[{"content":"The fastest and easiest way with the latest Flutter version.\nStep 1: Install Flutter using Snap sudo snap install flutter --classic Step 2: Install OpenJDK sudo apt install openjdk-17-jdk -y Step 3: Download Android CLI Tools Go here and grab the latest for Linux.\nCreate folder:\nmkdir ~/Android/Sdk Make sure you are using this exact structure:\n~/Android/Sdk/cmdline-tools/latest/bin/ ← sdkmanager Step 4: Add to ~/.bashrc export ANDROID_SDK_ROOT=$HOME/Android/Sdkexport ANDROID_HOME=$ANDROID_SDK_ROOTexport PATH=$PATH:$ANDROID_SDK_ROOT/cmdline-tools/latest/binexport PATH=$PATH:$ANDROID_SDK_ROOT/platform-tools # Nextexport JAVA_HOME=/usr/lib/jvm/java-17-openjdk-amd64export PATH=$PATH:$JAVA_HOME/binexport CHROME_EXECUTABLE=/usr/bin/brave-browser Step 5: Install sdkmanager sdkmanager \u0026#34;platform-tools\u0026#34; \u0026#34;platforms;android-36\u0026#34; \u0026#34;build-tools;36.0.0\u0026#34; sdkmanager --update Step 6: Flutter Setup flutter config --android-sdk ~/Android/Sdkflutter doctor --android-licenses # Accept all Step 7: Check flutter doctor -v You now have a clean Flutter setup without Android Studio.\nThanks – build on! 🚀\n","date":"2026-04-14T01:15:39Z","permalink":"/how-to-setup-flutter-for-development-in-ubuntu-24-04/","title":"How to Setup Flutter for Development in Ubuntu 24.04"},{"content":"If you love wearing a wearable device like a Mi Band but want to protect your privacy (like me), there\u0026rsquo;s a great way to do it!\nCheck Device Compatibility First The first step is to verify if your device is supported. Xiaomi and Huawei devices generally have the best compatibility. I recommend checking two popular alternatives:\nGadgetBridge: Fully open-source and highly privacy-focused. It works reliably, though the UI isn\u0026rsquo;t the most modern or beautiful. Notify for Mi Band: Offers a much nicer, more polished UI (in my opinion), but it\u0026rsquo;s not open-source and the Pro version (ad-free) costs about $3. Privacy-wise, both options are far superior to the official Xiaomi app—no constant data sharing with servers.\nIt\u0026rsquo;s almost ironic that Chinese-brand devices end up providing better privacy options than many Western brands when paired with these alternatives. This is likely just a side effect of their popularity and competitive pricing.\nExtract the Authentication Token Unfortunately, you\u0026rsquo;ll need the official app temporarily. Download the Xiaomi Mi Fitness app, pair your band, create a Xiaomi account, and update the firmware to the latest version*.\nOnce that\u0026rsquo;s done, you need to extract the authentication (auth) token from Xiaomi. The easiest method right now is using the Notify for Mi Band app.\nDownload Notify for Mi Band from the Google Play Store (there are two versions, ensure that you are downloading the correct one for your device) Start the setup process in the app. You\u0026rsquo;ll see two options for getting the token: Offline and Online. The offline method requires exporting logs from the official Mi Fitness app and extracting the token from them. I tried this several times, but it never worked for me—I couldn\u0026rsquo;t even find the relevant logs manually.\nSo, I strongly recommend the online method:\nLog in with your Xiaomi account email and password. Xiaomi will send a verification code to your email. Enter the code, and the app will automatically retrieve the token for you. Final Steps: Switch Over and Uninstall the Official App After getting the token:\nEnter it in Notify for Mi Band (or GadgetBridge, if you\u0026rsquo;re using that). Grant all necessary permissions. Uninstall the official Mi Fitness app immediately. The band can only connect and sync with one app at a time. Keeping the official app installed will cause connection issues or prevent proper syncing with your chosen alternative.\nNow you\u0026rsquo;re all set! Customize notifications, enable/disable features as you like, find your phone or band, install free watchfaces, and track steps, calories, and heart rate—all in a clean, beautiful UI with no privacy compromises.\nOne minor issue I\u0026rsquo;ve noticed: sleep tracking is not syncing properly. I\u0026rsquo;m not sure if this is specific to the Mi Band 10, a firmware quirk, or a setting I changed. The data still shows correctly on the band itself, so it\u0026rsquo;s just a sync problem. Personally, I don\u0026rsquo;t mind—I mainly use my Mi Band for a convenient clock, flashlight,quick heart rate checks during workouts and changing music on a bluetooth speaker.\nAt least for the Mi Band 10, the latest firmware (as of Dec 2025) hasn\u0026rsquo;t broken compatibility with Notify for Mi Band. ","date":"2025-12-23T20:23:05Z","permalink":"/ditch-the-official-app-use-your-mi-band-privately-with-open-source-alternatives/","title":"Ditch the Official App: Use Your Mi Band Privately with Open-Source Alternatives"},{"content":"If you\u0026rsquo;re using Finamp to stream or download music from your Jellyfin server and encountering a blank (or grey) screen when opening an album page—where no tracks load and you may need to force-close the app—this is a common issue, especially after upgrading Jellyfin to version 10.11.x.\nThis problem typically occurs due to changes in how Jellyfin handles music metadata in newer versions, causing Finamp to fail loading album tracks properly.\nThe Fix: Refresh Metadata in Jellyfin (Search for Missing Metadata) The most reliable workaround is to force Jellyfin to refresh your music library metadata:\nLog in to your Jellyfin web dashboard (admin account recommended). Go to Dashboard \u0026gt; Libraries. Select your Music library. Click the three dots (\u0026hellip;) menu next to the library name. Choose Refresh Metadata. In the refresh options: Check Search for missing metadata. Optionally enable other options like \u0026ldquo;Replace existing images\u0026rdquo; or \u0026ldquo;Replace all metadata\u0026rdquo; if needed. Click Refresh (or OK) to start the scan. Note: This process can take several minutes depending on your library size. Once done, restart Finamp and try opening albums again—they should now load tracks normally.\nAdditional Notes on Jellyfin 10.11.x The Finamp team and users have reported performance regressions in Jellyfin 10.11.x, particularly with music libraries (slower loading, higher resource usage). If possible, consider staying on or downgrading to Jellyfin 10.10.x for better performance until fixes are fully rolled out in later 10.11 patches. For me. I can confirm that even on the latest 10.11.x, the metadata refresh resolves the blank album issue, and overall functionality works well afterward. Credits GitHub Issue: https://github.com/jmshrv/finamp/issues/1412 If the issue persists after the scan, check for Finamp updates or report it on the Finamp GitHub repository. Happy listening! :)\n","date":"2025-12-15T15:02:30Z","permalink":"/fixing-blank-grey-screen-on-album-pages-in-finamp-jellyfin-music-player/","title":"Fixing Blank/Grey Screen on Album Pages in Finamp (Jellyfin Music Player)"},{"content":"Hardware-accelerated video decoding offloads playback from CPU to GPU, improving performance, reducing heat, and extending battery life—especially for high-resolution videos. On Linux, this works in Chromium-based browsers like Brave, but often requires flags. No more relying on h264ify extensions or downloading videos for MPV!\nBenefits Smoother high-res (1080p+) playback Lower CPU usage Better battery life on laptops Prerequisites (Ubuntu-Based Distros, e.g., Mint) For Intel GPUs (common on laptops):\nsudo apt update sudo apt install intel-media-va-driver-non-free vainfo Verify with vainfo (should list supported profiles like VP9/H.264).\nAMD/NVIDIA: Ensure Mesa/proprietary drivers are installed.\nEnabling Flags Support on Ubuntu-Based Distros Brave\u0026rsquo;s Debian package doesn\u0026rsquo;t read brave-flags.conf by default (unlike Arch\u0026rsquo;s AUR package). Create a wrapper:\nFix permissions:\nsudo chown --reference=/usr/bin/brave-browser-stable.original /usr/bin/brave-browser-stable sudo chmod --reference=/usr/bin/brave-browser-stable.original /usr/bin/brave-browser-stable Create new launcher:Bash\nsudo nano /usr/bin/brave-browser-stable Paste:\n#!/bin/sh : $$ {XDG_CONFIG_HOME=\u0026#34; $${HOME}/.config\u0026#34;} unset -v flags_conf flags_conf=\u0026#34;${XDG_CONFIG_HOME}/brave-flags.conf\u0026#34; if [ -f \u0026#34;${flags_conf}\u0026#34; ] then unset -v flags flags=\u0026#34;$$ (sed \u0026#39;s/#.*//\u0026#39; \u0026lt; \u0026#34; $${flags_conf}\u0026#34; | tr \u0026#39;\\n\u0026#39; \u0026#39; \u0026#39;)\u0026#34; set -- $$ {flags} \u0026#34; $$@\u0026#34; fi exec /usr/bin/brave-browser-stable.original \u0026#34;$@\u0026#34; Divert the original launcher:\nsudo dpkg-divert --add --rename --divert /usr/bin/brave-browser-stable.original /usr/bin/brave-browser-stable Now create/edit ~/.config/brave-flags.conf for flags.\nRecommended Flags Add to ~/.config/brave-flags.conf (one line, restart Brave):\nWayland (often default/best):\n--enable-features=AcceleratedVideoDecodeLinuxGL,AcceleratedVideoDecodeLinuxZeroCopyGL,AcceleratedVideoEncoder Xorg/X11 (or fallback):\n--enable-features=VaapiVideoDecoder,VaapiIgnoreDriverChecks,Vulkan,DefaultANGLEVulkan,VulkanFromANGLE Verification Play a video (e.g., YouTube 1080p+). Ctrl + Shift + I → Three dots → More tools → Media. Check Decoder name: VaapiVideoDecoder = GPU accelerated (avoid FFmpegVideoDecoder). Credits This amazing commentary on github: https://github.com/brave/brave-browser/issues/2300#issuecomment-2718755680\nAs always, the Arch Wiki is an invaluable resource for all things Linux. If hardware video acceleration still doesn\u0026rsquo;t work, check the wiki directly for the latest flags and troubleshooting tips. https://wiki.archlinux.org/title/Chromium#Hardware_video_acceleration\n","date":"2025-12-14T01:35:15Z","permalink":"/how-to-enable-hardware-accelerated-video-decoding-in-brave-on-linux-smoother-playback-and-better-battery/","title":"How to enable hardware-Accelerated Video Decoding in Brave on Linux: Smoother Playback and Better Battery"},{"content":"If your Ubuntu 24.04 system (especially one that started as a server install) randomly suspends or goes to sleep even though it\u0026rsquo;s supposed to be a headless server, you\u0026rsquo;re not alone.\nThis seems to happen when a server installation gets partially or fully converted to a \u0026ldquo;desktop\u0026rdquo; environment at some point — even if you never intentionally installed a desktop. In my case, I installed Ubuntu Server 24.04 directly with balenaEtcher onto NVMe/SSD and I got this weird behavior (my N100 server was suspending after 15 minutes).\nThe Simple One-Liner Fix Run this single command and the random suspensions stop immediately (and persist across reboots):\nsudo systemctl mask sleep.target suspend.target hibernate.target hybrid-sleep.target That is it!\n","date":"2025-12-12T19:58:45Z","permalink":"/quick-fix-stop-ubuntu-24-04-from-automatically-suspending-sleeping/","title":"Quick Fix: Stop Ubuntu 24.04 from Automatically Suspending/Sleeping"},{"content":"Introduction One of the major pain points of Monero is restoring an old wallet. Today, I will compare the speed of three popular Monero wallets to check which one is the fastest at restoring.\nTest data Date of test: 2025-12-10 Device: Samsung Galaxy A56 (Exynos 1580, 8 GB RAM, mid-range 2025 phone) Connection: Local Monero full node over Wi-Fi (same LAN, Using Deco S7) Wallet: Legacy 25-word seed created in December 2024 (~1 year old, moderate transaction history) Goal: Full restore + sync from my restore height with each wallet to see real-world performance on a typical self-hosted setup in 2025.\nThe contenders Wallet Version Restore height method Notes Cake Wallet 5.6.2 Legacy 25-word Official multi-coin wallet Stack Wallet 2.4.2 Legacy 25-word Privacy-focused, Bitcoin-first but good XMR support Monerujo 4.1.7 (Exolix build) Legacy 25-word Long-time Android-only Monero favorite Results Wallet Total time to full sync Behavior at 90–100% Screen stay-on? Finished? Notes Monerujo 21 minutes 45 seconds Steady speed, no slowdown No Yes Absolutely crushed it Cake Wallet 40 minutes and 13 seconds Very slow after ~90%, ETA broken Yes (huge W) Yes Got there, but it was a bit slow Stack Wallet Gave up after ~1 hour 16 minutes Crawled after 98%, resync didn’t help No No Stuck forever around 98–99% Detailed observations Monerujo 4.1.7 – The clear winner Started scanning instantly Progress was smooth and predictable the entire time Never slowed down, even in the final 10% Just worked. 