Latest Posts (20 found)
neilzone Yesterday

'Serious Saturday' at Red Alert Airsoft, Newbury

I started playing Airsoft a year ago , after a long hiatus. Since then, I have played quite a lot, pretty much every two weeks (and then, during the summer, an additional Friday evening targets session, every other week). I am still not particularly good at it, and I could certainly do with getting fitter, but I have got to a point where I am content with the equipment that I have, and I can go out and play with a sense of purpose. I have played all of my games at Red Alert Airsoft, in Newbury. This is for three reasons: the people there are just lovely . Such a friendly, welcoming, down to earth group. it is about 10 minutes away, which is very convenient I enjoy it! I like the mix of games, and while some days have, perhaps inevitably, been better than others, none has been less than excellent. I am sure that there are other good Airsoft sites, but I’ve just got no incentive to go anywhere else. The days that I enjoy the most are the “Serious Saturday” days. This is an all-morning game, with a break for lunch, and then either an all-afternoon game, or a slightly slower pace of smaller/shorter games during the afternoon. There is nothing particularly “serious” about it - everyone is there to have fun, as usual, and no-one takes the games too seriously. There’s always a chance for a laugh and a chat with the other team, normally after you’ve just been hit after spending ages getting to the other side of the site. In my experience - perhaps because of the scary-sounding “serious” name, or the fact that it is on a Saturday when Red Alert mostly runs Sunday games - Serious Saturday has fewer participants, and most of the ones I have played have had somewhere between 10 and 25. Given the size of the site, that makes for two (or three) small teams, and the possibility of splitting down into two-person squads, and that - for me - really works. Skirmish days, when there are 100+ people on the site, are fine, but I do prefer the quieter, slightly more strategic, days. The games are more objective-focussed, and work best when everyone on a team works together. Sure, there’s scope for sneaky individual game play - I spent quite a lot of last Saturday hiding in some ferns, on overwatch on a couple of key points on the site, happily taking down people as they appeared nearby - but it needs to fit in with the overall team strategy to make sense. Red Alert has acquired some rather fun Arduino-powered “bombs”, which can be used for various game modes. Last Serious Saturday, we were playing a “disarm the bomb” game: someone had planted a bomb at our base, and we had to comb the site (30+ acres…) to find the digits making up the code. We had to get them back to the bomb, and disarm it, in the 30 minute time period. The other team had the same objective, and the team which disarmed their bomb first won - not that, honestly, it really matters (to me, anyway) who wins. I’m there to have fun, and get a bit of exercise. The “bombs” are really rather impressive, and I think that they could actually be used to trigger a pyrotechnic device at the end of the countdown… and that would be fun. I also spent a bit of time testing the Topdon TS004 thermal monocular for Airsoft - I will probably try that again when the ferns have died down, and sight lines have opened up a bit. There’s one more “Serious Saturday” this year, and I am looking forward to it. the people there are just lovely . Such a friendly, welcoming, down to earth group. it is about 10 minutes away, which is very convenient I enjoy it! I like the mix of games, and while some days have, perhaps inevitably, been better than others, none has been less than excellent.

0 views
neilzone 5 days ago

AI as the new search engines?

I have never done much in the way of advertising for decoded.legal. When someone new gets in touch to ask about legal work, if it something which we might be well placed to support, I typically offer an initial chat. As part of that, I ask how they heard about us. It is mostly “[x] recommended you to me”, or else “I follow you in the fediverse / I read your blog”. This has been pretty consistent, and word of mouth recommendations, or repeat business from happy clients, accounts for the vast majority of our work. Occasionally, someone says “Your site came up in a search engine”. Recently, there has been an increase in people saying “AI recommended you”. It seems that they were using their genAI tool of choice, and asking that for recommendations for tech solicitors, although I have not asked specifically what prompts they used (and I am not sure what I would do with that information anyway). I have done nothing to the decoded.legal website or blog in terms of “search engine optimisation”. The sites are mostly text, with some basic formatting applied. They load fast over pretty much any connection, because they are tiny. I don’t have a clever plan for cross-linking posts, or a particular structure to what I write, or anything like that. Perhaps I should. But I do not. Most of the time, for blogposts, I don’t even include a “and if you need help with this kind of issue, please contact us” ending because, well, that just seems unnecessary. But anyway, apparently, the sites have good “agentic / AI search optimisation”. I don’t know enough about the topic, but I am surprised that genAI can “recommend” anything. I am surprised that anyone would ask a tool like that for a “recommendation”, which implies some kind of analysis and consideration. For me, this is just search engine territory, and so perhaps some people are using genAI in the same way that they might have used DuckDuckGo, or Startpage, or Google. But people are doing it, and decoded.legal’s name and details are coming up.

0 views
neilzone 1 weeks ago

Mutual aid posts and the fediverse

Over the last couple of years, I’ve noticed more and more “mutual aid” posts. These are posts in which someone is asking for money (usually) or some other kind of support, other than on a commercial basis.) Mutual aid posts are nothing new - I certainly remember them from Twitter - but I don’t recall seeing the same volume of them. Just counting those in my feed right now (mostly boosts by people I follow of other people’s posts) there are 16. It could be that I am just seeing more of them. The number is the same, but I am exposed to more of the people who are asking. It could also be that there simply are more of them. That more people are finding things difficult, or have reached their threshold for needing to ask for help. And, given everything ( waves hands ) going on in the world at the moment, that feels entirely plausible. More people are struggling. I am also seeing a difference in approach. I am used to seeing public #mutualaid posts, phrased in a variety of different styles. Some, recently, seem more aggressive? assertive? guilt-tripping? than I recall. That might be frustration or sheer need talking. I don’t see these too often. The more substantial change is that over the last year or two, there seems to be an increase in the number of people - people with whom I don’t recall a previous interaction, and I’m not following them - replying to my posts, or else starting a conversation in my DMs. These are nearly all asking for money. I am not getting loads of these directed mutual aid requests - I know that someone else is getting far, far more - but perhaps a three or four a month. I know (because they have told me so) that some people regard all mutual aid posts as actual or potential scams, and so filter them out, or simply ignore them. Personally, I tend to support people with whom I have some kind connection. This feels like being part of a community: trying to help others who need it. I am willing to accept that I may fall for a scam from time to time, but I’d rather risk being scammed for a few pounds every so often, than not doing anything to support people who need it for fear of a scam. That said, I do not tend to engage with mutual aid requests from people without some kind of personal link, especially in my replies or PMs. I don’t have a pithy conclusion; this was just something on my mind.

