Sign in

Phoenix Paulina Schmid

@posts.blog.gelbphoenix.de.ap.brid.gy
0 followers 0 following 16 posts

The Future is federated! Ready to join? 🌉 bridged from ⁂ blog.gelbphoenix.de, follow @ap.brid.gy to interact

PostsRepliesMedia
Phoenix Paulina Schmid @posts.blog.gelbphoenix.de.ap.brid.gy · 30/08/2026
The ECB's Digital Euro promises financial inclusion. But the architecture is surveillance first. GNU Taler offers a cryptographic alternative that the EU isn't building. GNU Taler-Series #2
blog.gelbphoenix.de
GNU Taler vs. the Digital Euro: A Question of Cryptographic vs. Institutional Privacy
Imagine your passport wasn't issued by a country but by a commercial payments network. If that network updated its terms, faced regulatory pressure, or decided to deprioritize your region, your ability to transact would vanish overnight. This isn't science fiction. We're sleepwalking into exactly this with central bank digital currencies (CBDCs). The European Commission is building the Digital Euro, a system that will give the ECB real-time visibility into every transaction you make, with the ability to freeze, limit, or condition your money on their terms. There's an alternative that already exists: GNU Taler. It offers genuine financial privacy without sacrificing regulatory compliance. But the ECB isn't building it. Neither is any major government. And that silence says something. ## __The Digital Euro promise__ The pitch sounds good. A digital version of the euro, available to everyone, that works offline and costs nothing to use, with no more reliance on commercial banks and direct access to central bank money. The ECB emphasizes accessibility for unbanked people, more competition, and payments that are instant and settlement-final. But read the fine print. The architecture is surveillance-first: the ECB will hold real-time transaction data for every Digital Euro movement, not anonymized, not aggregated. Individual records tied to your identity, your devices, your geographic location, your spending patterns. That's not a feature. It's the whole point. ## __The Privacy inversion__ Commercial banks today are required to report suspicious transactions to authorities. There's friction, procedures, an assumption of baseline privacy: the ECB doesn't watch every coffee purchase. Digital Euro infrastructure inverts this. Total observation becomes the default. Privacy becomes the exception you have to argue for, not the right you inherit. And the argument gets framed as a threat: "Privacy-preserving payments? You must be hiding something. Only criminals want that." This move, conflating financial privacy with criminality, is a red herring. Legitimate reasons to want transactional privacy abound: protection from abusive partners, security from targeted theft, defense against political persecution, freedom from commercial profiling. But once observation is built into the infrastructure, those reasons don't matter. The capability exists, and history shows it gets used. ## __GNU Taler's cryptographic alternative__ GNU Taler inverts the privacy model. It uses cryptographic commitments to separate two truths the Digital Euro tries to merge: the merchant knows you paid, but the central bank doesn't know who paid. Here's how: you withdraw a coin from your bank (authenticated). The bank issues a coin with a blinded serial number, cryptographically hidden from the bank itself. You spend the coin at a merchant. The merchant verifies it's genuine. The merchant deposits the coin at the bank. The bank confirms it's valid. The bank, though, never links which withdrawal belongs to which spending. The blinding prevents that. The merchant learns who paid (for refunds, shipping, warranties), but the central bank learns only aggregate flows and balances, no transaction graph, no spending-pattern surveillance. The result: transaction transparency for regulatory compliance, spending privacy for citizens. ## __Technical & Institutional Comparison__ **Observation Model** _Digital Euro:_ Total observation by default, opt-out privacy (with friction and exceptions)._GNU Taler:_ Privacy by default, transparency where it matters (merchants, aggregate compliance). **Issuance and Control** _Digital Euro:_ Centralized, issued by the ECB, policy set by technocrats and finance ministers._GNU Taler:_ Can be issued by any bank or institution. The cryptography is open-source and auditable. Multiple issuers compete; no single point of control. **Resilience** _Digital Euro:_ A centralized payment rail. ECB systems go down, payments stop. ECB policy changes overnight, your financial freedom changes.****_GNU Taler:_ Decentralized by design, with different issuers meaning different policies. Cryptographic verification works offline, and one issuer's failure doesn't collapse the network. **Regulatory Compliance** _Digital Euro:_ Compliance through surveillance. The ECB watches everything, then enforces rules.****_GNU Taler:_ Compliance through transparency. The system verifies legitimate transactions without identifying individuals. Banks verify coins, regulatory oversight still happens, but it doesn't require a total transaction ledger. ## __Why this matters__ The Digital Euro is marketed as a public good. It'll increase inclusion and choice. On the surface, fair enough. But the architecture reveals this isn't really about inclusion or choice: it's about centralizing state surveillance over economic life. Once a government controls the rails, the basic layer of how money moves, it doesn't just get regulatory information, it gets policy leverage. Frozen accounts aren't a bug. They're a feature. Conditional spending (you can't buy X) isn't theoretical. It's an operational capability waiting to be deployed. Canada in 2022 is one data point: the government froze trucker protestors' bank accounts with a single keystroke. Russia's capital controls are another. So is what China's doing with digital yuan tracking. These aren't edge cases: they're demonstrations of what's possible when you combine total observation with centralized policy. The EU is more liberal than those examples. But the question isn't whether today's administrators would abuse the power, it's whether tomorrow's will. And once the infrastructure is in place, it's much harder to undo than to expand. ## __What should happen__ I'm not arguing the Digital Euro should be killed. Centralized CBDCs are coming. The question is what we build alongside them. **GNU Taler, or something like it, should be a co-equal payment rail, not an alternative for fringe users:** a funded, supported, standard option with the same interoperability and reach as the Digital Euro. Citizens should genuinely choose between privacy-preserving and surveilled payment systems. **Cryptographic privacy should be the default, not the exception.** If we're building public payment infrastructure, the baseline should be that individuals aren't profiled, with transparency opt-in only for specific transactions such as audits, compliance checks, or fraud investigations, not universal surveillance. **Open source auditing is non-negotiable.** If the ECB is building critical financial infrastructure, the code should be open, the cryptography reviewed, and the policies public. "Trust us" isn't good enough. **Multiple issuers should be possible from day one.** The ECB can issue euros, but so should major banks, payment services, and fintech platforms, each with their own policies, risk profiles, and privacy choices. Citizens pick which issuer to trust. Will any of this happen? Almost certainly not. The ECB didn't design Digital Euro surveillance into the architecture by accident. It's the whole point. ## __Why this silence matters__ GNU Taler's absence from the Digital Euro infrastructure is a choice, not an accident. Choices about monetary infrastructure are choices about power. The ECB will tell you the Digital Euro is about financial inclusion, speed, removing middlemen. True enough. But that's not the whole story. The whole story is that the Digital Euro is about centralizing observation and control over how Europeans move money. That's not automatically evil. Governments have legitimate reasons for financial oversight: fraud prevention, tax compliance, sanctions enforcement. But the infrastructure you build determines whether that oversight can be abused. Once total observation is baked in, the pressure to use it expands. History shows this. GNU Taler exists to prove another way is possible: one that maintains regulatory compliance without requiring total surveillance, and that respects both the legitimacy of oversight and the legitimacy of privacy. The EU isn't building it. That tells us what the actual priorities are. ## __What you can do__ If you care about this, if you think financial privacy matters or you're skeptical of unchecked state surveillance, here's what's actionable: **Learn the technical details.** Understand how the Digital Euro will work. Understand what GNU Taler does differently. The more technically literate citizens are, the harder it becomes to hand-wave away the implications. **Demand alternatives.** Talk to your MEPs. Write to the ECB. Ask why privacy-preserving payment systems aren't being co-funded alongside the Digital Euro. Make it politically uncomfortable to ignore. **Support the projects building this.** GNU Taler is open-source and peer-reviewed. If you have the skills, contribute. If you don't, fund the people who do. The only way alternatives survive is if they're resourced. **Think long-term.** The Digital Euro will launch. You'll probably use it. That's fine. But infrastructure choices made today shape policy possibilities for the next decade. If you care about financial freedom in 2035, care about how payments are architected in 2026. The Digital Euro is coming. The question isn't whether you can stop it. The question is whether you'll push for alternatives: whether you'll insist that the infrastructure of money reflects both legitimate oversight and legitimate privacy. That question is open for now. If you want to hear more from me, you can find me in the Fediverse at @gelbphoenix@social.gelbphoenix.de (Mastodon) or @gelbphoenix@gram.social (Pixelfed). For more posts like this subscribe to my newsletter or support me by becoming a member or donating. Liked this post? Please share it with others via: Mastodon, Bluesky or anywhere else by copying the link.
