waltuh

Reader

What's on the waltuh user's mind?

from Jim's Personal Blog

Google Cloud gives new accounts $300 in free trial credits valid for 90 days. If you want to run Gemini models on Google Cloud (formerly Vertex AI, now part of Gemini Enterprise / Agent Platform) rather than the separate Google AI Studio, these credits can cover your first-party Gemini API calls.

Here is how to claim the credits, set up your billing and project without getting hit by trial quota limits, and wire everything into gcloud, gemini-cli, and VS Code Copilot agents.


1. Claim the $300 Credit and Pass Verification

To sign up for the free trial at Google Cloud Free Features, you need a Google account and a valid credit or debit card.

A few practical details about payment methods: – Google runs a small temporary pre-authorization charge ($0 to $1) to verify you are human and prevent bot abuse. Google reverses this charge automatically. – Standard credit cards (Visa, Mastercard, Amex) work best. Debit cards usually work as long as your issuing bank supports international transactions and online 3D Secure verification. – Prepaid cards, virtual disposable cards, and some regional gift cards almost always fail Google's fraud checks. If your card gets declined, try a standard bank-issued card.


2. Consumer Gemini vs. Gemini Enterprise (Deploying Models Like Ollama)

Before spending credits, it helps to separate what Google sells to consumers from what Google Cloud provides to developers.

Consumer / Individual Gemini (Any Tier)

When you use the free Gemini web app (gemini.google.com), buy Google One AI Premium ($20/month for Gemini Advanced), or add Gemini to your personal Google Workspace, you are buying a finished consumer application: – You interact through an opinionated chat interface with pre-packaged consumer tools (Google Drive/Docs integration, Gems, Imagen image generation). – You pay a flat monthly subscription. – You do not get raw API endpoints, custom system telemetry, IAM permissions, or VPC network controls. – Your prompts and data fall under consumer terms of service unless covered by a commercial enterprise contract. You cannot connect this account to external coding agents or custom software.

Gemini Enterprise on Google Cloud

Gemini Enterprise (formerly Vertex AI, now part of Google Cloud's Agent Platform) works like a remote, cloud-scale version of Ollama.

When you run Ollama on your local machine, you do not pay a monthly subscription for a chat application. Ollama downloads raw model weights (like Gemma or Llama) and runs a local server that accepts HTTP POST requests with prompt payloads, token counts, and temperature settings.

Gemini Enterprise on GCP does the exact same thing, but hosted across Google's infrastructure: – Raw API Endpoints: You do not buy an app subscription. You query managed endpoints for models like gemini-2.5-flash or gemini-1.5-pro (or deploy open weights directly in Model Garden). – Pay-Per-Token Billing: You only pay for what you consume—fractions of a cent per million input/output tokens, context caching seconds, or dedicated GPU/TPU hours. – Enterprise Data Privacy: Under Google Cloud terms, your prompts, context, and completions are never logged or used to train Google's base models. – Pluggable Backend: Because it exposes standard endpoints, you can plug your Gemini Enterprise backend into any client: terminal tools (gemini-cli), VS Code Copilot extensions, backend microservices, or direct cURL calls.


3. The Free Trial Catch: Upgrading to Paid

By default, the Google Cloud Free Trial runs inside an isolated sandbox. You cannot request certain quota increases, access GPUs, or use some production APIs until you lift trial restrictions.

To get full API access, you need to upgrade your Cloud Billing account: 1. Open the Google Cloud Console. 2. Go to Billing > Billing Account Overview. 3. Click the Upgrade button in the top banner.

How Billing Works After Upgrading

Many developers hesitate to click “Upgrade” because they assume it wipes out the free credit balance. According to official GCP documentation: – You keep your remaining $300 credit. Upgrading ends the trial status, but your remaining balance stays active until the original 90-day window expires. – Google burns the credit first. Any eligible usage draws down your promotional credits before charging your card. – Credit limitations: The $300 credit applies to Google Cloud services, including first-party Gemini models on Vertex AI. It does not cover Google AI Studio (which is billed separately) or third-party partner models offered as Model-as-a-Service on Vertex AI. – Post-credit billing: Once your credits hit $0 or 90 days pass, Google bills your card for ongoing usage.


4. Create a Project and Enable Vertex AI

Google Cloud groups all resources, IAM permissions, and billing inside projects.

Create the Project

In the GCP Console or via terminal, create a fresh project:

gcloud projects create gemini-trial-lab --name="Gemini Trial Lab"

Link your billing account to the new project in the console under Billing > Account Management, or run:

gcloud billing projects link gemini-trial-lab --billing-account=YOUR_BILLING_ACCOUNT_ID

Enable the Required APIs

To send requests to Gemini models, enable the Vertex AI API (aiplatform.googleapis.com):

gcloud services enable aiplatform.googleapis.com --project=gemini-trial-lab

5. Set Up Authentication on Linux

Tools like gemini-cli and the Google GenAI SDK look for Application Default Credentials (ADC) to authenticate against Google Cloud.

Install the Google Cloud CLI (gcloud) if you have not already:

# On Debian/Ubuntu
sudo apt-get install apt-transport-https ca-certificates gnupg curl
curl https://packages.cloud.google.com/apt/doc/apt-key.gpg | sudo gpg --dearmor -o /usr/share/keyrings/cloud.google.gpg
echo "deb [signed-by=/usr/share/keyrings/cloud.google.gpg] https://packages.cloud.google.com/apt cloud-sdk main" | sudo tee -a /etc/apt/sources.list.d/google-cloud-sdk.list
sudo apt-get update && sudo apt-get install google-cloud-cli

Authenticate your user account and configure ADC:

# 1. Log in to the CLI
gcloud auth login

# 2. Generate local Application Default Credentials (ADC)
gcloud auth application-default login

# 3. Set your active project
gcloud config set project gemini-trial-lab

# 4. Set the quota project so billing attributes correctly
gcloud auth application-default set-quota-project gemini-trial-lab

6. Configure and Run gemini-cli

gemini-cli can target either Google AI Studio (via API key) or Google Cloud Vertex AI (via ADC and GCP project settings). When using your GCP trial credits, you want Vertex AI mode.

Set Environment Variables

If you currently have a GEMINI_API_KEY or GOOGLE_API_KEY exported in your shell, unset them so the CLI does not default to AI Studio:

unset GEMINI_API_KEY
unset GOOGLE_API_KEY

Then tell the CLI which Google Cloud project and region to query:

export GOOGLE_CLOUD_PROJECT="gemini-trial-lab"
export GOOGLE_CLOUD_LOCATION="us-central1"

To persist these variables across terminal sessions, add them to your ~/.bashrc or put them directly in ~/.gemini/.env:

mkdir -p ~/.gemini
cat <<EOF >> ~/.gemini/.env
GOOGLE_CLOUD_PROJECT="gemini-trial-lab"
GOOGLE_CLOUD_LOCATION="us-central1"
EOF

Test the CLI

Run a quick prompt to verify the connection:

gemini -m gemini-2.5-flash -p "Explain how a reverse proxy works in two sentences."

If you prefer interactive mode, start a session directly:

gemini -m gemini-2.5-flash

7. Hook into VS Code Copilot Agents via Extensions

You can use your Google Cloud project and $300 trial credits directly inside VS Code's native Chat and Copilot agent workflows.

VS Code exposes a Language Model API (vscode.lm) that lets extensions register custom language models. Once installed, these models show up alongside default choices in the VS Code Copilot Chat panel.

Option 1: Use the Vertex AI Models Chat Provider Extension

The community extension Vertex AI Models Chat Provider connects the native VS Code Chat interface directly to your GCP project using Application Default Credentials.

  1. In VS Code, open the Extensions view (Ctrl+Shift+X or Cmd+Shift+X) and search for Vertex AI Models Chat Provider. Click Install.
  2. Make sure you already ran the ADC authentication command in your terminal: bash gcloud auth application-default login
  3. Open your project folder in VS Code, create a .vscode/settings.json file (or edit your user settings), and specify your project ID and region: json { "vertexAiChat.projectId": "gemini-trial-lab", "vertexAiChat.location": "us-central1" }
  4. Open the Copilot Chat panel (Ctrl+Alt+I or Cmd+Alt+I). Click the model selector dropdown at the bottom of the chat box. You will see your Vertex AI Gemini models listed. Select one, and all chat questions and agent turns will route through your GCP project and draw from your trial credits.

Option 2: Use the Official Gemini Code Assist Extension

If you want codebase indexing, whole-repo awareness, and inline code suggestions in addition to chat:

  1. Install the official Gemini Code Assist extension from the VS Code Marketplace.
  2. In your Google Cloud project, enable the Cloud AI Companion API: bash gcloud services enable cloudaicompanion.googleapis.com --project=gemini-trial-lab
  3. Click the Gemini status item in the VS Code bottom status bar, sign in with your Google account, and choose gemini-trial-lab.

Clarification on GitHub Copilot's Built-in Model Picker

GitHub Copilot natively offers Gemini 2.5 Pro in its dropdown for Copilot subscribers. That option runs on GitHub's infrastructure and burns your GitHub subscription quota, not your Google Cloud $300 credit. To draw from your Google Cloud trial balance, use the Language Model Provider extension approach above, which routes your queries through your own GCP project ID.


8. Calling Models from Code or cURL

You can also call the same models in scripts using your trial credits.

Python (google-genai SDK)

Install the official SDK:

pip install google-genai

Run a generation query with vertexai=True:

from google import genai

client = genai.Client(
    vertexai=True,
    project="gemini-trial-lab",
    location="us-central1"
)

response = client.models.generate_content(
    model="gemini-2.5-flash",
    contents="Name three practical use cases for Redis."
)

print(response.text)

Direct cURL Request

To test from bash without installing Python packages:

TOKEN=$(gcloud auth print-access-token)
PROJECT_ID="gemini-trial-lab"
LOCATION="us-central1"
MODEL="gemini-2.5-flash"

curl -X POST \
  -H "Authorization: Bearer ${TOKEN}" \
  -H "Content-Type: application/json" \
  "https://${LOCATION}-aiplatform.googleapis.com/v1/projects/${PROJECT_ID}/locations/${LOCATION}/publishers/google/models/${MODEL}:generateContent" \
  -d '{
    "contents": [
      {
        "role": "user",
        "parts": [{"text": "Hello from curl!"}]
      }
    ]
  }'

9. Budget Guardrails: Avoid Surprise Bills

The $300 credit gives you plenty of room to test, but you should set limits so you avoid unexpected charges when the trial ends or credits run out.