0 views
neilzone 1 weeks ago

Testing the Topdon TS004 thermal monocular for Airsoft

I was very lucky that @edent kindly lent me one of his thermal scopes - according to his review, the Topdon TS004 Thermal Monocular - to try out for Airsoft. I took it today, to Red Alert’s “Serious Saturday” game. This was an absolutely cracking day, which I should probably write about some point. I only used the thermal scope in the morning, for a little bit, for a few reasons: I did not try to mount it to my MTW (rifle); I just leashed it to myself, stuck it in a pouch, and used it standalone. And while that worked, it was a bit cumbersome. I was a bit worried about getting the glass / lens shot out. It does not work if there is a normal plastic scope / red dot shield in front of it and, while the lens is recessed and relatively small, it is still bigger than a BB. It was, I felt, a bit too good. The Red Alert site is - at this time of year - covered in ferns, which provide excellent cover for sneaky play. Or they would provide cover, if you couldn’t see hot bodies moving around / lying still in them through a thermal scope. If someone was deep in the ferns, they were still very hard to see, but if someone was relatively close, even if invisible to the naked eye, they had a pretty obvious heat signature. I was the only one today with a thermal scope, and it just didn’t seen fair play to continue to use it. I am sure that, particularly as they come down in price, thermal scopes will become more common in Airsoft. As, I expect, will stuff to help make you less obvious to them. Sadly, I can’t make the night game which Red Alert is running for Hallowe’en, as I suspect that it would be amazing for that… I will look forward to trying it again, when the ferns have died down on the site, to see how it well it works then. But, for now anyway, I don’t plan on using it for Airsoft on a regular basis. If I did want to use a thermal scope, I’d probably look for one which was capable of being mounted on the rifle itself. I did not try to mount it to my MTW (rifle); I just leashed it to myself, stuck it in a pouch, and used it standalone. And while that worked, it was a bit cumbersome. I was a bit worried about getting the glass / lens shot out. It does not work if there is a normal plastic scope / red dot shield in front of it and, while the lens is recessed and relatively small, it is still bigger than a BB. It was, I felt, a bit too good. The Red Alert site is - at this time of year - covered in ferns, which provide excellent cover for sneaky play. Or they would provide cover, if you couldn’t see hot bodies moving around / lying still in them through a thermal scope. If someone was deep in the ferns, they were still very hard to see, but if someone was relatively close, even if invisible to the naked eye, they had a pretty obvious heat signature. I was the only one today with a thermal scope, and it just didn’t seen fair play to continue to use it.

0 views
neilzone 1 weeks ago

Replacing our SIP doorbell with a plain, old-fashioned, doorbell

Just over six years ago, I installed a shiny Fanvil i10 SIP doorbell. It was little more than a SIP phone in a doorbell box (as the configuration options made clear), but I wanted something which would ring my phone and Sandra’s phone when someone rang it, wherever we were, and I wanted it to go as SIP/RTP, rather than using a proprietary app. So I installed it, popped it on its own VLAN (because I had to run an ethernet cable to the outside of the front door), configured it to talk to our PBX, and went with it. I didn’t bother with the video side of things. And, for those six years, it has been fine, ringing our phones whenever the doorbell was pressed. Recently, calls from the doorbell have been intermittent in their success in calling Sandra’s phone, whether terminating via SIP client, or routing a call to Sandra’s cellular network. And, sure, I could probably spend the time debugging it, but I was trying to solve a problem which didn’t really need solving: we just need a button for someone to press, and for it to result in a noise in the house, and in my office. We have a parcel box, which is very obvious and next to the door. Delivery drivers are great at dropping a parcel in there, and leaving without ringing the doorbell, which is absolutely fine. There’s usually an emailed delivery notification and, if we are that desperate, we can always open the box and check (although I did consider fitting a sensor the parcel box door, to trigger Home Assistant, but in the end I did not…). We are not - currently, anyway - in a position in which we need to know exactly who is at the day (or, rather, who they claim to be) before we answer the door. So perhaps I didn’t need a “smart” doorbell after all… A £18 Tecknet wireless doorbell has solved this just fine, and has meant that I can get rid of the ethernet cabling across the front of the house. It has no problem transmitting through the house, across the garden, and to the alarm box in my office and, if I want, I can change the alert mode from noise and light to just light. It claims to be IP65-rated, and in any case, it is under a porch - the Fanvil device was just fine there.

0 views
neilzone 1 weeks ago

How does one genuinely identify one's own, non-technical, learning and development needs?