21m45s from entering the 25th word to “synchronized”. Does NOT prevent screen timeout → Android kept suspending the process Cake Wallet 5.6.2 – It gets there… eventually Restore started fine ETA counter was not precise (showed 2 minutes for 30 minutes) Massive slowdown after ~90% Kept screen on the entire time ← this alone probably saved the sync from dying Eventually finished Stack Wallet 2.4.2 – Disappointing Actually started the fastest of all three Flew to 98% in ~25 minutes… then died Speed dropped Restarting the app resumed at 98.49% but didn’t fix the crawl Tried using the \u0026ldquo;Resync\u0026rdquo; button – no improvement Does NOT prevent screen timeout → Android kept suspending the process Abandoned after 1+ hours of no meaningful progress Conclusion: Monerujo is the fastest in 2025 If you want to restore an old Monero wallet on a phone using your own node in 2025, the answer is crystal clear:\nMonerujo is in a completely different league.\nCake Wallet is still very usable and has an amazin UI/polish, but the sync performance lag is real. Stack Wallet unfortunately seems broken/super slow for large restores right now\nShoutout to the Monerujo dev(s) — whatever witchcraft you did with the scanning engine, thank you. Privacy on mobile just became faster.\nTested on 2025-12-10 with a local node. Your mileage may vary with transaction count, but the relative ordering should hold.\n","date":"2025-12-10T22:46:43Z","permalink":"/fastest-monero-wallet-on-android-in-2025-i-timed-all-three-with-my-own-node/","title":"Fastest Monero Wallet on Android in 2025? I Timed All Three With My Own Node"},{"content":"Introduction Starting a fresh WordPress site in 2026? Whether it\u0026rsquo;s a blog, eCommerce store, or portfolio, these tweaks will supercharge speed, lock down security, and ensure buttery-smooth performance from day one.\nNo paid tools required — just free plugins and quick configs. Let\u0026rsquo;s dive in!\n1. Auto-Resize \u0026amp; Compress Images on Upload Images are the #1 bandwidth killer. Don\u0026rsquo;t upload a 10MB photo and hope for the best — automate compression to keep your site lean.\nRecommended Plugin: Resize Image After Upload (Free, 90K+ active installs, 4.8/5 rating)\nInstall \u0026amp; activate it first thing. Set max width/height (e.g., 1920px wide) and compression level (default 82% JPEG quality is solid). It auto-resizes JPEG/PNG/GIF on upload, slashes file sizes by 50–80%, and boosts SEO with faster load times. Pro tip: For bulk-optimizing existing images, pair it with Smush (free tier handles 50 images/month).\nResult: Pages load 2–3x faster, less server strain, happier Google rankings.\n2. Strip Out Unnecessary Bloat WordPress ships with \u0026ldquo;extras\u0026rdquo; you might not need — like Gutenberg blocks, XML-RPC, or emoji scripts. Trim the fat for a lighter core.\nRecommended Plugin: Unbloater (Free, 10K+ active installs, 5/5 rating)\nSimple dashboard under Settings \u0026gt; Unbloater.\nRecommended toggles:\nBackend: Disable auto-updates (if you handle them manually), limit post revisions to 3, hide update nags for non-admins, disable XML-RPC. Frontend: Remove RSD/WLW manifests, shortlinks, feed links, jQuery Migrate, emoji scripts. Block Editor: Fully disable Gutenberg (if using Classic Editor) or remove unused blocks. Extras: Block DNS prefetch to WordPress.org, remove generator meta tag. Everything is reversible — toggle off if issues arise. This cuts database queries and JS/CSS bloat by 20–30%.\n3. Tame the Heartbeat API WordPress\u0026rsquo; Heartbeat API pings your server every 15–60 seconds for autosave, user presence, etc. Great for collaboration, but it spikes CPU on shared hosting.\nRecommended Plugin: Heartbeat Control (Free, 90K+ active installs, 4.1/5 rating)\nGo to Settings \u0026gt; Heartbeat Control. Set intervals: 60 seconds (frontend), 120 seconds (dashboard/editor). Or disable entirely on frontend if you don\u0026rsquo;t need live previews. Unbloater can handle this too. Expect 10–20% CPU savings on idle sessions.\n4. Limit Post Revisions By default, WordPress saves 25 revisions per post — bloating your database over time (e.g., a 1,000-post site = 25K+ entries).\nAdd to wp-config.php (before \u0026ldquo;That\u0026rsquo;s all, stop editing!\u0026rdquo;):\n// Limit to 3 revisions (or false to disable) define(\u0026#39;WP_POST_REVISIONS\u0026#39;, 3); Unbloater has a toggle for this. Clean up old ones with WP-Optimize (free).\nResult: Smaller DB = faster queries and backups.\n5. Disable XML-RPC (Unless Needed) XML-RPC enables remote posting/apps but is a brute-force magnet (most bots target it).\nIf using Jetpack/mobile apps: Keep it, but whitelist your IP. Otherwise: Block via .htaccess (Apache/LiteSpeed): \u0026lt;Files xmlrpc.php\u0026gt; Order Deny,Allow Deny from all # Allow from YOUR.IP.ADDRESS (uncomment if needed) \u0026lt;/Files\u0026gt; Unbloater or Loginizer (free, 1M+ installs) can disable it too.\n6. Lock Down Logins with Rate Limiting Bots hammer /wp-login.php 24/7. Limit attempts to stop brute-force attacks cold.\nTop Pick: Limit Login Attempts Reloaded (Free, 2M+ installs, 4.9/5 rating)\nDefaults: 3 failed attempts → 15-min lockout (escalates to 24h). Covers wp-admin, XML-RPC, WooCommerce, custom logins. Logs + notifications included. Alternative: BruteGuard (Free, cloud-based botnet blocking via shared network).\nLoginizer (1M+ installs) adds 2FA + reCAPTCHA for extra layers.\nTest: Try wrong logins — you\u0026rsquo;ll see instant blocks.\n7. Vet Plugins Before Installing Not all plugins are equal — some bloat your site with 1MB+ RAM usage or JS errors. Always check:\nWP Hive: Chrome extension + site for automated tests (memory, page speed impact, PHP/WordPress compatibility, DB footprint). E.g., Yoast SEO 20.1: +0.1s load time, 1MB RAM (heavier than average). PluginTests.com: Basic compatibility/smoke tests for 98% of WP.org plugins (activation errors, obvious breaks). Quick Example (2025 Benchmarks):\nYoast SEO: Solid but resource-heavy (+0.1s load, 1MB RAM). Great for readability. Rank Math SEO: Lighter (no load impact, \u0026lt;250KB RAM), more free features. Often 4x faster in tests. Aim for lightweight picks — only add \u0026ldquo;heavy\u0026rdquo; ones if essential.\nWrap-Up Implement these today, and your site will launch 2–3x faster, more secure, and future-proof. Total time: ~30 minutes. No excuses!\nThanks for reading! 🚀\n","date":"2025-12-09T01:45:24Z","permalink":"/7-things-that-you-should-do-after-installing-wordpress/","title":"7 things that you should do after installing WordPress"},{"content":"Introduction One of the most frustrating things when working on a server?\nYour SSH session dies because of a brief Wi-Fi hiccup, idle timeout, or flaky connection.\nFix it forever in 30 seconds.\nThe Universal Fix: Edit Your SSH Config This works on Linux, macOS, and Windows — and survives network glitches up to ~4–5 minutes.\nStep 1: Create or Edit the SSH Config File On Linux / macOS:\nmkdir -p ~/.ssh nano ~/.ssh/config On Windows (PowerShell):\n# Replace YourUsername with your actual Windows username mkdir \u0026#34;$HOME\\.ssh\u0026#34; -Force notepad \u0026#34;$HOME\\.ssh\\config\u0026#34; Step 2: Add These Lines sshHost * ServerAliveInterval 120 ServerAliveCountMax 3 TCPKeepAlive yes Save and exit.\nDone. That’s it.\nWhat This Actually Does Setting Meaning Host * Apply these rules to every SSH connection ServerAliveInterval 120 Every 2 minutes, your computer sends a tiny “I’m still here” packet ServerAliveCountMax 3 If 3 packets in a row fail → only then close the connection (~6 min) TCPKeepAlive yes Extra OS-level keepalive (helps with some routers/firewalls) Result: Your SSH session now survives:\nWi-Fi switching Laptop sleep/wake Brief internet drops VPN reconnects …without freezing or dying.\nYou\u0026rsquo;re Now Unbreakable From now on, when your internet blinks, your SSH session just… waits patiently.\nNo more “Connection reset by peer” No more lost tmux sessions No more rage\nYou’ve officially leveled up.\nThank you for reading — stay connected!\n","date":"2025-12-09T01:41:02Z","permalink":"/how-to-avoid-timeouts-while-you-are-logged-on-ssh/","title":"How to avoid timeouts while you are logged on SSH"},{"content":"Introduction Whether you\u0026rsquo;re debugging a full VPS, cleaning up a home server, or just curious — here are the fastest and most useful commands to understand what\u0026rsquo;s eating your disk space.\n1. Find the Biggest Files \u0026amp; Folders in the Current Directory du -shc * | sort -rh | head -15 du -shc * → shows size of everything in the current folder (human-readable, with total) sort -rh → sorts from biggest to smallest head -15 → shows only the top 15 culprits (change number as needed) Perfect for quickly spotting that one huge log file or backup folder.\nPro tip: Run it in /var, /home, or / to hunt down space hogs.\n2. Check Overall Disk Usage (All Partitions) df -h Shows:\nTotal/used/available space Percentage used Mount point Look for the line with / (root) or your main drive. Example: 64G used / 226G total → 28% full\nAdd \u0026ndash;exclude-type=tmpfs to hide temporary filesystems:\ndf -h --exclude-type=tmpfs --exclude-type=devtmpfs 3. Check Inode Usage (When \u0026ldquo;Disk Full\u0026rdquo; But df Shows Space Left) Sometimes your disk is full of millions of tiny files (logs, cache, sessions, etc.). Each file uses one inode.\nCheck inodes per folder in current directory:\ndu --inodes --max-depth=1 . | sort -nr Or system-wide:\ndf -i If \u0026ldquo;IUsed\u0026rdquo; is near 100%, you’re out of inodes — time to clean up small files!\nBonus One-Liners # Top 10 biggest directories in /home du -h /home | sort -rh | head -10 # Find files bigger than 1GB find / -type f -size +1G 2\u0026gt;/dev/null # Show only real disks (clean output) df -h -x squashfs -x tmpfs -x devtmpfs That’s it!\nYou now have the ultimate toolkit to never be surprised by a full disk again.\nThank you for reading!\n","date":"2025-12-09T01:34:27Z","permalink":"/how-to-check-disk-usage-per-file-or-directory-on-linux/","title":"How to check disk usage per file or directory on linux"},{"content":"If you’re like me, you prefer to run everything in Docker containers. They’re fast, isolated, and perfect for running multiple apps on one VPS.\nBut what happens when you want to:\nMove a container to a new server? Backup a database volume (NextCloud, PhotoPrism, Vaultwarden, etc.)? Restore data after a crash? Docker doesn’t include a built-in “export volume” button — but there’s a super simple and reliable trick using a temporary Ubuntu container.\nLet’s go!\nStep 1: List Your Volumes docker volume ls Example output:\nDRIVER VOLUME NAME local nextcloud_data local photoprism_storage local vaultwarden_data Pick the one you want to export (e.g., nextcloud_data).\nStep 2: Export a Volume → backup.tar.gz Run this one-line command (replace nextcloud_data with your volume name):\ndocker run --rm -v nextcloud_data:/data -v \u0026#34;$(pwd)\u0026#34;:/backup ubuntu \\ tar -czf /backup/nextcloud-data-backup.tar.gz -C /data ./ What this does:\nMounts your volume to /data inside a temporary container Mounts your current folder to /backup Creates a compressed archive of the entire volume After it finishes, you’ll have a file like: nextcloud-data-backup.tar.gz ← ready to download or move!\nPro tip: Add the date for clarity\ndocker run --rm -v nextcloud_data:/data -v \u0026#34;$(pwd)\u0026#34;:/backup ubuntu \\ tar -czf \u0026#34;/backup/nextcloud-data-$(date +%Y-%m-%d).tar.gz\u0026#34; -C /data ./ Step 3: Import on the New Server Copy your backup.tar.gz file to the new server (via scp, rsync, etc.) Then, create the empty volume (important!):\ndocker volume create nextcloud_data Run the import command (from the folder containing the backup file):\ndocker run --rm -v nextcloud_data:/data -v \u0026#34;$(pwd)\u0026#34;:/backup ubuntu \\ tar -xzf /backup/nextcloud-data-2025-04-05.tar.gz -C /data Done! Your volume is now fully restored.\nNever let Docker auto-create the volume during import — it can cause permission issues or merge problems.\nBonus: Using External Volumes with Docker Compose If you\u0026rsquo;re using docker-compose.yml, tell Docker that the volume is external (already exists):\nservices: nextcloud: image: nextcloud:latest volumes: - nextcloud_data:/var/www/html volumes: nextcloud_data: external: true Indentation matters — use exactly two spaces.\nReal-World Use Cases Migrating NextCloud to a new VPS Backing up Vaultwarden before upgrading Moving PhotoPrism library to a bigger server Disaster recovery This method is 100% reliable, works with any volume, and requires zero extra tools.\nYou now have a bulletproof Docker volume backup strategy.\nHappy containerizing! 🐳\nThank you for reading!\n","date":"2025-12-09T01:22:26Z","permalink":"/how-to-easily-export-and-import-docker-volumes/","title":"How to easily export and import docker volumes"},{"content":"Introduction Want to run heavy services on a powerful server at home, even though your ISP puts you behind CGNAT? This guide shows you exactly how to put them online — the old-school, bulletproof way using SSH reverse tunnels.\nNo Cloudflare Tunnel. No Ngrok. Just SSH + systemd.