Set Up a Budget and Alerts

  1. In Google Cloud Console, navigate to Billing > Budgets & alerts.
  2. Click Create Budget.
  3. Set your target budget amount (e.g., $300 during trial, or $20/month if continuing on your own funds).
  4. Configure threshold rules (such as 50%, 90%, and 100% of actual spend). Google sends email alerts to billing administrators whenever your spend crosses these thresholds.

Model Cost Awareness

Gemini pricing on Google Cloud scales by input and output tokens: – Flash models (e.g. Gemini 2.5 Flash, 1.5 Flash) are inexpensive: fractions of a dollar per million tokens. You can run hundreds of thousands of test prompts before making a noticeable dent in the $300 credit. – Pro models (e.g. Gemini 1.5 Pro, 2.5 Pro) cost significantly more per token and consume credits much faster, especially with long context windows and audio or video inputs.

When You Are Done Experimenting

If you decide not to keep using Google Cloud after testing: – Delete the project via gcloud projects delete gemini-trial-lab or from the console's Resource Management page. Shutting down the project immediately stops all billable services linked to it. – If keeping the project, disable the Vertex AI API:

  gcloud services disable aiplatform.googleapis.com --project=gemini-trial-lab

Closing Takeaways

Using Google Cloud's $300 trial credit for Gemini models gives you 90 days of high-end LLM infrastructure without paying a subscription. You can run hundreds of thousands of requests through gemini-cli, build prototypes with the google-genai Python SDK, or route your VS Code Copilot agent turns through your own project.

Two practical habits will keep this setup painless: 1. Always check your active project: Run gcloud config get-value project before starting a session so you do not accidentally send requests to a production or unmonitored project. 2. Watch your budget thresholds: Keep billing alerts active so you know exactly when the trial balance is running low. When the 90 days end, Flash models cost only pennies for casual development work, but shutting down unused projects ensures you are never billed for background idle resources.


Sources & Official Documentation

 
Read more...

from Yonle

This blog will cover the Armbian installation guide for B860H V1 / V2.

Caution: This model MUST not be confused with V5, as both revision have an entirely different hardware inside.

B860H V1 STB Top B860H V1 STB Bottom

The method that's used here will not be requiring the set top box to be already rooted, or at most, outside of the stock rom. Assuming that the STB is still in the stock.

At best, It's recommended to do all of the flashing in Linux desktop, Otherwise the Windows equivalent exists, which i will talk about later.

This guide also works on FiberHome HG680P box (however, check Trivia).


Requirements

  • A Personal Computer with microSD slot (otherwise, use microSD<–>USB adapter. These will work)
  • A microSD card (Use class 10 microSD card if you're going to use this as main)
  • A specifcally made HDMI Boot Dongle which you can made yourself or by purchasing an already premade one via online store (id: Shopee Indonesia | global: Tindie)
  • The actual box itself (B860H) that can still be powered on regardless the boot state (LED is orange, or green, or whatever. does not matter it's rooted, still in stock, or not).
  • Not copy and pasting blindly the attached commands

Installation

The B860H must use the HG680P U-Boot bootloader to work, Which you can obtain it from here (save it as u-boot.bin).

The following steps must be done in order.

1. Flashing the Armbian

You can obtain the Armbian image from ophub/amlogic-s9xxx-armbian, With each consisting of different distros. For example, as of the time of this writing: – resolute is a Ubuntu edition of Armbian OS – trixie is a Debian edition of Armbian OS.

You will want to look for a release with the two keywords: s905x, and b860h. For example:

Armbian_26.11.0_amlogic_s905x-b860h_trixie_6.18.51_server_2026.09.14.img.gz

Once you have downloaded it, Uncompress it:

gzip -k -d -v Armbian_26.11.0_amlogic_s905x-b860h_trixie_6.18.51_server_2026.09.14.img.gz

Note: Adjust the filename with the release that you have downloaded.

Insert a microSD card to be flashed on, check where it was located:

yonle@yonle:/mnt$ lsblk
NAME        MAJ:MIN RM   SIZE RO TYPE MOUNTPOINTS
mmcblk0     179:0    0  58.6G  0 disk 
├─mmcblk0p1 179:1    0   511M  0 part
└─mmcblk0p2 179:2    0  58.1G  0 part 

In this case, it's /dev/mmcblk0

Special: If you're using an SDcard USB adapter, These usually are named with sd[a...c] prefix (example: sdb). It must not be confused with an existing main SATA drive.

and then flash the Armbian image to the card:

sudo dd if=Armbian_26.11.0_amlogic_s905x-b860h_trixie_6.18.51_server_2026.09.14.img of=/dev/mmcblk0 bs=4M status=progress

sync

(yes, sync IS a command)

Adjust /dev/mmcblk0 to the path to your microSD slot, Which you can check via lsblk command.

Caution: Doing this will wipe ALL the datas that's in the microSD card. Please back up important stuff if there's one before proceeding.


There is no need to alter the BOOT partition after flashing as these will be done automatically during boot stage.

2. Flashing the U-Boot

On Windows, Doing this step is essentially done by using a program called Amlogic Bootcard Maker.

Similarly, we can do the same on Linux.

Head to the directory where the earlier u-boot.bin is downloaded, for example:

cd ~/Downloads

Then flash it:

sudo dd if=u-boot.bin of=/dev/mmcblk0 conv=fsync,notrunc bs=1 count=442
sudo dd if=u-boot.bin of=/dev/mmcblk0 conv=fsync,notrunc bs=512 skip=1 seek=1

sync

And finally, Yeet the microSD card out.

Flashing TL;DR

To put it simply, The above tasks is simply:

sudo dd if=Armbian_26.11.0_amlogic_s905x-b860h_trixie_6.18.51_server_2026.09.14.img of=/dev/mmcblk0 bs=4M status=progress
sudo dd if=u-boot.bin of=/dev/mmcblk0 conv=fsync,notrunc bs=1 count=442
sudo dd if=u-boot.bin of=/dev/mmcblk0 conv=fsync,notrunc bs=512 skip=1 seek=1

sync

To the box...

the box, already on Linux

You can determine whenever the box is already hacked or not, And it's usually determined via the LED indicator: – If it's green, Chances are it's running Android. – If it's orange, It's not using a regular android bootloader or is in emergency download mode

On a box with the factory Android rom inside, You usually cannot just insert the microSD right into the box, and then hopes it will boot immediately to what's on the microSD card. The stock bootloader will immediately boot to the Android OS anyway and then indirectly alter the BOOT partition, which is probably not what you wanted.

the specialized HDMI dongle

A specialized HDMI dongle is made specifically to make the bootloader on this box to boot whatever that's in the microSD card, supposedly for emergency / download mode.


To check whenever this HDMI dongle is exactly what we wanted, We can use i2cdetect (installable via i2c-tools) to check the HDMI bus:

First, we will want to know which bus is the bus for the HDMI port in my laptop:

yonle@yonle:~$ sudo i2cdetect -l
i2c-0	i2c       	Synopsys DesignWare I2C adapter 	I2C adapter
i2c-1	i2c       	Synopsys DesignWare I2C adapter 	I2C adapter
i2c-2	i2c       	i915 gmbus dpa                  	I2C adapter
i2c-3	i2c       	i915 gmbus dpb                  	I2C adapter
i2c-4	i2c       	i915 gmbus dpc                  	I2C adapter

On the above example, My bus is at i2c-2, Which is i915 gmbus dpa (notice the dpX prefix). From the 2 at the end of the i2c-2, Add it by +1, Which then: 3.

So now we plug our HDMI dongle to our HDMI port in our laptop:

yonle@yonle:~$ sudo i2cdetect -y -r 3
     0  1  2  3  4  5  6  7  8  9  a  b  c  d  e  f
00:                         -- -- -- -- -- -- -- -- 
10: -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- 
20: -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- 
30: -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- 
40: -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- 
50: -- -- 52 -- -- -- -- -- -- -- -- -- -- -- -- -- 
60: -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- -- 
70: -- -- -- -- -- -- -- --   

If this dongle is what we are looking for, In 0x50, There should have 52 in the third column just like shown above.

Then verify what's inside:

yonle@yonle:~$ sudo i2cdump -y -r 0xf8-0xff 3 0x52
No size specified (using byte-data access)
     0  1  2  3  4  5  6  7  8  9  a  b  c  d  e  f    0123456789abcdef
f0:                         62 6f 6f 74 40 53 44 43            boot@SDC

The string value must be boot@SDC.


Now that we know that the dongle is exactly what we're looking for, Let's begin the installation process:

Now unplug the box from any power source, – Insert the microSD card that we flashed earlier to the microSD card slot, – Plug the HDMI dongle to the box

Then plug it to the power source, and pay attention to the power LED indicator, The green indicator must have turned into orange on this phase.

Keep in mind that the indicator MUST STAY on orange LED light for as long as 15 seconds (it mustn't turn green on this phase, If it did, Then you're flashing it wrong!).

If after 15 seconds passed the LED is staying orange, You can now unplug the HDMI dongle and plug a HDMI cable from your TV/Monitor/CaptureCard to your box, You must see something resembling TTY:

the screen

From there, Once you get into a phase where Armbian asks you for setup, There's two method you can do this: 1. Keyboard way: Plug your keyboard to the STB, and do set up from here 2. Networking: You want to set this box up via ssh: Plug a LAN cable from your router to the box, Check for it's IP address on the router page, and ssh into it:

ssh root@10.42.x.x

The default password is 1234. You will be asked for setup and a new password setup.

The default ARMBian experience

Once you're done, Then that's it. You're done installing Armbian to your microSD via your box, However you will still need to use that HDMI dongle to force it using U-Boot.

