<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Nikos Roussos</title>
  <link href="https://www.roussos.cc/feed.xml" rel="self" />
  <link href="https://www.roussos.cc/" />
  <icon>https://www.roussos.cc/favicon.ico</icon>
  <logo>https://www.roussos.cc/static/img/me.jpg</logo>
  <updated>2026-10-01T12:35:19Z</updated>
  
    <entry>
      <title>39c3 notes</title>
      <link href="https://www.roussos.cc/2026/01/07/39c3/"/>
      <content type="html">
        <![CDATA[
          <p><img alt="39c3" src="/2026/01/07/39c3/39c3.jpg" /></p>
<p>This is a quick notes post about the recent <a href="https://events.ccc.de/congress/2025/infos/startpage.html">Chaos Computer Congress</a>. It was nice to participate again after two years.</p>
<h4>Talks</h4>
<ul>
<li>
<p><strong><a href="https://media.ccc.de/v/39c3-all-sorted-by-machines-of-loving-grace-ai-cybernetics-and-fascism-and-how-to-intervene">All Sorted by Machines of Loving Grace? "AI", Cybernetics, and Fascism and how to Intervene </a></strong><br>
The talk explores the roots of today's tech fascism and its love for tech. Full of nice rants.</p>
</li>
<li>
<p><strong><a href="https://media.ccc.de/v/39c3-a-post-american-enshittification-resistant-internet">A post-American, enshittification-resistant internet</a></strong><br>
A very condensed talk, in the usual style of Cory Doctorow. A bit optimistic, but the whole analysis definitely worths it.
I loved the phrase <em>"Time to seize the means of computation!"</em>.</p>
</li>
<li>
<p><strong><a href="https://media.ccc.de/v/39c3-ai-agent-ai-spy">AI Agent, AI Spy</a></strong><br>
Based on a Signal Foundation research. How AI compromises the trust we usually have on operating systems.
Very critical when you are relying on end-to-end encryption, making the assumption that you can trust both ends.</p>
</li>
<li>
<p><strong><a href="https://media.ccc.de/v/39c3-coding-dissent-art-technology-and-tactical-media">Coding Dissent: Art, Technology, and Tactical Media</a></strong><br>
Artistic practices that engage with sociotechnical systems through tactical interventions.
Showcasing certain Art/Tech projects with political impact.</p>
</li>
<li>
<p><strong><a href="https://media.ccc.de/v/39c3-suing-spyware-in-europe-news-from-the-front">Suing spyware in Europe: news from the front!</a></strong><br>
The current status of the legal action against European governments using spyware (like Pegasus and Predator) to spy on people.</p>
</li>
</ul>
<h4>Self-organized sessions</h4>
<ul>
<li>
<p><strong><a href="https://events.ccc.de/congress/2025/hub/en/event/detail/repressions-and-surveillance-of-pro-palestine-spee">Repressions and Surveillance of Pro-Palestine Speech in Germany</a></strong><br>
An overview of how German authorities have engaged in systematic repression of Pro-Palestine speech.
With a reference to a <a href="https://reclaimthenet.org/berlin-approves-new-expansion-of-police-surveillance-powers">new Berlin law</a> that allows police to physically compromoise devices by intruding into private homes.</p>
</li>
<li>
<p><strong><a href="https://events.ccc.de/congress/2023/hub/en/event/running-a-ngo-on-freesoftware/">Running a NGO on FreeSoftware</a></strong><br>
Fascillitated by <a href="https://fsfe.org/">FSFE</a> to showcase what kind software is being used for day to day operations. Many other tech people from other NGOs participated in the discussion. Common struggles on getting away from big tech companies.</p>
</li>
<li>
<p><strong><a href="https://events.ccc.de/congress/2025/hub/en/event/detail/tales-of-apartheid">Tales of apartheid</a></strong><br>
Stories of a Palestinian Israeli citizen on what Apartheid actually <a href="https://visualizingpalestine.org/">looks like</a>.</p>
</li>
</ul>
<h4>Projects</h4>
<p>Some quick links on projects and ideas captured in my notes based on discussions during the Congress.</p>
<ul>
<li><a href="https://aiwar.cloud/">AI War Cloud</a> αn interactive database exploring the connection of tech companies with military operations and warfare. This was set up as an interactive installation during the Congress.</li>
<li>I was reminded again about Tor <a href="https://snowflake.torproject.org/">Snowflake</a> proxy project.
Something we could fairly easily set up on <a href="https://libreops.cc/">LibreOps</a>.</li>
<li><a href="https://plaintext.casa/">plaintext</a>, yet another chat project. This one aims on being
a decentralized social network that uses plain text files over HTTP.</li>
<li><a href="https://codeberg.org/nicebread/39C3-solarpunk-missions">Solarpunk missions</a>, that run through out the
Congress but can be an inspiration for future projects.</li>
<li><a href="https://github.com/TecharoHQ/anubis">Anubis</a> AI firewall. If your website is suffering from excessive AI bots scraping.</li>
<li><a href="https://github.com/MacLemon/CongressChecklist">Congress Checklist</a> could be handy for the next one ;)</li>
</ul>
        ]]>
      </content>
      <published>2026-01-07 12:27:00</published>
    </entry>
  
