Sign in

Home [Unofficial]

@neilzone.co.uk.web.brid.gy
7 followers 0 following 36 posts

🌉 bridged from 🌐 neilzone.co.uk: fed.brid.gy/web/neilzone.co.uk

PostsRepliesMedia
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 29/09/2026
neilzone.co.uk
How does one genuinely identify one's own, non-technical, learning and development needs?
As a solicitor, each year, I need to make a statement of solicitor competence. Aside from the regulatory requirement, I _want_ to do a great job for my clients: it is a source of my own personal, professional pride. Similarly, most of my work comes from word of mouth referrals so, simply from a grubby money-making point of view, doing a good job just makes sense. The requirement, at a high level, is pretty obvious: > the ability to perform the roles and tasks required by one’s job to the expected standard The Solicitors Regulation Authority helpfully breaks this down into a number of different areas: * A Ethics, professionalism and judgment * B Technical legal practice * C Working with other people * D Managing themselves and their own work ## Technical competence Crucially, based on the SRA’s list, technical competence - the “knowing and applying the law” bit - is just one facet of overall competence. In terms of learning outcomes / knowing what continuing education I need, this is pretty straightforward: I know that I need to keep on top of my stuff. For me, this means both law and technology, since much of what I do draws heavily on both aspects. In practice, I do this through keeping track of numerous different sources of information, and most of my reflections end up as posts on my work blog. Sure, there is an awful lot of change in both technology and law, and keeping on top of all the various legal issues can be challenging, but at least I can work out what I need to do reasonably easily. ## Other aspects of competence I find it harder to assess my learning needs in other areas. Not in a box-ticking sort of a way - actual, genuine, “this would be useful”, development. Stuff that it is worth spending my time on. I have no colleagues, and while I’ve asked clients for feedback, specifically what I can do better, or things they’d like me to do differently, or things that they have valued in other professional advisors, I have turned up nothing. I will keep asking every so often, but I cannot rely on this as a source of learning needs. I do my best to assess my own performance, but I struggle. I keep a document of “practice reflections”, in which I note down issues which cross my mind. Looking back on it for this year, themes include ethics (below), IT and cybersecurity, and, perhaps inevitably, AI. I mentor people, but I have not been mentored. Perhaps that is something to explore. Nevertheless, I do what I can - this year, I had a particular focus on ethics, in the light of the Post Office scandal - but I’d like to be _better_. I could be led by what is on offer, in terms of seeing what CPD providers are offering, and what other resources are available, and seeing if I fancy any of them. But that feels like the wrong way round to me, since it is not centred on my own learning needs - but it could still be a good source of inspiration. ## What others do So I asked other professionals in the fediverse what _they_ did for their own continuing professional development. (Importantly, I did not ask what they think that I should do, but rather what they themselves did.) I got a range of answers (including many focussed on technical competence), which I have paraphrased / collated here: * a company gives a week off each year for CPD, but the training must be nothing to do with their everyday work. * I keep a journal, including things that I find myself hesitating to do, or something that I feel that I did poorly. A variation of this was a “leadership lessons” log, with things that the author saw others do well/poorly, and what they themselves did well/poorly. * annually, I prepare a document that contains low points, high points and what I learned from the previous year, and new things I want to try or do / things I want to continue doing / things I want to stop doing for the next year. * breadth first and depth first investigations. * focussed time, periodically, thinking about my career and role. * pay attention to the long term changes. * paying for a business coach. * looking at people I admire and what they can do, that I wish I could do. * talking to people in relevant areas, asking them about challenges they face and skills they have, and comparing it to what I can do or struggle with, and asking what they are up to * formal reflections following a template. * browse the CPD section of their professional institute, for inspiration. ## Next year I will see what I can take on board here, for the coming year. And, if you are a client, and you think of something that I can do differently, or better, please do let me know!
001
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 26/09/2026
neilzone.co.uk
On Free software project boards and governance
As always, these are just my opinions. ## A board needs a clear, accepted remit If the remit of the board is not clear to all concerned - the broader community, not just the members of the board - and if that remit is not accepted, argument and politics around what the board should be doing are inevitable. This wastes everyone’s time, on meta debates and side issues, and leads to conflict and division. Does the board set the strategy? Define the policy? Hold an executive to account? Mediate or arbitrate disputes? Act as a point of escalation? Fundraise? And so on. That remit may change over time, and I see no problem in that, as long as that change is in itself both clear and accepted. ## A board needs clear, measurable, documented priorities Similar to the point above, without a clear focus, and a set of documented and measurable objectives / priorities, the board is but an iceberg, bobbing around in the ocean, haphazardly knocking against interesting things. Without priorities, the board may be full of people who, individually, are all doing, or are capable of doing, great things in support of some broader mission, but without the cohesion needed for a board. What are the board’s success factors? Failure criteria? ## A board meeting needs planning, preparation, and focus To be productive and worthwhile, board meetings need to have an agenda, and all relevant pre-reading, circulated sufficiently in advance for board members (volunteers, who have other commitments) to read, contemplate, and prepare. The goal of each agenda item must be clear. Is a decision required? Is this an update (which, for some reason, could not be delivered asynchronously)? Is a discussion required, and if so, to what end? Sufficient time must be allowed accordingly. ## A board of volunteers needs to cope, even thrive, with inconsistent participation In the context of a group of volunteers, consistent participation may be unrealistic. People have other priorities, and may not be able to volunteer every month. A board which requires 100% of board members to be present to form a quorum for a meeting is not conducive to effective decision making if participation is inconsistent. It means that taking decisions during a meeting is rarely possible. Similarly, if an asynchronous decision making process requires all board members to vote one way or another, or to abstain, before a decision can be reached, then that process is neutered by a voting member’s non-response. A board needs to be set up with inconsistent participation in mind, if that is the operating reality of the board. ## A board needs transparency, and equal access to relevant information It is impossible for a board to have informed conversations, and make good decisions - decisions which are truly in the interests of the community that the board serves - unless everyone on the board has access to all relevant information. Information asymmetry leads, at best, to poor and inconsistent decision making and, at worst, to factionalism and mistrust.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 25/09/2026
neilzone.co.uk
An increased sense of perspective
Over the last couple of years, I’ve found myself increasingly aware of my sense of perspective. Or aware of an increasing sense of perspective. Of the notion that we have a limited time until we die, and that some of the things - many of the things - which might previously have mattered to me or seemed significant are, in fact, inconsequential, and are not worth getting bothered, let alone worked up, about. That some things are just not worth the time or effort. Not to the point of not caring, but rather about being more conscious of the things that I actually care about. I have long been a fan of “don’t worry about things that I cannot change”, and also the idea of “don’t worry about the small stuff”, and that pretty much everything is “small stuff”. Conversely, that some things which may seem minor, or inconsequential, may actually have a significant impact on me, or someone else, and so are worthy of focus, of care. Not everything is “small stuff”. It doesn’t stop me having a flash of annoyance at things, or a sudden urge to Make Something Happen, but it does mean that I am faster, or more willing, to take a step back and think “does this really matter to me? Do I really want to be spending time on this?”. I don’t know if this is a “getting older” thing, or a “getting wiser” thing, or something else. But it is a noticeable thing. It’s… curious.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 17/09/2026
neilzone.co.uk
Initial thoughts on the EU KIDS Act
The European Commission has proposed the EU KIDS Act. It is yet another set of Internet/web regulation proposals to examine, for jurisdictional overreach, lack of common sense in terms of material scope, and so on. ## It is only a proposal currently It is only a legislative proposal at the moment, so it may not become law, and it may not become law in this form. Based on a quick skim, this is indeed another fine mess, full of unrealistic expectations. ## It has an incredibly broad scope The proposal covers a lot of services: * online social networking services; * video-sharing platform services; * software application stores * online games; * operating systems; * AI companions; * general conversational chatbots. I have read this from the perspective of online social networking services, thinking predominantly about Mastodon and other fediverse services. At least code forges are out of scope (“open-source software-developing and-sharing platforms”). And Wikipedia seems to have its own bespoke exemption (“not-for-profit online encyclopaedias”). Small, low risk services are in scope. The covering material specifically notes: > small and micro enterprises are not exempted from this Regulation, since they may equally provide harms to minors. It would undermine the objective of this proposal to exclude them from scope Wow. I wonder if the drafters will realise just how harmful this is. In terms of territorial scope, it is broader than the EU GDPR, and indeed the UK’s Online Safety Act, purporting to apply > to providers of services irrespective of where they have their place of establishment where they offer those services to recipients of the service that have their place of establishment or are located in the Union I wonder if anyone working on this stopped to think about the boundaries of their laws, and whether they really think that they can impose obligations on people in other countries, merely because that person is running a service which happens to be available to people in the EU? Do I, as someone who runs my own fedi server, where people in the EU can read my toots and respond to them from their own instance, fall into scope? I do not know. ## The proposal would appear to demand age verification for the fediverse > Providers of online social networking services … shall not allow a natural person below the age of 15 years to create an account with that service or to access that service by means of an account, created for, or attributed to, that person, where the service poses a risk to the privacy, safety or security of a minor below that age. (Article 6(1)) The tests for “poses a risk” set an incredibly low threshold, and include: > enables recipients who access the service through an account to transmit content in real-time to an indeterminate number of other recipients of the service, including through live streaming of audio-visual content and > enables recipients who access the service through an account to contact, communicate and otherwise interact with other recipients of the service not part of the recipient’s pre-existing connections or subscriptions So a “papers, please” web would become the norm, according to this. ## Some of the obligations are just unrealistic For example: > When creating an account for a minor pursuant to paragraph 2 of this Article, the provider of online social networking services … shall take measures to establish whether the person creating the account is the holder of parental responsibility over that minor in accordance with Article 26 and verify that the recipient of the service has reached the age of 13 years in accordance with Article 28(1). (Article 6(3)) Article 26 sets out how the European Commission envisages this working, but, wow, I just don’t see it. ## A watershed for the web? Harking back to (what should be the exceptionalism of) broadcast regulation, there’s another banger: > Providers of online social networking services… shall put in place effective measures to ensure: > > 1. time-limited access for minors on their service; > > 2. interruption of usage by minors on their service. > > > > Such measures shall be designed in a way that protects school time and core sleep hours of minors. (Article 9) Sorry, I have to turn off my fedi server now, because a child in a different timezone might be heading off to bed and my toots might be distracting… ## Unrealistic requirements Some of the proposals seem to relate to core browser functionality: > Providers of online social networking services … shall put in place measures to ensure that settings are set by default to a high level of privacy, security and safety of minors. To ensure compliance with this paragraph, such providers shall, by default, turn off at least the following settings: > > … > > 2. access to microphone and camera > and > other recipients of the service shall not be able to download or take screenshots of contact, location or account information of minors or of any content uploaded or shared by minors on the service; I have no idea how the drafters of this expect the provider of a social media service available via a web browser to restrict screenshots of everything posted by a user. It is not within their gift. The only way to make this work would be either to force all access to be via an app (which would be daft), or preclude child access (which has age verification challenges). ## Child use restrictions Some of the use restrictions would seem very challenging: > Providers of online social networking services … shall put measures in place that ensure a high level of privacy, safety and security of minors as regards contacts between minors and other recipients of the service. Those measures shall at least ensure that: > > other recipients of the service are not able to initiate direct contact with the minor, if the minor has not pre-approved such contact So a 17 year old here posts something interest. No-one is able to interact with their post, unless the 17 year hold has “pre-approved” it. Oh, don’t worry, you won’t be able to see their post anyway: > by default, other recipients of the service not previously accepted by the minor shall not be able to access account information of the minor or content uploaded or shared by the minor on the service
