<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"><title>Sergey Budaev</title><link href="https://budaev.info/" rel="alternate"></link><link href="https://budaev.info/feeds/all.atom.xml" rel="self"></link><id>https://budaev.info/</id><updated>2026-03-15T12:00:00+01:00</updated><entry><title>The machine stops: AI bubble must burst</title><link href="https://budaev.info/the-machine-stops-ai-bubble-must-burst.html" rel="alternate"></link><published>2025-11-25T15:00:00+01:00</published><updated>2025-12-13T12:00:00+01:00</updated><author><name>Sergey Budaev</name></author><id>tag:budaev.info,2025-11-25:/the-machine-stops-ai-bubble-must-burst.html</id><summary type="html">&lt;div id="preamble"&gt;
&lt;div class="sectionbody"&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;As more and more investments are poured into the current AI, there is a feeling in the industry that neural networks, large language models and other AI technologies—as they are construed now—are by far not as effective and useful as the the affectionate visionaries, tech prophets and evangelists …&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</summary><content type="html">&lt;div id="preamble"&gt;
&lt;div class="sectionbody"&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;As more and more investments are poured into the current AI, there is a feeling in the industry that neural networks, large language models and other AI technologies—as they are construed now—are by far not as effective and useful as the the affectionate visionaries, tech prophets and evangelists try to convince us. Even though rather feeble voices of critics have been appearing from the start of the so called “AI revolution” (and even more from the moment of the Sam Altman’s resignation comedy in 2023), it became quite clear that &lt;strong&gt;the expectations from the technology largely surpassed its objective capabilities.&lt;/strong&gt; The current AI and its obsession with greater, grander and more ambitious projects, such as the “General Artificial Intelligence” (promised to approach the human mind) cannot be fulfilled because of numerous causes and inherent limitations. We still know too little about the human cognition and mind. &lt;strong&gt;It is ridiculous how can they think to create an analogue of the human mind without first even trying to understand how did it come about, and without trying to make a functional analogue of a cockroach or a bee mind.&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="ulist"&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;
AI Incident Database: &lt;a href="https://incidentdatabase.ai/"&gt;https://incidentdatabase.ai/&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Bender, E. M., Gebru, T., McMillan-Major, A., and Shmitchell, S. (2021). On the dangers of stochastic parrots: can language models be too big?, in Proceedings of the 2021 ACM Conference on Fairness, Accountability, and Transparency, (Virtual Event Canada: ACM), 610–623. &lt;a href="https://doi.org/10.1145/3442188.3445922"&gt;https://doi.org/10.1145/3442188.3445922&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Bishop, J. M. (2021). Artificial intelligence is stupid and causal reasoning will not fix it. Frontiers in Psychology, 11, 1–18. &lt;a href="https://doi.org/10.3389/fpsyg.2020.513474"&gt;https://doi.org/10.3389/fpsyg.2020.513474&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Floridi, L. (2025). A conjecture on a fundamental trade-off between certainty and scope in symbolic and generative AI. Philos. Technol. 38, 93, s13347-025-00927-z. &lt;a href="https://doi.org/10.1007/s13347-025-00927-z"&gt;https://doi.org/10.1007/s13347-025-00927-z&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Gibney, E. (2024). AI models fed AI-generated data quickly spew nonsense. Nature 632, 18-19. &lt;a href="https://doi.org/10.1038/d41586-024-02420-7"&gt;https://doi.org/10.1038/d41586-024-02420-7&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Gundlach, H., Lynch, J., and Thompson, N. (2025). Meek models shall inherit the Earth. &lt;a href="https://doi.org/10.48550/arXiv.2507.07931"&gt;https://doi.org/10.48550/arXiv.2507.07931&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Jaeger, J. (2024). Artificial intelligence is algorithmic mimicry: Why artificial “agents” are not (and won’t be) proper agents. Neurons, Behavior, Data Analysis, and Theory. &lt;a href="https://doi.org/10.51628/001c.94404"&gt;https://doi.org/10.51628/001c.94404&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Huang, L., Yu, W., Ma, W., Zhong, W., Feng, Z., Wang, H., Chen, Q., Peng, W., Feng, X., Qin, B., &amp;amp; Liu, T. (2024). A survey on hallucination in large language models: principles, taxonomy, challenges, and open questions. ACM Transactions on Information Systems, 3703155. &lt;a href="https://doi.org/10.1145/3703155"&gt;https://doi.org/10.1145/3703155&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Kafka, P. (2025). The godfather of Meta&amp;#8217;s AI thinks the AI boom is a dead end. Business Insider. &lt;a href="https://www.businessinsider.com/meta-ai-yann-lecun-llm-world-model-intelligence-criticism-2025-11?op=1"&gt;https://www.businessinsider.com/meta-ai-yann-lecun-llm-world-model-intelligence-criticism-2025-11?op=1&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Kalai, A. T., Nachum, O., Vempala, S. S., &amp;amp; Zhang, E. (2025). Why language models hallucinate. &lt;a href="https://openai.com/index/why-language-models-hallucinate/"&gt;https://openai.com/index/why-language-models-hallucinate/&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Marcus, G., &amp;amp; Davis, E. (2019). Rebooting AI. Building artificial intelligence we can trust. Pantheon Books.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Mind Prison, We have made no progress toward AGI. (2025). Mind Prison. &lt;a href="https://www.mindprison.cc/p/no-progress-toward-agi-llm-braindead-unreliable"&gt;https://www.mindprison.cc/p/no-progress-toward-agi-llm-braindead-unreliable&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Narayanan, A., and Kapoor, S. (2024). AI snake oil: what artificial intelligence can do, what it can&amp;#8217;t, and how to tell the difference. Princeton Oxford: Princeton University Press.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Pearl, J. (2019). The limitations of opaque learning machines. In John Brockman (Ed.), Possible Minds: 25 Ways of Looking at AI. Penguin Press (&lt;a href="https://ftp.cs.ucla.edu/pub/stat_ser/r489.pdf"&gt;https://ftp.cs.ucla.edu/pub/stat_ser/r489.pdf&lt;/a&gt;).
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Roli, A., Jaeger, J., and Kauffman, S. A. (2022). How organisms come to know the world: Fundamental limits on artificial general intelligence. Front. Ecol. Evol. 9, 806283. &lt;a href="https://doi.org/10.3389/fevo.2021.806283"&gt;https://doi.org/10.3389/fevo.2021.806283&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Schlereth, M. M. (2025). AGI is impossible. here is the proof. &lt;a href="https://philpapers.org/archive/SCHAII-17.pdf"&gt;https://philpapers.org/archive/SCHAII-17.pdf&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Schlereth, M. M. (2025). AGI is mathematically impossible 2: when entropy returns. &lt;a href="https://philarchive.org/archive/SCHAIM-14"&gt;https://philarchive.org/archive/SCHAIM-14&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Schlereth, M. M. (2025). AGI is impossible 3 compression vs. comprehension. &lt;a href="https://philpapers.org/archive/SCHAII-18.pdf"&gt;https://philpapers.org/archive/SCHAII-18.pdf&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Sikka, V., and Sikka, V. (2025). Hallucination stations: On some basic limitations of transformer-based language models. (arXiv:2507.07505)  &lt;a href="https://doi.org/10.48550/arXiv.2507.07505"&gt;https://doi.org/10.48550/arXiv.2507.07505&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Stiefel, K. M., and Coggan, J. S. (2023). The energy challenges of artificial superintelligence. Front. Artif. Intell. 6, 1240653. &lt;a href="https://doi.org/10.3389/frai.2023.1240653"&gt;https://doi.org/10.3389/frai.2023.1240653&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Xu, Z., Jain, S., and Kankanhalli, M. (2024). Hallucination is inevitable: An innate limitation of large language models. &lt;a href="https://doi.org/10.48550/arXiv.2401.11817"&gt;https://doi.org/10.48550/arXiv.2401.11817&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Zhang, M., Press, O., Merrill, W., Liu, A., &amp;amp; Smith, N. A. (2023). How language model hallucinations can snowball (No. arXiv:2305.13534). arXiv. &lt;a href="https://doi.org/10.48550/arXiv.2305.13534"&gt;https://doi.org/10.48550/arXiv.2305.13534&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;But it is clear already that the current data driven, opaque, associative “deep” learning approach based on simple patter matching, interpolating big amount of data in a manner of statistical approximation has failed. Now, LLMs have access to most of the human produced texts and images—to a large extent because of &lt;a href="https://www.transparencycoalition.ai/news/so-meta-pirated-your-books-and-articles-heres-what-you-can-do"&gt;massive&lt;/a&gt; &lt;a href="https://www.tomshardware.com/tech-industry/artificial-intelligence/meta-staff-torrented-nearly-82tb-of-pirated-books-for-ai-training-court-records-reveal-copyright-violations"&gt;copyright&lt;/a&gt; &lt;a href="https://the-decoder.com/openai-could-face-a-billion-dollar-fine-over-claims-it-used-pirated-books-in-ai-training/"&gt;infringement&lt;/a&gt;, unauthorised web scraping, deceptive ToS aimed for data exploitation and similar dubious approaches. The expected amount of new genuinely human generated data &lt;a href="https://www.theverge.com/2024/12/13/24320811/what-ilya-sutskever-sees-openai-model-data-training"&gt;goes to a diminishing return limit&lt;/a&gt;. But in spite of the gigantic amount of learning data and &lt;a href="https://www.theguardian.com/technology/2025/aug/09/open-ai-chat-gpt5-energy-use"&gt;huge energy use costs&lt;/a&gt;, the newest models are only marginally better than those at previous iteration. An ancient rule-based ELIZA language modeli, a &lt;a href="https://www.livescience.com/technology/eliza-the-worlds-1st-chatbot-was-just-resurrected-from-60-year-old-computer-code"&gt;product of computer archeology&lt;/a&gt;, running on the weakest CPU from the 60s outperformed on the Turing test then revolutionary ChatGPT-3 that required huge datacenters to run.&lt;/p&gt;&lt;/div&gt;
&lt;div class="ulist"&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;
Jones, C., &amp;amp; Bergen, B. (2023). Does GPT-4 pass the Turing Test? &lt;a href="http://arxiv.org/abs/2310.20216"&gt;http://arxiv.org/abs/2310.20216&lt;/a&gt;.
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;But the negative effects abound. &lt;strong&gt;The web is poisoned with a growing amount of meaningless and grossly inaccurate digital waste generated by AI.&lt;/strong&gt; Yet, instead of trying to focus on &lt;strong&gt;radical change of the architecture&lt;/strong&gt;, The Big Tech &lt;a href="https://archive.md/kUGMj"&gt;invest even more in data centres&lt;/a&gt;, consuming even more electric power (&lt;a href="https://www.accenture.com/us-en/insights/sustainability/powering-sustainable-ai?c=acn_glb_fy25poweringthemediarelations_14236911&amp;amp;n=mrl_0625"&gt;therefore even greater carbon emission&lt;/a&gt;) and try to be even more intrusive in sucking out and exploiting human-generated content. For example: &amp;#9785; &lt;a href="https://www.malwarebytes.com/blog/news/2025/11/gmail-is-reading-your-emails-and-attachments-to-train-its-ai-unless-you-turn-it-off"&gt;Gmail reads the users emails and attachments to train its “smart” features&lt;/a&gt;.&amp;#9785; &lt;a href="https://www.404media.co/linkedin-is-training-ai-on-user-data-before-updating-its-terms-of-service/"&gt;LinkedIn Is Training AI on User Data Before Updating Its Terms of Service&lt;/a&gt;. &amp;#9785; &lt;a href="https://pod.geraspora.de/posts/17342163"&gt;AI bots scraping the net are as malacious as DDOS attacks&lt;/a&gt;. &amp;#9785; &lt;a href="https://www.theverge.com/news/718319/perplexity-stealth-crawling-cloudflare-ai-bots-report"&gt;Perplexity AI bots continue crawling the content explicitly blocked for access&lt;/a&gt;. &amp;#9785; &lt;a href="https://doubleverify.com/blog/web/verify/ai-crawlers-and-scrapers-are-contributing-to-an-increase-in-general-invalid-traffic"&gt;AI scraper bots are responsible for 86% increase of invalid Internet traffic&lt;/a&gt;. &amp;#9785; &lt;a href="https://www.nature.com/articles/d41586-025-01661-4"&gt;AI bots disrupt scientific scientific databases and journals&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;&lt;strong&gt;The verbiage surrounding the current AI is wrong and deceptive.&lt;/strong&gt; Essentially, the currently popular AI is just seeking correlation patterns in a large amount of data. Therefore it cannot be described meaningfully as "generative" or "agentic." A program implementing a straight line regression model has the same level of "generativity" if it generates &lt;em&gt;Y&lt;/em&gt; from a given &lt;em&gt;X&lt;/em&gt;. A similar program that just gets a &lt;em&gt;X&lt;/em&gt; values from a sensor and executes a program loop converting the &lt;em&gt;Y&lt;/em&gt; into some action has the same level of "agency" as current AL agents, essentially, it does not exceed the level of a trivial thermostat. Yet, the key figures of the AI monopolies, OpenAI, Anthropic and Google, use words like "learning," "thinking," "reasoning" and "logic" to describe pattern matching and generation of statistically probable outputs. This is a deliberately deceptive and misleading strategy. It is a complete misrepresentation of the technology. And it is potentially dangerous. A computer program functioning like a regression model cannot "hallucinate" because it doesn&amp;#8217;t have a mind, it can just malfunction and output wrong result.&lt;/p&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="sect1"&gt;
&lt;h2 id="_the_facts_are_that"&gt;The facts are that&lt;/h2&gt;
&lt;div class="sectionbody"&gt;
&lt;div class="ulist"&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;AI is hugely unprofitable, too expensive and inefficient:&lt;/strong&gt; &amp;#9760; &lt;a href="https://www.planetearthandbeyond.co/p/is-openai-a-ponzi-scheme"&gt;Is OpenAI A Ponzi scheme?&lt;/a&gt;; &amp;#9760; &lt;a href="https://www.planetearthandbeyond.co/p/you-have-no-idea-how-screwed-openai"&gt;You have no idea how screwed OpenAI actually is&lt;/a&gt;; &amp;#9760; &lt;a href="https://archive.md/sM8DD"&gt;Wall Street blows past bubble worries to supercharge AI spending frenzy&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;AI is still unreliable and untrustable:&lt;/strong&gt; Bansal, V. (2025). Meet the AI workers who tell their friends and family to stay away from AI | Artificial intelligence (AI). The Guardian. &lt;a href="https://www.theguardian.com/technology/2025/nov/22/ai-workers-tell-family-stay-away"&gt;https://www.theguardian.com/technology/2025/nov/22/ai-workers-tell-family-stay-away&lt;/a&gt;; &amp;#9760;  &lt;a href="https://cointelegraph.com/news/consumers-increase-distrust-artificial-intelligence-salesforce-survey"&gt;Consumer surveys show a growing distrust of AI and firms that use it&lt;/a&gt;.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;False information generated by AI tools creepis into formerly reputable scientific resources:&lt;/strong&gt; &lt;a href="https://irisvanrooijcogsci.com/2025/08/12/ai-slop-and-the-destruction-of-knowledge/"&gt;van Rooij, I. (2025) AI slop and the destruction of knowledge&lt;/a&gt;.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;AI models produce many false claims even on the sources they provided:&lt;/strong&gt; Venkit, P. N., Laban, P., Zhou, Y., Huang, K.-H., Mao, Y., &amp;amp; Wu, C.-S. (2025). DeepTRACE: Auditing deep research AI systems for tracking reliability across citations and evidence (No. arXiv:2509.04499). arXiv. &lt;a href="https://doi.org/10.48550/arXiv.2509.04499"&gt;https://doi.org/10.48550/arXiv.2509.04499&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;AI chatbots give harmful medical advises:&lt;/strong&gt; Andrikyan, W., Sametinger, S. M., Kosfeld, F., Jung-Poppe, L., Fromm, M. F., Maas, R., &amp;amp; Nicolaus, H. F. (2025). Artificial intelligence-powered chatbots in search engines: A cross-sectional study on the quality and risks of drug information for patients. BMJ Quality &amp;amp; Safety, 34(2), 100?109. &lt;a href="https://doi.org/10.1136/bmjqs-2024-017476"&gt;https://doi.org/10.1136/bmjqs-2024-017476&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;AI "agents" fail at an alarming rate:&lt;/strong&gt; Xu, F. F., Song, Y., Li, B., Tang, Y., Jain, K., Bao, M., Wang, Z. Z., Zhou, X., Guo, Z., Cao, M., Yang, M., Lu, H. Y., Martin, A., Su, Z., Maben, L., Mehta, R., Chi, W., Jang, L., Xie, Y., ? Neubig, G. (2025). TheAgentCompany: Benchmarking LLM agents on consequential real world tasks (No. arXiv:2412.14161). arXiv. &lt;a href="https://doi.org/10.48550/arXiv.2412.14161"&gt;https://doi.org/10.48550/arXiv.2412.14161&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;Even the best AI agents achieve no more than 2.5% automation rate:&lt;/strong&gt; Mazeika, M., Gatti, A., Menghini, C., Sehwag, U. M., Singhal, S., Orlovskiy, Y., et al. (2025). Remote Labor Index: Measuring AI automation of remote work. &lt;a href="https://arxiv.org/abs/2510.26787"&gt;https://arxiv.org/abs/2510.26787&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;AI tools can generally reduce company’s productivity:&lt;/strong&gt; Niederhoffer, K., Rosen Kellerman, G., Lee, A., Liebscher, A., Rapuano, K., &amp;amp; Hancock, J. T. (2025). AI-Generated “workslop” is destroying productivity. &lt;a href="https://hbr.org/2025/09/ai-generated-workslop-is-destroying-productivity"&gt;https://hbr.org/2025/09/ai-generated-workslop-is-destroying-productivity&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;Despite skyrocketing investments in generative AI, 95% of companies get &lt;em&gt;zero&lt;/em&gt; return:&lt;/strong&gt; Challapally, A., Pease, C., Raskar, R., &amp;amp; Chari, P. (2025). The GenAI Divide: State of AI in Business 2025. MIT NANDA. &lt;a href="https://mlq.ai/media/quarterly_decks/v0.1_State_of_AI_in_Business_2025_Report.pdf"&gt;https://mlq.ai/media/quarterly_decks/v0.1_State_of_AI_in_Business_2025_Report.pdf&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;AI is harmful for the environment:&lt;/strong&gt; &lt;a href="https://www.unep.org/news-and-stories/story/ai-has-environmental-problem-heres-what-world-can-do-about"&gt;https://www.unep.org/news-and-stories/story/ai-has-environmental-problem-heres-what-world-can-do-about&lt;/a&gt;; &lt;a href="https://news.mit.edu/2025/explained-generative-ai-environmental-impact-0117"&gt;https://news.mit.edu/2025/explained-generative-ai-environmental-impact-0117&lt;/a&gt;; &lt;a href="https://theconversation.com/ai-is-bad-for-the-environment-and-the-problem-is-bigger-than-energy-consumption-247842"&gt;https://theconversation.com/ai-is-bad-for-the-environment-and-the-problem-is-bigger-than-energy-consumption-247842&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;AI tools reduce developer productivity:&lt;/strong&gt; Becker, J., Rush, N., Barnes, E., &amp;amp; Rein, D. (2025). Measuring the impact of early-2025 AI on experienced open-source developer productivity. &lt;a href="https://metr.org/blog/2025-07-10-early-2025-ai-experienced-os-dev-study/"&gt;https://metr.org/blog/2025-07-10-early-2025-ai-experienced-os-dev-study/&lt;/a&gt;; Uplevel Data Labs. (2024). Can Generative AI Improve Developer Productivity. &lt;a href="https://resources.uplevelteam.com/gen-ai-for-coding"&gt;https://resources.uplevelteam.com/gen-ai-for-coding&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;Using AI leads to increased amount of unneeded code, reduced code quality and tends to introduce severe bugs:&lt;/strong&gt; Harding, W., &amp;amp; Kloster, M. (2024). Coding on Copilot 2023 data shows downward pressure on code quality. &lt;a href="https://www.gitclear.com/coding_on_copilot_data_shows_ais_downward_pressure_on_code_quality"&gt;https://www.gitclear.com/coding_on_copilot_data_shows_ais_downward_pressure_on_code_quality&lt;/a&gt;; CodeRabbit. (2025). State of AI vs human code generation. &lt;a href="http://www.coderabbit.ai/whitepapers/state-of-AI-vs-human-code-generation-report"&gt;http://www.coderabbit.ai/whitepapers/state-of-AI-vs-human-code-generation-report&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;Using AI tools adds more security vulnerabilities:&lt;/strong&gt; Veracode. (2025). 2025 GenAI code security report. &lt;a href="https://www.veracode.com/wp-content/uploads/2025_GenAI_Code_Security_Report_Final.pdf"&gt;https://www.veracode.com/wp-content/uploads/2025_GenAI_Code_Security_Report_Final.pdf&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;Autonomous AI software development almost always fails:&lt;/strong&gt; Husain, H., Flath, I., and Johno, W. (2025). Thoughts on a month with Devin. Answer.AI. Available at: &lt;a href="https://www.answer.ai/posts/2025-01-08-devin.html"&gt;https://www.answer.ai/posts/2025-01-08-devin.html&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;AI-based browser is a security disaster:&lt;/strong&gt; &lt;a href="https://venturebeat.com/ai/when-your-ai-browser-becomes-your-enemy-the-comet-security-disaster"&gt;https://venturebeat.com/ai/when-your-ai-browser-becomes-your-enemy-the-comet-security-disaster&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;Using AI-driven "vibe coding" can result in a catastrophic disaster:&lt;/strong&gt; &lt;a href="https://fortune.com/2025/07/23/ai-coding-tool-replit-wiped-database-called-it-a-catastrophic-failure/"&gt;https://fortune.com/2025/07/23/ai-coding-tool-replit-wiped-database-called-it-a-catastrophic-failure/&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;AI tools can be destructive for learning:&lt;/strong&gt; Bastani, H., Bastani, O., Sungu, A., Ge, H., Kabakcı, Ö., &amp;amp; Mariman, R. (2024). Generative AI can harm learning. SSRN. &lt;a href="https://doi.org/10.2139/ssrn.4895486"&gt;https://doi.org/10.2139/ssrn.4895486&lt;/a&gt;; Kosmyna, N., Hauptmann, E., Yuan, Y. T., Situ, J., Liao, X.-H., Beresnitzky, A. V., Braunstein, I., &amp;amp; Maes, P. (2025). Your Brain on ChatGPT: Accumulation of cognitive debt when using an AI assistant for essay writing task. arXiv. &lt;a href="https://doi.org/10.48550/ARXIV.2506.08872"&gt;https://doi.org/10.48550/ARXIV.2506.08872&lt;/a&gt;; Lee, H.-P., Sarkar, A., Tankelevitch, L., Drosos, I., Rintel, S., Banks, R., &amp;amp; Wilson, N. (2025). The impact of generative AI on critical thinking: self-reported reductions in cognitive effort and confidence effects from a survey of knowledge workers. &lt;a href="https://doi.org/10.1145/3706598.3713778"&gt;https://doi.org/10.1145/3706598.3713778&lt;/a&gt;; Elsayed, Y., &amp;amp; Verheyen, S. (2024). ChatGPT and the illusion of explanatory depth. Proceedings of the Annual Meeting of the Cognitive Science Society, 46; Abbas, M., Jam, F. A., and Khan, T. I. (2024). Is it harmful or helpful? Examining the causes and consequences of generative AI usage among university students. Int J Educ Technol High Educ 21, 10. &lt;a href="https://educationaltechnologyjournal.springeropen.com/articles/10.1186/s41239-024-00444-7"&gt;https://educationaltechnologyjournal.springeropen.com/articles/10.1186/s41239-024-00444-7&lt;/a&gt;; Azeem, S., and Abbas, M. (2025). Personality correlates of academic use of generative artificial intelligence and its outcomes: does fairness matter? Educ Inf Technol 30, 18131?18155. &lt;a href="https://link.springer.com/10.1007/s10639-025-13489-6"&gt;https://link.springer.com/10.1007/s10639-025-13489-6&lt;/a&gt;.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;Generative AI can cause "Generative AI addiction syndrome":&lt;/strong&gt; Kooli, C., Kooli, Y., and Kooli, E. (2025). Generative artificial intelligence addiction syndrome: A new behavioral disorder? Asian Journal of Psychiatry 107, 104476. &lt;a href="https://doi.org/10.1016/j.ajp.2025.104476"&gt;https://doi.org/10.1016/j.ajp.2025.104476&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;AI tools contribute to massive amount of fake news and misinformation:&lt;/strong&gt; NewsGuard. (2025). Tracking AI-enabled Misinformation: Over 2000 Undisclosed AI-Generated News Websites (and Counting), Plus the Top False Narratives Generated by Artificial Intelligence Tools—NewsGuard. NewsGuard. &lt;a href="https://www.newsguardtech.com/special-reports/ai-tracking-center/"&gt;https://www.newsguardtech.com/special-reports/ai-tracking-center/&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;AI tools supercharge scammers providing a cheap scam generator:&lt;/strong&gt; &lt;a href="https://www.ftc.gov/news-events/news/press-releases/2024/09/ftc-announces-crackdown-deceptive-ai-claims-schemes"&gt;FTC Announces Crackdown on Deceptive AI Claims and Schemes&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;AI tools involve large amount of invisible human labour:&lt;/strong&gt; &amp;#9760; &lt;a href="https://www.washingtonpost.com/world/2023/08/28/scale-ai-remotasks-philippines-artificial-intelligence/"&gt;There are "digital sweatshops" in the Philippines or other poor countries where people work out of sight and behind the scenes to identify, sort and refine content for AI companies like OpenAI, Meta and Microsoft.&lt;/a&gt; &amp;#9760; &lt;a href="https://www.technologyreview.com/2022/04/20/1050392/ai-industry-appen-scale-data-labels/"&gt;How the AI industry profits from catastrophe in Venezuela.&lt;/a&gt;; &amp;#9760; &lt;a href="https://time.com/6247678/openai-chatgpt-kenya-workers/"&gt;Exclusive: OpenAI Used Kenyan Workers on Less Than $2 Per Hour to Make ChatGPT Less Toxic&lt;/a&gt;; &amp;#9760; &lt;a href="https://archive.ph/NGSUN"&gt;Inside Facebook&amp;#8217;s African Sweatshop.&lt;/a&gt; &amp;#9760; &lt;a href="https://www.justice.gov/usao-sdny/pr/tech-ceo-charged-artificial-intelligence-investment-fraud-scheme"&gt;An "AI-powered" service Nate helping customers make purchases turned out to be a fraud scheme with all the work done by people from Philippines call centres.&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="sect1"&gt;
&lt;h2 id="_the_machine_stops"&gt;The machine stops&lt;/h2&gt;
&lt;div class="sectionbody"&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;&lt;strong&gt;Where are all these really big multi-billion money going to go? Chances are high that all the money that are currently inflating the AI bubble will be lost. The pain from the expected AI bubble crash is likely to be much greater than from the two and half decades ago dot-com crash. Few people remember, but it took a decade to recover the value of the assets lost at that time. Yet, the number of US households that invest exceeded 20%, surpassing the numbers before the dot-com crash. All these people should be prepared to lose their cash or withdraw before the burst.&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="ulist"&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;
