Sabtu, 03 Oktober 2026

We View Consumer Data as Toxic Waste

Obscura VPN's Carl Dong

The VPN industry runs on a promise. Pick almost any provider and the pitch is the same: "we don't keep logs." You hand over your entire internet connection and, in return, you get a pinky-promise that nobody is writing anything down.

For a lot of privacy-minded people, that promise stopped being good enough a while ago. A no-logs policy is only as honest as the company making it, and even an honest company can be hacked, subpoenaed, or quietly acquired.

Obscura VPN is trying to answer to that problem. Instead of asking you to trust its word, it splits the job across two independent companies so that neither one can tie your identity to your browsing. The first hop is Obscura's own servers; the exit hop is run by Mullvad. a respected VPM company out of Sweden. Your traffic is end-to-end encrypted to Mullvad's keys, so Obscura literally can't read it, and Mullvad never sees who you are.

The person behind it is Carl Dong, a former top-5 Bitcoin Core contributor who signs off his own website as "head-janitor" and "I fight for the users." I sent him a set of questions around Obscura. Here's the conversation.

Obscura team

You went from being a top contributor to Bitcoin Core to founding a VPN company. What convinced you the VPN space needed rebuilding rather than just improving?

"Don't Trust, Verify" is a cornerstone of the cypherpunk principles I grew up with. I see this Trust Minimization as crucial when building human-centric, security- and privacy-critical technologies. Yet the VPN industry is riddled with scandals (e.g., Onavo), broken promises, and "no-log" pinky promises. This never sat right with me.

When I saw what Apple's iCloud Private Relay was doing under the hood, I saw what the next generation of VPNs would look like: VPNs that are verifiably private and that outsmart internet censorship. I wanted to make this a reality outside of Apple's walled garden. The world doesn't need another VPN company; it needs a totally new approach to privacy.

Your whole pitch takes direct aim at the "no-logs" model everyone else uses. Why has that promise become inadequate?

The VPN industry is living in the past. Three conglomerates dominate and give the illusion of choice, while betraying their users' trust and operating a payola scheme using media cut-outs to push their talking points. The no-logs pinky-promise has never been adequate for software that can access the entirety of your internet traffic, and verges on being useless in 2026 when LLM-driven cyberattacks run rampant.

At the end of the day, even honest VPN providers who abide by their no-logs policy can be hacked. Users are waking up to this, and there's been an increasing call within the cybersecurity community to stop using VPNs altogether. Obscura is a direct answer to this: you no longer have to trust any single company's word for your internet privacy. That's the way it should have always been.

Walk our readers through the two-party relay in plain terms. How does it actually change the trust model compared to a normal multi-hop VPN?

When you use a traditional VPN, a single company sees your identity (via your connecting IP + your payment information) and your internet traffic. Using a multi-hop option doesn't change the fact that it's still a single company, and oftentimes just adds additional latency for no good reason.

With Obscura's Two-Party Relay, we use a fully independent company (Mullvad) as our second exit hop, with Obscura as the first hop. All of your internet traffic is encrypted to a key controlled by Mullvad's servers, and only relayed through Obscura's servers. That way, Obscura's relay servers never see your actual internet traffic, and Mullvad's exit servers never see your identity (connecting IP or payment information).

For those familiar with Tor, it's like if Tor only had 2 hops, but the hops were dedicated, high-performance hops optimized for maximum speed and reliability.

A skeptic could say you've just moved the trust problem around. Now users trust two companies instead of one, and the two of you could collude or be compelled together. How do you respond?

Obscura 2 hops

I'd first lightheartedly point out that using traditional VPNs is just moving trust from your (possibly regulated) ISP to a single wholly unregulated private company. 😆

In all seriousness though, our goal with Obscura is to make sure there's no single party that can jeopardize your internet privacy. No one entity should have that power. With Obscura, as long as either Obscura or Mullvad isn't compromised, no one can correlate your personal identity with your internet activity. This is strictly better than trusting either your ISP or a traditional VPN's pinky-promise.

Let's get technical. Your stealth protocol is built on QUIC to mimic HTTP/3 traffic. Why QUIC specifically, and how does it hold up against serious censorship?

We chose QUIC not only because it looks like HTTP/3, but also because its Unreliable Datagram extension allows us to avoid the TCP-over-TCP meltdown problem that plagues TCP-based VPNs. I'd encourage folks to read this for more details.

As for outsmarting censorship, QUIC has been notably harder for middleboxes to do Deep Packet Inspection on. QUIC allows messages to be fragmented and shuffled across UDP datagrams, which means censorship systems have to reassemble them, making it far more costly. I don't know of any QUIC censorship system currently deployed that does reassembly. More information can be found here.

You accept Monero and Bitcoin over Lightning, need no email, and log in with just a random account number. But Obscura still sees the user's connecting IP. How anonymous can a user really be, and where's the honest limit?

Obscura payment methods

We view consumer data as toxic waste. We don't want it, don't need it, and do as much as possible to make sure you don't have to give us any. Aside from what you mentioned, our website is also accessible over Tor.

But you're absolutely right. We can still see the user's connecting IP address. That will not change unless humanity completely rethinks the OSI stack, which will make the IPv6 transition look like a walk in the park. 😆

The fact that we can't avoid seeing your connecting IP address is the point of Obscura though: if we have to see it, then the most private thing to do is to completely decouple that information from your internet traffic. That's what our Two-Party Relay does.