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 15/09/2026
neilzone.co.uk
Initial thoughts on the Social Media Platforms (Ofcom Licensing) Bill
There’s nothing like waking up to find people telling me about proposed new legislation which, if passed, would geoblock people in the UK from so many online services, end numerous services in the UK, and criminalise myriad people in the UK. Today’s proposal is the Social Media Platforms (Ofcom Licensing) Bill. The gist of the proposal is that anyone who “operate[s] a social media platform that is available to users in the United Kingdom” commits a criminal offence unless they obtain a licence from Ofcom, and comply with the terms of that licence. Is it a private members bill, and is unlikely to pass - more a declaration of intent than a serious attempt at legislating - so there is a risk that, in responding to it as a serious proposal, one gives it more credibility than it deserves. Nevertheless, here are three quick, pre-breakfast, thoughts, based on the text of the bill here. # The objective of the bill is not clear My starting point, in anything like this, is “what is the problem that the legislation is trying to solve?”. Here, I just do not know. I cannot get to the point of trying to assess whether it is the best way of trying to solve the problem (although this is incredibly unlikely), because I cannot tell what the problem is. # I can’t imagine legislation making a pub or cafe owner criminally liable for regulating their customers’ conversations The Online Safety Act 2023 already started down the very slippery slope of regulating people’s conversations, through the guise of requiring platforms to do things in respect of those conversation / interactions. Ostensibly it is not content regulation yet, in practice, that is really the outcome that is sought. The same is true here, and this bill is even more concerning. I cannot imagine someone attempting to pass a law telling pub landlords or cafe owners that they - on pain of criminal liability - : > must take all reasonable and proportionate steps to ensure— > 1. that conversation in the pub/cafe complies with the laws of the United Kingdom; > > 2. that conversation in the pub/cafe is not materially harmful to users or to the public interest; > > 3. that conversation in the pub/cafe does not incite criminal conduct, violence, hatred or public disorder; > > 4. that systems are in place to minimise the dissemination of materially false or misleading information; > > 5. that users are provided with transparent information concerning the identity and authenticity of persons having conversations in the pub/cafe; > > 6. that harmful conversation identified by Ofcom is removed, restricted or otherwise addressed within such period as Ofcom may specify. > (All I have done here is replace “content made available on its social media platform”, from clause 4 of the bill, with “conversation in the pub/cafe”, and “content” with “conversation” in (f).) I don’t know how someone might go about some of these things? How does the provider of, say, a running forum make a determination of whether a conversation contains misleading information? Is a campaign against facial recognition cameras in public places “harmful … to the public interest”? Who decides? How does a forum for vulnerable people who wish to share sensitive information comply with (e), to provide “transparent information concerning the identity and authenticity” of other users, without causing users harm and stifling their speech? How does this interplay with a user’s rights to freedom of expression, privacy, or data protection? # The scope of the bill is unclear but probably very, very broad The lack of a conjunction at the end of clause 3(a) renders the scope unclear. Does a platform have to meet both (a) and (b) to be in scope? Or either (a) or (b)? If it is an “or”, then the scope is very broad indeed. If it is an “and”, then it is slightly more narrow, but still incredibly broad. I do not know what “other than those with whom they communicate privately” is trying to get at. Does it include only direct messaging between a small number of participants? Is a large, but closed, group chat “private”? If I run a fedi service for my family, but everyone can see each others’ posts, is that private communication? There is no carve-out for small, low risk, services. Off the top of my head, I’d have to obtain a licence for several services that I run at home. This is an existing problem with the Online Safety Act 2023, but since the impact of this bill would be to criminalise me unless I obtained (and presumably paid for? since Ofcom could not run the infrastructure needed to staff etc. this for free) a licence. Right. Breakfast time. Oh my.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 05/09/2026
neilzone.co.uk
My views on genAI and F-Droid
This is just a record of a fediverse post that I made today, and my subsequent (collective) response to the main points raised by various people who replied to me. There is a proposal for F-Droid to adopt an interim AI policy, along the lines of Debian’s pro-AI policy. [I am not in favour of this(https:// gitlab.com/fdroid/admin/-/work_items/699#note_3771382103). In particular, I don’t want to see genAI code in either F-Droid’s own software, or in apps in F-Droid’s repository. Mine is, of course, just one voice. But I will continue to push for human-written FOSS apps, for human users. (Yes, I am an F-Droid board member. Yes, I’m a volunteer, like everyone else. Yes, others seem to have different views. I do what I can.) * * * I have had a lot of replies to this, and I am sorry that I will not be able to reply to each individually. But I can at least try to reply thematically. Again, my personal views. > I like genAI / I use genAI Okay. > genAI is really good Even if true, on its own, this does not carry enough weight in my eyes to justify overlooking the problems. > It is the output that counts, not how it is made. Ethics matter to me. I support codes of conduct for projects. I can’t ignore the horrible views of an author to let me enjoy their writing. And so on. A community is about more than code, and I don’t buy a “make the code better at all costs”. > It is too late to stop genAI Why? Is there actually an argument here? > A ban would not stop people using genAI / people will not tell you that they are using genAI I agree. If someone is willing to lie about their use of genAI, and submit it anyway (assuming that it was prohibited), then the F-Droid volunteers may not be able to detect it. There is a limit to what any project can do about bad faith actors, willing to break the rules because it suits them. Importantly, a position sends a signal. It says “this is what we want our community to be”. Laws against murder do not stop murders. People still drive while intoxicated. etc. > It is not for F-Droid to determine what F-Droid hosts F-Droid already has an inclusion policy (https://f-droid.org/docs/Inclusion_Policy/). I can’t see this changing (nor would I want to default to “anything goes”). The repository system is open, in that developers can host their own repositories or use a third party repository, and users can choose what repositories to add. So F-Droid already determines the boundaries of what it is wiling to host. > You can just choose not to use an app made by genAI? This is hard to reconcile with an argument that people will not disclose their use of genAI. Both cannot be true. In any case, developers who wish to use genAI could “just choose” not to submit to F-Droid’s own repositories, and run their own, and make whatever decisions they like about the governance of that repo. Again, my views. Not those of F-Droid. I am just one voice here. etc.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 03/09/2026
neilzone.co.uk
RSS feeds for individual authors of The Register using The Register's new API
Tech website The Register used to offer author-specific RSS feeds. It has recently changed how it does RSS feeds, to use the new api.theregister.com. Thanks to a kind fedizen for showing how one can still use this new API to get author-specific feeds: https://api.theregister.com/api/v1/article?query=created_by=%22Liam%Proven%22&orderBy=published&site_id=2&remapper=rss&limit=20 One can also use `author=` instead of `created_by`, and this brings back a slightly different set of posts. I don’t know which is “right” or better for my use case. Annoyingly, whichever selector one uses, this results in one single massive block of text, without paragraphs or other formatting. Which is better than nothing, but not ideal. I have yet to find a way to deal with this.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 01/09/2026
neilzone.co.uk
Airsoft and the UK's consultation on changing the rules around fireworks and pyrotechnics
The UK government is consulting on changing the rules around fireworks and pyrotechnics in the UK. Like many people, I enjoy using P1 pyrotechnics safely and responsibly as part of playing Airsoft. I had fun this weekend with both flashes and smoke grenades at my local Airsoft site, Red Alert. Although the kind of pyro used in Airsoft is not the main focus of the consultation, some of the questions that the government is asking - particularly around P1 pyro, and noise levels - mean that changes to the rules could still have an (unintentional or otherwise) impact on Airsoft. If you enjoy using pyro for Airsoft or paintball, please do consider responding to the consultation, with simple, clear answers. ## How to respond You can respond to this consultation online, or by email to fireworksconsultation@businessandtrade.gov.uk, using this response form. It takes just a couple of minutes to complete the online form, and you do not have to answer all the questions. Get your response in before 7 October 2026. ## My consultation response For inspiration, here is what I said. (For all the other questions, I said “No answer”.) > 5. Are there any other specific F1 and P1 pyrotechnics that should have their regulatory requirements increased or decreased? Please state which products, what regulatory requirements you think they should have and give your reasons. > Products: P1 pyrotechnics used in Airsoft and paintball games (e.g. smoke grenades, thunderflashes, and frag grenades) Reasons: Numerous adult players of Airsoft and paintball enjoy using P1 pyrotechnics safely and responsibly as part of their games. This includes: * smoke grenades (to provide cover, or to imitate different gases) * pyrotechnic devices which cause either or both flashes and bangs (to distract, and to imitate grenades) * frag grenades which explode while ejecting dried peas and the like (to imitate grenades) * more specialist pyrotechnics such as mortars and launchable devices (to simulate rockets). These are often sold to players 18 or over at Airsoft and paintball sites and shops, providing a valuable source of revenue to UK businesses. They are used safely and responsibly, at dedicated sites. Airsoft and paintball sites include rules around use of these pyrotechnics as part of their pre-game safety briefings, and games are played with the supervision of trained marshals. There should be no change in the regulatory requirements relating to P1 pyrotechnics used for Airsoft and paintball purposes. > 6. Do you agree the decibel level of fireworks consumers use should be lowered? Choose one of the following options: > I selected “No, the maximum noise limit for fireworks should remain at 120 dB (A,imp)”. > 8. What might be the negative impacts of reducing the maximum decibel level of fireworks available to the general public? Please explain your answer, providing evidence where possible. > In the context of Airsoft and paintball, the existing decibel level provides a degree of realism. This is a key part of the reason why players use noise-generating pyrotechnics while playing. > 9. How much lead in time would businesses need to prepare for the changes proposed in this consultation and why? Please state a lead in time in months or years, and explain your answer, providing evidence where possible. > Companies making pyrotechnics for the UK market will need time for research and development, initial manufacturing, safety and compliance testing, and then manufacturing and distribution of new pyrotechnics. Airsoft and paintball sites and shops which sell pyrotechnics will need time to sell off old stock, and to source and obtain new stock (dependent on manufacturers and wholesalers having stock of newly-compliant devices available), to avoid a gap in sales and associated drop in revenue. I would expect this to take several months.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 29/08/2026
neilzone.co.uk
Automating local backups of UniFi OS Server on Linux with uos-backup
Earlier today, I migrated my self-hosted UniFi controller from Network Manager to UniFi OS Server. One of the annoyances of the new setup is that it does not allow automated local backups - just automated backups to Ubiquiti’s cloud. Fortunately, one can work around this. ## Set up a new user In the UniFi interface, I set up a new local user, `backup`, to use for this automated backup. ## Set up `uos-backup` I am using uos-backup. `uos-backup` is a simple Python scripts which someone has kindly written and shared. I did the following, on the machine I wanted to use to take and store the backups. Get the code: git clone https://gitlab.com/faerbit/uos-backup.git Change to the directory with the code: cd uos-backup Edit the python script, for the correct URL, username for my new backup user, and password. Check that the requirements are met: sudo apt install python3-requests -y Copy the script to `/usr/local/bin/`: sudo cp uos-backup.py /usr/local/bin/ Make it executable: sudo chmod +x /usr/local/bin/uos-backup.py Create the directory to store the backups. This is the directory specified in the script; you can create a directory with a different path, and then just update the script according sudo mkdir -p /var/lib/uos-backup Test that the script works: sudo /usr/local/bin/uos-backup.py Even though I had just set up a new user, I had managed to get the username and password wrong in the script, and this step helped me debug it. I checked in /var/lib/uos-server/ to check that I had backup files. Set up the systemd services: sudo cp uos-backup.service uos-backup.timer /etc/systemd/system/ sudo systemctl daemon-reload sudo systemctl enable --now uos-backup.timer I then added the backup directory path to restic, so that it gets picked up with my automated restic backups too.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 29/08/2026