000
Phoenix Paulina Schmid @posts.blog.gelbphoenix.de.ap.brid.gy · 21/07/2026
TL;DR: Centralized platform handles are rented land. Owning a personal domain is the single most effective step toward true digital sovereignty, allowing you to anchor your email, Fediverse identity, Matrix chats, Bluesky handles and other identifiers to a name you control.
blog.gelbphoenix.de
The Domain as Your Passport
Imagine your passport wasn't issued by a country (like the ones in the upper picture) but by a commercial media network. If you broke an arbitrarily updated Terms of Service or if the platform simply decided to sunset your account then all things connected to that account (your identity, connections, history and – if applicable – your way to earn money) would suddenly vanish in a second overnight. This is the reality of modern internet and online identity. We rely upon `@example` on Instagram, Twitter and co, `example` on Discord or `example@gmail.com`. In every of those cases, you are a tenant on corporate infrastructure. True digital sovereignty requires a portable and self-owned identity. And the tool to achieve exactly this isn't some blockchain system but exists sind 1983 – the **Domain Name System (DNS)**. ## __Why are Domains the Ultimate Identity Anchor__? While you "rent" – which is more like paying a fee for the re a domain from a registrar does DNS remain one of the most successful decentralised naming platforms and systems in the world. No single company owns `.de`, `.org` and `.com`. You unlock two critical powers if you use your own domain (e.g. `yourdomain.com`) as your identity across services. Firstly the power of portability as you can simply change your DNS records if your server hoster, Fediverse instance or mail provider goes down or changes their policy. That allows that your audience doesn't loose you as your identity follows you. Also do you unlock the power of independent verification without relying upon a gatekeeper as you don't need to pay a subscription to gain a check mark. Pointing to a domain's DNS or hosting configuration files proves ownership instantly and cryptographically across the web. _****If you like this blog post you can support my work by either becoming a paid member or leaving a tip.****_ Donate ## __The Sovereign Identity Stack__ One Domain, Five Protocols A single domain can serve as you unified identity across completely different network architectures. Protocol / Platform | Sovereign Handle Format | How Your Domain Connects | What It Gives You ---|---|---|--- Email | you@yourdomain.com | MX records, SPF, DKIM, DMARC | Complete ownership of your communication channel and newsletter audience. Fediverse (ActivityPub) | @you@yourdomain.com | Webfinger redirects or hosting your own single-user instance | Permanent social handle regardless of which server holds your data. Matrix | @you:yourdomain.com | /.well-known/matrix/ JSON configs & DNS SRV records | Sovereign, end-to-end encrypted chat identity across the Matrix network AT Protocol (Bluesky) | @yourdomain.com | DNS TXT record (_atproto) or HTTP well-known path | Instant, free verification that proves you are who you claim to be. IndieWeb / Webmention | yourdomain.com rel="me" links & IndieAuth | Cross-site authentication and unified identity across independent blogs. | ## __How does this work__ Under the hood do almost all modern open protocols verify domain ownership using one of the following two methods. ### DNS Records (TXT & SRV) For example does the AT Protocol or custom email setups ask you to add a simple TXT record to your domain's DNS zone. What that process can look like for the AT Protocol have I described here. ### Well-Known Configuration Files Protocols like Matrix or ActivityPub check the ownership of domains via a small file that your domain serves over HTTP from a standard location (e.g. `yourdomain.com/.well-known/`). For Matrix does a simple `matrix/client` file tell clients where your actual homeserver is. { "m.homeserver": { "base_url": "https://matrix.yourdomain.com" } } This abstraction layer means your actual infrastructure can move from a VPS to a home server in your living room without your public handle changing. ## __Breaking free from the "Rent-A-Handle" Economy__ When you rely upon platform-native handles, you give the control over your equity away to others who you can't control or don't even know. By treating your domain as your digital passport do you decouple **who you are** from **where your data is stored**. It turns the web back into what it was always intended to be: a federated ecosystem where individuals hold the keys to their own presence. **_If you haven't already, register a personal domain for cheap and point your handles to it. It’s the smallest investment you can make for the highest return in digital autonomy._** If you want to hear more from me, you can find me in the Fediverse at @gelbphoenix@social.gelbphoenix.de (Mastodon) or @gelbphoenix@gram.social (Pixelfed). For more posts like this subscribe to my newsletter or support me by becoming a member or donating. Liked this post? Please share it with others via: Mastodon, Bluesky or anywhere else by copying the link.
000
Phoenix Paulina Schmid @posts.blog.gelbphoenix.de.ap.brid.gy · 05/07/2026
If you're anything like me then you aren't just getting your eBooks and eComics on just one platform but many different ones. Problem with that is how you're getting all this together into a single place, organised and synchronised with your eReader. You end up manually downloading eBooks […]
blog.gelbphoenix.de
Streamlining Digital Libraries
If you're anything like me then you aren't just getting your eBooks and eComics on just one platform but many different ones. Problem with that is how you're getting all this together into a single place, organised and synchronised with your eReader. You end up manually downloading eBooks, trying to fix metadata by hand and wrestling with cables or cloud uploads just to read a book. It works if you have a book or two but not with a growing library. Managing it quickly turns from a relaxing hobby into basically a second job. For a long time Calibre and Calibre Web have been the go-to solutions for taking back control of your media. But even then, I found myself wanting more – more automations and better integration with my devices and the services that I use. That's exactly why I built Autocaliweb. ## __What is Autocaliweb?__ In short, Autocaliweb is an open-source eBook management platform that you can self-host. It takes the web interface of Calibre-Web, supercharges it with the heavy-lifting automation services of Calibre-Web Automated you actually need to keep a library running in the background and combines it with own features. Instead of forcing you to jump between different tools to download, convert, and sync, Autocaliweb acts as the central brain of your digital bookshelf. _****If you like this blog post you can support my work by either becoming a paid member or leaving a tip.****_ Donate ## __What make it different to other solutions?__ While being built on top of amazing free and open-source projects I didn't just wanted to smash these projects together. I wanted to add features and fix specific friction points while – at that time – providing a up to date version of the projects. Those core features that define Autocaliweb are: * A native support for docker mods (like those from LinuxServer.io) which adapt perfectly to your stack without requiring a manual custom build. * Autocaliweb provides granular Kobo eReader syncing. You can set if your Kobo eReader should show the Kobo Plus or Overdrive tabs and Instapaper Integration directly from the Web UI. * Send your eBook library to multiple Send-to-Reader eMail addresses. * Full support for custom Open ID Connect (OIDC) providers with `well-known` configuration support with an optional auto-login. * It features native integration with **Hardcover.app** to cache author information and sync your reading progress (especially helpful if you're using a Kobo eReader). ## __Moving to a new home__ If you've been already following my work, you have noticed that Autocaliweb had it's repository moved from GitHub to the Berlin-based Codeberg. Making it – from my perspective the f**irst and only** calibre based web platform **with an official repository on Codeberg**. When you build a project centered around digital sovereignty and taking back control of your eBook library, it only feels right to host the code in a place that shares those exact same community-driven values. Moving away from corporate, algorithm-heavy US platforms to an independent, European forge aligns perfectly with what Autocaliweb stands for. ## __What's coming next?__ Next on the roadmap is an official Autocaliweb addon for Libre Workspace. If you have further ideas than please either mention those in the exclusive Matrix space _(for Growth members)_ or as a feature request on the repository. In the meantime you can try and use Autocaliweb via Docker, natively or as an Proxmox LXC via the Proxmox Helper Scripts. Let me know how it works for your library, and happy reading! 📖 If you want to hear more from me, you can find me in the Fediverse at @gelbphoenix@social.gelbphoenix.de (Mastodon) or @gelbphoenix@gram.social (Pixelfed). For more posts like this subscribe to my newsletter or support me by becoming a member or donating. Liked this post? Please share it with others via: Mastodon, Bluesky or anywhere else by copying the link.
