#the-water-cooler
1 messages Β· Page 649 of 1
I have a teams meeting in 6 minutes, i did the update anyway π
Oh cool
I also use Modbus with 9 STM32's located in my garden controlling tanks and irrigation , some also output PWM to control lights
Thanks. This makes sense. So my only option is to upgrade and hope that nothing breaks.
Or you could disable all custom_components. But updating is probably better.
I've upgraded three boxes in the last half hour, including my production host, no issues
Production went from 0.117 to 2021.1.2 π¬
I do like my custom components π
My concern is that one of them could stop working after the upgrade. I will do that anyway, of course
I assume the docker image was updated etc. That's what I use
My thermostat is one of the custom components, so it is quite important for me.
Would a move from Home Assistant 2021.1.1 to Openhab 3.0 be an upgrade or downgrade?
Wrong place to ask I think π€£
The update is very unlikely to cause custom components to stop working.
No bias thanks π
Anyways, I have backups
Clearly it would cause your house to halt and catch fire π
I never used openHab, but there will always be things beter on openhab and homeassistant
It was more tongue in cheek, I think the consensus is these days that HASS due to popularity is more versatile thanks to large support and community base.
But certainly openhab still has some benefits and a user base.
Mainframe still has a userbase
Well, with all the knowledge i have built around Homassistant, i would not move to another platform and start over again
If the custom component breaks with this extra layer of security you want to ditch that component right away
The "makemoneyfromhome.ru" integration seems to have a security flaw?
I agree in principle. But in the end itβs just my risk assessment between potential security issues and usefulness of a component. If the potential issue is of developers neglect, of course. Anything pure evil must be thrown out.
and these things are open source, probably could be fixed if neededβ
Fair enough
Another delight of working from home because of the pandemic: I donβt have to wait until I get home in the evening to update everything π
Well you can always update remotely and hope everything works π
Security flaws are mostly minor things. The commit did include filtering out some nasty injections that were possible before.
oh noeeezzz
I will say that my upgrade from 0.117.x went smoothly
- π± That must be, like, 24241 releases ago!
fingers crossed,
i skipped since 0.117 due to the auto discovery..
no way around now π€£
Admittedly with all my Z-Wave and Zigbee on other hosts, there's not a lot of critical external integrations left π
Disclosing the vulnerable custom components could alert a potential attacker of the problem, and allow them time to attack users who are not quick enough to remove them. So does this update only impact those components and future ones and none of the others?
@forest edge well, I saw this commit in HACS π https://github.com/hacs/integration/commit/f2b7cb711e41a94b81610f6ff96ea314e9879114
which seems pretty relevant
Please try to avoid speculation as far as possible.
We really don't like having to do it this way
There really is no way to tighten all future security holes except pulling the network cable.
I have to fumble in the dark sometimes when they update cards just to get the card back to working when there is no explicate mention of what changed to break what. most annoying thing ever so forgive me being hesitant on updating on something we know nothing about lol
And I woulnd't really trust that either
would you be able to elaborate whether an entirely-private hassio would be vulnerable?
because mine is not reachable from the internet.
Encase it in concrete, toss it into the sun, that should be safe if it gets there...
(as are most, I'd guess)
Mine is reachable, but only to webhooks
been running the same components for over a year now so I know i don't have whatever is being brought up but updating and having to fumble in the dark to fix what isn't broken would annoy me greatly
I'd rather not say. You're probably better of updating anyway - the latest release is always the best so far
alright, so that's a yes π
Don't worry, I have a 0.88.6 box that's never getting updated π
Full blown access from the internet π
mine setup works fine after the upgrade, wonderful
I always upgrade, without issues so far
well i will update once i know what was changed lol
It's even in the release notes π
Iβm always upgrade too. I was just concerned this could be breaking change for some components
lucky you you werent around for the grat migration π
stuff broke every release
i only read what frenck posted earlier and been busy to catch up on anything posted after that
If it breaks, it was likely doing something shady
Those were the days. Right around card-gate too.
and what frenck posted was vague
card-gate didnt hit me so bad, still were using groups and such
Card-gate 1 or card-gate 2?
missed probably cardgate 2 completly
First one was when npm went down and all custom cards relied on that for LitElement.
Second was when the configurations were frozen, and any card that tried to change it broke.
ops i replied to wrong person
not all shady is bad tho, sometimes you gotta bend some rules to achieve what you want
there
@deft pewter so you are the security breach π all this to spy on my teams status
π
uh oh incomming norwegian input
as I said, itβs all risk assessment. There is shady you know and can live with, and thereβs shady shady. Last one iβd probably try to avoid
please stand up
Best thing I ever made
I knew it'd be the perfect match for the grid card.
The beauty is the simplicity
β€οΈ
thanks btw π€£
good one
I gone from deepl, to duckduck straight to google sehcohrity ~= security ?
Yeah, mine were all about the same. I'm waiting longer for some stuff from the UK π
What shipping method?
Carrier pigeon.