As a solicitor, each year, I need to make a statement of solicitor competence . Aside from the regulatory requirement, I want to do a great job for my clients: it is a source of my own personal, professional pride. Similarly, most of my work comes from word of mouth referrals so, simply from a grubby money-making point of view, doing a good job just makes sense. The requirement, at a high level, is pretty obvious: the ability to perform the roles and tasks required by one’s job to the expected standard The Solicitors Regulation Authority helpfully breaks this down into a number of different areas: Crucially, based on the SRA’s list, technical competence - the “knowing and applying the law” bit - is just one facet of overall competence. In terms of learning outcomes / knowing what continuing education I need, this is pretty straightforward: I know that I need to keep on top of my stuff. For me, this means both law and technology, since much of what I do draws heavily on both aspects. In practice, I do this through keeping track of numerous different sources of information, and most of my reflections end up as posts on my work blog . Sure, there is an awful lot of change in both technology and law, and keeping on top of all the various legal issues can be challenging, but at least I can work out what I need to do reasonably easily. I find it harder to assess my learning needs in other areas. Not in a box-ticking sort of a way - actual, genuine, “this would be useful”, development. Stuff that it is worth spending my time on. I have no colleagues, and while I’ve asked clients for feedback, specifically what I can do better, or things they’d like me to do differently, or things that they have valued in other professional advisors, I have turned up nothing. I will keep asking every so often, but I cannot rely on this as a source of learning needs. I do my best to assess my own performance, but I struggle. I keep a document of “practice reflections”, in which I note down issues which cross my mind. Looking back on it for this year, themes include ethics (below), IT and cybersecurity, and, perhaps inevitably, AI. I mentor people, but I have not been mentored. Perhaps that is something to explore. Nevertheless, I do what I can - this year, I had a particular focus on ethics, in the light of the Post Office scandal - but I’d like to be better . I could be led by what is on offer, in terms of seeing what CPD providers are offering, and what other resources are available, and seeing if I fancy any of them. But that feels like the wrong way round to me, since it is not centred on my own learning needs - but it could still be a good source of inspiration. So I asked other professionals in the fediverse what they did for their own continuing professional development. (Importantly, I did not ask what they think that I should do, but rather what they themselves did.) I got a range of answers (including many focussed on technical competence), which I have paraphrased / collated here: a company gives a week off each year for CPD, but the training must be nothing to do with their everyday work. I keep a journal, including things that I find myself hesitating to do, or something that I feel that I did poorly. A variation of this was a “leadership lessons” log, with things that the author saw others do well/poorly, and what they themselves did well/poorly. annually, I prepare a document that contains low points, high points and what I learned from the previous year, and new things I want to try or do / things I want to continue doing / things I want to stop doing for the next year. breadth first and depth first investigations. focussed time, periodically, thinking about my career and role. pay attention to the long term changes. paying for a business coach. looking at people I admire and what they can do, that I wish I could do. talking to people in relevant areas, asking them about challenges they face and skills they have, and comparing it to what I can do or struggle with, and asking what they are up to formal reflections following a template. browse the CPD section of their professional institute, for inspiration. I will see what I can take on board here, for the coming year. And, if you are a client, and you think of something that I can do differently, or better, please do let me know! A Ethics, professionalism and judgment B Technical legal practice C Working with other people D Managing themselves and their own work a company gives a week off each year for CPD, but the training must be nothing to do with their everyday work. I keep a journal, including things that I find myself hesitating to do, or something that I feel that I did poorly. A variation of this was a “leadership lessons” log, with things that the author saw others do well/poorly, and what they themselves did well/poorly. annually, I prepare a document that contains low points, high points and what I learned from the previous year, and new things I want to try or do / things I want to continue doing / things I want to stop doing for the next year. breadth first and depth first investigations. focussed time, periodically, thinking about my career and role. pay attention to the long term changes. paying for a business coach. looking at people I admire and what they can do, that I wish I could do. talking to people in relevant areas, asking them about challenges they face and skills they have, and comparing it to what I can do or struggle with, and asking what they are up to formal reflections following a template. browse the CPD section of their professional institute, for inspiration.

0 views
neilzone 2 weeks ago

On Free software project boards and governance

As always, these are just my opinions. If the remit of the board is not clear to all concerned - the broader community, not just the members of the board - and if that remit is not accepted, argument and politics around what the board should be doing are inevitable. This wastes everyone’s time, on meta debates and side issues, and leads to conflict and division. Does the board set the strategy? Define the policy? Hold an executive to account? Mediate or arbitrate disputes? Act as a point of escalation? Fundraise? And so on. That remit may change over time, and I see no problem in that, as long as that change is in itself both clear and accepted. Similar to the point above, without a clear focus, and a set of documented and measurable objectives / priorities, the board is but an iceberg, bobbing around in the ocean, haphazardly knocking against interesting things. Without priorities, the board may be full of people who, individually, are all doing, or are capable of doing, great things in support of some broader mission, but without the cohesion needed for a board. What are the board’s success factors? Failure criteria? To be productive and worthwhile, board meetings need to have an agenda, and all relevant pre-reading, circulated sufficiently in advance for board members (volunteers, who have other commitments) to read, contemplate, and prepare. The goal of each agenda item must be clear. Is a decision required? Is this an update (which, for some reason, could not be delivered asynchronously)? Is a discussion required, and if so, to what end? Sufficient time must be allowed accordingly. In the context of a group of volunteers, consistent participation may be unrealistic. People have other priorities, and may not be able to volunteer every month. A board which requires 100% of board members to be present to form a quorum for a meeting is not conducive to effective decision making if participation is inconsistent. It means that taking decisions during a meeting is rarely possible. Similarly, if an asynchronous decision making process requires all board members to vote one way or another, or to abstain, before a decision can be reached, then that process is neutered by a voting member’s non-response. A board needs to be set up with inconsistent participation in mind, if that is the operating reality of the board. It is impossible for a board to have informed conversations, and make good decisions - decisions which are truly in the interests of the community that the board serves - unless everyone on the board has access to all relevant information. Information asymmetry leads, at best, to poor and inconsistent decision making and, at worst, to factionalism and mistrust.

0 views
neilzone 2 weeks ago

An increased sense of perspective

Over the last couple of years, I’ve found myself increasingly aware of my sense of perspective. Or aware of an increasing sense of perspective. Of the notion that we have a limited time until we die, and that some of the things - many of the things - which might previously have mattered to me or seemed significant are, in fact, inconsequential, and are not worth getting bothered, let alone worked up, about. That some things are just not worth the time or effort. Not to the point of not caring, but rather about being more conscious of the things that I actually care about. I have long been a fan of “don’t worry about things that I cannot change”, and also the idea of “don’t worry about the small stuff”, and that pretty much everything is “small stuff”. Conversely, that some things which may seem minor, or inconsequential, may actually have a significant impact on me, or someone else, and so are worthy of focus, of care. Not everything is “small stuff”. It doesn’t stop me having a flash of annoyance at things, or a sudden urge to Make Something Happen, but it does mean that I am faster, or more willing, to take a step back and think “does this really matter to me? Do I really want to be spending time on this?”. I don’t know if this is a “getting older” thing, or a “getting wiser” thing, or something else. But it is a noticeable thing. It’s… curious.