Vogelstein, F. (2025). We remember the internet bubble. This mania looks and feels the same. &lt;a href="https://crazystupidtech.com/2025/11/21/boom-bubble-bust-boom-why-should-ai-be-different/"&gt;https://crazystupidtech.com/2025/11/21/boom-bubble-bust-boom-why-should-ai-be-different/&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Dooley, L. (2025). Reflexivity and the AI boom: A Sorosian analysis. Vincents. &lt;a href="https://vincents.com.au/reflexivity-and-the-ai-boom-a-sorosian-analysis"&gt;https://vincents.com.au/reflexivity-and-the-ai-boom-a-sorosian-analysis&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Goldman Sachs. (2025). AI: In a bubble? Goldman Sachs Top of Mind, 143. &lt;a href="https://www.goldmansachs.com/insights/top-of-mind/ai-in-a-bubble"&gt;https://www.goldmansachs.com/insights/top-of-mind/ai-in-a-bubble&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Goldman Sachs. (2024). Gen AI: too much spend, too little benefit? Goldman Sachs Top of Mind, 129. &lt;a href="https://www.goldmansachs.com/intelligence/pages/gen-ai-too-much-spend-too-little-benefit.html"&gt;https://www.goldmansachs.com/intelligence/pages/gen-ai-too-much-spend-too-little-benefit.html&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Example: Despite multibillion investments into AI, Microsoft &lt;a href="https://www.theinformation.com/articles/microsoft-lowers-ai-software-sales-quotas-customers-resist-newer-products"&gt;struggles to sell Copilot&lt;/a&gt; and return the investments, but the only strategy is &lt;a href="https://www.theinformation.com/articles/microsofts-nadella-pressures-deputies-accelerate-copilot-improvements"&gt;desperately repeat doing the same thing hoping for a completely different result&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;It does not sound likely that the current AI will take over the planet and destroy human race etc. All the scary prophecies assume that it is a real and genuinely intelligent AGI, which is false. The false prophecies willingly or unwillingly play the role of the Alcibiades' dog tail, diverting attention from real dangers of AI to unrealistic imaginary, but appearing much scarier, dangers. The current AI is harmful  for human learning, cognition, environment and investors' pockets. &lt;strong&gt;The dangers of AI are not caused by AI itself.&lt;/strong&gt; They are, as most other calamities, are consequences of human actions. AI does not seem to add anything over the human sins. &lt;strong&gt;It just multiplies human-generated evils to higher speed, scale and scope.&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="ulist"&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;
Is the current AI a massive fraud scheme aimed to cover failed expectations like the disgraced Theranos?
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;All the prophecies about the imminent arrival of AGI are not based on a scientific prediction. It is rather the marketing bullshit, a strategic smokescreen, aimed to attract naive, uninformed and FOMO-nervous  investors. The current "AGI" development has already hit a ceiling. The consequences for the world&amp;#8217;s economy will be quite serious. &lt;strong&gt;While the AI is provided for free or nearly free (for a small fraction of real price), the users are happy to play around with even inferior quality service. But what will happen when the bubble has blown and they are forced to pay the real price for buggy, indeterministic, glitchy and defective product?&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;&lt;strong&gt;The machine slops. Then the machine stops.&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
</content><category term="AI"></category><category term="LLM"></category><category term="Blog"></category></entry><entry><title>Norwegian researchers develop digital twin model to optimize fish feeding</title><link href="https://budaev.info/norwegian-researchers-develop-digital-twin-model-to-optimize-fish-feeding.html" rel="alternate"></link><published>2025-08-16T10:00:00+02:00</published><updated>2025-08-16T10:00:00+02:00</updated><author><name>Andrea Magugliani</name></author><id>tag:budaev.info,2025-08-16:/norwegian-researchers-develop-digital-twin-model-to-optimize-fish-feeding.html</id><summary type="html">&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.aquafeed.com/newsroom/news/norwegian-researchers-develop-digital-twin-model-to-optimize-fish-feeding/"&gt;Norwegian researchers develop digital twin model to optimize fish feeding.&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Ivar Rønnestad and Sergei Budaev developed a proof-of-concept using digital
twin models to explore smarter, more sustainable fish feeding strategies.&lt;/p&gt;
&lt;p&gt;Led by University of Bergen (UiB) professor Ivar Rønnestad and researcher
Sergei Budaev from the Department of Biological Sciences, FishMet …&lt;/p&gt;</summary><content type="html">&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.aquafeed.com/newsroom/news/norwegian-researchers-develop-digital-twin-model-to-optimize-fish-feeding/"&gt;Norwegian researchers develop digital twin model to optimize fish feeding.&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Ivar Rønnestad and Sergei Budaev developed a proof-of-concept using digital
twin models to explore smarter, more sustainable fish feeding strategies.&lt;/p&gt;
&lt;p&gt;Led by University of Bergen (UiB) professor Ivar Rønnestad and researcher
Sergei Budaev from the Department of Biological Sciences, FishMet is an
early-stage proof-of-concept venture that is exploring how years of marine
physiology and behavioral research can be translated into tools for the
aquaculture sector.&lt;/p&gt;
&lt;p&gt;FishMet originated from a collaboration between UiB researchers and Vestlandets
Innovasjonsselskap (VIS). The initiative centers on a digital twin model for
precision aquaculture feeding strategies, aiming to help salmon and trout
farming operations optimize feeding, reducing waste and improving fish welfare.
Although still at a low Technology Readiness Level (TRL 5), the concept has
been made available for exploratory licensing opportunities through VIS.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.aquafeed.com/newsroom/news/norwegian-researchers-develop-digital-twin-model-to-optimize-fish-feeding/"&gt;Read more: aquafeed.com&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;See paper: Budaev, S., Cusimano, G., Rønnestad, I., (2025) FishMet: A Digital
Twin framework for appetite, feeding decisions and growth in salmonid fish.
Aquaculture, Fish and Fisheries, 5, e70064.
&lt;a href="https://doi.org/10.1002/aff2.70064"&gt;https://doi.org/10.1002/aff2.70064&lt;/a&gt;&lt;/p&gt;</content><category term="News"></category><category term="interview"></category></entry><entry><title>Microsoft Word for scientific texts? No, thanks.</title><link href="https://budaev.info/microsoft-word-for-scientific-texts-no-thanks.html" rel="alternate"></link><published>2025-04-03T23:00:00+02:00</published><updated>2025-04-03T23:00:00+02:00</updated><author><name>Sergey Budaev</name></author><id>tag:budaev.info,2025-04-03:/microsoft-word-for-scientific-texts-no-thanks.html</id><summary type="html">&lt;p&gt;Microsoft Word still has no support for regular expressions and  very poor LaTeX. In 2025.&lt;/p&gt;</summary><content type="html">&lt;p&gt;I am often using &lt;a href="https://www.libreoffice.org/"&gt;LibreOffice&lt;/a&gt;, which is far from
ideal text editor. But it allows to work with genuine LaTeX equations, thanks
to the &lt;a href="https://extensions.libreoffice.org/en/extensions/show/texmaths-1/"&gt;TexMaths extension&lt;/a&gt;. &lt;/p&gt;
&lt;p&gt;It allows to add and edit equations in the LaTeX format fairly easily. All the
beautiful TeX typographic is retained. And the document can be shared
with those who use Microsoft Word, frankly, the majority. Then, the equations
appear as embedded graphics in the Word file. Not bad, because not everyone is
ready to accept pure LaTeX files and work with them.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;However, most of those using LaTeX will sooner or later face the challenge of
developing a document in Word, because of the requirements of a project leader
or funding organization, or just because there is no chance that some of the
team members will use LaTeX in their collaborative writing effort. [1] &lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;&lt;strong&gt;When this situation occurs, it is time to use &lt;em&gt;LibreOffice&lt;/em&gt; with &lt;em&gt;TexMaths&lt;/em&gt;
and share the docx format document.&lt;/strong&gt; (Another alternative not considered here
is to use and share the &lt;a href="https://www.overleaf.com"&gt;Overleaf&lt;/a&gt; web-based LaTeX
editor with nice visual mode and open source &lt;a href="https://github.com/overleaf/overleaf"&gt;community
edition&lt;/a&gt;.)&lt;/p&gt;
&lt;p&gt;&lt;img alt="TexMaths" src="images/msword-001.gif" title="TexMaths"&gt;&lt;/p&gt;
&lt;p&gt;Weirdly enough, not all journals and publishers accept LaTeX files. Then,
Word with TexMaths-generated equations as graphics work well during the peer
review. &lt;/p&gt;
&lt;p&gt;Once the manuscript is accepted, the production needs the final text with
all equations in some editable format: if it is Microsoft Equation (in Word)
or genuine LaTeX. But sometimes they do not accept LaTeX and ask for Word.&lt;/p&gt;
&lt;p&gt;Microsoft Word now declares support for LaTeX equations. So converting
equations from raw LaTeX code to the weird Microsoft format should be as easy
as select and click. If there are many equations in the text, one needs to make
sure nothing is missed. This can be trivially done by delimiting the LaTeX code
into some symbols. Two dollar signs &lt;code&gt;$$&lt;/code&gt; look convenient because it is used by
some software to delimit embedded LaTeX code and very unlikely to conflict with
other text. &lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;$$ MAPE=1/n  \sum ( \left\lvert  O_i-P_i  \right\rvert / \left\lvert O_i \right\rvert ) $$
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Further, to make the LaTeX pieces to stand out, it is convenient to use
highlighting or colour. In LibreOffice and all decent text editors, this is
trivial to do using &lt;a href="https://en.wikipedia.org/wiki/Regular_expression"&gt;regular
expressions&lt;/a&gt;. Just find and
select the text pattern, then change formatting. (In LibreOffice this can be
done in a single step with &lt;strong&gt;"Find All"&lt;/strong&gt;.)&lt;/p&gt;
&lt;p&gt;The pattern to select is simple. To find any text within &lt;code&gt;$$&lt;/code&gt; but not including
any &lt;code&gt;$&lt;/code&gt; symbol within, one can use this: &lt;code&gt;\$\$ .[^\$]* \$\$&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;&lt;img alt="Select regular expressions" src="images/msword-002.gif" title="Select regular expressions"&gt;&lt;/p&gt;
&lt;p&gt;Regular expressions is a super powerful tool to work with text.  See
&lt;a href="https://help.libreoffice.org/latest/en-US/text/shared/01/02100001.html"&gt;LibreOffice
documentation&lt;/a&gt;
for details. &lt;/p&gt;
&lt;p&gt;Converting LaTeX code back into nice rendered equations is super easy in
LibreOffice: just find select regular expression text &lt;code&gt;\$\$ .[^\$]* \$\$&lt;/code&gt; 
and click for converting to equation (the 'pi' button):&lt;/p&gt;
&lt;p&gt;&lt;img alt="Select and render" src="images/msword-003.gif" title="Select and render"&gt;&lt;/p&gt;
&lt;p&gt;(Although, unfortunately, converting equations must be done individually for 
each).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;But this does not work in Microsoft Word, the "most advanced text processor."
Nope.&lt;/strong&gt; &lt;/p&gt;
&lt;p&gt;Regular expressions cannot be searched in the Find menu. And this is despite
Microsoft VBScript library supports regular expressions from years ago (it was
part of Internet Explorer 5.5). Yes, there is an "Advanced Find", with &lt;a href="https://support.microsoft.com/en-us/office/examples-of-wildcard-characters-939e153f-bd30-47e4-a763-61897c87b3f4"&gt;"use
wildcards"&lt;/a&gt; 
option. But this is not even close to &lt;em&gt;regular expressions&lt;/em&gt; (too
advanced for a typical Word user?).&lt;/p&gt;
&lt;p&gt;Then, it is not easy to do without first highlighting all &lt;code&gt;$$&lt;/code&gt; delimited test
in LibreOffice first. Fortunately, visually locating bright yellow highlights
is easy even in the Microsoft product.&lt;/p&gt;
&lt;p&gt;Now, it is the order to click for LaTeX!&lt;/p&gt;
&lt;p&gt;&lt;img alt="Word, no LaTeX" src="images/msword-004.gif" title="Word, no LaTeX"&gt;&lt;/p&gt;
&lt;p&gt;Oh, no. Microsoft Word does support only the most trivial LaTeX code. If you
need a matrix, then no, it does not work: "This expression is currently unsupported".&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;And the genuine TeX typographics is much better in LibreOfice:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt="LaTex in Libreoffice" src="images/msword-006.png" title="LaTex in Libreoffice"&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;... than in Microsoft Word:&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt="LaTex in Word" src="images/msword-005.png" title="LaTex in Word"&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;What? Microsoft Office from multi-billion dollar company does not support
regular expressions in 2025? And no LaTeX?&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;(Note that regular expressions for matching text patterns first appeared in
computer-based text editors in ... the &lt;em&gt;sixties!&lt;/em&gt;)&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Microsoft Word for scientific texts? No, thanks.&lt;/strong&gt;&lt;/p&gt;
&lt;h2&gt;References&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;Mamishev, A., Sargent, M., 2013. Creating research and scientific documents
   using Microsoft Word. Microsoft Press, Redmond.&lt;/li&gt;
&lt;/ol&gt;</content><category term="Blog"></category><category term="Microsoft"></category></entry><entry><title>FishMet: Digital twin for precision aquaculture</title><link href="https://budaev.info/fishmet-digital-twin-for-precision-aquaculture.html" rel="alternate"></link><published>2025-03-14T10:00:00+01:00</published><updated>2025-03-14T10:00:00+01:00</updated><author><name>visinnovasjon.no</name></author><id>tag:budaev.info,2025-03-14:/fishmet-digital-twin-for-precision-aquaculture.html</id><summary type="html">&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.visinnovasjon.no/lisensmuligheter/fishmet-digital-twin-for-precision-aquaculture"&gt;FishMet: Digital twin for precision aquacultur.&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Software model for optimized feeding and waste reduction for salmon and trout farming.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Background&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The aquaculture industry, especially salmonid fish farming, is a significant
contributor to global food security and economic development. As the pressure
mounts to boost production while minimizing environmental impact, innovative …&lt;/p&gt;</summary><content type="html">&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.visinnovasjon.no/lisensmuligheter/fishmet-digital-twin-for-precision-aquaculture"&gt;FishMet: Digital twin for precision aquacultur.&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Software model for optimized feeding and waste reduction for salmon and trout farming.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Background&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The aquaculture industry, especially salmonid fish farming, is a significant
contributor to global food security and economic development. As the pressure
mounts to boost production while minimizing environmental impact, innovative
solutions are critical.&lt;/p&gt;
&lt;p&gt;Traditional feed management systems often fail to capture the complexity of
fish feeding behavior and environmental variables. FishMet is an advanced
digital twin platform that integrates biological and environmental data to
predict fish appetite, feed intake, and growth. Unlike conventional feeding
models or AI-driven systems, FishMet leverages biology-driven algorithms to
deliver transparent, accurate, and fully explainable predictions. This
innovation is the result of over a decade of research into fish physiology,
metabolism, and growth regulation.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.visinnovasjon.no/lisensmuligheter/fishmet-digital-twin-for-precision-aquaculture"&gt;Read more at www.visinnovasjon.no&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;See paper: Budaev, S., Cusimano, G., Rønnestad, I., (2025) FishMet: A Digital
Twin framework for appetite, feeding decisions and growth in salmonid fish.
Aquaculture, Fish and Fisheries, 5, e70064.
&lt;a href="https://doi.org/10.1002/aff2.70064"&gt;https://doi.org/10.1002/aff2.70064&lt;/a&gt;&lt;/p&gt;</content><category term="News"></category></entry><entry><title>Fish &amp; chips? Modellen som kan hjelpe oppdrettere med å optimalisere fôrstrategier</title><link href="https://budaev.info/fish-chips-modellen-som-kan-hjelpe-oppdrettere-med-a-optimalisere-forstrategier.html" rel="alternate"></link><published>2024-12-11T10:00:00+01:00</published><updated>2024-12-11T10:00:00+01:00</updated><author><name>visinnovasjon.no</name></author><id>tag:budaev.info,2024-12-11:/fish-chips-modellen-som-kan-hjelpe-oppdrettere-med-a-optimalisere-forstrategier.html</id><summary type="html">&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.visinnovasjon.no/prosjekter/fish-amp-chips-modellen-som-kan-hjelpe-oppdrettere-med-optimalisere-frstrategiernbsp"&gt;Å kombinere biologisk forskning og matematisk modellering har åpnet døren for
en ny tilnærming til fiskeoppdrett.&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Vi møter professor i fysiologi, Ivar Rønnestad og forsker, Sergey Budaev på
Høyteknologisenteret i Bergen. Begge jobber ved Institutt for Biovitenskap ved
Universitetet i Bergen og står bak prosjektet FishMet. Som en del av …&lt;/p&gt;</summary><content type="html">&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.visinnovasjon.no/prosjekter/fish-amp-chips-modellen-som-kan-hjelpe-oppdrettere-med-optimalisere-frstrategiernbsp"&gt;Å kombinere biologisk forskning og matematisk modellering har åpnet døren for
en ny tilnærming til fiskeoppdrett.&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Vi møter professor i fysiologi, Ivar Rønnestad og forsker, Sergey Budaev på
Høyteknologisenteret i Bergen. Begge jobber ved Institutt for Biovitenskap ved
Universitetet i Bergen og står bak prosjektet FishMet. Som en del av dette
prosjektet er det utviklet en simuleringsmodell med samme navn, som er
resultatet av mange år med forskning i Rønnestads forskningsgruppe.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.visinnovasjon.no/prosjekter/fish-amp-chips-modellen-som-kan-hjelpe-oppdrettere-med-optimalisere-frstrategiernbsp"&gt;Les mer: www.visinnovasjon.no&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;See paper: Budaev, S., Cusimano, G., Rønnestad, I., (2025) FishMet: A Digital
Twin framework for appetite, feeding decisions and growth in salmonid fish.
Aquaculture, Fish and Fisheries, 5, e70064.
&lt;a href="https://doi.org/10.1002/aff2.70064"&gt;https://doi.org/10.1002/aff2.70064&lt;/a&gt;&lt;/p&gt;</content><category term="News"></category><category term="interview"></category></entry><entry><title>The omnipotence paradox reduces to the omniidiota dilemma</title><link href="https://budaev.info/the-omnipotence-paradox-reduces-to-the-omniidiota-dilemma.html" rel="alternate"></link><published>2024-11-07T18:00:00+01:00</published><updated>2024-11-07T18:00:00+01:00</updated><author><name>Sergey Budaev</name></author><id>tag:budaev.info,2024-11-07:/the-omnipotence-paradox-reduces-to-the-omniidiota-dilemma.html</id><summary type="html">&lt;div id="preamble"&gt;
&lt;div class="sectionbody"&gt;
&lt;div class="verseblock"&gt;
&lt;pre class="content"&gt;&lt;em&gt;&amp;#8230;sed evanuerunt in cogitationibus suis et obscuratum est insipiens
cor eorum dicentes enim se esse sapientes stulti facti sunt.&lt;/em&gt;&lt;/pre&gt;
&lt;div class="attribution"&gt;
&amp;#8212; Rom 21-22
&lt;/div&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;There is an old—perhaps ancient—“puzzle” or “paradox” that is quite often used
by atheists—even today—to prove that the concept of omnipotence is
self-contradictory; ergo the …&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</summary><content type="html">&lt;div id="preamble"&gt;
&lt;div class="sectionbody"&gt;
&lt;div class="verseblock"&gt;
&lt;pre class="content"&gt;&lt;em&gt;&amp;#8230;sed evanuerunt in cogitationibus suis et obscuratum est insipiens
cor eorum dicentes enim se esse sapientes stulti facti sunt.&lt;/em&gt;&lt;/pre&gt;
&lt;div class="attribution"&gt;
&amp;#8212; Rom 21-22
&lt;/div&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;There is an old—perhaps ancient—“puzzle” or “paradox” that is quite often used
by atheists—even today—to prove that the concept of omnipotence is
self-contradictory; ergo the existence of omnipotent being is logically
impossible. One of the cornerstones of this reasoning is the paradox of the
stone.&lt;/p&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;&lt;span class="image"&gt;
&lt;img src="https://budaev.info/images/rock.jpg" alt="https://budaev.info/images/rock.jpg" height="300" /&gt;
&lt;/span&gt;&lt;/p&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="sect1"&gt;
&lt;h2 id="_the_paradox_of_the_stone"&gt;The paradox of the stone&lt;/h2&gt;
&lt;div class="sectionbody"&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;&lt;strong&gt;Can God create a stone so heavy that He cannot lift it?&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="ulist"&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;If He can, then He is not omnipotent&lt;/strong&gt; because of inability to lift
  such a stone.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;If He cannot create such a stone, then He is not omnipotent&lt;/strong&gt; because
  of inability to create such a huge object
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;&lt;strong&gt;In either case, the conclusion is straightforward: an omnipotent being (God)
cannot exist, it is a logically contradictory concept.&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;St Thomas Aquinas did not address the paradox of the stone directly. His
treatment of the omnipotence (&lt;em&gt;Summa Theologiae&lt;/em&gt; I Q XXV) is much more
abstract, detailed and deeper than the stone paradox caricature. Nonetheless,
St Thomas concedes that &lt;em&gt;“Sed rationem omnipotentiae assignare videtur
difficile.”&lt;/em&gt; (It is difficult to account omnipotence). Moreover, St Thomas
considers whether negation capacities like “deny Himself” are consistent with
omnipotence, e.g.  (2) &lt;em&gt;"&amp;#8230; Sed Deus non potest peccare, neque seipsum negare,
ut dicitur II Tim.  2,13. Ergo Deus non est omnipotens.”&lt;/em&gt; (&amp;#8230; But God cannot
sin, nor deny Himself as it is said in 2 Tim. 2:13. Therefore He is not
omnipotent), and further, in (5) &lt;em&gt;“Utrum Deus possit facere quae non facit”&lt;/em&gt;
(Can God do what He does not?).&lt;/p&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;Moreover, further, he clearly states &lt;em&gt;“Hoc enim omnipotentiae non subditur, non
propter defectum divinae potentiae; sed quia non potest habere rationem
factibilis neque possibilis. Quaecumque igitur contradictionem non implicant,
sub illis possibilibus continentur, respectu quorum dicitur Deus omnipotens. Ea
vero quae contradictionem implicant sub divina omnipotentia non continentur:
quia non possunt habere possibilium rationem. &lt;strong&gt;Unde convenientius dicitur quod
non possunt fieri, quam quod Deus non potest ea facere&lt;/strong&gt; &amp;#8230;”&lt;/em&gt; (For this is not
submitted to omnipotence, not because of a lack of divine power; but because it
cannot have a reason that is feasible or possible. All things, therefore, which
do not imply a contradiction, are contained under those things which are
possible, in respect of which God is said to be omnipotent. But those things
which imply a contradiction are not contained under the divine omnipotence:
because they cannot have the reason of the possible. &lt;strong&gt;Hence it is more
appropriate to say that they cannot be done, than that God cannot do them.&lt;/strong&gt;)
Incidentally, there is a close similarity between this omnipotence attribute
following St. Thomas and the concept of positive qualities—purely positive
qualities that are not limited or negated—used by Kurt Gödel as the principal
element in hist modal version of the “ontologisk bevis”  (see Gödel, 1995, pp.
389, 401, 403).&lt;/p&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;The paradox of the stone stone has been considered by many modern philosophers,
including Mavrodes (1963), Frankfurt (1964), Cowan (1965,1974), Plantinga
(1967), Schrader (1979), Anderson (1984) and more recently Cogburn (2004), Hill
(2014), Beall &amp;amp; Cotnoir (2017), Wreen (2022), Bassford (2023). The treatment of
the paradox by these authors seems overtly inkhorn, over-complicated, confusing
and deliberately verbose. The Wikipedia (2024) description of the “omnipotence
paradox” follows the confusing line of the modern philosophy.
It looks like the philosopher’ job is to make trivial things fully
unintelligible. Basically, if one dares to make a winding way through the
thicket of quantum entangled reasoning, the principal argument nearly repeats
that in the St. Thomas’ wording: omnipotence does not entail arbitrary,
logically impossible and contradictory things: inability to do a
self-contradictory task does not imply that the agent is limited.  [An
alternative is the Cartesian view that God is above and not subject to logic,
so free from any contradiction, (see Bassford, 2023), but this position is
incoherent (Geach, 1973)].&lt;/p&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;Some go much further by arguing that there must be truth-value gaps not
accounted for by classical logic (Beall &amp;amp; Cotnoir, 2017), that the omnipotence
concept is useless in theology (Cowan, 1974), that the solution to the stone
paradox is that “it proves nothing” (Schrader, 1979) or that God is not
omnipotent even if we do not deny His perfections and power (Hill, 2014).&lt;/p&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;However, the simplest and best solution to the stone paradox in my view was
provided by (Savage, 1967): &lt;strong&gt;“God can create stones of any poundage, and God
can lift stones of any poundage”&lt;/strong&gt; (p. 79). Strangely, this transparent phrase
does not look like the conclusions most philosophers like to come to.&lt;/p&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;However, the paradox of the stone can be reduced to a trivial form which I call
“the omniidiota dilemma,” with an instructive corollary. The argument is as
follows.&lt;/p&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="sect1"&gt;
&lt;h2 id="_the_omniidiota_dilemma"&gt;The omniidiota dilemma&lt;/h2&gt;
&lt;div class="sectionbody"&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;&lt;strong&gt;Definition.&lt;/strong&gt; &lt;strong&gt;&lt;em&gt;Idiot&lt;/em&gt;&lt;/strong&gt; is defined as someone suffering from (in certain cases,
perhaps enjoying) extreme intellectual disability, primarily an utmost form of
&lt;em&gt;acalculia&lt;/em&gt;.&lt;/p&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;&lt;strong&gt;Comments.&lt;/strong&gt; &lt;em&gt;Dyscalculia&lt;/em&gt; describes a deficit in processing numerical
information, learning and recalling arithmetic, as well as making calculations
(American Psychiatric Association, 2022). Its extreme form is well described in
the psychiatric and psychological literature as &lt;em&gt;acalculia&lt;/em&gt; (Dehaene, 1997;
Nieder, 2025). A person with acalculia suffers from extreme challenges with
even the most basic arithmetic operations, often as a consequence of severe
brain damage or extreme developmental disorder. For example, if asked to add
one to a given number, the he/she is unable to do such elementary calculation.
It is important to note that the term “idiot” should not be understood
pejoratively. The original meaning of
&lt;a href="https://lsj.gr/wiki/%E1%BC%B0%CE%B4%CE%B9%CF%8E%CF%84%CE%B7%CF%82"&gt;ἰδιώτης&lt;/a&gt; in
Greek is just a normal person.  There is also a large literature on idiot
savants who combine extreme deficit in one cognitive capacity or many diverse
capacities with much above the average achievement in certain specific
intellectual domain (Dehaene, 1997).&lt;/p&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;The omniidiota dilemma:&lt;/p&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;&lt;strong&gt;Can a person make such a big number that he/she cannot imagine a number