neilzone.co.uk
Migrating my self-hosted UniFi controller from Network Manager to UniFi OS Server
One of the jobs that has been on my list for a while is to migrate my UniFi controller installation from the self-hosted network manager tool to the new UniFi OS Server tool. The only reason that it was a job at all is because UniFi has decided to discontinue support for the UniFi network manager. Which is probably for the better, as it contained outdated packages anyway. Frankly, I’m not massively impressed with UniFi any more. If I were starting again, I am not sure that I would pick UniFi kit, but I don’t know what I would go for instead. I simply want to run my own controller, without external access or access by anyone else, to control the network infrastructure at home. I did the migration, and it _mostly_ worked. Here’s what I did: ## Read the instructions I read the Unifi OS Server installation instructions. I also read the Backups and Migration in UniFi instructions. ## Snapshot my virtual machine My UniFi controller is running in a virtual machine, so I took a snapshot of that first. If all else failed, I could roll back the snapshot. ## Back up my existing controller’s configuration I backed up the configuration of my existing UniFi network manager configuration. I downloaded it to my local machine. ## Back up ssh config info I also backed up the ssh configuration information for my UniFi devices, in line with the instructions: > It is also recommended to copy the SSH username and password from Devices > Device Updates & Settings > Device SSH Settings, in case any devices need help later when connecting to the new instance of UniFi Network. ## Stop existing UniFi systemd service I stopped the UniFi network manager with `sudo systemctl stop unifi`. ## Install new software Unifi OS Server I followed the Unifi OS Server installation instructions. It worked. It will be interesting to see how updates work. ## Change my nginx config The instructions say: > Captive portals will be served on port 8444, changed from port 8843 on Network Server. It did not mention that there was also a change to the port to the controller. However, the final line of the set up information showed that it was port 11443. So I changed my nginx proxy config from 8443 to 11443, and reloaded nginx. I could now access the new UniFi OS Server interface. It went downhill from here. ## Set up UniFi OS Server I was intending to restore from backup, so I clicked the option for this. It then prompted me to - forced me to - sign in with a ui.com account. I’ve no idea why. It is a local controller, and I don’t want any remote access facilities. Nevertheless, I could not find a way around it. So I did, but I can’t say that I am impressed by this. It then said: > We’ve discovered that you already have a self‑hosted UniFi Network installation. Would you like to import your current network settings into UniFi OS Server? But the options were not “Yes” and “No”, but rather “Continue without importing” and “Next”. This was a surprise anyway, as the instructions say: > On macOS and Windows, the installer will automatically detect and offer to migrate your existing Network Server setup (if installed in the default location). > On Linux, or if auto-migration doesn’t occur, you can manually migrate by installing UniFi OS Server and using the Site Export tool I am running it on Linux, so I did not expect any migration. I guessed that “Next” means “yes”, so I selected “Next”. It took me to a url ending `/net-migration-offer`. This was a blank screen. Nothing at all. I waited a couple of minutes, then refreshed the page. It then showed me a page showing that it was “restoring backup”, but the progress bar remained blank for quite a while. It also said that it was restoring to settings from January 2026, not last night’s backup, which surprised me. After a couple of minutes, the progress bar flashed by, and it was done. ## Check the configuration The import/migration appears to have correctly imported all my devices, and is set up to talk to them. But other aspects of the migration were underwhelming. ### Mailserver config does not work It did not restore the settings for my mailserver. It was preset to use the “UI Mail Server”. I set it up to use my own mailserver, and it failed, with a useless error message. When I logged in to my mailserver to see what was going on, I saw `improper command pipelining after CONNECT from unknown`. _sigh_ It appears that I am not the only person with this issue, albeit with a slightly different setup. They seem to have resolved it by disabling TLS, which is not an option for me. I have not yet got this to work. ### Automatic backups do not work Even though I had configured automatic backups on the previous Unifi Network Server, they were not enabled on the new UniFi OS Server. I tried to set it up, but I was prompted for my “Ubiquiti SSO account password”. I tried the password for my ui.com account, but I got an error message of “Something went wrong. Please try again later.” Which was no use at all. Having turned off Remote Access (below), I went back to the Backups dialogue. Now, there was an option to download, or upload & restore, but nothing about automation. The info box says that I can schedule backups here, but there is no user interface for that. I took a manual backup. I cannot see a way to do automated backups to my local file system. If this is correct, this is absurd. I may see if I can do something using the command line. *Edit: yes, I can, with python and systemd. See Automating local backups of UniFi OS Server on Linux with uos-backup. ### Remote access is enabled by default “Remote access” is enabled by default, even though I am confident that I did not have remote access enabled before. When I attempted to untick it, it showed a dialogue box: Disable Remote Access Are you sure you want to disable Remote Access? Please note that you will lose access to: System Config Cloud Backups Access through the UniFi Site Manager Teleport and Site Magic VPN Notification Services So I disabled it. https://help.ui.com/hc/en-us/articles/220066768-Updating-and-Installing-Self-Hosted-UniFi-Network-Servers-Linux ### Time format was incorrect It did not restore my preferred time format (24 hours). ### Analytics is on by default I had to turn off analytics, which was on by default. ## So it kind of worked It worked better than I was expecting, but that’s mainly because my expectations were very low. Why the email server and automated backups do not work, I do not know. I will need to investigate these. But at least I am now running a supported controller again. Once I’ve done a scan of the new system with greenbone, I’ll be interested to see what it reports.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 28/08/2026
neilzone.co.uk
Time to drop .legal?
My wife and I run a small law firm in the UK. Originally, we called it decoded:Legal. It made sense at the time, even though quite a few places struggled with the idea that a company name might have a colon in it. We used `decodedlegal.com`, and I registered `decodedlegal.co.uk` too (and, it seems, `decodedlegal.uk`) although I don’t think I’ve set up DNS for either of them. Then, when a friend pointed out that there is a `.legal` tld, I thought “that looks nicer”, and we switched to `decoded.legal`, both as the company name and also our domain name. I wonder if - nice though it still is - I should think about using a different tld. (If I moved, I’d maintain decoded.legal indefinitely anyway, because people are used to sending email to @decoded.legal addresses.) ## A poor reputation? The .legal tld appears to have a poor reputation. For instance, it is on this list of “The Top Most Abused Top Level Domains”. It would be a shame if people could not find our business, or access any of its online properties, because .legal is on that list. (And, yes, I could seek an exception, but that hardly seems the point.) As far as I know, this has not been a problem so far, but this could be survivorship bias: I don’t know about the people who have never seen me. ## Control over .legal The .legal tld is operated by Binky Moon, LLC, which is based in the USA. I wonder if it would be sensible to use a .tld subject to UK control instead. Obviously, it would be nice if I was not dependent on anyone other than me for my domain name, but that is unrealistic. ## What about .onion? I use a few .onion domains - for access within Tor - including for decoded.legal properties. For instance, our website and blog are available at http://dlegal66uj5u2dvcbrev7vv6fjtwnd4moqu7j6jnd42rmbypv3coigyd.onion. (And, yes, it is intentional that this no longer has https.) Realistically though, the vast majority of people are not going to visit us in onionspace.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 27/08/2026
neilzone.co.uk
On lawyers, ethics, and integrity
I have been reading some of Richard Moorhead’s new book, arising mainly from the UK’s Post Office scandal, “Frail Professionalism? Lawyers’ Ethics after the Post Office and Other Cases”. It is open access, and available as a PDF (linked above), with html available too; I have not found, nor made, an ePub. I focussed on chapter 8, “Routes Back to Proper Professionalism”, to see the author’s recommendations. Mainly, I was reading this through the lens of “what can I, personally, do better”. For anyone reading this who does not know me, it might be worth noting here that my work is predominantly Internet and telecoms law (with a side helping of data protection). My work is fundamentally commercial in nature, whether it is advisory (as a lot of it is) or transactional. Day to day, a lot of it is simply “solving problems”. I don’t litigate or go to court. I don’t prosecute people. I do not get involved in employment disputes. For me, a key part of my toolkit for solving problems entails building enduring, trusted relationships, through being honest, reasonable, practical, and diligent, to be able to collaborate in an open, genuine manner. As a consequence, I place considerable stock in my personal integrity. These things are important to me. So, _of course_ , I like to think that I already act with integrity and with ethics - these traits are important to me - but I would be foolish to think that there nothing I could do to improve, or that I could not reflect usefully and meaningfully on my own approach. This is not a review, far less a critique, of the book and more me just noting parts which I found particularly resonant, and reflecting on my own working life. > What we see in the PO scandal is information being processed based on what is arguable or helpful rather than what is true, fair, and balanced. A culture of ‘can we get away with it?’ is driven by wishful thinking and legitimised by lawyerly zeal. Yes. I think that this is particularly true when someone has determined the conclusion that they wish to reach, and is asking for legal advice to support that pre-determined outcome, irrespective of what a neutral, independent appraisal of the situation might conclude. Conversely, if someone has a goal in mind, but is genuinely open to hearing “there is no appropriate (that’s a tricky word; that needs unpacking) way of doing it, but here are some alternatives”, then that is rather different. > [Lawyers] compete on being commercial, and more business partnerish. Yes, absolutely. For me, “being commercial” means giving my clients practical, sensible advice, consistent with the broader context of whatever the issue might be. It does not mean - to me - being willing to bend rules, or look away, or act unethically because that will maximise revenue, or increase shareholder value, or make a problem go away, and so on. For what it is worth, I think that “being commercial”, in the sense of my definition above, is a desirable trait in a solicitor. People want, and deserve, pragmatic problem solving, at a reasonable price. If “being commercially aware” is being used as a shield for impropriety, then that is indeed problematic. > If a lawyer is asked for an opinion that will foreseeably assist illegality or mislead others they should decline or take reasonable steps to prevent or limit that risk. Yes. I am struggling to see how preparing advice with the intention of misleading someone could be consistent with a professional duty to act with integrity. > Harm to a client’s opponents, for instance, cannot always be avoided, but being required to consider and, if proportionate, mitigate or alleviate harm might reduce some of the unnecessary excess that lawyers engage in. I am not entirely sure what the author is angling at here. It is a short section, almost standing on its own. Could it, for example, condemn the common and (to my mind) unsavoury practice of timing letters, and ensuring deadlines, over holiday periods, to cause maximum inconvenience and stress? Quite possibly, where that is a tactic in itself. Writing friendlier, or at least more neutral, less aggressive letters? Some lawyers trade on aggression. I don’t; that’s just not me. In terms of mitigating harm, if I act for Client A, negotiating a contract with Client B (who is also represented), how far would a duty to “alleviate harm” extend? Would my duty extend to helping Client B achieve the best deal for them, for instance (rather than focussing on my own client’s objectives)? How far would it go into trying to solve someone else’s problems? (Reaching a deal which is in the interests of both parties may well be desirable for all number of reasons, but that is separate to a professional duty.) It is curious that this is formulated adversarially, in terms of a “client’s opponents”. It presupposes litigation or conflict. I wonder to what extent it might apply to, say, advice in developing a computer system, where the system could adversely impact the rights and freedoms of third parties who are not “opponents”. Would it stretch to a professional duty to only advise in the context of designing the least harmful online services, for example. Perhaps not a bad thing, although placing that on the doorstep of solicitors, rather than on the companies developing those services, seems backwards. > Ethical knowledge and practice should of course be a routine and proactive part of competence review for all lawyers I would be all for the regulator producing an annual ethics refresher course - perhaps an hour or so’s reading. That would seem very helpful. > We need to more clearly challenge the claim that lawyers do law but not morality I agree that “this is arguably legal” is a very low standard. Similarly, that what is legal is not the same as what is _right_. I wonder how morality would be judged. Does it depend on a solicitor’s own sense of what is moral, or on some subjective notion of morality? What of the situation in which there are two, perhaps polarised, stances, with groups behind each stance claiming that morality is on their side? I don’t think that I object to the notion of solicitors needing to consider morality, but in terms of how that professional duty should be constructed, that seems to need quite careful thinking. Perhaps it has already been tackled in other jurisdictions.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 25/07/2026