You've open-sourced the client and talk a lot about reproducible builds, clearly something you carried over from Bitcoin Core. For a non-developer, why do reproducible builds matter for a VPN?

I did a lot of reproducible builds work for Bitcoin Core, so this is near and dear to my heart. I believe that reproducible builds matter for any piece of open-source security-critical software. Even if the published source code is not malicious, that says nothing about the app you download. It essentially answers this question: does the app that I download correspond to the source code that is on GitHub (or whatever other forge you may use).

For Bitcoin Core, a malicious app could mean loss/theft of funds. For VPNs, a malicious app has access to the entirety of your internet traffic and can leak that regardless of the security of your VPN provider.

At Obscura, we of course take reproducible builds seriously. We already have a prototype for Android reproducible builds, and are looking to make other platforms work as well.

Obscura is $8/month, and reviewers note that stacking two providers can cost more than one. Beyond the privacy story, how do you make the economics work as a small team without VC pressure to monetize users?

First, we have no user data to monetize. Second, I think in the tech world we've vastly overcomplicated our businesses. For a business to work, you need your costs to be lower than your revenue over time. That's it. We aren't going to construct a massive data center. We aren't going to put tens of millions into R&D in a lab in Switzerland. We're a small group of six people, working remotely, charging fair prices. As long as we keep our customers happy, we don't have anything to worry about. My goal was never to compare yachts with Bezos.

There's a classic tension between maximum privacy and everyday usability, with Tor as the usual cautionary tale. Where do you draw that line?

The goal is for my mom to use Obscura, and she does! (Hopefully not just because I'm her son.)

I don't think that tension between privacy and usability is always inherent: a VPN doesn't have to be complicated. You should flip a switch and it should just work and you should forget you have it on. The goal is to be seamless. Power users and technical folks who want more should always have the ability to tinker, and we offer that, but the goal is to build a product so good that both feel right at home.

Oftentimes we've also found that giving users a choice is the way to go: while cryptocurrencies may be the most private way to pay for Obscura, my mom is likely to want a credit card option. 😄

Looking at the next few years, with encryption under legislative pressure and tracking everywhere, what worries you most about online privacy?

Every day there is another story about a country or international body proposing new rules that jeopardize the open and free internet we all love. Sometimes these are well-meaning protections that legislators don't fully grasp the ramifications of; other times their motivations are less noble.

What all these scenarios have in common is that, somewhere along the way, behavior that was once considered odd and Orwellian became normalized. You go grab a coffee and you give them your phone number, then you download an app (and allow location permissions), and before you know it companies know every aspect of your life.

Then when you read about how the government can legally purchase this data from data brokers, you start to appreciate just how much of your life can be reconstructed to where you essentially have given away every aspect of your privacy for a free coffee on your birthday. (I'm as guilty as anyone.) So what really worries me is our own complicity in trading privacy for convenience. And I hope with Obscura and other smaller privacy-focused start-ups we can make an easier, simpler to use tech that helps protect people and allows them to make better privacy decisions where there is no trade-off between convenience and privacy.

Finally, a fun one. Your site has a "Cursed Knowledge" page. What's the most cursed thing you've learned about how the internet actually works since starting Obscura?

I think the TLS SNI extension has gotta be one of the most cursed things about how the internet works.

Most people assume that if a connection is encrypted by TLS, then it's fully encrypted. What they don't know is that there's a part of every TLS connection called the SNI where the server's domain name is in plaintext, completely unencrypted! In fact, ISPs and middleboxes often use this as a way to enact internet censorship, since it's a much more reliable mechanism than trying to match connections with DNS requests.

Last year, Obscura was erroneously blocked by a few US ISPs, and SNI was exactly what they used. Of course, using a VPN protects you against that, but it's still quite cursed that TLS has this at all. Hopefully Encrypted Client Hello gets adopted soon so that we can have actual secure TLS!


Whether Obscura's split-trust model is right for you is up to you to decide, but it's definitely a different approach to a problem the VPN world has glossed over for years. The client is open source, so you don't have to take any of this on faith. You can read the code, check your exit hop's key against Mullvad's published list, and verify the claims yourself.

You can learn more at obscura.com, and the source is up on GitHub.



from It's FOSS https://ift.tt/bUS7XtK
via IFTTT

Kamis, 01 Oktober 2026

YT-DLP is Being Treated as a Piracy Tool By The IFPI

yt-dlp has over 195,000 stars on GitHub, supports thousands of platforms, and is actively maintained by a global developer community. Unfortunately, the IFPI would like to see it on the EU's piracy watchlist.

Just so you know, the International Federation of the Phonographic Industry (IFPI) represents around 8,000 music labels across 70 countries.

In its submission to the EU's Counterfeit and Piracy Watch List consultation, the group calls yt-dlp "a major problem for the music industry" and names four of its maintainers by their GitHub handles.

A Piracy Watch List?

eu's public consultation on the counterfeit and piracy watch list webpage showing some key details

Run by the European Commission's Directorate-General for Trade and Economic Security, the Watch List identifies online services and physical marketplaces outside the EU reported to engage in or facilitate copyright infringement.

While it sounds serious, the undertaking isn't meant to gather legal findings and does not mandate any form of direct action. It's closer to a naming exercise intended to pressure operators and governments outside the EU into addressing the identified services.