000
Phoenix Paulina Schmid @posts.blog.gelbphoenix.de.ap.brid.gy · 18/06/2026
A look into BizzFed's security collapse, the Fediverse's immune response, and the dangerous reality of relying on AI-assisted "vibecoding" for infrastructure.
blog.gelbphoenix.de
The Price of Vibecoding
When looking at the current world of Commercial Media**** only a few platforms feel as exhausting as Microsoft's LinkedIn. It has become a optimized ecosystem of algorithmic manipulation, content generated by Large Language Models or short LLM (what people also call "AI-slop") and corporate tracking. For anyone advocating and promoting the Open Social Web does the alternative likely seem obvious: We need a decentralised, private alternative to LinkedIn that is build on open protocols like ActivityPub. A place where professionals, freelancers and companies can connect without an central middleman collecting and selling their data. An earlier idea for an post on this blog was a new part of the series "A Beginner's Guide to Decentralized Social Media" about Bizzfed. But as I looked into the platform I did find a massive security breach which was a direct result of how Bizzfed was and is build. Let's unravel why the platform became a textbook example of the hidden dangers of Vibecoding – the practice of letting LLM agents code a whole software and deploy it into production. ## The Illusion of Transparency The development of Bizzfed is unique. The Codeberg repository features an explicit "AI-Notice", where the developer René Hamdorf transparently laid out that large portions of Bizzfed's codebase was generated by Anthropic's Claude LLM. Those commits are tagged with an `Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>` trailer. In earlier project announcements did Hamdorf defend this modern workflow: > KI-gestützte Entwicklung: Ja, Claude von Anthropic war mein Entwicklungsassistent — wie andere Entwickler heute Copilot oder Cursor nutzen. Den Code schreibe, reviewe und verantworte ich. Das Projekt ist Open Source (AGPL-3.0), jeder kann reinschauen: codeberg.org/rhamdorf/BizzFed The source is in German, the text is in English: "AI-assisted development: Yes, Claude from Anthropic was my development assistant – like other developers use Copilot or Cursor today. I write, review and take responsibility for the code. The project is Open Source (AGPL-3.0), everybody can take a look at it: codeberg.org/rhamdorf/BizzFed" On paper does it sound like a sort of win for Open Source but in the world of cyber security and decentralised infrastructure can't you just "vibe" your way through code reviews. ## When the LLM Handles the Deployment The scepticism of the community grew as users looked under the hood. A user shared that Claude didn't just generate a large part of the codebase it was also responsible for the deployment and configuration. From own experience can I say: When you stop intimately understand your own deployment pipeline because you let an LLM drive your terminal, disaster is usually only a coin flip away. And Hamdorf lost that coin flip. Within days of releasing the early access was the official account of Bizzfed compromised because the LLM published the password publically in the repository while Bizzfed's Two-Factor Authentication (2FA) process failed to function. Said account released posts like "SLOP SLOP SLOP SLOP SLOP SLOP SLOP" and "Sad to see another good idea be ruined by vibecoding..." Screenshot of the posts released when the official Bizzfed account was compromised. Source: @ryan_harg@chaos.social ## The Immune Response of the Fediverse In decentralised networks is security a collective responsibility. If a instance is poorly managed and secured or leaks staff credentials does it become a attack vector for spam, malicious data injection or security exploits across the entire network. Therefor was the reaction of some admins of Fediverse instances swift and uncompromising as they started to defederate the main instance of Bizzfed. This was an natural immune response of the Fediverse. Handing the keys to an LLM agent contradicts the very culture of the decentralised web and the very core of what makes self-hosting safe. ## Hard Lesson for the Open Web Painful is the irony of the Bizzfed situation. We need a alternative to LinkedIn and co without commercial AI-slop and the toxic "hustle culture" but an attempt of that was compromised by the own reliance of vibecoding. Let me be clear: LLMs and AI technology can be a good tool if used correctly but an over reliance of it leads to situations like these. You can't delegate responsibility to an LLM in the sovereign and decentralised web as true sovereignty requires human vigilance. **_What do you think? Was it a proof that the Fediverse is too delicate for vibecoding or was it a case of poor human oversight? Let me know your thoughts?_** 🤖 If you want to hear more from me you can find me in the Fediverse at @gelbphoenix@social.gelbphoenix.de (Mastodon) or @gelbphoenix@gram.social (Pixelfed). For more posts like this subscribe to my newsletter or support me by becoming a member or donating. Liked this post? Please share it with others via: Mastodon, Bluesky or anywhere else by copying the link.
010
Phoenix Paulina Schmid @posts.blog.gelbphoenix.de.ap.brid.gy · 08/06/2026
Why and How I Moved My Analytics Backend to a Local Deployment
blog.gelbphoenix.de
Digital Sovereign Ghost
Ghost is a wonderful blogging and publishing platform and running an own modern blog is more than just putting a Content Management System on a VPS or use a dedicated provider. As it is a constant commitment to digital sovereignity, data ownership and minimizing unnecessary dependencies on foreign cloud providers. When Ghost published its 6.0 version, it introduced a native analytics feature that relies upon the New York, US-based Tinybird for cookie-free, real-time data processing. And by default does the documentation steer the admin of self-hosted Ghost instances (servers) to signup for an free Tinybird account for the cloud based offering. The free offering is good for small and medium blogs but does run on the cloud infrastructure of Google and(/or) Amazon. Exactly this point feels for me like an compromise of the very principles that led for me to do self-hosting in the first place and therefore led to me to look for the possibility to pull that dependency into my own control. ## __The Experiment__ My try to move to local Tinybird Tinybird offers two ways to self-host its infrastructure. Tinybird **Self-Managed Regions** and **Tinybird Local**. The former one is aimed at enterprise-scale deployments with the related resources, whereas the latter is designed for development. But with the right configuration and a robust reverse proxy can the Tinybird Local container function as a lightweight, permanent backend for Ghost Analytics on a self-hosted Ghost instance. **I tested** the possibility of that in the **night from** the **6th to the 7th of June 2026**. And as you see this version of the blog post I can say that **this was successful** – the analytics of this blog use the Tinybird Local container instead of the cloud offering. ## __The Architecture__ What is running under the hood We need to look at what the Tinybird Local is to understand how this works. This isn't a monolithic black box but a developer-centric streaming data platform build on top of **ClickHouse** – an database designed for analytics data. When you spin up the `tinybird-local` container you are essentially starting a lightweight project model similar to like in the cloud offering of Tinybird but contained in a single container. Here is how the data flows in this self-hosted ecosystem: 1. **The Reader:** Someone visits the blog. Ghost's native tracking script sends an event. 2. **Caddy:** Intercepts the analytics traffic and securely routes it to the local infrastructure. 3. **Tinybird Local:** Ingests the raw event stream, validates it, and efficiently stores and aggregates the analytics data. 4. **Ghost Dashboard:** Queries the local Tinybird API to display your real-time visitor stats. _****If you like this blog post you can support my work by either becoming a paid member or leaving a tip.****_ Donate ## __The Setup__ Making it Work ⚠️ The following is not officially supported by either team of Ghost or Tinybird. Proceed with your own risk. To transition your analytics backend from the cloud offering to an deployed instance of Tinybird Local we have to do the following (Requirement is to have Ghost already deployed via Docker): **Docker Compose** We can simply add the following configuration to the compose.yml with which we run Ghost: tinybird-local: image: tinybirdco/tinybird-local:latest container_name: tinybird-local restart: unless-stopped ports: - "127.0.0.1:7181:7181" volumes: - ./data/tb_local/clickhouse:/var/lib/clickhouse - ./data/tb_local/redis:/redis-data profiles: [analytics] networks: - proxy healthcheck: test: ["CMD", "curl", "-fsS", "http://localhost:7181"] interval: 5s timeout: 5s retries: 30 tinybird-sync: # Do not alter this without updating the Ghost container as well image: ghost:${GHOST_VERSION} container_name: tinybird-sync command: > sh -c " if [ -d /var/lib/ghost/current/core/server/data/tinybird ]; then rm -rf /data/tinybird/*; cp -rf /var/lib/ghost/current/core/server/data/tinybird/* /data/tinybird/; echo 'Tinybird files synced into shared volume.'; else echo 'Tinybird source directory not found.'; fi " volumes: - ./data/tinybird/files:/data/tinybird depends_on: tinybird-local: # Add this condition: service_healthy # Add this tinybird-login: condition: service_completed_successfully networks: - proxy profiles: [analytics] restart: no tinybird-deploy: build: context: ./tinybird dockerfile: Dockerfile container_name: tinybird-deploy working_dir: /data/tinybird command: > sh -c ' for i in $(seq 1 20); do if tb-wrapper --cloud deploy -v; then exit 0 fi echo "Tinybird deploy not ready yet, retrying in 5s..." sleep 5 done exit 1 ' # Change this volumes: - ./data/tinybird/home:/home/tinybird - ./data/tinybird/files:/data/tinybird depends_on: tinybird-sync: condition: service_completed_successfully profiles: [analytics] networks: - proxy tty: true **Caddy** Allowing Ghost to talk with the Tinybird Local container requires that we add the following to the Caddyfile. Replace `DOMAIN` with your own domain. # Tinybird for Ghost tinybird.DOMAIN { @tinybird_admin { path /tokens* not remote_ip 127.0.0.1 ::1 100.64.0.0/10 } respond @tinybird_admin "Forbidden" 403 reverse_proxy 127.0.0.1:7181 } **Environment file** After starting the `tinybird-local` container for the first time can we look up the tokens via the `http://localhost:7181/tokens` URL and changing or adding the respective tokens to the .env file. Don't forget to also change the .tinyb file in the subdirectories of data/tinybird. ## __Closing thoughts__ Securing your own digital sovereignty isn't always easy. It sometimes requires peeking behind or around official documentations and occasionally repurposing tools to serve production needs. By pulling the Ghost Analytics of self-hosted instances out of the cloud do we eliminate a major point of external surveillance and take responsibility for the data privacy of the readers of our blog and members of our communities. It's just pure and high-power independent publishing. **_Would you – if you have a Ghost based blog – switch your analytics backend or stay with whatever you have? Let's discuss!_** 📝 If you want to hear more from me you can find me in the Fediverse at @gelbphoenix@social.gelbphoenix.de (Mastodon) or @gelbphoenix@gram.social (Pixelfed). For more posts like this subscribe to my newsletter or support me by becoming a member or donating.