greater than that?&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="ulist"&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;If he/she can imagine such a number, then it proves he/she is an idiot,&lt;/strong&gt;
  since the task of guessing a number that is greater than the given number
  (without any other conditions or restrictions) is trivial. It can be solved
  in any of many different ways, e.g. adding one or two to the big number, or
  just doubling this number. Incapacity to increase a number (big or small)
  points to severe cognitive deficit.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;If he/she cannot imagine such a number, then he/she is an idiot,&lt;/strong&gt;
  because just imagining any number is a trivial task: take any number and then
  imagine an even bigger number using any of the elementary arithmetic
  operations.  Incapacity to create a number therefore points to severe
  cognitive deficit.
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;It follows from the omniidiota dilemma that you (the reader) and I (the writer)
are all idiots: Being not an idiot is a logically contradictory proposition.
The dilemma is then simple: everyone is either an idiot or &amp;#8230; an idiot:
&lt;em&gt;tertium non datur&lt;/em&gt;.&lt;/p&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;&lt;strong&gt;Corollary.&lt;/strong&gt; It follows from The paradox of the stone and The omniidiota
dilemma that, if God’s omnipotence is considered self-contradictory, then
everyone is necessarily an idiot.&lt;/p&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="sect1"&gt;
&lt;h2 id="_references"&gt;References&lt;/h2&gt;
&lt;div class="sectionbody"&gt;
&lt;div class="ulist"&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;
American Psychiatric Association, ed (2022). Diagnostic and statistical manual
  of mental disorders: DSM-5-TRTM. American Psychiatric Association Publishing,
  Washington, DC, Fifth revised edition.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Anderson, C.A. (1984). Divine omnipotence and impossible tasks: An intensional
  analysis– Int J Philos Relig 15: 109–124.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Bassford, A.D. (2023). God and the problem of logic. Cambridge University
  Press.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Beall, J. &amp;amp; Cotnoir, A.J. (2017). God of the gaps: a neglected reply to God’s
  stone problem– Analysis 77: 681–689.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Cogburn, J. (2004). Paradox lost– Can. J. of Philosophy 34: 195–216.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Cowan, J.L. (1965). The paradox of omnipotence– Analysis 25: 102–108.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Cowan, J.L. (1974). The paradox of omnipotence revisited– Can. J. of
  Philosophy 3: 435–445.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Dehaene, S. (1997). The number sense: how the mind creates mathematics. Oxford
  University Press.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Frankfurt, H.G. (1964). The logic of omnipotence– Philosophical Review 73:
  262–263.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Geach, P.T. (1973). Omnipotence– Philosophy 48: 7–20.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Gödel, K. (1995). Collected Works: Volume III: Unpublished essays and lectures–
  (S. Feferman, J. W. D. Jr., W. Goldfarb, C. Parsons, &amp;amp; R. Solovay, Eds.).
  Oxford University Press
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Hill, S. (2014). Giving up omnipotence– Can. J. of Philosophy 44: 97–117.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Mavrodes, G.I. (1963). some puzzles concerning omnipotence– The Philosophical
  Review 72: 221.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Nieder, A. (2025). The calculating brain– Physiological Reviews 105: 267–314.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Plantinga, A. (1967). God and other minds. Cornell University Press.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Savage, C.W. (1967). The paradox of the stone– The Philosophical Review 76:
  74-79.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Schrader, D.E. (1979). A solution to the stone paradox– Synthese 42: 255–264.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Wikipedia (2024, November 7). Omnipotence paradox.
  &lt;a href="https://en.wikipedia.org/wiki/Omnipotence_paradox"&gt;https://en.wikipedia.org/wiki/Omnipotence_paradox&lt;/a&gt;.
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Wreen, M. (2022). The contradiction approach to solving problems about
  omnipotence– TheoLogica 6: 52533.
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;hr /&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;A slightly modified version of this text is available at:&lt;/p&gt;&lt;/div&gt;
&lt;div class="ulist"&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;
Budaev, S., (2024). The Omnipotence paradox reduces to the omniidiota dilemma.
  Available at SSRN: &lt;a href="https://ssrn.com/abstract=5017222"&gt;https://ssrn.com/abstract=5017222&lt;/a&gt; (November 07, 2024)
  [&lt;a href="https://budaev.info/pub/pubs/ssrn-5017222.pdf"&gt;PDF&lt;/a&gt;].
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
</content><category term="Blog"></category><category term="Catholicism"></category><category term="Faith"></category></entry><entry><title>Det er enkelt å dele</title><link href="https://budaev.info/det-er-enkelt-a-dele.html" rel="alternate"></link><published>2024-11-03T23:00:00+01:00</published><updated>2024-11-03T23:00:00+01:00</updated><author><name>Sergey Budaev</name></author><id>tag:budaev.info,2024-11-03:/det-er-enkelt-a-dele.html</id><summary type="html">&lt;p&gt;Den gamle gode e-posten er fortsatt veldig nyttig.&lt;/p&gt;</summary><content type="html">&lt;p&gt;Informasjonsdeling innenfor en liten gruppe er brukes ganske typisk. For
eksempel, hvis barna dine er i en skole eller barnehage, må du gå inn i en
klassegruppe for å dele forskjellig informasjon, meldinger osv. Ofte
proprietære sentraliserte plattformer som Facebook eller Whatsapp (Å, begge er
i bunn og grunn det samme uetiske selskapet, Meta!) eller noen ganger Telegram.&lt;/p&gt;
&lt;p&gt;Mange ikke-IT-folk bruker bare det de pleide å bruke i dagliglivet. De som er
mer bekymret for personvern og sikkerhet til dem og barna deres, vil ikke
bruke noen av Meta eller andre store teknologiske apper. Men det er andre og
det er en behov til å kommunisere. Valget er enkelt: Enten blir du med i
foreldregruppen på Facebook eller så blir du ekskludert. Hvis ekskludert,
vil du ikke få oppdateringer om arrangementer, bursdager og så videre. De andre
foreldrene vil kanskje se på deg med en viss mistanke: er du en spion eller en
narkohandler som prøver å gjemme deg i en skygge av darknet? Dette er hva Cory
Doctorow kaller "the nettwork effect." Og det utnyttes og promoteres av de
gigantiske plattformene. De gjør sitt beste for å manipulere deg til å se på
plattformen og reklame deres så mye tid som mulig, ideelt sett 24 timer i
døgnet, og de lokker deg til å gi ut så mye privat data som mulig. Ingen vet
hvordan disse dataene vil bli brukt i fremtiden. Det er skjult i usikkerhet.
Den eneste sikkerheten er at brukerne utnyttes for andres fortjeneste.&lt;/p&gt;
&lt;p&gt;Mens Facebook og andre prøver å pålegge enorme byttekostnader for å holde deg
på plattformen, &lt;strong&gt;er det en enkel løsning som er tilgjengelig for alle. Det er
den gamle gode e-posten.&lt;/strong&gt; Alle har det nå. Men noen bruker det kun til å
registrere seg på nettsider, få lenker til tilbakestilling av passord og
lignende. Nei, e-post er fortsatt i live og er faktisk bedre enn mange pleide å
tro.&lt;/p&gt;
&lt;h2&gt;Epostlister&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Maillister&lt;/strong&gt; er velkjente. Vanligvis brukes de bare å spam deg med unødvendig
informasjon, reklame kampanjer og så videre. Men epostlister kan brukes til
bedre. Det er noe åpen kildekode-programvare for e-postlistebehandling som du
(jeg antar at du er administrator for gruppen) kan bruke på din egen server.
Deretter kan du abonnere alle i gruppen på listen (eller nyhetsbrevet ditt).
Okay– nå får alle i gruppen oppdateringer. Enkelt. Folk kan ha muligheten til å
abonnere seg på listen, eller avslutte abonnementet seg selv (uten din,
administratorens, manuelle handling). Det er nyttig.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Et eksempel på denne programvaren er Listmonk: &lt;a href="https://listmonk.app"&gt;https://listmonk.app&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Non-rofit group service &lt;a href="https://groups.io/"&gt;https://groups.io/&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;E-post diskusjonsgrupper&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;E-postdiskusjonsgrupper&lt;/strong&gt; eller &lt;strong&gt;listserv&lt;/strong&gt; er egentlig en eldgammel (et
bedre ord: moden) teknologi som har blitt brukt for flere tiår siden. Den
brukes fortsatt mye av programvareutviklerfellesskapet med åpen kildekode. For
eksempel det berømte Linux kernel prosjektet. Ideen er bare triviell:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Du abonnerer på e-postlisten&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Du får gruppens e-post ("listserv") e-postadresse, f.eks. &lt;code&gt;foreldre@din.fqdn&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Alle meldinger sendte en melding til denne gruppeadressen (ja,
   &lt;code&gt;foreldre@your.fqdn&lt;/code&gt;) spres til hver abonnents postkasse.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Deretter, hvis du abonnerer, svarer det å svare på gruppeadressen til å dele
e-postmeldingen med alle medlemmer.&lt;/p&gt;
&lt;p&gt;Den gode gamle e-posten konkurrerer ikke om oppmerksomheten din med irrelevante
og irriterende varsler, manipulerer deg ikke til å blikk og dumscrolling. Alt
kommer bare til postkassen din. Du kan svare når som helst fra hvilken som
helst enhet, ingen spesielle apper er nødvendig.&lt;/p&gt;
&lt;p&gt;Men slutt, for å bruke listserv trenger du din egen (eller kontrollerte)
e-postserver, domenenavn, kompetanse og tid for konfigurering og vedlikehold.
Hvis du er modig nok, kan du konfigurere din egen GNU Mailman:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;GNU Mailman: &lt;a href="https://www.gnu.org/software/mailman"&gt;https://www.gnu.org/software/mailman&lt;/a&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Men hvis du liker å unngå bryet, er det flere åpne servere som tillater
registrering og gratis hosting for små ideelle grupper.&lt;/p&gt;
&lt;p&gt;Det er også en Listserv on steroids som er gratis for små ikke-rpfit-grupper
(opptil 1000 abonnenter, som vanligvis er nok):&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Gaggle mail: &lt;a href="https://gaggle.email"&gt;https://gaggle.email&lt;/a&gt;&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Her kan du:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Registrer din (admin) konto&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Legg til gruppe-e-poster&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Del, svarer, videresend gruppe-e-poster, med arkiver og mye annen funksjonalitet.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;hr&gt;
&lt;p&gt;Doctorow, C. 2023. The internet con: how to seize the means of computation.
Verso.&lt;/p&gt;</content><category term="Blog"></category><category term="wiki"></category><category term="Q&amp;A"></category></entry><entry><title>Durov, Telegram and responsibility</title><link href="https://budaev.info/durov-telegram-and-responsibility.html" rel="alternate"></link><published>2024-08-26T18:00:00+02:00</published><updated>2024-08-26T18:00:00+02:00</updated><author><name>Sergey Budaev</name></author><id>tag:budaev.info,2024-08-26:/durov-telegram-and-responsibility.html</id><summary type="html">&lt;p&gt;If you rent out a hammer for profits, you get responsibility for its abuse&lt;/p&gt;</summary><content type="html">&lt;p&gt;The founder and head of the Telegram messenger, multimillionaire Pavel Durov
was detained by police immediately after arrival at Le Bourget airport. French
law enforcement have long been unhappy with Durov’s refusal to moderate content
and to cooperate with authorities in disclosing information about users
suspected of distributing drugs, child pornography, fraud and other criminal
activity. Moderation is nearly nonexistent on Telegram except the most severe
cases like islamist terrorism: usually banning their public channels.&lt;/p&gt;
&lt;p&gt;However, Telegram did also cooperate with Putin's Russia authorities in banning
Navalny's "smart voting." Durov's own explanation for this was that "it is better
to ban Navalny than ban Telegram in Russia." This is clearly a deceit because a
few years before that, Russian authorities have demonstrated their inability to
block Telegram.&lt;/p&gt;
&lt;p&gt;Durov is positioning himself as a hardcore libertarian protecting all kinds of
freedoms, especially the freedom of speech and expression (against evil state).
Many believe it is true, hence the wave of public support: &lt;code&gt;#FreePavel&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;&lt;img alt="Du Rove" src="images/durov.png" title="Du Rove"&gt;&lt;/p&gt;
&lt;p&gt;The real picture is, however, quite different. Apart from the very extravagant
personality of Pavel Durov (many still remember as he threw rouble banknotes
from his St. Petersburg head office balcony for personal amusement), neither
the Telegram platform nor the company in fact have anything in common with
protecting liberties. &lt;strong&gt;Telegram is quite a standard commercial walled garden 
platform with the main aim to monetize its growing user base. "Privacy" for
Telegram is nothing more than a marketing ploy.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Telegram is advertised as "secure" and "private" although it has from the
beginning been devised as a centralized platform aimed to get exclusive control
over its users' communication. There is no end-to-end encryption by default.
The MTProto protocol used by Telegram is a home-made thing, never seriously
audited by cryptography experts. The Telegram client is open source (and is
even available in &lt;a href="https://f-droid.org/en/packages/org.telegram.messenger"&gt;blob-free open source version on
F-Droid&lt;/a&gt;), but the
server is not. So nothing is known about what actually happens with the user's
communication data and metadata. This is not a minor thing because Telegram
keeps all the data on its cloud servers for user's "convenience." This means
that all the messages are unencrypted (for Telegram), and potentially
accessible to the third parties.&lt;/p&gt;
&lt;p&gt;Fun, soon after Durov's detention in Paris, bureaucrats from the administration
of the president in Russia, the ministry of defence and large state owned
corporations were instructed to delete their Telegram communications. No, this
won't help if everything is kept on the cloud servers. It is well known that
Telegram has a reputation of "inaccessible to FSB" and therefore widely used by
a range of Russian governmental and military users. These people have been
reluctant to use the official "safe" and "encrypted" tools that have full FSB
certification because they believe (quite reasonably) that these are all
wiretapped.  Telegram is also the common communication tool for Russian troops
attacking Ukraine. Now it is easy to guess how confused and scared they are!&lt;/p&gt;
&lt;p&gt;Every user of Telegram is identified with and linked to the mobile number,
which is really a mockery of privacy. Participants of Hong Kong protests were
able to verify this: the mobile numbers and therefore personal identity of many
of them were easily obtained from by the "private" Telegram by the mainland
Chinese police. To access the account of most users (two-step auth is not
enabled by default, there is no password for most users!) the attacker just
needs...  access to the SMS, which is a trivial task for the mobile operator
and therefore the law enforcement (or in many cases even a hacker using social
engineering to reissue the SIM-card). Then the content is not encrypted, except
for the "secret chats" that only few actually use. &lt;/p&gt;
&lt;p&gt;Some years ago, Russian authorities tried to access Telegram contents of quite
a few members of Putin's opposition by secretly coercing the mobile operators
to forward authentication codes sent by SMS. Admins of quite a few Russian and
Belorussian opposition chats and even regular subscribers were also identified.
There exist several OSINT tools that help identify Telegram chatters, some are
available for just everyone for a moderate price.&lt;/p&gt;
&lt;p&gt;Not only privacy and security, but even data integrity of Telegram is
questionable. The company protocols of dealing with the data are questionable.
There are rumors that some years ago Durov himself deleted Telegram chats of
his personal rivals at will.&lt;/p&gt;
&lt;p&gt;Telegram is "free" to users, but running it incurs huge costs. Who pays then?
The users actually pay for it with their ever accumulating private data (their
privacy), their increasing flock size, traffic and now also paid subscription
and the TON cryptocurrency.&lt;/p&gt;
&lt;p&gt;Telegram has always been a secretive non-transparent company. There are rumors
that its major investors include Emirates' funds with the major beneficiaries
from Russia. Even though Durov usually denies any links with Russia, Telegram
very likely significantly depends on Russian oligarchs' money.  But little is
still known about the financial affairs at Telegram. Also little is known about
the organizational structure of Telegram. Nonetheless, everything looks like a
single person--the CEO Pavel Durov--has the complete control over everything,
from technology to HR, finances and relations with investors.&lt;/p&gt;
&lt;p&gt;It looks like Durov has created a platform advertised for "freedom" and
"privacy," inviting everyone for whatever purposes, even the most evil and
criminal ones. But Telegram was deliberately created as a single centralized
platform, apparently to benefit from the full control for profit. Full control,
however, involves full responsibility, including law enforcement access and
moderation. &lt;/p&gt;
&lt;p&gt;"Guardians of internet freedoms" say that accusing Durov of complicity in
crimes the users do is equal to accusing the manufacturer of a hammer: everyone
can use it for nailing as well as for killing, all outside of the maker's
control or even knowledge. But this is not true. In the case of Telegram, the
instrument is not given to the users. Users do not possess it. They are just
allowed to hold it for a while. Durov's situation is equivalent to renting out
a hammer for securing profits, without asking if it is actually used for
nailing or killing. And even knowing that in many cases it is in fact used for
killing, breaking into houses and other criminal purposes. The purpose is
profit.  Then, those who rent out the hammer are responsible for what their
paying users do with it. Any benefits obtained from criminal abuse of the
hammer are complicity, even if indirect.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The only way to protect liberties and freedom of speech and expression is
through decentralized or federated platforms. Then, the end user is the owner
of the decentralized unit and bears full responsibility for his/her own use.
Decentralized technology is not only safer and more secure, but also more
responsible.&lt;/strong&gt;&lt;/p&gt;</content><category term="privacy"></category><category term="Telegram"></category></entry><entry><title>Bruk F-Droid i stedet av Google Play Store</title><link href="https://budaev.info/bruk-f-droid-i-stedet-av-google-play-store.html" rel="alternate"></link><published>2024-04-15T09:30:00+02:00</published><updated>2024-04-15T09:30:00+02:00</updated><author><name>Sergey Budaev</name></author><id>tag:budaev.info,2024-04-15:/bruk-f-droid-i-stedet-av-google-play-store.html</id><summary type="html">&lt;p&gt;Bruk F-Droid i stedet av Google Play Store for personvern og sikkerhet.&lt;/p&gt;</summary><content type="html">&lt;p&gt;Googles Android Play Store blir verre over tid. Det blir stadig mer strødd med ubrukelige apper som utelukkende tar sikte på å vise reklame. I navnet av "personvern" gjennomfører Google ytterligere hindringer for både utviklere og brukere, mens ekte skadelig programvare &lt;a href="https://usa.kaspersky.com/blog/malware-in-google-play-2023/29356/"&gt;blomstrer&lt;/a&gt; på plattformen. Det ofte blir et mareritt for utviklere av åpne kilde programmer som er fokusert på personvern og sikkerhet. Den nylige de-listingen av &lt;a href="https://snikket.org/"&gt;Snikket&lt;/a&gt;&amp;#x2014;en sikker, personvernsentrert melding app&amp;#x2014;viser at personalet som er ansvarlig for applikasjonsvurdering på Googles side, er mentalt forsinket idioter. Sjekk ut hele historien her: &lt;a href="https://snikket.org/blog/snikket-google-play-removal/"&gt;https://snikket.org/blog/snikket-google-play-removal/&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Google, er det slik at ansatter med IQ&amp;lt;50 koster mindre? Eller alle mennesker på Google ble erstattet med en AI som mangler intelligens? Mange utviklere gir opp å slite med idioter på Googles applikasjonsvurdering og slutter å distribuere appene sine i Play Store (&lt;a href="https://kanoa.de/@blabber/108289026302640506"&gt;her&lt;/a&gt; kommer en annet eksempel).&lt;/p&gt;
&lt;p&gt;Situasjonen kan være så absurd at åpne kilde &lt;a href="https://conversations.im/"&gt;Conversations&lt;/a&gt; appen som går ikke fri (NOK 47) på Google Play måtte &lt;a href="https://codeberg.org/iNPUTmice/Conversations/src/branch/master/CHANGELOG.md#version-2-13-3"&gt;forringe funksjonaliteten på denne distribusjonsplattformen&lt;/a&gt;. Den samme appen &lt;a href="https://f-droid.org/packages/eu.siacs.conversations/"&gt;går gratis med fult funksjonalitet&lt;/a&gt; på F-Droid.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Men det er en løsning for alle Android-brukere: bare installer &lt;a href="https://f-droid.org/"&gt;F-Droid&lt;/a&gt;, en appbutikk som publiserer åpne kilde programmer uten reklame, traking, datalekkasjer, skadevare og bakdører.&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;F-Droid:&lt;/strong&gt; &lt;a href="https://f-droid.org/"&gt;https://f-droid.org/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Den eneste garantien mot skadelig programvare er &lt;strong&gt;åpen kildekode&lt;/strong&gt; som alle som helst kan sjekke og revidere: mange øyne oppdager problemer tidligere og bedre. F-Droid gjennomfører &lt;a href="https://f-droid.org/en/docs/Reproducible_Builds/"&gt;"reproducible builds"&lt;/a&gt; som sikrer at binær apk bloben er bygget av samme kildekoden som utvikler har publisert, så det finnes ikke noe uautorisert tilleg eller endringer (apk fra Google Play inkluderer Googles blober for reklame og tracking). &lt;strong&gt;Det anbefales å søke apper først på &lt;a href="https://f-droid.org/"&gt;F-Droid&lt;/a&gt; og gå til Google Play kun når den ikke er tilgjengelig.&lt;/strong&gt; Da skal Google Play brukes bare for apper som er klarert på forhånd, f.eks. banken.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://www.cnet.com/tech/mobile/fight-android-malware-by-quitting-google-play-and-using-f-droid-to-install-android-apps/"&gt;Fight Android malware by quitting Google Play and using F-Droid for Android apps&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://www.wired.com/story/android-users-to-avoid-malware-ditch-googles-app-store/"&gt;To Avoid Malware, Try the F-Droid App Store&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;</content><category term="Blog"></category><category term="privacy"></category><category term="security"></category><category term="platform"></category><category term="Android"></category></entry><entry><title>A year with Mikrotik router</title><link href="https://budaev.info/a-year-with-mikrotik-router.html" rel="alternate"></link><published>2024-03-19T23:00:00+01:00</published><updated>2024-03-19T23:00:00+01:00</updated><author><name>Sergey Budaev</name></author><id>tag:budaev.info,2024-03-19:/a-year-with-mikrotik-router.html</id><summary type="html">&lt;p&gt;A year with Mikrotik router. No issues, lots of functions.&lt;/p&gt;</summary><content type="html">&lt;p&gt;I use &lt;a href="https://www.nextgentel.no/"&gt;NextGenTel&lt;/a&gt; with fibre broadband connection
as my home Internet provider. The connection line works fairly well with
no interruptions. I have been using a &lt;a href="https://mikrotik.com/product/hap_ax2"&gt;Mikrotik router&lt;/a&gt;
for nearly a year now and have experienced no single interruption.
No hanging internet, no problems at all. I nearly forgot that it is 
here.&lt;/p&gt;
&lt;p&gt;&lt;img alt="Year traffic plot" src="images/traff-yearly.gif" title="Year traffic plot"&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt="Mikrotik" src="images/mikrotik.jpg" title="Mikrotik"&gt;&lt;/p&gt;
&lt;p&gt;Why I love Mikrotik is the &lt;a href="https://help.mikrotik.com/docs/display/ROS/RouterOS"&gt;Router
OS&lt;/a&gt;, a
professional operating system with tons of configurability and
fine tuning. You can tweak any aspect and configure a variety of
services. For example VPNs with different protocols for connecting
into the local home network is easy to configure using the &lt;a href="https://help.mikrotik.com/docs/display/ROS/"&gt;Mikrotik
documentation&lt;/a&gt;.
&lt;a href="https://help.mikrotik.com/docs/display/ROS/Queues"&gt;Queues&lt;/a&gt; are a nice
configuration feature to control and manage bandwidth given to 
devices in the local network. There is also quite advanced
&lt;a href="https://help.mikrotik.com/docs/display/ROS/Scripting"&gt;scripting&lt;/a&gt; that can
be used to do many interesting things. I do not recommend Mikrotik to an
average user, however, because Router OS has a professional interface with
too many options and details: you need to understand what you are doing. 
&lt;a href="https://mikrotik.com/"&gt;Mikrotik&lt;/a&gt; is a &lt;a href="https://www.latvia.eu/business-innovation/export/mikrotik/"&gt;Latvian company&lt;/a&gt; 
that makes a lot of professional carrier-grade 
&lt;a href="https://mikrotik.com/products"&gt;equipment&lt;/a&gt;, all run the same OS.&lt;/p&gt;
&lt;p&gt;The previous router provided by the NextGenTel was pure disaster. I in fact
used &lt;a href="https://hjelp.nextgentel.no/no_NO/-finn-din-ruter/-inteno-dg150"&gt;two&lt;/a&gt;
&lt;a href="https://hjelp.nextgentel.no/no_NO/-finn-din-ruter/inteno-dg200"&gt;different&lt;/a&gt;
units of the same marque: &lt;em&gt;Inteno.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt="Intento shit router" src="images/router-ngt-inteno.jpg" title="Intento shit router"&gt;&lt;/p&gt;
&lt;p&gt;This shit router tended to hung up at least one or twice a week, leaving no
connection. The NextGenTel support was useless, with the routine advice to
reboot router. Rebooting helped indeed until the next hangup, maybe the
next day. It is not a solution to fix bad hardware. It is so weird that
they supply their users with this shit when the competition between
providers is so intense. Many people would not figure out that it is
the router that is so bad and will blame NextGenTel as a whole and
switch to another provider. Shame, NextGenTel.&lt;/p&gt;
&lt;p&gt;But if you subscribe for the &lt;a href="https://www.nextgentel.no/produkter/telefoni"&gt;home telephone&lt;/a&gt; 
line with NextGenTel, then you are out of luck because telephone is 
served by the Inteno router which also includes a &lt;a href="https://en.wikipedia.org/wiki/Session_Initiation_Protocol"&gt;SIP&lt;/a&gt; 
service via built in &lt;a href="https://www.asterisk.org/"&gt;Asterisk&lt;/a&gt; server pre-configured 
by the provioder. The only solution is then to torture NextGenTel with service 
requests and replacing the router. (But, of course, a better alternative is 
to set up your own asterisk-based SIP VoIP server with trunks from any of the