0 views
neilzone 3 weeks ago

Initial thoughts on the EU KIDS Act

The European Commission has proposed the EU KIDS Act . It is yet another set of Internet/web regulation proposals to examine, for jurisdictional overreach, lack of common sense in terms of material scope, and so on. It is only a legislative proposal at the moment, so it may not become law, and it may not become law in this form. Based on a quick skim, this is indeed another fine mess, full of unrealistic expectations. The proposal covers a lot of services: I have read this from the perspective of online social networking services, thinking predominantly about Mastodon and other fediverse services. At least code forges are out of scope (“open-source software-developing and-sharing platforms”). And Wikipedia seems to have its own bespoke exemption (“not-for-profit online encyclopaedias”). Small, low risk services are in scope. The covering material specifically notes: small and micro enterprises are not exempted from this Regulation, since they may equally provide harms to minors. It would undermine the objective of this proposal to exclude them from scope Wow. I wonder if the drafters will realise just how harmful this is. In terms of territorial scope, it is broader than the EU GDPR, and indeed the UK’s Online Safety Act, purporting to apply to providers of services irrespective of where they have their place of establishment where they offer those services to recipients of the service that have their place of establishment or are located in the Union I wonder if anyone working on this stopped to think about the boundaries of their laws, and whether they really think that they can impose obligations on people in other countries, merely because that person is running a service which happens to be available to people in the EU? Do I, as someone who runs my own fedi server, where people in the EU can read my toots and respond to them from their own instance, fall into scope? I do not know. Providers of online social networking services … shall not allow a natural person below the age of 15 years to create an account with that service or to access that service by means of an account, created for, or attributed to, that person, where the service poses a risk to the privacy, safety or security of a minor below that age. (Article 6(1)) The tests for “poses a risk” set an incredibly low threshold, and include: enables recipients who access the service through an account to transmit content in real-time to an indeterminate number of other recipients of the service, including through live streaming of audio-visual content enables recipients who access the service through an account to contact, communicate and otherwise interact with other recipients of the service not part of the recipient’s pre-existing connections or subscriptions So a “papers, please” web would become the norm, according to this. For example: When creating an account for a minor pursuant to paragraph 2 of this Article, the provider of online social networking services … shall take measures to establish whether the person creating the account is the holder of parental responsibility over that minor in accordance with Article 26 and verify that the recipient of the service has reached the age of 13 years in accordance with Article 28(1). (Article 6(3)) Article 26 sets out how the European Commission envisages this working, but, wow, I just don’t see it. Harking back to (what should be the exceptionalism of) broadcast regulation, there’s another banger: Providers of online social networking services… shall put in place effective measures to ensure: time-limited access for minors on their service; interruption of usage by minors on their service. Such measures shall be designed in a way that protects school time and core sleep hours of minors. (Article 9) Sorry, I have to turn off my fedi server now, because a child in a different timezone might be heading off to bed and my toots might be distracting… Some of the proposals seem to relate to core browser functionality: Providers of online social networking services … shall put in place measures to ensure that settings are set by default to a high level of privacy, security and safety of minors. To ensure compliance with this paragraph, such providers shall, by default, turn off at least the following settings: other recipients of the service shall not be able to download or take screenshots of contact, location or account information of minors or of any content uploaded or shared by minors on the service; I have no idea how the drafters of this expect the provider of a social media service available via a web browser to restrict screenshots of everything posted by a user. It is not within their gift. The only way to make this work would be either to force all access to be via an app (which would be daft), or preclude child access (which has age verification challenges). Some of the use restrictions would seem very challenging: Providers of online social networking services … shall put measures in place that ensure a high level of privacy, safety and security of minors as regards contacts between minors and other recipients of the service. Those measures shall at least ensure that: other recipients of the service are not able to initiate direct contact with the minor, if the minor has not pre-approved such contact So a 17 year old here posts something interest. No-one is able to interact with their post, unless the 17 year hold has “pre-approved” it. Oh, don’t worry, you won’t be able to see their post anyway: by default, other recipients of the service not previously accepted by the minor shall not be able to access account information of the minor or content uploaded or shared by the minor on the service online social networking services; video-sharing platform services; software application stores online games; operating systems; AI companions; general conversational chatbots. time-limited access for minors on their service; interruption of usage by minors on their service. access to microphone and camera

0 views
neilzone 3 weeks ago

Initial thoughts on the Social Media Platforms (Ofcom Licensing) Bill

There’s nothing like waking up to find people telling me about proposed new legislation which, if passed, would geoblock people in the UK from so many online services, end numerous services in the UK, and criminalise myriad people in the UK. Today’s proposal is the Social Media Platforms (Ofcom Licensing) Bill . The gist of the proposal is that anyone who “operate[s] a social media platform that is available to users in the United Kingdom” commits a criminal offence unless they obtain a licence from Ofcom, and comply with the terms of that licence. Is it a private members bill, and is unlikely to pass - more a declaration of intent than a serious attempt at legislating - so there is a risk that, in responding to it as a serious proposal, one gives it more credibility than it deserves. Nevertheless, here are three quick, pre-breakfast, thoughts, based on the text of the bill here . My starting point, in anything like this, is “what is the problem that the legislation is trying to solve?”. Here, I just do not know. I cannot get to the point of trying to assess whether it is the best way of trying to solve the problem (although this is incredibly unlikely), because I cannot tell what the problem is. The Online Safety Act 2023 already started down the very slippery slope of regulating people’s conversations, through the guise of requiring platforms to do things in respect of those conversation / interactions. Ostensibly it is not content regulation yet, in practice, that is really the outcome that is sought. The same is true here, and this bill is even more concerning. I cannot imagine someone attempting to pass a law telling pub landlords or cafe owners that they - on pain of criminal liability - : must take all reasonable and proportionate steps to ensure— (All I have done here is replace “content made available on its social media platform”, from clause 4 of the bill, with “conversation in the pub/cafe”, and “content” with “conversation” in (f).) I don’t know how someone might go about some of these things? How does the provider of, say, a running forum make a determination of whether a conversation contains misleading information? Is a campaign against facial recognition cameras in public places “harmful … to the public interest”? Who decides? How does a forum for vulnerable people who wish to share sensitive information comply with (e), to provide “transparent information concerning the identity and authenticity” of other users, without causing users harm and stifling their speech? How does this interplay with a user’s rights to freedom of expression, privacy, or data protection? The lack of a conjunction at the end of clause 3(a) renders the scope unclear. Does a platform have to meet both (a) and (b) to be in scope? Or either (a) or (b)? If it is an “or”, then the scope is very broad indeed. If it is an “and”, then it is slightly more narrow, but still incredibly broad. I do not know what “other than those with whom they communicate privately” is trying to get at. Does it include only direct messaging between a small number of participants? Is a large, but closed, group chat “private”? If I run a fedi service for my family, but everyone can see each others’ posts, is that private communication? There is no carve-out for small, low risk, services. Off the top of my head, I’d have to obtain a licence for several services that I run at home. This is an existing problem with the Online Safety Act 2023, but since the impact of this bill would be to criminalise me unless I obtained (and presumably paid for? since Ofcom could not run the infrastructure needed to staff etc. this for free) a licence. Right. Breakfast time. Oh my. that conversation in the pub/cafe complies with the laws of the United Kingdom; that conversation in the pub/cafe is not materially harmful to users or to the public interest; that conversation in the pub/cafe does not incite criminal conduct, violence, hatred or public disorder; that systems are in place to minimise the dissemination of materially false or misleading information; that users are provided with transparent information concerning the identity and authenticity of persons having conversations in the pub/cafe; that harmful conversation identified by Ofcom is removed, restricted or otherwise addressed within such period as Ofcom may specify.