    <entry>
      <title>Italy and Switzerland road trip</title>
      <link href="https://www.roussos.cc/2025/06/17/italy-switzerland/"/>
      <content type="html">
        <![CDATA[
          <p><img alt="Basque" src="/2025/06/17/italy-switzerland/italy-switzerland.jpg" /></p>
<p>This is a travel post to document the recent road trip to Italy and Switzerland (29.05-14.06.2025).</p>
<h4>Day 1</h4>
<p>Drove to <a href="https://www.openstreetmap.org/way/145658867">Igoumenitsa</a> to get the ferry. A 18 hours trip through Ionian and Adriatic seas.</p>
<p><img alt="Ancona" src="/2025/06/17/italy-switzerland/italy-switzerland-ancona.jpg" /></p>
<h4>Day 2</h4>
<p>Arrived at <a href="https://www.openstreetmap.org/relation/42499">Ancona</a>. Made a stop at <a href="https://www.openstreetmap.org/way/60519675">Campo Del Sole, Lake Trasimeno</a>. Then drove all the way up to <a href="https://www.openstreetmap.org/way/85667572">Cortona</a>.</p>
<p><img alt="Cortona" src="/2025/06/17/italy-switzerland/italy-switzerland-cortona.jpg" /></p>
<h4>Day 3</h4>
<p>Still in the Tuscan region. Visited <a href="https://www.openstreetmap.org/node/61753737">San Gimignano</a>, <a href="https://www.openstreetmap.org/way/376812997">Monteriggioni</a> and <a href="https://www.openstreetmap.org/node/61753373">Siena</a>.</p>
<p><img alt="San Gimignano" src="/2025/06/17/italy-switzerland/italy-switzerland-san-gimignano.jpg" /></p>
<h4>Day 4</h4>
<p>Drove further up to the north. Made a stop at <a href="https://www.openstreetmap.org/relation/42602">Florence</a> and at <a href="https://www.openstreetmap.org/way/648304257">Parma Parco Della Citadella</a>. Reached <a href="https://www.openstreetmap.org/relation/46797">Dervio</a> at the Como Lake.</p>
<p><img alt="Como Lake" src="/2025/06/17/italy-switzerland/italy-switzerland-como.jpg" /></p>
<h4>Day 5</h4>
<p>Visited <a href="https://www.openstreetmap.org/relation/46735">Bellano</a> and did a short hike to the spectacular <a href="https://www.openstreetmap.org/node/2993795907">Orrido di Bellano</a> waterfalls.</p>
<p><img alt="Bellano" src="/2025/06/17/italy-switzerland/italy-switzerland-bellano.jpg" /></p>
<h4>Day 6</h4>
<p>Drove to <a href="https://www.openstreetmap.org/relation/2888417">Lugano</a>, crossing the borders to Switzerland. Took the funicular from Cassarate and all the way up to <a href="https://www.openstreetmap.org/node/291524462">Monte Bre</a>. Visited <a href="https://www.openstreetmap.org/way/28285131">Parko Ciani</a>.</p>
<p><img alt="Lugano" src="/2025/06/17/italy-switzerland/italy-switzerland-lugano.jpg" /></p>
<h4>Day 7</h4>
<p>Drove towards the <a href="https://www.openstreetmap.org/relation/1682891">Lucerne lake</a>, through the <a href="https://www.openstreetmap.org/way/431339440">Gotthard Road Tunnel</a> (17km). That’s the 2nd longest road tunnel in Europe (after <a href="https://flickr.com/photos/comzeradd/36270103065/">Lærdal</a>). Stopped at <a href="https://www.openstreetmap.org/node/240128251#map=15/46.98679/8.31416">Hergiswil</a> and took the ferry to Lucerne.</p>
<p><img alt="Lucerne" src="/2025/06/17/italy-switzerland/italy-switzerland-lucerne.jpg" /></p>
<h4>Days 8-10</h4>
<p>Stayed at <a href="https://www.openstreetmap.org/relation/1683619">Basel</a>.</p>
<p><img alt="Basel" src="/2025/06/17/italy-switzerland/italy-switzerland-basel.jpg" /></p>
<h4>Day 11</h4>
<p>Drove through <a href="https://www.openstreetmap.org/node/11405191376">Julier Pass</a> (2284m) and reached <a href="https://www.openstreetmap.org/relation/1684175">Saint Moritz</a>. Took the funicular to <a href="https://www.openstreetmap.org/node/12040711121">Muottas Muragl</a> (2569m).</p>
<p><img alt="St. Moritz" src="/2025/06/17/italy-switzerland/italy-switzerland-moritz.jpg" /></p>
<h4>Day 12</h4>
<p>Drove towards Bolzano through <a href="https://www.openstreetmap.org/node/4353043451">Stelvio Pass</a> (2757m), ascending from the west (34 hairpins) and descending to the east (48 hairpins). Reached <a href="https://www.openstreetmap.org/relation/47207">Bolzano</a>.</p>
<p><img alt="Stelvio Pass" src="/2025/06/17/italy-switzerland/italy-switzerland-stelvio.jpg" /></p>
<h4>Day 13</h4>
<p>Hiked around <a href="https://www.openstreetmap.org/relation/18054420">Lago di Carezza</a>. Reached <a href="https://www.openstreetmap.org/way/338451906">Puster Valley</a> in Dolomites.</p>
<p><img alt="Lago di Carezza" src="/2025/06/17/italy-switzerland/italy-switzerland-carezza.jpg" /></p>
<h4>Day 14</h4>
<p>Visited <a href="https://www.openstreetmap.org/relation/14517899">Lago di Braies</a> and <a href="https://www.openstreetmap.org/relation/16301091">Lago di Misurina</a>. Reached <a href="https://www.openstreetmap.org/relation/45511">Treviso</a>.</p>
<p><img alt="Lago di Braies" src="/2025/06/17/italy-switzerland/italy-switzerland-braies.jpg" /></p>
<h4>Day 15</h4>
<p>Reached <a href="https://www.openstreetmap.org/relation/42791">Rimini</a> and took a swim at its 15km sandy beach.</p>
<p><img alt="Rimini" src="/2025/06/17/italy-switzerland/italy-switzerland-rimini.jpg" /></p>
<h4>Day 16</h4>
<p>Reached Ancona and took the ferry back to Greece.</p>
<h4>Day 17</h4>
<p>Returned to Athens. The moto trip meter was showing 3500km in total. For more photos, visit the <a href="https://roussos.cc/photos/Europe-Italy">Italy</a> and <a href="https://roussos.cc/photos/Europe-Switzerland">Switzerland</a> albums. And here is an <a href="https://ridewithgps.com/routes/56663033?privacy_code=5V9csX0zRfCyXlnLDsPbK5G2vPabhFSY">approximated route</a> with all the major stops.</p>
        ]]>
      </content>
      <published>2025-06-17 16:37:00</published>
    </entry>
  
    <entry>
      <title>Evritania road trip</title>
      <link href="https://www.roussos.cc/2024/11/09/evritania-road-trip/"/>
      <content type="html">
        <![CDATA[
          <p>This is a travel post to document the recent road trip to <a href="https://en.wikipedia.org/wiki/Evrytania">Evritania</a>.</p>
<video width="100%" controls>
  <source src="/2024/11/09/evritania-road-trip/evritania-karpenisi-time-lapse.mp4" type="video/mp4">
</video>

<h3>Day 1</h3>
<p>That involved just traveling from Athens to <a href="https://www.openstreetmap.org/node/136440062">Karpenisi</a> (290km) and settling in.</p>
<p><img alt="Karpenisi" src="/2024/11/09/evritania-road-trip/evritania-karpenisi.jpg" /></p>
<h3>Day 2</h3>
<p>Drove towards <a href="https://www.openstreetmap.org/node/1184796273">Prousos</a>, passing through a nice spot where the road is completely covered by the mountain.</p>
<p><img alt="Road to Prousos" src="/2024/11/09/evritania-road-trip/evritania-road.jpg" /></p>
<p>Stopped at the <a href="https://en.wikipedia.org/wiki/Prousou_Monastery">Monastery</a>.</p>
<p><img alt="Road to Prousos" src="/2024/11/09/evritania-road-trip/evritania-moni.jpg" /></p>
<p>Sat for a coffee for the rain to ease down and then took the footpath to <a href="https://www.openstreetmap.org/way/550868507">Black cave springs</a>.</p>
<p><img alt="Black cave springs" src="/2024/11/09/evritania-road-trip/evritania-black-cave.jpg" /></p>
<p>Continued driving to <a href="https://www.openstreetmap.org/node/1227020508">Tornos</a>. Then did a 2km hiking to <a href="https://www.openstreetmap.org/node/5320213720">Mikro Panta Vrechi</a> and enjoying the Gorge. Although a short hiking, it's quite difficult because of the elevation gain.</p>
<p><img alt="Mikro Panta Vrechi" src="/2024/11/09/evritania-road-trip/evritania-mikro.jpg" /></p>
<h3>Day 3</h3>
<p>Drove to <a href="https://www.openstreetmap.org/relation/36275">Kremasta Lake</a>, passing through the <a href="https://www.openstreetmap.org/way/105753265">Megdova bridge</a>.</p>
<p><img alt="Megdova bridge" src="/2024/11/09/evritania-road-trip/evritania-megdova.jpg" /></p>
<p>Stopped at <a href="https://osm.org/go/xb8zpESgb?m=">Ag. Georgios village</a> to enjoy the view.</p>
<p><img alt="Kremasta lake" src="/2024/11/09/evritania-road-trip/evritania-kremasta.jpg" /></p>
<h3>Day 4</h3>
<p>Drove to small villages of <a href="https://www.openstreetmap.org/node/1226800720">Krikello</a> and <a href="https://www.openstreetmap.org/node/1226777182">Domnistra</a>. Beautiful route through the fir forest.</p>
<p><img alt="Krikello" src="/2024/11/09/evritania-road-trip/evritania-krikello.jpg" /></p>
<p>Visited <a href="https://www.openstreetmap.org/node/1229281330">Fourna</a> village on the north side. Even more beautiful route.</p>
<p><img alt="Fourna" src="/2024/11/09/evritania-road-trip/evritania-fourna.jpg" /></p>
<h3>Day 5</h3>
<p>After returning to Athens, the moto trip meter was showing 1000km in total.</p>
        ]]>
      </content>
      <published>2024-11-09 14:01:00</published>
    </entry>
  
