• 0 Posts
  • 90 Comments
Joined 2 years ago
cake
Cake day: August 1st, 2023

help-circle

  • Schlemmy@lemmy.mltoSelfhosted@lemmy.worldRaspberry Pi 4B
    link
    fedilink
    English
    arrow-up
    28
    ·
    20 days ago

    I’m running Home Assistant on mine at the moment. It’s amazing. Really. Apart from being an great smart home solution I’ve found it a good solution to create dashboards for life.

    I have set up our family calendar, train schedules that change routes depending on the time. Waste collection notifications. It warns me to get a raincoat and umbrella in the morning. I get news headlines for my interests…

    Before that I’ve tried a lot. It was my first step into home labbing 2 years ago. It brought me back to my youth. Breaking the family computer and trying to fix it before anyone noticing it.

    Most of the stuff I ran used Docker.

    • Joplin notes
    • Mealie
    • Immich
    • Authentic
    • Wanderer
    • Homarr
    • pihole
    • portainer

    Within a year I grew out of my pi setup and bought a second hand mini Lenovo that now runs Proxmox. Minor investment, huge upgrade. Moved away from dockers also.

    The pi is a fun gateway drug.











  • Ah, you can see clearly who gets which data with every authentication. It’s logged and I can look it up on my portal.

    Actually’', apart from ItsMe, I can see every time someone did any lookup on my online data with the federal government for the last 10 years. I even get to see their names.

    There’s no third party watching with ItsMe because the traffic is encrypted. The data is owned by the Federal government and the party that requests authentication gets to see what the are legally allowed to see and what you clear. With every authentication you get to see what info they request.




  • I can’t find the blog post that I was referring to but this might help:

    From their own site: https://www.itsme-id.com/en-NL/why-itsme/security

    ISO cert: https://www.itsme-id.com/en-BE/business/blog/iso27001

    It’s good to point out that the system was developed by a consortium of banks to simplify identity verification en prevent fraud. Banks are held to ‘‘Know Your Customer’’. KYC entails that they need to check your identity every now and then and up until ItsMe that meant that you had to verify with your eID and a card reader. Those card readers have issues. Outdated firmware and whatnot make the proces a terible experience. I have several government websites that I use from day to day and the all need my eID for authentication.

    Some figures. Nearly 1.700.000 authentications every day for 11.700.000 Belgians. 80% Of the Belgians use the app.




  • We have a local privacy podcast (Dasprivé). The CISO was featured on the podcast. I can’t transcribe everything but the community consents on the fact that they run a tight ship. The use case is very local so apart from Flemish and French speaking sources i sadly can’t get further than ‘trust me bro’ at the moment.

    Every authentication uses your SIM, your civil service number and your password (PIN, fingerprint, face id). Before authenticating you’ll see all the info that’ll be shared like your, date of birth, adress, phone number,…

    Acces is granular. If age verification is needed, the request will only state that you’re 18 or above for example. They don’t get my date of birth. As a resident, I get a reduction at our local swimming pool. The can use my id but the only info they see is whether I live in the city or whether I’m from outside.

    Everytime my data is accessed, the acces is logged. The log contains information about the organisation and, if it applies, the person that made the manual lookup. The legality is checked by logging the legal ground for acces.

    Are they trustworthy? I don’t know. We use our eID for online verification for over 20 years now and ItsMe has certainly made the whole process a breeze.