They could probably do it in 8 days but the labour union said they need rest breaks.
no surprise since I imagine what most people flush end up in norway anyways
shaved for the first time in like 6 months. thought my electric shaver was going to choke out a few times
This is not the place to talk about your asshairs tbh, that would be #330990055533576204 please mute and hide this channel @forest edge
just because you grow asshairs all over your face don't mean the rest of us do you eskimo dwarf
Get a room you two.
this is a room...?
pandemic pounds is nothing to be ashamed of!
Favorite Futurama quote.
s/o to coastward
Oh no, my pp
oh that's right you go by tonnes there
the sheer amount of wifi hacking station guides and tutorials popping up on youtube has me alittle concerned
I don't think that's a new phenomenon.
They were relatively new ... 20+ years ago when I first dabbled
The thing with YouTube is that you're seeing what their algorithm wants to show you. Doesn't mean the content is new, just that YT wants you to see it now.
On my 56k modem
Easier?
slaps mono around with a large trout
/flip
Yeah. Cos FOSS software needs to use open source chat tools too.
(β―Β°β‘Β°οΌβ―οΈ΅ β»ββ»
Don't you remember the lecture we got?
Even sec groups use slack
And they list their talk numbers in hex π€’
When is homeassistant/core:0x78 coming out
i dunno most of these are dated 2020
I mean you're seeing those now because YT wants you to see them now. Had their algorithm decided to show you WiFi hacking in 2018, you'd see a bunch of 2018 WiFi hacking content.
it doesn't make me any less concerned considering they are dated 2020 lol
some of these are new devices just for the act, like commercial built shit
i mean wtf
Well there's that commercial product sold to police to hack phones... none of this is a shock anymore.
We're getting to a point now where there's not much expectation of privacy.
that is true
Wardriving? Are we back in 2001?
so..i updated to the new version, worked for a few hours and suddenly my webui stopped responding and isn't loading even after reboot. what do i do.
You... stop asking support questions in lounge.
You're not new. You know the rules.
I used to think Egon was the most intelligent Ghostbuster. Now I'm starting to think it's Stantz.
I just watch screen rant movie pitch for movies I know will be bad
The next Venom movie is out in June too.
It was cheesy but fun.
The Marksman is out today. Liam Neeson being Liam Neeson again.
Gais, am I doin diz rite?
Are you attaching LED strips to your car? π€
Aren't they illegal that low
They are here at least
And illegal if too high
Or if you install them when saturn is inline with neptune
Also, Norway police, I'd like to report a crime. They were driving a VW with JD 69708
The only rule here before was all lights have to be in pairs
So 2-4-6-8-10-12
Now it just has to be within certain lumen ranges
Juliet Delta shutupayourface
@deft pewter yes, going to go full RGB for maximum acceleration and shitkid feel
All I want for the world, is for recipe sites to just have recipes on them
And not 800 words of poorly written blog trash, 8 overlay banners, 2 newletter signup videos and 3 video commercials
I agree with you... but they do that for SEO.
Blame Google's algorithms for demoting pages without all that shit.
I usually stick to sites I already know for recipes rather than Googling.
The BBC site isn't too bad: https://www.bbc.co.uk/food/recipes
allrecipes ain't too bad either: https://www.allrecipes.com/
Both get straight to the point and have no/minimal ads.
Start of the recipe. For reference the scroll bar is down to where kosher salt is
Yeah... having to scroll over two thirds of the way down just to get to the ingredients is a joke.
Google search needs to be put down really
For a lot of things, Google search is great. For certain content types, it's a PITA.
Taken out the back shed and let new worms rise up from it's rotting corpse
It's a perfect example of why organisms don't live for ever
They'd just become self sustaining blobs of tumours and open plan offices
I need to do a LinkedIn profile picture
Do you think, glasses or no glasses
I'm leaning towards glasses
I'd suggest posting both here for a critique but you'll probably just get a load of shit from us π
@deft pewter the ledbar is AliExpress btw
But... why?
And it's legal there to just add random lights to vehicles?
I find number of after market lights on a car is proportional to insecurity of the driver
lol
Hi all, new here just making the switch from OpenHab to HA
Hi Mono
Guten Tag
I don't want to be him βοΈ
lol
I'm installing home assistant now. I don't know why it took me so long to try it. But I do know that I am an idiot, so I'll be here reading everything, and then ask questions.
As long as you read channel topics, you'll be fine π
Shitposting goes in here, support goes... somewhere else.
And if you like bagpipe music, I think Tinkerer's putting on a performance later.
I don't think I have an opinion on bagpipes so I'll judge it entirely on Tinkerer... but it's an automatic like if it spits out flames.
Only when it's angry... and Tinkerer doesn't like being called an it.
Ha, gotcha
Watch out for the server's pet raccoon too.
Of course there's a raccoon... every server has a raccoon.
Yeah me to Im installing it, been stuck on the Preparing Home Assistant page now for going on 45 minutes, cant run any commands as it dont look like a normal Linux OS
I haven't really messed with Linux, I don't think... but the video I watched said it could take a long time getting the latest version and it automatically does that
anyone know the default username and password for the CLI?
It's not a normal OS... but you want to ask in #330990055533576204 if you're having trouble
No support in here π
thanks Momo
No problem, kc.
Getting EU job offers now too π€
Those are atleast more interesting than the US ones
Ability to orchestrate a pursuit team
π€’
That actually sounds fun
They know you're an overweight slob though, right? Pursuit is not in your nature.