The 2027 edition is being compiled from submissions received through September 2026, with the final list expected in Q2 2027.

What does their submission say?

IFPI's submission covers a wide range of copyright enforcement concerns, from AI music generators and cyberlockers to streaming fraud services and domain registrars. yt-dlp appears under the "stream ripping" section, grouped with commercial websites like Y2mate and Savefrom.

They describe the tool as an application that retrieves content by parsing web page data and interacting with platform playback endpoints, with GitHub serving as the primary delivery method for its source code, pre-compiled binaries, and installation instructions.

IFPI names four of the project's maintainers by their GitHub handles: pukkandan, who founded the project and led it between 2021 and 2024, and some core maintainers mentioned in the project's Maintainers.md file, like coletdjnz, bashonly, and Grub4K.

The same submission also flags X, Discord, Telegram, and Vimeo as platforms facilitating copyright infringement at scale.

It's a tool, not a service

the yt-dlp github repo

The Watch List, as described by the European Commission, targets online service providers and physical marketplaces located outside the EU. yt-dlp fits neither description in any conventional sense.

IFPI acknowledges this by noting that the project's open source nature, its Unlicense licensing, and an extensive international developer community make it "difficult to contain and/or remove."

From their point of view, there's no central domain to block, no payment processor to cut off, and no hosting provider to strongarm into complying with a takedown request.

The source code is distributed globally and can be compiled by anyone with the skills to do so. But that doesn't mean yt-dlp is a piracy platform.

It's a command-line tool for downloading audio and video content, and categorizing it alongside dedicated ripping or piracy websites conflates a general-purpose downloader with services whose primary purpose is facilitating unauthorized copying.

Closing thoughts

The Watch List has been used in connection with enforcement against commercial stream-ripping platforms before.

Y2mate.com and eleven other stream-ripping sites were shut down in Vietnam in 2025, and Y2mate had previously appeared on the list.

Before that, in 2024, a German court held the host provider for youtube-dl.org liable in connection with facilitating circumvention. This shows that grouping an open source command-line tool with those commercial services in the same breath does not, by itself, make the tool one of those.

Via: TorrentFreak



from It's FOSS https://ift.tt/4dlrbqc
via IFTTT

FOSS Weekly #26.40: NixOS is European Choice, Firefox Nova and Features, Free Terminal Course, Homelab Improvements and More

FOSS Weekly

Canonical is moving Ubuntu's kernel update cycle from four weeks to two, with the expected result being a kernel release landing every week due to cycle overlap. They did this because AI-assisted vulnerability hunting is causing CVEs to land faster than the old timeline could respond to.

They have also enabled upgrades from Ubuntu 24.04 LTS to Ubuntu 26.04.1. And the delayed beta release of Ubuntu 26.10 should arrive today.

AlmaLinux now has software certification, which means publishers can list products and users can confirm what runs on their hardware, with everything going into a public catalog with a free read-only API facilitating bulk data export.

GhostBSD's lead developer is building a new desktop called Mocka to eventually replace MATE. It is built from scratch with no shared code from the MATE project, and the name comes from a typo.

postmarketOS is now Nura. The rename has been in the works since March 2025, drew over 300 community submissions, and went through a trademark review and a vote before it was finalized. On the same note, F-Droid has a major revamp. In case you did not know, F-Droid is the FOSS alternative to Google Play Store.

openSUSE is consolidating its distro lineup. Leap Micro, the separate immutable flavor for container and edge workloads, is going away, and Leap 16.1 absorbs its functionality via an optional installer mode.

This edition of FOSS Weekly is supported by Dawarich, an open source alternative to Google Timeline.

Dawarich is a private alternative to Google Timeline.

Google killed browser Timeline and is limiting data retention. You can import your entire location history into Dawarich in minutes. It is private and encrypted. No ads. No data selling.

It is open source and can also be self-hosted. Or, you can opt for their encrypted service.

Try Dawarich Today

🧠 What We’re Thinking About

The Netherlands is building a NixOS-powered work environment after watching Microsoft cut off ICC access in 2025. Though it turns out France's digital agency had beat them to it, already running their own version of NixOS on internal workstations.

🐧 Tuxdle is rising

Last week I shared my weekend project, Tuxdle. It's a word game where you have to guess the Linux term within six attempts. The game has gained good popularity. We are getting more than 500 plays every day. A good number for a game that is less than a week old.

I have made some enhancements to the game. You can see your stats and you can also see stats on the day's puzzle. That tells you how many people played the game and how many people actually solved it. Streak badges have also been added.

Want more fun and challenges? On Linux Handbook, we have created a fun Capture the Flag game. You have 10 levels to solve. When you solve a level, the next level gets unlocked. The challenges run in custom docker containers. Everything on your system really. No sign up is needed.

🧮 Linux Tips, Tutorials, and Learnings

I am also enhancing the user experience on the It's FOSS website. One of the first things I did was organize the series/courses in a proper format.

If you visit the terminal course or bash scripting course, you will see the chapters in the series in the left sidebar. This will give you easier navigation.

There are many Linux distros that don't provide a dock by default, and if you want one, there's no dearth of options: Latte for KDE users, Cairo for old-school animations, and Dash to Dock for GNOME users; there's something for every taste and desktop setup.