0 views
neilzone 1 months ago

My views on genAI and F-Droid

This is just a record of a fediverse post that I made today, and my subsequent (collective) response to the main points raised by various people who replied to me. There is a proposal for F-Droid to adopt an interim AI policy, along the lines of Debian’s pro-AI policy. [I am not in favour of this(https:// gitlab.com/fdroid/admin/-/work_items/699#note_3771382103). In particular, I don’t want to see genAI code in either F-Droid’s own software, or in apps in F-Droid’s repository. Mine is, of course, just one voice. But I will continue to push for human-written FOSS apps, for human users. (Yes, I am an F-Droid board member. Yes, I’m a volunteer, like everyone else. Yes, others seem to have different views. I do what I can.) I have had a lot of replies to this, and I am sorry that I will not be able to reply to each individually. But I can at least try to reply thematically. Again, my personal views. I like genAI / I use genAI genAI is really good Even if true, on its own, this does not carry enough weight in my eyes to justify overlooking the problems. It is the output that counts, not how it is made. Ethics matter to me. I support codes of conduct for projects. I can’t ignore the horrible views of an author to let me enjoy their writing. And so on. A community is about more than code, and I don’t buy a “make the code better at all costs”. It is too late to stop genAI Why? Is there actually an argument here? A ban would not stop people using genAI / people will not tell you that they are using genAI I agree. If someone is willing to lie about their use of genAI, and submit it anyway (assuming that it was prohibited), then the F-Droid volunteers may not be able to detect it. There is a limit to what any project can do about bad faith actors, willing to break the rules because it suits them. Importantly, a position sends a signal. It says “this is what we want our community to be”. Laws against murder do not stop murders. People still drive while intoxicated. etc. It is not for F-Droid to determine what F-Droid hosts F-Droid already has an inclusion policy (https://f-droid.org/docs/Inclusion_Policy/). I can’t see this changing (nor would I want to default to “anything goes”). The repository system is open, in that developers can host their own repositories or use a third party repository, and users can choose what repositories to add. So F-Droid already determines the boundaries of what it is wiling to host. You can just choose not to use an app made by genAI? This is hard to reconcile with an argument that people will not disclose their use of genAI. Both cannot be true. In any case, developers who wish to use genAI could “just choose” not to submit to F-Droid’s own repositories, and run their own, and make whatever decisions they like about the governance of that repo. Again, my views. Not those of F-Droid. I am just one voice here. etc.

0 views
neilzone 1 months ago

RSS feeds for individual authors of The Register using The Register's new API

Tech website The Register used to offer author-specific RSS feeds . It has recently changed how it does RSS feeds , to use the new api.theregister.com. Thanks to a kind fedizen for showing how one can still use this new API to get author-specific feeds: One can also use instead of , and this brings back a slightly different set of posts. I don’t know which is “right” or better for my use case. Annoyingly, whichever selector one uses, this results in one single massive block of text, without paragraphs or other formatting. Which is better than nothing, but not ideal. I have yet to find a way to deal with this.

0 views
neilzone 1 months ago

Airsoft and the UK's consultation on changing the rules around fireworks and pyrotechnics

The UK government is consulting on changing the rules around fireworks and pyrotechnics in the UK . Like many people, I enjoy using P1 pyrotechnics safely and responsibly as part of playing Airsoft. I had fun this weekend with both flashes and smoke grenades at my local Airsoft site, Red Alert . Although the kind of pyro used in Airsoft is not the main focus of the consultation, some of the questions that the government is asking - particularly around P1 pyro, and noise levels - mean that changes to the rules could still have an (unintentional or otherwise) impact on Airsoft. If you enjoy using pyro for Airsoft or paintball, please do consider responding to the consultation, with simple, clear answers. You can respond to this consultation online , or by email to [email protected], using this response form . It takes just a couple of minutes to complete the online form, and you do not have to answer all the questions. Get your response in before 7 October 2026. For inspiration, here is what I said. (For all the other questions, I said “No answer”.) P1 pyrotechnics used in Airsoft and paintball games (e.g. smoke grenades, thunderflashes, and frag grenades) Numerous adult players of Airsoft and paintball enjoy using P1 pyrotechnics safely and responsibly as part of their games. This includes: These are often sold to players 18 or over at Airsoft and paintball sites and shops, providing a valuable source of revenue to UK businesses. They are used safely and responsibly, at dedicated sites. Airsoft and paintball sites include rules around use of these pyrotechnics as part of their pre-game safety briefings, and games are played with the supervision of trained marshals. There should be no change in the regulatory requirements relating to P1 pyrotechnics used for Airsoft and paintball purposes. I selected “No, the maximum noise limit for fireworks should remain at 120 dB (A,imp)”. In the context of Airsoft and paintball, the existing decibel level provides a degree of realism. This is a key part of the reason why players use noise-generating pyrotechnics while playing. Companies making pyrotechnics for the UK market will need time for research and development, initial manufacturing, safety and compliance testing, and then manufacturing and distribution of new pyrotechnics. Airsoft and paintball sites and shops which sell pyrotechnics will need time to sell off old stock, and to source and obtain new stock (dependent on manufacturers and wholesalers having stock of newly-compliant devices available), to avoid a gap in sales and associated drop in revenue. I would expect this to take several months. Are there any other specific F1 and P1 pyrotechnics that should have their regulatory requirements increased or decreased? Please state which products, what regulatory requirements you think they should have and give your reasons. smoke grenades (to provide cover, or to imitate different gases) pyrotechnic devices which cause either or both flashes and bangs (to distract, and to imitate grenades) frag grenades which explode while ejecting dried peas and the like (to imitate grenades) more specialist pyrotechnics such as mortars and launchable devices (to simulate rockets). Do you agree the decibel level of fireworks consumers use should be lowered? Choose one of the following options: What might be the negative impacts of reducing the maximum decibel level of fireworks available to the general public? Please explain your answer, providing evidence where possible. How much lead in time would businesses need to prepare for the changes proposed in this consultation and why? Please state a lead in time in months or years, and explain your answer, providing evidence where possible.