Making U-Boot permanent

Just like earlier, Send the earlier u-boot.bin to the box via network:

scp u-boot.bin root@10.42.xx.xx:u-boot.bin

Get into the shell, and check which MMC is our eMMC:

root@armbian:~# lsblk
NAME         MAJ:MIN RM  SIZE RO TYPE MOUNTPOINTS
mmcblk1      179:0    0 58.6G  0 disk 
├─mmcblk1p1  179:1    0  511M  0 part /boot
└─mmcblk1p2  179:2    0 58.1G  0 part /
mmcblk2      179:32   0  7.3G  0 disk 
├─mmcblk2p1  179:33   0  511M  0 part 
└─mmcblk2p2  179:34   0  6.1G  0 part 
mmcblk2boot0 179:64   0    4M  1 disk 
mmcblk2boot1 179:96   0    4M  1 disk 

In this case, Since we're booting from SDcard, mmcblk2 is our target, So:

sudo dd if=u-boot.bin of=/dev/mmcblk2 conv=fsync,notrunc bs=1 count=442
sudo dd if=u-boot.bin of=/dev/mmcblk2 conv=fsync,notrunc bs=512 skip=1 seek=1

Caution: This will permanently wipe the android bootloader in the eMMC. If you plan to install Armbian to eMMC, Do armbian-install and reflash U-Boot to the eMMC via steps above again

Installing to eMMC

Caution: Doing the following will wipe what's in the eMMC, Which includes the Android base itself.

Assuming you have been in the shell, run armbian-install as root:

root@armbian:~# armbian-install 
[ STEPS ] Installing Armbian to internal eMMC...
[ STEPS ] Checking dependencies...
[ INFO ] Dependency check completed. Proceeding installation...
[ STEPS ] Initializing the environment...
[ INFO ] Use mainline u-boot: [ no ]
[ INFO ] Use ampart tool: [ no ]
[ INFO ] Show all devices: [ no ]
[ INFO ] Detected eMMC device: [ /dev/mmcblk2 ]
[ STEPS ] Start selecting device...
-----------------------------------------------------------------------------------------------------
ID    SOC        MODEL                                         DTB                                               
-----------------------------------------------------------------------------------------------------
101   s905d      Phicomm-N1                                    meson-gxl-s905d-phicomm-n1.dtb                    
102   s905d      Phicomm-N1(DMA-thresh)                        meson-gxl-s905d-phicomm-n1-thresh.dtb             
103   s905d      MECOOL-KI-Pro                                 meson-gxl-s905d-mecool-ki-pro.dtb                 
104   s905d      SML-5442TW                                    meson-gxl-s905d-sml5442tw.dtb                     
105   s905x      HG680P                                        meson-gxl-s905x-p212.dtb                          
106   s905x      B860H                                         meson-gxl-s905x-b860h.dtb                         
107   s905x      Nexbox-a95x                                   meson-gxl-s905x-nexbox-a95x.dtb                   
108   s905x      TX9                                           meson-gxl-s905x-tx9.dtb                           
109   s905x      T95,XiaoMI-3S,X96,BTV9                        meson-gxl-s905x-p212.dtb                          
110   s905x      TBee                                          meson-gxl-s905x-tbee.dtb                          
-----------------------------------------------------------------------------------------------------
111   s905w      TX3-Mini,MeCool-m8s-pro-W                     meson-gxl-s905w-tx3-mini.dtb                      
112   s905w      W95                                           meson-gxl-s905w-p281.dtb                          
113   s905w      X96-Mini                                      meson-gxl-s905w-x96-mini.dtb                      
114   s905w      X96W,FunTV,MXQ-Pro-4K                         meson-gxl-s905w-x96w.dtb                          
115   s905l      UNT402A,M201-S,MiBox-4C,IP108H,B860AV2.1      meson-gxl-s905l3b-m302a.dtb                       
116   s905l      MG101,Mibox-4,E900V21C,XiaoMI-4C              meson-gxl-s905l-venz-v10.dtb                      
117   s905l      Tencent-Aurora-1s                             meson-gxl-s905x-p212.dtb                          
118   s905l      ZXV10-B860AV2.1U,HM201                        meson-gxl-s905x-tx9.dtb                           
119   s905l2     MGV2000,MGV3000,M301A,CM201-1,IP108H          meson-gxl-s905l2-x7-5g.dtb                        
120   s905l2     E900v21E,MGV2000-K,e900v21d                   meson-gxl-s905l2-x7-5g.dtb                        
-----------------------------------------------------------------------------------------------------
121   s905l2     Wojia-TV-IPBS9505                             meson-gxl-s905l2-ipbs9505.dtb                     
122   s905l3     CM311-1,HG680-LC,M401A,UNT402A,CM201-1-6-YS   meson-gxl-s905l2-x7-5g.dtb                        
123   s905l3     CM211-1,M411A,B860AV3.2M,B860AV2.1U,M301A     meson-gxl-s905l3b-m302a.dtb                       
124   s905l3     UNT400G1,E900V22D-2,UNT400G,IP108H            meson-gxl-s905l2-x7-5g.dtb                        
125   s905l3     UNT402A,UNT400G                               meson-gxl-s905l3b-m302a.dtb                       
126   s905l3b    E900V21E,E900V22E,MGV2000/CW,M411A            meson-gxl-s905l3b-e900v22e.dtb                    
127   s905l3b    M302A,M304A,CM201-1,CM211-1,CM311-1           meson-gxl-s905l3b-m302a.dtb                       
128   s905l3b    UNT403A                                       meson-gxl-s905l3b-m302a.dtb                       
129   s905l3b    RG020ET-CA                                    meson-gxl-s905l3b-e900v22e.dtb                    
130   s905l3b    IP103H,TY1608,BV310,B860AV-2.1M               meson-gxl-s905l3b-m302a.dtb                       
-----------------------------------------------------------------------------------------------------
131   s905l3b    E900V22D,TY1608                               meson-gxl-s905l2-x7-5g.dtb                        
132   s905l3b    E900V21D,B860AV2.1-A                          meson-gxl-s905l2-x7-5g.dtb                        
133   s905mb     S65                                           meson-gxl-s905x-p212.dtb                          
134   s905lb     BesTV-R3300L,SumaVision-Q7,MG101              meson-gxl-s905x-p212.dtb                          
135   s905lb     Q96-mini                                      meson-gxl-s905x-p212.dtb                          
136   s905lb     IPBS9505                                      meson-gxl-s905l2-x7-5g.dtb                        
0     Other      Customize                                     Enter-custom-dtb-name                             
-----------------------------------------------------------------------------------------------------
[ OPTIONS ] Please Input ID: 106

Pick 106, or B860H.

Pressing enter will tell you to pick filesystem type:

[ INFO ] Input Box ID: [ 106 ]
[ INFO ] Model Name: [ B860H ]
[ INFO ] FDTFILE: [ meson-gxl-s905x-b860h.dtb ]
[ INFO ] MAINLINE_UBOOT: [  ]
[ INFO ] BOOTLOADER_IMG:  [  ]
[ INFO ] UBOOT_OVERLOAD: [ u-boot-p212.bin ]
[ INFO ] NEED_OVERLOAD: [ no ]
[ STEPS ] Selecting root filesystem type...
-----------------------------------------------
  ID   TYPE
-----------------------------------------------
  1    ext4
  2    btrfs
-----------------------------------------------
[ OPTIONS ] Please Input ID (1/2): 

Depending on your workload, you can use either ext4 or btrfs for your eMMC. But if you're unsure, I'd recommend ext4.

It has received plenty of improvements over the years, so it's not the same ext4 people might remember from years ago. It's still a very solid choice for eMMC.

From there, It will install the system to the eMMC from SDcard, which will take several minutes until it's finished.

After it's finished, Reflash U-Boot to the eMMC like how we flash it to microSD:

sudo dd if=u-boot.bin of=/dev/mmcblk2 conv=fsync,notrunc bs=1 count=442
sudo dd if=u-boot.bin of=/dev/mmcblk2 conv=fsync,notrunc bs=512 skip=1 seek=1

sync

So:

[ INFO ] Copying ROOTFS partition data...
[ INFO ] Copying [ etc ] ...
[ INFO ] Copying [ home ] ...
[ INFO ] Copying [ opt ] ...
[ INFO ] Copying [ root ] ...
[ INFO ] Copying [ selinux ] ...
[ INFO ] Copying [ srv ] ...
[ INFO ] Copying [ usr ] ...
[ INFO ] Copying [ var ] ...
[ INFO ] Generate the new fstab file.
[ INFO ] Update parameters related to the releases file.
[ SUCCESS ] Installation completed successfully. Run [ poweroff ], remove the installation media, then re-insert the power supply to boot the new system.
root@armbian:~# sudo dd if=u-boot.bin of=/dev/mmcblk2 conv=fsync,notrunc bs=1 count=442
442+0 records in
442+0 records out
442 bytes copied, 0.00554292 s, 79.7 kB/s
root@armbian:~# sudo dd if=u-boot.bin of=/dev/mmcblk2 conv=fsync,notrunc bs=512 skip=1 seek=1
4095+0 records in
4095+0 records out
2096640 bytes (2.1 MB, 2.0 MiB) copied, 0.1678 s, 12.5 MB/s
root@armbian:~# 

After these are all done, Run poweroff. Once it's off (the LED light will turn to green, Don't worry), Unplug from power source, now you can also unplug the microSD card.

