long as you recognize it for what it is. I’m a prison abolitionist. Ultimately what I strive for is a society that doesn’t need prisons. I don’t know if total prison abolition is possible, but worst case scenario, we get as close as possible. What’s so bad about that?
Similarly, I’m a communist, in the classical anarchist sense: abolition of state, class, and money. Are these things possible? Maybe not. In fact, probably not, at least not in any timeframe where humanity will be recognizable to us, as it would require true peace between all people and absolute post-scarcity in every way available to everyone. But worse case scenario, we get as close as possible.
Ultimately, adopting a utopian ideal is a recognition that the struggle to do better never ends. We’re never “done”. There’s no end of history. Even if we do somehow achieve it, it must be maintained.
Solar Bear@slrpnk.netto
Fediverse@lemmy.world•Lemmy's gaining popularity, so I thought new people should see this.English
186·1 year agoUse lemmy.ml how you want to use it, and if you want to participate in other political leanings, go to a different instance. No one is really stopping you, and that’s the whole idea of the fediverse. And there really isn’t any value lost, because this isn’t a “choose one and only one” situation. You’ve got all of the fediverse at your fingertips.
Until you make the mistake of replying with the wrong kind of comment to the wrong sub, and get banned from the entire instance and lose the ability to post on many of the largest subs on this side of the fediverse. Or maybe they just see you out and about and decide to ban you on sight because they don’t like what you said. There’s nothing stopping that.
Admin overreach and abuse is a major issue for the fediverse because it affects more than just the user in question. Admins of large instances get to decide who has access to the users and communities on their instances, and very often the users of the instance aren’t even aware of the actions taken on their behalf. Mastodon recently implemented a notification for when blocks and defederation remove your follows or followers, and this is a great first step. Users deserve to know when they are impacted by decisions such as these.
I love the fediverse and want to see it thrive, so we need to stop putting our heads in the sand on this issue. It’s always discussed as if it’s an issue with a few problematic instances rather than the systemic issue in need of a solution that is is. Admins need the tools to protect their instances from real abuse, but we need to balance that with the right of the users to know what’s going on and not be unfairly deprived of the social aspect of this social media experiment, especially without knowing.
Solar Bear@slrpnk.netto
politics @lemmy.world•Gov. Tim Walz doesn't own a single stockEnglish
11·1 year agoAnd of that 61%, only a third are directly investing. The rest get it as part of their compensation package for their work, which they can’t benefit from without penalty until retirement. Additionally, it skews heavily by race. It’s 66% of white families, but only 39% of black families and 28 percent of hispanic families. The amount invested follows similar trends.
Solar Bear@slrpnk.netto
politics @lemmy.world•Gov. Tim Walz doesn't own a single stockEnglish
171·1 year agoActually most of us work for a living and don’t have the luxury of having enough money for investments to be practical in the first place, but I guess you can pretend it’s necessary to get by if it makes you feel better about it.
Solar Bear@slrpnk.netto
Selfhosted@lemmy.world•Does the form factor between 3.5" and 2.5" matter in a NAS server?English
16·2 years agoWhatever you get for your NAS, make sure it’s CMR and not SMR. SMR drives do not perform well in NAS arrays.
I just want to follow this up and stress how important it is. This isn’t “oh, it kinda sucks but you can tolerate it” territory. It’s actually unusable after a certain point. I inherited a Synology NAS at my current job which is used for backup storage, and my job was to figure out why it wasn’t working anymore. After investigation, I found out the guy before me populated it with cheapo SMR drives, and after a certain point they just become literally unusable due to the ripple effect of rewrites inherent to shingled drives. I tried to format the array of five 6TB drives and start fresh, and it told me it would take 30 days to run whatever “optimization” process it performs after a format. After leaving it running for several days, I realized it wasn’t joking. During this period, I was getting around 1MB/s throughput to the system.
Do not buy SMR drives for any parity RAID usage, ever. It is fundamentally incompatible with how parity RAID (RAID5/6, ZFS RAID-Z, etc) writes across multiple disks. SMR should only be used for write-once situations, and ideally only for cold storage.
Solar Bear@slrpnk.netto
World News@lemmy.ml•Netanyahu's Cabinet votes to close Al Jazeera offices in Israel following rising tensionsEnglish
501·2 years agoWhen people recognize they were wrong about something, as smugly satisfying as it may be it’s not actually helpful to tell them that they should have been correct sooner.