0 views
neilzone 1 months ago

Automating local backups of UniFi OS Server on Linux with uos-backup

Earlier today, I migrated my self-hosted UniFi controller from Network Manager to UniFi OS Server . One of the annoyances of the new setup is that it does not allow automated local backups - just automated backups to Ubiquiti’s cloud. Fortunately, one can work around this. In the UniFi interface, I set up a new local user, , to use for this automated backup. I am using . is a simple Python scripts which someone has kindly written and shared. I did the following, on the machine I wanted to use to take and store the backups. Get the code: Change to the directory with the code: Edit the python script, for the correct URL, username for my new backup user, and password. Check that the requirements are met: Copy the script to : Make it executable: Create the directory to store the backups. This is the directory specified in the script; you can create a directory with a different path, and then just update the script according Test that the script works: Even though I had just set up a new user, I had managed to get the username and password wrong in the script, and this step helped me debug it. I checked in /var/lib/uos-server/ to check that I had backup files. Set up the systemd services: I then added the backup directory path to restic, so that it gets picked up with my automated restic backups too.

0 views
neilzone 1 months ago

Migrating my self-hosted UniFi controller from Network Manager to UniFi OS Server

One of the jobs that has been on my list for a while is to migrate my UniFi controller installation from the self-hosted network manager tool to the new UniFi OS Server tool. The only reason that it was a job at all is because UniFi has decided to discontinue support for the UniFi network manager. Which is probably for the better, as it contained outdated packages anyway. Frankly, I’m not massively impressed with UniFi any more. If I were starting again, I am not sure that I would pick UniFi kit, but I don’t know what I would go for instead. I simply want to run my own controller, without external access or access by anyone else, to control the network infrastructure at home. I did the migration, and it mostly worked. Here’s what I did: I read the Unifi OS Server installation instructions . I also read the Backups and Migration in UniFi instructions. My UniFi controller is running in a virtual machine, so I took a snapshot of that first. If all else failed, I could roll back the snapshot. I backed up the configuration of my existing UniFi network manager configuration. I downloaded it to my local machine. I also backed up the ssh configuration information for my UniFi devices, in line with the instructions: It is also recommended to copy the SSH username and password from Devices > Device Updates & Settings > Device SSH Settings, in case any devices need help later when connecting to the new instance of UniFi Network. I stopped the UniFi network manager with . I followed the Unifi OS Server installation instructions . It will be interesting to see how updates work. The instructions say: Captive portals will be served on port 8444, changed from port 8843 on Network Server. It did not mention that there was also a change to the port to the controller. However, the final line of the set up information showed that it was port 11443. So I changed my nginx proxy config from 8443 to 11443, and reloaded nginx. I could now access the new UniFi OS Server interface. It went downhill from here. I was intending to restore from backup, so I clicked the option for this. It then prompted me to - forced me to - sign in with a ui.com account. I’ve no idea why. It is a local controller, and I don’t want any remote access facilities. Nevertheless, I could not find a way around it. So I did, but I can’t say that I am impressed by this. It then said: We’ve discovered that you already have a self‑hosted UniFi Network installation. Would you like to import your current network settings into UniFi OS Server? But the options were not “Yes” and “No”, but rather “Continue without importing” and “Next”. This was a surprise anyway, as the instructions say: On macOS and Windows, the installer will automatically detect and offer to migrate your existing Network Server setup (if installed in the default location). On Linux, or if auto-migration doesn’t occur, you can manually migrate by installing UniFi OS Server and using the Site Export tool I am running it on Linux, so I did not expect any migration. I guessed that “Next” means “yes”, so I selected “Next”. It took me to a url ending . This was a blank screen. Nothing at all. I waited a couple of minutes, then refreshed the page. It then showed me a page showing that it was “restoring backup”, but the progress bar remained blank for quite a while. It also said that it was restoring to settings from January 2026, not last night’s backup, which surprised me. After a couple of minutes, the progress bar flashed by, and it was done. The import/migration appears to have correctly imported all my devices, and is set up to talk to them. But other aspects of the migration were underwhelming. It did not restore the settings for my mailserver. It was preset to use the “UI Mail Server”. I set it up to use my own mailserver, and it failed, with a useless error message. When I logged in to my mailserver to see what was going on, I saw . It appears that I am not the only person with this issue , albeit with a slightly different setup. They seem to have resolved it by disabling TLS, which is not an option for me. I have not yet got this to work. Even though I had configured automatic backups on the previous Unifi Network Server, they were not enabled on the new UniFi OS Server. I tried to set it up, but I was prompted for my “Ubiquiti SSO account password”. I tried the password for my ui.com account, but I got an error message of “Something went wrong. Please try again later.” Which was no use at all. Having turned off Remote Access (below), I went back to the Backups dialogue. Now, there was an option to download, or upload & restore, but nothing about automation. The info box says that I can schedule backups here, but there is no user interface for that. I took a manual backup. I cannot see a way to do automated backups to my local file system. If this is correct, this is absurd. I may see if I can do something using the command line. *Edit: yes, I can, with python and systemd. See Automating local backups of UniFi OS Server on Linux with uos-backup . “Remote access” is enabled by default, even though I am confident that I did not have remote access enabled before. When I attempted to untick it, it showed a dialogue box: So I disabled it. https://help.ui.com/hc/en-us/articles/220066768-Updating-and-Installing-Self-Hosted-UniFi-Network-Servers-Linux It did not restore my preferred time format (24 hours). I had to turn off analytics, which was on by default. It worked better than I was expecting, but that’s mainly because my expectations were very low. Why the email server and automated backups do not work, I do not know. I will need to investigate these. But at least I am now running a supported controller again. Once I’ve done a scan of the new system with greenbone, I’ll be interested to see what it reports.

