It's easier than you are probably thinking, most that are labeled as 100% juice are preservative free. Look in the juice aisle next time and you'll see it's many or perhaps even most of them if they're actually sold as juice and not some kind of flavored soft drink. The ingredients and label will make it pretty clear, if it doesn't have any ingredients listed other than juice and maybe sometimes water you should be good to go.
In my experience you also need to do some extra things to get good cider though. You need to use cider-specific yeast and add yeast nutrient, and it needs to ferment cool. Stabilizing the end product (which will usually be bone dry) so you can add a bit of sugar (I recommend dark) also makes for a better, more apple-y flavor. All that said, you can make something drinkable even with a lot less care than that. Cider is fairly forgiving.
You should try a dedicated cider yeast rather than US-05. I kept being unhappy with the store juice ciders I tried to make, they always came out kind of thin and bland. Turns out cider specific yeast strains were what I was missing and the difference was dramatic. SafCider AB-1 is my favorite.
The hierarchy and usage of pronouns is complicated and the rules are fast and loose. Using first person boku in many situations as a man, and maybe even more as woman, has somewhat childish connotations. I've known adult Japanese women who preferred to use ore if they wanted a more tomboyish tone.
WG is not meant to be a stealthy protocol and is easy to detect at the ISP level. It has distinct characteristics that packet inspection tools can use to identify it by examining the traffic and block or flag it. Blocking it completely is trivial for any ISP, much less a nation.
There are modified versions like AmneziaWG that make it stealthier, or alternative protocols built to evade traffic inspection like xray or sing-box (these two are really more like protocol frameworks that have multiple protocols you can use). It's a bit of an arms race for packet inspection tools to be able to reliably identify these intentionally stealthy protocols, but the advantage is generally in your favor as long as you are using your own servers and not public VPNs. Though even then you need to take care to camouflage your traffic to be truly safe, like if you are shoving all of your traffic through one remote server that has approximately the same amount of traffic going out immediately etc that is something that can also be identified.
How much precaution is actually warranted depends on where you are and what the potential consequences are. You don't have to go to a full tinfoil hat paranoia level setup to avoid most blocking.
See also, xray and v2ray, which are similar, but in my experience sing-box is a bit better documented (at least in English) and has better maintained client apps.
Setting any of these up can be complicated, but LLMs can get you pretty far if you have safe access.
I used to live nearby, it always seemed empty whenever we drove by, every time. I dunno how it survived, I think the owner must have had money to burn because they always had a rotation of nice classic cars parked outside. Knew it must have been the owner's though because it was the same rotation of 5 or so.
You can do most everything Tailscale does with native Wireguard, it's just a lot of work to manage any of what Tailscale does beyond the most basic. It's a lot of convenience on top of Wireguard. If you just need a basic "I want my phone to easily get back to my home network" then I would probably stick to Wireguard (and maybe a GUI on top like wg-easy). If you want to do more complicated stuff, like link multiple sites, mesh routing between multiple networks, sophisticated user access controls, etc, Tailscale starts to be maybe be worthwhile. Or another solution, I personally actually prefer to use Netbird, which is basically similar.
One thing it does do that native Wireguard does not is it includes a relay server, so that if two hosts can't actually reach each other directly they can still negotiate a direct connection or even fall back to using the relay server to communicate. This is useful if you're stuck behind something like CGNAT or other networking schemes where hosts may not be able to have a publicly routable IP address.
Tailscale (and Netbird) also offer one extra convenience which is they both have built in reverse proxies that integrate with the VPN network they generate. Strictly speaking that part is separate from Wireguard; you can also do that yourself but it's rather convenient. This lets you have publicly trusted TLS certificates and stuff for your internal sites and depending on how you use it can replace stuff like Cloudflare tunnels. So you can host sites without port forwarding.
FWIW I primarily use a native wireguard server with wg-easy for most of my VPN needs and I only really use Tailscale (actually, Netbird) for some specialized uses. Mostly replacing Cloudflare tunnels with something I fully control.
Best way to think about it is as an abstraction layer where you can make any computer anywhere talk to another one like they are on the same network without being. You can build networks however you want and it mosly just works. It became popular to do things like tie together multiple machines or networks in datacenrers or home or wherever and let them network together irrespective of the underlying isolation. At home people like to use it to let them access their home network and self hosted services on the go without having to expose anything to the Internet.
Under the hood it's mostly "just" a VPN with some extra convenience and controls, but it made VPN networking a lot more convenient.
What is your usage like? Are you a normal person? Homelabber? Content creator?
Ethernet gives you much more future proofing, and the ability to use power over Ethernet for things like wireless access points or security cameras. MoCA is pretty good for most uses as well, but probably at a dead end as a standard so it isn't going to get better. Re-pulling Ethernet is a huge pain in the ass, however, and should not be underestimated.