many available SIP providers; this will be much more flexible and 
cost-effective solution).&lt;/p&gt;</content><category term="Blog"></category><category term="other"></category></entry><entry><title>Shit happens: det kommer garantert til å skje hvis dumhet gjentas</title><link href="https://budaev.info/shit-happens-det-kommer-garantert-til-a-skje-hvis-dumhet-gjentas.html" rel="alternate"></link><published>2023-12-31T10:00:00+01:00</published><updated>2023-12-31T10:00:00+01:00</updated><author><name>Sergey Budaev</name></author><id>tag:budaev.info,2023-12-31:/shit-happens-det-kommer-garantert-til-a-skje-hvis-dumhet-gjentas.html</id><summary type="html">&lt;p&gt;Shit happens: det kommer garantert til å skje hvis dumhet gjentas.&lt;/p&gt;</summary><content type="html">&lt;p&gt;&lt;strong&gt;Shit happens.&lt;/strong&gt; Det er en triviell visdom. Ofte er det en direkte konsekvens
av en enkelt stupid ting. I mange tilfeller kan lite gjøres for å forhindre
det skal skje. Uansett, sannsynligheten antas veldig lav. Katastrofen er
uforutsigbar. Det er en ulykke, helt tilfeldig. Ikke sant?&lt;/p&gt;
&lt;p&gt;&lt;img alt="Den bærbare datamaskinens tastatur er dekket av kaffe (eller brus). Å shit..." src="images/spill-mac.jpg" title="Den bærbare datamaskinens tastatur er dekket av kaffe (eller brus). Å shit..."&gt;&lt;/p&gt;
&lt;p&gt;Det gjelder for en enkelt hendelse. Kanskje en enkelt hendelse
av dumhet eller klønete...  Men hvis toskeskap gjentas (f.eks. hvis det er en
&lt;em&gt;vane&lt;/em&gt;) er situasjonen en helt forskjellige. Sannsynligheten av shit som
skal skje er nå&lt;/p&gt;
&lt;p&gt;&lt;img alt="P(1|n)=1-(1-p)^n" src="images/eq-shit-01.svg" title="P(1|n)=1-(1-p)^n"&gt;&lt;/p&gt;
&lt;p&gt;her er &lt;em&gt;P(1|n)&lt;/em&gt; sannsynligheten for at shit skjer minst én gang i en gruppe
av &lt;em&gt;n&lt;/em&gt; hendelser; hver hendelse har sjansen &lt;em&gt;p&lt;/em&gt; (veldig lav!) til å skje, og &lt;em&gt;n&lt;/em&gt;
er antall hendelser.&lt;/p&gt;
&lt;p&gt;For eksempel, hvis sjansen for en singel ulykke er så lavt som 0.01 og
antallet dumme handlinger er 365 (bare en gang om dagen i løpet av et år),
blir sjansen for at shit skjer i løpet av denne tiden&lt;/p&gt;
&lt;p&gt;&lt;img alt="1-(1-0.01)^365=0.97" src="images/eq-shit-02.svg" title="1-(1-0.01)^365=0.97"&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Det er nesten sikkert at shit skjer minst én gang i løpet av et år.&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Drikker du kaffe/brus/smoothie/vin på den bærbare datamaskinen til vanlig?
  Forberede for å erstatte tastaturet. Det vil skje.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Vant til å sende sms mens du kjører? Har du en god forsikring?&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Løper ofte over veien foran lastebil/buss/bil? Det er på tide å bestille
  krykker (eller enda kiste) på forhånd.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;</content><category term="Blog"></category><category term="Wisdom"></category><category term="Q&amp;A"></category></entry><entry><title>Telefonen til et barn</title><link href="https://budaev.info/telefonen-til-et-barn.html" rel="alternate"></link><published>2023-11-05T14:00:00+01:00</published><updated>2023-12-28T10:00:00+01:00</updated><author><name>Sergey Budaev</name></author><id>tag:budaev.info,2023-11-05:/telefonen-til-et-barn.html</id><summary type="html">&lt;p&gt;Ikke la barnet ditt bli smarttelefonzombie&lt;/p&gt;</summary><content type="html">&lt;p&gt;Både voksne og barn blir stadig mer avhengige av smarttelefonene sine. Et
morsomt begrep for slike rusavhengige er smarttelefonzombie. Men dette er
ikke morsomt. Faktisk, &lt;strong&gt;smarttelefoner dreper.&lt;/strong&gt; For eksempel har det
vært en økning i antall dødsfall hos barn fordi barna sitter klistret
til telefonene sine&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.ibtimes.co.uk/smartphone-zombies-child-road-deaths-spike-because-kids-are-glued-their-phones-1604722"&gt;Smartphone zombies: Child road deaths spike because kids are glued to their phones&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Stadig flere barn nå eier smarttelefoner. Nesten alle ungdommer
eier en smarttelefon i Norge, Storbritannia, USA og mange andre
land. Smarttelefonavhengighet er en verdensomspennende plage (&lt;a href="https://doi.org/10.1016/j.chb.2021.107138"&gt;Olson et al.,
2022&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;&lt;img alt="Smartphone zombie sign" src="images/smartphone-zombie.jpg" title="Smartphone zombie sign"&gt;&lt;/p&gt;
&lt;p&gt;Imidlertid, forskning viser  at smarttelefonavhengighet fører til en rekke
alvorlige psykologiske, helse- og velværeproblemer, inkludert nevrologiske
lidelser (e.g. &lt;a href="https://doi.org/10.3390/ijerph182212257"&gt;Ratan et al., 2022&lt;/a&gt;;
&lt;a href="https://doi.org/10.3390/healthcare11010014"&gt;Achangwa et al., 2023&lt;/a&gt;). Mange
undersøkelser viser at bruk av smarttelefoner påvirker
studentenes akademiske prestasjoner negativt (e.g. &lt;a href="https://doi.org/10.1016/j.ijer.2020.101618"&gt;Amez &amp;amp;
Boert, 2020&lt;/a&gt;; &lt;a href="https://doi.org/10.1016/j.lindif.2021.102035"&gt;Sapci
etal. 2021&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;Smarttelefonen din er en dedikert spionenhet, men enda mer bekymringsfull
er det faktum at apper målrettet mot barn sporer, samler inn personlige
data og laster dem opp til ukjente tredjeparter (e.g.
&lt;a href="https://blues.cs.berkeley.edu/wp-content/uploads/2018/04/popets-2018-0021.pdf"&gt;Reyes et al., 2018&lt;/a&gt;).
Men det handler ikke bare om data og reklame. Smarttelefoner kan
direkte påvirke fysisk sikkerhet av barn. En russisk studie indikerte
at nesten 50% av barna får nye bekjentskaper i sosiale medier og 36%
av dem møter disse nye menneskene i virkeligheten etterpå (&lt;a href="https://www.kaspersky.ru/about/press-releases/2022_pochti-chetvert-zayavok-v-druzya-deti-poluchayut-ot-vzroslyh-polzovatelej"&gt;Kaspersky Lab,
2022&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;Vi må løse en avveining mellom behovet for å kommunisere med barna våre,
men unngå avhengighet. &lt;strong&gt;Så hva er løsningen? Jeg tror det er en kombinasjon
av gammel stil (men ikke foreldet!) knapptelefon og et stort nettbrett.&lt;/strong&gt;&lt;/p&gt;
&lt;h2&gt;Knappetelefoner er klassiske, men ikke udaterte!&lt;/h2&gt;
&lt;p&gt;&lt;img alt="Cool buttonphone" src="images/buttonphone-ascii.svg" title="Cool buttonphone"&gt;&lt;/p&gt;
&lt;p&gt;Fordeler med knappetelefon, i tillegg til at det neppe forårsaker avhengighet,
inkludere&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;BATTERI&lt;/strong&gt; fungerer lange eller veldig lange, ingen grunn til å tenke på
  lading, det er liten risiko for å sitte igjen med en død, utladet telefon
  i det mest uleilige øyeblikket. Batteriet dør ikke i kulden. Batteriet
  er avtakbart og kan enkelt skiftes ut. Det er ingen risiko for at barnet
  vil lade ut batteriet på grunn av intens spilling på telefonen. Det
  vil ikke skje i verste øyeblikk, for eksempel når han eller hun trenger
  hjelp fra foreldrene&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;SIKKERHET:&lt;/strong&gt; det er ingen konstant tilkobling til Internett, viktige data,
  passord, personlige dokumenter, kredittkortdata lagres ikke på telefonen:
  det er ingen risiko for lekkasje eller hacking, selv om telefonen er mistet
  eller stjålet. Plasseringen kan ikke spores og lekkes. Mange hackere og
  sikkerhetseksperter bær ikke smarttelefoner. &lt;em&gt;Men knappetelefonen tjener
  sin hovedfunksjon, kommunikasjon, helt perfekt.&lt;/em&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;PRIS&lt;/strong&gt; telefonen er billig, ikke bry deg om det, den er lett å erstatte hvis
  den er ødelagt, mistet eller druknet. Men dette er spesielt viktig siden du
  alltid har telefonen med deg. Barn er ofte uforsiktige og kan bryte ned ting.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;FYSISK STYRKE:&lt;/strong&gt; En liten skjerm, sterk telefon, går ikke i stykker med
  det minste fall, mindre utsatt for vann. Jeg har erfaring med at en telefon
  ble vasket i vaskemaskin og fortsatte å virke etterpå.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;FYSISK KNAPPER&lt;/strong&gt; &lt;a href="https://news.usni.org/2019/08/09/navy-reverting-ddgs-back-to-physical-throttles-after-fleet-rejects-touchscreen-controls"&gt;er fortsatt et av de beste
  brukergrensesnittene&lt;/a&gt;,
  praktisk å bruke. Du kan konfigurere ett-tasts hurtigvalg. Knapper er
  også lettere å bruke med hansker i kaldt vær.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;STØRRELSE&lt;/strong&gt; en liten telefon passer lett i lommen. Det er bare praktisk.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;IKKE FORELDET&lt;/strong&gt; en trykkknapptelefon kan betraktes som &lt;em&gt;en "fysisk
  app"&lt;/em&gt; som ikke blir foreldet og rett og slett alltid fungerer uten
  å kreve konstante "oppdateringer."&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Knappetelefon blir ofte sett på som noe enkelt og kjedelig, selv om det ikke
er helt utdatert. Men det finnes noen få moderne, elegante, designertelefoner,
for eksempel &lt;strong&gt;&lt;a href="https://www.punkt.ch/"&gt;Punkt&lt;/a&gt;&lt;/strong&gt; (overpriset!).&lt;/p&gt;
&lt;h2&gt;Nettbrett gir mye bedre brukeropplevelse&lt;/h2&gt;
&lt;p&gt;Men vi kan ikke frata barna våre internett, spillkommunikasjon med venner
og alt annet som en smarttelefon gir! Riktig nok, men det finnes et bedre
enhet enn smarttelefon: nettbrett&lt;/p&gt;
&lt;p&gt;&lt;img alt="Tablet for the young" src="images/tablet-ynge.png" title="Tablet for a young"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;STOR SKJERM:&lt;/strong&gt; nettbrettet har en stor skjerm som gir mye bedre
  brukeropplevelse for alle bruksområder: Internett, video, spill, tegning,
  skriving og til og med lydsamtaler. En stor skjerm kan bare ikke sammenlignes
  med den lille skjermstubb på typisk smarttelefon. Det er mye bedre for
  alle slags kreative aktiviteter.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;LAVERE ER BEDRE:&lt;/strong&gt; Det er ikke så lett å ta en tablett med deg hele
  tiden. Med andre ord er tilgjengeligheten lavere og det er noen små
  kostnader forbundet med bruken. Faktisk må du gå til laderen eller et
  bord, ta nettbrettet og først deretter bruke det. Det er ganske stor
  forskjell fra smarttelefonen som ofte alltid ligger i lommen. Dette gjør
  det mindre sannsynlig at du blir avhengig av et nettbrett.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;STOR OG MERKBAR:&lt;/strong&gt; Bruk av nettbrett er lettere å legge merke til. Dette
  gjør det også lettere for foreldrene å overvåke og kontrollere barnas
  nettbrettbruk.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Konklusjon&lt;/h2&gt;
&lt;p&gt;Konklusjonen er denne: &lt;strong&gt;i stedet for en smarttelefon, er det tilrådelig
å gi en grunnleggende knappetelefon til barnet ditt å bære med seg. Men
de bør også eie et nettbrett hjemme for å bruke til internett, videoer,
spill, studier og alt smarttelefonen som normalt brukes til.&lt;/strong&gt;&lt;/p&gt;
&lt;h3&gt;Anbefalt lesing&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Gabrielsen, Bjørn (2020) Skjermslaver: hva skjermene har gjort med oss,
  og hva vi kan gjøre med dem. Kagge (ISBN: 9788248925231).&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Oppdatering: lenker&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://skjermfribarndom.no/"&gt;Skjermfri barndom&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://www.nrk.no/kultur/xl/er-det-mulig-a-ha-en-normal-barndom-uten-smarttelefon_-1.17055762"&gt;Det var kanskje ikke så smart å gi ungene smarttelefon&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://www.nrk.no/mr/okende-skjermbruk-blant-unge-_-syver-johnsen-i-alesund-bruker-mobilen-ni-timer-daglig-1.16995346"&gt;19 år gamle Syver bruker mobiltelefonen 9 timer om dagen&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://www.theguardian.com/books/2024/mar/24/the-anxious-generation-jonathan-haidt-book-extract-instagram-tiktok-smartphones-social-media-screens"&gt;Generation Anxiety: smartphones have created a gen Z mental health crisis, but there are ways to fix it&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://www.theguardian.com/world/2024/apr/30/stop-children-using-smartphones-until-they-are-13-say-french-experts-in-report"&gt;Stop children using smartphones until they are 13, says French report&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://www.cnbc.com/2023/03/29/dumb-phones-are-on-the-rise-in-the-us-as-gen-z-limits-screen-time.html"&gt;Dumb phones are on the rise in the U.S. as Gen Z looks to limit screen time&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://newsroom.ee.co.uk/ee-launches-age-guidance-for-smartphone-usage-in-drive-to-improve-childrens-digital-wellbeing/"&gt;EE launches age guidance for smartphone usage in drive to improve children’s digital wellbeing&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;</content><category term="wiki"></category><category term="Q&amp;A"></category></entry><entry><title>XMPP server on 1-2-3</title><link href="https://budaev.info/xmpp-server-on-1-2-3.html" rel="alternate"></link><published>2023-10-10T10:00:00+02:00</published><updated>2026-03-15T12:00:00+01:00</updated><author><name>Sergey Budaev</name></author><id>tag:budaev.info,2023-10-10:/xmpp-server-on-1-2-3.html</id><summary type="html">&lt;p&gt;How to setup one's own XMPP messaging server and not be used by Facebook/Telegram/Microsoft/Snapchat etc.&lt;/p&gt;</summary><content type="html">&lt;p&gt;Messaging continues to be of rise. The new generation is more willing to
send texts than to call. Communicating with an instant messenger has an
unique advantage over the old good email: you can easily send replies
over replies quickly, resulting in a dialogue. But there is a serious problem:
many of the instant messengers are commercial products that work such that
their "users" are in fact the exploitable resource having no control or
choice.&lt;/p&gt;
&lt;p&gt;Most corporations are fair providers of various products and services we
can buy. But not these "Big Tech" that offer "free applications," including
instant messengers. There is, obviously, nothing free on the Earth. Then,
&lt;strong&gt;if you do not pay, then you are the product not the customer.&lt;/strong&gt; The Big
Tech corporations &lt;a href="https://www.wired.com/story/ways-facebook-tracks-you-limit-it/"&gt;exploit the "end-users" to suck out private data&lt;/a&gt;,
often for further resale. Nearly all of these messengers have centralised
architecture and the user's account is linked to the telephone number,
completely destroying privacy. The link to the telephone number is also
very inconvenient because you cannot get several accounts easily, this
requires obtaining several mobile subscriptions. It's just illogical,
expensive and silly. Centralized architecture dictates that the
communication is kept on the corporate servers
so &lt;a href="https://www.vice.com/en/article/xwnva7/snapchat-employees-abused-data-access-spy-on-users-snaplion"&gt;theoretically many employees can read
messages by abuse&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Some of the products are advertised as end-to-end encrypted. But nearly
all of them are closed source so there is no way to check how this is
implemented and if and when the service owner can have access to private
messages content.  Moreover, we have evidence for the opposite. Many
so called  "end-to-end encrypted" messages &lt;a href="https://arstechnica.com/gadgets/2021/09/whatsapp-end-to-end-encrypted-messages-arent-that-private-after-all/"&gt;are actually read by AI and human
contractors&lt;/a&gt;.
Even if communication is technically end-to-end encrypted, the company owns
and fully controls the server, the client application and network traffic, so
a &lt;strong&gt;man-in-the-middle attack&lt;/strong&gt; by silently changing certificates is possible
(e.g. in the context of lawful intercept, or unlawful abuse). &lt;strong&gt;Metadata&lt;/strong&gt;
(technical information information about all aspects of communication,
including the addressees, their locations, IP addresses, telephone number
etc.) is always accessible to the service. But metadata is often even
more informative than the message content. How such metadata is used is
typically unclear. The user has no authority here at all.&lt;/p&gt;
&lt;p&gt;Nearly all of these messengering systems have closed proprietary protocol. This
means that how you use the product is completely controlled by the owner
company. The only way to use the product is with the &lt;strong&gt;official application.&lt;/strong&gt;
You cannot just choose for yourself which application program to use. This
is cardinally different from the email, for example, where you can use the
provider's web interface, its mobile app or any of the many available email
applications such as &lt;a href="https://www.thunderbird.net/en-US/"&gt;Thunderbird&lt;/a&gt; or
&lt;a href="https://k9mail.app/"&gt;K-9 Mail&lt;/a&gt;. With such a third-party application you
can easily consolidate several email accounts in one place and easily make
use of the functionality the provider does not offer, such as &lt;a href="https://emailselfdefense.fsf.org/en/infographic.html"&gt;end-to-end
encryption&lt;/a&gt;. Another
major problem is monopoly and lack of interoperability. The "users" (in
reality, the exploited resource) are completely restricted to the owner's
platform and are unable to communicate with the other (especially competing)
platforms (e.g. Facebook to Snapchat) as a way to keep users within the silo.
This is as if you were unable to call/send sms across different mobile
operators. And this is silly. To break down monopoly, ensure fairer
competition and interoperability across the services, the EU has developed
the &lt;strong&gt;&lt;a href="https://digital-markets-act.ec.europa.eu/index_en"&gt;Digital Markets Act (DMA) regulation&lt;/a&gt;.&lt;/strong&gt;
This is a big step, but it does not solve many of the problems with
centralization, privacy and regular &lt;a href="https://www.eff.org/deeplinks/2021/04/553000000-reasons-not-let-facebook-make-decisions-about-your-privacy"&gt;security flaws&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Take back your freedom, privacy and security&lt;/h2&gt;
&lt;p&gt;So, why use the restricted, inconvenient, monopolistic, insecure and
non-private platforms for the trivial task of sending instant messages? There
are several ways to configure one's own privately controlled instant messaging
system: &lt;a href="https://xmpp.org/"&gt;XMPP&lt;/a&gt; and &lt;a href="https://matrix.org"&gt;Matrix&lt;/a&gt;. XMPP is
lightweight, easy to install, and &lt;a href="https://nebuchadnezzar-megolm.github.io/"&gt;more private and
secure&lt;/a&gt;, yet covers all the typical
instant communication purposes: text, file share and voice. Moreover, XMPP
servers are by default
&lt;a href="https://en.wikipedia.org/wiki/Federation_(information_technology)"&gt;federated&lt;/a&gt;:
it is easy to send messages across the different servers like in the email.
There are &lt;a href="https://xmpp.org/software/"&gt;many different applications for all operating systems and
platforms&lt;/a&gt; the user can choose. Update: &lt;strong&gt;XMPP can
communicate with federated Matrix network because ejabberd now implements a
&lt;a href="https://www.process-one.net/blog/matrix-gateway-setup-with-ejabberd/"&gt;Matrix
gateway&lt;/a&gt;.&lt;/strong&gt; 
(By the way, ejabberd also works with &lt;em&gt;SIP&lt;/em&gt;, standard VoIP telephony protocol,
and &lt;em&gt;MQTT&lt;/em&gt;, an IoT protocol.)&lt;/p&gt;
&lt;p&gt;A nice thing is that even if you use a particular XMPP server provider, you can
easily &lt;strong&gt;migrate your whole account&lt;/strong&gt; from it to a different one. Avoiding
vendor or provider lock-in is a good thing for many reasons. You may not be
satisfied with security, reliability or usability of your service, updated TOS,
or anything else. Or may just decide to migrate from a public server to your
own self-hosted solution. There are several tools, just check out the &lt;strong&gt;&lt;a href="https://docs.modernxmpp.org/projects/portability/"&gt;XMPP
Account Portability
project&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;It is very easy to set up one's own XMPP server for a small group,
&lt;a href="https://www.process-one.net/blog/how-to-move-the-office-to-real-time-im-on-ejabberd/"&gt;company&lt;/a&gt;,
&lt;a href="https://budaev.info/xmpp-en-ideell-direktemeldingssystem-for-et-familie.html"&gt;the family&lt;/a&gt; or just an individual. You will need
two things:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Server&lt;/strong&gt; that will be the central hub for the communication network running
  24x7. This can be anything, from a Rasberry PI in a cupboard to a &lt;a href="https://en.wikipedia.org/wiki/Virtual_private_server"&gt;Virtual
  Private Server&lt;/a&gt;
  (VPS) somewhere in a data centre or just an old PC running in your
  basement. A small scale VPS useful for an XMPP server can be very cheap,
  up to a three Euro per month. There exist even cheaper options, such as
  &lt;a href="https://mrvm.net/lxc/"&gt;EUR 6 per year&lt;/a&gt;. There are also dedicated search engines
  to help locate cheap VPS, e.g. &lt;a href="https://lowendbox.com/category/virtual-servers,dedicated-servers,reseller-hosting,shared-hosting,special-offers,seedbox-offers,community-offers,vpn/"&gt;LowendBox&lt;/a&gt;
  and &lt;a href="https://www.serverhunter.com/#query=stock%3Ain_stock+virtualization%3A%28none+OR+hyperv+OR+kvm+OR+lxc+OR+xen+OR+vmware%29"&gt;ServerHunter&lt;/a&gt;.
  A typical operating system running on the server is Linux (very secure,
  highly configurable, free and open source).&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Domain name&lt;/strong&gt; that needs to be used to connect to the XMPP server. Domain
  can be registered to the user (e.g. &lt;code&gt;myname.no&lt;/code&gt;), which costs about 30 Euro
  yearly. But a sub-domain can be obtained for free using the
  &lt;a href="https://freedns.afraid.org"&gt;https://freedns.afraid.org&lt;/a&gt; or similar "free
  DNS" services. In the later case you might have something like
  &lt;code&gt;myownchat.mooo.com&lt;/code&gt; or &lt;code&gt;myownchat.ptchat.net&lt;/code&gt;. Other free DNS options include
  &lt;a href="https://docs.github.com/en/pages/getting-started-with-github-pages/creating-a-github-pages-site"&gt;Github pages&lt;/a&gt;, 
  &lt;a href="https://nic.eu.org/"&gt;EU.org&lt;/a&gt;, &lt;a href="https://is-a.dev/"&gt;is-a.dev&lt;/a&gt;, 
  and &lt;a href="https://www.duckdns.org/"&gt;DuckDNS&lt;/a&gt;.  It is possible to run the XMPP
  server purely on IP address even without domain name, but it is much less
  convenient (e.g. then federation with other servers is lost).&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Given you have got a server (VPS or dedicated machine) and the domain,
configuring an XMPP server can be done on 1-2-3. There exist several Linux
variants (distributives) with different management commands (usually for
installing software). I assume &lt;strong&gt;&lt;a href="https://www.debian.org/"&gt;Debian Linux&lt;/a&gt;&lt;/strong&gt;
is used below (the same commands also work for Ubuntu and other Debian-based
Linux systems).&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Grab a working configuration template and adjust according to your domain 
name and IP address:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Example configuration: &lt;a href="images/ejabberd.yml"&gt;ejabberd.yml&lt;/a&gt; &lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;GitHub: &lt;a href="https://github.com/sbudaev/xmpp-1-2-3"&gt;https://github.com/sbudaev/xmpp-1-2-3&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;h2&gt;1. Install XMPP server software&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Login.&lt;/strong&gt; When you have got a server of any kind, you need to&lt;strong&gt;login&lt;/strong&gt;
to it, typically with &lt;code&gt;ssh&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;ssh debian@1.2.3.4
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;here the user name on the server is &lt;code&gt;debian&lt;/code&gt; and the server ip
is &lt;code&gt;1.2.3.4&lt;/code&gt;.  Typically, you may need to create the ssh key and
upload it to the server to authenticate (refer the server documentation, e.g.
&lt;a href="https://www.digitalocean.com/community/tutorials/how-to-configure-ssh-key-based-authentication-on-a-linux-server"&gt;this&lt;/a&gt;).
I assume logging-in is not a problem.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Prepare server.&lt;/strong&gt; First of all, update the software on the new server&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;sudo apt update -y &lt;span class="o"&gt;&amp;amp;&amp;amp;&lt;/span&gt; sudo apt-get upgrade -y
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Install some useful monitoring and security-enhancing utilities&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;sudo apt install -y mc htop atop nload nmon tree zip pwgen fail2ban dnsutils iptables-persistent locate unattended-upgrades
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Install &lt;a href="https://certbot.eff.org/"&gt;certbot&lt;/a&gt;, a system that manages the
&lt;a href="https://en.wikipedia.org/wiki/Public_key_certificate"&gt;TLS certificates&lt;/a&gt;
for secure connection&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;sudo apt -y install certbot
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;&lt;strong&gt;Install the &lt;a href="https://www.ejabberd.im/"&gt;ejabberd&lt;/a&gt; server,&lt;/strong&gt; which is is very
reliable and light on resources. It is also very secure, with few
vulnerabilities found for years (see
&lt;a href="https://www.cvedetails.com/vulnerability-list/vendor_id-4455/product_id-7709/Process-one-Ejabberd.html"&gt;this&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;&lt;img alt="ejabberd https://repo.process-one.net/" src="images/ejabberd-logo-rounded-index.png" title="ejabberd https://repo.process-one.net/"&gt;&lt;/p&gt;
&lt;p&gt;It is &lt;strong&gt;strongly recommended&lt;/strong&gt; to install ejabberd &lt;strong&gt;package repository&lt;/strong&gt; as explained 
here: &lt;a href="https://repo.process-one.net/"&gt;https://repo.process-one.net/&lt;/a&gt;. Then ejabberd
software will automatically update without need to download every new version from
the site (use standard Debian command as &lt;code&gt;sudo apt update &amp;amp;&amp;amp; sudo apt upgrade&lt;/code&gt;).&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;sudo apt install ejabberd
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;&lt;strong&gt;Firewall.&lt;/strong&gt; To allow incoming network access to this server by the XMPP
clients and also third-party servers, the server needs to configure
the &lt;strong&gt;firewall rules.&lt;/strong&gt; This can be done differently in different
installations. For example, some VPS may do this using a friendly web
interface. The standard Linux firewall is done via &lt;code&gt;iptables&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;The XMPP system requires incoming acces via ports 5222, 5223, 5269, 5443,
5280, 3478. To determine the ports refer to the listen section of the XMPP
configuration file below.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt; sudo iptables -A INPUT -p tcp --dport &lt;span class="m"&gt;5222&lt;/span&gt; -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
 sudo iptables -A INPUT -p tcp --dport &lt;span class="m"&gt;5223&lt;/span&gt; -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
 sudo iptables -A INPUT -p tcp --dport &lt;span class="m"&gt;5269&lt;/span&gt; -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
 sudo iptables -A INPUT -p tcp --dport &lt;span class="m"&gt;5443&lt;/span&gt; -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
 sudo iptables -A INPUT -p tcp --dport &lt;span class="m"&gt;5280&lt;/span&gt; -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT

 &lt;span class="c1"&gt;# STUN is over udp&lt;/span&gt;
 sudo iptables -A INPUT -p udp --dport &lt;span class="m"&gt;3478&lt;/span&gt; -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;&lt;a name="bytestream"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;The port 7777 is used for a proxy for peer-to-peer (bytestream) file
transfer. If peer-to-peer file sharing  is intended for use, an additional
rule should be set allowing incoming connections:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;sudo iptables -A INPUT -p tcp --dport &lt;span class="m"&gt;7777&lt;/span&gt; -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;To see what firewall rules are in effect issue this:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt; iptables -L --line-numbers
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;It makes sense to save the iptables rules so they are automatically get in
effect after reboot&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt; iptables-save &amp;gt; /etc/iptables/rules.v4
&lt;/pre&gt;&lt;/div&gt;


&lt;h2&gt;2. Configure your XMPP server&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Secure connection certificate.&lt;/strong&gt; Get a free
&lt;a href="https://letsencrypt.org/"&gt;Let's Encrypt&lt;/a&gt;
&lt;a href="https://en.wikipedia.org/wiki/Transport_Layer_Security"&gt;TLS certificate&lt;/a&gt;.
I assume you have got a free domain &lt;code&gt;myownchat.ptchat.net&lt;/code&gt; from
&lt;a href="https://freedns.afraid.org"&gt;https://freedns.afraid.org&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;XMPP server will iideally need several subdomains (although may work with 
a single domain). In our case these are the following:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;primary domain name: &lt;code&gt;myownchat.ptchat.net&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;conference: &lt;code&gt;conference.myownchat.ptchat.net&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;proxy: &lt;code&gt;proxy.myownchat.ptchat.net&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;pubsub: &lt;code&gt;pubsub.myownchat.ptchat.net&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;upload: &lt;code&gt;upload.myownchat.ptchat.net&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;blockquote&gt;
&lt;p&gt;Note that ejabberd can manage (issue and update) TLS certificates on its
own, but this needs some configuration as described in the
&lt;code&gt;acme&lt;/code&gt; configuration option:
&lt;a href="https://docs.ejabberd.im/admin/configuration/basic/#acme"&gt;https://docs.ejabberd.im/admin/configuration/basic/#acme&lt;/a&gt;.
An advantage of the standalone certificate management system (as here) is
that it is slightly less tricky and can easily be used with a
&lt;strong&gt;web server&lt;/strong&gt; on the same machine.
Why not also configure a web server for a small static web site here?
Ejabberd is very lightweight and will happily coexist with many other
servers running on the same machine.
If a stand-alone XMPP server is required, check out the last section of 
this post on configuring acme. For now, do not configure TLS certificates
&lt;code&gt;certfiles:&lt;/code&gt; in the ejabberd.yml file, leave them as is with the default
cerrtificates.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Before requesting certificate, you must be sure that incoming connections on 
the port 80 of the server are not blocked by firewall. If this is
not so (port closed), use the following command:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;sudo iptables -A INPUT -p tcp --dport &lt;span class="m"&gt;80&lt;/span&gt; -m conntrack --ctstate NEW,ESTABLISHED -j ACCEPT
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Do not forget to save iptables rules with the &lt;code&gt;iptables-save&lt;/code&gt; as above.&lt;/p&gt;
&lt;p&gt;Now, it is time to request the certificate. Do this (minimal) command:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;sudo certbot --standalone certonly -d myownchat.ptchat.net
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;or for all subdomains domains (strongly recommended!):&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;sudo certbot --standalone certonly -d myownchat.ptchat.net -d conference.myownchat.ptchat.net -d proxy.myownchat.ptchat.net -d pubsub.myownchat.ptchat.net -d upload.myownchat.ptchat.net
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;(note that the above is one line)&lt;/p&gt;
&lt;p&gt;This command will ask a few questions and issue a TLS certificate. &lt;/p&gt;
&lt;p&gt;The certificate files are located in
&lt;code&gt;/etc/letsencrypt/live/myownchat.ptchat.net/fullchain.pem&lt;/code&gt; directory.&lt;/p&gt;
&lt;p&gt;For the sake of security, the certificate directories have by default no
access to anyone except the admin (root) user. But this precludes the XMPP
server ejabberd to access the certificate. This can be easily fixed with the
following commands&lt;/p&gt;
&lt;p&gt;First, add ejabberd to the root group&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;sudo adduser ejabberd root
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Second, allow access to the certificate directories to the group&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;sudo chmod g+rx /etc/letsencrypt/live/myownchat.ptchat.net
sudo chmod g+rx /etc/letsencrypt/live
sudo chmod g+rx /etc/letsencrypt/
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;&lt;strong&gt;Configure ejabberd.&lt;/strong&gt; Once the preparations are done, it is time to
&lt;em&gt;configure the ejabberd&lt;/em&gt; messaging server.  Edit the configuration file
(assuming the &lt;em&gt;mcedit&lt;/em&gt; text editor is used)&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Check out example configuration here: &lt;a href="images/ejabberd.yml"&gt;ejabberd.yml&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;sudo mcedit /etc/ejabberd/ejabberd.yml
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;This is a long configuration file that may look scary. But in fact only a few
changes are required to make the server running with the default options. But
note that the indents are important, try to keep them as in the original file.&lt;/p&gt;
&lt;p&gt;Any line starting with &lt;code&gt;#&lt;/code&gt; is considered a comment, this can be easily used
to disable specific options by "commenting them out."&lt;/p&gt;
&lt;p&gt;First, set up the host name that is used for the server, it is the same as
the domain:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;hosts&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
  &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;myownchat.ptchat.net&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Second, configure the location of the TLS certificates that are used by the
server:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;certfiles&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
  &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;/etc/letsencrypt/live/myownchat.ptchat.net/fullchain.pem&amp;quot;&lt;/span&gt;
  &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;/etc/letsencrypt/live/myownchat.ptchat.net/privkey.pem&amp;quot;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Configure how user passwords are stored on the server. While the default is
plain text &lt;code&gt;plain&lt;/code&gt;, it is more secure to use &lt;code&gt;scram&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="l l-Scalar l-Scalar-Plain"&gt;auth_password_format&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;scram&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;(Check out the doc:&lt;a href="https://docs.ejabberd.im/admin/configuration/authentication/#supported-methods"&gt;https://docs.ejabberd.im/admin/configuration/authentication/#supported-methods&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;Configure the admin users who can manage the XMPP server:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;acl&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
   &lt;span class="l l-Scalar l-Scalar-Plain"&gt;admin&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;user&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
       &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;my_user_name@myownchat.ptchat.net&amp;quot;&lt;/span&gt;
       &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;@localhost&amp;quot;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Then, add configuration for http-file-upload module that will allow file
sharing (sending files):&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_http_upload&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;put_url&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;https://@HOST@:5443/upload&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;custom_headers&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="s"&gt;&amp;quot;Access-Control-Allow-Origin&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;https://@HOST@&amp;quot;&lt;/span&gt;
      &lt;span class="s"&gt;&amp;quot;Access-Control-Allow-Methods&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;GET,HEAD,PUT,OPTIONS&amp;quot;&lt;/span&gt;
      &lt;span class="s"&gt;&amp;quot;Access-Control-Allow-Headers&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;Content-Type&amp;quot;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;It is convenient to keep the latest messages on the server, it is done with
the "mam" module:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_mam&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
   &lt;span class="l l-Scalar l-Scalar-Plain"&gt;assume_mam_usage&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;
   &lt;span class="l l-Scalar l-Scalar-Plain"&gt;default&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;always&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Ejabberd supports several other communication protocols in addition to
XMPP. For example, it also works with &lt;a href="https://mqtt.org/"&gt;MQTT&lt;/a&gt; that is
typically used for IoT devices. If this functionality is not used,
just comment out the MQTT module to disable it.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt; &lt;span class="c1"&gt;# mod_mqtt: {}&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;The STUN and TURN protocol is mainly used for voice calls and needs the
actual IP address of the server (replace with your server IP addfress)&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt; &lt;span class="p p-Indicator"&gt;-&lt;/span&gt;
   &lt;span class="l l-Scalar l-Scalar-Plain"&gt;port&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;3478&lt;/span&gt;
   &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ip&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;::&amp;quot;&lt;/span&gt;
   &lt;span class="l l-Scalar l-Scalar-Plain"&gt;transport&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;udp&lt;/span&gt;
   &lt;span class="l l-Scalar l-Scalar-Plain"&gt;module&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ejabberd_stun&lt;/span&gt;
   &lt;span class="l l-Scalar l-Scalar-Plain"&gt;use_turn&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;
   &lt;span class="c1"&gt;## The server&amp;#39;s public IPv4 address:&lt;/span&gt;
   &lt;span class="l l-Scalar l-Scalar-Plain"&gt;turn_ipv4_address&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;1.2.3.4&amp;quot;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;&lt;a name="mod_register"&gt;&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;An important issue is wether to allow anonymous registrations of new users.
I strongly recommend not allowing this for security reasons. For a small
private server, you will normally add users manually and set them initial
passwords. Every user can then change password within the client program. So,
you need to disable access to the &lt;code&gt;mod_register&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_register&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="c1"&gt;## Only accept registration requests from the &amp;quot;trusted&amp;quot;&lt;/span&gt;
    &lt;span class="c1"&gt;## network (see access_rules section above).&lt;/span&gt;
    &lt;span class="c1"&gt;## Think twice before enabling registration from any&lt;/span&gt;
    &lt;span class="c1"&gt;## address. See the Jabber SPAM Manifesto for details:&lt;/span&gt;
    &lt;span class="c1"&gt;## https://github.com/ge0rg/jabber-spam-fighting-manifesto&lt;/span&gt;
    &lt;span class="c1"&gt;#ip_access: trusted_network&lt;/span&gt;
    &lt;span class="c1"&gt;## Allow change password by users&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;access&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;none&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;&lt;strong&gt;Start server!&lt;/strong&gt; &lt;em&gt;And that's all minimal configuration.&lt;/em&gt; Now it's time to
&lt;strong&gt;start the server:&lt;/strong&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;sudo systemctl start ejabberd
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;If there are any errors and the server fails to start, Linux logs can be
inspected with this command:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;sudo journalctl -xe
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;or logs for only ejabberd:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;sudo journalctl -xe --unit ejabberd
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;&lt;strong&gt;Additional stuff.&lt;/strong&gt; The above is enough to make the XMPP server running for
text. If voice is required, you need to configure the DNS as described here:
&lt;a href="https://www.process-one.net/blog/how-to-set-up-ejabberd-video-voice-calling/"&gt;https://www.process-one.net/blog/how-to-set-up-ejabberd-video-voice-calling/&lt;/a&gt;.
DNS is normally configured using the control panel of the domain registrar.&lt;/p&gt;
&lt;p&gt;The TLS certificate that is managed by &lt;a href="https://certbot.eff.org/"&gt;certbot&lt;/a&gt;
is updated each 90 days. This is an automatic process, but the ejabberd
server must know when certificate is changed. This can be done using the
deploy hook. Just create the hook file &lt;code&gt;reloadxmpp.sh&lt;/code&gt; (the file name can be
anything):&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt; sudo mcedit /etc/letsencrypt/renewal-hooks/deploy/reloadxmpp.sh
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;and add the following commands:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt; #!/bin/sh
 ejabberdctl reload_config
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;This file must be executable, so issue this command:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt; sudo chmod ugo+x /etc/letsencrypt/renewal-hooks/deploy/reloadxmpp.sh
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;The last note on the server is that it should be regularly updated for
bug fixes and security updates. This is done automatically by installing
&lt;code&gt;unattended-upgrades&lt;/code&gt; above. Yet, it is a good practice to log in regularly
over the ssh, check logs and update the system:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;sudo apt update -y &amp;amp;&amp;amp; sudo apt-get upgrade -y
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;There is a &lt;strong&gt;web admin panel&lt;/strong&gt; (enabled by &lt;code&gt;request_handlers:&lt;/code&gt; 
&lt;code&gt;"/admin": ejabberd_web_admin&lt;/code&gt; line in the configuration file at the address 
&lt;code&gt;https://myownchat.ptchat.net:5443/admin&lt;/code&gt;. Only the &lt;code&gt;admin&lt;/code&gt; user(s) have 
access to it. But it is very useful for controlling the system, such as adding 
new users or removing users.&lt;/p&gt;
&lt;h2&gt;3. Configure the XMPP users and client application&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Register new users.&lt;/strong&gt; First, you need to register the XMPP users. The
quickest method is to use the command line on the server, the command
&lt;code&gt;ejabberdctl&lt;/code&gt; has advanced functions.&lt;/p&gt;
&lt;p&gt;A secure random password can be generated withy &lt;code&gt;pwgen&lt;/code&gt;, e.g. the following
generates passwords with 18 symbols:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;pwgen 18
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;It normally generates an array of possible passwords to choose from.&lt;/p&gt;
&lt;p&gt;Now, to register the user &lt;code&gt;myname&lt;/code&gt;, It is the admin user configured in the main
configuration file &lt;code&gt;/etc/ejabberd/ejabberd.yml&lt;/code&gt; above.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;#                         user   domain               password
sudo ejabberdctl register myname myownchat.ptchat.net pee8chogh9Heel6hei
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Other users can be configured similarly. Note that the full user name for XMPP
has the same format se email: &lt;code&gt;myname@myownchat.ptchat.net&lt;/code&gt;. This is due to
the federated nature of both systems: you need to know both the user and
the server with whom to communicate.&lt;/p&gt;
&lt;p&gt;For this example let's register two additional users:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;sudo ejabberdctl register john.dow myownchat.ptchat.net ohyeeLeefo9yief4gu
sudo ejabberdctl register anna.karenina myownchat.ptchat.net hejo7phiy2iFeW9She
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;&lt;strong&gt;Use!&lt;/strong&gt; The final step is configure the client program on the
user's device. The biggest difficulty at this step is the plenty
of choice. For any major platform, one can choose any of &lt;a href="https://xmpp.org/software/"&gt;the many
available XMPP client programs&lt;/a&gt;. Some email
programs, e.g. &lt;a href="https://www.thunderbird.net"&gt;Thunderbird&lt;/a&gt; also support
XMPP (although only a limited subset of features). Check out the
&lt;a href="https://xmpp.org"&gt;https://xmpp.org&lt;/a&gt;. The configuration for the client
is simple:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Server:&lt;/strong&gt; your server, in the example above it is &lt;code&gt;myownchat.ptchat.net&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;User name:&lt;/strong&gt; your user name. In the example we used above, it can be
  &lt;code&gt;myname&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Note that the option to &lt;strong&gt;create new account&lt;/strong&gt; must &lt;strong&gt;NOT&lt;/strong&gt; be enabled as
long as the account has already been created on the sever and the in-band
registration (&lt;code&gt;mod_register&lt;/code&gt;, &lt;a href="#mod_register"&gt;see above&lt;/a&gt;) is disabled for
security.&lt;/p&gt;
&lt;p&gt;&lt;img alt="Pidgin configuration" src="images/xmpp-123-client.png" title="Pidgin configuration"&gt;
&lt;img alt="Thunderbird configuration" src="images/xmpp-123-thunderbird.png" title="Thunderbird configuration"&gt;
&lt;img alt="Conversations configuration" src="images/xmpp-123-convers.png" title="Conversations configuration"&gt;&lt;/p&gt;
&lt;p&gt;Some programs accept the full user name without specifying user and domain
separately. Then the user is just &lt;code&gt;myname@myownchat.ptchat.net&lt;/code&gt;. If you
plan to use the peer-to-peer (&lt;a href="#bytestream"&gt;bytestream&lt;/a&gt;) file transfer (but
this is not mandatory), you should also find where the file transfer proxy is
configured and set it with the &lt;code&gt;proxy&lt;/code&gt; subdomain, for our example it should be
&lt;code&gt;proxy.myownchat.ptchat.net&lt;/code&gt;. And that is all for basic client configuration.&lt;/p&gt;
&lt;p&gt;I recommend the &lt;a href="https://monocles.social/@monocles"&gt;Monocles&lt;/a&gt; XMPP application
for devices running Android. &lt;a href="https://www.yaxim.org/"&gt;Yaxim&lt;/a&gt; is the best option
for minimalists, it is notoriously miniature (only a few megabytes) and works
great even on the oldest and weakest devices. &lt;a href="https://gajim.org/"&gt;Gajim&lt;/a&gt;
is perhaps the best XMPP client for Windows and Linux. 
&lt;a href="https://miranda-ng.org/"&gt;Miranda NG&lt;/a&gt; is a powerful XMPP client program for 
Windows. There are also a few web-based clients: 
&lt;a href="https://conversejs.org/"&gt;https://conversejs.org/&lt;/a&gt; and 
&lt;a href="https://web.xabber.com/"&gt;https://web.xabber.com/&lt;/a&gt; that you can try right
away without installing anything. There is also a new cross-platform 
&lt;a href="https://www.process-one.net/fluux/"&gt;Fluux&lt;/a&gt; - check it out!&lt;/p&gt;
&lt;p&gt;The final step is to fill the contact list (called roster) with the addresses
of the people (or maybe devices, because XMPP can be easily configured for
bots accepting commands). Just remember that the address is full name as in
email: &lt;code&gt;user@server.domain&lt;/code&gt;. One useful option is so called &lt;a href="https://www.ejabberd.im/shared-roster-all/"&gt;Shared roster
groups&lt;/a&gt;: then you can configure
a group of contacts without the need to add them manually.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Happy chatting!&lt;/strong&gt;&lt;/p&gt;
&lt;h2&gt;Further&lt;/h2&gt;
&lt;p&gt;There are many advanced options and possibilities in ejabberd. Just check
the documentation at the official web site: &lt;a href="https://www.ejabberd.im/"&gt;https://www.ejabberd.im/&lt;/a&gt;
and documentation &lt;a href="https://docs.ejabberd.im/"&gt;https://docs.ejabberd.im/&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;There are also a few useful &lt;strong&gt;tutorials&lt;/strong&gt; that you may find useful e.g.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://www.process-one.net/blog/how-to-move-the-office-to-real-time-im-on-ejabberd/"&gt;https://www.process-one.net/blog/how-to-move-the-office-to-real-time-im-on-ejabberd/&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://www.codedge.de/posts/modern-messaging-running-your-own-xmpp-server"&gt;https://www.codedge.de/posts/modern-messaging-running-your-own-xmpp-server&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://medium.com/geekculture/how-to-setup-an-xmpp-server-for-private-messaging-dcb1f4740fe"&gt;https://medium.com/geekculture/how-to-setup-an-xmpp-server-for-private-messaging-dcb1f4740fe&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Secure connection for a stand-alone XMPP server&lt;/h2&gt;
&lt;p&gt;If you really like a stand-alone XMPP server that does not depend on certbot to
get and update TLS certificates, ejabberd configuration can proceed slightly
differently. Check outthis link:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://docs.ejabberd.im/admin/configuration/basic/#acme"&gt;https://docs.ejabberd.im/admin/configuration/basic/#acme&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;First, XMPP server will request the certificate and automatically update it
itself as needed. But server is normally running with limited rights and has no
access to the local port 80. No problem, port 80 can be forwarded using a few 
different tools. The simplest is sslh.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Port forwarding with sslh.&lt;/strong&gt; Install sslh with&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt; sudo apt install sslh
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Configure sslh to forward ports as needed, edit &lt;code&gt;/etc/default/sslh&lt;/code&gt; file:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt; DAEMON_OPTS=&amp;quot;--user sslh --listen 0.0.0.0:80 --listen 0.0.0.0:443  --http 127.0.0.1:5280 --ssl 127.0.0.1:5443 --xmpp 127.0.0.1:5223 --pidfile /var/run/sslh/sslh.pid&amp;quot;
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;This makes sslh listen on both ports 80 (unenctypted http) and 443 (encrypted
TLS) and forward the traffic depending on the protocol to the appropriate
software. Note that this configuration also forwards traffic from port 443 to
5223 for more resilient direct TLS connection. &lt;/p&gt;
&lt;p&gt;To enable the new configuration, restart sslh with &lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt; sudo systemctl restart sslh
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;&lt;strong&gt;Configure acme in ejabberd.&lt;/strong&gt; Now it's time to go the ejabberd configuration
'ejabberd.yml'&lt;/p&gt;
&lt;p&gt;Fixed certificates are not needed any more then, comment them 
out:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;#ca_file: /opt/ejabberd/conf/cacert.pem&lt;/span&gt;