000
Phoenix Paulina Schmid @posts.blog.gelbphoenix.de.ap.brid.gy · 04/06/2026
As part to maintain my own digital sovereignty and to archive my past public work do I publish an translation of a statement that I wrote in German back in January 2022. This statement was published by LISL NRW – a queer organisation in North Rhine-Westphalia which is closely associated with the […]
blog.gelbphoenix.de
Bringing my content home: Statement about the association "Liebe wen du willst"
As part to maintain my own digital sovereignty and to archive my past public work do I publish an translation of a statement that I wrote in German back in January 2022. This statement was published by LISL NRW – a queer organisation in North Rhine-Westphalia which is closely associated with the liberal Free Democratic Party in Germany – and addressed severe issues surrounding an association called "Liebe wen du willst e.V." (rough translation of that would be "Love who you want e.V."). At that time did the association – which claimed to be against hate speech and provided crisis and emergency hotlines as well as groups via WhatsApp – face heavy criticism from the queer Community in German and the German speaking area after the association and it's founder posted an video mocking neopronouns (which came up as the German language doesn't have a neutral gendered pronoun for people). Beyond this offensive content did looking closer at their infrastructure reveal several highly concerning problems regarding data privacy, structural transparency and uncertified crisis counselling involving minors. In light of my passion for digital rights and sovereignty, decentralised communication and saver spaces does archiving this perspective here remain important for me. Below is the complete and unaltered English translation of the original 2022 statement. (For transparency: I did pick up "Paulina" as my second name way after it's original publishing) Join me in celebrating Pride Month with a free one-week trial of the Growth membership! Claim your free Week ### This post is for subscribers only Become a member to get access to all content Subscribe now
000
Phoenix Paulina Schmid @posts.blog.gelbphoenix.de.ap.brid.gy · 02/06/2026
Why a digital cash system matters – GNU Taler-Series #1
blog.gelbphoenix.de
Digital Cash, Not Crypto
We have succumbed to a lie when it comes to the topic of digital payments. For years we had only the narrative that we have only a choice between giving up our privacy for massive credit card processors (like **MasterCard** or **Visa**) or dive into volatile energy-intensive and resource-hungry world of cryptocurrency (like **Bitcoin** or **Ethereum**). But since 2025 (since 2016 as Proof of Concept) exists a third way that is mostly unknown and is only somewhat used in Switzerland. This is a official GNU project and is called GNU Taler (or simply Taler). Unlike cryptocurrencies like those named above is Taler **not a new currency** but a payment protocol build on top of the traditional banking system. It doesn't use Blockchain technology, doesn't waste energy and solves one fundamental problem: > How do we make digital payments truly anonymous for buyers, while keeping them completely transparent for sellers? ## __The Core Concept behind GNU Taler__ Asymmetric Privacy Most of the privacy tools that exist today try to hide everyone. In recognising that payment systems need a different approach to survive in the real world and not being banned by governments for facilitating tax evasion, Taler split privacy right down the middle. **Customers are completely anonymous.** GNU Taler uses blind signatures (a cryptographic method that lets someone – in this case a bank – sign a digital coin without seeing the specific value or serial number). The shop you can buy from, banks and the infrastructure operators themselves have no idea who a customer is. **Merchants are completely visible.** Every transaction that a shop/merchant deposits is traceable. Businesses can't use it to hide income and making it completely compliant with taxation laws out of the box. ## __How it works__ Instead of relying on distributed ledgers does GNU Taler introduce a few simple roles to handle transactions securely: The ecosystem flow (__Source: GNU Taler)__ The magic of Taler happens in four core pieces: 1. **The Customer bank and Wallet** : Someone (You or anyone else) use regular fiat currency (like Euros or Swiss Francs) to fund their local Taler wallet. 2. **The Exchange** : The Exchange acts as the bridge as it takes your traditional money and issues signed digital coins to your wallet. And the exchange only knows it issued valid money but can't track specific coins back to the customer because of the blind signatures. 3. **The Merchant and Merchant bank** : When clicking "Pay" does the customer's wallet directly send the digital coins to the merchant – which checks the signatures instantly and hands over or confirms the order. 4. **The Auditor** : A critical independent body which checks that the cash reserves of the Exchange match the issued coins perfectly and that it doesn't print money out of thin air. ## __Why It beats traditional Crypto for Daily Use__ If you have ever tried to pay for a coffee with cryptocurrency like Bitcoin then you know the pain. Waiting minutes for block confirmations, dealing with price swings and paying unpredictable gas fees. Taler operates at the speed of all other web traffic. Transactions take milliseconds because they are just cryptographic signature verifications. Because a digital coin via Taler can be bound to a existing fiat currency (e.g. 1 Taler-€ = 1€) there is zero volatility risk. It acts exactly like the physical cash in your physical wallet – once you withdraw it, it's your business alone how you send it. _****If you like this blog post you can support my work by either becoming a paid member or leaving a tip.****_ Donate ## __Local sovereignty__ Digital regional currency without the Overhead One of the most fascinating aspects of Taler is that it isn't locked to fiat currency like the Euro, Swiss Franc or US Dollar. An Exchange operator can define coins in any custom denomination and GNU Taler is arguably the most robust infrastructure ever build for regional or complementary currencies. Regional currencies are designed to keep wealth within a specific community and encouraging people to buy from local shops instead of global retail giants. Historically these projects have relied upon paper vouchers that are a nightmare to maintain and audit. With GNU Taler a municipality, local business association or a community network can spin up their own Exchange using **FOSS** (Free and Open Source Software) tools. Taler includes `LibEuFin` a project that provides free software tooling for FinTech as well the possibility to create and manage own digital regional currency. And as payments with Taler are fast, mobile-friendly and dead-simple they can compete with the convenience of Apple Pay, Google Pay and co, while guaranteeing that the money stays within the regional economy. On a smaller scale (such as e.g. youth centers or street festivals) this exact tech stack can be used to run completely private and digital token or voucher systems which can run entirely without an connection to the outside world or an internet uplink. ## __Roadmap to Adoption__ GNU Taler isn't just an academic paper or a proof of concept anymore as it's gaining some traction. One of the biggest drivers is the NGI Taler initiative by the **European Commission** and the **Swiss Government**. Run in partnership with organizations like the **NLnet Foundation** , its explicit goal is to bring Taler to market across Europe as a production-ready, best-in-class electronic payment system. Even in the discussion of establishing **Central Bank Digital Currencies** (CBDCs) – like an **digital Euro –** does GNU Taler stand out as an strong alternative and even national banks have come forward to state their support for GNU Taler and the Swiss National Bank (SNB) highlighted the technical feasibility in it's Working Paper 3/2021. ## Taking back the Wallet The real power of GNU Taler isn't just the cryptography but that it successfully challenges the Status Quo. Taler proves that digital convenience doesn't inherently require to give up privacy and submit to surveillance capitalism or speculative financial bubbles. For privacy advocates and the open source community are protocols like Taler a missing piece to the answer to the digital sovereignty question. We already have reclaimed our communication with decentralised and/or open source tools, our hosting with independent infrastructure and our development environments with FOSS alternatives. It is only logical to think about doing the same thing to our financial transactions. Whether GNU Taler is ultimately adopted as the blueprint for a digital Euro or simply spun up by communities to power (local) economies, it shows us what an ethical digital future can look like. It's cash, completely upgraded for the Internet age and the infrastructure is completely open to build upon. **_Have you already tried GNU Taler or not? Let's talk about it! And come back when this series continues._** 🪙 If you want to hear more from me you can find me in the Fediverse at @gelbphoenix@social.gelbphoenix.de (Mastodon) or @gelbphoenix@gram.social (Pixelfed). For more posts like this subscribe to my newsletter or support me by becoming a member or donating.