    <entry>
      <title>Self-hosted media center</title>
      <link href="https://www.roussos.cc/2024/01/29/home-media-center/"/>
      <content type="html">
        <![CDATA[
          <p><img alt="jellyfin" src="/2024/01/29/home-media-center/jellyfin.jpg" /></p>
<p>This is a typical documentation post on how to set up a stack of open source tools to create a media center at home.
That involves not just the frontend, that you can use on your TV or other devices, but also the tools needed for monitoring
the release of certain movies and tv shows.</p>
<p>By the time you reach the end of the post and look at the code you will be wondering
<a href="https://xkcd.com/1205/">"is it worth the time?"</a>. I had the same reservations when I started looking to all these tools
and it's definitely something to consider. But they do simplify a lot of the tasks that you probably do manually now. And in the end,
you get an interface that has a similar user experience as many commercial streaming services do.</p>
<p>To minimize the effort of installing all this software and reducing future maintenance, you can use docker containers.
The <a href="https://www.linuxserver.io/">linuxserver.io</a> project has done some amazing work on this area, providing pre-built container images.
They definitely worth your support if you can afford donating.</p>
<h4>Stack</h4>
<ul>
<li>Movies: <a href="https://radarr.video/">Radarr</a></li>
<li>TV Shows: <a href="https://sonarr.tv/">Sonarr</a></li>
<li>Torrents: <a href="https://transmissionbt.com/">Transmission</a>. This is probably the only part of the whole stack that you have the flexibility to choose between various options.</li>
<li>Indexer: <a href="https://github.com/Jackett/Jackett">Jackett</a>. That works as a proxy that translates queries from all the other apps into torrent trackers  http queries, parses the html or json response, and then sends results back to the requesting software (Transmission in this case).</li>
<li>Subtitles: <a href="https://www.bazarr.media/">Bazarr</a></li>
<li>Media Center: <a href="https://jellyfin.org/">Jellyfin</a></li>
</ul>
<h4>Docker Compose</h4>
<p>Below I include a docker compose file that will make everything work together. Some prerequisites that you need to take care of:</p>
<ul>
<li>Create a new user that would be the one running these docker containers.</li>
<li>Depending on your Linux distribution, you many need to add this user to the <code>docker</code> group.</li>
<li>Switch to that use and run <code>id</code>. Use the numeric values from <code>uid</code> and <code>guid</code> to replace the values for <code>PUID</code> and <code>PGID</code> respectively in the compose file below.</li>
<li>All containers need to share a volume for all the media (see the <code>volumes</code> configuration at the bottom of the file). Hardlinks are being used then to avoid duplicating files or doing unnecessary file transfers. For a more detailed explanation see <a href="https://radarr.video/#downloads-docker">Radarr's documentation</a>.</li>
<li>If you live in a country that censors Torrent trackers, you need to override DNS settings at least for the Jackett service. The example below is using <a href="https://libreops.cc/radicaldns.html">RadicalDNS</a> for that purpose.</li>
<li>Adjust the volume paths to your preference. The example is using <code>/data</code> for configuration directories per app and <code>/data/public</code> for the actual media.</li>
<li>Save this file as <code>docker-compose.yml</code>.</li>
</ul>
<hr />
<pre><code>version: "3.7"

services:
  transmission:
    image: lscr.io/linuxserver/transmission:latest
    container_name: transmission
    environment:
      - PUID=1000
      - PGID=1000
      - TZ=Etc/UTC
      - UMASK=002
      - USER= #optional
      - PASS= #optional
    volumes:
      - /data/transmission:/config
      - data:/data
    ports:
      - 9091:9091
      - 51413:51413
      - 51413:51413/udp
    restart: unless-stopped

  sonarr:
    image: lscr.io/linuxserver/sonarr:latest
    container_name: sonarr
    environment:
      - PUID=1000
      - PGID=1000
      - TZ=Etc/UTC
      - UMASK=002
    volumes:
      - /data/sonarr:/config
      - data:/data
    ports:
      - 8989:8989
    restart: unless-stopped

  radarr:
    image: lscr.io/linuxserver/radarr:latest
    container_name: radarr
    environment:
      - PUID=1000
      - PGID=1000
      - TZ=Etc/UTC
      - UMASK=002
    volumes:
      - /data/radarr:/config
      - data:/data
    ports:
      - 7878:7878
    restart: unless-stopped

  jackett:
    image: lscr.io/linuxserver/jackett:latest
    container_name: jackett
    environment:
      - PUID=1000
      - PGID=1000
      - TZ=Etc/UTC
      - UMASK=022
    dns:
      - 88.198.92.222
    volumes:
      - /data/jackett:/config
      - data:/data
    ports:
      - 9117:9117
    restart: unless-stopped

  bazarr:
    image: lscr.io/linuxserver/bazarr:latest
    container_name: bazarr
    environment:
      - PUID=1000
      - PGID=1000
      - TZ=Etc/UTC
      - UMASK=022
    volumes:
      - /data/bazarr:/config
      - data:/data
    ports:
      - 6767:6767
    restart: unless-stopped

  jellyfin:
    image: lscr.io/linuxserver/jellyfin:latest
    container_name: jellyfin
    environment:
      - PUID=1000
      - PGID=1000
      - TZ=Etc/UTC
      - UMASK=022
      - JELLYFIN_PublishedServerUrl= #optional
    volumes:
      - /data/jellyfin:/config
      - data:/data
    ports:
      - 8096:8096
    restart: unless-stopped

volumes:
  data:
    driver: local
    driver_opts:
      type: none
      device: /data/public
      o: bind
</code></pre>
<h4>Nginx</h4>
<p>To make it easier accessing all those services Nginx can be used to map ports exposed by docker under the same domain.
You can of course just use your server's IP address, but having a domain name can also make it easier for
other people who are not as good as you in memorizing IP addresses (I know right?).</p>
<p>Although it may not considered a good practice to point an external domain to an internal IP, it be very convenient in
this use case since it allows you to issue a valid and free SSL certificate using <a href="https://letsencrypt.org/">Let's Encrypt</a>.</p>
<p>Below is a simple Nginx configuration that can work together with the docker compose setup described above.</p>
<hr />
<pre><code>upstream transmission {
  server 127.0.0.1:9091;
  keepalive 4;
}