\nThe Downsides (and Why They’re Manageable) Home internet isn’t datacenter-grade (outages happen) Most ISPs use CGNAT → you can’t open ports normally Solution: Use a cheap VPS as a public “jump box”. Your heavy server stays home. The VPS only forwards ports.\nHow It Works – The Magic of Reverse SSH Tunnels (-R) Internet → Cheap VPS (public IP) → SSH reverse tunnel → Your home server (behind CGNAT) Your home server initiates an outbound SSH connection to the VPS and says: “Anything that hits port 8096 on you → send it to my local Jellyfin on 8096”\nZero ports opened on your home router. Zero exposure.\nStep-by-Step Setup 1. On Your Home Server (the powerful one) # Create folder for tunnel configs sudo mkdir -p /etc/sshtunnels # Example: expose Jellyfin (port 8096) sudo nano /etc/sshtunnels/jellyfin.conf Content of the file:\n8096:8096 # remote_port:local_port 443:8443 # optional: HTTPS reverse proxy on VPS → your local 8443 80:8080 One line per service. First number = port on the VPS, second = port on your home server.\n2. Generate an SSH Key (if you don’t have one) ssh-keygen -t ed25519 -C \u0026#34;home-server-tunnel\u0026#34; Copy the public key to your VPS:\nssh-copy-id user@your-vps-ip 3. Create the Tunnel Manager Script sudo nano /usr/local/bin/sshtunnel.sh #!/bin/bash # === EDIT THESE === REMOTE_USER=\u0026#34;root\u0026#34; # or your VPS user REMOTE_HOST=\u0026#34;123.45.67.89\u0026#34; # your VPS public IP SSH_KEY=\u0026#34;/home/youruser/.ssh/id_ed25519\u0026#34; SSH_PORT=\u0026#34;22\u0026#34; # change if you use a non-standard port # ================== INSTANCE=\u0026#34;$1\u0026#34; CONFIG_FILE=\u0026#34;/etc/sshtunnels/${INSTANCE}.conf\u0026#34; if [[ ! -f \u0026#34;$CONFIG_FILE\u0026#34; ]]; then echo \u0026#34;Error: Config file $CONFIG_FILE not found!\u0026#34; exit 1 fi # Build -R arguments FORWARD_OPTS=\u0026#34;\u0026#34; while IFS=: read -r remote_port local_port; do [[ -z \u0026#34;$remote_port\u0026#34; || \u0026#34;$remote_port\u0026#34; =~ ^# ]] \u0026amp;\u0026amp; continue # Clean any old process using the remote port ssh -p \u0026#34;$SSH_PORT\u0026#34; \u0026#34;$REMOTE_USER@$REMOTE_HOST\u0026#34; \\ \u0026#34;lsof -i :$remote_port -t | xargs -r kill -9\u0026#34; 2\u0026gt;/dev/null FORWARD_OPTS=\u0026#34;$FORWARD_OPTS -R $remote_port:localhost:$local_port\u0026#34; done \u0026lt; \u0026#34;$CONFIG_FILE\u0026#34; echo \u0026#34;Starting tunnel $INSTANCE → $REMOTE_HOST ($FORWARD_OPTS)\u0026#34; exec ssh -o StrictHostKeyChecking=no \\ -o ServerAliveInterval=30 \\ -o ServerAliveCountThreshold=3 \\ -o ExitOnForwardFailure=yes \\ -o GatewayPorts=yes \\ -N -T \\ -i \u0026#34;$SSH_KEY\u0026#34; \\ -p \u0026#34;$SSH_PORT\u0026#34; \\ $FORWARD_OPTS \\ \u0026#34;$REMOTE_USER@$REMOTE_HOST\u0026#34; Make it executable:\nsudo chmod +x /usr/local/bin/sshtunnel.sh 4. Create a Systemd Service (Auto-Start \u0026amp; Auto-Reconnect) sudo nano /etc/systemd/system/sshtunnel@.service [Unit] Description=SSH Reverse Tunnel for %i After=network-online.target Wants=network-online.target [Service] User=youruser # ← change to your home user (not root!) Group=youruser ExecStart=/usr/local/bin/sshtunnel.sh %i Restart=always RestartSec=10 [Install] WantedBy=multi-user.target Reload and enable:\nsudo systemctl daemon-reload # Start a tunnel (example: jellyfin) sudo systemctl enable --now sshtunnel@jellyfin.service Check status:\nsudo systemctl status sshtunnel@jellyfin.service 5. On the VPS Side (Optional but Recommended) Install a tiny web server or Caddy/nginx to terminate TLS and proxy to the forwarded ports.\nExample with Caddy (automatic HTTPS):\n# On the VPS apt install caddy # /etc/caddy/Caddyfile jellyfin.yourdomain.com { reverse_proxy localhost:8096 } Now jellyfin.yourdomain.com → your home Jellyfin, fully encrypted.\nAll running on my beast home server behind CGNAT.\nPros of This Setup Works behind any CGNAT / ISP block No third-party dependency (no Cloudflare, no Ngrok) Full encryption possible Survives reboots (systemd + Restart=always) Costs almost nothing Final Words This is the one really cool way I’ve found to self-host heavy services at home in 2025.\nYour powerful hardware stays home. Your $1/month VPS is just a traffic cop.\nThank you for reading — now go build your unstoppable home lab!\n","date":"2025-12-09T01:13:41Z","permalink":"/how-to-easily-self-host-at-home-and-put-your-projects-online-under-cgnat/","title":"How to easily self-host at home and put your projects online under CGNAT"},{"content":"Introduction Ghost is an incredibly fast and elegant blogging platform. But unlike WordPress, it doesn’t have built-in one-click backup plugins.\nThat changes today.\nIn this guide, you’ll set up a fully automated daily backup system that:\nDumps your MySQL database Backs up all themes, images, and content Compresses everything into a single .zip Uploads it securely to your cloud storage (pCloud, NextCloud, Google Drive, Dropbox, etc.) All using free tools: rclone + a simple bash script + cron.\nLet’s get started.\nStep 1: Install Rclone sudo apt update \u0026amp;\u0026amp; sudo apt install -y rclone Rclone is the Swiss Army knife of cloud storage — it supports over 70 providers.\nFull list: https://rclone.org/overview/\nStep 2: Configure Rclone (Connect Your Cloud Storage) Run:\nrclone config Follow the prompts:\nn → new remote Name it something like ghost-backup or pcloud Choose your provider (e.g., webdav for NextCloud, pcloud, google drive, etc.) Enter your credentials/URL when asked Test it works:\nrclone ls ghost-backup: You should see your remote files (or an empty folder if new).\nType q to quit.\nStep 3: Get Your Ghost Database Credentials Log in as your Ghost user (not root):\nsu - yourghostuser cd /var/www/ghost # or wherever you installed Ghost cat config.production.json Look for the database section. You’ll see something like:\n\u0026#34;database\u0026#34;: { \u0026#34;client\u0026#34;: \u0026#34;mysql\u0026#34;, \u0026#34;connection\u0026#34;: { \u0026#34;host\u0026#34;: \u0026#34;localhost\u0026#34;, \u0026#34;user\u0026#34;: \u0026#34;ghost_db_user\u0026#34;, \u0026#34;password\u0026#34;: \u0026#34;yoursecretpassword\u0026#34;, \u0026#34;database\u0026#34;: \u0026#34;ghost_prod\u0026#34; } } Write down:\nDatabase name (ghost_prod) Username (ghost_db_user) Password Step 4: Create the Backup Script Create the script as root:\nnano /root/backup-ghost.sh Paste this (then edit the variables below):\n#!/bin/bash # === EDIT THESE VALUES === GHOST_USER=\u0026#34;yourghostuser\u0026#34; # e.g. ghost GHOST_PATH=\u0026#34;/var/www/ghost\u0026#34; # path to your Ghost install DB_NAME=\u0026#34;ghost_prod\u0026#34; # from config.production.json DB_USER=\u0026#34;ghost_db_user\u0026#34; # from config.production.json DB_PASS=\u0026#34;yoursecretpassword\u0026#34; # from config.production.json BACKUP_NAME=\u0026#34;theselfhostingart-blog\u0026#34; # name for your backup zip RCLONE_REMOTE=\u0026#34;ghost-backup\u0026#34; # name you gave in rclone config RCLONE_PATH=\u0026#34;/\u0026#34; # folder in your cloud (use / for root) # ========================= DATE=$(date +\u0026#39;%Y-%m-%d_%H-%M\u0026#39;) BACKUP_DIR=\u0026#34;/home/$GHOST_USER/backups/$DATE\u0026#34; ZIP_FILE=\u0026#34;$BACKUP_DIR/$BACKUP_NAME-$DATE.zip\u0026#34; echo \u0026#34;Starting Ghost backup: $DATE\u0026#34; # Create backup directory mkdir -p \u0026#34;$BACKUP_DIR\u0026#34; # Backup database echo \u0026#34;Backing up database...\u0026#34; mysqldump -u \u0026#34;$DB_USER\u0026#34; -p\u0026#34;$DB_PASS\u0026#34; --add-drop-table \u0026#34;$DB_NAME\u0026#34; | gzip \u0026gt; \u0026#34;$BACKUP_DIR/db.sql.gz\u0026#34; # Backup content folder (themes, images, etc.) echo \u0026#34;Backing up content folder...\u0026#34; rsync -av --exclude=\u0026#39;logs\u0026#39; --exclude=\u0026#39;cache\u0026#39; \u0026#34;$GHOST_PATH/content/\u0026#34; \u0026#34;$BACKUP_DIR/content/\u0026#34; # Compress everything echo \u0026#34;Compressing backup...\u0026#34; zip -r \u0026#34;$ZIP_FILE\u0026#34; \u0026#34;$BACKUP_DIR/content\u0026#34; \u0026#34;$BACKUP_DIR/db.sql.gz\u0026#34; \u0026gt; /dev/null # Upload to cloud echo \u0026#34;Uploading to cloud storage...\u0026#34; rclone copy \u0026#34;$ZIP_FILE\u0026#34; \u0026#34;$RCLONE_REMOTE:$RCLONE_PATH\u0026#34; # Cleanup: remove local backups older than 1 day (optional but recommended) echo \u0026#34;Cleaning up old local backups...\u0026#34; find /home/$GHOST_USER/backups -type d -mtime +1 -exec rm -rf {} + echo \u0026#34;Backup complete: $ZIP_FILE → $RCLONE_REMOTE:$RCLONE_PATH\u0026#34; Make it executable:\nchmod +x /root/backup-ghost.sh Test it manually first:\n/root/backup-ghost.sh Check your cloud storage — you should see a file like: theselfhostingart-blog-2025-04-05_03-22.zip\nStep 5: Automate with Cron (Daily Backups) crontab -e Add this line for daily backup at 2:00 AM:\ncron0 2 * * * /usr/bin/bash /root/backup-ghost.sh \u0026gt;\u0026gt; /var/log/ghost-backup.log 2\u0026gt;\u0026amp;1\nSave and exit.\nYour Ghost blog is now automatically backed up every day.\nWhat’s Included in the Backup? Full database (posts, users, settings) All uploaded images Custom themes Everything needed to restore or migrate You can even send this .zip to Ghost(Pro) support — they can import it directly.\nBonus: Restore in Case of Disaster To restore:\nInstall fresh Ghost Unzip backup Import DB: gunzip \u0026lt; db.sql.gz | mysql -u user -p dbname Replace content/ folder Run ghost restart Credits \u0026amp; Thanks This method is inspired and improved from this excellent post: How to Automatically Backup Ghost Blogs – Kenton Vizdos\nThank you, Kenton!\nYour self-hosted blog now sleeps better at night. 😴💾\nThank you for reading!\n","date":"2025-12-09T01:05:55Z","permalink":"/how-to-automatically-backup-your-self-hosted-ghost-blog/","title":"How to Automatically Backup Your Self-Hosted Ghost Blog"},{"content":"Introduction Today I’ll show you how to build what I genuinely believe is the fastest NextCloud stack available in 2025:\nOpenLiteSpeed – the fastest web server with built-in cache LSPHP 8.1/8.2 – LiteSpeed’s ultra-fast PHP implementation Redis + APCu – for blazing-fast caching and locking Runs completely non-root, under its own user Hardened with proper security headers, HSTS, and isolated data folder Even if NextCloud gets compromised, the attacker still can’t touch the rest of your server.\nLet’s go!\nStep 1: Secure Your VPS First Before anything, harden your server. Follow my full guide here: How to Make Your VPS Secure\nStep 2: Install OpenLiteSpeed, LSPHP, Redis \u0026amp; Tools Run as root:\n# Update system apt update \u0026amp;\u0026amp; apt upgrade -y # Add OpenLiteSpeed repository wget -O - https://repo.litespeed.sh | bash # Install essentials apt install -y curl gnupg2 imagemagick ffmpeg redis openlitespeed lsphp81* lsphp82* zip unzip mariadb-server mariadb-client Note: On Ubuntu 22.04+, the ImageMagick package might be libmagickwand-dev + imagemagick. The above works on most recent Debian/Ubuntu.\nEnable and restart Redis:\nsystemctl enable --now redis-server Step 3: Create a Dedicated System User for NextCloud adduser --shell /bin/bash files usermod -aG redis files # Allow access to Redis socket Step 4: Download \u0026amp; Extract NextCloud as the \u0026ldquo;files\u0026rdquo; User su - files mkdir -p ~/public_html cd ~/public_html wget https://download.nextcloud.com/server/releases/latest.zip unzip latest.zip rsync -av nextcloud/ ./ rm -rf nextcloud latest.zip .htaccess .user.ini exit Step 5: Configure OpenLiteSpeed Web Admin (Port 7080) Set an admin password:\n/usr/local/lsws/admin/misc/admpass.sh Now visit: https://your-vps-ip:7080 and log in.\nVirtual Host Setup Delete the default \u0026ldquo;Example\u0026rdquo; virtual host Add new Virtual Host: Virtual Host Name: yourdomain.com Virtual Host Root: /home/files/ Config File: $SERVER_ROOT/conf/vhosts/$VH_NAME/vhconf.conf Document Root: $VH_ROOT/public_html Script Handler → Add: Suffix: php Handler Type: LiteSpeed LVE Handler: lsphp81 (or lsphp82 if you prefer PHP 8.2) Rewrite Rules (force HTTPS): RewriteEngine On RewriteCond %{HTTPS} !=on RewriteRule ^(.*)$ https://%{HTTP_HOST}$1 [R=301,L] Security Headers (Context → Static → Add new context /): Strict-Transport-Security \u0026#34;max-age=63072000; includeSubDomains; preload\u0026#34; Content-Security-Policy \u0026#34;upgrade-insecure-requests\u0026#34; External App → LSPHP → Edit: Run as User/Group: files PHP_LSAPI_CHILDREN = 100 LSAPI_AVOID_FORK = 0 Listeners: Delete default listeners Add HTTP → port 80 Add HTTPS → port 443 (Secure = Yes) Map your domain to both listeners Graceful restart → OpenLiteSpeed → Graceful Restart\nStep 6: Issue Let’s Encrypt SSL apt install -y certbot certbot certonly --webroot -w /home/files/public_html -d yourdomain.com Note the paths (you’ll need them):\nFullchain: /etc/letsencrypt/live/yourdomain.com/fullchain.pem Privkey: /etc/letsencrypt/live/yourdomain.com/privkey.pem Add them in:\nVirtual Host → SSL tab Listener HTTPS → SSL tab Chained Certificate = Yes Graceful restart again.