000
Phoenix Paulina Schmid @posts.blog.gelbphoenix.de.ap.brid.gy · 20/05/2026
Deconstructing Commercial Media and Why Words matter
blog.gelbphoenix.de
Why I Call It "Commercial Media"
If you have interacted with me you might have seen me use the term **"Commercial Media"** instead of **"Social Media"** for platforms like **Instagram** , **TikTok** , **YouTube** , **Twitch** and co and use the term "Social Media" for the Fediverse. This isn't about semantic nitpicking or an attempt to be different and difficult. It's about language and how we perceive reality. For over a decade we have allowed a handful of conglomerates to dictate the terms of our digital interactions. It's a category error to call platforms like Facebook, Instagram or TikTok "Social Media" as it mistakes the user's activity for the platforms purpose. It should be time to look past the "pretty" interfaces and take the infrastructure into view. ## __Intent versus Infrastructure__ People defend these platforms usually with a single boiled down argument: "I use it to talk to my friends, find my community and share my art. That is social!" That's right. We Humans are inherently social and cooperative beings. If you would trap fifty people in a cooperative mall for hours you would see that those people have formed a community. They will eventually sit down, share stories and laugh because someone told a joke. But this wouldn't turn the mall into a public park or a community center as the mall was still build and engineered from the ground up to show advertisements, hold lots of foot traffic and extract money from your or anybodies presence. This logic also applies on the internet. The users intent is social, to form connections, help each other and express ourselves. The platforms infrastructure on the other hand is commercial, to maximize the daily active users, extract behavioural data and monetize it. _****If you like this blog post you can support my work by either becoming a paid member or leaving a tip.****_ Donate When we call it "Social Media" we center the conversation on our behaviour, calling it "Commercial Media" does it finally center the business model of the platforms. ## __Cost of the "Social" label__ Words have power. Platforms labeled as "Social" carry the connotation of public utility and we trade it like a public town square. But a true public town square doesn't require you to sign of data-harvesting agreement just to walk across the pavement and it doesn't employ hundreds to thousands of data scientists to engineer psychological traps to keep you staring. By framing these spaces as social do we internalize their systemic failures. When algorithms feed us outrage to boost engagement and activity, we blame "human nature" or "toxic internet culture". When we find ourselves doomscrolling at 2:00 AM, we blame an own "lack of discipline". But it isn't a failure of our willpower it's the success of highly optimized commercial products. You aren't failing to socialize but successfully being monetized. The algorithms do exactly what they were coded to do. ## __Changing Vocabulary, Reclaiming the Web__ Rebranding this in our speech does matter because it strips away the illusion of the unearned goodwill of these corporations and forces us to view a timeline on these platforms not as a stream of human consciousness but as ad-delivering mechanisms that tolerate human interaction to keep lights on. Once you see the commercial nature of these platforms that illusion shatters and you realise that those commercial platforms can't be reformed because they function exactly as intended. But the solution isn't to stop being online socially. It's time to move social lives to spaces especially designed for human beings and not shareholders. That's why the Open Social Web, self-hosting, federated protocols and decentralised spaces matter as they aren't just technical alternatives but ideological refusals to let our relationships be treated as resources for surveillance capitalism. **_Next time you talk about the Commercial Web, call it what it is. Words matter and on Commercial Media are you the product._** If you want to hear more from me you can find me in the Fediverse at @gelbphoenix@social.gelbphoenix.de (Mastodon) or @gelbphoenix@gram.social (Pixelfed). For more posts like this subscribe to my newsletter or support me by becoming a member or donating.
000
Phoenix Paulina Schmid @posts.blog.gelbphoenix.de.ap.brid.gy · 02/05/2026
Why Bluesky’s "ATmosphere" isn't the blueprint for a truly free Fediverse.
blog.gelbphoenix.de
The Glass Floor of Digital Sovereignty
When many talk about the Fediverse, they mean the "**Open Social Web** " – an collection of every platform that isn't a walled garden – including **Bluesky**. The platform – that was published in 2022 and has since then ever grown – has opened itself to Personal Data Servers (PDS) that can either be hosted by an third party or yourself. That fact gave me an question about if we really want and need the Bluesky kind of federation for the Fediverse or not. My answer – and here a spoiler alert – is a "No". Let me explain this for you. ## __What is the basis of Bluesky?__ Unlike the Fediverse wasn't Bluesky build upon the ActivityPub protocol – which is an official recommendation of the World Wide Web Consortium (W3C) – but Bluesky (the company) build an own protocol – the "**Authenticated Transfer Protocol** " or short "**AT Protocol** " ("ATproto"). Where ActivityPub functions more like E-Mail and SMS do (I explained the exact way in the linked article) does ATproto differentiate. The AT Protocol isn't exactly build to have separate servers but (simplified) three different layers: 1. **Personal Data Servers (PDS)** : These are where your content and digital live in the "ATmosphere" (a term for the ATproto space) lives. 2. **Relays** : Massive aggregators that crawl every PDS instance to create a "fire hose" of all global content. 3. **AppView(s)** : This is the frontend (or frontends) which you see and use to interact with the ATproto content. It also is responsible to create your feed out of the content that the underlying Relay provides. ## __The problem__ This layering is exactly where is see the problem. While the design of ATproto achieves to create identities that can be used for every type of content without having to create multiple accounts does it give control over your digital live to at least one third party that you generally don't know or control. This is most likely the operator of the relay that is connected with your PDS. While you can easily host an own PDS for cheap and low power does the story change if you want to control and host anything above this layer. To host and maintain an Relay is a massive network infrastructure project which needs the respective hardware specs. This makes it for home labs and private individuals technically and economically out of reach, not just difficult. Therefor creating a **"glass floor"** problem for digital sovereignty where you can own and control your data but not the pathways that deliver it as Relay providers can also block you as easy as any commercial media company (e.g. Meta, Google, X). ## __The gap of Sovereignty__ If I don't like how an Fediverse instance is operated or moderated. Or I just want to be on one with my friends then I just can move to a smaller instance or start an own instance. The style of federation that ActivityPub has ensures that rules of engagement and content are set by people I actually interact with. This isn't the case with how ATproto is designed. In the "ATmosphere" do the Relays and AppViews become gatekeepers of network visibility. If the operator of the largest Relay – Bluesky (the company) – decides to ban your PDS from their relay you aren't just blocked from one instance but invisible to anyone (the majority of the "ATmosphere") using that Relay to get their content. ## __The trade-off__ The argument for Bluesky and the AT Protocol is often performance. It is fast and handles viral moments better than ActivityPub. That is true but at what cost? We trade digital sovereignty with technical convenience when we choose the streamlined algorithmic efficiency of ATproto's infrastructure with the sometimes slow and messy server-to-server nature of the Fediverse and ActivityPub. The Fediverse is build on principles similar to Federalism and Subsidiarity. The fragmentation of the Fediverse – which many criticise – is a feature, not a bug. Especially in context of digital sovereignty. In the ActivityPub based network of instances does the "small world" server-to-server communication mean that there is no single point of failure – technically and/or politically. (Like it was the case with Bluesky) ## __Conclusion__ We don't need fancier versions of commercial media platforms and including Bluesky and ATproto in the Fediverse dilutes the meaning of the decentralisation that the Fediverse stands for. We would be accepting a whole network where the pathways are owned by a few massive entities which don't have to respect our values. Digital sovereignty doesn't just mean to own your data but also to own the means to work with and distribute said data. My No to the Bluesky kind of federation is not meant to discredit the existence of the platform as a whole and as part of the wider "Open Social Web". It's a fascinating experiment in network and protocol design as well as account portability. However it shouldn't be a blueprint for the future of the Fediverse. (Except for some features like "Starter kits".) Where the Fediverse is a network of allotments and community gardens is Bluesky a park owned by a corporation that lets us just enter. Both have their place, but only one is truly sovereign. **_What do you value more: the lightning-fast speed of a centralized relay, or the messy, resilient freedom of a sovereign instance? Let’s discuss this on the Fediverse._** If you want to hear more from me you can find me in the Fediverse at @gelbphoenix@social.gelbphoenix.de (Mastodon) or @gelbphoenix@gram.social (Pixelfed). For more posts like this subscribe to my new newsletter or support me by becoming a member.