upstream sonarr {
  server 127.0.0.1:8989;
  keepalive 4;
}

upstream radarr {
  server 127.0.0.1:7878;
  keepalive 4;
}

upstream jackett {
  server 127.0.0.1:9117;
  keepalive 4;
}

upstream bazarr {
  server 127.0.0.1:6767;
  keepalive 4;
}

upstream jellyfin {
  server 127.0.0.1:8096;
  keepalive 4;
}

server {
  listen 80;
  listen [::]:80;
  server_name media.example.com;
  return 301 https://$server_name$request_uri;
}

server {
  listen 443 ssl http2;
  listen [::]:443 ssl http2;
  server_name media.example.com;

  ssl_certificate "/etc/certs/acme/fullchain.cer";
  ssl_certificate_key "/etc/certs/acme/media.example.com.key";

  location /radarr {
    include /etc/nginx/snippets/proxy_pass.conf;
    proxy_pass http://radarr;
  }

  location /sonarr {
    include /etc/nginx/snippets/proxy_pass.conf;
    proxy_pass http://sonarr;
  }

    location /jackett {
    include /etc/nginx/snippets/proxy_pass.conf;
    proxy_pass http://jackett;
  }

  location /bazarr {
    include /etc/nginx/snippets/proxy_pass.conf;
    proxy_pass http://bazarr;
  }

  location /transmission {
    include /etc/nginx/snippets/proxy_pass.conf;
    proxy_pass_header X-Transmission-Session-Id;
    proxy_pass http://transmission;
  }

  location / {
    include /etc/nginx/snippets/proxy_pass.conf;
    proxy_pass http://jellyfin;
  }
}
</code></pre>
<p>Some things to take care of:</p>
<ul>
<li>Replace the <code>media.example.com</code> server name with yours.</li>
<li>With the exception of Jellyfin, all other services are served from a path. You may need to adjust the application settings after first run to make this work. As an example, Radarr will need a <code>&lt;UrlBase&gt;/radarr&lt;/UrlBase&gt;</code> at its <code>config.xml</code>.</li>
<li>Since <code>proxy_pass</code> options are the same for all services, there is an include directive pointing to the snippet below.</li>
</ul>
<hr />
<pre><code>proxy_set_header Host $host;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Host $host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_redirect off;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $http_connection;
</code></pre>
<h4>Certificates</h4>
<p>Since the subdomain will be pointing to an internal IP it can be difficult to use the http challenge to get a certificate.
Instead, you can use <a href="https://github.com/acmesh-official/acme.sh">acme.sh</a> that
<a href="https://github.com/acmesh-official/acme.sh/wiki/dnsapi">supports many DNS providers</a> and can automate the DNS
challenge verification.</p>
<p>Here is an example command for issuing a certificate for the first time, using Cloudflare DNS:</p>
<pre><code>acme.sh --debug --issue --dns dns_cf -d media.example.com --dnssleep 300
</code></pre>
<p>You will need to make that Nginx configuration points to the certificates created by acme.sh.</p>
<h4>Run it!</h4>
<p>All you have to do is bring docker containers up. Switch to the user you created for that purpose and
go to the directory you saved <code>docker-compose.yml</code>:</p>
<pre><code>docker-compose up -d
</code></pre>
<p>As root you should also start Nginx:</p>
<pre><code>systemctl enable --now nginx.service
</code></pre>
<p>And that's it!</p>
<h4>Configuration</h4>
<p>Some post-installation configuration to make everything work together:</p>
<ul>
<li>As mentioned above, make sure to adjust "URL base" and use the location path configured in Nginx (eg. <code>/sonarr</code> for Sonarr) in all the applications.</li>
<li>Whatever torrent client you choose, make sure to configure it for both Radarr and Sonarr as a Download Client under their Settings options.</li>
<li>On Transmission, you can choose "Require Encryption" in Preferences &gt; Peers &gt; Encryption mode. You will probably lose some peers, but you'll prevent your ISP from knowing what content you are downloading.</li>
<li>After you add some torrent trackers to Jackett, you would also need to configure Indexers under Settings options in both Sonarr and Radarr. You should copy the Torznab feed from Jackett and its API key to make it work.</li>
<li>For subtitles, you need first to add some Providers in Bazarr Settings options. And then create at least one Language Profile under Languages, so that Bazarr knows what languages to look for.</li>
<li>Both Sonarr and Radarr support importing existing media files and they provide some on-screen instructions on how to structure your files in a way they understand.</li>
</ul>
<h4>Future maintainance</h4>
<p>Upgrading the whole stack is just two commands:</p>
<pre><code>docker-compose pull
docker-compose restart
</code></pre>
<p>You can also make a systemd service to run the docker containers on boot.
It also helps if you want to check logs and you are familiar with <code>journald</code>.
Here is a simple service file:</p>
<hr />
<pre><code>[Unit]
Description=Media Center

[Service]
RemainAfterExit=yes
User=username
Group=group
WorkingDirectory=/home/username/
ExecStart=docker-compose up -d
ExecReload=docker-compose restart
ExecStop=docker-compose stop
Restart=always
</code></pre>
<ul>
<li>Make sure to replace <code>username</code> and <code>group</code> with your settings.</li>
<li>Create this file inside <code>/etc/systemd/system/</code></li>
</ul>
<p>Reload systemd to view the new service file and run and activate the service:</p>
<pre><code>systemctl daemon-reload
systemctl enable --now mediacenter.service
</code></pre>
<p>Enjoy!</p>
        ]]>
      </content>
      <published>2024-01-29 16:27:00</published>
    </entry>
  
