Incessant tinkerer since the 70’s. Staunch privacy advocate. SelfHoster. Musician of mediocre talent. https://soundcloud.com/hood-poet-608190196

  • 36 Posts
  • 2.07K Comments
Joined 1 year ago
cake
Cake day: March 24th, 2025

help-circle
  • Wow! That is a very intriguing question, and one that I have never considered before. Just spitballing here but you could possibly use trad apps like Lynis, Greenbone, Nikto, etc. These apps often produce rather verbose and sometimes cryptic output, i know Lynis sure does. So, you could use a prompt like:

    ‘You are a security analyst. Review the following Nmap scan results. Identify services running outdated or potentially vulnerable versions, suggest likely CVEs, and prioritize findings by risk.’

    Then use something like llama3.1:70b, mistral-nemo or deepseek-coder-v2, and pipe your security scans into your local AI. You could feed it your NGINX, docker configs, pFsense firewall rules in and ask the model to audit them.

    IDK, that’s a very good question I think. It’ll be interesting to see what others have to comment.


  • irmadlad@lemmy.worldtoSelfhosted@lemmy.world[AIT] paperless-ngx 3.0.0
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    edit-2
    9 hours ago

    I wonder if there’s a blogpost or something somewhere summarizing the main changes.

    I bet you could use AI summarize all the changes. LOL

    spoiler

    Breaking changes

    The biggest upgrade risks are removal of API v1 compatibility, dropping support for API version 9, dropping Python 3.10, removing support for document and thumbnail encryption, removing pybzar as a barcode reader, and changing the pre/post consume scripts so they no longer accept positional arguments.

    There’s also a change that decouples OCR control from archive file control, plus a refactor of advanced database settings to allow more user configuration. Search and indexing

    A major headline item is replacing the Whoosh search backend with Tantivy, along with unifying text search around Tantivy.

    The release also adds a number of search-related improvements, including better fuzzy matching, highlighting in title/content searches, better handling of special characters and CJK text, and fixes for date/query compatibility during the migration. AI and document intelligence

    Paperless-ngx v3 adds a larger AI feature set: Paperless AI, remote OCR with Azure AI, support for Ollama embeddings, direct LLM language selection, LLM timeout and context settings, and a revamped AI vector store approach.

    It also includes fixes and safety improvements around AI indexing, chat, embeddings, and permissions, suggesting this area was a big focus of the release. Documents and workflow

    The release introduces document file versions, sharelink bundles, a document parser plugin framework, and several workflow enhancements like more actions and trigger filters.

    There are also new or improved document-management behaviors such as moving to trash, password removal actions, better merge dialogs, live document updates, saved view sharing, and more detailed document attributes. UI and tasks

    The task system was redesigned, with a new Tasks UI, task summaries in system status, and better monitoring access.

    On the frontend side, the release updates Angular to v22, moves toward zoneless reactive behavior, improves mobile search behavior, refines thumbnails and image loading, and generally modernizes the UI. Performance and storage

    Performance work is a major theme: there are database indexes for common query patterns, SQLite tuning, faster imports/exports, memory reductions in document importing, and indexing optimizations.

    The release also standardizes checksums on SHA256, improves bulk operations, and adds a variety of backend and file-response fixes that should help reliability and speed. Practical impact

    For a fresh install, v3.0.0 mainly means newer architecture, better search, and more AI/document features. For an existing install, the main things to watch are the breaking changes around API compatibility, Python version, encryption support, and the search/index migration from Whoosh to Tantivy.





  • Finally, these things can cause literal harm to a device

    Unpack that a bit more. What are you using to determine the harm to the device? I understand the concept that heat kills, however, as someone who watches temps closely on my server and especially on my old PC, I can’t confirm that a site causes a dramatic rise in temps. I have openhardware monitor on my desktop that remains ‘always on top’ and I see very little variation from site to site as far as temps are concerned. Just curious as to how you came to that conclusion. Perhaps it’s because I lean heavily on my standalone pFsense firewall to filter traffic.


  • People don’t like Cloudflare, I assume, because it’s concentrating your data into one channel. They have control much like a lot of major data centers. So it’s 6 of this, half dozen of the other, and those idiosyncrasies are justified differently by different selfhosters. I would hazard a guess that all major banking institutions use Cloudflare. It’s just that ubiquitous. I use Cloudflare Tunnels/Zero Trust and I absolutely love it. Cloudflare is unavoidable on the internet.

    ETA: To answer your question directly, yes lemmy.world does employ Cloudflare.





  • Melisearch is integrated into Linkwarden. That’s about my extent of knowledge.

    And have you found a way to have it search within PDFs?

    I did look at melisearch briefly to see if I could use search engine databases in creating my own search engine just as a project because I’ve often toyed with the idea of having my own search engine, but it seemed a bit over my head. Smithsonian Libraries publish some of those databases.




  • In the AI evolution we find ourselves in, I have long looked at the very real possibilities of AI being used in a cyber attack. It’s is an obvious tool to me to use in such attacks. I am quite certain governments are experimenting with such capabilities. Where we used to use the old wardialing and sophisticated bots to jam communications when engaged in conflict, we would replace that with AI. I think that would be a natural progression of technology. For one, AI is relentless. It can find even the most minor soft spot in the ‘armor’ as it were, when programmed to do so.

    We now use AI to find vulnerabilities in software like Linux which basically underpins the entire global internet infrastructure. It would only be obvious that nefarious actors, governmental or otherwise, would also use AI. It does present a lot of issues, but I honestly do not view this as alarming in as much as I see it as a natural technological progression. All technology since the dawn of time wields a double edged sword and that is inescapable.

    I’ve long said AI desperately needs governmental regulation as much as I chafe against regulation which, in the hands of government, usually devolves into over regulation. Right now, it’s a wild wild west from AI rice cookers, to cyber attacks. Some look forward to the AI bubble bursting with glee. However, all that means to me is that the pieces left will be retooled into something else as history has revealed time and time again. I don’t think it’s a fad. I don’t think it’s going away. It may evolve into something else, but at it’s basis, I think AI is here to stay regardless of grassroots opposition.