000
Phoenix Paulina Schmid @posts.blog.gelbphoenix.de.ap.brid.gy · 26/04/2026
Why a Federal Europe and the Web needs to be federated
blog.gelbphoenix.de
The Architecture of Autonomy and Freedom
On the sixth of December 2025 I published an blog post about why we need a sovereign Europe. Back then I focused on the political shift of the US that happened in 2025 with and after the second inauguration of US President Donald Trump. That shift was and is a wake-up call to us Europeans. Our data, identities and security are in some sort or way in the hands of Washington DC. Sovereignty isn't just about trade agreements or military aid, it's also about the very infrastructure of our daily lives. If we want a united Europe then we can't build it upon rented infrastructure and security. European democracy can't survive when it's public discourse is hosted and controlled by platforms and algorithms designed in California and governed by the whims of billionaires. ## __The Digital Dimension of Subsidiarity__ In politics and in the context of the confederation that the European Union already is do we talk about subsidiarity – the idea that matters should be handled at the smallest and most regional authority. It's a idea designed to prevent a concentration of power and respect local autonomy. But we have ignored this idea in our pockets while we continue to fight for it in the European Parliament as well as our national parliaments. Our current digital lives as European societies are the antithesis of subsidiarity – they are hyper-centralised and governed by an approach where a single decision in a company headquarters in Silicon Valley or Texas can sway elections in Warsaw, Berlin or Bucharest. ## __A digital and technical mirror__ At this point does the Fediverse come into perspective – not as a collection of niche apps but as a technical mirror to the European project. We are essentially talking about digital subsidiarity when we talk about ActivityPub and decentralised networks. In the Fediverse a so called "instance" (commonly also referred to as a server) is like a EU member state or your local city/municipality. Instances have their own rules, culture and moderation – much like I described the necessity for Europe to have independent control in the blog post mentioned at the top of this blog post. Yet they form a united front because they basically speak the same open language. It's a federation that respects the individual while empowering collectives. ## __Security Policy "Protocols, not Platforms"__ We are outsourcing our sovereignty if we continue to host our digital discourse on proprietary platforms. For a united federal Europe to be resilient our public institutions – from the European Parliament to the local town administration – must inhabit a digital space they actually own. We don't need a "European [add US social media platform]" – that would be just a different kind of centralised trap – we need a commitment to open protocols for our digital infrastructure. By moving our digital hangouts and town squares to decentralised protocols we ensure that no single entity – be it either governments and/or a volatile billionaires – can pull the plug on our democratic discourse and exchanges. ## __Building the European Digital Town Square__ The 2025 wake-up call taught us that "strategic and tactical autonomy" is a hollow phrase if we don't own the very infrastructure and source code. At this time are we at a crossroads – we can remain digital tenants or we can become digital citizens in a decentralised web. A Federal Europe requires a decentralised and federal web. That point means that we Europeans need to invest in decentralised and open source infrastructure as diverse and resilient as us Europeans. It also means recognising that every Mastodon instance, every PeerTube node and every Forgejo server is a small part in the independent European digital town. ## __Conclusion__ This isn't a task for just Brussels, national or state governments but a mission for all of us. When we – Europeans, Americans or where ever we are on planet Earth – choose to host our own data, to contribute to open source projects or to move out communities to decentralised platforms (like for example in Moving The Hangout) are we performing an act of digital state building. We can prove that a different internet is possible – one which isn't used as an weapon of influence but as a tool for real connection. As like the future of Europe is federal so must be the web too. Instead of the ashes of the walled garden centralisation let us build a (digital) home that really belongs to us. **_The Future of Europe and the Web is Federated. Are you ready to join the it?_** If you want to hear more from me you can find me in the Fediverse at @gelbphoenix@social.gelbphoenix.de (Mastodon) or @gelbphoenix@gram.social (Pixelfed). For more posts like this subscribe to my new newsletter or support me by becoming a member.
000
Phoenix Paulina Schmid @posts.blog.gelbphoenix.de.ap.brid.gy · 25/03/2026
Why your Community and Friends should move to Matrix
blog.gelbphoenix.de
Moving the Hangout
When **Discord announced** that **mandatory age verification** will be rolled out (I wrote about it here), I recommended that you to switch to the **Matrix protocol** and explained what is generally is. In the time between this and the linked post Discord has delayed the rollout of the age verification policy and doubled down on it. Now you could possibly think something like "_But my friends and communities are on Discord"_ and I want to give you here reasons and argument points for why you, your friends and the communities your part of should switch to, not just visit, the **[matrix]**. ## __The trap__ "Inference" is just another word for Surveillance The age verification policy of Discord that will be rolled out in 2026 relies on Age Inference models that will guess your age based upon multiple factors like activity patterns, payment methods and device data. This is instead of just blatantly ask for an ID of you – which they will still do if they "doubt" you. This is **behavioral profiling** – not "safety". This won't protect minors from harm on Discord's platform but opens up that this data about you is collected and sold to both bad actors and government agencies which can't collect that data themselves. Discord is moving from being a chat app for gamers and communities to a profiling engine for bad actors, companies and governments. ## __The Fallacy of the Network Effect__ Many people will find it hard to leave Discord because of the **Network Effect** – an idea that a tool or a platform is only useful if you are there too. That economic phenomenon is specifically targeted to trap you in Walled Gardens. But leaving Discord for an open protocol doesn't have to mean to leave your friends and communities behind. **It is more about moving houses, not people.** ## __The Sovereign Alternative__ Your House, Your Rules A – if not the biggest – misconception about the move from Discord to [matrix] is that you could lose the feel that Discord has. There are of course some changes but the ecosystem around [matrix] has matured to a point where it isn't a and no longer feels like an compromise. Older Matrix clients felt like a terminal where Discord had a "digital living room" vibe. But with Matrix 2.0 this changed and clients like **Element** , **Element X** and **Cinny** support **Spaces** (similar to Discord's servers), **nested rooms** and with **MatrixRTC** a native voice and video call feature that rivals the voice channels of Discord – without the lag of a crowded **Jitsi** server. ## __Don't burn the bridge__ How you can reach your friends from the Matrix Where in this post I explained how you can start with [matrix], should the focus here be how you can reach your friends and communities from [matrix]. We can do that with co called "Bridges". In the Matrix protocol ecosystem **bridges connect** external **services with Matrix.** There are bridges for platforms like **Signal** , Meta's **WhatsApp** , **Slack** and Discord. The full list of services that can be bridged can you see here. But know that bridges won't work in end-to-end encrypted rooms For Discord we can use either the mautrix-discord__ bridge – __ if you want to self-host the bridge – or the bot from __ t2bot.io. You can also the other bridges to Discord or even bridge other services and messengers to Matrix and make our [matrix] Account a sort of "Super-App". ## __Security: Choice, not Setting__ Why [matrix] over Discord or messengers like WhatsApp and Signal? When you use Discord your messages, shared files are stored non encrypted on their servers. Video and voice calls on Discord are since March 2026 via their "DAVE" protocol end to end encrypted (E2EE). While the addition of this is an win for privacy does it show an fundamental difference in philosophy. Discord's encryption of voice and video calls as well as the encryption on messengers like WhatsApp**** and Signal are centralised E2EE solutions. Even if their encryption protocols are open source do the companies behind the platforms and messengers own the infrastructure on which they run aka (the literal "keys to the kingdom"). On Matrix is encryption not an feature to be added to a product but an essential part of the protocol. That is also the reason why governments (for example the governments of **France** and the **UK**), militaries (for example the **German Bundeswehr** and the **US Navy**), international organisations (like **NATO** and the **UN**) and companies (like **Hexagon** and **Mozilla**) use the Matrix protocol. And because of the open source and federated nature of the protocol is it also a solution if legislation similar to the existing Chat Control 1.0 and proposed Chat Control 2.0 in the European Union is more widely enacted. ## __Reclaim your Digital Space and Independence__ The move away from an engine of behavioral profiling and walled garden to an open source and federated space is not just an technical choice but the reclaiming of your digital sovereignty and independence. And it isn't one large step but a series of smaller steps and only so far as you want. If you also follow the "BuyFromEU" movement (or regional variants) then is also a big reason to do this switch the fact that Discord is a company based in the Californian city of San Fransisco. [matrix] itself is developed by an Foundation based in the UK. So if you want to start switching to [matrix] you can look at the tutorial in this post on how to do that. **_Are you and your friends switching? Either reach out to me on Matrix, join the Matrix space for paid members or comment._** 💬 If you want to hear more from me you can find me in the Fediverse at @gelbphoenix@social.gelbphoenix.de (Mastodon) or @gelbphoenix@gram.social (Pixelfed). For more posts like this subscribe to my new newsletter or support me by becoming a member.