    <entry>
      <title>37c3 notes</title>
      <link href="https://www.roussos.cc/2024/01/05/37c3/"/>
      <content type="html">
        <![CDATA[
          <p><img alt="37c3" src="/2024/01/05/37c3/37c3.jpg" />]</p>
<p>It’s been a few years since the last <a href="https://events.ccc.de/congress/2023/infos/">Chaos Computer Congress</a>. Same as many other people I highly enjoyed being there. Meeting with people, participating in discussions and a bit of hacking. Most of the things taking place in a congress are quite difficult to describe them in writing and most of happening outside of the presentation rooms. But stil, I thought I should share at least some sessions I enjoyed.</p>
<p><small><em>💡 If you use Kodi, install the <a href="http://kodi.wiki/view/Add-on:CCC-TV_(media.ccc.de)">relevant add-on</a> to watch these in comfort (or any other of the <a href="https://media.ccc.de/about.html#apps">apps</a>)</em></small></p>
<h4>Talks</h4>
<ul>
<li>
<p><strong><a href="https://media.ccc.de/v/37c3-12168-predator_files_how_european_spyware_threatens_civil_society_around_the_world">Predator Files: How European spyware threatens civil society around the world</a></strong><br>
A technical deep dive into <a href="https://securitylab.amnesty.org/latest/2023/10/technical-deep-dive-into-intellexa-alliance-surveillance-products/">Amnesty International investigation</a> about the spyware alliance Intellexa, which is used by governments to infect the devices and infrastructure we all depend on.</p>
</li>
<li>
<p><strong><a href="https://media.ccc.de/v/37c3-11996-tech_no_fixes_beware">Tech(no)fixes beware!</a></strong><br>
Spotting (digital) tech fictions as replacement for social and political change. As the climate catastrophe is imminent and global injustice is rising, a lot of new tech is supposed to help the transition to a sustainable society. Although some of them can actually help with parts of the transition, they are usually discussed not as tools to assist the broader societal change but as replacement for the broader societal change.</p>
</li>
<li>
<p><strong><a href="https://media.ccc.de/v/37c3-11995-a_libyan_militia_and_the_eu_-_a_love_story">A Libyan Militia and the EU - A Love Story?</a></strong><br>
An open source investigation by <a href="https://sea-watch.org/en/">Sea-Watch</a> and other organizations, on how EU (either directly or through Frontex) is collaborating with Tariq Ben Zeyad Brigade (TBZ), a notorious East Libyan land-based militia. TBZ were deeply involved in the failed passage of the boat that sank near Pylos, in which up to 500 people drowned.</p>
</li>
<li>
<p><strong><a href="https://media.ccc.de/v/37c3-11836-tractors_rockets_and_the_internet_in_belarus">Tractors, Rockets and the Internet in Belarus</a></strong><br>
How belarusian authoritarian regime is using technologies to repress it's population. With dropping costs of surveillance smaller authoritarian regimes are gaining easier access to different "out of the box" security solutions used mainly to further oppress people.</p>
</li>
<li>
<p><strong><a href="https://media.ccc.de/v/37c3-12004-please_identify_yourself">Please Identify Yourself!</a></strong><br>
Focused mostly on EU's eIDAS and India's Aadhaar, and highlighting how Digital Identity Systems proliferate worldwide without any regard for their human rights impact or privacy concerns. Driven by governments and the crony capitalist solutionism peddled by the private sector, these identification systems are a frontal attack on anonymity in the online world and might lead to completely new forms of tracking and discrimination.</p>
</li>
<li>
<p><strong><a href="https://media.ccc.de/v/37c3-12324-on_digitalisation_sustainability_climate_justice">On Digitalisation, Sustainability &amp; Climate Justice</a></strong><br>
A critical talk about sustainability, technology, society, growth and ways ahead. Which digital tools make sense, which do not and how can we achieve global social emancipation from self-destructive structures and towards ecological sustainability and a and a just world?</p>
</li>
<li>
<p><strong><a href="https://media.ccc.de/v/37c3-11796-energy_consumption_of_datacenters">Energy Consumption of Datacenters</a></strong><br>
The increase of datacenter energy consumption has already been exponential for years. With the AI hype, this demand for energy, cooling and water has increased dramatically.</p>
</li>
<li>
<p><strong><a href="https://media.ccc.de/v/37c3-12047-software_licensing_for_a_circular_economy">Software Licensing For A Circular Economy</a></strong><br>
How Open Source Software connects to sustainability, based on the <a href="https://eco.kde.org/">KDE Eco initiative</a>. Concrete examples on
Free &amp; Open Source Software license can disrupt the produce-use-dispose linear model of hardware consumption and enable the shift to a reduce-reuse-recycle circular model.</p>
</li>
</ul>
<h4>Self-organized sessions</h4>
<p>Anyone who has paricipated in a Congress knows that there is a wide variety of workshops and self-organized sessions outside of the
official curated talks. Most of them not recorded, but still I thought I should share some highlights and thoughts in case people want to dig a bit deeper into these topics.</p>
<ul>
<li>
<p><strong><a href="https://events.ccc.de/congress/2023/hub/en/event/running-a-ngo-on-freesoftware/">Running a NGO on FreeSoftware</a></strong><br>
Fascillitated by <a href="https://fsfe.org/">FSFE</a> to showcase what kind software is being used for day to day operations. Many other tech people from other NGOs participated in the discussion.</p>
</li>
<li>
<p><strong><a href="https://events.ccc.de/congress/2023/hub/en/event/greg-egans-orthogonal-a-universe-without-timelike-/">Greg Egan's „Orthogonal“: A universe without timelike dimensions</a></strong> <br>
If you are into hard sci-fi, you may have read a Greg Egan book already. My personal favorite being <a href="https://openlibrary.org/works/OL11442145W/Permutation_city">Permutation City</a>. This session was focusing on the physics behind the <a href="https://www.goodreads.com/series/59462-orthogonal">Orthogonal trilogy</a>.</p>
</li>
<li>
<p><strong><a href="https://events.ccc.de/congress/2023/hub/en/event/can-you-imagine-a-world-beyond-capitalism-explorin/">Can you imagine a world beyond capitalism? Exploring economic history with David Graeber's Debt</a></strong><br>
This was a nice session (and discussion) inspired by David Graeber's book: Debt, <a href="https://openlibrary.org/works/OL14909099W/Debt">The First 5,000 Years</a>.</p>
</li>
<li>
<p><strong><a href="https://events.ccc.de/congress/2023/hub/en/event/technologies-for-disaster_28uv/">Technologies for Disaster</a></strong><br>
A workshop for people in tech running OpSec trainings (eg. <a href="https://www.cryptoparty.in/">Cryptoparties</a>) for non-tech people in danger.
A big portion of the discussion was around threat modeling.</p>
</li>
<li>
<p><strong><a href="https://events.ccc.de/congress/2023/hub/en/event/decolonize_runet_decolonize_network_measurements_a_provocative_take_on_the_russian_sovereign_internet_project/">Decolonize runet! Decolonize network measurements! A provocative take on the Russian sovereign internet project</a></strong><br>
Not very familiar with Runet before this talk, a russian "sovereign internet" project.</p>
</li>
<li>
<p><strong><a href="https://events.ccc.de/congress/2023/hub/en/event/i-pack-my-ict-bag-for-gaza-and-i-take-with-me/">I pack my ICT-bag for Gaza and I take with me...</a></strong><br>
This was organized by <a href="https://www.cadus.org/en/">Cadus</a>, an emergency response organization. As they prepare on going to Gaza, the session was mostly about the challenges of preparing a humanitarian response to a conflict zone. But the discussion was also focused around the situation of communication networks in Gaza and how to workaround current limitations imposed by the Israel state.</p>
</li>
</ul>
<h4>Projects</h4>
<p>Some quick links on projects captured in my notes based on discussions during the Congress.</p>
<ul>
<li>Mastodon has now an <a href="https://write.as/sweetmeat/how-to-activate-the-mastodon-v4-deepl-api-text-translation-service">automatic translation functionality</a>.</li>
<li><a href="https://waydro.id/">Waydroid</a>: a container-based approach to boot a full Android system on Linux.</li>
<li><a href="https://snowflake.torproject.org/">Snowflake</a> importance was highlighted again by the Tor project people.</li>
<li>I knew (and have used) <a href="https://docs.mvt.re/en/latest/">Mobile Verification Toolkit</a> before, but it was a good reminder to check its status and talk with journalists that can be potential Predator targets.</li>
<li><a href="https://libregraphicsmeeting.org/2024/">Libre Graphics Meeting</a> is back after 3 years.</li>
</ul>
        ]]>
      </content>
      <published>2024-01-05 18:27:00</published>
    </entry>
  