And now let it boot into it's own glory by plugging the power source back, And lo and behold, Look. It runs without the microSD card!:

The Linux boot sequence

Extra: Setting up zram

This can save us some room in our RAM.

sudo apt update && sudo apt install systemd-zram-generator
sudo nano /etc/systemd/zram-generator.conf 

Put:

[zram0]
zram-size = ram
compression-algorithm = lzo-rle zstd(level=3) (type=idle)

Save it (CTRL+S), Exit (CTRL+X), and load it:

sudo systemctl daemon-reload
sudo systemctl start systemd-zram-setup@zram0.service

Extra: Setting up irqbalance

yonle@armbian:~$ cat /proc/interrupts
           CPU0       CPU1       CPU2       CPU3       
  9:          0          0          0          0    GICv2  25 Level     vgic
 11:   26055984   26123490   25924591   25663238    GICv2  30 Level     arch_timer
 12:          0          0          0          0    GICv2  27 Level     kvm guest vtimer
 14:          0          0          0          0    GICv2  58 Edge      ttyAML6
 15:        109          0          0          0    GICv2 225 Edge      ttyAML0
 16:          0          0          0          0    GICv2 231 Edge      c8100100.cec
 17:          0          0          0          0    GICv2 249 Level     d0072000.mmc
 18:          0          0          0          0    GICv2 220 Edge      gxl-crypto
 19:          0          0          0          0    GICv2 221 Edge      gxl-crypto
 20:         89          0          0          0    GICv2 248 Level     d0070000.mmc
 21:     124767          0          0          0    GICv2 250 Level     d0074000.mmc
 23:      86139          0          0          0    GICv2 241 Edge      platform_mhu_link
 24:     903241          0          0          0    GICv2 242 Edge      platform_mhu_link
 25:          2          0          0          0    GICv2 105 Edge      c1108680.adc
 26:          0          0          0          0    GICv2 169 Level     arm-pmu
 27:          0          0          0          0    GICv2 170 Level     arm-pmu
 28:          0          0          0          0    GICv2 185 Level     arm-pmu
 29:          0          0          0          0    GICv2 186 Level     arm-pmu
 30:       1301          0          0          0    GICv2  35 Edge      meson
 31:       2056          0          0          0    GICv2  89 Edge      dw_hdmi_top_irq, c883a000.hdmi-tx
 32:         21          0          0    3029612    GICv2  40 Level     eth0
 33:          0          0          0          0    GICv2  63 Level     c9100000.usb, c9100000.usb
 34:       2503          0   11186225          0    GICv2  62 Level     xhci-hcd:usb1
 35:         26          0          0          0    GICv2  41 Level     mdio_mux-0.1:08
 38:         16          0          0          0    GICv2 228 Edge      meson_ir
 39:          0          0          0          0    GICv2  76 Edge      vdec-mbox1
 40:          0          0          0          0    GICv2  64 Edge      esparserirq
 42:          0          0          0          0    GICv2 193 Level     gpmmu
 43:          0          0          0          0    GICv2 197 Level     ppmmu0
 44:          0          0          0          0    GICv2 199 Level     ppmmu1
 45:          0          0          0          0    GICv2 201 Level     ppmmu2
 46:          0          0          0          0    GICv2 192 Level     gp
 47:          0          0          0          0    GICv2 196 Level     pp0
 48:          0          0          0          0    GICv2 198 Level     pp1
 49:          0          0          0          0    GICv2 200 Level     pp2
 50:          0          0          0          0    GICv2 194 Level     pp_bcast
IPI0:     43769      44509      51827      43352       Rescheduling interrupts
IPI1:   1981654    2376448     760236    3324099       Function call interrupts
IPI2:         0          0          0          0       CPU stop interrupts
IPI3:         0          0          0          0       CPU stop NMIs
IPI4:         0          0          0          0       Timer broadcast interrupts
IPI5:     58603     293691      50386      56088       IRQ work interrupts
IPI6:         0          0          0          0       CPU backtrace interrupts
IPI7:         0          0          0          0       KGDB roundup interrupts
Err:          0

At some point, During it's workflows, One of the CPU core could be overworking than the rest of the other, Especially when it's doing certain workflows that involves what's on the hardware & software itself (eg. wifi, lan, NFS, USB, etc).

And you probably want something like irqbalance to be set up and running on your box:

sudo apt install irqbalance
sudo systemctl enable --now irqbalance

Trivia

Given how similar the hardware that's in B860H V1 and HG680P, Especially the SOC (you can flash the same u-boot.bin and it will still boots!), You can probably follow this guide alongside the same HDMI dongle trickery on HG680P too

especially when it's bootloader is broken (which i saw most HG680P had on), you can force Amlogic to boot the bootloader in microSDcard via the HDMI dongle like what i did here.

They will still boot and will work, But the device tree for the hardware will be partially different and might conflict to each other, So during armbian-install, You must instead chose this:

105   s905x      HG680P                                        meson-gxl-s905x-p212.dtb                          

Alternatively, if you don't have the HDMI dongle, you can bypass the eMMC boot on the HG680P and make the device boot from the SD card by shorting R162, 4C6, and GND on the motherboard simultaneously. The USB port can be used as the ground point. A pair of tweezers or a similar conductive tool can be used to make the connection (found by Jimed-rand).

A similar method can be used on the B860H V1/V2 by shorting R87 to enter boot/recovery mode.

Baffled?

There's a YouTube Video that i made specifically for this. The video won't reexplain what has been mentioned on this page, So feel free to watch how it was done in raw.

 
Read more...

from Jim's Personal Blog

Dadang M. Naser Kang Dadang M. Naser

Dadang Supriatna Kang Dadang Supriatna anu BEDAS

Pembukaan

Dari semenjak aku masih kelas 1 SD (2010) hingga masa kuliah saat ini (2026), aku sudah melalui banyak kehidupan dalam masa pemerintahan kedua Dadang ini yang membawa banyak perubahan di tempat kelahiran aku, yakni Kabupaten Bandung.

Yang selalu aku perhatikan dari mereka ketika menjabat sebagai bupati Bandung, baik kang Dadang Naser maupun kang DS (Dadang Supriatna) yang saat ini menjabat yakni janji manis mereka yang sebenarnya masih banyak kendala dalam pelaksanaan dan hingga saat ini masih belum selesai masalah tersebut.

Kedua Dadang ini berhasil mengubah Kabupaten Bandung menjadi salah satu wilayah administratif yang mulai berkembang pesat, akan tetapi masalah birokrasi masih ada aja terjadi (yang salah bukan mereka yang menjabat, tapi para pejabat dan rakyat nya sulit koordinatif).

Masalahnya apa?

Masing-masing dari kedua Dadang ini memiliki visi misi yang berbeda-beda dalam menjalankan pemerintahannya, tetapi punya satu tujuan yang sama dalam artian luas. Salah satunya yakni infrastruktur. Selama mereka menjabat, banyak sekali perubahan yang dilakukan dalam perjalanan mereka dalam menjalankan pemerintahan yang berusaha memenuhi prinsip good governance. Akan tetapi, mereka juga masih banyak pertimbangan dalam menentukan kebijakan tertentu yang berdampak bagi warganya.

Ketika Kang Dadang Naser tak lagi menjabat sebagai Bupati, beliau tahu bahwa apa yang dikerjakan beliau saat menjabat semuanya masih ada yang belum sempurna, dan pada akhirnya beliau memutuskan untuk menjadi anggota DPR RI (dari mencalonkan hingga terpilih ketika Pemilu 2024) sebagai alat bantu untuk menyampaikan aspirasi rakyat dan usahanya yang sudah terbangun saat masih menjadi bupati menjadi bahan evaluasi yang perlu dijalani hasil evaluasi nya. Di sisi lain, beliau yang berasal dari Ciparay ini juga merupakan DKM dari masjid Al-Karomah di Ciparay.

Nah, terus bagaimana dengan Kang DS? Beliau menurut aku awalnya seperti kurang serius, tetapi setelah 2 tahun menjabat akhirnya beneran serius dalam menjalankan program yang beliau rencanakan waktu Pilbup lalu, salah satunya fokus ke infrastruktur dan program BEDAS lainnya yang beliau rencanakan. Beberapa rumah sakit dengan nama BEDAS beneran dibangun dan beberapa jalanan kampung beneran di cor. Insentif ke guru pengajian juga salah satu program beliau yang membuat warga di Kabupaten Bandung pada tertarik. Namun ya, di sisi lain masih ada ketimpangan dan pelaksanaan yang kurang matang.

Di era Kang DS, beliau juga membangun program “Bewara DS” yang sebenarnya menyediakan layanan Internet gratis di wilayah kerja dan wilayah tertentu yang ditujuk, tetapi pada nyatanya mereka hanya diletakkan di balai desa yang jarang menyediakan lounge untuk warganya menggunakan internet publik tersebut, dan juga tidak semua fasilitas milik penerintah kabupaten tercover dalam program tersebut

Jadi, evaluasi nya bagaimana buat bupati sekarang?

Kang DS yang saat ini menjabat di masa kedua, tolonglah revisi lagi apa yang sudah pernah dijalankan di masa pertama dan matangkan kembali goal dan plan yang sudah dibangun selama ini dan usahakan untuk mendengarkan aspirasi rakyat

Disclaimer kecil

Tulisan ini hanya mencatat soal pengalaman kedua Dadang ini saat menjadi bupati Bandung, tidak bermaksud untuk merendahkan mereka berdua atau berniat buruk lainnya. AKu hanya menilai dari sisi perspektif aku saja. Jika ada yang salah, mohon maaf dan hubungi aku untuk koreksi artikel ini.

 
Read more...

from Jim's Personal Blog

You see my personal blog hasn't much updated, not because I am lazy to give an update, but because I am busy with some of stuff that I am managing and working for, and also I would like to continue my personal writing here, but NOT anymore for dumping, but rather than sharing the stuff I want to tell people about

Sometimes I am looking stupid, sometime I am looking insightful, yeah that's part of Autism which I am facing until now. And the thing I need to control is:

  • controllable behavior
  • languages
  • lust of something
  • circle of emotion

Also, as of the time I am writing this, I have new allergen of some seafood that makes me heavy influenza and has impact to body immune. Also, my dead teeth which has been patched is sick again. I am feeling like I am in the hell of the world.

For now, that's it from me. This post is just update of my condition right now, which soon would be outdated.

 
Read more...

from Yonle

I have one funny reason that still keeps me up doing it despite being a bit lazy.