Acknowledged leadership and motivational skills in large, cross-cultural teams.
This sounds like people responsibility
people π€’

Basically the job sounds like the same things I do today, just that I do it across 8 countries instead of 1
Should I say yes @deft pewter ? You are my guiding light
like
you either love looking at a terminal, or you love looking at teams/$(insert collab video zoom blinkylight here)/
I cant really thing of any cool stuff that doesn't involve some sort of terminal :p
Skydiving.
thats scary
Oh, wait... terminal velocity. π€¦ββοΈ
Depends on your definition of a terminal, for me that would be a VT100 monitor with attached keyboard
SEE!
I work on serial ports of devices as needed, then move over to IP based management, I seldom use a terminal, although I do sometimes when I touch 25 year old servers
how do you work on serial ports of devices?
With tweezers.
via a wireless serial dongle on my phone or my laptop, via a serial emulator of course
see, i'd call the serial emulator a terminal :p
I mean, most of my life is terminal emulations i suppose lol
If I ever use something, I use this
the application names for most terminal emulators are like, terminator, iterm, terminal, etc :p
iTerm best term.
yeah, i so like iterm, but i also end up with zsh and oh-my-zsh so i guess im fancy lol
rofl
zsh is the default on macOS now. It's awesome.
I just need to introduce more people to oh-my-zsh
surprised no one put integrations for snort in HA yet... after looking at the security filter middleware i assume it might be worth it.
better than writing your own middleware for exploit mitigation
You could go suggest that in the dev channels π
just did :p
if i was feeling more adventurous i'd try writing it myself lol
ugh, just learned a lot of the tuya stuff is being mitigated
there goes my dreams of cheap wifi switches that dont beacon out to strange places
these treatlife switches are $16, next cheapest z wave is $30 but it does have a repeater.
just gotta be patient with deals. $25 for zwave switches happens
or $10 zwave bulbs
A lot of stuff still has ESP82xx chips though, and those can always be serial flashed
There's also that
yeah, i think the tuya is moving quite a few to realtek
but the wiring of the two i put in before flashing is a cluster of wiring that i dont even want to attempt to try a do over again :p
in the future, ill probably just serial flash if i can
i'm at a place where im sure many people are, trying to decide on if i should stay with wifi or go mostly z-wave
the mesh wifi is pretty well covered in the house, where z-wave is currently just a zooz stick
two words. Radio spectrum.
yeah...
Zwave operates on 900ish mhz. wifi on 2.4 and rarely 5 for iot. Zigbee operates (mostly) on 2.4. bluetooth? 2.4.
hell, your microwave operates on 2.4
i do realize there will be far less interference with z-wave
also, lower freqs have better range, signal through tougher obstacles (like walls)
but also, if my house has enough EMF will it become more energy efficient by diverting solar radiation? π
i may move some things over to z-wave, i do like some of the water sensors
ΒΏPor que no los dos?
i'll likely use both, but i'll need a few repeaters for zwave atm. I do like that zwave is local, if i cant use tuya convert.
trying to decide of i want to spend money on moving fire detectors to nest protect. right now they are reverse polarity detectors that dont have internal sounders and im in the middle of a konnected convert. As it is, they literally do nothing if the alarm system isnt monitored.
My Xiaomi ZigBee smoke detector
are those things working fine? I'm deliberating to buy those once my old ones need replaciong
This looks to be viable presence detection technology
They just announced at CES and how some implementations, it is using radar for the monitoring
Actually it also does people counting
that could be amazing
@tropic adder non generic raccoon pfp reporting in
man, accurate presense/occupancy is the holy grail
@deft pewter you monster
π’
I would love good counting.... tried that with the motion sensor in my stairwell, one down, one up, but I can't get it to count reliable, even with 1 person in the house
I've only seen counting work semi-reliably with gate sensors (pair of beams to detect direction)
and even then, it has it's own limits
@deft pewter did you see I forgave you?
DON'T TAG HIM MICHELLE
yeah... well for beams I would have to start doing esp32 or pi zerro or something.. I don't think you can buy off the shelves ziggbee ones
hahahaha, oh man. that xandar system is $400 + $10/mo for people monitor (at least corporate)
any sensor that has two external inputs would work (there are zigbee/zwave/wifi ones out there)
i read something on the nest protect's motion sensors having decent presence detection, although i assume this system is going to be much more robust lol
Aren't Google working on radar-based solutions? That seems more likely to reach consumers than the one linked above.
Also... why haven't I logged in to discord earlier... it's such a delight to have this hivemind when working on HA.
Where did you get the pricing? I am curious
@tawny orchid haven't played with smoke yet, need to do that
someone say something about π« and π¦
Am I the only one that cringes a little when someone refers to a group of people as a hive mind? π€
the collective
would you prefer the term cult?
hahaha sorry I mean it very positive
Cult is more accurate. Yes, please.
I'm not saying you meant it in a negative way. It's just... odd.