    <entry>
      <title>Διχασμός</title>
      <link href="https://www.roussos.cc/2022/06/27/dixasmos/"/>
      <content type="html">
        <![CDATA[
          <p><img alt="Διχασμός" src="/2022/06/27/dixasmos/dixasmos.jpg" /></p>
<p>Υπάρχει μια μεγάλη στρέβλωση στην ελληνική κοινωνία. Είναι αρκετά έντονη αυτήν την περίοδο, με την παρούσα κυβέρνηση, αλλά δεν είναι καινούρια. Παρακολουθώντας την κυρίαρχη αφήγηση, τον δημόσιο λόγο αρκετών πολιτικών και δημοσιογράφων, αλλά και τις αντιδράσεις ανθρώπων που ανήκουν με κάποιον τρόπο στον πολιτικό χώρο που ξεκινάει απ’ το κέντρο και πάει προς τα δεξιά, δεν μπορώ να μην παρατηρήσω τις αντιφάσεις απ’ τις οποίες διέπεται.</p>
<p>Υπάρχει ένα κομμάτι της ελληνικής κοινωνίας που έχει κρατήσει για τον εαυτό της συγκεκριμένες πολιτικές ταυτότητες, όπως φιλελεύθεροι, κοσμοπολίτες, δημοκράτες, παραγωγικοί, ευγενείς, κλπ. Έννοιες που στο δικό τους κόσμο (και πιθανόν και σε ένα πολύ μεγαλύτερο κομμάτι της κοινωνίας) έχουν θετικό πρόσημο. Στην πραγματικότητα όμως, τα λόγια και οι πράξεις τους μας δείχνουν κάτι διαφορετικό.</p>
<p>Θα μιλήσουν ως φιλο-ευρωπαϊστές, θα μιλήσουν με περηφάνια για το πτυχία που έχουν από ξένα πανεπιστήμια ή θα εκφράσουν τον θαυμασμό τους γι αυτούς που τα έχουν. Θα μας πουν πόσο κοσμοπολίτες είναι. Οι ίδιοι άνθρωποι θα μιλήσουν για εισβολείς μετανάστες, για την ανάγκη δημιουργίας ακόμα περισσότερων κέντρων συγκέντρωσης. Θα μιλήσουν για αλλοίωση του πολιτισμού μας ή για το «γεγονός» πως «δεν χωράμε». Θα δικαιολογήσουν τις επαναπροωθήσεις ή ακόμα χειρότερα το τρύπημα σε βάρκες μεταναστών. Αλλά ταυτόχρονα δεν έχουν κανένα πρόβλημα να δεχτούν επενδύσεις απ’ το εξωτερικό ή να ανοίξουν τα σύνορα εν καιρώ πανδημίας σε τουριστικούς μετανάστες. Ο κοσμοπολιτισμός τους, όπως και ο ρατσισμός τους, είναι ταξικός.</p>
<p>Θα μιλήσουν ως φιλελεύθεροι, αλλά η ελευθερία τους εξαντλείται στην ελευθερία κίνησης χρήματος και εμπορευμάτων. Θα υψώσουν τείχη στα σύνορα, για να σταματήσουν την ελεύθερη μετακίνηση των ανθρώπων. Θα σταθούν απέναντι στην προάσπιση και διεύρυνση ατομικών και κοινωνικών ελευθεριών, ειδικά όταν αυτές περιλαμβάνουν ανθρώπους άλλου φύλου, διαφορετικού σεξουαλικού προσανατολισμού ή ακόμα και διαφορετικών πολιτικών πεποιθήσεων. Θα μιλήσουν ως φυσικοί συνεχιστές της Γαλλικής Επανάστασης, λησμονώντας να μιλήσουν για ισότητα και αλληλεγγύη.</p>
<p>Θα μιλήσουν ως το παραγωγικό κομμάτι της κοινωνίας, όταν πολλοί εξ αυτών θαυμάζουν ανθρώπους που δεν έχουν πεινάσει ή δεν έχουν εργαστεί ποτέ στη ζωή τους. Πιθανόν να ανήκουν και οι ίδιοι σε αυτούς. Την ίδια στιγμή θα εγκαλέσουν ως υποκριτές όσους βρίσκονται πολιτικά απέναντι τους και έχουν το θράσος να μην ζουν στη φτώχεια και στη μιζέρια. Πιστεύουν ακράδαντα πως είναι οι μόνιμοι ιδιοκτήτες αυτής της χώρας.</p>
<p>Θα μιλήσουν ως ευγενείς και «καθαροί», ως άνθρωποι μιας ανώτερης τάξης. Οι ίδιοι που θα δικαιολογήσουν κάθε κήρυγμα μίσους που εκτοξεύεται από κάποιον άμβωνα.</p>
<p>Θα μιλήσουν ως δημοκράτες και άνθρωποι της νομιμότητας. Αλλά γι αυτούς η παραβατικότητα χρήζει μεγαλύτερης και αυστηρότερης πάταξης απ’ την εγκληματικότητα. Θα δικαιολογήσουν κάθε μορφή αστυνομικής βίας, όσο εξόφθαλμα καταχρηστική κι αν είναι, γνωρίζοντας εκ τους ασφαλούς πως ο αποδέκτης της δεν θα είναι ένας απ’ αυτούς. Αποδέχονται το μονοπώλιο της βίας, ενώ καταδικάζουν τη βία απ’ όπου κι αν προέρχεται. Θα κουνήσουν το δάχτυλο για την τήρηση της νομιμότητας, επειδή ταυτίζοντας τον εαυτό τους με τον νομοθέτη, εξαιρούνται απ’ αυτή.</p>
<p><strong>Έχουν ταυτίσει τον εαυτό τους με την ηθική και την πρόοδο, όταν στην πραγματικότητα αντιπροσωπεύουν ό,τι πιο μισαλλόδοξο, πουριτανικό, ρατσιστικό και μικρόψυχο υπάρχει στην ελληνική κοινωνία. Ο διχασμός που βιώνουμε είναι πιο απλός απ’ όσο φανταζόμαστε. Είναι ένας διχασμός ανάμεσα σε ανθρώπους και τέρατα.</strong></p>
<hr>

<p><em>Comments and reactions on <a href="https://omniatv.com/853463421">OmniaTV</a>, <a href="https://libretooth.gr/@comzeradd/105894635105895300">Mastodon</a>, <a href="https://twitter.com/comzeradd/status/1371432600548560896">Twitter</a></em>.</p>
        ]]>
      </content>
      <published>2022-06-27 15:57:00</published>
    </entry>
  
    <entry>
      <title>Japan trip</title>
      <link href="https://www.roussos.cc/2020/01/27/japan/"/>
      <content type="html">
        <![CDATA[
          <p><img alt="Japan" src="/2020/01/27/japan/japan.jpg" /></p>
<p>This is a brief travel diary post, for the recent trip to Japan (01-16.01.2020).</p>
<h4>Day 1</h4>
<p>Flew to <code>Tokyo</code> (through Moscow).</p>
<h4>Day 2</h4>
<p>Arrived at Narita airport (NRT). Took the train to <code>Kyoto</code>.</p>
<h4>Day 3</h4>
<p>Kyoto: Walk to temples, shrines, Zen gardens.</p>
<h4>Day 4</h4>
<p>Kyoto: Castle/Palace, Gold temple, Shin market</p>
<h4>Day 5</h4>
<p>Kyoto &gt; <code>Osaka</code>. Namba station.</p>
<h4>Day 6</h4>
<p>Osaka &gt; <code>Hiroshima</code>. Peace Memorial Museum. First tast of Okonomiyaki.</p>
<h4>Day 7</h4>
<p>Osaka &gt; <code>Kobe</code>. Kobe &gt; <code>Himeji</code>. Visited Castle.</p>
<h4>Day 8</h4>
<p>Osaka &gt; <code>Tokyo</code>. Shibuya, Harajuku, Shimo-Kitozawa.</p>
<h4>Day 9</h4>
<p>Tokyo &gt; <code>Nikko</code>.</p>
<h4>Day 10</h4>
<p>Ghibli Museum. Shibuya.</p>
<h4>Day 11</h4>
<p>Tokyo &gt; <code>Hakone</code>. Tonzen Onsen. Nakano.</p>
<h4>Day 12</h4>
<p>Itõ. Atami. Shinjuku.</p>
<h4>Day 13</h4>
<p><code>Chiba</code>. Hitotsumatsu. Nakazato beach. Ichinomiya. Isumi. Ohara. Otaki. Kururi. Ueno.</p>
<h4>Day 14</h4>
<p>Ueno Onshi Park. Himalayan Cedar Tree. Ginza. Akihabara. Tokyo Edo Museum.</p>
<h4>Day 15</h4>
<p>Tokyo National Museum. Nezu. Odaiba. Unicorn Gundam Statue. Akihabara.</p>
<h4>Day 16</h4>
<p>Flew back from <code>Narita</code> airport.</p>
<p>You can see photos on the <a href="https://roussos.cc/photos/World-Japan">Japan</a> album.</p>
        ]]>
      </content>
      <published>2020-01-27 10:57:00</published>
    </entry>
  