I encountered a problem that has no optional fix around it that i wanted so i had to create one to solve the damn problem in any way myself. To be frank, i moved on and had a burnout a lot, but even so, i still began to create another kind of tool for myself, and if that still interests me, i often try to maintain it.

the thing is that, open source or foss stuff is not really my first passion to begin with when the first time i managed to code stuff by myself (that was before chatgpt even existed, god lord!)

and to this day, even though it seems like that i contribute to the open source / foss spaces with my own code being published for free, i wasn't here to contribute to the environment actually. i simply made a tool, once found it usable for myself, i simply share it as both archival/preservation and for other to be able to use my thing. because i do not like it when the thing that i code wasn't being used by anyone other than myself.

i might looked like helping some project by sending PR to them to fix certain bug, I might do helping them, yes. But the initial idea is still pretty much because i use their thing, and their thing is problematic, then finally it's technically resolveable, and somehow that's the healthier position for me.

Thing is, i liked creating and then expecting people to use it.

Because i do not like making a project that had no user.

and because i want to have people use my tools, i tend to make some of my projects flexible and controllable while still being easy to use.

for example, vsink, a project of mine that does some stuff with virtual pulseaudio sink, have these options:

$ vsink -help
Usage of vsink:
  -bypass string
    	Comma-separated application names to bypass capture
  -defaultSinkMode
    	Set the virtual sink as default sink. May help with some apps, but can cause issues with volume control.
  -monitor string
    	Comma-separated application names whose recordings should use the capture sink monitor
  -noLoopback
    	Disable loopback. Any app in the virtual sink will not be played back to the main speaker (except bypassed apps)
  -onlyCapture string
    	Comma-separated application names to exclusively capture into the capture sink
  -vSinkName string
    	The name of the virtual sink (default "SystemCaptureSink")

also, go-bwhero, an image compressor/thumbnailer proxy have these options:

$ ./go-bwhero -help
2026/08/20 13:28:14 bwhero, rewritten backend.
Usage of ./go-bwhero:
  -animSizeLimit int
    	Original animation size limit in bytes (default -1)
  -imgSizeLimit int
    	Original image size limit in bytes (default -1)
  -listen string
    	Listen address (default "localhost:8080")
  -userAgent string
    	User agent that go-bwhero should use. (default "Mozilla/5.0; go-bwhero [https://github.com/Yonle/bwhero]")
  -videoSizeLimit int
    	Original video size limit in bytes (default -1)
  -vipsConcurrencyLevel int
    	libvips concurrency level to use
  -workers int
    	Amount of workers to spawn (default 8)

and the most obvious one, unlockata, a tool for doing ATA security on ATA storage drives, have these options too:

$ unlockata -help
Usage of unlockata:
  -device string
    	ATA device ("list" to list ATA devices)
  -master
    	use the ATA master password instead of the user password
  -maximum
    	use maximum security level
  -noreadpart
    	do not reread the partition table after the ATA command
  -op string
    	ATA security operation ("help" to list supported operations) (default "unlock")
  -passwd string
    	Path to 32-byte binary password file
  -serial string
    	ATA device serial number ("list" to list ATA devices)
  -verbose
    	show CDB and Payload bytes being transmitted to the ATA drive.

$ unlockata -device test -op help
Available ATA security operations:
  set              SECURITY SET PASSWORD (0xf1)
  unlock           SECURITY UNLOCK (0xf2)
  freeze           SECURITY FREEZE LOCK (0xf5)
  erase            SECURITY ERASE UNIT (0xf4)
  erase-prepare    SECURITY ERASE PREPARE (0xf3)
  disable          SECURITY DISABLE PASSWORD (0xf6)

from there you can really see which part i really tried my best to convince people to use it in the most indirect way possible.


despite all of that, i do have one very common problem though. if the tool that i create already has a perfect code that then i had no idea what to add or what to fix let alone improve, most of the times, these became pretty much a stall,

which is funnily what happened with most of my go projects. but i don't think i should worry these though given how safe go already is (compared to javascript, heh)

well. with all that being said, now you know why i'm still around and still interested experimenting random things.

but yes. the fact that i use go is deadly for everyone.

cuz i have no longer need to suffer through python, node, c, c++, c##, lua, perl, java, erlang, or even rust problems just to fight one problem

 
Read more...

from Yonle

I do not like to be forced to explain something that i'm personally not comfortable to talk about. And when that happens, I always hung up the phone immediately. That's exactly what happened to me this week.

My Mum dialed me and asked whenever the tuition has been paid. It has been a week, But it hasn't. I told her that, and then hung up immediately as i knew that she will ask me many thousands of times and then teach me how to “scold my Dad to do it immediately”.

And as i guessed, She called me back. But the moment i hear the first 3 words of the same thing, I hung up immediately, again. Several minutes after i write this, She dialed. Again. Was about to ask the same question again, Which then i hung up again. Immediately.

I did tell her several weeks ago, Or many times that i do not like to be forced to answer some of his questions. But she doesn't like that answer and then said that i'm basically the same as my Dad, and “his Big Son doesn't like her”.

So that's basically another reason on why i always hung up my phone immediately and always reconsider myself every time i was planning to go back to my hometown. Because if i did so, She will go with that same darn heavy set of lines once again. That includes when i refuse his solution. too.

Well. It's always been like that. At some other day, His instict to always corner my Dad to send her money (which is normal, basically. I can't blame her) nearly everyday 3 times a day basically led my Dad to literally block his number immediately.

He wasn't really refusing to send money to my Mum. I did send some sum of money that my Dad told me to sent to my Mom via my Uncle's Bank account (since we're in remote town), But when she heard that i'm the one that send it to her, She's very dead picky and refuse to accept the money and insisted that i should keep it for myself (while that money is actually reserved for her. Not me).

Speaking of which, The same situation that she already led into already causes me to block her 2 times for 2 straight months before. And that's me being called “dark-minded”, “disobedient”, and then the most legendary “why should you even exists if i knew you will grow like this” and finally “if i were reborn once again, I swear to myself that i do not want to have a husband and a child”.

From there, You can see why i hung up my phone on her immediately.

and there you have it.

This is basically the everyday life of mine. But whenever i accept myself to become some kind of beggar is something else.

 
Read more...

from Hiki's Lifelog

Berikut merupakan 20 hal yang membuat saya senang (setelah saya pikir-pikir):

  • Dapat makan makanan yang disuka

Entah itu kebab, nasi goreng, sushi, ramen, atau curry, makan makanan yang disuka dapat menenangkan saya.

  • Stabil secara finansial

Walau saya masih memperjuangkan hal yang satu ini, namun punya tabungan yang cukup untuk bertahan hidup (serta dapat membeli barang kapanpun dibutuhkan), serta tak punya hutang pada siapapun, membuat hati tenang.

  • Baca novel

Tinggalkan smartphone, dan bacalah novel. Buat saya, baca novel jauh lebih menarik daripada doomscrolling sosial media, karena interaksi antar tokoh di novel banyak yang menarik perhatian, bahkan dapat membuat saya merenung dan mengubah hidup saya sebaagai pembaca.

  • Keluarga

Keluarga adalah tempat saya kembali setelah lelah beraktivitas, serta selalu menemani dan support saya di kala senang dan susah.

  • Rumah

Rumah bukan hanya sekedar tembok, atap, dengan furnitur-furniturnya. Rumah adalah tempat untuk beristirahat, berkumpul bersama keluarga, dan juga tempat di mana saya bisa menjadi diri saya sendiri sepenuhnya.

  • Khusyuk dalam beribadah

Bisa khusyuk dalam beribadah, dengan mengesampingkan (atau tanpa memikirkan) hal-hal duniawi dan hanya mengingat Tuhan adalah sebuah kenikmatan.

  • Mendengarkan lagu

Dapat mendengarkan lagu atau album yang disuka, sesuai dengan suasana hati, sangatlah menyenangkan.

  • Tidur tanpa set alarm

Adalah sebuah kenikmatan tersendiri bisa tidur tanpa mengatur alarm, jadi bisa tidur selama apa pun yang diinginkan dan bangun kalau memang tubuh betul-betul sudah merasa segar.

  • Mandi dengan air hangat

Setelah melakukan banyak aktivitas, dengan mandi air hangat rasa lelah tubuh jadi berkurang dan tidur jadi lebih enak.

  • Menghabiskan waktu sendirian

Saya adalah orang yang suka dengan kesendirian, entah itu nonton ke bioskop sendiri, atau makan di restoran sendirian. Saya malah tak nyaman kalau harus pergi berkelompok.

  • Suara rintik hujan

Konteksnya di sini adalah saat saya berada di rumah, hujan yang tidak begitu deras (jadi tak perlu khawatir banjir), tanpa suara petir yang menggelegar. Mendengarkan suara hujan, apalagi ditambah dengan membaca novel sambil minum kopi hangat sangatlah nikmat.

  • Bersepeda

Sedari kecil saya senang bersepeda. Mengayuh pedal dengan kekuatan kaki sendiri, serta menikmati pemandangan sekitar sudah membuat saya senang (walau saya hanya pergi ke minimarket).

  • Menginap di resort dengan pantai yang cantik

Walaupun saya baru beberapa kali ke resort dengan pemandangan pantainya yang cantik, namun menikmati semua itu saya sangat senang sekali, bahkan saat saya kembali ke rumah sekalipun.

  • Menyeduh (dan minum) kopi

Tools saya buat kopi di rumah simpel saja: perangkat coffee drip beserta filternya (yang saya beli di Daiso), serta kopi yang saya beli di supermarket. Lalu, kopi saya minum sebelum mengawali hari. Enaknya.

  • Kamar yang bersih

Siapa yang tak senang dengan kamar yang bersih? Barang-barang tersusun rapih, debu-debu yang menempel dibersihkan, serta kabel-kabel tak lagi terlihat acak-acakan.

  • Bepergian, sendirian

Berhubungan juga dengan poin ke-10, di poin ini bepergian yang saya maksud adalah melakukan perjalanan jauh, baik di dalam negeri maupun ke luar negeri. Saya tak suka bepergian dalam grup. Bepergian sendiri jauh lebih asik buat saya, karena tak ada yang perlu mengatur-atur saya ke mana saya harus pergi.