neilzone.co.uk
Driving to London for the first time in years
Today, for the first time in years - probably 20 or so - I drove to London. I didn’t really _want_ to drive to London, and it is daft that it was even a credible option. I’d much prefer to take public transport and, when I go to London for work, I do. Thankfully, there is a reasonable if not brilliant train service from Newbury to Paddington. Time-wise, there was not a massive difference between driving from Newbury to Westfield, and then taking the tube, and taking the train from Newbury and then taking the tube. Not much in it at all, assuming that everything is running correctly. No traffic jams, leaves on the line etc. The difference was in price. There were five of us travelling today - Sandra and me, and a friend with two children. The train fare alone, from the National Rail website, was going to be over £110, including a significant discount for travelling together (the “GroupSave” discount). There might have been a cheaper configuration of tickets, but this is what the National Rail website offered. I am not even sure if this covered the London Underground element or not. Instead, it cost about £10 in electricity for the car, £12 to park at Westfield, and then ~£30 on for the London Underground. So just over £50, plus some wear and tear to the car. And, of course, the initial outlay of buying and maintaining a car. Other than the last few miles to / from Westfield, the journey was easy. It was quiet (especially on the way back, when everyone else had a nap), comfortable, and cool. I still _prefer_ the train, as I do enjoy being able to work or read my book, and when I normally travel for work I take my bike so I don’t need to deal with the underground either. I don’t really want to drive to London, but it certainly made financial sense today.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 13/07/2026
neilzone.co.uk
Stepping down as a school governor
Two and a half years ago, I found a piece of paper in our parcel box, asking if anyone would consider becoming a governor of a local primary school. I ummed and aahed about it, and decided to express an interest. Within a few minutes I had arranged a visit to the school, and within a few days, I was a governor. I did a _lot_ of training, and spent the first 12 or so months trying to work out what on earth was going on. Being a school governor, and in particular understanding school accounting, was unlike anything that I had done before. Being a governor is a lot of responsibility, and it is - or, at least, was for me - a particularly challenging role, given how much a school has to do with so little money, particularly with an increase in the number of children with additional support needs. Frankly, a completely inadequate amount of money. In addition to general governor duties, I took on responsibility for data protection, chaired the policy committee, and helped improve numerous policies and processes, and stepped up whenever the school needed a lawyer-like person. Tonight, that came to an end. One of my many flaws is that I agree to do too much. I _love_ helping people, and I have a pretty useful set of skills and experiences. The outcome is that I put my hand up too much, and thus stretch myself too thinly. Sure, I get to do some fascinating stuff, and work with some lovely people, but it comes at a cost. I’ve had too many days recently where I’ve done more pro bono / volunteering work than I have done paid work. When I found that I was turning down paid work that I actually wanted to do because of volunteering commitments, I decided that I had got the balance wrong. And, in stretching myself too thinly, I don’t always have the time to give a role the time and attention that it needs. Perhaps, sometimes, doing at least some of the job is better than doing none of the job, I was increasingly nervous about taking that approach to being a school governor. Whether I give up any of my other voluntary stuff, I’m not sure. At times, it is certainly tempting. But, if nothing else, giving up governorship should mean I have a little more time to spend on my other commitments, for as long as I have them. I enjoyed my time as a governor. I certainly learned a lot, and I was pleased to be able to make numerous, and in some cases quite significant, contributions to the life of that small primary school.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 09/07/2026
neilzone.co.uk
Holiday reading, mostly from Standard eBooks
Sandra and I have had this week off, and one of the things I wanted to do was to catch up on my reading. All bar one so far has been from Standard eBooks. ## Soldier Spy From Kobo, I enjoyed this account of someone who claims to have worked for MI5 (I’ve no reason to doubt this, but, well, who knows) carrying out operational (i.e. on street / in car) human surveillance. How much is true, how much is hyperbole, I don’t know, but it made for an interesting, often challenging, read. I finished the book - perhaps as the author had intended - with a question mark as to his suitability for the role. ## The Call of the Wild A classic, which I last read many years ago, “The Call of the Wild” is a pretty brutal book about the life of (fictional?) dog in north America during the gold rush. I suspect that there are various parallels with humankind, in terms of the way in which different people treat the dog, and the dog’s move from bored domestic comfort to a wild animal, but frankly - animal abuse aside - it was just a good, fun, and short book. ## The Lost World I have read “Jurassic Park” before (better than the film, IMHO, and I think that the film is superb), but for some reason, I had not read “The Lost World” before. The story is, in essence, about some privileged white men exploring a dinosaur-laden plateau. The frankly appalling treatment by white men of the indigenous population seems to be a theme of the books I’ve been reading this week, perhaps because of the prevalent attitudes of the time in which they were written. If you ever wanted to read “Jurassic Park” in somewhat older English - which, I must admit, I find a joy to read - this is worth a look. ## Allan Quatermain Stories I jumped in at book two of the series - Allan Quatermain Stories - rather than with “King Solomon’s Mines”. I should probably rectify that. The book is, in essence, a series of stories reifying a hunter, Allan Quatermain, and his adventures in “unexplored” Africa. Basically, he shoots a lot of animals, supported by a cast of indigenous servants. ## The Last of the Mohicans My goodness, I found “The Last of the Mohicans” incredibly tedious and long-winded. I should probably stick with it, as I like the sound of the precis, but still, the 20 or so pages that I read were just hard work.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 06/07/2026
neilzone.co.uk
Being excited still about technology in 2026
I found myself wondering the other day whether I was still interested in, let alone excited by, technology. I think that this is partly down to “AI”, and the breathless hyperbole about how it is Going To Change Everything. In my spare time, I’m a lawyer, and there’s a non-stop feed of slop about how all lawyers need to “adopt AI or be left behind”, and I’m finding this kind of nonsense draining. The ongoing regulatory narratives, particularly around identity verification simply to go online, are as exhausting as they are unnecessary. So it is little surprise that I am feeling a bit glum. I suspect that many people are. But anyway. The positives. _Yes_ , I am still excited by some technologies. ## Solar power I jumped up and down a bit when, for the first time, we were running our home from a battery charged by the sun. I’m not a solar nerd, but I am certainly optimistic about the potential for making better use of solar power. I do want to see more being done to ensure that _everyone_ can get the benefit of solar power, not just people who can afford their own homes and to pay for panels to be installed, and I am hopeful that plug-in solar / balcony solar will have a role here. But as panels become more effective, and if we can find better, cheaper ways of storing the energy that we generate, happy days. I love it that I can charge my electric bike from the sun, for instance. That’s just _cool_. ## Small, low power, computers, and self hosting It still makes me smile that my entire online presence is thanks to a few small computers, running at home. I am sure that “the cloud” is great for some things, but for me, I get a kind of joy from hosting my websites - work and personal - on a tiny Raspberry Pi, sipping tiny amounts of power. I am - as I said at the beginning - concerned about the impact of various regulations around the world on people trying to host their own services, but for now, none is hitting me, personally, too hard. Sure, the fact that the price of all computers - including small computers - has increased because of unnecessary pressures on chip fabrication, and market forces, is unwelcome. But hopefully this too will pass. ## Cooperative / small community hosting While _I_ like self-hosting stuff, self-hosting is not for everyone. I am excited for the future - or resurgence, I am not sure - of “community hosting”: groups of people working together to host their infrastructure and services, for the benefit of small groups. Not everyone has the skills, time, or money to self-host - the _privilege_ - to self-host, yet nor should everyone be driven towards commercial, privacy-intrusive, options for lack of a better choice. Community or cooperative hosting has a role to play here, I think, and I love it when I see a new co-op announcing itself in the fediverse. Of course, we need to ensure that people who are without that kind of friendship group are not left out. I don’t have particular thoughts about how to do that though. ## Linux on mobile I’ve enjoyed experimenting with postmarketOS and Ubuntu Touch recently. Even using GrapheneOS, I am not sure that I see a future for Android for me, and I don’t want to use iOS. I also think that we need more than two operating systems for mobile devices. It would also be _amazing_ if we could do something more to tackle the growing pile of ewaste, bringing life back (for various tasks; not everything will be suited as a primary computing device) to older, but still capable, mobile hardware. I’m not under any misapprehensions about large companies trying to persuade people that they must have the latest and greatest phone, sadly. But I do like the idea of using a device which has broken free of the more mainstream OS, running a Free operating system. postmarketOS looks like the most likely contender for me. I know that SailfishOS is appealing to some, but the inclusion of non-Free software in SailfishOS likely means that it is not for me. ## And more I am sure that, if I took the time to think about it, that this list would be even longer. But, for me, this has served its purpose: I have not stopped enjoying technology, I can needed to re-ground myself a bit, looking beyond the hype and nonsense of some of the current sales cycles.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 04/07/2026
neilzone.co.uk
Chatting to a friend who has bought a pair of Meta AI glasses
I’ll be honest, I was a bit surprised that I knew anyone who would buy a pair of Meta AI glasses. Sure, they are readily available, and presumably heavily advertised, but most of the people with whom I spend time - online or offline - are not the kind of people who would buy them. I’ve got friends who use Facebook. I’ve got friends who use WhatsApp. But the glasses just - to me, anyway - feel rather different. Nevertheless, a friend _did_ buy a pair, and was happy to chat about them. My friend - like me - is a married, middle-aged, white man. Unlike me, he saw the glasses in our local optician’s, and wanted them. We didn’t chat for long, and, to be clear, I was _kind_ , not accusatory. And yes, he wore the glasses throughout our chat. * No, it did not worry him that using the glasses entailed sharing lots of data with Meta, or that this would entail sharing the personal data of other people * Yes, he thought that they were rather cool, and that, it seems, was the main selling point. He didn’t _need_ them for anything, he just _fancied_ them * No, he hadn’t really thought about whether other people might want to be filmed, or whether people might be worried about being filmed * Yes, he had seen other people talking about them online, and they were talking positively about them. He hadn’t seen any negative commentary / criticism * Yes, he uses “AI”, and rather likes it It was an interesting conversation, because it was so unexpected. His choices would not have been mine, for sure.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 26/06/2026
neilzone.co.uk
Restoring missing Address Book in Thunderbird 140 menu bar
For some reason, the Address Book tab/pane on Thunderbird’s menu bar had gone missing, and I struggled to find out how to get it back. So, for future me, what resolved it was: `Ctrl + Shift + b`
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 20/06/2026
neilzone.co.uk
Pondering routing more of my traffic via nodes outside the UK because of the direction of UK online safety policy
Some of the UK government’s policy announcements around the Internet - and, in particular, social media and VPNs - are downright concerning me at the moment. In the name of “online safety”, the fundamental rights of both freedom of expression and privacy appear to be under imminent threat. I have concerns which go beyond our shores - mostly stemming from Google, frankly - but the UK legislative / policy issues are bothering me especially at the moment. I value my ability to read, learn, and communicate almost without borders. I don’t like signing up to websites or newsletters (I prefer RSS), I don’t like storing my data on other people’s computers, and I’ve certainly no wish to prove my age or identity outside core government services. The current proposal to ban people under 16 - who also have the rights to freedom of expression and privacy - from some (as yet not fully delineated) social media services is likely to result in wide-spread verification. While I am unlikely to be affected directly - although it would depend on the definition of “social media” - I anticipate that more websites will simply choose to block traffic from UK IP addresses, especially if UK-originated traffic does not matter a huge amount to them. I am already seeing this as a consequence of the Online Safety Act, and I expect any future UK laws in this area to exacerbate that. I also anticipate that we will soon see the first court-ordered blocking injunctions under the Online Safety Act, when the fines issued by Ofcom against some website providers (so far, most quite niche porn sites, as far as I can tell, plus a “suicide discussion forum”) go unpaid and the “compliance issues” which Ofcom has identified go unresolved. Some - many - UK ISPs have already implemented, and carry out, DNS blocking, both for mandatory and non-mandatory reasons. Mine - A&A - is probably one of the outliers, with no blocking save for the mandatory sanctions-related requirements. In any case, so far, since I run my own recursive DNS infrastructure, I have not been affected. I use Tor quite a lot, but I’ve seen an increase - sure, a small increase, but an increase nevertheless - of sites which are blocking Tor traffic. And so, for the first time, I am considering locating something (perhaps a WireGuard node, or a SOCKS proxy, or a recursive DNS server / DNS proxy, or perhaps all of them) somewhere on the Internet outside the UK, so that I can route some traffic through that, as needed, to maintain my access to the web. Honestly, it seems such a shame to me, that UK Internet censorship should reach such a place, but there we go. I have not decided exactly what I might do, or exactly how, or where, I might do it, but it is far more attractive to me now that it has been ever before, in all the 30ish years that I’ve been online. To me, the need to even contemplate this kind of thing is the stuff of dystopian sci-fi. And yet here I find myself.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 17/06/2026