    <entry>
      <title>Blocking untrusted USB devices</title>
      <link href="https://www.roussos.cc/2019/08/19/usbguard/"/>
      <content type="html">
        <![CDATA[
          <p><img alt="badusb" src="/2019/08/19/usbguard/badusb.jpg" /></p>
<p>For fun and <a href="https://www.wired.com/2014/07/usb-security/">security</a> (and a bit of <a href="https://web.archive.org/web/20170618122633/https://www.electronicproducts.com/Hardware/Computers/What_is_a_mouse_jiggler_and_why_does_the_FBI_use_it_when_seizing_computers.aspx">paranoia</a>), I thought I should whitelist my trusted USB devices and block everything else.</p>
<h3>USBGuard</h3>
<p>We have a couple of tools that can help us with that. <a href="https://usbguard.github.io/">USBGuard</a> is the one I found to be the most configurable and well documented.</p>
<blockquote>
<p><strong>NOTICE</strong>: All commands here require certain privileges. To make commands easier to read, I omitted adding <code>sudo</code> in the beginning. But you probably need to.</p>
</blockquote>
<h3>Installation</h3>
<p>USBGuard should already be packaged for your favorite Linux distribution.</p>
<p>One important thing to consider though is that on Debian (and derivatives) installing a package that comes with a systemd service file ends up being started and enabled by default. That means that if your input devices are USB-connected, you will find yourself locked out of your system. This may include even devices that are not physically plugged in a USB port (eg. your laptop built-in keyboard).</p>
<p>The upstream developer actually has a relevant warning:</p>
<blockquote>
<p><strong>WARNING:</strong> before you start using usbguard be sure to configure it first unless you know exactly what you are doing (all USB devices will get blocked).</p>
</blockquote>
<p>But that didn't stop the Debian developers, who maintain that package, to allow USBGuard daemon to start with zero configuration 🤷</p>
<h3>Systemd</h3>
<p>You can find more <a href="https://major.io/2016/05/05/preventing-ubuntu-16-04-starting-daemons-package-installed/">detailed guides</a> on how to prevent this "feature", but for the scope of this post here is what I did.</p>
<p>Systemd comes with a mask feature, that will prevent a certain service from being started. So for instance, if you try this:</p>
<pre><code>sudo systemctl mask nginx.service
sudo systemctl start nginx.service
</code></pre>
<p>You'll get this error:</p>
<pre><code>Failed to start nginx.service: Unit nginx.service is masked.
</code></pre>
<p>In our case, we can't use the mask command because USBGuard is not installed yet. But what mask actually does is just create a symlink. So all we have to do is create it manually:</p>
<pre><code>sudo ln -s /dev/null /etc/systemd/system/usbguard.service
</code></pre>
<p>And now we can safely install USBGuard:</p>
<pre><code>sudo apt install usbguard
</code></pre>
<h3>Configuration</h3>
<p>First thing to do is create an initial policy that whitelists all of our usb devices. Now it's a good time to plug-in devices that you tend to use often and you already trust. You can of course whitelist devices at any point.</p>
<pre><code>usbguard generate-policy
</code></pre>
<p>The above command will display the list of your currently plugged devices with an <code>allow</code> keyword in the beginning. Let's save that to USBGuard's configuration file:</p>
<pre><code>usbguard generate-policy &gt; /etc/usbguard/rules.conf
</code></pre>
<p>Now it's safe to unmask, start and enable USBGuard daemon:</p>
<pre><code>systemctl unmask usbguard.service
systemctl start usbguard.service
systemctl enable usbguard.service
</code></pre>
<h3>Testing</h3>
<p>To test this actually works try to plug a new device, not whitelisted yet. Let's a simple USB stick. Hopefully it will be blocked. To confirm that:</p>
<pre><code>usbguard list-devices
</code></pre>
<p>This lists all your detected devices. The new device you just plugged-in should have a <code>block</code> keyword in the beginning. For a more filtered output:</p>
<pre><code>usbguard list-devices | grep block
</code></pre>
<p>You should see something like this:</p>
<pre><code>13: block id 0xxx:0xxx serial &lt;...&gt;
</code></pre>
<h3>Allowing devices</h3>
<p>Now let's say you actually want to unblock this device, because it came from a friend you trust. The command we run above also contained an ID number. The first thing on that line. We can use that and allow that device:</p>
<pre><code>usbguard allow-device 13
</code></pre>
<h3>Whitelisting devices</h3>
<p>Using <code>allow-device</code> doesn't whitelist the device for ever. So let's say you bought a new external disk and you want to whitelist it. USBGuard has an <code>append-rule</code> command. You just need to paste the whole device line starting with an <code>allow</code> keyword.</p>
<p>Plug the device and see the USBGuard output:</p>
<pre><code>usbguard list-devices | grep block
</code></pre>
<p>You should see something like this:</p>
<pre><code>21: block id 0xxx:0xxx serial &lt;...&gt;
</code></pre>
<p>Copy the whole line starting from <code>id</code> and then use it <em>but</em> prefix it with an <code>allow</code> keyword (mind the single quotes used to wrap the entire rule):</p>
<pre><code>usbguard append-rule 'allow id 0xxx:0xxx serial &lt;...&gt;'
</code></pre>
<h3>Editing rules</h3>
<p>At any point you can see the whitelisted devices:</p>
<pre><code>usbguard list-rules
</code></pre>
<p>And you use the id number in the beginning of each line in order to interact with that specific rule. For example to remove a device:</p>
<pre><code>usbguard remove-rule &lt;id&gt;
</code></pre>
<p>And remember, there is no such thing as <a href="https://xkcd.com/538/">absolute security</a>. It all comes down to your <a href="https://ssd.eff.org/en/glossary/threat-model">Threat model</a>.</p>
<hr>

<p><em>Comments and reactions on <a href="https://libretooth.gr/@comzeradd/102642480309495265">Mastodon</a>, <a href="https://librenet.gr/posts/2479827">Diaspora</a>, <a href="https://twitter.com/comzeradd/status/1163352092230205440">Twitter</a> and <a href="https://lobste.rs/s/itnef7/blocking_untrusted_usb_devices">Lobsters</a></em>.</p>
        ]]>
      </content>
      <published>2019-08-19 10:57:00</published>
    </entry>
  