&lt;span class="c1"&gt;#certfiles:&lt;/span&gt;
&lt;span class="c1"&gt;#  - /opt/ejabberd/conf/server.pem&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Now check go to the &lt;code&gt;listen&lt;/code&gt; part of the ejabberd configuration&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="l l-Scalar l-Scalar-Plain"&gt;listen&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;And make this config:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="l l-Scalar l-Scalar-Plain"&gt;listen&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;

&lt;span class="c1"&gt;# other congigs there&lt;/span&gt;

  &lt;span class="c1"&gt;# confugure for acme&lt;/span&gt;
  &lt;span class="p p-Indicator"&gt;-&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;port&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;5280&lt;/span&gt;
    &lt;span class="c1"&gt;#ip: &amp;quot;::&amp;quot;&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;module&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ejabberd_http&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;tls&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;false&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;request_handlers&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;/.well-known/acme-challenge&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ejabberd_acme&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Now go somewhere above module configurations (&lt;code&gt;modules:&lt;/code&gt;) and place the following&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;# ACME is enabled&lt;/span&gt;
&lt;span class="l l-Scalar l-Scalar-Plain"&gt;acme&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;auto&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;contact&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;mailto:postmaster@your_email.fqdn&amp;quot;&lt;/span&gt;
    &lt;span class="c1"&gt;## Staging environment&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ca_url&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;https://acme-staging-v02.api.letsencrypt.org/directory&lt;/span&gt;
    &lt;span class="c1"&gt;## Production environment (the default):&lt;/span&gt;
    &lt;span class="c1"&gt;#ca_url: https://acme-v02.api.letsencrypt.org/directory&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;This uncomments temporary staging environment for checking and comments out the
working config. Use it for initial tessting only.&lt;/p&gt;
&lt;p&gt;Restart server for the configuration change to take effect&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt; sudo systemctl restart ejabberd
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Now check that certificate request is working&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;ejabberdctl  request-certificate all
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;This will request certificates for all domains and subdomains&lt;/p&gt;
&lt;p&gt;If there are no errors, comment out the staging environment and enable the
production environment in the acme section:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;# ACME is enabled&lt;/span&gt;
&lt;span class="l l-Scalar l-Scalar-Plain"&gt;acme&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;auto&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;contact&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;mailto:postmaster@your_email.fqdn&amp;quot;&lt;/span&gt;
    &lt;span class="c1"&gt;## Staging environment&lt;/span&gt;
    &lt;span class="c1"&gt;#ca_url: https://acme-staging-v02.api.letsencrypt.org/directory&lt;/span&gt;
    &lt;span class="c1"&gt;## Production environment (the default):&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ca_url&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;https://acme-v02.api.letsencrypt.org/directory&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Restart server for the configuration change to take effect&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt; sudo systemctl restart ejabberd
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Now get the certificates!&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt; sudo ejabberdctl  request-certificate all
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Check the certificates with &lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt; sudo ejabberdctl list-certificates
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;If everythig went okay, ejabberd will care about TLS certificate update itself
in the future. It's all for this section.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Make file upload more resilent&lt;/strong&gt; Make use of port forwarding by sslh 443 to
5443 for XMPP file upload. This will help share files in restricted
environments that do not allow access to ports except 443.&lt;/p&gt;
&lt;p&gt;For this, go to the &lt;code&gt;mod_http_upload&lt;/code&gt; configuration and make a copy of the line
with the &lt;code&gt;put_url&lt;/code&gt; parameter as before and comment out the line with &lt;code&gt;:5443&lt;/code&gt;&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;  mod_http_upload:
    &lt;span class="c1"&gt;#put_url: https://@HOST@:5443/upload&lt;/span&gt;
    put_url: https://@HOST@/upload
    thumbnail: &lt;span class="nb"&gt;false&lt;/span&gt;
    access: &lt;span class="nb"&gt;local&lt;/span&gt;
    custom_headers:
      &lt;span class="s2"&gt;&amp;quot;Access-Control-Allow-Origin&amp;quot;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;quot;*&amp;quot;&lt;/span&gt;
      &lt;span class="s2"&gt;&amp;quot;Access-Control-Allow-Methods&amp;quot;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;quot;GET, POST, PUT, OPTIONS, DELETE&amp;quot;&lt;/span&gt;
      &lt;span class="s2"&gt;&amp;quot;Access-Control-Allow-Headers&amp;quot;&lt;/span&gt;: &lt;span class="s2"&gt;&amp;quot;Content-Type, Origin, X-Requested-With&amp;quot;&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Restart server to make this change to take effect&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt; sudo systemctl restart ejabberd
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Now try to connect and send file, if there are problems that are hard to fix,
you can revert port &lt;code&gt;5443&lt;/code&gt; use.&lt;/p&gt;
&lt;h2&gt;Simple web server&lt;/h2&gt;
&lt;p&gt;The stand-alone configuration of ejabberd allows slso to use it as a simple
stand-alone web server. Then, one needs to add a reference to the
&lt;code&gt;mod_http_fileserver&lt;/code&gt; module in the appropriate 'listen' section
&lt;code&gt;request_handlers&lt;/code&gt;. Best use port &lt;code&gt;5443&lt;/code&gt; that will forward from sslh &lt;code&gt;443&lt;/code&gt;.
Then common URL can be used to access the content.&lt;/p&gt;
&lt;p&gt;Here is an example, check out the last line. It shows that the URL starting
with just &lt;code&gt;/&lt;/code&gt; will be served by the &lt;code&gt;mod_http_fileserver&lt;/code&gt; module, efficiently
serving  &lt;em&gt;https://myownchat.ptchat.net:5443/&lt;/em&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;  &lt;span class="p p-Indicator"&gt;-&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;port&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;5443&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ip&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;::&amp;quot;&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;module&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ejabberd_http&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;tls&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;request_handlers&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="s"&gt;&amp;quot;/admin&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ejabberd_web_admin&lt;/span&gt;
      &lt;span class="c1"&gt;#&amp;quot;/api&amp;quot;: mod_http_api&lt;/span&gt;
      &lt;span class="s"&gt;&amp;quot;/bosh&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_bosh&lt;/span&gt;
      &lt;span class="c1"&gt;#&amp;quot;/captcha&amp;quot;: ejabberd_captcha&lt;/span&gt;
      &lt;span class="s"&gt;&amp;quot;/upload&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_http_upload&lt;/span&gt;
      &lt;span class="s"&gt;&amp;quot;/ws&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ejabberd_http_ws&lt;/span&gt;
      &lt;span class="c1"&gt;#&amp;quot;/oauth&amp;quot;: ejabberd_oauth&lt;/span&gt;
      &lt;span class="s"&gt;&amp;quot;/conversejs&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_conversejs&lt;/span&gt;
      &lt;span class="c1"&gt;# Web server configuration&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;/&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_http_fileserver&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Additionally, you also need to configure the &lt;code&gt;mod_http_fileserver&lt;/code&gt; module.
Below, the root will refer to the directory &lt;code&gt;/opt/www&lt;/code&gt; (&lt;code&gt;docroot&lt;/code&gt; parameter),
allowing use the browser address &lt;em&gt;https://myownchat.ptchat.net&lt;/em&gt;. Also, the
index files are defined by &lt;code&gt;directory_indices&lt;/code&gt; parameter: this is the name of
the file that is returned and shown by default. Such a configuration is an easy
way to make a launch page for the server with a hyperlink to the conversejs
&lt;em&gt;https://myownchat.ptchat.net/conversejs&lt;/em&gt;. Just place an appropriately written
&lt;code&gt;index.html&lt;/code&gt; into &lt;code&gt;/opt/www&lt;/code&gt;.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_http_fileserver&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;docroot&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;/&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;/opt/www&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;directory_indices&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;[&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;index.html&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;,&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;index.html&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;]&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Check out documentation here: &lt;a href="https://docs.ejabberd.im/admin/configuration/modules/#mod_http_fileserver"&gt;https://docs.ejabberd.im/admin/configuration/modules/#mod_http_fileserver&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Example configuration file&lt;/h2&gt;
&lt;p&gt;Here you can download an example configuration file for a &lt;strong&gt;stand-alone XMPP
server&lt;/strong&gt; that controls the acme-based update of TLS itself. Adapt it to your
needs.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Download example configuration: &lt;a href="images/ejabberd.yml"&gt;ejabberd.yml&lt;/a&gt; (or GitHub: &lt;a href="https://github.com/sbudaev/xmpp-1-2-3"&gt;https://github.com/sbudaev/xmpp-1-2-3&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Note that this configuration also enables &lt;strong&gt;conversejs&lt;/strong&gt; web interface and
&lt;strong&gt;http file server&lt;/strong&gt; for the landing page. &lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;Note that to make &lt;a href="https://en.wikipedia.org/wiki/OMEMO"&gt;OMEMO end-to end
encryption&lt;/a&gt; functional in the &lt;a href="https://conversejs.org/docs/html/index.html"&gt;ConverseJS&lt;/a&gt;
installation, you need to download the latest release from
&lt;a href="https://github.com/conversejs/converse.js/releases"&gt;https://github.com/conversejs/converse.js/releases&lt;/a&gt;
and place it somewhere on the server (the configuration uses path defined in
&lt;code&gt;conversejs_resources:&lt;/code&gt;, here&lt;code&gt;"/opt/lib/conversejs/package/dist"&lt;/code&gt;).  then
make subdirectory &lt;code&gt;/opt/lib/conversejs/package/dist/plugins&lt;/code&gt; and place all
&lt;code&gt;libsignal-protocol&lt;/code&gt; "js" files to &lt;code&gt;plugins&lt;/code&gt;. Check out documentation here:
&lt;a href="https://docs.ejabberd.im/admin/configuration/modules/#mod_conversejs"&gt;https://docs.ejabberd.im/admin/configuration/modules/#mod_conversejs&lt;/a&gt; &lt;/p&gt;
&lt;/blockquote&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="c1"&gt;###&lt;/span&gt;
&lt;span class="c1"&gt;###           ejabberd configuration file&lt;/span&gt;
&lt;span class="c1"&gt;###&lt;/span&gt;
&lt;span class="c1"&gt;### The parameters used in this configuration file are explained at&lt;/span&gt;
&lt;span class="c1"&gt;###&lt;/span&gt;
&lt;span class="c1"&gt;###       https://docs.ejabberd.im/admin/configuration&lt;/span&gt;
&lt;span class="c1"&gt;###&lt;/span&gt;
&lt;span class="c1"&gt;### The configuration file is written in YAML.&lt;/span&gt;
&lt;span class="c1"&gt;### *******************************************************&lt;/span&gt;
&lt;span class="c1"&gt;### *******           !!! WARNING !!!               *******&lt;/span&gt;
&lt;span class="c1"&gt;### *******     YAML IS INDENTATION SENSITIVE       *******&lt;/span&gt;
&lt;span class="c1"&gt;### ******* MAKE SURE YOU INDENT SECTIONS CORRECTLY *******&lt;/span&gt;
&lt;span class="c1"&gt;### *******************************************************&lt;/span&gt;
&lt;span class="c1"&gt;### Refer to http://en.wikipedia.org/wiki/YAML for the brief description.&lt;/span&gt;
&lt;span class="c1"&gt;###&lt;/span&gt;
&lt;span class="c1"&gt;### $Id: ejabberd.yml 1790 2026-03-14 15:30:37Z budaev $&lt;/span&gt;
&lt;span class="c1"&gt;###&lt;/span&gt;

&lt;span class="l l-Scalar l-Scalar-Plain"&gt;hosts&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
  &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;myownchat.ptchat.net&amp;quot;&lt;/span&gt;

&lt;span class="l l-Scalar l-Scalar-Plain"&gt;loglevel&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;info&lt;/span&gt;
&lt;span class="l l-Scalar l-Scalar-Plain"&gt;log_rotate_size&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;5242880&lt;/span&gt;
&lt;span class="l l-Scalar l-Scalar-Plain"&gt;log_rotate_count&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;4&lt;/span&gt;

&lt;span class="c1"&gt;# Default database type for a module lacking db_type option or if &lt;/span&gt;
&lt;span class="c1"&gt;# auth_method option is not set.&lt;/span&gt;
&lt;span class="l l-Scalar l-Scalar-Plain"&gt;default_db&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mnesia&lt;/span&gt;

&lt;span class="c1"&gt;# The option defines in what format the users passwords are stored, plain text&lt;/span&gt;
&lt;span class="c1"&gt;# or in SCRAM format:&lt;/span&gt;
&lt;span class="c1"&gt;# scram: The password is not stored, only some information required to verify&lt;/span&gt;
&lt;span class="c1"&gt;# the hash provided by the client. It is impossible to obtain the original&lt;/span&gt;
&lt;span class="c1"&gt;# plain password from the stored information; for this reason, when this value&lt;/span&gt;
&lt;span class="c1"&gt;# is configured it cannot be changed to plain anymore. This format allows&lt;/span&gt;
&lt;span class="c1"&gt;# clients to authenticate using: SASL PLAIN and SASL&lt;/span&gt;
&lt;span class="c1"&gt;# SCRAM-SHA-1/256/512(-PLUS). The SCRAM variant depends on the auth_scram_hash&lt;/span&gt;
&lt;span class="c1"&gt;# option.&lt;/span&gt;
&lt;span class="l l-Scalar l-Scalar-Plain"&gt;auth_password_format&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;scram&lt;/span&gt;

&lt;span class="c1"&gt;#ca_file: /opt/ejabberd/conf/cacert.pem&lt;/span&gt;

&lt;span class="c1"&gt;#certfiles:&lt;/span&gt;
&lt;span class="c1"&gt;#  - /opt/ejabberd/conf/server.pem&lt;/span&gt;

&lt;span class="l l-Scalar l-Scalar-Plain"&gt;listen&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
  &lt;span class="p p-Indicator"&gt;-&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;port&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;5222&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ip&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;::&amp;quot;&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;module&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ejabberd_c2s&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;max_stanza_size&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;262144&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;shaper&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;c2s_shaper&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;access&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;c2s&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;starttls_required&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;

  &lt;span class="c1"&gt;# Direct-TLS for C2S (XEP-0368). Good practice is to forward  traffic from&lt;/span&gt;
  &lt;span class="c1"&gt;# port 443 to 5223, possibly multiplexing with HTTP using e.g. sslh&lt;/span&gt;
  &lt;span class="c1"&gt;# [https://wiki.xmpp.org/web/Tech_pages/XEP-0368], so modern clients can&lt;/span&gt;
  &lt;span class="c1"&gt;# bypass restrictive firewalls (in airports, hotels, etc.).&lt;/span&gt;
  &lt;span class="p p-Indicator"&gt;-&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;port&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;5223&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ip&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;::&amp;quot;&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;module&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ejabberd_c2s&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;tls&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;max_stanza_size&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;65536&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;shaper&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;c2s_shaper&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;access&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;c2s&lt;/span&gt;
  &lt;span class="p p-Indicator"&gt;-&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;port&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;5269&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ip&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;::&amp;quot;&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;module&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ejabberd_s2s_in&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;max_stanza_size&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;524288&lt;/span&gt;
  &lt;span class="p p-Indicator"&gt;-&lt;/span&gt;
    &lt;span class="c1"&gt;## s2s with tls enforced&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;port&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;5270&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ip&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;::&amp;quot;&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;module&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ejabberd_s2s_in&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;max_stanza_size&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;524288&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;shaper&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;s2s_shaper&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;tls&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;
  &lt;span class="p p-Indicator"&gt;-&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;port&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;5443&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ip&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;::&amp;quot;&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;module&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ejabberd_http&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;tls&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;request_handlers&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="s"&gt;&amp;quot;/admin&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ejabberd_web_admin&lt;/span&gt;
      &lt;span class="c1"&gt;#&amp;quot;/api&amp;quot;: mod_http_api&lt;/span&gt;
      &lt;span class="s"&gt;&amp;quot;/bosh&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_bosh&lt;/span&gt;
      &lt;span class="c1"&gt;#&amp;quot;/captcha&amp;quot;: ejabberd_captcha&lt;/span&gt;
      &lt;span class="s"&gt;&amp;quot;/upload&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_http_upload&lt;/span&gt;
      &lt;span class="s"&gt;&amp;quot;/ws&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ejabberd_http_ws&lt;/span&gt;
      &lt;span class="c1"&gt;#&amp;quot;/oauth&amp;quot;: ejabberd_oauth&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;/conversejs&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_conversejs&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;/&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_http_fileserver&lt;/span&gt;

  &lt;span class="c1"&gt;# confugure for acme&lt;/span&gt;
  &lt;span class="p p-Indicator"&gt;-&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;port&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;5280&lt;/span&gt;
    &lt;span class="c1"&gt;#ip: &amp;quot;::&amp;quot;&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;module&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ejabberd_http&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;tls&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;false&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;request_handlers&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;/.well-known/acme-challenge&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ejabberd_acme&lt;/span&gt;

  &lt;span class="c1"&gt;# needed for audio/video, see&lt;/span&gt;
  &lt;span class="c1"&gt;# https://gist.github.com/iNPUTmice/a28c438d9bbf3f4a3d4c663ffaa224d9#notes-for-server-admins&lt;/span&gt;
  &lt;span class="p p-Indicator"&gt;-&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;port&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;3478&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ip&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;::&amp;quot;&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;transport&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;udp&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;module&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ejabberd_stun&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;use_turn&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;
    &lt;span class="c1"&gt;## The server&amp;#39;s public IPv4 address:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;turn_ipv4_address&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;111.222.333.444&amp;quot;&lt;/span&gt;
    &lt;span class="c1"&gt;## The server&amp;#39;s public IPv6 address:&lt;/span&gt;
    &lt;span class="c1"&gt;# turn_ipv6_address: &amp;quot;2001:db8::3&amp;quot;&lt;/span&gt;

&lt;span class="c1"&gt;#  -&lt;/span&gt;
&lt;span class="c1"&gt;#    port: 1883&lt;/span&gt;
&lt;span class="c1"&gt;#    ip: &amp;quot;::&amp;quot;&lt;/span&gt;
&lt;span class="c1"&gt;#    module: mod_mqtt&lt;/span&gt;
&lt;span class="c1"&gt;#    backlog: 1000&lt;/span&gt;

&lt;span class="c1"&gt;## Disabling digest-md5 SASL authentication. digest-md5 requires plain-text&lt;/span&gt;
&lt;span class="c1"&gt;### password storage (see auth_password_format option).&lt;/span&gt;
&lt;span class="l l-Scalar l-Scalar-Plain"&gt;disable_sasl_mechanisms&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
  &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;digest-md5&amp;quot;&lt;/span&gt;
  &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;X-OAUTH2&amp;quot;&lt;/span&gt;

&lt;span class="l l-Scalar l-Scalar-Plain"&gt;s2s_use_starttls&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;required&lt;/span&gt;

&lt;span class="l l-Scalar l-Scalar-Plain"&gt;acl&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;local&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;user_regexp&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;&amp;quot;&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;loopback&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ip&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;127.0.0.0/8&lt;/span&gt;
      &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;::1/128&lt;/span&gt;
      &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;::FFFF:127.0.0.1/128&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;admin&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;user&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
       &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;my_user_name@myownchat.ptchat.net&amp;quot;&lt;/span&gt;
       &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;@localhost&amp;quot;&lt;/span&gt;

&lt;span class="l l-Scalar l-Scalar-Plain"&gt;access_rules&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;local&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;allow&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;local&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;c2s&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;deny&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;blocked&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;allow&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;all&lt;/span&gt;
  &lt;span class="c1"&gt;## Only admins can send announcement messages:&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;announce&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;allow&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;admin&lt;/span&gt;
  &lt;span class="c1"&gt;## Only admins can use the configuration interface:&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;configure&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;allow&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;admin&lt;/span&gt;
  &lt;span class="c1"&gt;## Only accounts of the local ejabberd server can create rooms:&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;muc_create&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;allow&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;local&lt;/span&gt;
  &lt;span class="c1"&gt;## Only accounts on the local ejabberd server can create Pubsub nodes:&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;pubsub_createnode&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;allow&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;local&lt;/span&gt;
  &lt;span class="c1"&gt;## Only allow to register from localhost&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;trusted_network&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;allow&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;loopback&lt;/span&gt;

&lt;span class="l l-Scalar l-Scalar-Plain"&gt;api_permissions&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
  &lt;span class="s"&gt;&amp;quot;webadmin&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;from&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ejabberd_web_admin&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;who&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;access&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
        &lt;span class="l l-Scalar l-Scalar-Plain"&gt;allow&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
          &lt;span class="l l-Scalar l-Scalar-Plain"&gt;acl&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;admin&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;what&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;*&amp;quot;&lt;/span&gt;    
  &lt;span class="s"&gt;&amp;quot;console&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;commands&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;from&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ejabberd_ctl&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;who&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;all&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;what&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;*&amp;quot;&lt;/span&gt;
  &lt;span class="s"&gt;&amp;quot;admin&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;access&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;who&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;access&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
        &lt;span class="l l-Scalar l-Scalar-Plain"&gt;allow&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
          &lt;span class="l l-Scalar l-Scalar-Plain"&gt;acl&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;loopback&lt;/span&gt;
          &lt;span class="l l-Scalar l-Scalar-Plain"&gt;acl&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;admin&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;oauth&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
        &lt;span class="l l-Scalar l-Scalar-Plain"&gt;scope&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;ejabberd:admin&amp;quot;&lt;/span&gt;
        &lt;span class="l l-Scalar l-Scalar-Plain"&gt;access&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
          &lt;span class="l l-Scalar l-Scalar-Plain"&gt;allow&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
            &lt;span class="l l-Scalar l-Scalar-Plain"&gt;acl&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;loopback&lt;/span&gt;
            &lt;span class="l l-Scalar l-Scalar-Plain"&gt;acl&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;admin&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;what&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;*&amp;quot;&lt;/span&gt;
      &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;!stop&amp;quot;&lt;/span&gt;
      &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;!start&amp;quot;&lt;/span&gt;
  &lt;span class="s"&gt;&amp;quot;public&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;commands&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;who&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ip&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;127.0.0.1/8&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;what&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;status&lt;/span&gt;
      &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;connected_users_number&lt;/span&gt;

&lt;span class="l l-Scalar l-Scalar-Plain"&gt;shaper&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;normal&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;1000&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;fast&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;50000&lt;/span&gt;

&lt;span class="l l-Scalar l-Scalar-Plain"&gt;shaper_rules&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;max_user_sessions&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;10&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;max_user_offline_messages&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;5000&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;admin&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;100&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;all&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;c2s_shaper&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;none&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;admin&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;normal&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;all&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;s2s_shaper&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;fast&lt;/span&gt;

&lt;span class="l l-Scalar l-Scalar-Plain"&gt;max_fsm_queue&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;10000&lt;/span&gt;

&lt;span class="c1"&gt;# ACME is ensabled&lt;/span&gt;
&lt;span class="l l-Scalar l-Scalar-Plain"&gt;acme&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;auto&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;contact&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;mailto:postmaster@your_email.fqdn&amp;quot;&lt;/span&gt;      
    &lt;span class="c1"&gt;## Staging environment&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;ca_url&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;https://acme-staging-v02.api.letsencrypt.org/directory&lt;/span&gt;
    &lt;span class="c1"&gt;## Production environment (the default):&lt;/span&gt;
    &lt;span class="c1"&gt;#ca_url: https://acme-v02.api.letsencrypt.org/directory&lt;/span&gt;