0 views
neilzone 1 months ago

Time to drop .legal?

My wife and I run a small law firm in the UK. Originally, we called it decoded:Legal. It made sense at the time, even though quite a few places struggled with the idea that a company name might have a colon in it. We used , and I registered too (and, it seems, ) although I don’t think I’ve set up DNS for either of them. Then, when a friend pointed out that there is a tld, I thought “that looks nicer”, and we switched to , both as the company name and also our domain name. I wonder if - nice though it still is - I should think about using a different tld. (If I moved, I’d maintain decoded.legal indefinitely anyway, because people are used to sending email to @decoded.legal addresses.) The .legal tld appears to have a poor reputation. For instance, it is on this list of “The Top Most Abused Top Level Domains” . It would be a shame if people could not find our business, or access any of its online properties, because .legal is on that list. (And, yes, I could seek an exception, but that hardly seems the point.) As far as I know, this has not been a problem so far, but this could be survivorship bias: I don’t know about the people who have never seen me. The .legal tld is operated by Binky Moon, LLC , which is based in the USA. I wonder if it would be sensible to use a .tld subject to UK control instead. Obviously, it would be nice if I was not dependent on anyone other than me for my domain name, but that is unrealistic. I use a few .onion domains - for access within Tor - including for decoded.legal properties. For instance, our website and blog are available at http://dlegal66uj5u2dvcbrev7vv6fjtwnd4moqu7j6jnd42rmbypv3coigyd.onion . (And, yes, it is intentional that this no longer has https .) Realistically though, the vast majority of people are not going to visit us in onionspace.

0 views
neilzone 1 months ago

On lawyers, ethics, and integrity

I have been reading some of Richard Moorhead’s new book, arising mainly from the UK’s Post Office scandal, “Frail Professionalism? Lawyers’ Ethics after the Post Office and Other Cases” . It is open access, and available as a PDF (linked above), with html available too; I have not found, nor made, an ePub. I focussed on chapter 8, “Routes Back to Proper Professionalism” , to see the author’s recommendations. Mainly, I was reading this through the lens of “what can I, personally, do better”. For anyone reading this who does not know me, it might be worth noting here that my work is predominantly Internet and telecoms law (with a side helping of data protection). My work is fundamentally commercial in nature, whether it is advisory (as a lot of it is) or transactional. Day to day, a lot of it is simply “solving problems”. I don’t litigate or go to court. I don’t prosecute people. I do not get involved in employment disputes. For me, a key part of my toolkit for solving problems entails building enduring, trusted relationships, through being honest, reasonable, practical, and diligent, to be able to collaborate in an open, genuine manner. As a consequence, I place considerable stock in my personal integrity. These things are important to me. So, of course , I like to think that I already act with integrity and with ethics - these traits are important to me - but I would be foolish to think that there nothing I could do to improve, or that I could not reflect usefully and meaningfully on my own approach. This is not a review, far less a critique, of the book and more me just noting parts which I found particularly resonant, and reflecting on my own working life. What we see in the PO scandal is information being processed based on what is arguable or helpful rather than what is true, fair, and balanced. A culture of ‘can we get away with it?’ is driven by wishful thinking and legitimised by lawyerly zeal. I think that this is particularly true when someone has determined the conclusion that they wish to reach, and is asking for legal advice to support that pre-determined outcome, irrespective of what a neutral, independent appraisal of the situation might conclude. Conversely, if someone has a goal in mind, but is genuinely open to hearing “there is no appropriate (that’s a tricky word; that needs unpacking) way of doing it, but here are some alternatives”, then that is rather different. [Lawyers] compete on being commercial, and more business partnerish. Yes, absolutely. For me, “being commercial” means giving my clients practical, sensible advice, consistent with the broader context of whatever the issue might be. It does not mean - to me - being willing to bend rules, or look away, or act unethically because that will maximise revenue, or increase shareholder value, or make a problem go away, and so on. For what it is worth, I think that “being commercial”, in the sense of my definition above, is a desirable trait in a solicitor. People want, and deserve, pragmatic problem solving, at a reasonable price. If “being commercially aware” is being used as a shield for impropriety, then that is indeed problematic. If a lawyer is asked for an opinion that will foreseeably assist illegality or mislead others they should decline or take reasonable steps to prevent or limit that risk. Yes. I am struggling to see how preparing advice with the intention of misleading someone could be consistent with a professional duty to act with integrity. Harm to a client’s opponents, for instance, cannot always be avoided, but being required to consider and, if proportionate, mitigate or alleviate harm might reduce some of the unnecessary excess that lawyers engage in. I am not entirely sure what the author is angling at here. It is a short section, almost standing on its own. Could it, for example, condemn the common and (to my mind) unsavoury practice of timing letters, and ensuring deadlines, over holiday periods, to cause maximum inconvenience and stress? Quite possibly, where that is a tactic in itself. Writing friendlier, or at least more neutral, less aggressive letters? Some lawyers trade on aggression. I don’t; that’s just not me. In terms of mitigating harm, if I act for Client A, negotiating a contract with Client B (who is also represented), how far would a duty to “alleviate harm” extend? Would my duty extend to helping Client B achieve the best deal for them, for instance (rather than focussing on my own client’s objectives)? How far would it go into trying to solve someone else’s problems? (Reaching a deal which is in the interests of both parties may well be desirable for all number of reasons, but that is separate to a professional duty.) It is curious that this is formulated adversarially, in terms of a “client’s opponents”. It presupposes litigation or conflict. I wonder to what extent it might apply to, say, advice in developing a computer system, where the system could adversely impact the rights and freedoms of third parties who are not “opponents”. Would it stretch to a professional duty to only advise in the context of designing the least harmful online services, for example. Perhaps not a bad thing, although placing that on the doorstep of solicitors, rather than on the companies developing those services, seems backwards. Ethical knowledge and practice should of course be a routine and proactive part of competence review for all lawyers I would be all for the regulator producing an annual ethics refresher course - perhaps an hour or so’s reading. That would seem very helpful. We need to more clearly challenge the claim that lawyers do law but not morality I agree that “this is arguably legal” is a very low standard. Similarly, that what is legal is not the same as what is right . I wonder how morality would be judged. Does it depend on a solicitor’s own sense of what is moral, or on some subjective notion of morality? What of the situation in which there are two, perhaps polarised, stances, with groups behind each stance claiming that morality is on their side? I don’t think that I object to the notion of solicitors needing to consider morality, but in terms of how that professional duty should be constructed, that seems to need quite careful thinking. Perhaps it has already been tackled in other jurisdictions.