  • Punya teman yang dapat menerima saya

Untungnya, saya punya beberapa teman yang dapat menerima saya sepenuhnya, walau saya sudah melakukan banyak hal yang menurut saya tak baik pada mereka. Dan sebagai rasa terima kasih, saya pun sebisa mungkin juga support mereka dan menerima mereka, baik itu di kala senang maupun susah.

  • Bermain gim

Entah itu main gim di laptop, maupun di NDS, bisa main gim tanpa berpikir kalau apa yang saya lakukan hanyalah buang-buang waktu adalah sebuah kenikmantan.

  • Mendengarkan radio

Hal yang membuat saya senang saat dengar radio adalah menemukan lagu terbaru dan saya langsung suka, terlebih lagi saat penyiar memberitahukan lagu yang baru saja ia putar, jadi saya bisa cari lagu tersebut (dan bahkan membelinya).

  • Berolahraga

Berolahraga di sini adalah berolahraga dengan intensitas ringan, paling tidak 15-30 menit. Awalnya memang terasa berat, tetapi sejak membuahkan hasil, seperti jarang merasa lelah saat melakukan kegiatan harian, olahraga jadi terasa menyenangkan. Saat ini, saya melakukan olahraga ringan selama lima hari seminggu, dan dua hari sisanya saya pakai untuk beristirahat.

Sekian, dan sampai jumpa di tulisan berikutnya.

#Note #100DaysToOffload #D003Y2026

 
Read more...

from Hiki's Lifelog

Minggu ini terasa biasa-biasa saja buat saya. Setelah World Cup berakhir (selamat, Spanyol!), jam tidur saya belum kembali seperti biasanya. Saya baru tertidur pukul 2 atau 3 pagi, bangun sejenak untuk solat subuh di pukul 5-6 pagi, dan baru benar-benar terbangun di pukul 13 atau 14 siang hari.

Di hari Jumat dan Sabtu, saya datang ke kelas Engineering yang sudah berjalan lebih dari tiga bulan. Sejauh ini, saya merasa tak paham apa-apa tentang apa yang sudah saya pelajari. Materi yang disampaikan terlalu advanced buat saya yang otaknya pas-pasan ini. Tak ada satupun ilmu yang nyangkut di kepala saya. Saya ragu bisa lulus dari kelas Engineering ini. Jangankan lulus, mid-test yang rencananya diadakan minggu depan pun saya ragu bisa dapat nilai memuaskan.

Saat ini, saya masih melanjutkan baca buku The City and Its Uncertain Walls Karya Haruki Murakami, buku yang saya pinjam di perpustakaan umum. Buku yang cukup tebal, sekitar 430 halaman. Di hari saya tak datang ke kelas Engineering, saya menyempatkan baca buku ini dengan pace 50 halaman per hari. Dan sampai dengan saat ini, saya telah membaca kurang lebih setengah dari isi keseluruhan buku ini.

Selain datang ke kelas serta baca buku, di minggu ini saya menonton beberapa dokumenter dari NHK yang berjudul A Century on Film, salah satu dokumenter yang saya suka dari NHK, bukan karena saya suka dengan sejarah, namun lebih karena saya ingin tahu lebih mendalam mengenai apa yang terjadi seabad yang lalu, terutama pada zaman Perang Dunia kedua, yang menurutku adalah tragedi terbesar dalam sejarah umat manusia. Dan dengan menonton dokumenter ini pula saya berharap para pemimpin dunia tak melakukan hal yang sama atau bahkan lebih parah di masa yang akan datang.

Sekian Weeknotes di minggu ke-30, tahun 2026.

Sampai jumpa di Weeknotes selanjutnya.

#Weeknotes #100DaysToOffload #D002Y2026

 
Read more...

from Hiki's Lifelog

Secara tak sengaja (melihat federated timeline di Fedi), saya menemukan seseorang berhasil menyelesaikan 100 Days To Offload challenge-nya di tahun ini, dan share pencapaiannya. Buat yang belum tahu apa 100 Days To Offload challenge, di challenge ini, seorang blogger menantang dirinya sendiri untuk menulis 100 blog post dalam kurun waktu setahun. Saya pertama kali melihat challenge ini saat saya masih menulis blog di write.as beberapa tahun yang lalu, dan baru tahu detailnya saat membaca situs ini di awal minggu ini.

Sebetulnya, challenge ini bisa dikatakan cukup mudah. Anggaplah begini: dalam satu tahun ada 52 minggu. Dengan menulis blog dua kali seminggu saja, sudah bisa menghasilkan setidaknya 104 blog post (jika konsisten dan tak malas).

Dan entah kenapa saya tertarik untuk ikut challenge ini, di tahun 2026 yang kurang dari enam bulan lagi akan berakhir. Kalau dihitung secara kasarnya, untuk menyelesaikan challenge ini di tahun ini, saya harus menulis setidaknya lima tulisan setiap minggunya.

Kemudian, saya berpikir: “Apakah saya bisa menyelesaikannya?”, atau “Apakah saya punya ide tulisan setiap harinya hingga akhir tahun?”

Lalu, saya pun kembali membaca deskripsi dari situs https://100daystooffload.com berikut:

Posts don't need to be long-form, deep, meaningful, or even that well written. If there are spelling and grammar mistakes, or even if there's no real point to the post, so what? What's important is that you're writing about the things you want to write about.

Your posts could be how-to guides, or links to another post you have found interesting. They could include your own thoughts about that post, or a response to it. It could be a simple update about what you have done that day. Tell us about your dog, your cat, your fish tank, or whatever hobbies you have. Someone will find it interesting.

Tak apa menulis pendek, tanpa makna, bahkan jelek sekalipun. Tak perlu menulis sempurna selama 100 hari berturut-turut. Yang penting: Just.Write.

Sampai saat ini, yang terpikir adalah saya akan kembali menulis Week Notes setiap minggunya di akhir pekan, serta empat post lainnya dengan tema sedapatnya saat itu juga, atau dapat di tempat lain, seperti Pinterest atau Revospring.

Melalui tulisan ini, 100 Days To Offload challenge untuk tahun 2026 buat saya pun dimulai.

Berjuang!

#Note #100DaysToOffload #D001Y2026

 
Read more...

from Hiki's Lifelog

Di awal bulan April, saya mendapatkan kabar kalau saya mendapatkan beasiswa penuh untuk sekolah spesialis. Singkat cerita, saya tak perlu mengeluarkan biaya sepersenpun selama menjalani sekolah spesialis ini hingga selesai di akhir tahun.

Lalu, di bulan April kondisi Ayah makin memburuk. Ayah hanya bisa tidur di kasur sambil menahan rasa sakit yang dialaminya. Di awal bulan Mei, Ayah kembali dirawat di rumah sakit setelah mengalami sesak napas.

Dan di tanggal 12 Mei, pagi hari, Ayah menghembuskan nafas terakhirnya.

Sebelum Ayah wafat, saya, Ibu, beserta adik saya berada di sampingnya. Ayah menghembuskan nafas terakhirnya dengan sangat tenang sekali. Saat diberitahu suster kalau bapak dinyatakan wafat, kami semua hanya bisa menangis.

Dari pertengahan Mei hingga pertengahan bulan Juni, kami semua menjalani aktivitas seperti biasanya, tanpa Ayah. Tanpa Ayah, keadaan rumah menjadi sangat sepi. Kadang kami dapat menjalani aktivitas dengan baik, dan ada kalanya kami merasa sangat berduka.

Saat saya menulis ini, saya masih merasakan duka. Mungkin duka ini tak akan sepenuhnya hilang dalam diri saya. Saya ingin terus mengenang Ayah serta kebaikan-kebaikannya selama ia hidup selama-lamanya.

Terima kasih, Ayah.

#LifeUpdate

 
Read more...

from Hiki's Lifelog

This is a list of stores in Indonesia to get postcards, organized by region and city. I also put online shops and Indonesian postcards from outside the country. Please message me if you want to recommend a store (or online shop) in your city that sell postcards, so I can add it here. Thank you!

Jabodetabek (Jakarta, Bogor, Depok, Tangerang, Bekasi)

Jakarta

  • Kinokuniya Grand Indonesia (Grand Indonesia West Mall, LG Floor, Jl. M.H. Thamrin No. 1, Jakarta 10310). ±Rp10,000-Rp20,000 each. Sell view cards and illustrated cards. Maps ✅
  • Gramedia Bookstore. Mostly view cards. Available in some stores.
  • Sarinah Mall (Jl. M.H. Thamrin No.11, Jakarta). Reasonable price, ±Rp5,000-Rp15,000 each each.
  • Filateli Corner in Central Post Office Pasar Baru, Jakarta. ±Rp3,000 each. ✅
  • Pasaraya Department Store, Jakarta, on souvenir floor. ±Rp20,000 each, unreasonable price but some cards have real batik cloth.
  • Periplus. ±Rp10,000-Rp20,000 each. Available in some stores. ✅
  • Scoop and Scoop Ideas. Sell art cards. Available in some stores. ✅
  • Post Kantoor – Koffie . Art . Kultur (Jl. Cikini Raya No. 1, Jakarta). Sell illustrated cards. ±Rp15,000 each. Maps ✅
  • Galeri Nasional Indonesia (National Gallery of Indonesia), Jakarta. Sell view and illustrated cards. ±Rp50,000 per set (2-3 postcards). Maps ✅

Bandung

  • Pos Indonesia (Jl. Asia Afrika No. 49). Rp3,000 each.
  • Filateli Corner (Graha Pos Jl. Banda No. 30). Rp3,000 each.
  • Periplus (Jl. Dr.Setiabudi No. 42). Rp7,000 each, mostly tourist cards.
  • Books & Beyond (Bandung Indah Plaza 1st Floor, Jl. Merdeka No. 56). ±Rp10,000 each, mostly illustrated map cards from lestari_id.
  • Omuniuum (Jl. Ciumbuleuit No. 151B 2nd Floor). ±Rp10,000 each, usually small art cards probably from postcard box.
  • Kineruku (Jl. Hegarmanah No. 52). ±Rp12,000 each, usually art cards from various local artists.