You guys share an interest, so I'll refer to you as sharing a brain
It would be great if we could organise some bulk buy from the HA community and see what we could get the price down too
cult it is from now on π
$300 + $8/hour
one of us
one of us
so next time I have a question we'll start with: Hey HA cult, can you help me with this or that π
and we'll point you to the right channel, since this is the lounge π
of course I won't post it here!
also, if you're playing around with occupancy stuff. look into "wasp in a jar"
it adds some foolproof logic around occupancy that helps with the failures of sensors
at least until proper radar/counting is available cheaply to consumers
ignore @clear ferry he is norwegian's version of Milton from the movie Office Space.
And just like Milton, no-one would notice if atx was in a fire.
:(
But it's okay. He prefers to work in a basement with no-one around.
So my OG Pixel XL died an uneventful death overnight
At least it was peacefully in its sleep
All attempts to revive it have failed, I backed up all important data yesterday since it's been spontaneously rebooting and freezing for a few days. I was going to do a factory reset but uh...can't now
SlΓ inte mhath
Currently using my Nexus 5
Every time a new Google phone comes out, I debate getting one. But since I never leave the house now...
I recently moved to a oneplus 8T. very nice and dual sim
Loved the Nexus 5, but it had the "fun" issue of the touchscreen becoming partially unresponsive when the phone is plugged in
i'm still on the 2XL because nothing has interested me. I'm technically dual sim because i'm using the e-sim for Google Fi
@wet pilot I was using the OG XL for the same reason
There's one new on Amazon for $169, and I seriously might buy it
Or renewed for $119
its starting to show signs of failing so i'm not sure
Problem is the battery has been sitting for 4 years
i just don't know what to replace it with
Same
Still rocking an LG v35 here, great little phone
nah, startac > razr
lol get the new razr
The new RAZR actually looks pretty nice (the 2nd version, not the original launch version)
I like stock Android too much
yeah new razr2
Also, the song in the ad is a total bop https://www.youtube.com/watch?v=CI4sP1uwBk4
https://youtu.be/NLjfr06E3j8.
Invest in NSE & BSE
Invest and trade with Kite by Zerodha, Indiaβs largest retail stockbroker. Open an account now. https://zerodha.com/open-account?c=AL4299
Hey there! I have been investing in stocks and mutual funds using the Upstox platform and am quite impressed! Their platform is very secure an...
foldables are cool, but every one i've seen gets an ugly crease after a few months
oh, i don't do vzw so i guess i can't get it
new hinge on the 2 makes the radius looser so its less likely to crease
@wet pilot The launch exclusivity deal with Verizon is already over
ah ok
I think my favourite modern smartphone so far is the Huawei Mate 7
The P20pro was good too though
Also, the Verizon version is a "world phone" and has a SIM slot, so you can take it to any network you want
i think they're banned in freedomlandistan though
woof still 1.2k
Yeah, that's some expensive nostalgia
Lololol
The mate 7 was $550 when I bought it
Then again, I haven't paid for a cell phone in 13 years
I do love the idea of getting to use my old flip-phone muscle memory again, though
gets call, flicks wrist to open the phone and answer
Yeah, I never buy new phones on contract. I get last-year's flagship phones for under $200, outright, on Amazon π
I haven't paid for a phone in 8 years. work does that for me
speaking of. i need to see if the new S21 Ultra is up on the portal
This LG v35 I'm using now was $120 (brand new, in box), and was still so new that it got two major OS updates even though I'd already purchased it over a year into its lifecycle
Came with Android 8, got 9 and 10
Probably won't get 11, though
If someone tries to make me drink kool aid im out
I switched form P2XL to Pixel 4a and am extremely happy.
nice, that's what i was thinking. Wife is on a 3 that isn't doing well and i gotta figure something out for her too
My wife also has a 3 and is frustrated. She'll probably move to either a 4a or 5 if it gets worse.
To me, the main difference between the 4a and the 5 is wireless charging. I bought a usb wireless charging pad that fits inside my case and it's working fine for me. No need to upgrade to the 5 now.
+1 for wireless charging. Love that feature
Also slightly funny how many of my friends have phones with Qi charging who don't even realize it...
"Yo, do you have a charger I can borrow?"
"Yeah, but not with the right connector for your phone... wait... try the Qi charger on the kitchen counter"
da-ding!
Yeah. There was like one generation where it was hard to find (metal backs were popular)
i think the p5 is the only one with a metal back that has wireless charging
But then everyone went to glass (or plastic, or in some cases even wood/leather)
I distinctly remember LG releasing a phone with swappable plastic / leather / wood backs, that had Qi charging, while everyone else was using metal
Might have been the G4
Oh yeah, it was the G4. lol
I had wireless charging in 2010, it was great, I actually miss it
Palm Pre 2 was a great phone, although not much more
My first phone with wireless charging was my Nokia Lumia 920
but i have to take my pop socket off my phone to charge it :/
I still use the Nokia Qi charger that came with the 920. lol
I donated my palm wireless chargers to people with the 920 when it came out
webos was pretty great when it came out
i had a touchpad or two for a while when HP totally bombed them
Yeah, it's on some smart TVs
at least it's not Vista Sync (or whatever garbage GE used for a while)
I should download that Danish kids show with a guy with the world's longest penis
ford used whatever blackberry was for a bit
It looks fun
honda is just ancient android
ford used MS Sync as well
at least the ancient android in my pilot works with Android Auto. That's literally the only thing i need it for.
yeah
trying to integrate smartthings ... any one have luck ?