    <entry>
      <title>Portugal and Spain road trip</title>
      <link href="https://www.roussos.cc/2019/08/13/portugal-spain/"/>
      <content type="html">
        <![CDATA[
          <p><img alt="Basque" src="/2019/08/13/portugal-spain/basque.jpg" /></p>
<p>This is a brief travel diary post, for the recent road trip at Portugal and Spain (13-28.07.2019)</p>
<p>At the end of the post, there a slideshow of <a href="https://www.flickr.com/photos/comzeradd/albums/72157710282131877">photos</a>, just a glimpse from the various places, an aproximation of the drive <a href="https://ridewithgps.com/routes/56663141?privacy_code=D0jglSB7kGCHyNAvOCunq6FntfKXQ63J">route</a> and a <a href="https://umap.openstreetmap.fr/en/map/portugal-and-spain-road-trip_354866">map</a> with all the places mentioned here.</p>
<h4>day 1</h4>
<p>Flew from Athens to Porto.</p>
<h4>day 2</h4>
<p>Stayed at <code>Porto</code>. Walked through the old town, took a boat taxi across the river, a cable car to the top of the bridge, crossed the bridge on foot.</p>
<h4>day 3</h4>
<p>Drove towards <code>Valladolid</code>, crossed the borders through <code>Miranda do Douro</code>.</p>
<h4>day 4</h4>
<p>Drove towards Basque Country. Went for swimming at <code>Deba</code> and then <code>Lekeitio</code>. Drove to <code>Bilbao</code> for dinner, through <code>Gernika</code>. Drove to <code>Elgoibar</code> for the night.</p>
<h4>day 5</h4>
<p>Drove towards <code>San Sebastian</code>, did a stop at <code>Pamplona</code> and then ended up at <code>Zaragoza</code>.</p>
<h4>day 6</h4>
<p>Drove towards <code>Barcelona</code>, went to Sonar festival.</p>
<h4>day 7</h4>
<p>Went for swimming to <code>Platja de Gava</code>. Back to Barcelona for the Sonar festival.</p>
<h4>day 8</h4>
<p>Went to Sonar festival and then drove towards <code>Valencia</code>.</p>
<h4>day 9</h4>
<p>Stayed at Valencia. Saw many parts of the city. Went to the "City of Arts and Science" and visited the Oceanograffic.</p>
<h4>day 10</h4>
<p>Went for swimming at <code>Villajoyosa</code> after a quick stops at <code>Benidorm</code>. Stopped at <code>Alicante</code> and then drove towards <code>Cartagena</code>.</p>
<h4>day 11</h4>
<p>Went for swimming at <code>Playa de Percheles</code>. Did a stop at <code>Velez-Rubio</code> for lunch. Did a stop at <code>Granada</code> visited Alhambra and parts of the town. Drove towards <code>Malaga</code> for the night.</p>
<h4>day 12</h4>
<p>Did a quick pass through <code>Torremolinos</code> and then drove towards <code>Seville</code>.</p>
<h4>day 13</h4>
<p>Drove to <code>Faro</code>, went for a boat trip to <code>Ria Formosa</code>. Drove to <code>Lagos</code>, and went for swimming at <code>Praia Dona Ana</code>. Drove to <code>Meia Praia</code> for swimming and stayed there for the night.</p>
<h4>day 14</h4>
<p>Drove to <code>Odeceixe</code>, went for swimming at <code>Praia de Odeceixe-Mar</code> and <code>Seixe river</code>. Drove to <code>Vila Nova de Milfontes</code>, after a quick stop at <code>Praia das Furnas</code>, went for swimming at <code>Praia da Franquia</code> and <code>Mira river</code>. Drove towards <code>Lisbon</code> through the Vasco da Gama bridge.</p>
<h4>day 15</h4>
<p>Stayed at Lisbon. In the afternoon drove towards Porto airport. Did a stop at <code>Aveiro</code> and a boat trip to the canals. Reached airport at night and flew back to Athens.</p>
<p>
  <iframe src="https://ridewithgps.com/embeds?type=route&id=56663141&metricUnits=true&privacyCode=D0jglSB7kGCHyNAvOCunq6FntfKXQ63J" style="width: 1px; min-width: 100%; height: 550px; border: none;" scrolling="no"></iframe>
</p>

<p>
  <iframe width="100%" height="550px" frameborder="0" allowfullscreen src="https://umap.openstreetmap.fr/en/map/portugal-and-spain-road-trip_354866?scaleControl=false&miniMap=false&scrollWheelZoom=false&zoomControl=true&allowEdit=false&moreControl=true&searchControl=null&tilelayersControl=null&embedControl=null&datalayersControl=true&onLoadPanel=undefined&captionBar=false"></iframe>
</p>

<p>
  <a data-flickr-embed="true" href="https://www.flickr.com/photos/comzeradd/albums/72157710282131877"
     title="Portugal &amp; Spain road trip">
    <img src="https://live.staticflickr.com/65535/48519225062_ed0ca5ab77_c.jpg" width="100%" height="534" alt="Portugal &amp; Spain road trip">
  </a>
</p>

<script async src="//embedr.flickr.com/assets/client-code.js" charset="utf-8"></script>
        ]]>
      </content>
      <published>2019-08-13 11:57:00</published>
    </entry>
  
    <entry>
      <title>Κανονικότητα</title>
      <link href="https://www.roussos.cc/2019/05/11/kanonikotita/"/>
      <content type="html">
        <![CDATA[
          <p><img alt="cactus" src="/2019/05/11/kanonikotita/cactus.jpg" /></p>
<p>Η κανονικότητα είναι μια στρέβλωση τόσο παλιά, τόσο εδραιωμένη, που θέλει αρκετό κόπο για να την πετάξεις από πάνω σου.</p>
<p>Αντικανονικότητα (ή έστω αντίδραση στην κανονικότητα) δεν σημαίνει απαραίτητα να πράττεις και να συμπεριφέρεσαι διαφορετικά από το αναμενόμενο. Σημαίνει να μην αποδέχεσαι τίποτα ως αναμενόμενο, ή μάλλον να αναμένεις τα πάντα. Να μην περιμένεις, να μην δικαιολογείς, να μην αδικείς.</p>
<p>Αν υπάρχει κανονικότητα, είναι αυτή η ισοπεδωτική δύναμη που επιβάλει την ομοιομορφία, που καταπιέζει τις αποκλίσεις, που δεν ανέχεται την διαφορετικότητα, και που τελικά ο μόνος τρόπος που μπορεί να επιβληθεί είναι βίαιος. Αλλά με μια υποχθόνια ορμή, που δεν αφήνει πάντα εμφανή τα σημάδια της στο σώμα, που δεν αφήνει τίποτα απρόσμενο στο πέρασμα της.</p>
<p>Στην ροή της ζωής όλα είναι απρόσμενα, πολύμορφα, πολύχρωμα, διαφορετικά. Όλα είναι κανονικά, γιατί τίποτα δεν είναι.</p>
<blockquote>
<p>“Ο κόσμος που ποθούμε είναι πιο αληθινός από τον κόσμο που αποδεχόμαστε παθητικά.” ~ lost bodies</p>
</blockquote>
<p><small><em>(όπως δημοσιεύτηκε στο <a href="http://chimeres.gr/zine">38ο τεύχος</a> του fanzine chimeres)</em></small></p>
        ]]>
      </content>
      <published>2019-05-11 15:48:00</published>
    </entry>
  
</feed>