RSSAmplifier

Blog

Noah Bailey

Recent content on Noah Bailey

nbailey.caRSS feed ↗72 posts

Latest posts

The People against Scalability

In my career in technology, I’ve heard one specific term so many times that it’s lost all meaning.
The stack needs to be scalable. Our team needs to be scalable. Why aren’t we using a scalable database? That thing in particular, that thing over there, it’s not scalable enough!
And it’s not just that it’s meaningless, it’s that I find it entirely…

There's so much to do

Over the past couple of years it’s been difficult to ignore stagnation of the world around us. Products have gotten smaller and quality has been reduced, roads have more potholes than ever, and food seems more bland and less nutritious than ever. Our software and services cost more than ever, but seem to constantly suffer from issues they never had before. Years of neglect seem to be…

How to turn anything into a router

I don’t like to cover “current events” very much, but the American government just revealed a truly bewildering policy effectively banning import of new consumer router models. This is ridiculous for many reasons, but if this does indeed come to pass it may be beneficial to learn how to “homebrew” a router.
Fortunately, you can make a router out of basically…

Letters to my MP: Age Verification

The following are emails I sent to my member of parliament. I encourage everybody to read, copy, and take inspiration from these.&#xA;March 13, 2026&#xA;Hi <MP Name>&#xA;I’m writing to you today about the upcoming vote on the “online harms” bill. I believe you think you are doing the right thing; protecting the youth from the horrible things that can happen on the web. However, this legislation…

Deploy to Cloudfront from GitHub using OpenID Connect

A common usage of CI/CD tools today is to build and deploy a static website to a CDN.&#xA;This has many advantages over the old way (like running Wordpress), such as security, cost, and flexibility. Developers love the ability to use any crazy JavaScript library they want on the client side, Sysadmins love not having another PHP server to feed and water, and accountants love the bill!&#xA;However,…

Data was the new oil; now AI is the new plastic

I can&rsquo;t count the number of times over the last decade I have heard the phrase, &ldquo;Data is the new oil!&rdquo;&#xA;I&rsquo;m unsure who originally coined the phrase, but it&rsquo;s been repeated so many times that surely everybody in the tech world, whether they work for an ad firm (oil=good), are a staunch privacy advocate (oil=bad), or believe in incrementally changing the status quo…

Backup Postgres databases with Kubernetes CronJobs

A key part of operating any safe and reliable system is ensuring that there is a way to recover deleted or lost data in a prompt and consistent way. One key part of that is to maintain automatic backups that are recoverable and verifiable.&#xA;This is a quick and easy way to accomplish that goal, by using existing pieces of infrastructure that are common in production networks. There are countless…

The spelling error made 200 billion times a day

Like anybody, I&rsquo;ve made my fair share of spelling mistakes in my life. It was never something I had a particular talent in, having never gotten a spelling bee medal myself. Red underlines have always been a simple fact of life for me.&#xA;But fortunately, I&rsquo;ve never made a spelling mistake so consequential that it&rsquo;s been broadcast at least 200 billion times every day!&#xA;This is…

Restarting Kubernetes pods using a CronJob

In an absolutely perfect world, we&rsquo;d never have to restart our server software ever, because it would be flawless. There would be no bugs, memory leaks, state locks, and we&rsquo;d all get along with each other!&#xA;Unfortunately, we live in a much crappier world where our software is imperfect, and we don&rsquo;t have enough time or resources to fix it properly.&#xA;In the olden days,…

You&#39;ve just bought a new domain. Now what?

You&rsquo;ve got a new idea for a product, or a store, or maybe just a neat pun. So it&rsquo;s time to buy a domain, isn&rsquo;t it?&#xA;That&rsquo;s the easy part. Put in your credit card info, add a reminder for next year so you remember to renew it, and you&rsquo;re set. But that&rsquo;s far from the end! There&rsquo;s a lot of work to make sure everything is set up correctly, and the best time…

On Building Pyramids

I recently had the pleasure of attending a community meeting. The purpose was to form a group to represent our neighbourhood at the municipal level, as a liaison, and as a check against the ward councillor. I expected, and hoped, there would be some lively discussion about issues at hand, solutions, and ideas.&#xA;What I got instead was an hour of bickering between different groups about who…

Who Sawed My Motherboard???