&lt;span class="l l-Scalar l-Scalar-Plain"&gt;modules&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_adhoc&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_admin_extra&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_auth_fast&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;token_lifetime&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;14day&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_announce&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;access&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;announce&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_avatar&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_block_strangers&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;log&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_blocking&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_bosh&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_conversejs&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;websocket_url&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;auto&lt;/span&gt;
    &lt;span class="c1"&gt;#conversejs_css: https://cdn.conversejs.org/12.0.0/dist/converse.min.css&lt;/span&gt;
    &lt;span class="c1"&gt;#conversejs_css: https://cdn.conversejs.org/12.0.0/dist/converse.css&lt;/span&gt;
    &lt;span class="c1"&gt;#conversejs_script: https://cdn.conversejs.org/12.0.0/dist/converse.min.js&lt;/span&gt;
    &lt;span class="c1"&gt;#conversejs_script: https://cdn.conversejs.org/12.0.0/dist/converse.js&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;conversejs_resources&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;/opt/lib/conversejs/package/dist&amp;quot;&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;conversejs_plugins&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;[&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;libsignal-protocol.min.js&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;]&lt;/span&gt;
    &lt;span class="c1"&gt;#conversejs_plugins: [&amp;quot;libsignal-protocol.js&amp;quot;]&lt;/span&gt;
    &lt;span class="c1"&gt;# File path is: /opt/lib/conversejs/package/dist/plugins/libsignal-protocol.min.js&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;conversejs_options&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;default_domain&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;myownchat.ptchat.net&amp;quot;&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;embed_3rd_party_media_players&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;enable_smacks&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;auto_away&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;30&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;auto_reconnect&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;synchronize_availability&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;false&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;message_carbons&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;omemo_default&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;show_images_inline&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;clear_cache_on_logout&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;false&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;i18n&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;ru&amp;quot;&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;locked_domain&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;@HOST@&amp;quot;&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;message_archiving&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;always&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;auto_list_rooms&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;auto_join_on_invite&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;theme&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;dracula&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_caps&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_carboncopy&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_client_state&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_configure&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_disco&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_s2s_bidi&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_fail2ban&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_http_api&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_http_upload&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="c1"&gt;#put_url: https://@HOST@:5443/upload&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;put_url&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;https://@HOST@/upload&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;docroot&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;/var/ejabberd/upload&amp;quot;&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;thumbnail&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;false&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;access&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;local&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;custom_headers&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="s"&gt;&amp;quot;Access-Control-Allow-Origin&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;*&amp;quot;&lt;/span&gt;
      &lt;span class="s"&gt;&amp;quot;Access-Control-Allow-Methods&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;GET,&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;POST,&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;PUT,&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;OPTIONS,&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;DELETE&amp;quot;&lt;/span&gt;
      &lt;span class="s"&gt;&amp;quot;Access-Control-Allow-Headers&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;Content-Type,&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;Origin,&lt;/span&gt;&lt;span class="nv"&gt; &lt;/span&gt;&lt;span class="s"&gt;X-Requested-With&amp;quot;&lt;/span&gt;
  &lt;span class="c1"&gt;# Configure fileserver serving lounching page&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_http_fileserver&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;docroot&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;/&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;/opt/www&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;directory_indices&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;[&lt;/span&gt;&lt;span class="s"&gt;&amp;quot;index.html&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;,&lt;/span&gt; &lt;span class="s"&gt;&amp;quot;index.html&amp;quot;&lt;/span&gt;&lt;span class="p p-Indicator"&gt;]&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;accesslog&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;/var/log/ejabberd/access.log&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_last&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_mam&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="c1"&gt;## Mnesia is limited to 2GB, better to use an SQL backend&lt;/span&gt;
    &lt;span class="c1"&gt;## For small servers SQLite is a good fit and is very easy&lt;/span&gt;
    &lt;span class="c1"&gt;## to configure. Uncomment this when you have SQL configured:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;db_type&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mnesia&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;assume_mam_usage&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;default&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;always&lt;/span&gt;
  &lt;span class="c1"&gt;# mod_mqtt: {}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_muc&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;access&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;allow&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;access_admin&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;allow&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;admin&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;access_create&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;muc_create&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;access_persistent&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;muc_create&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;access_mam&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;allow&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;default_room_options&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;allow_subscription&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;  &lt;span class="c1"&gt;# enable MucSub&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mam&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_muc_admin&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_muc_log&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_muc_occupantid&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_offline&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;access_max_user_messages&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;max_user_offline_messages&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_ping&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_privacy&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_private&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_proxy65&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;access&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;local&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;max_connections&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;50&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_pubsub&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;access_createnode&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;pubsub_createnode&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;plugins&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;flat&lt;/span&gt;
      &lt;span class="p p-Indicator"&gt;-&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;pep&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;force_node_config&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
      &lt;span class="c1"&gt;#&amp;quot;eu.siacs.conversations.axolotl.*&amp;quot;:&lt;/span&gt;
      &lt;span class="c1"&gt;#  access_model: open&lt;/span&gt;
      &lt;span class="c1"&gt;## Avoid buggy clients to make their bookmarks public&lt;/span&gt;
      &lt;span class="l l-Scalar l-Scalar-Plain"&gt;storage:bookmarks&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
        &lt;span class="l l-Scalar l-Scalar-Plain"&gt;access_model&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;whitelist&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_push&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_push_keepalive&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_register&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="c1"&gt;## Only accept registration requests from the &amp;quot;trusted&amp;quot;&lt;/span&gt;
    &lt;span class="c1"&gt;## network (see access_rules section above).&lt;/span&gt;
    &lt;span class="c1"&gt;## Think twice before enabling registration from any&lt;/span&gt;
    &lt;span class="c1"&gt;## address. See the Jabber SPAM Manifesto for details:&lt;/span&gt;
    &lt;span class="c1"&gt;## https://github.com/ge0rg/jabber-spam-fighting-manifesto&lt;/span&gt;
    &lt;span class="c1"&gt;#ip_access: trusted_network&lt;/span&gt;
    &lt;span class="c1"&gt;## Allow change password by users&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;access&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;none&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_roster&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;versioning&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;true&lt;/span&gt;
  &lt;span class="c1"&gt;# mod_s2s_dialback: {}&lt;/span&gt;
  &lt;span class="c1"&gt;# mod_s2s_bidi: {}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_shared_roster&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_stream_mgmt&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;resend_on_timeout&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;if_offline&lt;/span&gt;
  &lt;span class="c1"&gt;# mod_stun_disco -- needed for audio/video, see&lt;/span&gt;
  &lt;span class="c1"&gt;# https://gist.github.com/iNPUTmice/a28c438d9bbf3f4a3d4c663ffaa224d9#notes-for-server-admins&lt;/span&gt;
  &lt;span class="c1"&gt;# and also https://www.process-one.net/blog/how-to-set-up-ejabberd-video-voice-calling/&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_stun_disco&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_vcard&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_vcard_xupdate&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="p p-Indicator"&gt;{}&lt;/span&gt;
  &lt;span class="l l-Scalar l-Scalar-Plain"&gt;mod_version&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt;
    &lt;span class="l l-Scalar l-Scalar-Plain"&gt;show_os&lt;/span&gt;&lt;span class="p p-Indicator"&gt;:&lt;/span&gt; &lt;span class="l l-Scalar l-Scalar-Plain"&gt;false&lt;/span&gt;

&lt;span class="c1"&gt;### Local Variables:&lt;/span&gt;
&lt;span class="c1"&gt;### mode: yaml&lt;/span&gt;
&lt;span class="c1"&gt;### End:&lt;/span&gt;
&lt;span class="c1"&gt;#&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;</content><category term="Blog"></category><category term="wiki"></category><category term="Q&amp;A"></category><category term="XMPP"></category><category term="Jabber"></category><category term="chat"></category><category term="security"></category><category term="interoperability"></category></entry><entry><title>XMPP: en ideell direktemeldingssystem for et familie</title><link href="https://budaev.info/xmpp-en-ideell-direktemeldingssystem-for-et-familie.html" rel="alternate"></link><published>2023-02-06T17:00:00+01:00</published><updated>2022-11-01T17:00:00+01:00</updated><author><name>Sergey Budaev</name></author><id>tag:budaev.info,2023-02-06:/xmpp-en-ideell-direktemeldingssystem-for-et-familie.html</id><summary type="html">&lt;p&gt;Forskjellige meldingssystemer ble populær de siste tiårene. Den
meste kjente eksempler er Whatsapp, Facebook Messenger, Snapchat eller
Discord. Mange bruker dem uten å tenke bare fordi de ser praktiske ut og er
gratis. Kostnadene er imidlertid alvorlig: &lt;strong&gt;den er personvernkatastrofe.&lt;/strong&gt;
Brukere har ingen egenkontroll, så eieren kan endre alle funksjoner …&lt;/p&gt;</summary><content type="html">&lt;p&gt;Forskjellige meldingssystemer ble populær de siste tiårene. Den
meste kjente eksempler er Whatsapp, Facebook Messenger, Snapchat eller
Discord. Mange bruker dem uten å tenke bare fordi de ser praktiske ut og er
gratis. Kostnadene er imidlertid alvorlig: &lt;strong&gt;den er personvernkatastrofe.&lt;/strong&gt;
Brukere har ingen egenkontroll, så eieren kan endre alle funksjoner uten
at brukerne vilje. Disse tjenstene (platformene) er laget og fullstendig
kontrollert av store monopoler fokuserte på å suge alle slags av
brukerdata. Personvernkostnaden til store kommersielle direktmeldingssystemer
av er mye høyere enn brukervennligheten. De er &lt;strong&gt;bevisst laget for å være
gjensidig uforenlige&lt;/strong&gt;. En bruker av Whatsapp kan ikke sende en melding til
noen på Telegram eller Facebook. Bare se for deg at du hadde Telenor men kunne
ikke sende sms til noen på Telia, kun til sin eget system Telenor. Eller
se hvis du kunne ikke sende en epost fra Gmail til Yahoo. &lt;strong&gt;Det er helt dumt.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Nå, blant de populære systemene er det bare epost det eneste systemet på
internett som har ikke vært monopolisert. Og det er fortsett fordi epost
ikke er en &lt;em&gt;plattform&lt;/em&gt; (eller 'ecosystem'), men &lt;em&gt;åpen og federert protokoll&lt;/em&gt;
etter eget design. &lt;strong&gt;Alle kan konfigurere og kjøre egen mailserver og meldinger
skal sendes mellom evt. Alle kan velge mellom mange epost apper. Alle kan
legge til ytterligere funksjonalitet, slik at ende-til-ende kryptering,&lt;/strong&gt; men
&lt;strong&gt;interoperabilitet opprettholdes.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Protokoll betyr et sett med regler og konvensjoner for interoperabilitet,
ikke et enkelt komplett produkt.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt="xmpp logo" src="images/xmpp-logo.svg" title="XMPP logo"&gt;&lt;/p&gt;
&lt;p&gt;Men, det finnes en direktemeldingssystem som er like enkel å bruke
som Whatsapp, men mangler de fleste av problemene. Faktisk, er det
&lt;strong&gt;&lt;a href="https://xmpp.org/"&gt;XMPP&lt;/a&gt;&lt;/strong&gt;. Det er en åpen og federert protokoller
som epost. Alle kan ha egen server, så kan ha kontakt med noen på alle
serverer som helst, akkurat som epost eller mobil. I tillegg, kan alle også
velge mellom ulike app etter vilje: foretrekker du funksjonalitet,
eller skjønnhet eller bare det å være veldig lett... Det finnes også
flere XMPP serverer programvare å velge mellom, de fleste er gratis og
åpen kildekode. Med XMPP kan du få alt: &lt;strong&gt;direktemeldinger, filer, tale,
video, gruppechat, flere enheter&lt;/strong&gt;. Det er også flere typer av
&lt;strong&gt;ende-til-ende kryptering&lt;/strong&gt;
(&lt;a href="https://conversations.im/omemo/"&gt;OMEMO&lt;/a&gt;, &lt;a href="https://gnupg.org/"&gt;GPG&lt;/a&gt;,
&lt;a href="https://otr.im/"&gt;OTR&lt;/a&gt;) og mye mer. Det finnes enda en XMPP-basert
sosialnettverk: &lt;a href="https://movim.eu/"&gt;Movim&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;XMPP er ikke alene. Det finnes også en alternativ åpen og
federert protokoll: &lt;strong&gt;&lt;a href="https://matrix.org/"&gt;Matrix&lt;/a&gt;&lt;/strong&gt;. Men
sammenlignet med XMPP, har den flere mangler: (a) &lt;a href="https://github.com/libremonde-org/paper-research-privacy-matrix.org"&gt;problemer med
personvern&lt;/a&gt;
(selv om mange ikke bryr seg om det), (b) alvorlige ytelsesproblemer:
mens XMPP fungerer fint selv på den minste og billigste
&lt;a href="https://no.wikipedia.org/wiki/Virtuell_privat_server"&gt;VPS&lt;/a&gt;, Matrix
server krever mange gigabyter med RAM og stor diskplass, på denne grunn
er det dyrere i drift, også krever Matrix mye mer oppmerksomhet (f.eks. se
&lt;a href="https://disroot.org/it/blog/matrix-closure"&gt;her&lt;/a&gt;). Det kan være berettiget
i bedrifts- eller stororganisasjonsbruk, men ikke i hjemmebruk.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Så XMPP er ideell for å lage et helt privat kommunikasjonssystem
for et familie.&lt;/strong&gt; Du trenger bare dette:  (a) &lt;strong&gt;en server:&lt;/strong&gt; billigste
&lt;a href="https://no.wikipedia.org/wiki/Virtuell_privat_server"&gt;VPS&lt;/a&gt; eller enda
en Rasberry Pi boks vil fungere fint (f.eks ejabberd skal støtte
hundrevis brukere med dette nivå); (b) &lt;strong&gt;server programvare&lt;/strong&gt;
som kjøres alt: sjekke ut flere og velge selv, de mest populære er
&lt;a href="https://www.ejabberd.im/"&gt;ejabberd&lt;/a&gt; og &lt;a href="https://prosody.im/"&gt;Prosody&lt;/a&gt;;
(c) &lt;strong&gt;domenenavn&lt;/strong&gt; slik at brukere kan konnektere til: domenenavn er også
en del av brukernavn, som i epost, f. eks &lt;code&gt;alexander@johansson.me&lt;/code&gt; (&lt;a href="https://www.process-one.net/blog/how-to-set-up-ejabberd-video-voice-calling/"&gt;enkelt DNS
oppsett&lt;/a&gt;
trenges for å støtte tale og video); (d) hver bruker kan velge hvilken
&lt;strong&gt;&lt;a href="https://xmpp.org/software/"&gt;klientapp&lt;/a&gt;&lt;/strong&gt; som skal brukes (f. eks
&lt;a href="https://monal-im.org/"&gt;Monal&lt;/a&gt; eller &lt;a href="https://siskin.im/"&gt;Siskin IM&lt;/a&gt; på
iPhone). Og det er det.&lt;/p&gt;
&lt;p&gt;Nå må serveren konfigureres. Så kontrollerer du systemet fullt
ut! Du kan &lt;strong&gt;registrere så mange brukere at du trenger&lt;/strong&gt;, men for en
familieserver anbefaler jeg ikke å tillate åpen registrering av alle som
helst. For eksempel du kan registrere flere kontoer for en enkelt bruker
hvis nyttig (å bruke med forskjellige formål). Ingen mobilnummer kreves:
f.eks. trenger du ikke fem SIM-korter for fem brukere, faktisk ingen er
nødvendig. Det også anbefales å konfigurere &lt;strong&gt;‘Shared roster group’&lt;/strong&gt;
(delt brukerliste) for å unngå å legge til familiekontakter manuelt for
alle familiemedlemmer. &lt;strong&gt;Ende-til-ende kryptering&lt;/strong&gt; er ikke avgjørende
for din egen private server fordi transportkryptering (TLS) brukes alltid;
men det er lettere å konfigurere hvis du bruker flere enheter (mobil,
nettbrett, desktop, laptop, web-basert). Men det er bedre og sikrere å
bruke ende-til-ende kryptering til å kommunisere med noen på andre
offentlige servere.&lt;/p&gt;
&lt;p&gt;Og nå, når flere grupper har sine egne private servere, kan de
&lt;strong&gt;kommunisere fritt og sikkert&lt;/strong&gt;. For eksempel, det er nå lett
for &lt;code&gt;pappa@johansson.me&lt;/code&gt; å sende melding (eller video-ringe) til
&lt;code&gt;mattias@johansson.me&lt;/code&gt; (samme familier og på samme privat server) eller
til en venn &lt;code&gt;john@dowfamily.info&lt;/code&gt; eller enda alle som bruker &lt;a href="https://list.jabber.at/"&gt;hundrevis av
åpne gratis offentlige serverer&lt;/a&gt; f. eks &lt;code&gt;maria@jabber.no&lt;/code&gt;
(på &lt;a href="https://www.jabber.no/"&gt;Jabber Norge&lt;/a&gt;), &lt;code&gt;christian@jabber.de&lt;/code&gt;,
&lt;code&gt;oyvindharaldsson@tigase.org&lt;/code&gt; eller &lt;code&gt;nikolaibode@riseup.net&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;&lt;img alt="Federated network" src="images/federated.svg" title="Federated network"&gt;&lt;/p&gt;
&lt;p&gt;Det kan være vanskelig å velge den beste offentlige serveren. Men det finnes et
verktøy som viser hvilke funksjoner serverne støtter. For eksempel hvis
serveren du sjekker støtter &lt;strong&gt;"XEP-0363: HTTP File Upload"&lt;/strong&gt;, noe som er
avgjørende for å kunne dele filer enkelt. En annen viktig funksjon er
&lt;strong&gt;"XEP-0384: OMEMO Encryption"&lt;/strong&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Sjekk kompatibilitet og funksjoner her: &lt;a href="https://compliance.conversations.im/"&gt;https://compliance.conversations.im/&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Liste over offentlige serverer med 100% kompatibilitet: &lt;a href="https://compliance.conversations.im/api/compliant_servers/"&gt;https://compliance.conversations.im/api/compliant_servers/&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://providers.xmpp.net/"&gt;Offentlige XMPP tjensteleverandører&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Se &lt;a href="https://budaev.info/xmpp_clients_no.html"&gt;her&lt;/a&gt; for litt mer informasjon
  om &lt;a href="https://xmpp.org/"&gt;XMPP&lt;/a&gt;.&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Lenker&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://budaev.info/xmpp-server-on-1-2-3.html"&gt;XMPP server på 1-2-3&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://www.process-one.net/blog/how-to-move-the-office-to-real-time-im-on-ejabberd/"&gt;Hvordan å konfigurere XMPP server ejabberd&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://www.process-one.net/blog/ejabberd-xmpp-server-useful-configuration-steps/"&gt;Useful configuration steps for ejabberd&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://medium.com/geekculture/how-to-setup-an-xmpp-server-for-private-messaging-dcb1f4740fe"&gt;Hvordan å konfigurere XMPP Server Prosody&lt;/a&gt; eller
  &lt;a href="https://landchad.net/prosody/"&gt;Install Prosody&lt;/a&gt; eller &lt;a href="https://jacksonjs.github.io/2016/09/09/prosodyonpi/"&gt;Install Prosody on your Raspberry Pi&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://disroot.org/services/xmpp"&gt;Disroot.org&lt;/a&gt;&lt;/strong&gt; - en åpen XMPP server (100% standarder)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;&lt;a href="https://www.jabjab.de/"&gt;Jabjab.de&lt;/a&gt;&lt;/strong&gt; en åpen XMPP server med transporter til andre meldingssystemer (100% standarder)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://jabber.no"&gt;Jabber Norge&lt;/a&gt; - en åpen XMPP server fra Norge (anbefales ikke lenger pga manglende overholdelse av standarder og funksjoner)&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;</content><category term="XMPP"></category><category term="Jabber"></category><category term="chat"></category><category term="direktemelding"></category><category term="privacy"></category><category term="platform"></category><category term="federation"></category><category term="decentralized"></category></entry><entry><title>Intervju kristendom</title><link href="https://budaev.info/intervju-kristendom.html" rel="alternate"></link><published>2022-11-01T17:00:00+01:00</published><updated>2022-11-01T17:00:00+01:00</updated><author><name>Sergey Budaev</name></author><id>tag:budaev.info,2022-11-01:/intervju-kristendom.html</id><summary type="html">&lt;p&gt;Skolens intervju kristendom&lt;/p&gt;</summary><content type="html">&lt;p&gt;Jeg hadde en intervju med studenter av &lt;a href="https://www.stpaulgymnas.no/"&gt;St Paul
gymnas&lt;/a&gt;. Her er noen svar.&lt;/p&gt;
&lt;h2&gt;Hvordan å praktisere religionen?&lt;/h2&gt;
&lt;p&gt;Å praktisere religionen betyr at du leve med Gud i hjertet ditt. Først,
det er viktig å bare være god i livet og unngå noe som er dårlig. Unngå
synd og dårlige ting som er enda uten av synd. Men det er ikke nok å bare
ikke gjøre noe. Det er viktigste å gjøre god ting i livet for God hjelper
oss når vi gjøre det som er godt. Jeg tror det er den Guds ligning:&lt;/p&gt;
&lt;!--
E = i * G
--&gt;