\nStep 7: Auto-Renew SSL crontab -e Add:\ncron0 3 * * * /usr/bin/certbot renew --quiet\nStep 8: Install \u0026amp; Secure MariaDB/MySQL mysql_secure_installation Then create database \u0026amp; user:\nmysql -u root -p CREATE DATABASE nextcloud CHARACTER SET utf8mb4 COLLATE utf8mb4_general_ci; CREATE USER \u0026#39;ncuser\u0026#39;@\u0026#39;localhost\u0026#39; IDENTIFIED BY \u0026#39;strong-password-here\u0026#39;; GRANT ALL PRIVILEGES ON nextcloud.* TO \u0026#39;ncuser\u0026#39;@\u0026#39;localhost\u0026#39;; FLUSH PRIVILEGES; EXIT; Step 9: Optimize PHP \u0026amp; Enable OPCache + APCu # Edit the correct php.ini (adjust path if using lsphp82) sed -i \u0026#39;/usr/local/lsws/lsphp81/etc/php/8.1/litespeed/php.ini\u0026#39; \\ -e \u0026#39;s/memory_limit = .*/memory_limit = 1024M/\u0026#39; \\ -e \u0026#39;s/upload_max_filesize = .*/upload_max_filesize = 10G/\u0026#39; \\ -e \u0026#39;s/post_max_size = .*/post_max_size = 10G/\u0026#39; \\ -e \u0026#39;s/max_execution_time = .*/max_execution_time = 3600/\u0026#39; \\ -e \u0026#39;s/opcache.enable=.*/opcache.enable=1/\u0026#39; \\ -e \u0026#39;s/;opcache.memory_consumption=.*/opcache.memory_consumption=512/\u0026#39; \\ -e \u0026#39;s/;opcache.interned_strings_buffer=.*/opcache.interned_strings_buffer=64/\u0026#39; \\ -e \u0026#39;s/;opcache.max_accelerated_files=.*/opcache.max_accelerated_files=20000/\u0026#39; # Enable APCu CLI echo \u0026#34;apc.enable_cli = 1\u0026#34; \u0026gt;\u0026gt; /usr/local/lsws/lsphp81/etc/php/8.1/litespeed/php.ini pkill -f lsphp systemctl restart lsws Step 10: Configure Redis as Unix Socket sed -i \u0026#39;s/port 6379/port 0/\u0026#39; /etc/redis/redis.conf sed -i \u0026#39;s|# unixsocket /var/run/redis/redis-server.sock|unixsocket /var/run/redis/redis-server.sock|\u0026#39; /etc/redis/redis.conf sed -i \u0026#39;s/# unixsocketperm 700/unixsocketperm 770/\u0026#39; /etc/redis/redis.conf sed -i \u0026#39;s/# maxmemory .*/maxmemory 1gb/\u0026#39; /etc/redis/redis.conf systemctl restart redis-server Step 11: Final NextCloud Configuration Move Data Folder Outside Web Root (Critical!) During setup, set data directory to: /home/files/data\nEdit config.php (after first login) su - files nano /home/files/public_html/config/config.php Add right after \u0026lsquo;installed\u0026rsquo; =\u0026gt; true,:\n\u0026#39;memcache.local\u0026#39; =\u0026gt; \u0026#39;\\\\OC\\\\Memcache\\\\APCu\u0026#39;, \u0026#39;memcache.distributed\u0026#39; =\u0026gt; \u0026#39;\\\\OC\\\\Memcache\\\\Redis\u0026#39;, \u0026#39;memcache.locking\u0026#39; =\u0026gt; \u0026#39;\\\\OC\\\\Memcache\\\\Redis\u0026#39;, \u0026#39;redis\u0026#39; =\u0026gt; [ \u0026#39;host\u0026#39; =\u0026gt; \u0026#39;/var/run/redis/redis-server.sock\u0026#39;, \u0026#39;port\u0026#39; =\u0026gt; 0, ], Set Up Background Jobs (Cron) su - files crontab -e Add:\ncron*/5 * * * * /usr/local/lsws/lsphp81/bin/php -f /home/files/public_html/cron.php\nThen in NextCloud Admin → Basic Settings → Background jobs → Select Cron (recommended).\nBonus: Make occ Easy to Use Forever su - files echo \u0026#34;alias occ=\u0026#39;/usr/local/lsws/lsphp81/bin/php /home/files/public_html/occ\u0026#39;\u0026#34; \u0026gt;\u0026gt; ~/.bashrc source ~/.bashrc Now from anywhere in ~/public_html:\ncd ~/public_html occ status occ maintenance:repair occ db:add-missing-indices You\u0026rsquo;re Done! You now have:\nThe fastest NextCloud stack (OpenLiteSpeed + Redis + APCu) Fully non-root and isolated Automatic SSL renewal Hardened security headers Proper data folder protection Enjoy your blazing-fast, private cloud!\nThank you for reading! 🚀\n","date":"2025-12-09T00:59:45Z","permalink":"/how-to-install-nextcloud-with-openlitespeed-lomp-stack/","title":"How to install NextCloud with OpenLiteSpeed (LOMP stack)"},{"content":"Introduction Have you ever deleted a file or a folder by mistake in a VPS? That feeling sucks. Sometimes you are working fast and you delete a really important file/folder. This happened to me previously. Today I want to share an amazing tool with you guys: trash-cli . It adds a trash in the CLI to prevent these human mistakes.\nInstalling trash-cli trash-cli is a lightweight, command-line tool available in Debian repositories, making it ideal for VPS environments with limited resources.\nInstallation Steps Update your package list: sudo apt update Install trash-cli: sudo apt install trash-cli Verify the installation: trash --version You should see version information if installed correctly.\nThis process is quick and adds minimal overhead to your VPS.\nUsing trash-cli for Safer Deletions Once installed, trash-cli provides commands to manage files safely. It moves items to ~/.local/share/Trash/ instead of deleting them.\nBasic Commands Trash a file or directory: trash file.txt or trash directory. List trashed items: trash-list (shows files with deletion dates). Restore items: trash-restore (interactive menu to select and recover files). Empty the trash: trash-empty (permanently deletes all trashed items). Empty old items: trash-empty 30 (deletes items older than 30 days). Example workflow:\ntrash important_file.txt # Move to trash trash-list # Check what\u0026#39;s there trash-restore # Recover if needed This replaces risky rm usage in daily operations.\nAliasing rm to Use trash-cli To make rm safer by default, alias it to trash in your shell configuration. This ensures most deletions go to the trash bin.\nSetting Up the Alias Edit your ~/.bashrc file: nano ~/.bashrc Add this line at the end: alias rm=\u0026#39;trash\u0026#39; Save and exit (Ctrl+X, Y, Enter).\nReload the configuration:\nsource ~/.bashrc Now, rm file.txt will use trash instead of permanent deletion.\nAutomating Trash Emptying with Cron To prevent the trash from accumulating indefinitely, automate emptying with a cron job.\nSetting Up Weekly Emptying Edit your crontab: crontab -e Add this line for weekly deletion (e.g., every Sunday at 2 AM): 0 2 * * 0 /usr/bin/trash-empty 0 2 * * 0: Sunday at 2:00 AM. /usr/bin/trash-empty: Clears all trash. Save and exit.\nVerify:\ncrontab -l Adjust the schedule as needed (e.g., change 0 to 1-6 for weekdays). For partial emptying, use trash-empty 30 to delete items older than 30 days.\nConclusion By installing trash-cli, aliasing rm to trash, and setting up automated emptying, you can make your VPS much safer against accidental deletions. This approach adds a recoverable layer without sacrificing performance. Remember to combine it with regular backups and cautious command usage. If you\u0026rsquo;re new to VPS management, start small and test thoroughly. For more advanced setups, explore integrating with monitoring tools. Stay safe out there!\n","date":"2025-12-09T00:31:57Z","permalink":"/how-to-make-your-vps-safer-against-accidental-deletions/","title":"How to Make Your VPS Safer Against Accidental Deletions"},{"content":"Introduction If you just bought a VPS and are starting to self-host, this is one of the most important security improvements you can make.\nBy switching to SSH key authentication and disabling password login, your server becomes nearly immune to brute-force attacks — even if someone discovers your password or you\u0026rsquo;re still using the default port 22.\nStep 1: Generate an SSH Key Pair on Your Local Machine Linux \u0026amp; macOS Open a terminal and run:\nssh-keygen -t rsa -b 4096 or (newer recommended format):\nBash\nssh-keygen -t ed25519 Press Enter to accept the default file location and leave the passphrase empty (just hit Enter twice).\nYour keys will be saved as:\nPrivate key: ~/.ssh/id_rsa or ~/.ssh/id_ed25519 Public key: ~/.ssh/id_rsa.pub or ~/.ssh/id_ed25519.pub Never share the private key!\nWindows (PowerShell) Open PowerShell and run:\nssh-keygen.exe -t ed25519 (or -t rsa -b 4096 if ed25519 is not supported)\nPress Enter through the prompts (no passphrase). Keys will be created in C:\\Users\\YourUser.ssh\\\nStep 2: Copy Your Public Key to the VPS Linux \u0026amp; macOS (Easiest Method) ssh-copy-id user@your-vps-ip Replace user and your-vps-ip with your actual username and server IP.\nWindows Paste your public key (it’s one long line starting with ssh-ed25519 or ssh-rsa) → Save with Ctrl+O → Enter → Ctrl+X Test it: Open a new terminal/PowerShell and try logging in. It should work without asking for a password. Edit the file:Bash\nnano ~/.ssh/authorized_keys Create the .ssh folder and authorized_keys file (if they don\u0026rsquo;t exist):Bash\nmkdir -p ~/.ssh chmod 700 ~/.ssh touch ~/.ssh/authorized_keys chmod 600 ~/.ssh/authorized_keys Log into your VPS normally (with password):PowerShell\nssh user@your-vps-ip Copy your public key to clipboard:PowerShell\nGet-Content $HOME\\.ssh\\id_ed25519.pub | Set-Clipboard (or id_rsa.pub if you used RSA)\nStep 3: Disable Password Authentication Now that key login works, disable password login entirely.\nLog into your VPS (using your key) and edit the SSH config:\nsudo nano /etc/ssh/sshd_config Find and change (or add) these lines:\nPasswordAuthentication no ChallengeResponseAuthentication no UsePAM no PubkeyAuthentication yes Save and exit.\nRestart the SSH service:\nsudo systemctl restart sshd (or sudo service ssh restart on older systems)\nFinal test: Try logging in from a new terminal. It should only work with your private key — password attempts will be rejected instantly.\nDone! Your VPS is now protected against:\nBrute-force attacks Credential stuffing Weak or leaked passwords Even if an attacker knows your username and password, they cannot log in without your private key file.\nPro tip: Back up your private key securely and consider adding a passphrase later using ssh-keygen -p.\nThank you for reading! 😊\n","date":"2025-12-09T00:30:29Z","permalink":"/how-to-make-your-vps-secure/","title":"How to make your VPS secure"},{"content":"Introduction Unfortunately, many hosting providers impose very low upload limits (sometimes as little as 2–50 MB), and the official Unlimited Extension costs $69.\nIf you’re in that situation and need a free way to upload huge backups (10 GB, 40 GB, or more), this simple trick will help.\nThe Solution: Use \u0026ldquo;Big File Uploads\u0026rdquo; Plugin The free version of All-in-One WP Migration doesn’t artificially limit uploads — it simply respects whatever limit your hosting or server enforces. The paid Unlimited Extension works by splitting the .wpress file into smaller chunks during upload.\nGood news: there’s a completely free plugin that does the exact same chunking trick!\nStep-by-Step Guide Install and activate the plugin called Big File Uploads → Direct link: https://wordpress.org/plugins/tuxedo-big-file-uploads/ After activation, go to: Settings → Big File Uploads (or find it under the Plugins page → “Settings” link under the plugin name) You’ll see the current maximum upload size (it will match your host’s default limit at first). Change it to whatever you want: 1 GB = 1024 MB 10 GB = 10240 MB 40 GB = 40960 MB (Just type the number in megabytes — no need to add “MB” or “GB”) Click Save Changes That’s it! The new limit takes effect immediately.\nNow when you go back to All-in-One WP Migration → Import, the max file size will reflect your new value (even 40 GB or higher works perfectly).\nConclusion This is not meant as an attack on ServMask — they’ve built an amazing plugin and absolutely deserve support. If you can afford it, please buy the official Unlimited Extension.\nBut if budget is tight and you just need to migrate or restore a huge site once or twice, the Big File Uploads plugin is a 100% free and reliable alternative that works perfectly with the free version of All-in-One WP Migration.\nThank you for reading! 🙂\n","date":"2025-12-09T00:25:04Z","permalink":"/how-to-remove-upload-limits-on-all-in-one-wp-migration/","title":"How to remove upload limits on All In One WP Migration"},{"content":"Introduction Monero is one of the most important cryptocurrencies in my opinion. It does not have the same market share as Bitcoin, but it is quite unique in one aspect: privacy. Monero is just like cash — no one needs to know how much Monero was sent or who sent it. It\u0026rsquo;s the opposite of Bitcoin in this regard. In fact, Bitcoin is worse than fiat money when it comes to privacy.\nYou can read more details here: https://lukesmith.xyz/articles/monero-maximalism-or-how-bitcoin-is-a-coin/\nObs: I\u0026rsquo;m NOT recommending anyone invest in Monero. Monero is supposed to be a currency, but since crypto is still extremely volatile, many people treat it as an investment. Do your own research — I\u0026rsquo;m not responsible for any investments you make.\n1. Choose a VPS or set it up at home First things first, you will need a server. You can use your own home PC if you prefer, or a VPS. A VPS is easier because it stays online 24/7 and you can always open the required ports.\nAt home, many ISPs block incoming ports, so your node wouldn’t be public (it would still help the network, but you couldn’t easily connect to it from outside without something like ngrok).