It was a cold, rainy November night in 2013, and I was hunched up over my desk trying to get my sound card working.&#xA;In my teenage years, I had taken on a keen interest in &ldquo;Hackintoshing&rdquo;, that is, installing Apple&rsquo;s Mac OS (then OSX) on regular non-Apple PC hardware. While my box was fairly well behaved, it had two quirks that were eluding me. My sound card didn&rsquo;t work…

Linux on the P8 Aliexpress Mini Laptop

I finally caved and bought one of the no-name 8" mini laptops from Aliexpress. I&rsquo;ve had my eye on these for a long time. Really, since the days of my youth with the Sony Vaio P and other iconic UMPCs of the early 00&rsquo;s. The game changer was the original GPD Pocket from a few years back. Now, there&rsquo;s a cambrian explosion of cool tiny computers coming from China.&#xA;This particular…

Recovering Mysql/Mariadb after a nasty crash

Database recovery is tricky at the best of times, and it never seems to happen when and how you expect. In this case, my self-hosted Zoneminder server crashed hard and came up broken. It appears to be related to some index or table in the database getting corrupted, but I&rsquo;m not enough of a &ldquo;database surgeon&rdquo; to say with any certainty.&#xA;When this crash happened, the first sign…

Using EXIF data to pick my next lens

A neat feature of almost every modern digital camera is that every single photo you take includes detailed metadata, including all of the photo&rsquo;s settings including shutter speed, aperture, sensitivity, and focal length.&#xA;The focal length, or simply the &ldquo;zoomness&rdquo; of your photo is of particular interest. All of the other settings are very easy to change by adjusting a dial (or…

Converting and developing RAW photos on Linux automatically

Taking photos is fun and easy.&#xA;Just kidding, it&rsquo;s a fractal of complexity, FOMO, and slowly realizing how little you actually know.&#xA;However, one nice thing is that using some simple Unix/Linux tools, it&rsquo;s remarkably easy to mass produce good looking JPEG images from your raw photos, without having to actually learn Lightroom.&#xA;After a few days of fiddling with the settings,…

Thank you, 2016 iPhone

This is my phone. It&rsquo;s a 2016 iPhone SE, and for the past seven years, it has been my main computing device and the centre of my digital life.&#xA;It&rsquo;s outlived four laptops, three pairs of headphones, survived through dozens of trips away from home over three continents, a couple drops, and one close call with a broken umbrella in the fierce Ontario summer rain. It&rsquo;s had two…

Don&#39;t Make It Work

I&rsquo;ve realized recently that I have to very carefully create boundaries around my hobbies to protect them.&#xA;I like to take pictures. Sometimes of my cats, other times of neat things I see while traveling or exploring, and always to document things that I find interesting in the physical world.&#xA;The encroachment of legitimacy It starts with a cheap sewing machine before spiraling into…

Self-hosted Surveillance with ZoneMinder

While there are plenty of IOT security cameras that promise privacy, none of them really do. Eufy recently got busted for secretly accessing peoples&rsquo; feeds, Unifi got breached, and literally every off-shore IOT device is slurping as much metadata (and regular data) off your devices as they possibly can. It&rsquo;s not hard to understand a need for secure and private home security…

Backups, Monitoring, and Security for small Mastodon servers

With Mastodon quickly becoming a refuge for former bird-site users fleeing the new regime, many are considering self-hosting their Fediverse instance. There&rsquo;s many good reasons to do this, such as privacy, data ownership, or even maintaining consistent performance while larger communities struggle to on-board an influx of new users.&#xA;But, as always, self-hosting means new…