Maybe a hybrid setup, swap out a few critical lines for Ethernet and use MoCA elsewhere. Otherwise, if you're a heavy duty user its worth it to swap everything, and if you're more normal MoCA is plenty.
Is that a hot take? I see a lot of people saying this, including myself. Kubernetes solves problems at work, but is way overkill even for my moderately elaborate home setup that would cause more troubles than it solves. If people want to use k8s at home go ahead, but I don't.
I agree that there is some value to obscurity generally, but Wireguard already evades port scans and fingerprinting. Unless a packet is signed with a known key, it gives no response to traffic, so scanners and fingerprinters see a closed port. You ISP can identify WG traffic while you are connected by inspecting your traffic, but random scanners won't see anything. Look on shodan, you won't see Wireguard.
I ended up building it myself, which may be the best option if you want to use other plugins. I have it set up in my own Forgejo with a CI configuration to auto build the binary and docker image. Forgejo let's you also host container images, so I can just pull from the latest build wherever I need it.
Both those tools analyze service logs for suspicious activity and block based on patterns. If you aren't hosting anything externally, they probably aren't doing anything.
Crowdsec is probably more effective than fail2ban overall, but both are only part of a defense in depth strategy and are really last resort protection.
Its interesting, I have the HA Voice Preview and I've been trying out using Gemini as the brains. Yes I know this defeats the point, but it's an experiment and I wanted to see how the normal Flash model handles things.
It works great, nearly perfect. So whatever they have done to lobotomize their existing devices/assistant over the last year or so is not just Gemini being bad at it.
It's usually preferable to use a firewall rather than telling Caddy to bind to a specific address. Or do both. What I mean though is, you shouldn't neglect also configuring a firewall if this machine is public.
OO is significantly closer to MS office UI wise. As to why they forked it, OO was basically only open source on paper and didn't really accept external contributions. They tried to shut down this fork with some dubious legal claims that are blatantly in conflict with at least the spirit of the open source license as icing on the cake.
It's easier than you are probably thinking, most that are labeled as 100% juice are preservative free. Look in the juice aisle next time and you'll see it's many or perhaps even most of them if they're actually sold as juice and not some kind of flavored soft drink. The ingredients and label will make it pretty clear, if it doesn't have any ingredients listed other than juice and maybe sometimes water you should be good to go.
In my experience you also need to do some extra things to get good cider though. You need to use cider-specific yeast and add yeast nutrient, and it needs to ferment cool. Stabilizing the end product (which will usually be bone dry) so you can add a bit of sugar (I recommend dark) also makes for a better, more apple-y flavor. All that said, you can make something drinkable even with a lot less care than that. Cider is fairly forgiving.
You should try a dedicated cider yeast rather than US-05. I kept being unhappy with the store juice ciders I tried to make, they always came out kind of thin and bland. Turns out cider specific yeast strains were what I was missing and the difference was dramatic. SafCider AB-1 is my favorite.
The hierarchy and usage of pronouns is complicated and the rules are fast and loose. Using first person boku in many situations as a man, and maybe even more as woman, has somewhat childish connotations. I've known adult Japanese women who preferred to use ore if they wanted a more tomboyish tone.
What a cool cover.
WG is not meant to be a stealthy protocol and is easy to detect at the ISP level. It has distinct characteristics that packet inspection tools can use to identify it by examining the traffic and block or flag it. Blocking it completely is trivial for any ISP, much less a nation.
There are modified versions like AmneziaWG that make it stealthier, or alternative protocols built to evade traffic inspection like xray or sing-box (these two are really more like protocol frameworks that have multiple protocols you can use). It's a bit of an arms race for packet inspection tools to be able to reliably identify these intentionally stealthy protocols, but the advantage is generally in your favor as long as you are using your own servers and not public VPNs. Though even then you need to take care to camouflage your traffic to be truly safe, like if you are shoving all of your traffic through one remote server that has approximately the same amount of traffic going out immediately etc that is something that can also be identified.
How much precaution is actually warranted depends on where you are and what the potential consequences are. You don't have to go to a full tinfoil hat paranoia level setup to avoid most blocking.
Sing-box is a VPN tool built to evade censorship https://github.com/SagerNet/sing-box . It is extremely resilient and stealthy.
See also, xray and v2ray, which are similar, but in my experience sing-box is a bit better documented (at least in English) and has better maintained client apps.
Setting any of these up can be complicated, but LLMs can get you pretty far if you have safe access.
My partner eats muffins from the top down. Sometimes, I've caught her just eating the tops off the muffins and leaving the bottoms.