@fathom prairie -> probably #integrations-archived
ill try there thx
i wonder if the honda android used in infotainment would run the homeassistant app

#755367578381058178 squirrel cam
@deft pewter Diz u?
these squirrels are thicc
oh shit, squirrel gang fights are starting
nvm, they didn't want no trouble right now
oh, they back
Is Bu trying to scare people off in hangout?
snow and squirrels are scary, yes
I bet he doesnβt need wireless remotes to control his smarthome...
Some would argue if you do it's not "smart"
Would you rather be smarthung or have a smarthome?
Is here someone who would like to help me with installing? π
Read the topic and think about that question again.
I usually check my temp sensors or a weather service
you're outside the standard operating parameters for the Human integration.
anyone delt with rasbpis much? im trying to have communicate with one through mqtt. and getting connection refused but cant find any firewall and npin command showed the port open and connecting
read the topic
k

ffs
I have also seen directional network cables, for connecting your NAS to your smart speaker
i had a guy at best buy tell me how the $50 HDMI cable will provide a better picture than the $5 one. i said that's not how a digital signal works
Oh, I have low expectations. I'll just have to lower them even more.
i bought one like that when i was 12 ! though it was very fancy
That is almost as bad as the Denon link cables....
Oh that was a horrible picture
lol wtf
That's just a CAT cable, right? wtf?
4 used for $400 now that's a deal.

Prostupid.
there are cases of more expensive ones being better, but it's usually stuff like active cables, fiber , etc
build quality could certainly differ too, but still
i wouldn't buy a more expensive cable unless i was doing a long run behind a wall or something heh
Been saving up to buy this usb cable for months now.
https://www.audiogon.com/listings/lisa57ff-synergistic-research-galileo-sx-usb-cable-sets-a-new-bar-for-usb-cable-performance-digital
Audiogon is a pretty interesting site. π
Make Offer
$5
lol, who the fuck is buying that
atx is
Spend some time on that site you will be amazed. @night zodiac
To put in his box of junk in the garage.

Or to put in his junk. Who knows?
i'm sure his car is fine mono, damn
Yeah... his car...
Speaker cables anyone?
https://www.audiogon.com/listings/lisa65h9-masterbuilt-signature-bi-wire-speaker-cable-3m-speaker
Funny all that for a bi-wire π€£
how much gold can u buy for tha tmoney
About this much: #the-water-cooler message
https://squirrels.donger.in/ lol, by the time I completed this, they are all gone
Tree rats.
siiick
I didn't think you had to open them
he is so good at soldering
the xiaomi ble you have to
yee, I thought you just opened a website with your phone and connnected to it

well, you don't have to solder, you can tape the connectors to the pads
you can flash these here https://github.com/pvvx/ATC_MiThermometer
I was just about to ping quad
Pair and flash.
atx is making things up
I think he saw the USB to UART instructions for when you brick it
Anyone have a good recommendation for ceiling fan control?
girlfriend
@night zodiac should be done in less than a minute
I got the Treatlife ones but can't flash tasmota via OTA updates.
quad, I don't have mine yet. atx was just talking about he had to solder them but I didn't think so
Thanks! I've had good experience getting sonoff to work
@shy comet no write permissions on shield pro smb mount ?
umm not sure lol i use kodi with mysql for all my local media consumption
I guess quad has to buy dsh a new one now. thems the rules
For years now I've had a light switch that can be programmed to turn itself on/off on a schedule. The switch is programmed with the date, time, time zone, and lat/long and then you can create a schedule such as, "turn the lights on at sun set". It works pretty well except when 1/ daylight savings time starts or stops (the schedule doesn't adjust...
ugh i dont want to disconnect them lol
luckily, i dont have to worry about solder , tape or glue. I just use the logic analyzer clips
@tidal bronze checkout reddit and maybe reach out to hte dev...the dude is pretty responsive from what ive seen
@heavy ginkgo does tuya-convert not work with them? Worth a shot if you haven't tried already
quick poll, what is the current preferred install, rpi4, docker, vm? Any reason to pick one over the other?
VM on a high available cluster
what about not SD card but a USB flash drive instead?
be sure you have some sort of snapshot/backup schedule as well
Good news, USB flash drives are worse than SD cards π
yikes, so not an RPI
SD/USB thumb drive < eMMC < HDD/SSD
you can do rpi4 with a SSD over USB3
Pi4 +SSD works fine
but NUC > pi all day every day
Or old laptop
have had an instance running in docker to play, but thinking it is time to just load up a VM and get serious
Docker rocks
Docker all the things
Except Docker
is docker better than VM then?
Generally speaking... 200% yes
A Docker container is a lightweight little thing
A VM isn't
generally yes, buut what about for home assistant
A VM is a bloated whale, compared to the Docker's bowl of petunias
Well, HA is HA, however you run it
yeah, love me some docker

OK, so maybe I spin up a new container and make it clean.