You've seen "upstream" and "downstream" in patch notes, bug trackers, and forum replies without it ever being fully explained. We have already tackled what the terms actually mean, both for the kernel and for applications, and why it matters when you're deciding where to file a bug report.

👷 AI, Homelab and Hardware Corner

One of the biggest annoyances of homelab is accessing services by using IP address and port number. I fixed this by giving a custom domain name to every service I run. I used AdGuard as DNS and Nginx Proxy Manager for reverse proxy. And the end result is that I can use Jellyfin by typing jellyfin.internal instead of typing 192.168.0.23:8097.

Most SBC projects end with your drawer filling up with HATs for different use cases. Vicharak's Axon-Lite tries a different approach where it offers swappable interface modules for voice, vision, sensing, and AI data.

✨ Apps and Projects Highlights

Firefox's Nova redesign is finally here, and it looks good! There's also a neat toggle for anyone who doesn't prefer it's pill-shapedness.

📽️ Videos for You

And here's 21 useful Firefox features to give you a reminder why this browser keeps coming back, even after the wrong turns it has taken these past few years.

💡 Quick Handy Tip

0:00
/0:16

In KDE Plasma, you can copy a wide range of time/date formats to the clipboard by right-clicking on the Clock widget in the panel.

All you have to do is right-click on the digital clock in the panel, hover your mouse cursor over the "Copy to Clipboard" option, and click on the format you want copied.

Desktop Linux is mostly neglected by the industry but loved by the community. For the past 14 years, It's FOSS has been helping people use Linux on their personal computers. And we are now facing the existential threat from AI models stealing our content.

If you like what we do and would love to support our work, please become It's FOSS Plus member. It costs $49 a year (less than the cost of a McDonald's burger a month), and you get an ad-free reading experience with the satisfaction of helping the desktop Linux community. And there are also free Linux ebooks.

Join It's FOSS Plus

🎋 Fun in the FOSSverse

Sharpen your networking command knowledge by completing this crossword!

Linux is for power users. 💪

linux sudo meme

🗓️ Tech Trivia: On September 27, 1983, Richard Stallman announced the GNU Project, an effort to build a completely free Unix-compatible operating system. It helped spark the free software movement and popularize copyleft through the GPL, shaping how software is shared, modified, and built collaboratively.

🧑‍🤝‍🧑 From the Community: Neville is making the case for small, well-written programs; do you have an opposing view to present?



from It's FOSS https://ift.tt/YE2FRXz
via IFTTT

F-Droid's New App Shows it Isn't Going Anywhere

f-droid 2.0 release banner

Since 2010, F-Droid has been the go-to place for downloading free and open source apps for Android. Its client app is the one people interact with the most, and it has received many upgrades over the years.

But now it's time for a massive rewrite that has emerged from more than a year of development and numerous test releases.

A comprehensive redesign

Kotlin replaces the original Java codebase, and the interface has been rebuilt on Jetpack Compose. The result is an app that follows Material Design throughout, so that it looks and behaves like it belongs on a modern Android device.

The app's bottom bar now has three sections: Discover for browsing, Search for queries and quick access to categories, and My Apps for tracking installed apps, updates, and issues.

You will also find that the Settings menu has moved to the top-right, being placed alongside the new Repositories menu.

Coming back to the Discover page, it has been configured to highlight newly added apps, recently updated ones, and the most downloaded ones in the repository. Related categories are grouped together, making it easier to browse the full catalog without getting lost in a long list.

Search now handles categories, app descriptions, and translated content in addition to app names, and results for Chinese, Japanese, and Korean queries have improved. Your search history is also saved for future queries.

Filtering has been reworked too; results can be narrowed by anti-features, device compatibility, and category all at once.

What else's changed?

The app now checks for updates in the background by default, removing the need for the pull-to-refresh gesture that used to trigger repository scans. Of course the manual check is still available from the My Apps page once you go into the three-dot menu.

Similarly, the app hiding feature for changing F-Droid's logo to a calculator app has been moved into the Settings menu under "App Icon," and the Nearby app sharing tool has been temporarily removed.

Concluding their announcement, F-Droid stated that:

F-Droid 2.0 represents a major milestone, but it is not the end of the story. Rebuilding the app has given us a stronger foundation, yet there is still plenty of work ahead.

As the rollout reaches more users, we expect to learn a great deal from real-world usage. Community feedback has shaped F-Droid 2.0 from its earliest design discussions through many alpha and RC releases, and it will continue to guide future improvements.

A looming threat

Last year in August, Google announced that starting 2027, every Android app developer would need to register with the company, providing government-issued ID, signing key evidence, and a fee.

This way, apps from unregistered developers would be blocked from running on certified Android devices.

Of course F-Droid didn't sit by idly; one of their board members, Marc Prud'hommeaux, launched the Keep Android Open campaign in response, which has since brought together over 70 organizations from 20+ countries.

Its signatories include big names like the Electronic Frontier Foundation, the Free Software Foundation, KDE, Proton, Codeberg, VideoLAN, LineageOS, CryptPad and the Tor Project.

Seeing that we are shy of the 90-day mark for this absurd lockdown to occur, F-Droid introducing such a major update only strengthens their stance of not backing down to Google's strongarming tactics.