neilzone.co.uk
Dark Division's CQB (close quarters battle) training
A while ago, I heard that a friend of a friend was running a close quarters battle training course, at an Airsoft site not far from me (Ironsight, in Andover). So I schedule a rare mid-week day off, and signed up. That day was today :) Honestly, I was a bit nervous going into the day. Would I know anyone? Would everyone be fitter than I am? Or just better at it? It turned out that I knew, or at least recognised, at least half of the attendees. That made it easier to chat to some of the others too - and they were all a friendly bunch. Everyone was very supportive, cheering each other on and - especially - offering reassurance and kindness when people screwed up. And we _all_ screwed up at some point, given how much there was to think about at any one time. Since a lot of the day was about team work, and communicating effectively, that kind of camaraderie was great. It also turned out that my fitness, while obviously something that I could improve, was more than good enough, and that I am confident and accurate shot. So that was nice. The training itself was superb. We had two friendly, knowledgeable instructors, who were able to share their knowledge and experience effectively and with humour. If someone needed a bit of extra help, they got it, and it was all very positive. It was very practical / hands-on, to get as much time as possible to turn basic theory into practice. Having never done this before, I would certainly benefit from some more practice, to reinforce what I learned today. We covered a lot of stuff, focussing on how to clear rooms (which may or may not have hostile people in them) quickly and safely (well, safe-ish). Different techniques for different types of room, rooms with and without doors and doors opening in different directions, rooms with obstacles in them, and for corridors. We also did various shooting drills, focussing on arcs of fire (to avoid hitting other team members) and on ensuring that we put enough rounds into the targets to count them as “down”. We finished the day with explosives, and how to plant them to breach a closed door, and then follow up into the room. I am _very_ glad that I had my ear protection with me for this, as they were incredibly loud at close range. Overall, it was a superb day, and I would happily sign up to do another of them soon. Whether I can count this training as part of my continuing professional development, I’m less convinced. “Conflict resolution”, perhaps.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 16/06/2026
neilzone.co.uk
Speeding up static site generation with BSSG
Three months ago, I moved from hugo to BSSG for this blog (and my work blog). You can get BSSG here. I’ve been really happy with BSSG, and a couple of recent changes by Stefano have made it even better. ## Less content, less to generate I have a minimalist blog. A list of posts on the front page, and generally text-only posts. I like it to load _fast_ even though it is running on a Raspberry Pi 4, along with a couple of other bits. This means that there are some features of BSSG that I do not use, including descriptions of blogposts. I use the title for that, on the basis that this should be informative in itself. It suits me, anyway. There are also some other UI elements that I do not need, such as reading time. I bodged my way around these, using CSS rules to hide the unwanted content from display. I could have changed the code to neither generate nor display them, but I didn’t really want to run, and need to maintain, my own branch. With the recent changes, Stefano added some new config options: SHOW_HEADER_MENU=false # Set false to remove nav menu from header SHOW_INDEX_DESCRIPTIONS=false # Set false to hide descriptions/excerpts on index GENERATE_EXCERPT=false # Set false to skip auto-generating excerpts SHOW_READING_TIME=false # Set false to hide reading time on posts These are set to “true” by default - to preserve the experience for people who already use BSSG and expect these things, which makes sense to me - but now I can set them to “false”, and have an even slicker, faster experience. ## Incremental updates The second brilliant change is about the way the scripts handle incremental updates. The idea being that, rather than building every post, every time, it will just build the new posts. I struggled to get this to work initially, as it was building all posts, every time. This turned out to be entirely down to me: my build script, which I use to control building and deploying both the cleartext and .onion versions of the blogs, cleared the output directory each time. I removed that, and bingo, incremental updates! This combination of things meant that building each site went from ~10 minutes (which was a bit painful) to ~1 minute (which is fine!). Happy days.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 03/06/2026
neilzone.co.uk
Why are there no good tablets at the moment?
A friend was looking for a new tablet, and they asked me for a recommendation. And… I just don’t have one. The only good tablet, because Android can be replaced with GrapheneOS, was the Google Pixel Tablet, and that is no longer available. Secondhand prices are sky high. That was my go-to recommendation for a while. But it looks like Google has abandoned this project too. Amazon’s range of FireOS tablets are, IMHO, bloated with crapware which one cannot easily remove. Even the Fire-Tools scripts only get one so far. I can’t recommend one. There are some fun-looking “tablet computers”, but they are all expensive. A secondhand Surface Go, if one wants a Linux-based tablet, is readily available and pretty cheap, but honestly not what most people will want. And, while I like it as a cheap, touchscreen, Linux machine, it is not particularly powerful, which can be frustrating. And getting the camera working is a nuisance. I guess that there are some iPads, if one is accepting of Apple / iOS. Again, that wouldn’t be my choice, but I can see why some people like them. Why is there no good (non-Apple) tablet at the moment?
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 12/05/2026
neilzone.co.uk
Fixing a proxying problem with my HomeAssistantOS installation by replacing nginx proxy manager
tl;dr: I removed the “nginx proxy manager” add-on, and replaced it with the Let’s Encrypt add-on and (second) the nginx add-on. A couple of months ago, I moved my HomeAssistant installation to HAos. I think that it is fair to say that I was not overly pleased with this. Honestly, I preferred the “Core” python-venv approach, but I also wanted a “supported” installation, and so I switched to HAos. i got it up and running okay, and I thought that I had got proxying working too, using an add-on called “nginx proxy manager”. This is not something that I had used before; I’d rather just configure nginx myself. Well, either I got something wrong, or it just does not work very well, as I kept having problems using HomeAssistant, stuck on a “loading data” screen, or it simply not responding. This bugged me for quite a while. Annoyingly, the logs available to me within HAos were unhelpful. I couldn’t spot anything indicating a problem. Using the console in my web browser, I noted that some files were not loading correctly, but _why_ that was the case, I wasn’t sure. I thought that I’d had a similar issue with my “Core” installation years ago, which I got down to the issue of the `trusted_proxies` in the `configuration.yaml` file, but that looked correct here (which I was able to check, using the SSH add-on. I tried various parameters in the nginx proxy manager add-on, but to no avail. In the end, I tried removing the nginx proxy manager add-on, and replacing it with the Let’s Encrypt add-on (which I installed, configured, and ran first), and then the nginx add-on. And it immediately started working correctly. So I don’t know exactly why my original set-up was not working, but at least it is working better now.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 29/04/2026
neilzone.co.uk
Please consider publishing a full-text RSS feed for your website or blog
I have used RSS (“Really Simple Syndication”) as my default web browser (for some stuff) for ages now. Ages as in “20+ years”. It seems to be enjoying a bit of a resurgence, and I am delighted. ## What is RSS RSS is a way of publishing web content in a machine-readable format. When you publish a blogpost, as well as the new blogpost showing on your site, it is also added to a file, often call index.xml or feed.xml or similar. I publish RSS feeds for my personal blog and the decoded.legal blog. Your loyal, eager readers “subscribe” to your RSS feed, but that just means add the link to that RSS file to their RSS reader or aggregator. I use FreshRSS as my RSS aggregator (the thing which collects all the RSS feeds), and then Readrops on Android and newsboat (I wrote about newsboat) on Linux to read the feeds. You can see a list of blogs that I follow via RSS. A reader’s aggregator or reader periodically downloads the RSS .xml file from each of the sites, and, if there’s an update (because of a new blogpost, most commonly), shows the new blogpost(s) to the reader. They might even have set up a tool like Calibre - an ebook management tool - to download your feed and convert it into a file that they can enjoy on their ereader. It is a wonderful way for a reader to create their own personalised reading list of their favourite authors, making sure that they never miss a post. For authors, it is an easy, free way of making their works available, under their own control, without the hassle or cost of running an email subscription service. ## Full-text RSS ftw! One can make available either (or both) an RSS feed containing snippets of posts (e.g. a headline, perhaps an initial paragraph or sentence, and a link to the website), or the full text of posts (as well as a link). Please, consider making a full-text feed available! This is probably as simple as adjusting a config setting in WordPress, or whatever else you use for your blog. By doing so, you give your readers an easy way of enjoying what you write, without you incurring any extra cost, and lessening the risk of them missing one of your posts. It is not the end of the world if you do not or cannot do it - I’ve written before about using CSS selectors in FreshRSS to get full-text content for a snippet-only feed - but, by giving them full text, they do not have to faff around with this. It is also advantageous from an accessibility point of view, as your reader can set up their RSS reader however best works for them, be that a different font, or large font sizing, or just a distraction-free environment, and they still get to enjoy what you write. If you care about analytics / readership (and I am not one of those people; I’ve no idea how many people read this), then offering an RSS feed might skew these. But if it is skewing it by a statistically significant amount, this just means that lots of people are enjoying what you write! (And I’d have thought that bots were already skewing your stats, but that’s another topic…) Your own writing, on your own server, just made available to your own readers in a convenient, free of charge way. What’s not to like!
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 18/04/2026
neilzone.co.uk
Just let me compute in peace
## Computing can be so _noisy_ these days No, I don’t want to sign up to your newsletter. No, I don’t want to create an account to read your site. (Well, I will for paid subscriptions, I guess.) No, I’m not going to create an account on your system to use my computer, or configure a router. I have a local account on the machine, and that’s just fine. No, I don’t want your app. You have a website. And yes, if you pretend that I can only do something via your app because I’m on a mobile browser, _of course_ I’ll switch to desktop mode. No, I’m not installing your “app” to configure this hardware. It is a sodding kettle. I’ll press the button when I want hot water. No, your tracking will not make my experience better. What would make my “experience” better is if you had not interrupted my “experience” in the first place with your weasel-y worded, bad faith compliance, annoyance of an overlay which probably does nothing anyway. No, I am not going to “consent or pay”. No, I don’t want to hear from your sponsor. No, I don’t want to use your Discord “server”. That’s not documentation. No, I don’t want to see “promoted” content. Just show me stuff in chronological order. No, that’s not a “newsletter”, that’s marketing. No, I don’t want your newsletter anyway. No, I don’t want adverts. (Although, personally, I can absolutely live with FOSS developers including occasional prompts for support. So I’ve got double standards. Oh well.) No, I am not going to disable my ad blocker. No, I am not going to verify my identity or age. No, I don’t want your chatbot. If I can’t find what I want on your website, you’ve screwed up. No, I don’t care what “Dave (48), Alabama” had to say about this. (Thanks, “Shut Up” comments blocker extension!) No, I am not giving you free labour to determine if that blurry image contains a car. No, I don’t want the upsell. No, I don’t want your survey. No, I don’t want a reminder that there’s something left in a basket. I know. I put it there. No, I don’t want to rate your product, let alone your choice of courier. You took my money, now sod off and leave me alone. ## Computing can be so _noisy_ these days, but it need not be so. If you make Free software which I can install via apt or F-Droid and just use, thank you. If you make a full-text RSS feed available for your site, thank you. If you make your site a pleasure to read in a text-only browser, thank you.