Yogyakarta

Kantor Pos Besar Yogyakarta (Central Post Office)

  • Loket Filateli / Philatelic counter. Open: Mon-Sat 08.00-14.30. Selling official postcards from Pos Indonesia, but sometimes not available. Price: Rp3,000.
  • Koperasi Kantor Pos Yogyakarta (north entrance of the building). Touristic postcards,Batik postcards. Price: Rp5,000.
  • Some street vendors on the west of the post office are also selling postcard.

Around Malioboro

  • The Lucky Boomerang Bookshop (Sosrowijayan Wetan Gang 1). Touristic, black & white, real batik postcards. Price: Rp5,000.
  • Sari Ilmu Bookstore (opposite to Mall Malioboro). Touristic (Yogyakarta), there are some old ones. Price: Rp3,000.
  • Hamzah Batik. Touristic (Indonesia), vintage ad postcards. Price: Rp6,500.
  • Prapanca (near Museum Sonobudoyo). Touristic, black & white. Price: Rp6,000.
  • Toko Kembang Gulo.

Other Places in Yogyakarta

  • Togamas Bookstore (in Kotabaru & Jalan Affandi). Touristic, black & white, illustration postcards. Price: Rp5,000.
  • Yogyatourium Dagadu Djokdja. Historic transportation series postcards; great illustrations but on thin paper. Price: Rp10,000.
  • Museum Affandi. Affandi paintings. Price: Rp5,000.
  • Artlinx Store. Illustration postcards. Maps

Note: places and prices in Yogyakarta was updated in February 2020. For more information, you can visit this blog.

Denpasar

  • Tourist shops in Sanur, Bali.
  • Nacivet Art Photography Gallery Ubud.

Makassar

  • Street-vendors right outside the post office in Jl. Selamet Riyadi No.10 (selling view cards).
  • Bookstore at Sultan Hasanuddin International Airport (UPG). ✅

Online Shops

Local Shops

Online Printing

Indonesian Postcards from Outside the Country

Others

Unexpected Postcards

Events

  • Comic Frontier or Comifuro, typically held on Saturday and Sunday, bi-annually each year. Some local artists/illustrators sell their illustrated postcards in this event.
  • Artket or Art & Illustration Market. Held in Jakarta. Some local artists/illustrators sell their illustrated postcards in this event.
  • Kira Kira Art Market, also held in Jakarta. Some local artists/illustrators sell their illustrated postcards in this event.
  • Biggle or Biggle Creative Market, also held in Jakarta. Some local artists/illustrators sell their illustrated postcards in this event.
  • Semasa Piknik, held in Lapangan Banteng, Jakarta once a year. Some local artists/illustrators sell their illustrated postcards in this event.

Note:
NEW → Recently added (!) → This store has been inactive in the past 30 days or temporarily closed ✅ → Verified, I visited myself

Last updated: 24 June 2026

#Postcrossing #Postcards

 
Read more...

from Jim's Personal Blog

Detox social network

After I am shocked and asking help to my close friend, I decided to detox myself from using any social media, both centralised and decentralised. With exception, I keep my accounts on Peertube under MakerTube, Funkwhale under Funkwhale Italia, YouTube (with new account), and some podcast platform both for consuming good content and content creation.

I was already told people on Facebook that I am stopping to use fediverse due to the unstable behaviour behalf on myself. Until then, I just make them as “newspaper” rather than communicating with them. Sometimes, I have too much consuming the inappropiate content like what my friend Yonle told me. History stuff, geopolitics, government stuff, hot news, and more. Those have effect to my brain and affects how I am communicating with people.

Also, my friend Runa told me to do what she was doing to make detox effective. She told me to getting back to old style communication modes such as emails and IRCs (I was there, and still registered at Libera Chat), and also reducing to follow the trends. Well, it seems not complicated at theories, but for practices, I am trying hard. Well, since I have joined bunch of communities that suits with my job both as Software Developer and SysAdmin, I am getting new insight and I decide to put my times into more reasonable hobbies such as making programs and learn about developer experiences (DX).

The thing is, detoxing is quite hard at first, but this is the requirments that I should face to prevent more damages on my mental health. Also, as people with bipolar, I am really need to control my neuronic environment and manage the stress to prevent unstable behaviour breaks out. That's why I choose to detox both on centralised and decentralised, except for content distribution. I am nearly compared to Lain Iwakura from SE Lain, but worse.

During my detox time, I am just communicating with close relative and few communities that I trusted. Also, I am keep writing the post when I needed to on this instances and start over from zero for content comsumption by making new Google account and subscribe some insightful channels about vintage computers, tech stuff, and more on YouTube in new accounts. For my presence on Facebook and Instagram, I want to abandon again in my detox time.

How's my future as VTuber? Since I cannot follow their culture, I decided to be hybrid content creator and start over from zero. I want take the inspiration from my friend Faiz Intifada and do my own. Not because VTuber culture is niche, but because it won't fit in my behave.

So, I'll start over my life from zero again and if you want to communicate with me, just email me or find me in communities such as IMPHNEN, The openSUSE Project, Cursor Bandung Community, and GNU/Weeb. I am there and open for you to communicate.

 
Read more...

from Jim's Personal Blog

KVM logo

As a person with sysadmin skills, sometimes I need to test the program that I made without thinking about looking for another computer hardware (unless for ARM, that I need hardware for testing), and I have been familiar with VMware for nearly 2 years, and somehow VMware isn't fit for me because it's really obese, and sometimes it cannot interoperate like what VirtIOFS does. I don't want to run a Docker-based container because it wastes my storage, and I don't necessarily need it for now. After a few months trying QEMU/KVM, I guess we finally have a virtualised environment that we can tweak whatever we want without the limitations that VMware and VirtualBox didn't offer.

Basically, when I want to run the subsystem that could integrate like what WSL2 did, I am trying to learn how to utilise the KVM by reading some docs that exist so much on the Internet, even on openSUSE Docs regarding KVM, I would give an try for this one, since I want to be less dependent on VMware, and it's amazing. They did have running under libvirtd with some other components that were required for running the VMs. The performance I faced when running is really great since the module is built into the Linux kernel.

For management, I am using virt-manager, which is a program made by Red Hat for managing virtual machines. Since QEMU is a free and open source emulation program, and they require you to understand the commands and have comfort using the terminal, I guess these management tools like virt-manager really help. KVM only accelerate the architecture that you're using on your computer. If you have x86_64, then it only accelerates on Intel/AMD's 64-bit architecture. But if you're on ARM64 or aarch64, it could be the same as what Intel/AMD's 64-bit does. I even think of running the first Intel-based Mac OS X using QEMU/KVM if I could.

Well, I guess this is just the beginning of using QEMU/KVM in my daily computing. Should you use QEMU/KVM? If you want to learn and use it on your Linux computer for your daily work, then you should try it. For beginners? If you want, take it.

 
Read more...

from Yonle

sepucuk pendapat pribadi: siswa, dan sekolah

jika kamu pikir-pikir, keadaan siswa-siswi Indonesia yang kebanyakan tidak dapat menyerap banyak ilmu maupun pengetahuan dari sekolahnya cenderung akan lebih tolol lagi jika pemblokiran wikipedia benar-benar terjadi. kamu lihat:

kurikulum yang tidak jelas, tidak realistis

saat aku pegang kedua buku yang berbeda, satu dari berbasis kurikulum 2013, dan satunya dari kurikulum merdeka, perbedaannya sangat menonjol:

dalam buku kurikulum k13 tersebut, penjelasan materi cenderung lebih luas daripada sebuah tugas per bab. Setiap tugas yang diberikan di dalam buku itu mereferensikan dengan apa yang sudah dijabarkan kepada siswa, Mau itu telah dijelaskan oleh guru maupun tidak, semua jawaban dan pengetahuan dapat didapatkan dari satu buku ini secara otodidak oleh siswa.

perhatikan lampiran 2 halaman ini, lalu simpulkan sendiri: gambar gambar

sedangkan pada buku kurikulum merdeka, penjelasan pada sebuah materi hampir cenderung nihil pada buku mata pelajaran masing-masing. jika tugas-tugas ini dijelaskan oleh guru terlebih dahulu, mungkin masuk akal, namun jika orang tua yang menjelaskan kepada anaknya, maka kenapa siswa harus masuk sekolah dari awal?

kejadian di lapangan menunjukkan bahwa kebanyakan guru cenderung jarang memberikan penjelasan pada jam kelas dan terkadang hanya dijelaskan pada saat les, dan walaupun itu dibantu dengan memperpanjang waktu sekolah siswa yang awalnya dari jam 6 pagi sampai jam 12 (atau 1 siang) menjadi jam 6 pagi (lebih awal) sampai jam 3:45.

masalahnya, begini: – penyampaian materi pada buku-buku ini cenderung kompleks, dan bahkan demikian saat lapangan menunjukkan bahwa di Sekolah Dasar pun memiliki masalah seperti ini. – guru di lapangan yang baru terjun di mata pelajaran ini justru kewalahan dengan kompleksitivitas metode penyampaian materi yang disampaikan. ini seharusnya sudah tidak terjadi di beberapa wilayah, namun hasil di lapangan pun menunjukkan bahwa guru baru pun tetap memiliki masalah serupa. – kebanyakan guru di lapangan cenderung tidak melakukan penjelasan, dan justru memberikan tugas lalu kemudian, begitu saja (keluar dari kelas saat belum istirahat, memberikan siswa jam kosong). – siswa yang tidak mengerti dengan materi yang disampaikan cenderung terjebak dengan materi yang diberikan jika tidak ada semacam les, atau pengajaran di rumah – orang tua terbebankan oleh tugas-tugas anaknya yang dimana seharusnya sudah dijelaskan oleh guru

dan sebenarnya? beberapa sekolah cenderung mengkeep beberapa mata pelajaran agar tetap mengajarkan beberapa dari kurikulum 2013.

kita sudah melihatnya di lapangan, dan konsenkuensinya, bukan main

perhatikan, lalu buka peramban internetmu sendiri: – beberapa murid-murid SMA pun tidak dapat membaca, atau bahkan menghitung aritmatika dasar (tambah, kurang, kali, bagi) yang dimana seharusnya sudah bisa – masih sma, tidak dapat baca jam dinding?? apa kabar dengan gurunya sebelumnya? apakah di lingkungannya tidak pernah ajari cara membaca jam dinding sama sekali??

lalu, begini masalahnya: – jika kita sebut guru-guru molor pada tugasnya di lapangan, sebenarnya ada faktor yang memperjelaskan keadaan guru:

guru kita underpaid. serius.

jika kita lihat keadaan di lapangan, beberapa guru hanya digaji sekitaran 200 ribu ataupun hanya 150 ribu perbulan.

iya. sebanyak uang kas yang kita keluarkan setiap 4 hari.

sebenarnya, beberapa pihak sudah mendesak pemerintah untuk menaikkan gaji guru, namun pemerintah condong ke MBG yang secara bersamaan menyebabkan inflasi harga sembako di beberapa kota beserta tutupnya beberapa UMKM di wilayah sekolah. dan secara bersamaan, gaji guru dipotong di situasi yang bersamaan.

sekarang, sudah lihat kan?


mungkin itu saja dariku.

jika terdapat kesalahan, buatlah pos yang mengkoreksi artikelku ini.

sekian,

seorang mantan siswa yang melihat transisi k13 ke kurikulum merdeka.