\nI personally recommend Contabo for running a Monero node because they offer excellent prices on storage VPS plans. Check their pricing here: Contabo Storage VPS\nThe Storage VPS S is more than enough. The Monero blockchain currently uses about 175 GB, less than 2 GB of RAM, and barely any CPU once fully synced (~3 % usage).\n2. Securing the VPS First of all, disable password login.\nThen install and configure UFW (if it’s not already set up):\nsudo apt install ufw sudo ufw default deny incoming sudo ufw default allow outgoing sudo ufw allow ssh sudo ufw allow 18080 sudo ufw allow 18089 sudo ufw enable 3. Creating a dedicated user For security reasons, never run Monero as root. Create a normal user instead:\nadduser monerouser Set a password and press Enter through the rest of the prompts.\n4. Changing settings and syncing the node Switch to the new user:\nsu monerouser cd ~ Download the official Monero CLI binaries (Linux 64-bit):\nwget -c https://downloads.getmonero.org/cli/monero-linux-x64-v0.18.3.4.tar.bz2 mkdir monero tar -xjvf monero-linux-x64-v0.18.3.4.tar.bz2 -C monero --strip-components=1 (Replace the version in the URL/filename with the latest one from https://getmonero.org if needed.)\nEnter the folder and start monerod once just to create the config files (stop it after a few seconds with Ctrl+C):\ncd monero ./monerod Now edit the configuration file:\nnano ~/.bitmonero/bitmonero.conf Paste the following recommended settings:\n# P2P full node public-node=true # Advertises the RPC-restricted port over p2p # RPC settings rpc-restricted-bind-ip=0.0.0.0 rpc-restricted-bind-port=18089 # Node settings enforce-dns-checkpointing=true db-sync-mode=safe # Slow but reliable db writes enable-dns-blocklist=true # Block known-malicious nodes no-igd=true # Disable UPnP no-zmq=true # Bandwidth settings (much faster sync + better contribution) out-peers=32 in-peers=32 limit-rate-up=1048576 # 1 GB/s upload limit-rate-down=1048576 # 1 GB/s download Save with Ctrl+O → Enter → Ctrl+X.\nStart the node in detached mode:\n./monerod --detach You\u0026rsquo;re done! Now just wait for it to fully sync.\nCheck sync status anytime with:\n./monerod status The initial sync usually takes a few hours depending on your connection and VPS speed.\nOnce it\u0026rsquo;s fully synced, you can connect any Monero wallet (Cake Wallet, Monero GUI, Feather, etc.) to your own node using your VPS IP and port 18089.\nConclusion \u0026amp; Credits That\u0026rsquo;s it! Running your own full node is strongly encouraged by the Monero community. It makes the network more decentralized and gives you maximum privacy.\nThis guide wouldn’t have been possible without these excellent resources:\nhttps://www.getmonero.org/resources/user-guides/vps_run_node.html https://www.coincashew.com/coins/overview-xmr/guide-or-how-to-run-a-full-node Thank you for reading! 🙂\n","date":"2025-12-09T00:07:50Z","permalink":"/how-to-run-your-own-monero-node/","title":"How to run your own monero node"},{"content":"Introduction Piped is a privacy-first, open-source alternative YouTube front-end. No Google tracking, no ads (even on videos that normally have unskippable ones), and it works perfectly with SponsorBlock and dearrow.\nSelf-hosting your own instance is incredibly easy with Docker and takes less than 20 minutes.\nRequirements A domain (or subdomain) A cheap KVM VPS with Docker support (avoid OpenVZ — old kernel) ~$3–6/month is more than enough (1 CPU, 1–2 GB RAM) Great cheap providers in 2025:\nRackNerd Hostinger (my affiliate if you want to support https://hostinger.com.br?REFERRALCODE=waterdownfall) Cloudcone, Hetzner Cloud, BuyVM, etc. Step 1: Secure \u0026amp; Prepare Your VPS (SSH keys only, firewall, etc. — do this first!)\nThen install Docker (Ubuntu/Debian example):\napt update \u0026amp;\u0026amp; apt upgrade -y apt install -y ca-certificates curl gnupg lsb-release # Add Docker repo sudo mkdir -p /etc/apt/keyrings curl -fsSL https://download.docker.com/linux/ubuntu/gpg | gpg --dearmor -o /etc/apt/keyrings/docker.gpg echo \u0026#34;deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] https://download.docker.com/linux/ubuntu $(lsb_release -cs) stable\u0026#34; \u0026gt; /etc/apt/sources.list.d/docker.list apt update apt install -y docker-ce docker-ce-cli containerd.io docker-compose-plugin Step 2: Deploy Piped with the Official Docker Setup cd /opt git clone https://github.com/TeamPiped/Piped-Docker cd Piped-Docker ./configure-instance.sh During the script:\nChoose Caddy as reverse proxy (easiest + automatic SSL)\nEnter your domain and subdomains:\nFrontend → piped.yourdomain.com Backend API → pipedapi.yourdomain.com Proxy → pipedproxy.yourdomain.com Step 3: Point DNS to Your VPS Create three A records at your DNS provider:\npiped.yourdomain.com → VPS_IP pipedapi.yourdomain.com → VPS_IP pipedproxy.yourdomain.com → VPS_IP Step 4: Launch Everything docker compose up -d That’s it! After DNS propagates (usually \u0026lt; 10 minutes), your private YouTube will be live at:\nhttps://piped.yourdomain.com\nCaddy automatically handles free Let’s Encrypt SSL — no manual certbot needed.\nStep 5: (Optional) Check Logs Bash\n# See what Caddy is doing docker logs -f caddy # Or any other container docker logs -f piped-frontend Bonus Tips Want to make it public? Just share the URL — anyone can use your instance. Want it private? Block it with Cloudflare firewall rules or basic auth in Caddy. Pair it with the LibreTube (Android) app for the full de-Googled experience. You now have your own ad-free, tracking-free, SponsorBlock-enabled YouTube — fully under your control.\nThanks for reading!\n","date":"2025-12-08T23:58:10Z","permalink":"/how-to-self-host-your-own-piped-instance/","title":"How to Self Host your own Piped Instance"},{"content":"Introduction GRUB Menu Not Showing → Windows Not Appearing on Boot\nJust installed Xubuntu (or Ubuntu) 23.10 alongside Windows and now it boots straight into Linux without showing the GRUB menu? Don’t worry — this is the new default behavior. Starting with recent Ubuntu versions, GRUB_TIMEOUT_STYLE is set to hidden and the timeout is 0 seconds, so the menu is completely skipped unless you hold Shift during boot.\nHere’s the permanent two-line fix.\nThe Fix (Takes 30 Seconds) Open a terminal and edit the GRUB config:\nsudo nano /etc/default/grub Make sure these lines are present and exactly like this (add them if missing):\nGRUB_TIMEOUT_STYLE=menu GRUB_TIMEOUT=10 Optional but recommended — make the menu look nicer and be 100% reliable:\nGRUB_TERMINAL=console Full example of the relevant section:\n# Show the GRUB menu every time GRUB_TIMEOUT_STYLE=menu GRUB_TIMEOUT=10 # seconds to wait before auto-booting the default entry GRUB_TERMINAL=console Save (Ctrl+O → Enter → Ctrl+X) and update GRUB:\nsudo update-grub Reboot and you’ll now see the full GRUB menu with both Ubuntu/Xubuntu and Windows listed. You can change the 10 to any number you like (or even -1 to wait indefinitely until you pick an entry).\nWhy This Happens Canonical decided to hide the menu by default for a “cleaner” boot experience on single-OS machines. For dual-boot users it’s just annoying — this fix restores the classic behavior permanently.\nThat’s it — enjoy easy access to both operating systems again!\n(Original solution via AskUbuntu community)\nThanks for reading!\n","date":"2025-12-08T23:53:06Z","permalink":"/how-to-setup-grub-for-dual-boot-on-ubuntu-23-10-fix/","title":"How to setup grub for Dual Boot on Ubuntu 23.10 (fix)"},{"content":"Introduction This is the fastest, most secure, and most resource-efficient way to self-host WordPress in 2025. We’ll use a proper LEMP stack (Linux + Nginx + MySQL/MariaDB + PHP-FPM) with per-site PHP isolation, Redis object caching, automatic SSL, and WP-CLI — everything tuned for speed and security.\nLet’s go.\nStep 0: Secure \u0026amp; Update Your VPS (If you haven’t already, follow a VPS hardening guide first — SSH keys only, firewall, fail2ban, etc.)\napt update \u0026amp;\u0026amp; apt upgrade -y apt autoremove --purge reboot Step 1: Install the Core Stack # Nginx apt install nginx -y systemctl enable nginx # MariaDB (better than MySQL on Debian) apt install mariadb-server -y systemctl enable mariadb # PHP 8.3 + all needed extensions (using ondrej/sury repo) apt install ca-certificates apt-transport-https lsb-release -y wget -qO- https://packages.sury.org/php/apt.gpg | gpg --dearmor \u0026gt; /usr/share/keyrings/sury-php.gpg echo \u0026#34;deb [signed-by=/usr/share/keyrings/sury-php.gpg] https://packages.sury.org/php/ $(lsb_release -sc) main\u0026#34; \u0026gt; /etc/apt/sources.list.d/sury-php.list apt update apt install php8.3-fpm php8.3-mysql php8.3-curl php8.3-gd php8.3-mbstring php8.3-xml php8.3-zip php8.3-intl php8.3-imagick php8.3-redis -y systemctl enable php8.3-fpm # Redis curl -fsSL https://packages.redis.io/gpg | gpg --dearmor -o /usr/share/keyrings/redis-archive-keyring.gpg echo \u0026#34;deb [signed-by=/usr/share/keyrings/redis-archive-keyring.gpg] https://packages.redis.io/deb $(lsb_release -cs) main\u0026#34; \u0026gt; /etc/apt/sources.list.d/redis.list apt update \u0026amp;\u0026amp; apt install redis-server -y systemctl enable redis-server # Certbot + WP-CLI apt install python3-certbot-nginx -y curl -O https://raw.githubusercontent.com/wp-cli/builds/gh-pages/phar/wp-cli.phar chmod +x wp-cli.phar \u0026amp;\u0026amp; mv wp-cli.phar /usr/local/bin/wp Step 2: Secure MariaDB \u0026amp; Create Database mysql_secure_installation mysql -u root -p CREATE DATABASE wp_yoursite; CREATE USER \u0026#39;wp_yoursite\u0026#39;@\u0026#39;localhost\u0026#39; IDENTIFIED BY \u0026#39;strongpassword\u0026#39;; GRANT ALL ON wp_yoursite.* TO \u0026#39;wp_yoursite\u0026#39;@\u0026#39;localhost\u0026#39;; FLUSH PRIVILEGES; EXIT; Step 3: Isolate PHP-FPM Per Site (Security + Stability) cd /etc/php/8.3/fpm/pool.d/ cp www.conf yoursite.conf nano yoursite.conf Replace:\n[www] → [yoursite] user = www-data → user = yoursiteuser (we’ll create this user soon) group = www-data → group = yoursiteuser listen = /run/php/php8.3-fpm.sock → listen = /run/php/php8.3-fpm-yoursite.sock Change process manager from dynamic → ondemand (saves RAM) systemctl restart php8.3-fpm (It will fail until the user exists — that’s fine.)\nStep 4: Optimize PHP \u0026amp; Enable OPcache sed -i \u0026#34;s/memory_limit = .*/memory_limit = 1024M/\u0026#34; /etc/php/8.3/fpm/php.ini sed -i \u0026#34;s/upload_max_filesize = .*/upload_max_filesize = 10240M/\u0026#34; /etc/php/8.3/fpm/php.ini sed -i \u0026#34;s/post_max_size = .*/post_max_size = 10240M/\u0026#34; /etc/php/8.3/fpm/php.ini sed -i \u0026#34;s/max_execution_time = .*/max_execution_time = 600/\u0026#34; /etc/php/8.3/fpm/php.ini sed -i \u0026#34;s/;opcache.enable=1/opcache.enable=1/\u0026#34; /etc/php/8.3/fpm/php.ini sed -i \u0026#34;s/;opcache.memory_consumption=.*/opcache.memory_consumption=512/\u0026#34; /etc/php/8.3/fpm/php.ini sed -i \u0026#34;s/;opcache.max_accelerated_files=.*/opcache.max_accelerated_files=20000/\u0026#34; /etc/php/8.3/fpm/php.ini sed -i \u0026#34;s/;cgi.fix_pathinfo=1/cgi.fix_pathinfo=0/\u0026#34; /etc/php/8.3/fpm/php.ini Step 5: Create System User \u0026amp; Site Directory adduser yoursiteuser --shell /bin/bash su yoursiteuser mkdir ~/public_html \u0026amp;\u0026amp; cd ~/public_html echo \u0026#34;cd ~/public_html\u0026#34; \u0026gt;\u0026gt; ~/.bashrc exit Step 6: Nginx Config (Fast \u0026amp; Secure) nano /etc/nginx/sites-available/yoursite.conf upstream php-yoursite { server unix:/run/php/php8.3-fpm-yoursite.sock; } server { listen 80; listen [::]:80; server_name yourdomain.com www.yourdomain.com; root /home/yoursiteuser/public_html; index index.php index.html; client_max_body_size 10G; location / { try_files $uri $uri/ /index.php?$args; } location ~ \\.php$ { include fastcgi_params; fastcgi_pass php-yoursite; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; } location ~* \\.(js|css|png|jpg|jpeg|gif|ico|svg|woff2?|ttf|eot)$ { expires max; log_not_found off; } } ln -s /etc/nginx/sites-available/yoursite.conf /etc/nginx/sites-enabled/ nginx -t \u0026amp;\u0026amp; systemctl reload nginx Step 7: Install WordPress via WP-CLI (as the site user) su yoursiteuser cd ~/public_html wp core download wp config create --dbname=wp_yoursite --dbuser=wp_yoursite --dbpass=\u0026#39;strongpassword\u0026#39; --locale=en_US wp core install --url=https://yourdomain.com --title=\u0026#34;Your Site\u0026#34; --admin_user=admin --admin_password=\u0026#39;strongpass\u0026#39; --admin_email=you@domain.com Step 8: SSL with Let’s Encrypt (Auto-renew) certbot --nginx -d yourdomain.com -d www.yourdomain.com # Choose redirect to HTTPS when asked Add auto-renew cron:\ncrontab -e # Add: 0 0 * * 0 certbot renew --quiet Step 9: Enable Redis Object Cache # As root usermod -aG redis yoursiteuser chmod 770 /var/run/redis/redis-server.sock # Optimize Redis config sed -i \u0026#39;s/port 6379/port 0/\u0026#39; /etc/redis/redis.conf sed -i \u0026#39;s|# unixsocket /run/redis/redis-server.sock|unixsocket /var/run/redis/redis-server.sock|\u0026#39; /etc/redis/redis.conf sed -i \u0026#39;s/# unixsocketperm 700/unixsocketperm 770/\u0026#39; /etc/redis/redis.conf sed -i \u0026#39;s/# maxmemory .