I used to live nearby, it always seemed empty whenever we drove by, every time. I dunno how it survived, I think the owner must have had money to burn because they always had a rotation of nice classic cars parked outside. Knew it must have been the owner's though because it was the same rotation of 5 or so.
You can do most everything Tailscale does with native Wireguard, it's just a lot of work to manage any of what Tailscale does beyond the most basic. It's a lot of convenience on top of Wireguard. If you just need a basic "I want my phone to easily get back to my home network" then I would probably stick to Wireguard (and maybe a GUI on top like wg-easy). If you want to do more complicated stuff, like link multiple sites, mesh routing between multiple networks, sophisticated user access controls, etc, Tailscale starts to be maybe be worthwhile. Or another solution, I personally actually prefer to use Netbird, which is basically similar.
One thing it does do that native Wireguard does not is it includes a relay server, so that if two hosts can't actually reach each other directly they can still negotiate a direct connection or even fall back to using the relay server to communicate. This is useful if you're stuck behind something like CGNAT or other networking schemes where hosts may not be able to have a publicly routable IP address.
Tailscale (and Netbird) also offer one extra convenience which is they both have built in reverse proxies that integrate with the VPN network they generate. Strictly speaking that part is separate from Wireguard; you can also do that yourself but it's rather convenient. This lets you have publicly trusted TLS certificates and stuff for your internal sites and depending on how you use it can replace stuff like Cloudflare tunnels. So you can host sites without port forwarding.
FWIW I primarily use a native wireguard server with wg-easy for most of my VPN needs and I only really use Tailscale (actually, Netbird) for some specialized uses. Mostly replacing Cloudflare tunnels with something I fully control.
Best way to think about it is as an abstraction layer where you can make any computer anywhere talk to another one like they are on the same network without being. You can build networks however you want and it mosly just works. It became popular to do things like tie together multiple machines or networks in datacenrers or home or wherever and let them network together irrespective of the underlying isolation. At home people like to use it to let them access their home network and self hosted services on the go without having to expose anything to the Internet.
Under the hood it's mostly "just" a VPN with some extra convenience and controls, but it made VPN networking a lot more convenient.
Its named after the Esperanto word, but the intended pronunciation is for-JAY-oh.
https://forgejo.dev/forgejo.dev/forgejo
Official pronunciation audio: https://forgejo.org/static/forgejo.mp4
The Princess Bride got this right. "Life is pain, Highness. Anybody who says differently is selling something."
What is your usage like? Are you a normal person? Homelabber? Content creator?
Ethernet gives you much more future proofing, and the ability to use power over Ethernet for things like wireless access points or security cameras. MoCA is pretty good for most uses as well, but probably at a dead end as a standard so it isn't going to get better. Re-pulling Ethernet is a huge pain in the ass, however, and should not be underestimated.
Maybe a hybrid setup, swap out a few critical lines for Ethernet and use MoCA elsewhere. Otherwise, if you're a heavy duty user its worth it to swap everything, and if you're more normal MoCA is plenty.
Is that a hot take? I see a lot of people saying this, including myself. Kubernetes solves problems at work, but is way overkill even for my moderately elaborate home setup that would cause more troubles than it solves. If people want to use k8s at home go ahead, but I don't.
I agree that there is some value to obscurity generally, but Wireguard already evades port scans and fingerprinting. Unless a packet is signed with a known key, it gives no response to traffic, so scanners and fingerprinters see a closed port. You ISP can identify WG traffic while you are connected by inspecting your traffic, but random scanners won't see anything. Look on shodan, you won't see Wireguard.
I ended up building it myself, which may be the best option if you want to use other plugins. I have it set up in my own Forgejo with a CI configuration to auto build the binary and docker image. Forgejo let's you also host container images, so I can just pull from the latest build wherever I need it.
Both those tools analyze service logs for suspicious activity and block based on patterns. If you aren't hosting anything externally, they probably aren't doing anything.
Crowdsec is probably more effective than fail2ban overall, but both are only part of a defense in depth strategy and are really last resort protection.
Its interesting, I have the HA Voice Preview and I've been trying out using Gemini as the brains. Yes I know this defeats the point, but it's an experiment and I wanted to see how the normal Flash model handles things.
It works great, nearly perfect. So whatever they have done to lobotomize their existing devices/assistant over the last year or so is not just Gemini being bad at it.
It's usually preferable to use a firewall rather than telling Caddy to bind to a specific address. Or do both. What I mean though is, you shouldn't neglect also configuring a firewall if this machine is public.
OO is significantly closer to MS office UI wise. As to why they forked it, OO was basically only open source on paper and didn't really accept external contributions. They tried to shut down this fork with some dubious legal claims that are blatantly in conflict with at least the spirit of the open source license as icing on the cake.