002
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 14/04/2026
neilzone.co.uk
Resources to aid understanding someone else's perimenopause / menopause
I asked for reading recommendations, for a _partner_ of someone who is going through the perimenopause / menopause. I got a lot of responses; thank you. I have included below those which seemed most relevant, for me to follow up on them. Apologies if I didn’t include your particular suggestions. I received quite a lot of advice too; thank you. ## Reading suggestions ### Books * “Burning Up, Frozen Out” by Joe Warner and Rob Kemp * “Menopause Manifesto” by Dr Jen Gunter (several recommendations for this) * “Perimenopause Power” by Maisie Hill * “Woman on Fire” by Sheila de Liz (multiple recommendations) * anything by Dr Louise Newsome ### Blogs and microblogs * Trans experience of the menopause by Quinn Rhodes * Two posts by Sundial: “Perimenopause hit me like a brick” and “Perimenopause: My HRT Journey” * “Nobody told me about the way menopause restructures marriage. Here’s what I wish I knew then.” * Ben’s toots Thayer said: > I often help men understand their partners’ journeys as part of my therapy & coaching as it really affects men as well ## Podcasts * “Body of Evidence”, including this episode * “What’s Up Docs?”, including this episode ## Videos * “BDSM and the menopause” * a Davina McCall documentatary (possibly this one)
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 08/04/2026
neilzone.co.uk
Thoughts on increasing ssh security using a hardware security key
I have been using hardware security keys (including YubiKeys and Titan keys) for FIDO2 and TOTP for a while, but not for ssh. At the moment, I harden the ssh config on my servers, lock down access by IP address, and use password-protected certificates for authentication, blocking password-based authentication. So I think that I do at least reasonably well as it is. But I was interested to see if I could introduce a further aspect of security for ssh, using a security key. My security keys support the generation of both resident and non-resident keys. Resident keys are stored on a slot on the YubiKey, while non-resident keys are stored on the client computer, but require the YubiKey. I picked non-resident. I set a passphrase as part of the ssh-keygen process, so, when it comes to using that key, I need to enter that passphrase _and_ insert and touch the security key. So now someone would need: * to be connected to the correct network * to have a copy of my private key * to know the passphrase for that private key * to have one of my security keys (my main security key, and my backup security key) I can, I think, add a PIN to the YubiKey but, to date, I have not done this. Perhaps I should. Honestly, I was probably fine without this, but, well, I had the security keys, so why not. But, while this works fine from my laptop, I can’t get it to work on my phone (GrapheneOS). At the moment, I use Termux, and from there, I can ssh in to my servers. But I can’t get Termux to use my _*_-sk keypair. There is a six year old issue in the Termux Github repo which indicates that it might, some point, be coming, and that would be welcome. Apparently it can be done using a closed source tool, but since I’m only looking to use FOSS, that’s not on the cards for me. So that is a bit of a pain, as it is convenient to be able to log in from my phone from time to time.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 07/04/2026
neilzone.co.uk
Sex and the Fedi
Over the weekend, Girl on the Net - an esteemed sex blogger who, incidentally, happens to be one of the smartest, strongest, and downright loveliest people that I know - tooted: > If you ever get sick of me banging on about my life and think ‘ugh I wish she would stick to the porn’ then please know: hardly anyone ever boosts the … porn. And this made me think. I had an engaging conversation with numerous people about it, and I still don’t have good answers, but I enjoyed the discussion and wanted to keep a note of it. This is that note. ## More sex, fewer boosts I follow and chat with quite a lot of sex positive / sex work-related people in the fediverse, and many have expressed similar sentiments. They create, they share, they get “likes” - and, of course, ample criticism - but very few boosts / shares. It must be _incredibly_ demoralising. (I am in a different position in that I neither know nor care how many views my blogposts get.) It made me ponder _why_ people do not share sex-related content, when sex is clearly part of life for many (but not all) people. ## Why? My thoughts were: * stigma about sex as pleasure. It’s fine to have sex, but not to talk about it. One of Girl on the Net’s regular themes is about communication, and simply asking questions (not just about sex, but also including about sex and one’s preferences and horizons). But I imagine that, for some, talking about sex is uncomfortable, including sharing other people talking about sex. * concerns relating to professional expectations and obligations. I fall into this category. I am sex positive, but I do not know where the Solicitors Regulation Authority would draw the line, and I don’t wish to be even close to where that line might be. So I play it safe, even though there is stuff that I would like to post or share. But, oh well, self-censorship ftw. Sometimes, I would love not to be “me” online. * being embarrassed about what others here might think. Similar, but different, to the points above. This is about other fedizens, who might be co-workers, employers, family members, or whatever. * sex as being in the sphere of one’s private life. * older people, perhaps especially men, being self-aware of engaging with younger adults posting sex-related stuff, and coming across as creepy. I _completely_ get this, and I am somewhat paranoid about it myself. Several people responded to say that, yes, they felt like this. They might _want_ to engage with public content (and I’m not talking about responding lasciviously, or sending dick pics), but do not want to be perceived as being inappropriate. I received some thought-provoking feedback too: * women and non-binary people said that they felt unsafe boosting or posting sex-related content, because of reactions from men hitting on them. That, by posting about sex, some men took it as an unwelcome opportunity to solicit sex with them. * some people not wanting to boost as they feel that they don’t have enough followers to make it worthwhile. And, in terms of increasing the distribution of a toot, yes, that makes sense. It probably still sends a nice endorphin boost to the poster though, that someone likes their work enough to want to boost it :) Where someone has a popular “main” account, and a less popular “alt” account, but would only be willing/able to post sex-related stuff via that alt, this perhaps comes into play. * just not liking the stuff enough to boost it. Fair enough! * concerns over whether their server rules allow boosting of this kind of content, and not wanting to get blocked / banned. I can understand each of these, and why they might lead to a “like” rather than a “boost”. None of them inhibit paying or tipping someone, as a thank you for their work though, which is another way of being supportive. ## An increasingly difficult climate for sex workers and sex-related creators But this also comes against a backdrop of increasing difficulties for sex workers and other people post sex-related stuff. Payment processors denying income streams. Platform operators enforcing their ever more restrictive morality rules, making working harder, and requiring more admin just to keep going. If people take, take, take, without giving back in some meaningful way, then that is challenging even for those who create and share for fun (for appreciation, perhaps, rather than tooting into the void), let alone those for whom this is their livelihood. I wish that I had better answers than I do.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 30/03/2026
neilzone.co.uk
Three months of not reading the news
Three months ago, I stopped reading the news. I made a note to force myself to reflect on it, after three months, and this is that reflection. ## This is about general news / news sites I still read lots of RSS feeds of people’s blogs. I _love_ this. I still read industry-specific news sites (mainly law-related stuff), and other sources of information which are often the basis of news coverage (e.g. government or regulator press releases and updates). I still read local news, but _wow_ is that a rubbish experience. I get that local news needs funding to survive, but making the product so unappetising makes selling me a subscription a very hard sell indeed. Frankly, I could probably just not read the local news and keep an eye on the local council’s roadworks website instead. I still have my 404Media subscription although, to be honest, I am a bit on the fence about it. I am not sure if I will renew it or not at this point. No slight to the quality of their journalism. What I have basically stopped doing is reading the BBC, the FT, the Guardian etc. ## It took a while for me to adjust I had not appreciated just how conditioned I was to reading the news when I had a spare moment. It took me quite a while to get used to the idea of not opening the BBC website, in particular. I did not go to the extent of blocking news sites, so this was just based on self-control / choosing not to do it. Curiously, what I found hard was that almost instinctive “fingers move to open a news site” behaviour, rather than actually missing reading the news. I had to train myself out of it, and now, it doesn’t cross my mind. ## I still see some general news, just less of it I have not managed to avoid general news entirely, nor was I really intended to do so. This was about _lessening_ my exposure, rather than doing all that I can to avoid it. I still see people posting news-related stories in the fediverse, and I just scroll on by. In some cases, I can filter by keywords, and so no If someone posts news too much (or, in particular, posts party political stuff), I either unfollow them or mute them. I’ve no temptation to click the links. ## Am I less informed? Yes, and that is by design! Before, I was informed about a whole load of things, in a way, and to an extent, that I didn’t find helpful or healthy. Now, I am aware, in broad terms, of major stuff going on around the world, but I am far less familiar with the minutiae, or the endless “up to the minute” reporting. That feels like a good level of awareness for me. I am also far less exposed to stuff that I never cared about in the first place, especially “celebrity” news, of which I remain blissfully ignorant, sport, and so on. To each, their own. ## I don’t miss reading the news at all For now, anyway, I don’t miss reading the news. At all. I’ve overcome that reflex of opening a news site. I have not - as far as I know, anyway, which I appreciate is quite a caveat - missed anything which, had I known about it, would have made a significant difference to anything important. I read far more books (and buying the tiny, pocketable, X4 ereader was an attempt to distract me from my phone more often, letting me read even more). So I am going to carry on with this experiment for now, and see how I get on. I can’t _prove_ that this experiment has been good for my mental health, but it certainly feels that way. ## Perhaps a monthly summary of “important” stories would be nice? Even though I do not want to read the news, I wonder if a monthly, edited, one-or-two page kind of approach, of key / important news stories, might be welcome. Of course, there would be complexity in determining what is “key” or “important”, as that is subjective.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 28/03/2026
neilzone.co.uk
Implementing the somewhat whimsical human.json protocol on my website
Terence blogged about adding a human.json file to his website. I wanted to do the same. The specification for human.json describes itself as > a lightweight protocol for humans to assert authorship of their site content and vouch for the humanity of others. It uses URL ownership as identity, and trust propagates through a crawlable web of vouches between sites. A bit like signing each other’s PGP keys, really. There are a few steps: * add a json file to your webserver, with some basic information * update that file when you “vouch” for someone else’s site, as being created by a human and free of AI * added some header material to your website, to reference the source of your human.json file * set a couple of web server headers (below) * use a browser extension to surface that file on other people’s websites if they have implemented human.json ## bash to update the list I made a simple bash script to simplify the process of creating the json to vouch for someone: #!/bin/bash set -euxo pipefail FILE=/home/neil/neilzone_bssg/static/human/human.json URL="$1" SANITISEDURL="$(echo "$URL" | sed 's/\//\\\//g')" VOUCHEDDATE="$(date -I)" COMMAND=".vouches += [{ \"url\": \"$SANITISEDURL\", \"vouched_at\": \"$VOUCHEDDATE\", }]" jq "$COMMAND" "$FILE" > temp.json && mv temp.json "$FILE" cp -r /home/neil/neilzone_bssg/static/human /var/www/neilzone.co.uk/public_html/ I am sure that there are better ways of doing this, but it works for me. ## Headers I am using a separate directory for this json file, as it wants specific headers. I am using apache, so in the `.htaccess` file in `human`, I have: header set Access-Control-Allow-Origin "*" header set Content-Type "application/json" ## Browser extension Using the Firefox browser extension, which is probably available for other browsers too, I can see if a site offers human.json file, or is vouched for by another person whose own human.json file I have already trusts. ## Thoughts Will it catch on? I doubt it. It is a bit of whimsy, and that is no bad thing. I have only included URLs where the site owner has consented for me to do so. If you are such a person and wish me to remove the “vouch” from my site, then please do just let me know. Consent is sexy. Because I am low-key “vouching” for people, I’ve only vouched for people that I know, even for a relatively limited definition of “know”. Not strangers, but not limited to the most intimate of relationships either. Mostly fedi friends, which is nice. Is it _bad_? I don’t think so. I have seen a couple of comments about it being a useful thing for AI scrapers to follow, but frankly they seem to be doing just fine anyway. If signalling to fellow humans also attracts unwanted traffic well, in this case, so be it.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 27/03/2026