Get F-Droid 2.0

This revamp is rolling out gradually over the coming weeks, so if you haven't received this on your existing installation, just wait. For new installations, it is a similar situation, as the latest stable release is still v1.23.2.

On the other hand, if you can't be bothered with practicing the virtue of patience, then you could download the latest 2.0 beta build from the packages portal.



from It's FOSS https://ift.tt/FCTPvEj
via IFTTT

How I Fixed the Biggest Annoyance of My Homelab

Internal domain name setup in homelab

My homelab started small, and so did the annoyance.

To open Jellyfin, I typed 192.168.0.x:8097. For Home Assistant, it was another IP and :8123. For Karakeep, Ollama and the rest, even more IP and port combinations to either remember or bookmark.

The bookmarks weren't reliable either. My ZimaCube got its IP address from the router like any other device. Swap a cable or let it reconnect, and it mostly came back with a different IP, breaking every bookmark and config pointing to it. That's worse for Jellyfin because typing a full combination IP address and port number with a TV remote will give you a taste of medieval torture.

So, one weekend I decided to fix it. I started with assigning dedicated IP address to my Zima devices (ZimaBoard and ZimaCube) but ended up with a full network clean up.

Now my setup is smooth with all the regular services running with a .internal domain. Now I just type jellyfin.internal in the browser. No IP, no port number. Saved me a midlife crisis.

My setup, before and after

Here's what my network looked like before the cleanup. The router from my ISP feeds a TP-Link router, which runs the homelab network, with a OneMesh node extending the Wi-Fi.

ZimaBoard consumes less power and runs services like Jellyfin that need to be on all the time. ZimaCube is a powerful device, and with Nvidia Ada RTX on it, I use it for local AI exploration. To cut down on my electricity bill, I only turn it on when I need it.

My original homelab setup before the DNS changes

And here's what it looks like now. Both Zima devices have fixed IPs, the ZimaBoard handles DNS and the reverse proxy, and every service has a proper name.

my homelab setup after dns and reverse proxy manager

The idea in a nutshell: AdGuard as DNS and Nginx Proxy Manager

The whole setup rests on two pieces working together. AdGuard Home, running as the network's DNS server, turns a name like jellyfin.internal into an IP address.

Nginx Proxy Manager then looks at which name you asked for and forwards the request to the right port. Because AdGuard can only work on the IP address, not port numbers.

Once that's in place, adding a new service is a two-step routine: one DNS rewrite in AdGuard, one proxy host in Nginx Proxy Manager. That's it.

🚧
This is my setup, built around my routers, my Zima devices, and the services I run in my homelab. Take inspiration from it and use it as a reference, but don't copy it blindly. Your IP addresses, ports, router menus and commands will almost certainly be different.

Step 1: Give the core devices fixed IPs

Everything in this setup depends on IP addresses that never change. If the DNS server's IP changes, the entire setup breaks. So the first job was setting DHCP reservations on the router.

On my TP-Link, this lives under Advanced -> Network -> DHCP Server -> Address Reservation.

It actually shows me the connected device and gives the option to reserve the IP from there itself.

reserving ip address for devices on local

That may not always be the case for all the routers. So, you can find the MAC address on Linux with:

ip link show

That will show the MAC address of the current device. You can use a networking command like arp to scan the mac address of other devices connected to your network. The best place still is the router for this activity because it sees all the connected devices to the network anyways.

💡
I also moved the start of the DHCP pool to 192.168.0.10, so no phone or laptop ever grabs an IP I've reserved.

Here's the addressing scheme I ended up with:

Device IP Notes
Router 192.168.0.1 Homelab network gateway
ZimaBoard 192.168.0.4 Runs 24x7, hosts AdGuard and Nginx Proxy Manager
ZimaCube 2 Pro 192.168.0.5 Not always on, runs heavier services
Dynamic pool 192.168.0.10 to 253 Phones, laptops, everything else

I have also assigned fixed IPs to Raspberry Pi and other SBCs in this setup. They are used for running local AI harnesses like Nanoclaw and Hermes agents. I am also setting up Frigate for the cameras. I will share my experience with those things in some later article.

Note that some devices may need to be rebooted or renew its DHCP lease to pick up the reserved IP.

📋
Since I used ZimaOS, things were more click click and install. For other setup, you will have to install and setup AdGuard DNS and Nginx Proxy Manager. Instructions can be found on their respective websites.

Step 2: Install AdGuard Home on the always-on box

AdGuard Home becomes the DNS server for the entire homelab network, so it has to be up all the time. My ZimaBoard runs 24x7 while the ZimaCube doesn't, so the choice was easy.

In the ZimaOS App Store, I installed the AdGuard Home (HOST) variant, not the regular one. Host networking lets AdGuard bind directly to port 53 and see the real IPs of clients. With Docker's default bridge network, traffic gets NATed through the container and you lose both.

The install shows a tips popup with a config script. Its wget command failed on my system with a "Can't be verbose and quiet at the same time" error, so I ran the same script with curl instead:

sudo bash -c "$(curl -fsSL https://raw.githubusercontent.com/bigbeartechworld/big-bear-scripts/master/generate-adguard-home-config/run.sh)"

Don't skip sudo here. Without it, the script fails to create directories but still prints a success message.

I accepted the default config path, restarted the app from the ZimaOS dashboard, and opened http://192.168.0.4:3000 manually. Clicking the app icon doesn't work for host-mode apps.