Block web scanners with ipset & iptables

Anybody who runs an internet-facing webserver has seen their fair share of spammy scanners in the logs. It varies server to server, but some of mine get up to 15,000 scans per day.&#xA;Almost all of these are harmless network mappers, but they still annoy me. Many are compromised hosts or belong to hackers & organized crime rings. While it&rsquo;s possible to create false positives, it&rsquo;s…

Executing commands over SSH with GitHub Actions

Several admins and developers like automatically updating their servers with new builds as they become available. Commonly known as &ldquo;CI/CD&rdquo;, this process allows teams to iterate much faster and speed up product development.&#xA;Often, this is simply pulling from a repo and running a couple docker-compose commands, which is very easy to automate.&#xA;A bad way to do this is using a cron…

Debian Sid on encrypted ZFS

This guide is for an advanced Debian GNU/Linux installation using the ZFS storage system with an encrypted root volume for security and privacy. It will also be upgraded from the current Stable release (Bullseye) to the rolling-release Unstable version (Sid).&#xA;ZFS has long been considered the last word on advanced storage developments. With its advanced safety, efficiency, and performance…

Protect your dangerously insecure redis server

If you&rsquo;ve put Redis on the internet you&rsquo;ve probably had your box hacked one way or another. Unfortunately, the service has very weak defaults with no authentication, encryption, or meaningful access control. While it&rsquo;s true that redis is a back-end service that should only be used between servers, it&rsquo;s often misused and abused.&#xA;For example, there are about 40,000 redis…

Debian: the luxurious boring lifestyle

Since late 2018, I had been a full-time Arch Linux user. At that time, it was worth it for me to spend the extra time dealing with Arch&rsquo;s quirks, meticulously updating my AUR software, fiddling with all-manual configuration, and manually migrating any software between major versions whenever Pacman updated them. It was both a great learning experience, and&hellip; well&hellip; A bit of a…

Monitor radiation with a Raspberry Pi

I have an odd fascination with radiation&hellip; Not to the point that I&rsquo;m buying &ldquo;Naturally Occurring Radioactive Materials&rdquo; (or NORMs for short) on eBay, but certainly to the point that I own a digital geiger counter and regularly measure&hellip; things&hellip;&#xA;Recently, I discovered https://radmon.org, a site where users can connect a counter to their API and send data to…

Simple Linux server alerts: Know your performance, errors, security, syslog, and security

Log aggregation systems are fantastic. As are time-series metrics databases. But that&rsquo;s not what this post is about. These methods aren&rsquo;t a replacement for those systems at all, but a basic way to implement the core basics of monitoring and alerting.&#xA;You see, the strength of a SIEM or log aggregation system is its numbers. It correlates data from hundreds or thousands of sources,…

NUC crashes on debian 11 - How I fixed it

I recently installed Debian Bullseye on an old Intel NUCCAY6H mini PC I had lying around. It&rsquo;s a great little device for a home server, as it&rsquo;s very cheap, fits 16G of memory, and with 4 mini-cores it&rsquo;s no slouch.&#xA;The first install attempt didn&rsquo;t go well, with missing firmware for the NIC causing hanging for a couple minutes during boot. This happens quite a bit with…

Basic Linux server security with fail2ban, ossec, and firewall

There are lots of &ldquo;very correct&rdquo; ways to make your server &ldquo;very secure.&rdquo; Most of them rely on paid services, complicated agent-manager topologies, and cool buzzwords like &ldquo;zero trust&rdquo;.&#xA;However, as they say, perfection is the enemy of progress. Many are discouraged by this absolutist approach to server safety, and forget the very basics. Obviously, the…

Windows 11 will create heaps of needless trash

The latest announcements for Windows 11 have revealed that the next version of the Windows operating system will have very stringent hardware requirements. Some of them are, in my opinion, quite reasonable. For example, they&rsquo;re finally dropping support for 32 bit X86 and legacy BIOS boot. These make sense, because almost every PC manufactured since 2011 has supported X64 and UEFI. It also…