0 views
neilzone 2 months ago

Driving to London for the first time in years

Today, for the first time in years - probably 20 or so - I drove to London. I didn’t really want to drive to London, and it is daft that it was even a credible option. I’d much prefer to take public transport and, when I go to London for work, I do. Thankfully, there is a reasonable if not brilliant train service from Newbury to Paddington. Time-wise, there was not a massive difference between driving from Newbury to Westfield, and then taking the tube, and taking the train from Newbury and then taking the tube. Not much in it at all, assuming that everything is running correctly. No traffic jams, leaves on the line etc. The difference was in price. There were five of us travelling today - Sandra and me, and a friend with two children. The train fare alone, from the National Rail website, was going to be over £110, including a significant discount for travelling together (the “GroupSave” discount). There might have been a cheaper configuration of tickets, but this is what the National Rail website offered. I am not even sure if this covered the London Underground element or not. Instead, it cost about £10 in electricity for the car, £12 to park at Westfield, and then ~£30 on for the London Underground. So just over £50, plus some wear and tear to the car. And, of course, the initial outlay of buying and maintaining a car. Other than the last few miles to / from Westfield, the journey was easy. It was quiet (especially on the way back, when everyone else had a nap), comfortable, and cool. I still prefer the train, as I do enjoy being able to work or read my book, and when I normally travel for work I take my bike so I don’t need to deal with the underground either. I don’t really want to drive to London, but it certainly made financial sense today.

0 views
neilzone 3 months ago

Stepping down as a school governor

Two and a half years ago, I found a piece of paper in our parcel box, asking if anyone would consider becoming a governor of a local primary school. I ummed and aahed about it, and decided to express an interest. Within a few minutes I had arranged a visit to the school, and within a few days, I was a governor. I did a lot of training, and spent the first 12 or so months trying to work out what on earth was going on. Being a school governor, and in particular understanding school accounting, was unlike anything that I had done before. Being a governor is a lot of responsibility, and it is - or, at least, was for me - a particularly challenging role, given how much a school has to do with so little money, particularly with an increase in the number of children with additional support needs. Frankly, a completely inadequate amount of money. In addition to general governor duties, I took on responsibility for data protection, chaired the policy committee, and helped improve numerous policies and processes, and stepped up whenever the school needed a lawyer-like person. Tonight, that came to an end. One of my many flaws is that I agree to do too much. I love helping people, and I have a pretty useful set of skills and experiences. The outcome is that I put my hand up too much, and thus stretch myself too thinly. Sure, I get to do some fascinating stuff, and work with some lovely people, but it comes at a cost. I’ve had too many days recently where I’ve done more pro bono / volunteering work than I have done paid work. When I found that I was turning down paid work that I actually wanted to do because of volunteering commitments, I decided that I had got the balance wrong. And, in stretching myself too thinly, I don’t always have the time to give a role the time and attention that it needs. Perhaps, sometimes, doing at least some of the job is better than doing none of the job, I was increasingly nervous about taking that approach to being a school governor. Whether I give up any of my other voluntary stuff, I’m not sure. At times, it is certainly tempting. But, if nothing else, giving up governorship should mean I have a little more time to spend on my other commitments, for as long as I have them. I enjoyed my time as a governor. I certainly learned a lot, and I was pleased to be able to make numerous, and in some cases quite significant, contributions to the life of that small primary school.

0 views
neilzone 3 months ago

Holiday reading, mostly from Standard eBooks

Sandra and I have had this week off, and one of the things I wanted to do was to catch up on my reading. All bar one so far has been from Standard eBooks . From Kobo , I enjoyed this account of someone who claims to have worked for MI5 (I’ve no reason to doubt this, but, well, who knows) carrying out operational (i.e. on street / in car) human surveillance. How much is true, how much is hyperbole, I don’t know, but it made for an interesting, often challenging, read. I finished the book - perhaps as the author had intended - with a question mark as to his suitability for the role. A classic, which I last read many years ago, “The Call of the Wild” is a pretty brutal book about the life of (fictional?) dog in north America during the gold rush. I suspect that there are various parallels with humankind, in terms of the way in which different people treat the dog, and the dog’s move from bored domestic comfort to a wild animal, but frankly - animal abuse aside - it was just a good, fun, and short book. I have read “Jurassic Park” before (better than the film, IMHO, and I think that the film is superb), but for some reason, I had not read “The Lost World” before. The story is, in essence, about some privileged white men exploring a dinosaur-laden plateau. The frankly appalling treatment by white men of the indigenous population seems to be a theme of the books I’ve been reading this week, perhaps because of the prevalent attitudes of the time in which they were written. If you ever wanted to read “Jurassic Park” in somewhat older English - which, I must admit, I find a joy to read - this is worth a look. I jumped in at book two of the series - Allan Quatermain Stories - rather than with “King Solomon’s Mines” . I should probably rectify that. The book is, in essence, a series of stories reifying a hunter, Allan Quatermain, and his adventures in “unexplored” Africa. Basically, he shoots a lot of animals, supported by a cast of indigenous servants. My goodness, I found “The Last of the Mohicans” incredibly tedious and long-winded. I should probably stick with it, as I like the sound of the precis, but still, the 20 or so pages that I read were just hard work.

0 views