💡
AdGuard offers AdGuard DNS as a paid cloud service. But its open source equivalent is free to install and use on your own device. That's what I used here.

When ports are already taken

The setup wizard asks for an admin port and a DNS port, and both clashed with something. Port 80 for the web UI was taken, so I set AdGuard's admin UI to 3786 instead.

Port 53 was more surprising. Unusual, right? Turns out I had a Pi-hole container running that I had completely forgotten about. I found it with:

sudo docker ps --format "{{.Names}}: {{.Ports}}"

Pi-hole and AdGuard do the same job, so there was no point running both. I removed Pi-hole.

Step 3: Point the network at AdGuard

AdGuard was running, but no device was using it yet. On my TP Link, I went to Advanced -> Network -> Internet, expanded Advanced Settings, and switched DNS Address to "Use the Following DNS Addresses".

Primary DNS is AdGuard at 192.168.0.4, and secondary is 1.1.1.1. Here. 192.168.0.4 is the IP address of the ZimaBoard that has AdGuard running on it.

AdGuard setup as DNS in the router

Here's what this setting actually does. Devices on the network still use the router as their DNS server, and the router forwards their queries to AdGuard. That's why AdGuard's query log mostly shows the router as the client, not individual devices. For per-device stats, setting AdGuard's IP in the DHCP Server page should work, so that the router hands it to devices directly.

📋
The 1.1.1.1 secondary is a safety net, so the internet doesn't go dark when the ZimaBoard is down. It comes with a trade-off, though. DNS clients don't always wait for the primary to fail before trying the secondary. When a query goes to Cloudflare instead, the ad slips through and .internal names don't resolve, since Cloudflare has no idea they exist. If you notice a hostname failing occasionally, this is the likely culprit.

When a device ignores the new DNS

While testing, I manually set 192.168.0.4 as DNS on a Linux laptop through GNOME's network settings. dig @192.168.0.4 google.com worked, but browser traffic never showed up in AdGuard's log. Running resolvectl status revealed the system was still using the router, as GNOME hadn't applied the change to the live connection.

Reconnecting to Wi-Fi fixed it. The more dependable way is doing it through nmcli:

nmcli connection modify "<connection-name>" ipv4.dns "192.168.0.4"
nmcli connection modify "<connection-name>" ipv4.ignore-auto-dns yes
nmcli connection down "<connection-name>" && nmcli connection up "<connection-name>"

Step 4: Create the .internal names with DNS rewrites

This is where the hostnames come to life. In AdGuard, go to Filters -> DNS rewrites -> Add DNS rewrite, enter a domain like jellyfin.internal, and point it to an IP address.

AdGuard DNS rewrites

Here's the thing. ZimaBoard runs multiple services. DNS rewrite only accepts IP address, not port numbers. If I have to add jellyfin.internal and homeassistant.internal in the DNS, both will be pointed to the same 192.168.0.4 IP address. And they won't be resolved.

I mean, I could do zimaboard.internal:8097 and that would land me on Jellyfin but what's the point? A proper jellyfin.internal is what I would want. We need the port numbers.

AdGuard DNS rewrites

This is why we need a proxy manager to properly map the domain names with both IP addresses and the port numbers. But a proxy manager cannot act as DNS and hence we need both AdGuard DNS in combination with a tool like Ngnix Proxy Manager.

📋
Why .internal? A good option was .local but it is reserved for mDNS (Bonjour, Avahi), so many devices resolve it outside your DNS server, which could lead to inconsistent results. .lan and .home aren't reserved and could become real domains someday, just like .dev did when Google bought it. .home.arpa is official but clunky to type. In 2024, ICANN permanently reserved .internal for private networks. It's short, readable, and will never clash with a real website. And it fits the entire homelab narrative.

Step 5: Use the port numbers with Nginx Proxy Manager

DNS only translates a name into an IP. It knows nothing about ports. To make http://jellyfin.internal work without :8097, something has to listen on port 80, check which hostname was requested, and forward it to the right port. That's a reverse proxy.

I'd have preferred Caddy, as that's what I use on some of my servers. But Caddy wasn't available as a one-click app in ZimaOS and I want to keep everything in Zima ecosystem. So I opted for Nginx Proxy Manager (NPM) as it does the same job with a web interface instead of a config file. Like AdGuard, it went on the always-on ZimaBoard.

Port 80 issue, again

NPM needs ports 80, 443 and 81 (its own admin UI). Port 80 was taken again, this time by zimaos-gateway, the process serving the ZimaOS dashboard for ZimaBoard. I confirmed it with:

sudo ss -tulpn | grep :80

The tempting fix is giving NPM a different port, but that defeats the whole purpose. You'd be back to typing port numbers.

Instead, I moved the ZimaOS dashboard to port 8888 from its Settings page. That was easy and that's why I like ZimaOS. It makes managing homelab a lot easier.

Anyways, the NPM install dialog still complained about port 80 for a while, and a full ZimaBoard reboot cleared that stale check.

Adding proxy hosts

Once installed, NPM's admin UI is at http://192.168.0.4:81. Log in with the default admin@example.com and changeme, and it asks you to set new credentials right away.

To add a service, go to Hosts -> Proxy Hosts -> Add Proxy Host and fill in the details.