000
Phoenix Paulina Schmid @posts.blog.gelbphoenix.de.ap.brid.gy · 17/03/2026
A deep dive into Libre Workspace
blog.gelbphoenix.de
Open-Source Alternative to Microsoft 365 and Google Workspace
**Libre Workspace** is a crucial part of my self-hosting infrastructure, running smoothly on one of my VPS instances at Hetzner¹. (As I wrote in **Why I Still Self-Host**) In this article we'll explore what Libre Workspace exactly is, how you can run it and what it replaces. ## Libre... What? Libre Workspace is an modular server platform which aims to be an alternative to Microsoft 365, Google Workspace and co. It relies only on free and open source components as its core. The collaboration platform is modular and developed as a free and open source (FOSS) project with its **repository** on Codeberg. The project includes in its core **Nextcloud** with either **Collabora Office** or **ONLYOFFICE** as its Cloud and Online Office solutions, **Matrix** with the **Element** Web Client as an alternative to Microsoft Teams, **Jitsi** as its web meeting and call solution, **Guacamole** for the Cloud Desktop and Samba AD-DC for centralised user and group management. Libre Workspace is also extendable with addons which are available via either the included Addon Manager or the **Libre Workspace Forum**. Some of the available Addons (official ones also have their repositories on Codeberg under the Libre Workspace organization) include **Immich**, **Mailcow****** and **Vaultwarden**. ## How to run it? You have decided to run Libre Workspace and have four ways to do it. One is that you decide to use the offer of **Libre Workspace Cloud** the let the developer of Libre Workspace manage it for you. The smallest offer only costs 12,30€/Month If you want to run it on your own hardware you can either do the setup and management yourself or use the offerings of **Libre Workspace Pilot**. If you want to also use addons or software that needs constant access to the wider internet (like Mailcow or **Mastodon**) then it's more preferable to setup Libre Workspace on an VPS. Here can you also use the One-Time Setup Service of Libre Workspace Pilot or you can do it yourself via the methods described in the **documentation** of Libre Workspace. ## Conclusion The project Libre Workspace simplifies self-hosting for me. It's Open ID Connect Provider allows me to use my account on my Libre Workspace instance to connect to multiple different self-hosted software and services. **_Are you already self-hosting your workspace, or are you still relying on Microsoft and Google? Let me know in the comments or join the discussion on the Fediverse or the Libre Workspace forum!_** If you want to hear more from me you can find me in the Fediverse at @gelbphoenix@social.gelbphoenix.de (Mastodon) or @gelbphoenix@gram.social (Pixelfed). For more posts like this subscribe to my new newsletter or support me by **becoming a member**. * * * ¹ [Affiliate Link: Following this link gives you $20 in Hetzner Cloud Credit when registering]
001
Phoenix Paulina Schmid @posts.blog.gelbphoenix.de.ap.brid.gy · 09/02/2026
Escaping Discord’s upcoming age verification wall
blog.gelbphoenix.de
Your Face or Your Features
On the 9th of Feburary 2026 Discord announced that they will roll out their age verification requirement worldwide. This would require every account to basically dox themselves to access every feature as accounts are being set to a teen experience per default as long as they don't verify their age with either a face scan or an photo of their government-issued ID. This brings criticism from Discord's users and privacy minded people because this policy treats every user like they are a teenager unless they give Discord their personally identifiable data. And that despite the fact that Discord already lost user data and IDs of ~70.000 users of the platform in a massive data breach in October of 2025 as news sources like The Verge reported. ## __What can you do about it?__ With the rollout happening in early March 2026 users have to prepare to either one of these options: live with a massively reduced feature set, having to give Discord their data to regain access to the full feature set or leave the platform for other alternatives like IRC or the Matrix protocol. I personally are recommending the Matrix protocol ("[matrix]") because of following reasons: * **Decentralisation** : The Matrix protocol is inherently designed to be decentralised and therefor harder to regulate than a centralised platform. * **Open Source** : The protocol is completely open source meaning that even if a government tries to ban the protocol or tries to influence it to be worse can people take the source code and make it into another project. This point plus the decentralisation also allows the community to develop different servers so that admins have a choice which one they want to host. * **E2E Encrypted** : [matrix] is also inherently designed to have end to end encryption per default. Meaning that your messages are only readable by you and the ones who you send messages to. No admin, government or other people can read your messages. * **Interoperability** : You can easily use different clients (like Element, FluffyChat and Cinny) and can even use bridges to chat with people using other services and protocols. * **Self-hostable** : If you don't want to trust an server admin or want to provide an server for your friends and family you can do that. ## __How can I start?__ Short tutorial to start with Matrix If you want to follow my recommendation and start using Matrix you can do the following steps: 1. **Find a server you want to join.** This can be whatever homeserver (as they are called by [matrix]) you like. Either the main matrix.org homeserver or other homeservers like tchncs.de or socialnetwork24.com. 2. **Create an account.** Creating an account on an homeserver can include different requirements. Like providing an e-mail address for account recovery and solving an captcha for bot prevention. 3. **Add another devices and start chatting with other people.** After creating your account and logging in you can start to chat with other people or join rooms – even those on other homeservers if your server allows federation. You can also add other devices like your smartphone or an desktop client. ⚠️ ****Keep your recovery key save.**** Without it you loose access to all of your chats if you loose access to your account and nobody can help you with that. So please either print it out and/or secure it in your password manager. ## __How to move your friends?__ The hardest part of leaving Discord isn't the software; it's the network effect – convincing your friends to come with you. Don't force a full switch right now. It doesn't mean that you can't try to convince your friends to switch – you definitely can do that but it shouldn't be a reason to argue about. Discord has made its choice to prioritize surveillance over user trust. Now, we have to make ours. **_If you decide to make the jump, feel free to_**** _reach out to me on Matrix_**** _– I’ll see you there!_** 💬 If you want to hear more from me you can find me in the Fediverse at @gelbphoenix@social.gelbphoenix.de (Mastodon) or @gelbphoenix@gram.social (Pixelfed). For more posts like this subscribe to my new newsletter or support me by **becoming a member**.
000
Phoenix Paulina Schmid @posts.blog.gelbphoenix.de.ap.brid.gy · 06/12/2025
blog.gelbphoenix.de
A Sovereign Europe: The West's Last Stand for Democracy
Since Donald Trump’s second inauguration in the end of January 2025, the West’s geopolitical environment has changed dramatically. Washington has shifted from a broadly cooperative transatlantic stance under the previous Biden-Harris administration to a far more confrontational, transactional posture. If this trajectory continues, it amounts to a 180° reversal in U.S. policy toward Europe. ## How did this came about? After the second Trump administration started its term on the 20th January 2025 it was fast to reduce much of the US economic and logistical support for Ukraine – which is in a defensive war against Russia since 2022 – and started to spread views and falsehoods against Europe. The new escalation of the deterioration of the transatlantic alliance was the "Liberation Day" where the European Union as a whole market was hit with tariffs of twenty percent – a symbol against a strong and united European Common Market capable of competing with US economic hegemony. This did cause a worldwide reaction – other countries were themselves hit with a tariff of at least ten percent –, retaliatory tariffs and the starting of communities like Buy from EU. ## Newest developments In the start of December 2025 was a new National Security Strategy paper released by the second Trump administration. You would think "so far – so good" but that paper is different from older National Security Strategy papers as this is not a routine rewording of old talking points. The new US National Security Strategy recasts Europe less as a partner to be steadied and more as a theatre in which Washington will pursue transactional bargains and – in places – actively shape domestic politics and political landscapes. It also shifts the adversary position from Russia to the European Union and proposes that the US should “cultivate resistance” inside Europe. Which means that what had long been framed as “common interest” between Europe and the US – shared values, collective defence, coordinated diplomatic posture – is now being replaced by a transactional, interest‑first paradigm. For many European states, this risks undermining decades of post‑war integration and cooperation. After three years of large-scale US support, international trackers show a sharp decline in some categories of military aid through mid-to-late 2025 – even as humanitarian and EU funding streams remain active – leaving Kyjiw to rely more heavily on European and multilateral support mechanisms for urgent requirements. ## What comes now? If the current trajectory of US foreign policy continues – transactional, ideologically driven, and dismissive of Europe as a partner – then Europe must stop treating the US as a security guarantor. Instead, it ought to embrace sovereignty and collective resilience. Because the reality is stark: in a world of shifting power balances, Europe’s survival as a global actor depends on its ability to act independently and united. **The US was a shining beacon of democracy and freedom.** The stature of liberty is a symbol of that. If the current trajectory of US policy continues to move forward then this position changes and the beacon of democracy will become another authoritarian state in this world. When and if that happens a united Europe would stand alone for democracy and it's values and if it accepts that it can no longer take foreign guarantees for granted, it may rediscover and reinforce its own strengths: political cohesion, economic integration, and a shared commitment to pluralistic democracy. **A sovereign, self‑reliant Europe that acts with confidence and solidarity could become not a vassal of global power games, but a proactive actor shaping its own destiny.** If the U.S. falters, Europe may yet rise – not as a follower, but as a beacon of stability. And maybe, in that transformed Europe, the values once championed by the West will endure – because they were defended by Europeans themselves. **_Have you reacted to the policy changes from the US – either personally and/or work-related? Let's discuss!_** 🗽 If you want to hear more from me you can find me in the Fediverse at @gelbphoenix@social.gelbphoenix.de (Mastodon) or @gelbphoenix@gram.social (Pixelfed). For more posts like this subscribe to my new newsletter.