 
Read more...

from Yonle

Well, Look. Since i've said this before in the VC, So i might wanna make things clear a bit since i spoke all of that during my little jogging that i can't really focus on my words.

Caution to reader: This might sounded misogynistic at first, But it's actually not. If you still thought so, Close this tab.


To begin with, I literally didn't care if you're a male or female to begin with. If one completely acted like a cunt to the point i can't even hold my fury, then so be it.

Like any usual middle high schoolers, There's always that one person that literally despise you for no reason but then will need you for something else, and that kind of person is always here. I would like to say this, though. I really don't want to have debates to begin with, But given the amount of volumes of BS that i get everyday from these individuals, That same exact incident changed exactly who i am since that very day.

Please remember: I talk about one specific person. It doesn't even mean that i will treat everyone exactly the same treatment. There's a reason for why the following happens.

There's that one girl who since the last year of middle school will always cut me off everytime i talk to teacher or my close friend (rare, but it occurs), or during group discussion. These cuts are not even polite or anything, but rather pure disrespect.

There are time where i literally had enough to that girl that i literally slam my hands onto the table to shut that one person off due to constant cutting off and the disrespect that she put,

When she fight back with words, This time i snapped and shouted back at her, It's all going on back and forth until a classmate stop both of us.


Well, This is basically a messy rambling that i try to recall on my brain that then ended up being messy.

To be frank, I do not really want to be a debater to begin with, But i guess there's so many factors to the point that I literally became one.

 
Read more...

from autumn

The Social Web Foundation Adds End-to-End-Encryption to Mastodon and Why This Is Probably Not a Great Idea


As gregarious as people are, they also love their privacy. Eavesdropping, reading over the shoulder, going through personal affects? Everyone can agree, it is egregious behavior when your privacy is violated, even when justified. Thusly, it is in one's nature – innocent or otherwise – to engage in the right of privacy. What people do not have the right to, is to demand provision of this privacy from external sources. Historically, you learn to wear your own mask, to bury your own secrets.

Simultaneously, we continue to see that people are contrarian. As much as the people love their anonymity, they equally love their identity, expressing themselves in both private and public spaces such as bars, clubs, boardwalks, or even Social Networking Services (SNS) like Mastodon. Within these spaces people hold a reasonable expectation to both privacy and respect, i.e. not to be harassed, mocked, doxxed, stalked, have their personal space, or likeness violated, etc. Unfortunately, this cannot always be guaranteed in public or even in private spaces, leading us to the necessity of moderation, which we will touch on later.

Considering these facts, you are likely to enjoy the idea of secure and private conversations with your associates. If this is the case, you are probably looking for a service that offers End-to-End-Encryption (E2EE). There are many services to choose from, some more secure than others. Whatsapp for example offers convenient but highly insecure E2EE, while Signal Messenger offers a less convenient, but more secure implementation.


E2EE explained simply is when everyone has two keys and a signature. You generate these keys, one public, one private, then start trading public keys and signatures with known associates. When you send a message to anyone, it will be encrypted using their public key & decrypted only by their private key. Your message stays secure in transit. Seal that letter with your signature we mentioned and you've proven yourself as the origin, avoiding impersonation.

Note: E2EE doesn’t stop the network from seeing who talks to who, when, or how often – “privacy” is leaky even if message content is encrypted.

Many individuals – including myself – have recommended using PGP's key generation, signing & message encryption/ decryption capabilities to send encrypted messages “anywhere”... this is less than ideal in 2026. The author of The PGP Problem – lvh – stated that if you want to talk,

Use Signal. Or Wire, or WhatsApp, or some other Signal-protocol-based secure messenger.

Modern secure messengers are purpose-built around messaging. They use privacy-preserving authentication handshakes, repudiable messages, cryptographic ratchets that rekey on every message exchange, and, of course, modern encryption primitives. Messengers are trivially easy to use and there’s no fussing over keys and subkeys. If you use Signal, you get even more than that: you get a system so paranoid about keeping private metadata off servers that it tunnels Giphy searches to avoid traffic analysis attacks, and until relatively recently didn’t even support user profiles.

As for email?

Don't.


Now that we have explained what E2EE is, 'The PGP Problem', and the use of dedicated tools, let us take a look at this – From the Social Web Foundation, Implementing Encrypted Messaging over ActivityPub:

“Encrypted messaging has become a common feature on many social networks since ActivityPub was created, and its lack has inhibited Social Web adoption and public trust in the network.”

Do you genuinely believe the lack of E2EE is keeping the masses at bay? The grandmas and grandpas who just want to message their grandchildren? The mothers who just want to know when the next soccer meet is? I assure you, not a single “normie” is worried about E2EE unless they have swallowed marketing material. Perceived low conversion rates are because these people are literally addicted to their dopamine apps. The “Social Web” is fundamentally not Facebook, that is what you're observing.


Everyone has some expectation of privacy, particularly in regards to federated SNS. Many users are tired of service providers like Facebook “harvesting their data points for actionable business insights” leading them to options that provide a semblance of self agency and sovereignty. On one hand, these services do not traditionally track users, on the other hand, ActivityProtocol (AP) is running behind the scenes as the language of many of your favorite services, i.e. Mastodon. This type of protocol and the way it behaves is referred to as a broadcast protocol. Everyone, everywhere can see you and what you do, who you talk to, and when.

This is especially true when the other server is not fully respecting the protocol, when disrespected, “private” accounts and posts requiring follower approval may not be entirely private. This can lead to confusion and anger between users and operators for being followed by people who shouldn't have access, bots, or tracking services, each of which are disrespecting wishes, consent, or the protocol.

Because of these quirks, there are some nuanced avenues for harassment I will not outline here. Actively processing, investigating, and remediating the deluge of reports in the attempt to promptly moderate against rule breakers, abuse, harassment, exploitation, scams, etc. is already a Herculean and Sisyphean task. Due to abuse by both network users and operators, there are now regulations around the world regarding data retention or lack thereof, along with legal obligations and potential demand.


Everything so far leads the question with E2EE & SNS to quickly become: How do we deploy this at scale, without breaking moderation, without confusing users, & without inviting legal or security failure?

If an operator offers E2EE on an SNS like Mastodon – due to the nature of the protocol being comparable to a public space – suddenly we see the landscape become exponentially difficult, if not impossible to moderate. Operators will place themselves into the unfortunate position where they cannot properly serve and protect their users, or their legal obligations. Additionally, if you offer a secure service and it is not secure or your implementation is bad, what will you do if a litigious troll attempts to sue?

To introduce E2EE into public‑facing SNS while simultaneously trying to “solve” abuse, moderation, & legal exposure, the path of least resistance is likely to be “just verify everyone”, pushing identity‑linked, KYC‑style identity checks as a way to “anchor” trust & accountability. The loudest users and largest operators may start demanding identity verification to ease this friction.


This appears in the long run to be potentially bad for privacy, and it’s exactly why I strongly believe E2EE should be kept out of the core social layer & kept within dedicated tools instead. If people want to hide themselves, they have many options – third party clients, applications, and tools – as they have always had the ability and right to do/ use. It is not the operators responsibility to provide their users the ability to hide. Don't know how to encrypt your own messages? Talk on Signal. Mastodon is a public space, take your private conversation elsewhere. Don't forget, people were writing encrypted messages by hand before computers.

The cost outweighs the benefit. Please, make the sane decision, don't over complicate the backend and keep the public social layer unencrypted. Mastodon is a public space, use purpose built tools like Signal for your private conversations.


P.S. You do not need E2EE everywhere. If you indiscriminately E2EE with everyone across your personal, business, and social life, then a single impersonation can spread everywhere. At that point, the question becomes: how do you prove an imposter is not you?


Yes, at the moment these are optional features, but we ultimately teach our users unsafe and unsanitary practices by telling them it is alright to shit where they eat. Once it is the social norm, even if optional, it will be hard to offer a service that doesn't let users shit where they eat. In the long run this idea appears horrible. As the user, why are you putting the burden of your secrecy on the operator? As the operator, what will you do when users start placing the burden of their secrecy on you?

Source: https://socialwebfoundation.org/2025/12/19/implementing-encrypted-messaging-over-activitypub/


Update: Was informed of and removed mention of GPG as it is insecure, that same friend just provided this article as well, it is a wonderful read, and I will be updating this piece accordingly:

https://www.lvh.io/posts/the-pgp-problem/

Second Update: Removed this following section and updated due to old/ misinformation -

If you want to send encrypted messages anywhere, regardless of service, you could do-it-yourself by using PGP's key generation & message encryption/ decryption capabilities, alongside something like openBSD's Signify for signing and verification. There is also terminology like key rotation and key recovery but these over-complicate things for a simple chat between known associates.

Trade public keys, treat private-key leaks as full identity compromise, and keep circles small to foster high-trust networks.

 
Read more...