Your Car Has Two Steering Wheels

Your brand new cars is loaded to the gills with neat new tech. The dash is basically a giant tablet full of games and apps. It&rsquo;s the hottest new tech product.&#xA;But it does have one strange quirk. While your last car had one steering wheel, which is largely considered the correct amount, this one has two.&#xA;To be more specific, you originally sought out to buy a vehicle with no steering…

Castles, alligators, machine guns, and mail

One day you&rsquo;re asked to fortify your home in the name of &lsquo;safety and security&rsquo;.&#xA;Depending on your career, socio-economic, and cultural backgrounds, you may produce a very different result. And with no other context besides &lsquo;safety and security&rsquo; that&rsquo;s understandable.&#xA;Some may choose to upgrade their doors to thick steel ones, and fit wrought iron bars on…

The billion dollar hotdog stand

There&rsquo;s a little hotdog stand outside every shopping center, supermarket, mall, and street corner in the world. It looks run down and nasty, but somehow they&rsquo;re still in business. You&rsquo;ve never had one. Well, once. You spent the next day feeling sick so you never went back.&#xA;How on earth are they worth $300 Billion dollars, so much that nobody in the world can seem to nail an…

Domesticated Kubernetes Networking

I have wanted to run Kubernetes at home for some time, but the main obstacle has been a reliable solution for providing load balancing for ingress or services, and the lack of a reasonable way to manage NAT transparently. While publicly routable IPv4 addresses are seemingly limitless* in the cloud, typically we only get one at home.&#xA;Similarly, there isn&rsquo;t a straightforward way to build…

The Cursed Certificate

This is the story of the most awful SSL certificate I have ever made. This was done entirely for my own amusement, and for the minute possibility that I could make somebody I don&rsquo;t like miserable.&#xA;Now, why on earth would I want to do this? Well, I don&rsquo;t particularly respect scanner people. Their scanners are annoying, their tools always suck, and they create tonnes of noise in my…

Our mostly disposable and entirely stupid world

Across the street from my apartment is a house which has been in a perpetual state of renovation for nearly six months. This past week, a for sale sign has popped out of the ground just in time for the spring rush.&#xA;It turns out, the man who bought the house did so about a year ago with the sole purpose of renovating and flipping it to make a quick buck.

Trying out OpenBSD (as a Linux geek)

There&rsquo;s always been a kind of temptation from the proverbial &lsquo;other side of the fence&rsquo; when it comes to Unix-like operating systems. This idea that there&rsquo;s an entirely separate and similar, but entirely distinct system from what I&rsquo;m used to is exactly what&rsquo;s pulled me towards OpenBSD today. As somebody experienced with almost every mainstream Linux distro, I…

Making VoIP Calls with Antique Rotary Phones

One of the worst parts of modern life is how unsatisfying it is to hang up on somebody. Tapping on the &lsquo;End Call&rsquo; button on an iPhone or angrily clicking &lsquo;Leave Meeting&rsquo; on Zoom just isn&rsquo;t nearly as fun as slamming down the handset on a real phone.&#xA;This particular project was to breathe some life into the antique Northern Telecom phone from my grandparents&rsquo;…

Monitoring WAN speed with speedtest-cli and ElasticSearch

Similar to another post about WAN latency, this is a simple system to automate periodic internet speed tests. The two main components are speedtest-cli and ElasticSearch. These were chosen because I already had both set up and running, along with all the visualization and analytical software. To get a basic POC set up, just install ElasticSearch and Kibana with Docker. Once the node/cluster is…

Monitoring WAN latency with InfluxDB

This is a simple, &lsquo;quick and dirty&rsquo; way to measure network latency over long periods of time. The only &lsquo;complicated&rsquo; part is setting up InfluxDB, but I imagine that many folks already have it set up. To get started, check the official documentation.&#xA;Network latency will be measured with the good old ping command, then formatted with generic Unix tools. Then, statistics…