@shy comet thank you.
docker > VM for home assistant, best regards from a VCP-DCV
i started repurposing an unused i7-6500u laptop for HA
its a bit overkill but nobody else needs the thing
It's a fine docker host and more
although makes sense to sell it off and buy something else
It has a built in ups
a callback to the earlier discussion about audiogon, i found something worse: https://www.thecableco.com/optimism-emm-st-toslink.html
Aural Symphonics is amongst the top companies as rated by audiophiles and high-end audio manufacturers for producing state of the art products for fiber optic data transmission.
I tried the docker install, but ended up with the OS install for ease of use
sweet
i've been the opposite for 2 years or so, I run containers for everyhing now. HA was the first docker, only had LXC stuff before
but LXC is more like VM light
I have a VM for running docker containers, but I still opted to run HA separately
VM Liteβ’οΈ
lol, so many emojis
I have more than enough resources to run an additional VM for HA. lol
Hell, i'm still trying to figure out how to use HA. Docker can wait a bit.
Straya
I have no idea what i am looking at
hi
where can I find which integrations are problematic, security-wise?
i don't get it. it just says to update. I've received that notification 3 times
couple of emails, discord notifications
Also it's only some custom integrations (at least per the blog post)
which integrations?
it says
"certain custom integrations have security issues and could potentially leak sensitive information. "
which ones?
And that's it
Nobody is saying right now
There's no point in asking again and again π
If you run it and you get a warning in your logs, it is that one
If there was more information, it would be in that thread.
There's not, so stop asking
It'd be in the blog post anyway π
And now, it's time for the classic piano piece, Girls All The Bad Guys Want:
https://open.spotify.com/track/36x30CV8ISbiBoIYYTH3FO?si=69s1LoPvRzGDfow-BX3ysg
They're not saying which ones and what the specific vulnerability is because then people with malicious intent could potentially take advantage of it
lol, middle school music time
At least not until it's patched
oh, haha
well shit
plays
I got a part list together for a new door bell that can take mp3s. my blues clues mail time song is incoming
thank you for providing an answer
that makes sense
btw, is there a mechanism for persons who have HA installed but are not registered on the foruns (or on this Discord server) to be notified of these urgent updates?
just curious
Yeah, watch the website.
hah
The blog has an RSS feed
There's also a "update" notification you can get right in HA
i have a friend like that but I called him
I'm not kidding. Subscribe to the feed, pay attention to the new posts.
Well, they should subscribe to either the RSS feed or join Discord and sub to #announcements
I'll tell him to register on the community website that will ensure he receives the emails at least
I'm sure this have been discussed already but as far as I understand this isn't actually a direct problem with HA. So unless you're using 3rd party code you haven't read it should still all be good.
didn't they post on twitter or something ? i had someone that isn't here or on the forum that already knew when i read the annoncement
I got an email a little while ago
didn't, but that's nice
sorry, I don't know that. it says "certain things" which for me means nothing. I know for a fact that he has the Tuya integration and a few others. but to know if it's 1st, 2nd or 3rd party code is impossible
i haven't upgraded yet, and i am using custom component, but i'll do next morning.
yep, also got it on twitter
the fact that they don't specify which also help reduce the chance of an automated attack
This only applies to third party - custom - integrations. If they're using things listed on the HA site itself it doesn't apply
Tuya is a core integration - this does not apply
@clever mortar there's 3rd party Tuya plugins as well
Yeah, but if they're using https://www.home-assistant.io/integrations/tuya then ... not so much
Hence my first statement there π
Also, the sky isn't falling. If it takes you a day or two to update I doubt the world will end...
I'd not be shocked if >80% of HA's userbase is months outdated
Anything that is loaded from custom_components. If you use HACS, installs go to custom_components as well. This is why they said you can change the name of the custom_components folder until you update.
i know, i'm really only preocupied with the users that install and have no mechanism to be called back for these more urgente security updates
From all I can understand it's not really a HA issue either. People pulling in 3rd party code is always a risk
I try to stay up to date. just never install the .0 version
The thing is, there's been things like this before - this isn't the first
@sturdy jewel honestly, if you install 3rd party code and don't follow along you probably should rethink that.
HACS has its own blacklist for that reason
Many folks just don't update, ever. They'll always be outdated, and vulnerable 
Assuming you update HACS π
but what's exactly third party code? I have the web+ssh add-on made by someone that required some protection flag to be turned off
is that 3rd party ?
I've updated to the latest version now AND moved out the two custom_components I'm using.
@sturdy jewel 3rd party code is anything that is being installed outside of the normal HA.
aight, this is zzz. can we talk shit or look at trash pandas
I love that you can finally scp from Windows.
Gonna make an effort to actually document/blog my projects but wanted to get a bunch of images from my PC to my server.
or danger noodles
Danger noodles are creepy. Raccoons ftw.
I assume since I just got them theyβll give the psk error, but I have to try first.
Just preparing myself lol
I'm sorry if this was previously answered or not (I tried looking above but I can't see it specifically). If you have a docker version of home assistant, you're not going to see the supervisor menu option, correct? Is there anything else we'd need to do to protect ourselves from this recent vulnerability?
Did you check the topic?