Nginx Proxy Manager Settings
  1. Domain Names: the hostname, like jellyfin.internal
  2. Scheme: http
  3. Forward Hostname / IP: the IP of the device running the service
  4. Forward Port: the service's actual port, like 8097
  5. Websockets Support: on (Jellyfin and Home Assistant need it for live updates, and it doesn't hurt the rest so I always enable it)
📋
I left the SSL tab alone, since this traffic never leaves my home network.

Save it, open http://jellyfin.internal in a new tab, and there it is. No port number.

Here's how my proxy hosts look right now:

Nginx Proxy Manager
💡
The "Public" access label might look scary, but it only means NPM doesn't add its own login prompt. These names resolve only through my AdGuard, so nobody outside my network can reach them. To access it from outside, a service like Tailscale should be used.

Troubleshooting afterwards

Network setup never goes 100% trouble free. I did a face a couple of issues. Here are at least two that I recall (and have recorded):

Home Assistant threw a 400 error

Everything worked except Home Assistant, which returned 400: Bad Request through homeassistant.internal. Direct access on port 8123 was fine. Home Assistant rejects proxied requests unless it explicitly trusts the proxy, as protection against spoofed headers.

The fix goes in Home Assistant's configuration.yaml:

http:
  use_x_forwarded_for: true
  trusted_proxies:
    - 172.17.0.3   # NPM container's IP on the Docker bridge network

I found the NPM container's IP with sudo docker inspect nginxproxymanager | grep IPAddress, then restarted Home Assistant with sudo docker restart homeassistant.

One catch: this IP can change if the NPM container gets recreated. Trusting the whole bridge subnet (172.17.0.0/16) instead of a single IP is more durable.

Netflix stopped working on the TV

Shortly after switching DNS, Netflix on my smart TV refused to connect. AdGuard's query log showed two blocked domains in red: logs.netflix.com and nrdp26.logs.netflix.com. They're telemetry endpoints, but the Netflix app treats them as part of its connectivity check.

You can unblock an entry from the query log's menu in AdGuard, or add allowlist rules under Filters -> Custom filtering rules:

@@||logs.netflix.com^
@@||nrdp26.logs.netflix.com^

Restart the app on the TV and it should work again.

💡
If something else breaks after you enable AdGuard, the query log is the first place to look.

Port conflicts

Port conflicts came up three times during this project, so this little drill is worth keeping handy. To see which process is using a port:

sudo ss -tulpn | grep :<port>

The process name in the output tells you who the culprit is. If it says docker-proxy, check which container it belongs to:

sudo docker ps --format "{{.Names}}: {{.Ports}}"

Then decide whether to remove the conflicting container or move the other service to a different port. Just don't remap the port of the thing you're trying to make port-free, like NPM.

One more thing to keep in mind: all of this works only inside your home network. The .internal names exist only in your AdGuard, so they won't resolve when you're outside, unless you bring a VPN into the picture.

Adding a new service later

This is where all the effort I put in this setup pays off. When I deployed Karakeep a few days later, giving it a proper name took just two steps:

  1. In AdGuard, add a DNS rewrite: karakeep.internal pointing to the ZimaBoard (192.168.0.4).
  2. In Nginx Proxy Manager, add a proxy host: karakeep.internal forwarding to the service's IP and port (14592 in my case).

If the service does its own host validation, like Home Assistant, it may also need to trust the proxy.

Wrapping up

I did all this a few months ago and it has been running smoothly so far. HTTPS for the .internal names would be nice to have. Perhaps I will think about implementing it some weekend.

I am sure there are other, perhaps better (?) ways of doing this. For now, this setup works for me, and I no longer have to remember a single IP address or port number in my homelab. I hope it gives you a few ideas for taming your own.

I welcome your questions and suggestions. What else could I do here? What would you like to do about a similar setup?



from It's FOSS https://ift.tt/E5bmxQJ
via IFTTT

Rabu, 30 September 2026

Local AI Weekly #4: The Fine Print of Running AI Locally

local ai weekly

Welcome to Local AI Weekly #4.

"Local AI" keeps meaning different things these days. Sometimes the model runs on your computer. Sometimes only the app does, while the model and your chat still run elsewhere.

There are lots of such "local AI" tools that are not really local. Before you pick a local AI tool, ask three things: where does inference happen, what account or network service is still required, and what does the license let you do? The best local AI tool is the one that doesn't need any of that.

🧪 On my bench

Team It's FOSS has moved from Discord to Buzz for internal chat. Buzz, from Jack Dorsey of Twitter fame, is a decentralized communication tool for humans and agents. Agents can run on remote servers or a local harness over ACP.

It has quirks. Clipboard screenshots won't paste into chat, and desktop notifications only fire for direct messages. Manageable for now.

🔍 Discover AI tools

Kubutu developer Rick Timmis is working on Klara, a local desktop AI assistant for KDE Plasma. The idea is to let you control the desktop via voice input. It is a work in progress for now.

OpenMuse is an MIT-licensed personal-agent app with a browser worker, durable tasks, and an optional Docker-based Linux computer. You can host it yourself, but setup still needs a CopilotKit Intelligence key, and open-ended tasks default to cloud providers. You can point it at an OpenAI-compatible endpoint, but there's no documented native Ollama path. Self-hosted software, not an assured offline agent.