000
Phoenix Paulina Schmid @posts.blog.gelbphoenix.de.ap.brid.gy · 21/11/2025
blog.gelbphoenix.de
Forgejo: The fresh outlook on Software Forges
Self‑hosting a site like **GitHub** or **GitLab** has never felt more “right” than it does now. **Forgejo** – the fork of **Gitea** that prides itself on lean code, speed, and enterprise‑ready features – is delivering a wave of improvements that make it an ideal choice for teams and solo devs alike. Below is a quick rundown of the most recent updates and the practical implications for your workflow. * * * ### 1. Forgejo's history Forgejo itself was forked from Gitea in 2022 because of the – sort of hostile – takeover of the Gitea peoject by the for-profit company Gitea Limited. The initial fork – which was carried out after the leadership of the Gitea project didn't responded to an open letter – was a so called "soft fork" but it was changed in 2024 to a "hard fork" (difference is that the project that has hard forked doesn't actively contribute to the former upstream project). After becaming a hard fork independent from Gitea was Forgejo attacked by maintainers of Gitea over the functioning of Git when the Forgejo maintainers cherry picked commits merged into Gitea despite that the Forgejo maintainers respecting the licence of the Gitea code. * * * ### 2. Security Boosts – 2FA, EXIF Stripping, and Actions Secrets * **Global Two‑Factor Enforcement** – With the new `security.GLOBAL_TWO_FACTOR_REQUIREMENT` setting, administrators can enforce TOTP (or other 2FA methods) for all users or just admins. This adds a solid layer of protection against credential‑stealing attacks. * **Avatar Privacy** – Forgejo now strips EXIF data from uploaded avatar images automatically. This small but important step removes the risk of leaking personally identifiable information (e.g., GPS coordinates) when sharing profile pictures. An admin can run the `forgejo doctor avatar-strip-exif` command to purge existing avatars of metadata. * **Secrets Management** – Secrets used in Actions are now handled by a more secure module introduced in 2024, already in use for TOTP secrets. This tightening reduces the attack surface for compromised repositories. * **Action Logs** – You can now view previous logs for retried Actions runs via a convenient dropdown, giving greater transparency into CI/CD pipelines. All these changes collectively tighten Forgejo’s security posture while keeping the user experience smooth. [3] * * * ### 3. Usability Enhancements * **Action Retry Visibility** – By adding a UI element for previous action attempts, developers can diagnose failures without digging through logs. * **Avatar Image Privacy** – The aforementioned EXIF stripping not only protects privacy but also reduces storage overhead by eliminating unnecessary metadata. * **Federation** – Forgejo works on implementing the ActivityPub protocol to federate software forges with each other. These incremental UI/UX tweaks make Forgejo a more developer‑friendly platform without adding bloat. * * * ### 4. Migration Path from Gitea If you’re moving deployments from Gitea, Forgejo provides a dedicated migration tutorial. Like Gitea Forgejo has migration tools to migrate or mirror repositories from other forges like GitHub, GitLab and co. You can even mirror your repositories from your Forgejo deployment to other forges. * * * ### 5. Installing Forgejo This pushed you to install Forgejo? Here's how you can install the software forge with Docker. Forgejo can be installed on either your own server in your Homelab or on a Virtual Private Server (e.g. from Hetzner¹) > _This requires that you have already installed Docker and Docker Compose on the install system._ At first we either use the Docker Compose example from Forgejo or an boilerplate repository (for example: My own boilerplates repo). Depending on which example you have chosen can you make your own changes and you should change the password for the database. If you want to use the existing SSH daemon on your system for Forgejo too you can follow the README for forgejo in my boilerplates repository for steps to activate SSH passthrough for Forgejo. * * * ## Why Forgejo is Worth a Second Look * **Simplicity & Speed** – Forgejo is designed to be lightweight, meaning faster startup times and lower resource footprints than heavier alternatives. * **Self‑Hosted Control** – You decide where your code lives, how it’s backed up, and who has access. * **Active Community** – The rapid release cadence and active support channels (chat, RSS feeds) mean bugs are squashed quickly. * **Future‑Proofing** – With LTS branches and regular point releases, you can stay secure without constant upgrades. If you’re building a team’s internal repo, a hobby project, or simply want to own your code, Forgejo give you the confidence that the platform will stay secure, responsive, and feature‑rich for years to come. **_Happy coding and happy self‑hosting!_** 💻 If you want to hear more from me you can find me in the Fediverse at @gelbphoenix@social.gelbphoenix.de (Mastodon) or @gelbphoenix@gram.social (Pixelfed). For more posts like this subscribe to my new newsletter. ¹ [Affiliate Link: Following this link gives you $20 in Hetzner Cloud Credit when registering]
000
Phoenix Paulina Schmid @posts.blog.gelbphoenix.de.ap.brid.gy · 16/08/2025
blog.gelbphoenix.de
Roblox: A Safehaven for Extremists and Predators
> **_CONTENT NOTE: > This article discusses child exploitation and extremist content in the kids online gaming platform Roblox. > Reader discretion is advised._** The gaming platform Roblox, a digital universe with nearly 400 million monthly users, is currently facing a significant crisis that calls into question its ability to moderate its content and protect its predominantly young user base of kids and minors. Recent events, particularly the banning of a popular user and content creator known as "Schlep" has ignited a firestorm of controversy, highlighting long-simmering concerns about extremism, child safety, and corporate negligence on the platform. ### **The 'Schlep' Controversy: A Tipping Point** The recent turmoil began when Roblox send a cease and desist to and banned popular user, content creator and activist Schlep, who had been exposing predatory content on the platform and who helped to arrest at least six predators. In response to his ban, Schlep announced his intention to sue Roblox, a move that reportedly caused the company's stock prices to plumet. This action by Roblox has been widely criticized as an attempt to silence a whistleblower rather than address the underlying issues he and others exposed. The backlash was swift and widespread, sparking a debate about the effectiveness of platform moderation versus the actions of vigilante users. Critics have accused Roblox of hypocrisy, suggesting the company prioritizes legal threats over the safety of its child user. This sentiment has fueled campaigns like "#FreeSchlep" and "#BoycottRoblox," which have gained support from major content creators. A petition demanding that Roblox CEO David Baszucki "fix what he’s caused or resign" had already gathered over 90,000 signatures at the point of writing. While Roblox released a statement explaining its policy on removing "vigilante groups," it did not mention Schlep by name but by assosiation. In Roblox's statement from the 13. August 2025 the company compared vigilante groups and individuals to actual predators. This caused for another outcry as many saw this also as Roblox directly comparing Schlep with actual predators. Some big Roblox focused content creators have left the companys "Star Program" since Schlep was banned from the platform. ### **A Breeding Ground for Extremism** The issue of extremism on Roblox is itself not a recent phenomenon; the platform has been a fertile ground for far-right and hateful ideologies for over a decade. This exploitation of the user-generated platform has manifested in various alarming ways, from the creation of a Nazi gas chamber simulation, which Roblox eventually removed, to games that simulate vehicle attacks against protesters, mirroring a common trope in far-right memes. Critics have identified specific games as "known extremist [and/or] nazi hub[s]," which Roblox has allowed to persist for years. Beyond hosting such content, extremists have used the platform's name and context for recruitment and radicalization on other sites like Telegram. The research group Tech Against Terrorism discovered messages containing bomb-making instructions disguised with references to the game, such as, “Hey kid, want to make a mailbox bomb for Roblox?” The danger has repeatedly spilled over from the virtual world into reality. In a particularly stark example, the FBI arrested a man who was allegedly using a game on Roblox – which is a known extremist hub – to plan a real-life terrorist attack. In another case, Roblox sued a YouTuber for $1.65 million after he made violent threats against a developers' conference and attempted to upload images of Adolf Hitler onto the platform. The platform's struggle with extremist content is ongoing and adapts to current events, as seen when the Israeli government urged users to report pro-Palestinian activity it claimed contained antisemitic content following the Hamas attack on October 7, 2023. ### **Allegations of Negligence and an Unsafe Environment** The platform's moderation challenges extend beyond extremist content. The controversy has brought renewed attention to Roblox's alleged "negligence toward protecting young players," which had previously been the subject of lawsuits in Texas. For years, parents and safety advocates have raised alarms about grooming, bullying, and exposure to inappropriate content on the platform. Critics argue that by banning a popular user and content creator who was actively trying to make the platform safer, Roblox has sent a chilling message that its corporate image and the happyness of it's investors is more important than the well-being and safety of its users. The current crisis facing Roblox is not merely about a single banned user. It is a symptom of systemic issues within a platform that has become a cornerstone of modern childhood. The community's response, through petitions and social media campaigns, as well as goverment lawsuits and media documentations indicates a deep-seated demand for accountability and fundamental change to ensure the digital playground is not a safe haven for those who wish to do harm. **_What do you think about this? If you're a Roblox user, have you drawn a consequence out of the ongoing situation?_** If you want to hear more from me you can find me in the Fediverse at @gelbphoenix@social.gelbphoenix.de (Mastodon) or @gelbphoenix@gram.social (Pixelfed). For more posts like this subscribe to my new newsletter.
000