I’m just this guy, you know?

  • 7 Posts
  • 189 Comments
Joined 1 year ago
cake
Cake day: June 12th, 2023

help-circle
  • I can’t speak to the quality of actual locksets or recommended any products, but LockPickingLawyer on YouTube has a number of short videos discussing smart locks. My impression is most of them are trash at just being a lock. The ones made by traditional lockset manufacturers probably aren’t generally good at being smart, but I’ve been wrong about major brands’ commitment to open standards before.

    Assuming you can find a decent lock that talks Z-Wave, I think you’re on the right track with Zwave2MQTT and a USB dongle. I’d be squeamish about using a Pi specifically in a mission critical security control system for a couple of reasons (reliability, complexity, WiFi interference), but as long as you have keyed backup, it’ll probably be OK.

    I’ll leave it to others to recommend the locks, but as I mentioned in another post her, most battery operated Z-Wave devices, in my experience, report their battery life. Most of mine seem to go from 100% to 70% to dead in about a day though, so accuracy might be hit & miss.

    Maybe just leave one door with an old school keyed lockset as a plan B.




  • I see Systems Engineering analogies in a lot of complex natural systems. It’s a great model to understand how the world around you works, as long as you remember it’s only a model.

    For example, I optimize my navigation around town sort of like the OSPF network routing protocol. I consider the speed limit & number of lanes to be analogous to the link cost, traffic lights as Layer 3 hops, and stop signs as Layer 2 hops. I consider the local highways to be my “backbone area” so navigation is optimized to find the shortest path from wherever I am to the nearest major highway. Sometimes the solution takes me a mile or two out of my way, but I’ll avoid 4 or 5 busy lights by taking a back road or cutting through a residential block.

    In fact, the airline network is similarly structured: for a given carrier, routes among their hubs are their backbone area, and routes between regional airports in different regions connect through one or two hubs. As a traveler between two regional airports, you’re likely to fly to the hub closest to your destination and meet a second leg back out the the other airport. All to better if you just live near a hub.


  • Secure file transfers frequently trade off some performance for their crypto. You can’t have it both ways. (Well, you can but you’d need hardware crypto offload or end to end MACSEC, where both are more exotic use cases)

    rsync is basically a copy command with a lot of knobs and stream optimization. It also happens to be able to invoke SSH to pipeline encrypted data over the network at the cost of using ssh for encrypting the stream.

    Your other two options are faster because of write-behind caching in to protocol and transfer in the clear-- you don’t bog down the stream with crypto overhead, but you’re also exposing your payload

    File managers are probably the slowest of your options because they’re a feature of the DE, and there are more layers of calls between your client and the data stream. Plus, it’s probably leveraging one of NFS, Samba or SSHFS anyway.

    I believe “rsync -e ssh” is going to be your best over all case for secure, fast, and xattrs. SCP might be a close second. SSHFS is a userland application, and might suffer some penalties for it








  • I used to selfhost more, but honestly it started to feel like a job, and it was getting exhausting (maybe also irritating) to keep up with patches & updates across all of my services. I made decisions about risks to compromise and data loss from breaches and system failures. In the end, In decided my time was more valuable so now I pay someone to incur those risks for me.

    For my outward facing stuff, I used to selfhost my own DNS domains, email + IMAP, web services, and an XMPP service for friends and family. Most of that I’ve moved off to paid private hosting. Now I maintain my DNS through Porkbun, email through MXroute, and we use Signal instead of XMPP. I still host and manage my own websites but am considering moving to a ghost.org account, or perhaps just host my blogs on a droplet at DO. My needs are modest and it’s all just personal stuff. I learned what I wanted, and I’m content to be someone else’s customer now.

    At home, I still maintain my custom router/firewall services, Unifi wireless controller, Pihole + unbound recursive resolver, Wireguard, Jellyfin, homeassistant, Frigate NVR, and a couple of ADS-B feeders. Since it’s all on my home LAN and for my and my wife’s personal use, I can afford to let things be down a day or two til I get around to fixing it.

    Still need to do better on my backup strategies, but it’s getting there.








  • With consistency. Whether I have 1 cup of coffee in the morning, or drink caffeinated beverages all day, the key for me is to do that consistently, or suffer dire consequences. Ramping up, I can’t focus and anxiety attacks. Ramping down I get migraines.

    Woe betide me if I am on a ramp down and find myself having to take an Excedrin or three. That spike keeps me up for days.