🎫 Get MCP Certified

The Linux Foundation now offers AI certifications. The Model Context Protocol Associate one could interest you if you're building MCP integrations, or want an AI credential on your resume. I plan to take it just for the sake of learning new skills.

📡 Open Model News

OpenDecider is a more modest use for local models: answer bounded questions, like which queue a ticket should go to, instead of writing long replies. Its nano model is about 400M parameters; the 4B small model is a Qwen-based adapter. The author says both were distilled from larger teachers, and reports 2.0 GiB for nano and 8.9 GiB for small in the tested setups.

Basically, you don't always need a giant model to route routine requests. A small student model can be the triage step ahead of a slower agent.

👀 Big Tech Watch

NVIDIA's September PAIR announcement also promises easier local-model setup in Hermes and OpenClaw. The one-click Hermes path launched on Windows, with Linux "coming soon." Don't confuse that future path with the Linux PAIR beta available now.

NVIDIA also quotes up to 1.9x throughput from llama.cpp optimizations on an RTX 5090. That's a vendor number on specific hardware, not a speedup I'd expect on yours.

🗂 AI Jargon: Distillation

Imagine you have a giant, super-smart teacher who knows everything about the world. This teacher has a massive brain, but its so big that it can only stay inside a giant school building.

AI distillation is like that big teacher sharing all their secrets with a little kid (the student).

Instead of making the kid read millions of textbooks, the big teacher says: "Don't worry, just watch how I solve these puzzles, and listen to how I think."

The little kid watches closely and learns the teacher's smart shortcuts. Soon, the kid becomes almost as smart as the teacher, but with a much smaller brain!

You can learn more about distillation here. And you will see that teacher-student is kind of official term in this context.

😂 Meme

When the open-weights drop looks a little too familiar...

AI meme

⚡ Quick Tip: Back up your Hermes agent before you need to rebuild the harness

Last issue: ollama ps, to see if your model was really on the GPU. This week, make sure you could rebuild the setup around it too.

If you run Hermes, run hermes backup. It writes a ZIP of your Hermes home, config and state included, restored later with hermes import path/to/backup.zip. hermes backup --keep N caps retained backups, and a script-only cron job runs it on schedule without starting an agent.

Then move one encrypted copy off the machine. That archive can hold credentials, sessions, memory, and config, so don't drop the raw ZIP in Git, even a private repo. It won't be wise.

If you have not subscribed to Local AI Weekly yet, you can subscribe from this page.

Subscribe to Local AI Weekly

See you next week.



from It's FOSS https://ift.tt/2zLDaTK
via IFTTT

Microsoft Has Made WSL Containers Available to Everyone

wsl containers banner shown with a laptop and two miniature containers

Announced via a two-part series of blogs, Microsoft has moved WSL containers (WSLC) out of public preview and into general availability. Let's take a look at what it offers.

The new release comes with wslc.exe, a dedicated command-line tool for Linux container workflows on Windows. It ships with a built-in alias, container.exe, for those who prefer that syntax.

A Windows API also ships alongside it, giving native Windows applications a way to spin up and manage containers directly from code, as well as some new commands that include wslc events for tracking container activity, and --mount and --stop-timeout flags on create and run operations.

Networking is handled through a new model called Consommé, where container traffic leaves the virtual machine as Ethernet frames and is picked up by a Windows process running under the calling user's account. That process handles DNS, routing, and port mapping, letting traffic pass through VPNs and firewalls like any other Windows process.

For organizations, Microsoft Intune has gained two new settings specific to WSL containers. The first lets administrators enable or disable access to the WSLC feature entirely across managed devices. The second is a container registry allow list, which restricts image pulls to a defined set of approved sources.

Microsoft Defender for Endpoint's WSL plugin has also been extended to cover container activity. It can retrieve process, file, and network events from inside WSLC, connecting them back to the Windows host.

What is WSLC?

wslc --version and wslc --help command outputs

First you have to know about WSL, which stands for Windows Subsystem for Linux, that lets developers run Linux environments directly on Windows without needing to partition their drive or setting up a separate Linux machine.

Since WSL 2, it has shipped with a real Linux kernel inside a managed virtual machine, giving users access to Linux tools, distributions, and command-line workflows from within Windows.

WSLC extends this further by adding a dedicated layer for creating and managing Linux containers within that same WSL environment, making containerized workflows a native part of the setup.

It also separates container operations from the main WSL service by routing them through a dedicated child process, wslcsession.exe, which runs under the current user's account. This keeps each session isolated and container operations in a less privileged state than the WSL service itself.

For developers already working inside WSL, this means containerized applications can run in the same environment without reaching for a separate tool. The Windows API exposure also means native Windows applications can interact with containers programmatically.

Microsoft's WSLC architecture deep dive is a must-read if you want to know more.

Get it now

wsl 3.0.1 release

Running wsl --update in your terminal pulls in the latest WSL release, which includes WSL containers. Once updated, wslc is ready to use.

You can use these new commands to manage your containers. 👇

Command What it does
wslc container restart Restart a container.
wslc container cp Transfer files to and from a container as a tar archive.
wslc system info Check the state of your WSLC environment.
wslc network connect / wslc network disconnect Join or remove a container from a network.
wslc network create Create a network, with support for custom driver options.

For the full changelog and access to the source, head to WSL 3.0.1's release page on GitHub.



from It's FOSS https://ift.tt/1njvFUR
via IFTTT