Solar Bear@slrpnk.netto
Selfhosted@lemmy.world•12TB for $80 - serverpartdeals.comEnglish
23·2 years agoRefurbished drives get their SMART data reset during the process, they absolutely had more than that originally.
Solar Bear@slrpnk.netto
Fediverse@lemmy.world•Maker Naomi Wu is Silenced by Chinese Authorities (And Why I Blame Elon Musk)English
51·2 years ago“Because I feel like it.”
So in other words, because she wants to? As in, “because it’s her body and she can do whatever she wants with it”?
Solar Bear@slrpnk.netto
World News@lemmy.ml•“A Breach of Yemeni Sovereignty”: Biden Becomes Fourth U.S. President to Bomb YemenEnglish
41·2 years agoI don’t know, that sounds like hard, thankless work that will take years of consistent effort, dealing with countless setbacks and losses but not giving up, before finally achieving our goals of making real and meaningful change. What if instead if that I just don’t buy Starbucks, will that work?
Solar Bear@slrpnk.netto
World News@lemmy.ml•South Korea passes ban on dog meat consumptionEnglish
41·2 years agoPlants aren’t sentient. When we say they “feel pain” and “communicate” we don’t mean like sentient creatures. We just don’t have better words to accurately convey the mechanics at play here. Computers also “communicate”.
Solar Bear@slrpnk.netto
World News@lemmy.ml•'100-200,000, not two million': Israel's finance minister envisions depopulated GazaEnglish
68·2 years agoI don’t support anyone. I oppose the worst outcome, and seek to steer our course away from it. Only narcissists and hobbyists hyperventilate about who they are “supporting”.
I engage in politics as a means to an end and nothing more. I take the best option available and I move on to the next task. To do otherwise is to value the self above the collective, and as a communist that is not a luxury I’m afforded.
Solar Bear@slrpnk.netto
World News@lemmy.ml•'100-200,000, not two million': Israel's finance minister envisions depopulated GazaEnglish
2820·2 years agoOne of those two will be president no matter what you do. They will then be in a position capable of inflicting great damage. Trump will use that position to hurt more people than Biden. The math here isn’t complicated, and it continually astounds me how many people on the left cannot actually solve the trolly problem when faced with it for real. It really shows which people are engaged in politics as a means to an end rather than as personal expression or a hobby.
Solar Bear@slrpnk.netto
Selfhosted@lemmy.world•This Week in Self-Hosted (8 December 2023)English
2·2 years agoIf you’re waiting for Jellyfin to run some kind of relay like Plex, you’ll be waiting a long time. That takes a lot of money to upkeep, and the demand for people who self-host FOSS and then want to depend on an external service is very minimal, certainly not enough to sustain such a service. I’d recommend just spending a weekend afternoon learning how to set up Nginx Proxy Manager and being done with it, the GUI makes it very easy.
Solar Bear@slrpnk.netto
Selfhosted@lemmy.world•Simplest For End User Wiki/Knowlege Repo for the end userEnglish
6·2 years agoI chose Bookstack for the same situation. It’s dead simple in usage and maintenance. No issues yet!
I will have an OG Xiaomi Mi Box and it’s absurd how over the years it went from a purely functional media device to a complete shit show covered ads. Genuinely disgusted me every time I turned the TV on. I couldn’t stand it anymore, I had to tear out the launcher with ADB and replace it with FLauncher.
I wish Kodi wasn’t such a pain in the ass to deal with, especially for YouTube. We really need a new FOSS media center application. Until then, at least FLauncher works for now as a simple app switcher for a handful of Android apps.


It’s definitely dried up a fair bit over the last couple of years. In January 2025 I got some recertified 12TB Ironwolfs for $140 each from GoHardDrive, and that was already a fair bit over what they historically had been. Same drives are now $200 on GoHardDrive, and $220 on Amazon. You can just get them new $250, so at that point I barely think it’s worth it to get recertified unless you’re really stretching a budget. I’m sure the businesses are very happy with the demand they got now, but it’s hard to escape the conclusion that LTT and other Youtubers covering these sites really drove up demand and prices.
Also, the smaller drives are a lot harder to find recertified these days since enterprise users will usually go for much larger capacities, so yeah, for 4TB you’ll probably have to go for new. You could also just get a larger drive and only use 4TB of it, assuming this is going into some kind of array. Upgrade the other one at a later date, then just expand your pool!