The Zeroshell botnet returns

Back in August, I discovered novel cyberattacks targeting network infrastructure. Now, four months later, another botnet is targeting these devices again.&#xA;My original report is here: https://nbailey.ca/post/zeroshell-botnet&#xA;New attack The previous version of the zeroshell malware would leave logs with this…

Installing Gentoo on a vintage Thinkpad T60

I installed Gentoo Linux on my vintage Thinkpad. This particular device has a rather colourful history. In mid 2015 I recovered it from an e-waste pile at my workplace and brought it back to life. In the years since, it&rsquo;s been a playground of sorts. In five years it&rsquo;s had four editions of Windows, three versions of BSD, exotic operating systems like Redox and ReactOS, and of course…

Malware emails 2: Russian boogaloo

Today I got yet another malware email. They just won&rsquo;t leave me alone. I suspect it has to do with the upcoming US election, based on all the CISA alerts I&rsquo;ve seen over the last couple days.&#xA;However, after going down the rabbit hole with this malware I do suspect that whatever is behind it is more sophisticated than a simple ransomware gang. I won&rsquo;t speculate too much, but…

TP-Link Device Weirdness

I recently started using a TP-Link C7 router to host a guest network at my house. I typically avoid consumer/prosumer gear for my network, sticking to either whitebox (homemade) or older enterprise gear. Alas, the price was right ($0). Every time I do encounter one of these devices I always manage to find something fun and interesting to poke&hellip;&#xA;Bad SSH server First red flag was the sshd…

ElasticSearch broke all my nice things (a story of cascading failure)

About two weeks ago, I upgraded my single node ElasticSearch cluster from 6.8.6 to the latest 7.9 version. Last night, all hell broke loose&hellip;&#xA;The upgrade itself wasn&rsquo;t perfect. There were some issues with my setup that the helpful &ldquo;Upgrade Assistant&rdquo; didn&rsquo;t pick up before I had already committed. I was missing a few formerly optional parameters in my…

A New Botnet is Targeting Network Infrastructure

Starting a little less than two weeks ago, my IDS sensors have been detecting the spread of a new botnet. Unlike previous Mirai botnets, this appears to specifically target the GNU/Linux firewall distribution, &ldquo;ZeroShell&rdquo;. While it&rsquo;s not especially dangerous as far as botnets are concerned, it does appear to be rather vigorous when it sends probes.&#xA;However, we got lucky this…

Malware on the Wire: Monitoring Network Traffic with Suricata and ClamAV

In my endless quest to essentially create a Cisco Firepower firewall for poor people, I found a bit of a gap in the open source security ecosystem. While we have great tools for detecting malicious network traffic patterns, we don&rsquo;t have easy ways of detecting malicious files in transit. So, a bit of fiddling around later, and I have a fairly basic system for integrating Suricata&rsquo;s…

Cloud Threat Protection with OSSEC and Suricata

The idea of this setup is to protect the Small Systems as well as we protect the Big Systems.&#xA;This solution uses a proven stack to protect webservers from modern threats. Using OSSEC, Suricata, and the built-in firewall capabilities of a modern Linux system it is possible to build a low maintenance and stable threat protection platform with relatively low performance impacts.&#xA;It&rsquo;s…

Encrypted LVM/LUKS Linux Install

This is a basic procedure for setting up a linux system my preferred way.&#xA;By no means is this a tutorial or a full guide to installing Linux. There are many parts that have been excluded, since this mainly focuses on the disk layout and partitioning.&#xA;Many parts are optional, and many partitions are not strictly required. For example, the ESP partition can be shared with the /boot…

SSH Agent as Systemd User-Service

Create a systemd user-level config directory:&#xA;mdkir -p .config/systemd/user/ Create the service unit file:&#xA;.config/systemd/user/ssh-agent.service&#xA;[Unit] Description=SSH key agent [Service] Type=simple Environment=SSH_AUTH_SOCK=%t/ssh-agent.socket ExecStart=/usr/bin/ssh-agent -D -a $SSH_AUTH_SOCK [Install] WantedBy=default.target Enable the unit.&#xA;systemctl --user enable --now…