neilzone.co.uk
I am a cis man
A friend asked: > Have you thought about your gender? What it would be like to not be your current gender? ## Until 2017, no Until 2017, no, I had not thought about my gender. This might not be quite the turn of words that I want here, but I had no _reason_ to think about my gender. I grew up as a boy, and I never disliked, or doubted, that I was a boy. As I turned into a man, it never crossed my mind that I was _not_ a man. I never had any reason or motivation - internal or otherwise - to think about it. I have had no sense of gender dysphoria, or not feeling comfortable in my own body shape / appearance, and such like. So what changed in 2017? ## “Queer Privacy” What changed was a book. Sarah Jamie Lewis’s edited book, “Queer Privacy”, was eye opening for me. Not only was it thoroughly fascinating, from the perspective of privacy, it showed my ignorance: I did not know what some of the terms meant. So I think that it was 2017 when I learned that I was “cis”, in the sense of learning that there is a term which described what I was: someone whose gender identity matches their assigned sex at birth. When I joined the fediverse, and started spending more time there from 2018 onwards, I got to rub virtual shoulders with a whole load of amazing people, with all sorts of gender identities and no gender identities. This was a new experience for me. I’d grown up with gay friends, but not, as far as I know (appreciating that gender identity is about what someone is, rather than how someone looks etc.) any trans, non-binary, or agender friends. ## Thinking about my own gender identity Over the last few years, yes, I do occasionally think about my own gender identity, generally stimulated by conversations on the fediverse with others. And, so far at least, the conclusion has always been the same: I am a cis man. It might be _interesting_ to experience being something other than a cis man, but I have no longing to be so, or a feeling that, actually, that is me.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 25/03/2026
neilzone.co.uk
Initial thoughts on the tiny XTEINK X4 ereader
What fits nicely in my hand and gives me hours of pleasure? A tiny ereader! I - like, it seems, quite a lot of people - bought an XTEINK X4 ereader. I bought an X4 because I love reading, and I was drawn to the idea of having a tiny ereader in my pocket. Instead of reaching for my phone, I hope that I will instead reach for the ereader, and enjoy some more reading. I am in the _very_ privileged position on having the X4 as an extra / secondary ereader, which perhaps colours my view of the device, in the sense of being willing to put up with more of its quirks than if it were my only ereader. (Since someone asked me about it, perhaps because of some of the marketing photos: this is a standalone ereader. Yes, one needs to transfer books to it (see below), but it is not tied to a phone / does not require a phone to function. One can attach it, magnetically, to the back of a phone, for reasons which are not entirely obvious to me.) ## Installing CrossPoint, a Free alternative firmware I had no plans to use the stock firmware, and used it only so far as to change the language to English before flashing the Free software alternative firmware, CrossPoint. (There are other firmwares for the device; I chose CrossPoint.) I did, however, note that the stock firmware does not require a user account / registration or anything like that, which I appreciated. I flashed CrossPoint using the tool at [https://xteink.dve.al]. When I tried to backup the existing firmware, I got an error of `Failed to execute 'open' on 'SerialPort': Failed to open serial port."` I ran `setfacl -m u:neil:rw /dev/ttyACM0`, to give my user the right permissions. With that done, I could dump the existing flash (which did indeed take about 25 minutes). I had the same error when flashing the CrossPoint firmware, so I ran `setfacl -m u:neil:rw /dev/ttyACM0` again, and it worked again. Once I had reset the device - hold the small button at the bottom on the right edge of the X4 for a second, then press-and-hold-for-a-few-seconds the power button at the top on the right edge of the X4 - it booted into CrossPoint _very_ quickly. ## Installing the screen protector The device comes with a screen protector. This is an excellent idea. It would have been even better if this has been installed in the factory, but never mind. ## Case I bought a cheap (£4) clear plastic shell, to protect the back of it. It add a bit of bulk to the device, but I’d like to protect it. ## Swapping the supplied microSD card I replaced the included 16GB (the manual says that it comes with a 32GB card…) XTEINK-branded microSD card as soon as I received the device, with a 128GB SanDisk card. This was mostly down to force of habit, as it would not be a particular problem for me if the microSD card in the device died. Annoying, for sure, but I could just pop in a new card and reload all my books from Calibre. The card slot is recessed, so pressing it to remove it, and to get it back in place, was quite tricky with short fingernails. This, it turns out, is a bit of a pain. ## Loading books via Calibre I use Calibre for managing my ebook library. For my other ereaders, I load books via a cable. Somewhat annoyingly, the X4 and its microSD card do not mount as a USB-writable device. The options are Wi-Fi-based, or else remove the microSD card. I have gone with the microSD card approach, despite it being a bit of a pain. In Calibre, I used the “Save to disk” / “Save only the EPUB format to disk in a single folder” option. This did - as expected - dump 500+ ebooks into a single directory, which is not ideal on the X4 with CrossPoint, given that they appear as a list, with no way to search. Press-and-hold on the side buttons does jump between full screens though (a bit like Page Up / Page Down), so it is not terrible. Perhaps I need to treat the X4 less like a portable library, and just move onto it a small number of books that I want to have so readily available. CrossPoint seems to struggle with books with a special character (e.g. “$”) in the title; I have yet to dig into this though. ## Wi-Fi I have not tried to connect it to Wi-Fi; I have no need for this. I have not found a way to turn off Wi-Fi, which is a bit annoying, as I don’t need to be on all the time, both in terms of battery life and privacy. ## The reading experience The reading experience is… good. Neither terrible nor amazing. What makes it good is that it is pocketable and there when I want it. The 4.3” screen is, apparently, 220 PPI. It is not as crisp/sharp as the screen on my Kobo or Tolino. A backlight would be wonderful, but I knew that it did not have one when I bought it. CrossPoint does not (currently, anyway) support dark mode - light text on a black background. I prefer dark mode when reading, but I can easily live without it on this device. There is a pull request to add dark mode to CrossPoint, but I note: > Did you use AI tools to help write this code? YES _sigh_ The X4 can fit a surprisingly large amount of text on the small screen. But, nevertheless, it means pressing the “next page” button a lot. The buttons on the front are bit “clicky”, but fortunately the buttons on the side are much quieter / softer. I imagine that, if I was using the front buttons to turn the page, and I was sitting next to my wife at the time, she would find it _very_ annoying. I would. Note that the two buttons on the front are, in fact, four buttons; each button is a bit like a rocker switch, I guess, with different actions for the left and right sides. I should have worked that out sooner (or read the manual)… I am quite content with the lack of a touch screen; I much prefer pressing a button to turn a page than mimicking a “swipe” action, as I don’t have to move my hand or hold the device awkwardly. It has 128 megabytes of RAM, which both feels like loads, and not much at all, at the same time. Books load more than fast enough, and page turns are rapid. ## Battery life / charging It has a 650mAh battery, and although my initial experience has been fine, I wonder just how long this is going to last with Wi-Fi on the whole time (needlessly). But the X4 charges via USB-C, which is excellent, as it means that I don’t need to carry yet another cable.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 20/03/2026
neilzone.co.uk
Moving (for now?) from HomeAssistant in Python venvs to HomeAssistantOS
I have used HomeAssistant for _years_. So many years, that I do not remember how many. Nothing I do with it is particularly fancy, but things like having my office lights turn on when I open the door if the light is below a certain luminosity, or turning off my Brompton bike charger once it has finished charging, are fun and convenient. We also have solar panels and a battery now, so I will be interested to see if I use HomeAssistant more for that. But anyway. I have been using HomeAssistant, on a Raspberry Pi 4, using Python venvs for years. It has worked absolutely fine for me, and I have (or, at least, had) no compelling reason to change. For me, this was the ideal setup, in that I could set the Pi up how I wanted, in terms of security and monitoring, and just run HomeAssistant on it. Updating HomeAssistant was as easy as running a simple bash script. I liked it. But… that approach is no longer supported, and, where possible, I prefer to use _supported_ means of running software. That means either running HomeAssistantOS, or else using a containerised instance of HomeAssistant. While I could probably find my way through setting up a HomeAssistant container via podman, it would not be my preference, so I decided to give HomeAssistantOS a go, albeit with some trepidation. ## Installing HAOS was easy enough As expected, it was easy to install HAOS: write the image to a microSD card, and pop it into the Pi. I already had the switch port set up to the right VLAN, so I plugged in the Pi and waited a few minutes. I had anticipated that it would offer https, via a self-signed certificate, so I was a bit baffled to get a TLS error when I connected to it. “Never mind”, I thought. “I’ll just ssh into it and sort it out.” But no, no ssh either. Fortunately, I discovered quite quickly that, out of the box, it does not offer TLS, and I was able to access the web interface. ## Restoring from my HA Core backup worked I had taken a backup from my existing HomeAssistant installation, and I used the web interface on the new installation to restore it. It took a few minutes, but restored absolutely everything. I was impressed. ## TLS and reverse proxying via Add-ons I was anticipating - indeed, hoping - to set up TLS and reverse proxying using certbot and nginx. But that is not possible. Instead, I achieved it (reasonably easily, but not as easily as using a command line) via Add-ons from within the HomeAssistant UI. I’d have prefer to have done it the normal way, via ssh, but oh well. ## But no firewall or security scanning, or restic for backups? Annoyingly, I’d also like to have configured a firewall on the machine, but that is not an option either. I’ve yet to determine if that is going to be a dealbreaker for me, or whether relying on the network-level firewall, controlling access to and from that VLAN, and that machine, will be sufficient. I have also not been able to set up a separate ssh account for my greenbone scanning software, or to configure Wazuh to get the machine talking to my SIEM. Again, I will need to consider the impact of this, but intuitively it does not sit comfortably with me. Nor can I find a way to use restic to backup the configuration and other bits, incrementally and automatically, onto another machine, liked I am used to doing. I will have a poke around with the backup tooling offered but again, this does not enthral me. I want to know that, if there’s a problem, I have a backup on my restic server. ## Initial impressions Since I have used HomeAssistant for so long, and since I just restored a backup, the most I can say really is that it is all still working. It doesn’t seen faster or slower. The limitations of the appliance-based approach are annoying me, and may be sufficient to drive me towards a container-based approach instead (although that does not appeal to me either). Ultimately, I accept that I am but one user, and perhaps many users do not want the things that I want. Importantly, I am not the developer, and so what I want may simply not be things that they wish to provide. And that is their choice. I guess - personal opinion - that I would prefer a _computer_ and not an _appliance_.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 18/03/2026
neilzone.co.uk
Musings on 'digital sovereignty'