There are a ton of support channels. And this subject is getting rather oooooold.
vuln topic. this is fine. @ivory haven just update to latest and you'll be fine. If you're super tinfoil hat, rename the custom_components folder in your config dir (if it exists)
@heavy ginkgo probably, but you never know. i've gotten lucky before
thankfully those aren't difficult to serial flash if needed
is it known since what version the vulnerability was introduced?
it has to do with some custom integrations
yeah, I got that much
not a home assistant version
but is it something that's always been a problem?
or was there a "door" opened in a version that wasn't made known until recently?
from the commit, the middleware function was entirely new so I imagine it has always beeen able to be done
looks like I got rid of whatever custom stuff I had
so it doesn't matter
yay
laziness++
it's not a at all weird really, you pull in 3rd party code and give it access to your system and internet. It's not really a vulnerability imho
Is he even frisking them? π
There are no ghosts surrounding them atleast
I thought maybe he was using a wand but whatever that is in his right hand isn't big enough and there's nothing in his left hand.
atx is used to small things in his right hand.
Why would I block you?
Inside joke π€£
π¦
lol
I only have about 4 people blocked at the moment. You could probably guess half of them π
Yup
π¦
@clear ferry doesnt block because he's a glutton for punishment
^
photoshopped
At least you unblocked me again.

any news on the security thingy?
@forest edge reminded me of you π
@tidal bronze you have a stroke?
No, he always talks like that.
idk i mean he could be in a perpetual stroke state?

fun take: the POE Hat on the RPi is the easiest way to get a locking power connector for it.
stroke effects more than just ability to speak. short term or memory loss all together is very common
he's obviously thinking about @dull chasm not me lol
Pretty sure it's you.
where is vasiley anyway, haven't seen him around for a while
fukkin Tediore lol
Vaseline
@forest edge was thinking about grass, sand rabbits and you.
astroturf, desert hare you mean
No astroturf gotta keep the rabbits happy.
one thing at a time. he just learned that some people have humidifiers instead of dehumidifiers.
@night zodiac Australian broadband. Street cable "joints"
this aimed at me? I have both in this house
no, quad. haha
he was questioning the purpose of a humidifier because he lives without winter
Sinus and humidifiers π€
the workday goes so much faster when listening to sonic the hedgehog 3 OST
badtelcotech, which side do you light
I'd burn the whole thing down if it was up to me
I believe you have my stapler
one time I ran into an australian that told me that ausi network was fine. the other 60 people I have asked about it have said it is dogshit
the one that said it was fine was the one trying to convince me the most though
That Aussie is either lying or misinformed
imagine Milton in goth makeup and clothing and you would be looking at @clear ferry
Probably reads Murdoch press exclusively
Everyone is entitled to an opinion, as long as it's not contrary to mine
big if true
@clear ferry beyond my budget
@forest edge nope
@amber bramble I work goverment and this viris has had me working 70 hour weeks on average .....i am just so damn tired of the protest and viris details
what do you mean nope, you always ask him about his hares
oh then yes
ugh, cold wet.
only if you're outside
i live in the swamp so it's hot and wet, not cold and wet
what the hell am i looking at?
damn i live in swamp and its cold and wet @barren hound
is that your driveway?
oh, shared?
there is a fence between us and neighbbors
damn a little shorter than my driveway
y'all have short driveways
https://share.busheezy.dev/3PSJgo.png this is from an hour ago
mines about 1k foot
vasiley dosen't count the half hour swamp boat ride in between the main road and his "driveway"
I can hold like 5 cars without touching concrete. good enough for me
my driveway also wraps behind my house, so there's that, too
well nobody comes knocking on door @forest edge
lol
Probably like me, on FTTP with a decent ISP.
"I dunno what you mob all complaining about, I get a nice fast gigabit connection"
my ISP is really new and their stuff hooks straight into cogent annd I love it
tracert to a box in chicago which is 160 miles away
nice. I like cogent a lot. no frills services, cheap as hell, good support.
Whats up with the security advisory today?? Does anyone know what HACS modules were the source of the problem?
https://www.amazon.com/5G-Radiation-Blocker-Tested-Certified/dp/B08BG3V186 Can I use this with my blueberry pi?
there is a rabbit at my squirrel feeders
You have to put the sticker on your forehead for it to work
will that affect my tinfoil hat?
That's where everyone gets it wrong
Bill Gates is the one who needs to wear the tinfoil hat
To stop him using his brain chip to turn on everyone elses
Any recommendations for the best channel, to get advice to "back door' into your server if SSL has gone tits up?
probably to the channel for your install method
Plug in keyboard and monitor
Hmmmm....if only I had a 3D printer π€ ||as if I clucking had chickens||
Oofph my brain hurts
Learning aws-cdk, graphql(appsync), dynamodb and react auth simultaneously for the first time
graphql seems like a good idea until you actually have to use it
Why's that
some of the behaviors are oddly anti-pattern
The Naming conventions are pretty sloppy
that too
but yeah, ran in to some "fun" recently where a resource was double paged
but if you try to page through the sub resource you get errors everywhere because the thing is too dumb to process that properly
also, if you post a query and something behind graphQL fails but not graphQL itself you still get a 200 but then have to check for the errors
and it'll mangle the format of the response so have fun with that
is salty
noice
but yeah, cool idea, not implemented well at all
also, beware your request limit setting on the server. Had some fun with the system rate-limiting itself because even though you're making one request to GQL the GQL layer might be making thousands of requests to the next level
I would write the worst SQL in the world if I started to use graphql
not that it is a problem with graphql, lol
yeah the syntax is hot garbage too
"what if we make it almost like json but not quite!"