*/maxmemory 1024mb/\u0026#39; /etc/redis/redis.conf systemctl restart redis-server # As yoursiteuser cd ~/public_html wp plugin install redis-cache --activate wp config set WP_REDIS_SCHEME unix wp config set WP_REDIS_PATH \u0026#39;/var/run/redis/redis-server.sock\u0026#39; wp redis enable Done! You now have:\nFully isolated PHP-FPM pool (1 user = 1 site = no cross-site damage) Redis object caching over Unix socket OPcache + huge upload limits Automatic SSL renewal Fastest possible Nginx routing WP-CLI ready Your wp-admin will feel instant, and the site will handle traffic like a champ — even on a $5/month VPS.\nNext steps:\nInstall a page cache plugin (any free one is ok) Set up Cloudflare (optional but recommended) Regular backups Enjoy your blazing-fast, private WordPress setup!\nThanks for reading! 😊\n","date":"2025-12-08T23:47:36Z","permalink":"/how-to-setup-wordpress-on-lemp-with-redis-and-wp-cli-on-debian-11/","title":"How to setup WordPress on LEMP with Redis and WP CLI on Debian 11"},{"content":"Introduction Want your own ultra-private email like name@yourdomain.com with a beautiful webmail interface? This guide walks you through setting up a full mail server in under an hour using Luke Smith’s legendary EmailWiz script + Roundcube webmail — all on a $2–3/month VPS.\nEverything is free, open-source, and 100% under your control.\nStep 0: Grab a Cheap VPS Good providers with frequent sales:\nContabo LowEndTalk “Offers” section Hostinger (my affiliate if you want to support me -\u0026gt; https://hostinger.com.br?REFERRALCODE=waterdownfall) Requirements:\nAny location (USA works fine) Debian 10 or 11 (we’ll use Debian 10 in this guide) At least 1 GB RAM (2 GB+ recommended) Set hostname during signup to your domain (e.g., sobremail.com) Wait for deployment → grab root password from email → SSH in.\nStep 1: Basic VPS Hardening ssh root@your-vps-ip apt update \u0026amp;\u0026amp; apt upgrade -y Change root password:\npasswd Create and upload an SSH key (do this from your local machine):\nssh-copy-id root@your-vps-ip Now disable password login:\nnano /etc/ssh/sshd_config Change:\nPasswordAuthentication no UsePAM no Then:\nsystemctl restart sshd Only your SSH key works now — much safer.\nStep 2: Install EmailWiz (the magic script) apt install curl nginx python3-certbot-nginx -y Point these DNS records to your VPS IP:\nyourdomain.com → VPS IP (A record) mail.yourdomain.com → VPS IP (A record) Run Luke’s script:\ncurl -LO lukesmith.xyz/emailwiz.sh sh emailwiz.sh Follow the prompts:\nSay Yes/Y to everything When asked for “System mail name” → enter ONLY yourdomain.com (NOT mail.yourdomain.com!) Wait ~5–10 minutes. When it finishes, it gives you three DNS records to add:\nDKIM TXT record (mail._domainkey.yourdomain.com) DMARC TXT record (_dmarc.yourdomain.com) SPF TXT record (root domain) Add them at your DNS provider (Cloudflare, Namecheap, etc.).\nStep 3: Set Up Reverse DNS (Critical for Deliverability!) In Cloudcone panel → Networking → rDNS → set to yourdomain.com Do NOT enable IPv6 (Cloudcone doesn’t support IPv6 rDNS yet — it will hurt deliverability).\nStep 4: Create Your First Mailbox useradd -G mail -m yourusername passwd yourusername Your email is now: yourusername@yourdomain.com\nTest in Thunderbird/IMAP client:\nIMAP: mail.yourdomain.com (port 993, SSL/TLS) SMTP: mail.yourdomain.com (port 465, SSL/TLS) Step 5: Install Roundcube Webmail Add backports + PHP 8.x repo:\napt install -y lsb-release ca-certificates apt-transport-https software-properties-common gnupg2 echo \u0026#34;deb https://packages.sury.org/php/ $(lsb_release -sc) main\u0026#34; | tee /etc/apt/sources.list.d/sury-php.list wget -qO - https://packages.sury.org/php/apt.gpg | apt-key add - apt update apt install -y php8.0-fpm php8.0-common php8.0-gd php8.0-imap php8.0-mysql php8.0-curl php8.0-zip php8.0-xml php8.0-mbstring php8.0-intl mariadb-server Secure MySQL:\nmysql_secure_installation Create Roundcube database:\nmysql -u root -p CREATE DATABASE roundcube; CREATE USER \u0026#39;roundcubeuser\u0026#39;@\u0026#39;localhost\u0026#39; IDENTIFIED BY \u0026#39;strongpassword\u0026#39;; GRANT ALL ON roundcube.* TO \u0026#39;roundcubeuser\u0026#39;@\u0026#39;localhost\u0026#39;; FLUSH PRIVILEGES; EXIT; Download \u0026amp; extract Roundcube (latest complete version):\ncd /var/www wget https://github.com/roundcube/roundcubemail/releases/download/1.6.9/roundcubemail-1.6.9-complete.tar.gz tar xvf roundcubemail-1.6.9-complete.tar.gz mv roundcubemail-1.6.9 roundcube rm roundcubemail-1.6.9-complete.tar.gz chown -R www-data:www-data /var/www/roundcube/temp /var/www/roundcube/logs mysql roundcube \u0026lt; /var/www/roundcube/SQL/mysql.initial.sql Nginx config for Roundcube (/etc/nginx/sites-enabled/roundcube):\nserver { listen 80; listen [::]:80; server_name yourdomain.com; root /var/www/roundcube; index index.php; location / { try_files $uri $uri/ /index.php; } location ~ \\.php$ { include fastcgi_params; fastcgi_pass unix:/run/php/php8.0-fpm.sock; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name; } location ~* \\.(jpg|jpeg|gif|png|webp|svg|woff|woff2|ttf|css|js|ico|xml)$ { expires 360d; access_log off; } } Test \u0026amp; reload Nginx, then get SSL:\nnginx -t \u0026amp;\u0026amp; systemctl reload nginx certbot --nginx -d yourdomain.com Visit https://yourdomain.com/installer → follow the wizard:\nDatabase: roundcube, user roundcubeuser, password you set IMAP host: localhost SMTP host: localhost Default host: mail.yourdomain.com Enable all plugins except Enigma (it breaks identities in older versions).\nAfter finishing, delete the installer:\nrm -rf /var/www/roundcube/installer Step 6: Quality-of-Life Tweaks Edit /var/www/roundcube/config/config.inc.php:\n// Login with just username (no need to type @domain.com) $config[\u0026#39;username_domain\u0026#39;] = \u0026#39;yourdomain.com\u0026#39;; // Stay logged in for 6 months $config[\u0026#39;session_lifetime\u0026#39;] = 259200; // Disable Enigma if you enabled it // Remove \u0026#39;enigma\u0026#39; from $config[\u0026#39;plugins\u0026#39;] array Increase attachment size:\nnano /etc/php/8.0/fpm/php.ini upload_max_filesize = 50M post_max_size = 50M Then:\nsystemctl restart php8.0-fpm Step 7: Brute-Force Protection with Fail2Ban apt install fail2ban -y cd /var/www/roundcube/plugins wget https://github.com/texxasrulez/roundcube_fail2ban/archive/refs/tags/1.4.zip unzip 1.4.zip mv roundcube_fail2ban-1.4 fail2ban rm 1.4.zip Enable in Roundcube config (config.inc.php):\n$config[\u0026#39;plugins\u0026#39;][] = \u0026#39;fail2ban\u0026#39;; Add jail (/etc/fail2ban/jail.local – create if missing):\n[roundcube] enabled = true port = http,https filter = roundcube action = iptables-multiport[name=roundcube, port=\u0026#34;http,https\u0026#34;] logpath = /var/www/roundcube/logs/errors.log maxretry = 5 bantime = 3600 Create filter (/etc/fail2ban/filter.d/roundcube.conf):\n[Definition] failregex = IMAP Error: Login failed for .* from \u0026lt;HOST\u0026gt; ignoreregex = Restart:\nsystemctl restart fail2ban php8.0-fpm Done! Your webmail is now protected.\nFinal Result You now have:\nFull email server with DKIM, SPF, DMARC Beautiful, fast Roundcube webmail Zero Google/Microsoft involvement Login once every 6 months Brute-force protection All for ~$50/year Welcome to real email freedom.\nThanks for reading! 😊\n","date":"2025-12-08T23:35:02Z","permalink":"/how-to-setup-your-own-email-server/","title":"How to setup your own email server"},{"content":" Introduction Brave Browser 1.69 introduced a game-changing feature: you can now connect Leo (Brave’s built-in AI assistant) to any model you want — including fully local models or third-party APIs. This means you get an always-available AI sidebar with zero subscription and total control over privacy and cost.\nHere are the two best methods I’ve tested (one ultra-private, one smarter but cloud-based).\nMethod 1 – Maximum Privacy: Run a Local Model with Ollama (No GPU Needed) You can run a surprisingly capable model completely offline, even on very modest hardware. The current sweet spot is Google’s Gemma 2 2B — it’s tiny (~1.4 GB), runs great on CPU, and works perfectly even with just 4–6 GB of RAM free.\nStep 1: Install Ollama Download and install Ollama from the official site: https://ollama.com (It has native packages for Windows, macOS, and Linux.)\nStep 2: Download Gemma 2 2B Open a terminal and run:\nollama pull gemma2:2b (If you use Docker: docker exec -it ollama ollama pull gemma2:2b)\nStep 3: Verify it’s running Open http://localhost:11434 in your browser. You should see “Ollama is running” — that’s all you need.\nStep 4: Add the model to Brave Leo Open Brave → Settings → Leo Click Add new model Fill in the details exactly like this: Label → anything you want (e.g., “Gemma 2 2B Local”) Model Request Name → gemma2:2b Server Endpoint → http://localhost:11434/v1/chat/completions API Key → leave empty (Optional but recommended) Set this model as your default for new chats. Done! You now have a fully private, offline AI inside Brave that uses almost no resources.\nMethod 2 – Smarter Answers (Cloud): Use CryptoTalks.ai (Pay-as-you-go, No Subscription) If you want access to the absolute best models (GPT-4o, Claude 3.5 Sonnet, Gemini 1.5 Flash, Llama 3.1 405B, etc.) without creating accounts at OpenAI/Anthropic/Google, CryptoTalks.ai is currently the best option. You pay only for what you use and can fund the account with Bitcoin or Lightning.\nStep 1: Create an account \u0026amp; get your token Go to https://cryptotalks.ai/signup → sign up → copy your API token (keep it safe!).\nStep 2: Add a tiny amount of credit Deposit any amount via Bitcoin or Lightning. Even $1–2 lasts a very long time for personal use.\nStep 3: Add the model(s) to Brave Leo Same process as before, just different values:\nLabel → e.g., “Claude 3.5 Sonnet”, “GPT-4o”, etc.\nModel Request Name → exact model ID from their docs, examples:\nopenai/chatgpt-4o-latest anthropic/claude-3.5-sonnet google/gemini-flash-1.5 meta-llama/llama-3.1-405b-instruct Server Endpoint → https://cryptotalks.ai/v1/chat/completions/\nAPI Key → paste your token\nYou can add as many models as you want and switch between them instantly in the Leo sidebar.\nPro tip: Check current model rankings at https://artificialanalysis.ai/models to pick the best one for your needs.\nReal-World Use With Leo + your own model you can:\nSummarize long articles or YouTube videos in one click Explain complex code snippets Draft emails or messages Translate on the fly All without ever leaving the browser and without sending data to big tech When I’m on battery and want zero extra power draw → I switch to the local Gemma 2 2B. When I need maximum intelligence → I switch to Claude 3.5 Sonnet or GPT-4o via CryptoTalks.\nConclusion Brave just turned every browser into a private, customizable AI workstation. Pick Method 1 for 100% privacy and zero cost, or Method 2 when you want the absolute best answers available today.\nEither way — welcome to the future of browsing.\nThanks for reading! 😊\n","date":"2025-12-08T23:15:59Z","permalink":"/how-to-use-ai-privately-at-brave-browser-2-methods/","title":"How to use AI privately at Brave browser (2 methods)"},{"content":" Understanding the Different Types of Caching (Especially for Scaling CMS Sites) If you’ve ever wondered what people mean when they talk about “page cache,” “object cache,” or “CDN cache,” this post is for you. These are the three main caching layers that make a massive difference when scaling WordPress, WooCommerce, or any other CMS.\nWhat is Page Caching? Page caching (also called full-page caching or HTML caching) is exactly what it sounds like: the entire rendered HTML page is saved as a static file.\nWith a truly static site (plain HTML + CSS + JS), there’s no need for page caching because every file is already static. But with a CMS like WordPress, every request normally triggers PHP → theme → plugins → database queries → HTML output. That process eats CPU and takes time.\nFull-page caching shortcuts all of that. The first visitor triggers the full PHP+MySQL process, the resulting HTML is saved, and every visitor after that gets served the pre-generated static HTML instantly — no PHP, no database queries, almost zero CPU.\nResult: 10–100× lower server load and dramatically faster page loads.\nWhat is Object Caching? Object caching stores the results of expensive database queries (or any slow computation) in fast memory (usually Redis or Memcached).\nThink of it as a super-fast middleman between your PHP code and the database.\nExample with WordPress:\nWordPress needs the list of published posts → it asks MySQL. First request: MySQL does the work, returns the data, object cache saves it in RAM. Next 10 000 requests: object cache instantly returns the same data from memory → MySQL sleeps peacefully. Object cache is smart — it automatically invalidates itself when data changes (e.g., you publish a new post).