

So if I understand: hosters will be able to provide the proof at a time/schedule of their choosing. On actual servers a simpler, automated cert renew process without the need for them to hold nameserver API credentials.


So if I understand: hosters will be able to provide the proof at a time/schedule of their choosing. On actual servers a simpler, automated cert renew process without the need for them to hold nameserver API credentials.


I think we misunderstand each other, let me try and be clearer myself. The line I suggest is:
TEMPDIR=$(mktemp --suffix -$$)
Which will look something like this when run:
TEMPDIR=/tmp/tmp.9qRCIGOb2k-30978
…if the pid is 30978 for example.
In the trap we can then check if TEMPDIR has been overwritten or not with:
trap ‘( [[ $TEMPDIR = /tmp/*-$$ ]] && rm -rf $TEMPDIR ) || echo “TEMPDIR var overwritten! Cleanup skipped.”’’ EXIT
I am on my phone so forgive if any syntax is not quite right.


Supply mktemp with a suffix for the temp dir name, based on the pid your script runs as, so mktemp --suffix=$$.
In your trap assert that the content of var TEMPDIR ends with your same current PID or fail before you clean anything up. You could also assert TEMPDIR is prefixed with $TMP or /tmp for even more robustness.
This gives you a decent guarantee that TEMPDIR is what it should be and is the temp dir for THIS script run.


The quoted proposals in the article, where they touch on privacy and security, only talk about keeping children safe from other users NOT from the service provider itself. So selling children’s data to advertisers is not affected?
Service providers will have identified the child quite precisely if they have had to request proof of age, making their data even more valuable.


BBC News - EU chief backs plan for Canada to become ‘associate member’ - BBC News https://www.bbc.co.uk/news/articles/cjwyzrr9d3dko


Say that new authelia exploit looks like one fail2ban already recognises or relies on timing/brute-force then you’re covered even before a patch is available.
Here’s a real authelia vuln:
https://app.opencve.io/cve/CVE-2026-47203
allowing an attacker to circumvent login throttling or account lockouts by simply altering the case of their credentials.
I think fail2ban would help protect authelia here?


Looks interesting, chapter names:
We just had a spot of rain after a long drought and the grass has greened back up but the clover looks dead. I think maybe a mix of both is best. The clover did stay greener much longer at the start of the drought.


Firewalling containers’ outbound access seems to be rare but another powerful layer of protection


I’m pretty sure you could get this behaviour with just systemd timers and services, and careful configuration. You get logging for free also this way.


Can you start to document the css in the source? So someone touches something, right above it is a comment: ‘this class used for all card layouts on these type pages’ or some such. Then there’s a chance to spot the danger, in code review at least.
I agree with others here: visual testing should be last result as it is brittle, sweeping and numbing.


I tried top 3 links in the vid, they all work? One is github.
I’d like to see more on the reasons NOT to adopt jj. I have not used jj myself yet but digging around there seem to be some big blockers, depending on your repo/project:
Love to hear others thoughts on this.


You’ve made a great start. How much further you go depends on your needs and threat model.
Rsync is ok as a start but there are dedicated backup tools that will give you access to your files at any point in time. This is important if you delete a file and later need it back after an rsync has already run and deleted it remotely too.
Rsync will not encrypt your backups. If a burglar takes your Pi will they have easy access to all your files too?
With rsync+ssh you are also vulnerable to either yourself (more likely) or a rogue process on your own machine deleting the files over ssh (e.g. ransomware attack).
The answer to that is append-only backups. A backup tool like restic has a backend you can host that does exactly this:
The --append-only mode allows creation of new backups but prevents deletion and modification of existing backups. This can be useful when backing up systems that have a potential of being hacked.
https://github.com/restic/rest-server
Take a look at restic to see what else you gain from switching to a dedicated tool versus rsync:
https://github.com/restic/restic#design-principles
There are others too such as borg.


I’m not familiar with Pikapods but Monica v4 has trouble with notifications. First you need to ensure it’s been configured right to even send a test email, this can be triggered with a command if you have access:
php artisan monica:test-email
Various Monica environment variables must be set to configure this, it should be in the docs somewhere if not I can fish my config out for you.
Even once that’s working you’ll need Monica to run its regular jobs for sending notifications, there’s config for that too. Finally the code has bugs and will often miss reminders in my experience. There are some open bugs still on this and I guess the devs have moved onto their rewritten version (chandler):
We’re also making it possible to add alt text for profile pictures and headers now, making your profile more accessible for blind and visually impaired users.
That’s good!


According to the research team, this unique formation directly influences the movement of Antarctica’s massive sheet of ice. The network of hidden geological features determines where the glaciers overlaying it will flow, which makes studying it crucial for predicting how climate change will change the southern ice cap.
Interesting


F-droid themselves gave an update in April:
https://f-droid.org/en/2026/04/03/twif.html
If you’ve been holding off updating Syncthing-Fork we have two pieces of news for you. First, the original dev continues to collaborate still, we know this was a pain point back then. Second, we’ve just added BasicSync, A simple app for running Syncthing, which just controls Syncthing’s running behaviour as hands off as possible, while the original service hums in the background.
So it seems since the handover things have settled but there is also a new fork which takes a more bare-bones approach.
One of the newswire articles is a great read
https://blog.colinbreck.com/i-dont-want-to-read-what-you-didnt-write/