• 0 Posts
  • 34 Comments
Joined 2 years ago
cake
Cake day: October 4th, 2023

help-circle

  • Your top priority should be “Are my backups good? / Can I trivially roll back any breaking changes?” If an account oopsie can permanently compromise your users’ photos, then you have bigger problems to worry about.

    But assuming your backups are good, there isn’t much to worry about. I recommend you don’t take my word for it and thoroughly read the documentation of each of the services you want to put behind Authentik, but in general, when a service is configured to use SSO, if a user with the same ID already exists on the target service, they are simply merged. The most common ID for this is the email associated with that user on both Authentik and the service. Worst case, if the ID doesn’t match, you either get an error saying the user is invalid or you get a new user created on the target service.








  • I have the 2020 G14 and I got this working once. I’m afraid easy and simple are not a thing here, as you need to understand what you’re doing if you want it to work well. The basics are:

    • Prevent the host system from loading any drivers that touch the discrete GPU. This is done by attaching it to the VFIO driver and uninstalling/blacklisting the Nvidia and Nouveau drivers.
    • Make sure you have the correct kernel parameters to support virtualisation and PCI-e passthrough.
    • Create a Windows VM and attach the Nvidia GPU to it.
    • Setup Looking Glass so you can play with the best possible latency. This will likely require a dummy USB-C display stick.

    Personally, I don’t think it’s worth the hassle. I keep a Windows install for when it’s needed, and do most of my gaming on a separate system.






  • If you have an interest in Arch, I’d recommend starting with a derivative distro like EndeavourOS. It’ll give you an easy installation process and a desktop that’s ready to use.

    Then just use it as your daily driver. You’ll eventually run into the occasional issue when package X or Y upgrades and breaks something, learn to fix that, and eventually learn the “ins and outs” of Arch. That’s how I started, I went from Mint to Antergos, used that for a while, then when Antergos was discontinued (RIP) I converted my install to “pure” Arch and never looked back.


  • RustDesk sort of fits the bill. It’s open-source, has 2FA, can be self-hosted (but not needed), the client runs on anything, but the main issue here is that no amount of workarounds will make an untrusted machine any less untrusted, you’re essentially extending the display and input from a dubious machine into your own.

    If you’re really worried about the security aspect, my suggestion would be to only use your phone as the client, and if you need to do anything more complex, use a Bluetooth keyboard connected to it. There are some foldable keyboards that don’t take too much space and are not terrible.