\nWhy you still need it even with full-page caching:\nLogged-in users (including the WordPress dashboard, WooCommerce account pages, etc.) can’t be fully cached for everyone. Those pages still hit PHP and MySQL → object cache makes them tolerable instead of painfully slow. Object cache + full-page cache together is the classic high-traffic combo.\nWhat is CDN Caching? A CDN (Content Delivery Network) copies your static assets (CSS, JS, images, fonts) — and optionally your full HTML pages — to “PoP” servers all over the world.\nWithout a CDN: a visitor in Japan downloads everything from your origin server in, say, Brazil → high latency.\nWith a CDN:\nStatic files are served from the closest PoP (often \u0026lt; 30 ms away). If you also enable full-page caching on the CDN, the entire HTML page is served from that nearby PoP too → the origin server is never touched for cached pages. This is why some sites load instantly from anywhere on the planet.\nReal-World Example: WordPress Traffic Flow No caching at all Visitor → Web server → PHP → dozens of plugin files → MySQL queries → HTML → visitor → High CPU, slow TTFB, easily hits resource limits.\nWith full-page caching only First visitor: same slow path as above (but the HTML is saved). Next 10 000 visitors: Web server instantly serves the pre-built HTML → almost zero CPU.\nWith object caching only Every request still runs PHP + plugins, but database queries are answered from RAM instead of disk → faster than no cache, but still heavy.\nWith full-page cache + object cache Anonymous visitors → static HTML (super fast, almost no load) Logged-in users → PHP runs, but object cache makes DB queries instant → manageable load Add CDN with full-page caching on top Even the static HTML is now served from edge locations worldwide. Your origin server can basically take a nap until something actually needs PHP (e.g., form submissions, cache invalidation).\nConclusion Here’s the hierarchy from most impactful to least (for most CMS sites):\nFull-page caching on the CDN → fastest for visitors, scales to millions of hits with almost zero origin load. Full-page caching on the origin → still massive win if you can’t cache on the CDN. Object caching (Redis/Memcached) → mandatory for logged-in users, WooCommerce, dashboards, etc. Everything else (OPcache, browser cache, etc.) → nice to have, usually enabled by default. If you only do one thing: enable proper full-page caching (and push it to your CDN if possible). If you have logged-in traffic or a shop: add Redis/Memcached object caching.\nThat’s it — the three caching layers that power basically every high-traffic WordPress site on the planet.\nHope this cleared things up!\nThanks for reading! 😊\n","date":"2025-12-08T23:13:04Z","permalink":"/page-cache-object-cache-and-cdn-cache-understanding-all-types-of-caching/","title":"Page Cache, Object Cache and CDN cache - Understanding all types of caching"},{"content":"Introduction Pop!_OS is one of the most used Linux Distros. It\u0026rsquo;s also a recommendation for beginners, gamers and even experienced users.\nBut is it worthy it? In today\u0026rsquo;s post I will write about my experience using it, from the installation to the day-to-day usage.\nInstallation Pop have one of the best installers there, I must admit. It\u0026rsquo;s simple, beautiful and feels modern. The installation is pretty simple, you can just click in a few buttons to setup language and a few other options. It\u0026rsquo;s also possible to encrypt the disk during the installation, which helps if you travel a lot and contain confidential information inside your laptop (like personal passwords, documents, photos, etc).\nFor the installation process, I will rate Pop 9/10. Why not 10? Well, it doesn\u0026rsquo;t contain a option to dual boot automatically. You need to do it manually if you are using Windows for example. Other than that, it works really well and does a great job to provide you a nice experience.\nFirst boot Pop first boot is also a great experience. You will be able to create your user and password and login normally at your new Gnome environment. Pop helps you to customize a few options (dark mode, docker location and online accounts). Those are all great options for beginners.\nThe default apps are also well integrated with the system and everything feels just in place.\nOverall, I hate the post installation as 10/10, I don\u0026rsquo;t see anything to improve here, they just did great.\nDetails that makes Pop!_OS special Probably this is the best part of Pop, that makes it a really really solid choice. These are some characteristics that are rare to find in other Distros:\nSystem76 Scheduler - Did you konow that Pop contains CPU optimizations by default? Yep, that is right. By defualt, Pop will reduce the latency and improve performance on apps, specially when the laptop is charging. This is also great for gaming, since you don\u0026rsquo;t need gamemode anymore. System76-Power - By default, Pop provides three options for your Battery: Economy, Balanced and high performance. That is amazing because under pop, battery optmimizations are already applied by default. You don\u0026rsquo;t need TLP and you have a easy GUI to control the battery mode. That is just awesome. Swappiness is set to 10. On most linux distros that I\u0026rsquo;ve ever used, swappiness is set to 60. This means that your Distro will start to use swap when ram usage reaches 40%. On Pop, swap will only be used when you use abour 90% of your ram. That feels amazing and much smoother since swap is really slow, even on a NVME ssd. Kernel isn\u0026rsquo;t the same of Ubuntu 22.04. Pop does a great job on keeping the kernel updated. This is great specially if you are using a newer desktop/laptop. As far as I know, Ubuntu 22.04 is serving Kernel 5.15.x. Pop os already on 6.1.x Custom shortcuts. At first, I hated it, but after trying the \u0026ldquo;pop way\u0026rdquo;, I loved it and I actually change other distros to their defaults on shortcuts! For example, instead of alt + f4 (which usually requires 2 hands), Pop uses \u0026ldquo;windows + q\u0026rdquo; which is more accessible and easier to use. Instead of ctrl + alt + t for the terminal, you can use \u0026ldquo;windows + t\u0026rdquo; on Pop. This is really great and helps when you are working with a lot of multitasking (pretty much anyone who works with CS will love it). Easy Firmware updates. Pop comes with a option inside gnome settings to make hardware updates. That is really great because it gives you more controls and details on these upgrades. Recovery as a option. On pop, you can have a \u0026ldquo;copy of the ISO\u0026rdquo; in the settings and \u0026ldquo;refresh the OS\u0026rdquo; if you ever need it. It may be useful if you broke something and want to restore the system without using a USB stick. SystemD boost instead of Grub. This doesn\u0026rsquo;t makes difference for me, but a lot of people seems to praise systemdboot. I think it provides a faster boot time and it\u0026rsquo;s \u0026ldquo;simpler to setup\u0026rdquo; (I\u0026rsquo;m used to grub, so grub is easier for me, but I barely customize anything on the boot) Pipewire instead of Pulseaudio. For years one of the softwares that people used to complain a lot about was Pulseaudio. It used to lag, crash, do not recognize devices, etc. Pipewire is the new guy that is leaner and has a lower latency. A lot of people praise it too. For much, I prefer Pipewire too as it just feels simpler and better to use than Pulseaudio. Flatpak theming right and not Snap. Snaps are being \u0026ldquo;forced\u0026rdquo; by Ubuntu distros, but a lot of people dislike them. Some dislike about the server not being open source, some complain about the bugs, space used some complain about auto updates (which can\u0026rsquo;t be turned off). For me, I also prefer Flatpaks, and it\u0026rsquo;s great to see that on Pop Flatpaks looks like native applications and flathub is Added by default. It\u0026rsquo;s also nice to see that Pop_Shop integrates well with Flatpaks. Pop created popsicle. This probably doesn\u0026rsquo;t get enough attention, but man! It\u0026rsquo;s WONDERFUL to have a iso flasher by default. And this one is so beautiful and integrates well with Pop. I like it more than Balena Etcher and other common software used on linux to create bootable sticks. Pop downsides Although Pop is amazing, I see a few downsides on it as well. Most of them are personal, so you may not actually see them as downsides.\nGnome. I just don\u0026rsquo;t like gnome at all. Feels heavy and changes all the time with major updates, breaking plugins and the user experience. The good part is that Pop is developing their own rust DE, which will be HOT when it releases. Pop_Shop uses 0.5GB of ram when idle. That may not be a issue for computers with more ram, but when you have less, that is kinda bad. If you have 4GB of ram for example (that is still common on third world countries) you will feel the difference. You can disable pop shop, but honestly the usage in idle should be lower. tracker-miner-fs can suck your CPU if you download folders that contains a lot of subdfolders. Once I downloaded a WordPress site backup and extracted it. It had a lot of subfolders. I did notice my laptop slower, but I didn\u0026rsquo;t know what was happening. When I checked the task manage, tracker miner was acting and sucking all the CPU trying to index that subfolder. I tried to reset tracker miner, clean, see the status but it wasn\u0026rsquo;t replying. In the end, I disabled it as a pop developer said it was 100% safe. Performance overall after 6 months After 6 months using Pop, I can say that I was quite satisfied with the performance. I had a issue while for a few seconds mouse was slow and audio was freezing, but that is probably due to something I did (or maybe due to my hardware not being able to handle encryption well. I\u0026rsquo;m on a 12GB ram Ryzen 5 5500U laptop with NVME ssd of 256GB).\nDue to the issues with tracker miner and this freezing issue, I decided to leave Pop and try Linux Mint XFCE for a while (I love XFCE and Mint is stable enough, so I decided to give it a try). I will probably review it after using it for a while as well.\nOverall, using pop was a pleasure and I could do a bunch of great work on it. I work as CS/Devops, so most of the time I was chatting with customers or using bash scripts on the server, and for that Pop worked fine. For gaming it also worked well so I\u0026rsquo;m not complaining and I definitely would recommend it for most people. Pop has the best defaults that I\u0026rsquo;ve ever seen. It\u0026rsquo;s the distro that I tweaked less, because it comes with everything that I need and use.\nConclusion Pop is awesome! If you like gnome, give it a try. It will give you a great performance and all optimizations that matters are there out of the box. Battery will be nice on laptops and drivers will probably be optimized for gaming. Vulkan is also enabled by default.\nMy dad is using Pop on his laptop (I installed it) and he loves it.\nI will definitely try Pop again once they release their new DE. In the meanwhile, I will enjoy my XFCE experience.\nThank you for reading :)\n","date":"2025-12-08T22:28:25Z","permalink":"/pop-os-22-04-review-after-6-months-of-use/","title":"Pop!_OS 22.04 review after 6 months of use"},{"content":"Introduction I recently reviewed Pop!_OS 22.04 after using it for a long time. I loved it, but I wanted to try something else long-term and ended up choosing Ubuntu 22.04 — specifically the Xubuntu flavor with XFCE.\nWhenever I install a fresh OS, there are a few things I always do to make sure the system feels snappy, performs well in games, and (on laptops) gets the best possible battery life.\nBefore starting any of the steps below, I strongly recommend doing a full system upgrade\nInstall the Liquorix Kernel Liquorix is an enthusiast Linux kernel optimized for desktop responsiveness, low-latency audio/video work, and reduced frame-time jitter in games.\nThe stock Ubuntu kernel is a general-purpose kernel that has to work well on both desktops and servers. Liquorix takes the same Linux kernel source and applies desktop-focused patches and build options. The result feels noticeably snappier, especially under heavy load or when alt-tabbing quickly in games.\nInstalling it on Ubuntu/Debian is one command:\nBash\ncurl \u0026#39;https://liquorix.net/install-liquorix.sh\u0026#39; | sudo bash Reboot afterward and you’ll be running the new kernel.