one time I was tutoring a guy in JS and he started to try to convince me why I should be using graphql one day, lol
I was like
lol
He had barely been able to code two weeks prior and suddenly had an opinion on APIs and such
was super confusing
rest is still best in my mind
I love REST and never really switched away. I have just learned over and over how to write better REST apis
yup
I wrote my own clients most of the time I am writing the API so graphql doesn't help me a ton
I usually design my databases first and then implement the API around 'er.
like, db in full
not just what I think I need at the time
i tend to use flask + sqlalchemy to do both at once
I use objection.js
but i draw out my tables before i get started
I'm a JS boy though and you are python so only our client tech will probably overlap
nice. Vue.js is my home
only connection from the frontend to the backend is via the rest api
and they run in separate containers
I work with Nuxt.js quite a bit because I like it
with objection.js, it lets another library knex pretty much do all of the queries and then objection.js just does the ORM stuffs
we wrote our own connector for flask since we use couchbase
though we're debating writing a dialect for sqlalchemy and then open sourcing it
ahh, I try to use postgres or mysql for most things and only really use nosql if I don't think I will know the data structure in the future
even then, I might make a relation between the RDM and the nosql, lol
everything we do fits well in the document world
I pretty much always know my data structure so I can just stick to RDB and migrate if needed
lucky me
its great when that works
I use elasticsearch for our logging aspects
but we're storing a lot of json data so it didn't make sense to break things out
gotcha
I have been trying to think of a fun integration I need for HA for days but everything is already implemented that would motivate me
haha
I used to use devcontainers but I'm just using wsl remote now
But for portable dev environments it's pretty sweet
To be honest package.json does a lot of the work for js environments
I've found js to be a lot less hassle than python for setting up the environment.
I'm using WSL remote at the moment and love it
Make fun of node_modules all you want, but it works
Make sure your workspace is inside your linux filesystem and not /mnt/c
yeah, haha. I used wsl1 and have been using it nonstop since wsl2
Wsl2 is great
Especially when I learnt to not use the windows filesystem in wsl remote
https://github.com/lextm/windowsterminal-shell here is a great shell script for windows terminal
Which is shitty that it's the default behaviour
hrmm, I don't remember it being default behavior
You know what shits me off. When i hit windowsKey and type terminal
the new term is pretty great
50/50 chance it brings up cmd.exe
Same but I like using the super key to launch things haha
Then I don't have to touch the mouse
fo sho
super + 3
But I love things that have different outputs for identical inputs
would launch it for him
Hmm. True
very nice. I didn't use that before but will now.
I do like commands that are transportable to any computer though
That has it installed of course
that is why I want to do the devcontainer stuff
I want to have like the full env everywhere I go ezpz
I found it a bit abrasive,
Having to rebuild the container and reload the window all the time
maybe I will save it for the project after next then
it can be but doesn't have to be
hrmm, I don't imagine I'll have to change the container much after it is done
depends on how it is configured. In most cases you only rebuild the last layer
I just sync my vscode settings to gist and lean on .vscode settings
but you could also pre-build the container and host it on dockerhub
Yeah it's just local build and I try and structure the layers,
i had to hack the python one because one of our required packages had some wonky requirements
I don't even go anywhere at the moment
not sure why I am worried about devcontainers for the projects only I work on
I mean you could put your requirements outside the container, but then you run the risk of config drift
If you're not prudent
it was container base os issues
if you pick the python3 base image in vscode you get alpine and that package required py3.6 on deb buster
pita
Yeah alpine is a false economy
For a dev environment though, size isn't that important
meh, might as well keep your container close to the prod env. our product is containerized already
I understand the reasoning behind that
But to be honest I haven't had huge benefit from that
I try and KISS for dev,
Then staging/prod is handled by CI and they can be in parity with each other with dispoable cloud environments
This mirrors my thoughts
I don't use containers during the development phase. I develop locally on my machine and integrate with remote APIs, databases, and services through configuration.
128
519
i get that and i actually have everything locally for me. But getting that set up is a pita and some of our content devs are too scruby to be trusted
the barrel plug that came with this power supply was trash. It was super hot and everything else was cool to the touch. I bought another one off of amazon and nothing is warm at all. much bettah
Was there a short somewhere with the barrel plug?
Speaking of which, I let the magic smoke out of something yesterday. It was already dead before though so I guess it's now super dead
no, it was one of the ones where you screw in the wires
I bought some proper ones that don't have any screw pinch shit
lol, the new ones are much better. soldered and heat shrinked
Mmmm woke up to -18 on my temp gauge, that means -25 down by the road
I thought you checked voltage drops
Let me check
It is actually high now, because most people are sleeping
my UPS reports voltages in ints intead of floats and gets wild on teh graph
Do you get more than 230V during the summer?
213v
Oml