I’ve heard a lot about “digital sovereignty” recently. I’ve heard it mostly in connection with USA-based tech companies, big ones in particular. I am not aware of a clear, agreed, definition, but it seems to boil down to wanting control over (all? some of?) one’s digital systems. Or, at least, not depending on technologies which are controlled by people/organisations in other countries. But I wonder how far the notion of “digital sovereignty” goes. ## Am I “digitally sovereign”? Can I be “digitally sovereign”? Take me, for instance. I use almost exclusively Free software, which I run locally on my own hardware. No-one can - short of hacking my systems - remove or limit the software that I use. No-one can lock me out, or delete my data. Does that make me “digitally sovereign”? If it does, that seems like a very shallow concept of sovereignty. Sure, it is better than being subject to the whims of a SaaS provider. But I am still dependent on a whole range of other people, whose software I benefit from using. And the people who maintain that software. And the people who package that software. And the people who distribute that software. And so on. I, personally, could not expect to have control over anything but a tiny, tiny part of that. Perhaps I can never, realistically, be “digitally sovereign”? ## Reliance on others is reality (for me, anyway) These wonderful, generous people could be anywhere in the world. They are - most likely - all over the world. So while I might have control over the software that I have already installed, I have no (realistic) control over updates, security patches, and the like. And while I might host everything myself, I have to get that software from _somewhere_. Sometimes - often - it is from Debian’s repositories. Sometimes, that is from people’s own code forges. And sometimes it is from Github. My Mastodon (glitch-soc) instance, for example. Were Github to stop hosting that code, or to stop me from accessing it, I’d either need to find another way to obtain it (to maintain patching/updates), or cease to run it. Let’s Encrypt is a USA-based organisation, so perhaps I should find another ACME TLS certificate provider… Perhaps viewing this from the perspective of me - just one person - is fundamentally flawed? Because _of course_ I am dependent on others - if I chose not to be so, I, and the vast majority of the population, would not be “digitally sovereign”, but rather digitally neutered. But individuals are indeed vulnerable to the whims of third parties, just as much as governments or big businesses. In fact, perhaps more so, based on the number of software providers that I’ve seen switch from on-machine software to SaaS, and then proceed to screw over their customers with increasingly expensive subscriptions and lock-ins. ## Is “digital sovereignty” about geographic borders? I wonder, to what extent geographic borders are relevant. Does “digital sovereignty” require that a nation (or company? Or individual? not sure…) can support all its own software, hardware, routing, hosting requirements etc. solely by or with people and companies from within its own geographic borders? Does it extend beyond supporting software, into only running software which is created within its regions? If it does, then that sounds incredibly inefficient, with each country needing to develop its own operating system, its own applications etc. What a waste of effort, competing rather than collaborating. From an individual point of view, sure, placing my trust in a company in another country may not be a great idea, but is placing my trust in a company within my own country’s borders significantly better? I self-host for a reason. I could have the rug pulled out from under my feet by a _domestic_ provider, with just as great an impact as a _foreign_ provider. I question if I can be “sovereign” at all, if I am reliant on someone else. If this is true, is geography-based “digital sovereignty” little more that digital xenophobia? Perhaps the principle of “digital sovereignty” only relates to governments, and others who have significant bargaining power. ## Greater control, at greater cost? I’ve yet to see a good, solid indication of how “digitally sovereignty” is to be funded. Yes, sure, an organisation might be spending a small fortunate on Microsoft’s services. They could indeed channel that money into a Free software alternative, and associated training. But are they going to do so? I’ve seen press releases about “savings”, which suggests money not being spent, rather than that money being spent elsewhere. I imagine that, in reality, “digital sovereignty” would be a remarkably expensive undertaking. Perhaps more expensive than buying commodity services from overseas third parties. Digital sovereignty may come at _premium_ pricing, rather than being a cheaper alternative, and that money needs to come from somewhere. ## Digital sovereignty beyond the tech And, beyond money, and beyond tech, there might be issues of incentivising local development (boosting local employment), removing tax breaks available to behemoth organisations, making laws comprehensible and applicable for small organisations with a cadre of lawyers and lobbyists, and so on. Digital sovereignty might be grounded in considerations of technology, but likely requires far, far broader thinking.
000
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 14/03/2026
neilzone.co.uk
Moving my static site blog generator from hugo to BSSG
I enjoy blogging. I blog on my own personal site (this blog), and I also have a blog for my work site, decoded.legal. In 2023, I moved my blog to a static site generated by hugo. I've been reasonably pleased with hugo, and it does the job, but I find it complex. In short, if an update broke my site, I am not 100% convinced that I would be able to fix it. I don't need much in the way of complexity; I have a simple, predominantly text, blog, and all I want is to be able to write posts in markdown, generate a static html site from it, andrsync it to a webserver, along with an RSS feed. I am using a Raspberry Pi 4 as my webserver, and this works fine, given my lightweight, low complexity, sites. ## Enter BSSG On the fediverse, I saw Stefano Marinelli discussing his own static site generator - the Bash Static Site Generator, also called "BSSG" - and I was keen to give it a try. I guess that I am simply more confident that, if there was a problem, I'd be more confident about fixing something written in bash. ## Installing BSSG I am running hugo (and now BSSG) on my Raspberry Pi 4 webserver. I could install it on something beefier, like my laptop, and then just rsync the output files to the webserver, but, again for simplicity, it makes sense to me to run the static site generator on the webserver itself. I don't have anything particular to note about the basic installation. ## Configuring BSSG I wanted to make quite a few changes to the default configuration, so I decided that the simplest thing to do was to copy the whole config file from the BSSG installation directory into my site directory, and then amend it. Here is my configuration file. (I have a separate file, in the same directory, for my .onion site; this is much the same, but referencing the .onion URL instead, and with a separate output directory.) ## Customising the theme I was happy with how my old blog looked, and, for the work blog, I wanted it to remain consistent with the main website. I started with the BSSG "minimal" theme, and then made the changes that I wanted to support "dark mode", remove transitions/transformations, and to generally get to the look that I wanted. Here is the resulting css. ## Adding fediverse stuff to the header Once can also have site-specific templates, so I copied the templates directory from the BSSG directory into my site directory, and made changes there. In particular, in the header template, I: * added an inline svg for the icon, in lieu of a favicon file * added a link for fediverse verification (`<link rel="me" href="https://mastodon.neilzone.co.uk/@neil"/>`) * added a link for "fediverse:creator", so that post previews in Mastodon link to my Mastodon account (`<meta name="fediverse:creator" content="@neil@mastodon.neilzone.co.uk" />`) * adjusted some of the OpenGraph (fedi previews) stuff, to use a static image, since I do not use header images (or, really, any images at all) Here is the header file. In the footer, I amended the copyright information, and, on the work blog, added a short disclaimer. (My footer.) ## Migrating content from my hugo blog There is a significant (but not total) overlap between the header material of blogposts for hugo and blogposts for BSSG. I'm not entirely sure that I needed to do anything at all, aside from copying the raw markdown files into BSSG's `src` directory, but I used a few regexes to align the header material anyway: # Change the date format sed -r -i 's/(^date: ".*)(T)(.*)(\+)(.*)(:)(.*$)/\1 \3 +\5\7/g' *.md # Change the date format in the "publishdate" field, and change the field name to "lastmod" sed -r -i 's/(^publishdate: ".*)(T)(.*)(\+)(.*)(:)(.*$)/\1 \3 +\5\7/g' *.md sed -r -i 's/publishdate/lastmod/g' *.md # Remove the year and month lead-in to the slug, and change the name to "slug" sed -r -i 's/(^url: )(.{8})(.*)/\1\3/g' *.md sed -r -i 's/^url/slug/' *.md # Remove the brackets from the tags, remove the quotation marks, and remove spaces sed -r -i 's/(^tags: )(\[)(.*)(\]$)/\1\3/' *.md sed -r -i '/^tags/ s/"//g' *.md sed -r -i '/^tags/ s/, /,/g' *.md (Yes, there might be shorter / cleaner / faster etc. ways of doing this. This worked for me.) I also found - thanks to an error message when I first tried to build the BSSG content - that BSSG does not like src files with spaces in the names. I did not have many (although one was enough), so I fixed that: rename 's/ /-/g' *.md One thing that I did not do with hugo is have descriptions for my posts. I think that I'd prefer not to have descriptions displayed at all, but I've yet to find a way to suppress them in BSSG without editing the underlying scripts, which (for ease of updating), I am loathe to do. ## Adding new content and building the blog I am not using BSSG's editing tool, or its command line tools for adding new posts (although I might need to use it for deleting posts). Instead, I prefer to write markdown in vim, and then upload that to the webserver and then build the site. I have a small shell script on my laptop and phone, which generates a text file (with a .md extension) with the correct header material, and it pre-populates the date and time in the correct format. I then have a separate script which I use to push the new blogpost to the webserver, and then, via ssh, runs a script in the relevant BSSG site directory to build the site and rsync it into place. Here is that build script. (Although "build script" makes it sound fancier than it is.) ## Initial thoughts It is early days, so these are little more than my immediate notes. I'd like to find a way to remove the descriptions from the index page. But, other than that, I am very happy with BSSG, and I am very grateful to Stefano for making it available. Building this blog on a Raspberry Pi 4, even using the (newly-fixed; thanks, Stefano!) "ram" mode, is not exactly rapid, but that is not a particular concern for me. I am very pleased. And, if you can read this - my first new blogpost since adopting BSSG - then everything is going well :)
020
Home [Unofficial] @neilzone.co.uk.web.brid.gy · 05/03/2026
neilzone.co.uk
My resolutions for International Women's Day
Each year, 8th March is International Women's Day. (Yes, yes, since someone asks Every. Single. Time., there is also an International Men's Day.) This year, IWD is on a Sunday. I saw an interesting toot in the fediverse from Eliza, asking men about their resolutions for IWD. I had a think about this. I work for myself, on my own, so things about "being more aware of things in an office environment" is less applicable to me. ## 1) An explicit conversation about load with Sandra ("Explicit" as in "clear, intentional", rather than "overly sexy". Probably.) I'm married, and Sandra and I share things pretty equally. It really should go without saying, but nevertheless: I cook, clean, do food shopping, wash clothes, tidy up (I'm the tidy one!), and so on. Sometimes one of us does more of one thing than the other, depending on what is going on in our lives. Other things are split based on enjoyment from doing it, or just plain interest and skill. Sandra enjoys planning holidays, more than I do. I have no objection to sorting out the gardening, or doing "handyman" jobs around the house. Sandra is better at choosing presents for people; I'll sort out the car servicing and maintenance. We communicate about this kind of thing quite a lot - we make a good team, IMHO, and that means genuinely working together and supporting each other - but one resolution for me, this IWD, is that I will take the opportunity to talk to Sandra explicitly about how we, as a couple, handle these things. We can replan accordingly. ## 2) A day of boosting more women's (and agender / non-binary people's) toots? I'm on the fence about this one, as it could be merely performative, and I already boost a lot. But it is something that I can do, and raising awareness does have a value. So, perhaps... And perhaps especially toots about women's equality / rights / contributions etc. Obviously, this would be based on "to the best of my knowledge" anyway. Not everyone wants to share what gender(s) they are, or are not, and that is absolutely their choice. _Update 2026-03-06_ : Quinn Norton kindly shared some feedback with me on this: > I want to make it clear that I – a man – am not trying to tell you what women want, but if you’re open to some feedback: I _personally_ really felt uncomfortable when I was tagged in International Women’s Day posts by (very well meaning) friends the first IWD after I’d come out on my blog as genderqueer/‘I’m not sure yet but probably not a cis woman??’ > > Obviously other agender, non-binary, etc. folks might feel differently (and there absolutely are people with those identities who feel aligned/connected to womanhood in some way) but to me it felt really invalidating of my gender. So - even in the context of boosts, rather than tagging anyone (because, yes, absolutely, that feels fraught with problems to me - perhaps back to the drawing board on this one. Or perhaps a focus solely on women, and - for this specific purpose - not including agender / non-binary people? ## Others? Perhaps. I will give this some more thought. But I wanted to post this sooner rather than later, so I could also draw inspiration from what other men are planning on doing.
000