\nAdd the Latest Graphics Drivers For Nvidia users:\nBash\nsudo add-apt-repository ppa:graphics-drivers/ppa sudo dpkg --add-architecture i386 sudo apt update sudo apt install -y nvidia-driver-560 libvulkan1 libvulkan1:i386 For AMD or Intel users (Kisak’s PPA – latest Mesa):\nBash\nsudo add-apt-repository ppa:kisak/kisak-mesa sudo dpkg --add-architecture i386 sudo apt update \u0026amp;\u0026amp; sudo apt upgrade sudo apt install libgl1-mesa-dri:i386 mesa-vulkan-drivers mesa-vulkan-drivers:i386 Even on an older LTS release, this gives you the newest open-source drivers and Vulkan support.\nLower Swappiness Pop!_OS sets vm.swappiness=10 by default (swap is only used when RAM is ~90% full). Ubuntu/Xubuntu defaults to 60, which is far too aggressive for desktop use.\nChange it permanently:\nBash\nsudo nano /etc/sysctl.conf Add this line at the end:\ntext\nvm.swappiness=10 Save and exit. The change applies immediately or on next reboot.\nInstall Essential Utilities These are the tools I install on every fresh setup:\nRedshift – blue-light filter Flameshot – best screenshot tool AppImageLauncher – integrates AppImages into your menu Gamemode – massive FPS improvements in many games TLP – essential for laptops (often doubles battery life) Bash\nsudo apt install redshift flameshot appimagelauncher gamemode tlp tlp-rdw (Enable TLP if needed: sudo tlp start)\nInstall Your Favorite Everyday Apps My personal picks:\nBrave Browser (privacy-focused Chromium) VLC (preferably via AppImage/Flatpak/Snap to avoid heavy Qt dependencies on XFCE) LibreOffice Create Handy Aliases Open your .bashrc:\nBash\nnano ~/.bashrc Add some useful aliases at the bottom, for example:\nBash\nalias apply_filter=\u0026#39;redshift -O 1900\u0026#39; alias update=\u0026#39;sudo apt update \u0026amp;\u0026amp; sudo apt upgrade -y\u0026#39; alias please=\u0026#39;sudo $(history -p !!)\u0026#39; # rerun last command with sudo Reload the file:\nBash\nsource ~/.bashrc Customize the Look \u0026amp; Feel (Optional) Xubuntu + XFCE is extremely customizable. I run a very minimal setup and control almost everything with keyboard shortcuts. You can configure them in Settings → Window Manager and Settings → Keyboard → Application Shortcuts.\nConclusion The three biggest performance wins — Liquorix kernel, latest graphics drivers, and low swappiness — make a dramatic difference. Real-world example: Life is Strange: True Colors jumped from ~23 FPS with stuttering on stock settings to a smooth 40+ FPS after applying these changes.\nIf you’re getting random lags or freezes on Xubuntu/Ubuntu, try these steps first. They solve a surprising number of issues.\nThanks for reading!\n","date":"2025-12-08T22:24:22Z","permalink":"/top-7-things-that-you-should-do-after-installing-xubuntu-22-04/","title":"Top 7 things you should do after installing Xubuntu 22.04"},{"content":" Zcash is NOT the most important project in the world, and it is losing. Zcash was born as a project to fix Bitcoin\u0026rsquo;s major flaw: privacy. But launching a new coin isn\u0026rsquo;t easy, and it\u0026rsquo;s not just about technical aspects.\nA serious cryptocurrency is supposed to be money, and it needs to be better than what we currently have with governments; otherwise, we should keep using the dollar. This means that while the technical aspects of any cryptocurrency are important, it should also be reliable, trustworthy, and as stable as possible. The main flaw in government money is inflation. Governments typically love to spend money and can charge a hidden tax by printing it. When money is printed, the amount of goods and services in society remains the same, but there is more money in circulation.\nThis means your money will now have reduced value. The winner in this case is the government or whoever spends the newly printed money first, because the market will adjust itself, leading to higher prices for services and goods.\nThe issue with Zcash Zcash sounds good. It deploys zk-SNARKs technology to prove transactions and store them privately, meaning that when you send transactions, everything is hidden (so no one can see the sender, the amount sent, or the receiver). Sounds amazing, right? Let\u0026rsquo;s buy Zcash then!!\nNo. And why not?\n1. Zcash was launched with a trusted setup\nYes, that\u0026rsquo;s right. When Zcash launched, it utilized a trusted setup to bootstrap the network. In this event, multiple participants collaboratively created cryptographic parameters without any single party having full control. This assumed that at least one participant destroyed their portion of the secret keys to guarantee privacy. If participants united their parameters, they could, in theory, create unlimited Zcash and trace shielded transactions.\nNow, I have to be fair. Zcash is currently running on NU5 (Network Upgrade 5). This upgrade removed the trusted setup, ensuring that after May 2022, Zcash does not depend on trusting anyone else.\nBut at the same time, as far as I know, there is no way to prove that everyone destroyed their parameters and that no Zcash was generated or traced.\n2. Zcash is not private by default.\nConsidering the latest updates (not using Sprout or Sapling), users can leave Zcash in a public address (t-address) or a shielded address (Orchard, ideally). So if some users want to use Zcash just like Bitcoin, they can.\nZcash aims to fix this by recommending privacy-friendly wallets. For example, Zashi wallet tries to shield your funds by default. The issue with this? Zcash is not widely used, so buying Zcash peer-to-peer or from a decentralized exchange like Bisq or Haveno Reto is very hard.\nSo you have to buy it from a non-privacy-friendly exchange like Binance or Coinbase. And of course, these exchanges do not support shielded addresses. You need to use your transparent address to receive your Zcash before shielding it.\nZcash somehow believes it can provide full privacy while complying with governments and anti-privacy laws. Zcash community and users are accustomed to buying their coins through non-private means. If the government decides that shielding your Zcash is illegal, you will not be able to buy and shield your coins because the government knows the t-address is related to you, and if you make a shielding transaction, you\u0026rsquo;ve just committed a crime.\nThey can even block \u0026ldquo;tainted\u0026rdquo; coins, so if a Zcash was ever shielded, it can be considered \u0026ldquo;tainted\u0026rdquo; and blocked on exchanges. During the Canada convoy protest, the government tried to seize Bitcoin, but since the wallet was non-custodial, they couldn\u0026rsquo;t. They quickly realized they could ask all exchanges to refuse those \u0026ldquo;dirty\u0026rdquo; Bitcoins.\nNow you may be wondering how Monero is any different. Well, Monero is private by default, meaning users don\u0026rsquo;t have to worry about shielding and \u0026ldquo;unshielding\u0026rdquo; coins. And every shop that accepts Monero does so for privacy, unlike Zcash, where shoppers and exchanges can accept Zcash only on transparent addresses.\nAnd yes, as you may have thought, some governments and exchanges have banned Monero, which was actually good for Monero. Why? Because it is now miles ahead of Zcash. Monero has an actual ecosystem. You can buy goods and services directly with Monero, you can buy Monero without any exchanges, and Monero knows how to survive in an environment without legal approval.\nFor example, you can buy gift cards at Coinsbee or Cake Pay directly with Monero, sell services and products for Monero directly at XMRBazaar, find different kinds of services accepting Monero at Monerica, use AI privately with Monero at Nano-GPT, or trade Monero privately with no KYC at RetoSwap.\nAnd this is just the beginning. Monero usage has been increasing, and the goal is to be able to live entirely with Monero to achieve financial freedom.\nSo, private by default is definitely the superior choice. Cash is private by default, just like Monero.\n3. Zcash is very centralized\nYep, that\u0026rsquo;s right. Perhaps you aren\u0026rsquo;t aware of this, but one mining pool of Zcash, ViaBTC, has nearly 70% of the mining power.\nThis means that if ViaBTC starts to act maliciously, they could, in theory, double-spend ZEC or censor transactions.\nZcash has a plan to fix that, but for now, it\u0026rsquo;s a promise and not something live. They want to create a PoS layer (proof-of-stake) to ensure users have more control over transaction validation.\nI don\u0026rsquo;t have a specific opinion about this PoS layer yet, so I will refrain from talking about it.\nThe point remains valid, though: Zcash is very centralized. And not only due to the mining pool. We can clearly see that the community on Reddit is not very active; you don\u0026rsquo;t see people promoting and running Zcash nodes as you do in the Monero community. The community groups are typically made up of Zcash-related institutions.\nZcash has to put effort into marketing and convincing people to use it, while Monero has natural adoption, and users spread the word for free. There are several community-based sites, podcasts, and you can actually see people using it instead of just buying it and hoping for a massive price increase.\nThere are several guides on how to use a Monero wallet, how to run a node, how to spend it, etc. With Zcash, you typically have promises that \u0026ldquo;the technology is amazing and it will have more value than Bitcoin.\u0026rdquo;\n4. Zcash has a developer tax\nIf you were proposing a global money to be used by everyone in the world, do you think it\u0026rsquo;s fair to allocate 20% of the mined money to pay for its development?\nI don\u0026rsquo;t think so, and most people don\u0026rsquo;t think so. Zcash did exactly that. 20% of the mined coins go directly to Zcash institutions that are supposed to develop and market Zcash.\nWith this proposal, developers and the governance of the coin do not need to gain the trust of users. They are compensated by default and will obviously sell the Zcash for fiat since that is basically their salary, and they have bills to pay.\nWith that in mind, potential investors and users will always fear a massive dump in the cryptocurrency when prices spike.\n5. Zcash UX still sucks\nZcash is still somewhat complex for the average user. To fix that, the recommended way to use Zcash nowadays is with Zashi, which tries to shield transactions by default.\nZashi has some serious issues, though. The first issue is the language. Only English is supported. I mean, is that serious? The most recommended wallet only supports English? Is Zcash only meant to be used in America/UK? It\u0026rsquo;s a shame that a project with a development tax can\u0026rsquo;t make a multi-language wallet. Cake Wallet, Stack Wallet, and Monerujo didn\u0026rsquo;t have any development tax, but they support several languages. What is your excuse, Zashi?\nThe second issue is that Zashi doesn\u0026rsquo;t seem to be stable, especially with larger amounts of Zcash. Recently, a user reported that he cannot spend his Zcash. That happens because Zashi only allows you to spend shielded Zcash, and the wallet is unable to shield his Zcash.\nI know this isn\u0026rsquo;t specifically a skill issue because not long ago, when I was testing Zcash, I had a similar issue. I received Zcash on Zashi but was unable to shield it. I don\u0026rsquo;t remember exactly what I did to solve the issue (I was trying Ywallet and Nighthawk), but it definitely wasn\u0026rsquo;t a good first impression of Zcash. I remember testing receiving Zcash on an older phone vs. a newer phone (both using Zashi), and my newer phone was able to receive and shield the coins easily, but the older phone struggled.\nI\u0026rsquo;m not sure if this was a coincidence, but it seemed that Zashi is heavy on your phone. I never had this issue with Monero before.\nSure, syncing Monero takes a while, but it works in the background seamlessly with Monerujo by just waiting. It runs even faster if you have a local Monero node running at your home, which I suspect 99% of Zcash users don\u0026rsquo;t have.\nRight now, Zashi also needs to be synced to be properly used, and it takes a lot of time and requires you to leave your screen turned on.\nBoth coins need to be easier to use, but Monero is still better than Zcash for UI. Users don\u0026rsquo;t need to worry about Sapling or Orchard pools or have issues \u0026ldquo;shielding\u0026rdquo; their coins.\n6. Price action\nDue to the trusted setup launch and the development tax, Zcash is likely destined to be a pump coin. With no real-world adoption, its price can be manipulated to rise, but such gains are unlikely to last.\nCryptocurrency enthusiasts are currently focused on Zcash due to a massive price pump, but I doubt this will sustain. If you zoom out the price graph for Zcash, it still looks ridiculous. In contrast, zooming out for Monero reveals steady and slow growth over time.\nConclusion Zcash sucks. After studying it better, calling it Ztrash is the right thing to do. Doing otherwise is not honest.\nCredits https://lukesmith.xyz/articles/monero-and-other-privacy-coins/\n","date":"2025-12-08T22:11:49Z","permalink":"/zcash-is-losing/","title":"Zcash is losing"}]