&lt;p&gt;&lt;img src="https://latex.codecogs.com/svg.image?\large&amp;space;E&amp;space;=&amp;space;i&amp;space;\times&amp;space;&amp;space;G"&gt;&lt;/p&gt;
&lt;p&gt;her E er effekt som vi får, i er menneskers innsats og G er Gods nåde. Hvis
innsats er null, helt effekt er null selv når Gud er enig å hjelpe den
største (f.eks. G = 1,000,000). Tå eksempel av Jesus og følge Kristus i
hverdagen aktivt. Tenke om dette: I velkjente miraklet tok Kristus få brød
og fisk fra folk og multipliserte dem til flere tusen. Det var i stedet av å
skape brød ut av ingenting. Den hovedbetingelsen for miraklet var en gratis
gave og samarbeid fra få enkle mennesker. Vi vet ikke hvor mange mirakler
som ikke skjedde fordi noen bestemte seg å gjøre ingenting. Den G-leddet i
den formelen er det viktigst del. Så vi kan ikke gjøre mye uten av Kristus
nåde. Det betyr at vi trenger sakramenter og be å få den G-ledder. Vi
lever i verden og Gud er transcendent, Jesus er i himmelen, ikke her med
oss nå. Det betyr vi ikke får direkte opplevelse av Gud og kan ikke se,
spørre og kjenne hva er som Guds vill. Men vi har masse informasjon i
skriften og den hellige tradisjon. Kirken får det i kirkelige dokumenter,
Codex juris, og mange teologiske og filosofiske verk. Vi kan lære mye av
dette hellige vitenskap ved hjelp av vår egen sunn fornuft.&lt;/p&gt;
&lt;p&gt;Kort fortalt: å praktisere religionen inkluderer dette: (1) å få Guds
nåde ved sakrament og be, (2) lære hva er som god og Guds vilje ved
hellige vitenskap og rasjonalitet, (3) vare aktivt å følge det som er god
i hverdagen.&lt;/p&gt;
&lt;h2&gt;Hvilke sakramenter påvirker ditt liv mest og hvordan?&lt;/h2&gt;
&lt;p&gt;Nattverd, Eukaristen, er den sakrament vi kan få og har oftest. Det er
også det sakramentet som forbinder oss med Gud fysisk. Det er den eneste
sakrament som tillater oss å se på Gud, streife på Gud og akseptere Gud
fysisk. Men det er også den vanskeligste sakrament vi har.&lt;/p&gt;
&lt;p&gt;Det kan være vanskelig å forstå hvordan et lite stykke brød kan være
Kristi legeme. Men tenk om enkelt ting, f.eks. så enkle ting som en stol
vi seter på. Det kan vare laget av tre, eller jern eller plastikk eller
glass. Men hva vi se som materialet er helt uviktig. Hvordan vi behandler
og bruker stolen er helt uavhengig av materialet, men bare faktum at det er
an stol. Å forstå hva stolen er og av hvilken grunn det brukes og hva det
brukes, må vi resonnere ved hjelp av kognisjonen og abstraksjonen vår. Det
trenger litt høyere nivå av tenking enn bare se på det ytre utseende. Men
vi hittil ikke forvirrer en tre stol med vedtre. Nå tenke om en dyr som ikke
får slik abstraksjonsevnen. En fly eller maur som seter på en tre stol og
etterpå har en opplevelse av en plastikk stol skal tenke at denne er helt
forskjellige ting og har ingenting til felles. Men vi kan få det rart:
vi finner det helt åpenbart at denne to objekter tilhører til samme kategori.&lt;/p&gt;
&lt;p&gt;Samme skjer med hvordan kan vi se på Eukaristen. Gud er transcendent og ikke
en del av denne verden. Så vi selv kunne ikke se på, eller på annen måte
oppleve Gud. Vi selv kan ikke ha denne kapasiteten. Men Kristus kommer til
oss i denne sakrament fysisk, bruker den vanligste ting som er en del av vår
verden, så vi kan vi kan kommunisere og enda forene med transcendent. Men
for dette, vi ikke har vårt eget konsept og må abstrahere å forstå.&lt;/p&gt;
&lt;p&gt;Å vare et menneske betyr å forstå hva er den naturen av verden og tinger
vi lever med. Hvordan vi forstår det påvirker hvordan vi lever livet vart.&lt;/p&gt;
&lt;h2&gt;Hvis gud er allmektig, hvorfor tror du det er så mye ondt i verden?&lt;/h2&gt;
&lt;p&gt;Nøkkelen å forstå dette er frie vilje av mennesker.&lt;/p&gt;
&lt;p&gt;Det var en metafor av Gud som skaper, i ekstrem form Gud som urmaker. Her
Gods allmakt og allvitenhet kunne se ut til å peke at verden som Gud skapte
er idealt som en maskin. Da er det Gud som er den eneste skuespilleren. Dette
synet blir spesielt populært da mennesker utviklet enkelt fysiske vitenskap,
Newtons fysikk som er basert på streng årsak og virkning. Tenke om dette:
årsaken A forårsaker B. Her A bare styrer en fiksert og helt bestemt effekt
B, men B ikke har noe rolle. Da Gud er tenkt som den første og hovedårsaken
av alle ting i verden. Konsekvens av dette er at Gud tar alt ansvar. Så bare
faktum at det ar noe galt i verden betyr det er Gud som har forårsaket dette.&lt;/p&gt;
&lt;p&gt;Men God som bare skaper eller urmaker er en feil metafor. Dessuten, motsier
det det bibelske synet. I bibelen Gud er tenkt om som en far. Noen kan tror
det er et utdatert og primitivt syn, ikke vitenskapelig som vi nå trenger. Men
konsept av faren, den forelderen, tar den eneste essensen av Guds rolle.&lt;/p&gt;
&lt;p&gt;En urmaker lager maskinen for et bestemt formål. Maskinen gjør kun det som
er urmakers formål, ingenting mer. Maskinen er ikke en uavhengig "agent"
med egen aktivitet. Det også finnes ikke en rolle av kjærlighet.&lt;/p&gt;
&lt;p&gt;Forelderen er helt motsatt av det synet. Forelderen føder ut av kjærlighet,
ikke for en funksjon. Barnet er ikke en programmert robot, men en uavhengig
agent som bare lever sitt eget liv. Det betyr at barnet har egen frie vilje
som forelderen skal respektere og helt verdsette. Det også betyr at barnet har
lov til å feile og lære av sine feil. Dessuten, barnet har likt lov å ikke
lære av sine feil og enda å gå helt galt. Forelderen kan ikke gjøre har,
men gi råd og kanskje lide over barnets feil. Fordi barnet har frie vilje,
det kan ikke fikses, kun kureres.&lt;/p&gt;
&lt;p&gt;På samme måte, Gud lar oss å leve vårt eget liv slik vi bestemmer
selv. Det betyr våre feil har lov til å være enorme. Men det at vi har
fri vilje skaper vår verdi som mennesker. En programmert robot med liten
selvstendighet og kreativitet er en helt kjedelig og dumt skapning.&lt;/p&gt;
&lt;p&gt;En del av frie vilje er ikke en ting Gud har gatt oss mennesker. Hele
verden er skapt til å være uavhengig, ikke som en klokke eller noe andre
maskin. Verden er ikke skapt som en endelig ideell ting, men det kan utvikle
seg selvstendig. Det finnes eksempler i kvantefysikk: elementærpartikler
kan fungere uten noe streng årsakssammenheng. Men den beste eksempel
er Darwins evolusjon. Her levende former utvikler seg kreativt uten Guds
kontroll. Uavhengighet og fri vilje er Guds plan og gaven, men det er også
et tungt ansvar.&lt;/p&gt;</content><category term="Faith"></category><category term="Catholicism"></category><category term="interview"></category></entry><entry><title>Goodbye Gmail</title><link href="https://budaev.info/goodbye-gmail.html" rel="alternate"></link><published>2022-04-22T00:57:00+02:00</published><updated>2022-04-22T00:57:00+02:00</updated><author><name>Sergey Budaev</name></author><id>tag:budaev.info,2022-04-22:/goodbye-gmail.html</id><summary type="html">&lt;p&gt;I do not use Gmail as my principal email provider any more, bye Google&lt;/p&gt;</summary><content type="html">&lt;p&gt;The old good &lt;strong&gt;email&lt;/strong&gt; remains the most &lt;a href="https://utcc.utoronto.ca/~cks/space/blog/tech/EmailCriticalInfrastructure"&gt;critical digital communication tool&lt;/a&gt;.
What makes the venerable email so useful and sustainable
over the long time is its &lt;strong&gt;openness and standardization.&lt;/strong&gt; Email is radically
different from the modern "apps" which integrate all pieces of technology--the
server, the client, and the protocol--by a single monopolist provider. With
email, we are free to choose the server (provider) and client with any
combination. It provides enormous flexibility, added privacy  and
security. Indeed, the provider does not control my client and cannot add
backdoors; there is no monoculture of client software with all the related
security risks (any security vulnerability is global). Email is one of
the few pieces of technology that is very resistant against internet
censorship. Repressive state can easily block a web site and even force
an app store to remove an app
&lt;a href="https://www.theguardian.com/world/2021/sep/17/apple-and-google-accused-of-political-censorship-over-alexei-navalny-app"&gt;(as the Navalny's "Smart Voting")&lt;/a&gt;.
Also, an app store can delete it for any other bizarre reason. But it
is much more difficult to block a mailing list: it is easy to redeploy and
recreate it on a different server (without the users even noticing anything).
Furthermore, The user can easily create several different email-based
identities (e.g. a separate one for politically sensitive activity) which
adds anonymity. And anonymity means physical security in some countries.&lt;/p&gt;
&lt;p&gt;It is not surprising that many internet services use the email address
to register users, authenticate, restore password and other similar
purposes. &lt;strong&gt;Open, standardized&lt;/strong&gt; and &lt;strong&gt;decentralized&lt;/strong&gt; email is one of the most
critical technology everything else depends on. After all, the flexibility
offered by the email technology--the freedom to choose all pieces (provider,
client etc.) is just very very handy, at least for an advanced user (you
can add new features on top of what the provider realized, even against the
provider's will--isn't it convenient?).&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;The whole email technology is build around open protocols rather than a
centralized platform. This facilitates competition, makes for better and
fairer service and reduce possible impacts of malicious monopolists
(&lt;a href="https://knightcolumbia.org/content/protocols-not-platforms-a-technological-approach-to-free-speech"&gt;Masnick, 2019&lt;/a&gt;).&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Google's Gmail has long been one of the main pillars of email, millions used
to rely upon every day. We should praise Google for popularising email
as the basic mainstream technology among the masses. &lt;strong&gt;I started using Gmail
many years ago when it was in its "beta" and available only by invitation.&lt;/strong&gt;
At that time Gmail openness and unrestricted nature was just blazing. The
web interface was lightweight and not really cluttered with ugly banners,
unlike other email providers. There were ads but they were small and
unobtrusive. Gmail had long supported all the basic protocols (POP, IMAP,
SMTP) that allowed to use any standard compliant client software, and that
was available for free (some other providers were more greedy and allowed
this only on paid plans). &lt;strong&gt;Google's POP, IMAP and SMTP implementations&lt;/strong&gt;
have been (and still remain!) &lt;strong&gt;quite idiosyncratic, incomplete and not
really standard-compliant which caused various glitches&lt;/strong&gt; (e.g. message
deletion and default sorting are weird, I always hated Gmail's labels). But
this was bearable.&lt;/p&gt;
&lt;p&gt;The &lt;a href="https://en.wikipedia.org/wiki/Privacy_concerns_regarding_Google"&gt;serious privacy problems and threats of Gmail&lt;/a&gt;,
such as user email scanning for context-specific advertising
(&lt;a href="https://blog.google/products/gmail/g-suite-gains-traction-in-the-enterprise-g-suites-gmail-and-consumer-gmail-to-more-closely-align/"&gt;until 2017&lt;/a&gt;)
or
&lt;a href="https://www.forbes.com/sites/daveywinder/2020/02/28/google-confirms-new-ai-tool-scans-300-billion-gmail-attachments-every-week/?sh=7e744fc83edd"&gt;AI tool&lt;/a&gt;
which could provide access to some pieces of data to &lt;a href="https://protonmail.com/blog/google-privacy-problem/"&gt;third-party&lt;/a&gt;
&lt;a href="https://www.pcmag.com/news/google-apps-can-scan-and-share-your-gmail-data-with-consent"&gt;developers&lt;/a&gt;.
&lt;strong&gt;That is nearly a disaster that cannot be fixed because spying on the user's
data is at the heart of Google's business model.&lt;/strong&gt; But who cares as long as
it is free! I have long been using and promoting &lt;strong&gt;PGP&lt;/strong&gt; encryption which
could fix many of the privacy (and security) problems.
Yes, PGP is &lt;a href="https://sequoia-pgp.org/blog/2021/06/29/202106-yes-we-want-cryptographic-protection-for-email/"&gt;crucial for individuals and businesses&lt;/a&gt;
and yes, &lt;a href="https://doi.org/10.2478/popets-2021-0037"&gt;a motivated user can encrypt&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Gmail still remained free and relatively open while an alternative of
deploying private email server is time-consuming and tedious (e.g. ensuring
that emails from a tiny private server don't end up in spam folders of
intended recipients). I used to pay with some of my privacy to get the
usability and stability of Gmail.&lt;/p&gt;
&lt;p&gt;But over time I became increasingly concerned about the clear trend taken
by Google to make the open email more and more difficult to use outside of
the Google monopolistic ecosystem.  There are signs of the famous
&lt;strong&gt;&lt;a href="https://en.wikipedia.org/wiki/Embrace,_extend,_and_extinguish"&gt;embrace, extend, and extinguish&lt;/a&gt;&lt;/strong&gt;
strategy. &lt;a href="https://developers.google.com/gmail/api"&gt;Gmail API&lt;/a&gt; is featureful and powerful... but only if
you really need the complexity and like to play with the Google rules. If
you don't like to see ads, for example, and for this use a standard IMAP
mail client of your choice, your must suffer. If you need full PGP support on
a mobile client, never offered by Google, you are out of luck and have to
use an IMAP-based mobile app like Android &lt;a href="https://k9mail.app/"&gt;K-9 Mail&lt;/a&gt;
that requires sacrificing some usability.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Google tends to draw its users by all means into its browser, its
own apps and APIs to get more user's private data and show ads.&lt;/strong&gt; For
that matter, Google's security usability has become just terrible. The
intrusive access-blocks when a mobile user with an IMAP client moves across
IP addresses can drive anyone crazy... Access can be blocked even if the
user switches just to the next IP address within the same provider's IP
pool.&lt;/p&gt;
&lt;p&gt;&lt;img alt="Google security alert" src="images/google-security-block.png" title="Google security alert"&gt;&lt;/p&gt;
&lt;p&gt;I have to use VPN with fixed IP address to avoid these stupid blocks!&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;To help keep your account secure, Google will no longer support the use
of third-party apps or devices which ask you to sign in to your Google
Account using only your username and password. Instead, you’ll need
to sign in using Sign in with Google.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;The Google's insistence on rather complicated and heavyweight
&lt;a href="https://oauth.net/2/"&gt;OAuth2&lt;/a&gt;
&lt;a href="https://medium.com/securing/what-is-going-on-with-oauth-2-0-and-why-you-should-not-use-it-for-authentication-5f47597b2611"&gt;mechanism&lt;/a&gt;
for basic email client access (remember, most email programs do not require
you to enter your password every time, diminishing the risk of phishing)
is understandable only as a means to limit all uncontrollable third-party
clients. Yes, OAuth2 is logical for complex workflows of data access delegation
across multiple web-based services with different login/password combinations
(the "Auth" stands for &lt;a href="https://oauth.net/2/"&gt;authorization&lt;/a&gt;, not
&lt;a href="https://medium.com/securing/what-is-going-on-with-oauth-2-0-and-why-you-should-not-use-it-for-authentication-5f47597b2611"&gt;authentication&lt;/a&gt;).
Whenever I need access to &lt;strong&gt;my own emails&lt;/strong&gt; I need to &lt;a href="https://en.wikipedia.org/wiki/Authentication"&gt;authenticate&lt;/a&gt;
my identity granting &lt;strong&gt;full access&lt;/strong&gt;. But isn't OAuth2 client secret kept
on the device just as the username/password combination? Yet, limiting the
(power) users access to their &lt;strong&gt;own data&lt;/strong&gt; provides just an illusion of
security at a large cost to usability and compatibility.&lt;/p&gt;
&lt;p&gt;The Google's move to OAuth2 &lt;strong&gt;authorization&lt;/strong&gt; seem to point that
the &lt;strong&gt;Gmail-hosted emails do not belong to me any more.&lt;/strong&gt; My emails are now
&lt;strong&gt;owned by Google,&lt;/strong&gt; who just "authorizes" (delegates) me access to some of
the data without trusting me. &lt;strong&gt;This is not what I need from my private
communication.&lt;/strong&gt; Does Google pretend to "zero-trust" any third-party
apps? Maybe it doesn't trust its users (&lt;strong&gt;the owners&lt;/strong&gt; of their data),
assuming they are all idiots?&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;If you think your users are idiots, only idiots will use it [your service]. ---
&lt;a href="https://mail.gnome.org/archives/usability/2005-December/msg00021.html"&gt;Linus Torvalds&lt;/a&gt;&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;And there is another side effect: as Google increasingly deployed more and
more heavyweight frameworks and technologies, &lt;strong&gt;Gmail became very sluggish
and bloated.&lt;/strong&gt; It is cluttered and confusing, especially to those who don't
use it often enough to remember all the idiosyncrasies. And it's still poorly
adaptable to the user's needs. How can I get a fixed-width font for my plain
text message? Where is my favourite basic (and very fast) HTML web interface?&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Enough is enough. I now go away from Gmail, and primarily not because of
big privacy concerns (which is quite expectable) but because of deteriorating
usability and growing incompatibility. It looks like the people at Google have
forgotten their old motto "Don't be evil." While I have been paying Google
with my privacy currency in the past to get functionality and usability,
the benefits of Gmail continuously went lower and now reached an unprofitable
level.&lt;/strong&gt;&lt;/p&gt;
&lt;h2&gt;Migadu is my choice&lt;/h2&gt;
&lt;p&gt;There are many hosted email providers, some are focused on privacy and
security. For example, &lt;a href="https://protonmail.com/"&gt;Protonmail&lt;/a&gt; is a fantastic
project that makes it nearly trivial to use PGP even for an uninitiated. But
its drawbacks are that it is non-standard and has too high publicity making
it quite undesirable in certain authoritarian countries. Simply said, if
you use Protonmail in some countries you may be suspected; Protonmail can
be blocked by the authorities, and worse still,
&lt;a href="https://habr.com/ru/company/habr/blog/443222/"&gt;blocked in quite idiosyncratic way&lt;/a&gt;.
Some services may also &lt;a href="https://protonmail.com/support/knowledge-base/website-blocks-protonmail-email-address/"&gt;reject registration&lt;/a&gt;
using this service.&lt;/p&gt;
&lt;p&gt;What I have finally chosen is &lt;strong&gt;&lt;a href="https://www.migadu.com/"&gt;Migadu&lt;/a&gt;.&lt;/strong&gt; It is not
yet another standard email hosting provider. It is a domain-based service. Once
you have got your own domain name (domains are now cheap), you can make your
own email service for your domain. That simple. This makes it &lt;strong&gt;super useful&lt;/strong&gt;
for companies, families, groups and NGOs without large budgets. &lt;strong&gt;For a
reasonable price you get nearly your own mail server with many configurable
features (any custom mailboxes, aliases, forwarding, regexp, webmail,
etc.) but without the need to maintain all this complex system.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;If you have a web site, you necessarily get a domain name for it. Now it's
easy to get your own email identity. True that some hosting providers also
do host email. But if you decide to switch to a different hosting it will
create a trouble: you need to move also email and this fact strongly limits
your next choice. &lt;strong&gt;Having a completely indpendent email system for your
existing domain avoids such hoster lock-in and makes life much easier.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;By the way, the Migadu standard &lt;a href="https://webmail.migadu.com/"&gt;webmail interface&lt;/a&gt;
is sleek and very simple. Looks modern but lightweight and quite fast. No
bloat whatsoever, only the most crucial functionality. I am not big fan
of web-based email, but use it from time to time. And there is even some
very basic support for PGP! (But remember that web-based PGP is
&lt;a href="https://www.migadu.com/procon/#not-encrypted"&gt;not a very secure solution&lt;/a&gt;.)&lt;/p&gt;
&lt;p&gt;I found the &lt;strong&gt;mail server configuration (including more esoteric stuff like
DNS setup and DKIM signatures) very easy.&lt;/strong&gt; In my view you do not need an
IT degree to configure your email server with full functionality. I like the
admin panel, it is &lt;strong&gt;minimalist and easy to use,&lt;/strong&gt; no stupid and distracting
visual effects. And &lt;a href="https://www.migadu.com/"&gt;Migadu&lt;/a&gt; is advertised as
&lt;strong&gt;fully open standard compliant service&lt;/strong&gt; without proprietary glitches and
limitations. So any standard (open source or closed source) software is very
likely to be fully usable. This freedom is very important. And they are also
clear and honest about the
&lt;a href="https://www.migadu.com/procon/"&gt;limitations and drawbacks&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Finally, goodbye Gmail.&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Masnick, M. 2019. Protocols, not platforms. A technological
  approach to free speech. &lt;em&gt;Knight First Amendment Institute&lt;/em&gt;
  &lt;a href="https://knightcolumbia.org/content/protocols-not-platforms-a-technological-approach-to-free-speech"&gt;https://knightcolumbia.org/content/protocols-not-platforms-a-technological-approach-to-free-speech&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;p&gt;&lt;strong&gt;PS:&lt;/strong&gt; Disclaimer: I have no links with &lt;a href="https://www.migadu.com/"&gt;Migadu&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This post is also published on
&lt;strong&gt;&lt;a href="https://sbudaev.substack.com/p/goodbye-gmail"&gt;Substack&lt;/a&gt;&lt;/strong&gt;
and &lt;strong&gt;&lt;a href="https://medium.com/@sbudaev/goodbye-gmail-7849f8c23baa"&gt;Medium&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;</content><category term="Blog"></category><category term="privacy"></category><category term="IMAP"></category><category term="email"></category><category term="GPG"></category><category term="PGP"></category><category term="Migadu"></category><category term="platform"></category><category term="federation"></category><category term="decentralized"></category></entry><entry><title>How to use open source openconnect for UiB VPN</title><link href="https://budaev.info/how-to-use-open-source-openconnect-for-uib-vpn.html" rel="alternate"></link><published>2021-11-10T14:19:00+01:00</published><updated>2021-11-10T14:19:00+01:00</updated><author><name>Sergey Budaev</name></author><id>tag:budaev.info,2021-11-10:/how-to-use-open-source-openconnect-for-uib-vpn.html</id><summary type="html">&lt;p&gt;How to use open source openconnect for UiB VPN&lt;/p&gt;</summary><content type="html">&lt;p&gt;&lt;strong&gt;Cisco AnyConect&lt;/strong&gt; is an unethical software. First, it is proprietary and
closed source code, although the nature of its functioning makes it capable
to control all the user's network traffic. Even worse, Cisco AnyConnect
implements controversial functionality making it technically a kind of malware:
the so called "posture" (HostScan) service is scanning the user's device and
(steals?) sends various information out (Cisco said this is done "to improve
security," e.g. to avoid non-certified and unauthorized devices), Cisco VPN
client can officially download and install spyware trojan on the user's device
(Cisco also advertises the trojan as a tool to "improve security"). Also,
the VPN client can reroute the network settings in arbitrary way without the
user's consent and knowledge. All this is a serious security and privacy
threat. (And Cisco products have a bad history of serious security flaws
that look like backdoors.)&lt;/p&gt;
&lt;p&gt;It can be justified to run &lt;strong&gt;Cisco AnyConnect&lt;/strong&gt; on a corporate-owned
machine (understanding the consequences for the user's privacy and
security). But &lt;strong&gt;installing it on the user's owned private
devices should be avoided.&lt;/strong&gt;&lt;/p&gt;
&lt;h2&gt;Openconnect&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Openconnect&lt;/strong&gt; is an open source SSL VPN client that supports several protocols
including Cisco AnyConnect. It can be used as an alternative to proprietary
Cisco software that may in some installation include controversial and
undesirable functions such as uncontrollable network re-routing, proprietary
scanning module, installable &lt;em&gt;spyware trojan&lt;/em&gt; etc.&lt;/p&gt;
&lt;p&gt;For more information go to the Opeconnect web site: &lt;a href="https://www.infradead.org/openconnect/"&gt;https://www.infradead.org/openconnect/&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Install openconnect&lt;/strong&gt; from the standard Linux repository, e.g. in case of
Ubuntu/Debian use:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;apt install openconnect network-manager-openconnect \
            network-manager-openconnect-gnome
&lt;/pre&gt;&lt;/div&gt;


&lt;h2&gt;Server settings&lt;/h2&gt;
&lt;p&gt;To connect to the vpn, go to the network configuration entry, then add a
new VPN connection, choosing &lt;strong&gt;Cisco AnyConnect Compatible VPN (openconnect)&lt;/strong&gt;
in the list.&lt;/p&gt;
&lt;p&gt;To connect to the UiB VPN one needs this:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Server gateway: &lt;code&gt;vpn3.uib.no&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;UiB username (short name, in the following examples &lt;code&gt;zzz000&lt;/code&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Basic connect using command line&lt;/h2&gt;
&lt;p&gt;The simplest command to connect to UiB network is:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;sudo openconnect --user zzz000 vpn3.uib.no
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Note that &lt;code&gt;sudo&lt;/code&gt; is required to set up the &lt;code&gt;tun&lt;/code&gt; device (It is, however,
possible to configure openconnect to run as unprivileged user, see
&lt;a href="http://www.infradead.org/openconnect/nonroot.html"&gt;http://www.infradead.org/openconnect/nonroot.html&lt;/a&gt;).&lt;/p&gt;
&lt;p&gt;There are also a few &lt;em&gt;useful options&lt;/em&gt;:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;--background&lt;/code&gt; run openconnect at the background&lt;/li&gt;
&lt;li&gt;&lt;code&gt;--syslog&lt;/code&gt; send messages to the system log&lt;/li&gt;
&lt;li&gt;&lt;code&gt;--pid-file  /var/run/openconnect.pid&lt;/code&gt; use specific pid file, then it is
  easy to switch off the background vpn using this command:
  &lt;code&gt;kill $(cat /var/run/openconnect.pid)&lt;/code&gt; assuming process pid is saved to
  &lt;code&gt;/var/run/openconnect.pid&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;These options result in this command:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;sudo openconnect --background --syslog --pid-file /var/run/openconnect.pid  \
                 --user zzz000 vpn3.uib.no
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;&lt;img alt="running on terminal" src="images/oconn-img1.png" title="command line example"&gt;&lt;/p&gt;
&lt;h2&gt;Connect using graphical user interface&lt;/h2&gt;
&lt;p&gt;Most Linux desktop environments (e.g. Gnome, xfce etc ) have graphical
utility that is accessible in the system tray. To configure it use:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;VPN protocol: &lt;em&gt;Cisco AnyConnect&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;Software token authentication: &lt;em&gt;TOTP&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;img alt="GUI step 1" src="images/oconn-img2.png" title="GUI example"&gt;&lt;/p&gt;
&lt;p&gt;Other options should be left intact.&lt;/p&gt;
&lt;p&gt;At login, the GUI program will ask the University user name and password. Enter
and press &lt;em&gt;Login&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt="GUI step 2" src="images/oconn-img3.png" title="GUI example"&gt;&lt;/p&gt;
&lt;p&gt;Then, Microsoft authentication code will be sent via SMS on the mobile phone.&lt;/p&gt;
&lt;p&gt;&lt;img alt="GUI step 3" src="images/oconn-img4.png" title="GUI example"&gt;&lt;/p&gt;
&lt;p&gt;There may be a caveat: DNS might not work with the default configuration
(web sites are inaccessible by their http names). If this is the case,
go to IPv4 settings and manually configure DNS servers, such as Google DNS
&lt;code&gt;8.8.8.8&lt;/code&gt; and &lt;code&gt;8.8.4.4&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt="GUI step 4" src="images/oconn-img5.png" title="GUI example"&gt;&lt;/p&gt;
&lt;p&gt;and then to IPv6 settings and enter DNS servers manually, e.g. Google DNS
&lt;code&gt;2001:4860:4860::8888, 2001:4860:4860::8844&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;&lt;img alt="GUI step 4" src="images/oconn-img6.png" title="GUI example"&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;Now UiB VPN should work in a private way.&lt;/em&gt; Openconnect turns out to be a
useful tool to connect to the UiB network in a simple and straightforward way.&lt;/p&gt;
&lt;h2&gt;Microsoft Windows&lt;/h2&gt;
&lt;p&gt;Openconnect also works on &lt;strong&gt;Microsoft Windows.&lt;/strong&gt; If you are
using &lt;a href="https://community.chocolatey.org/"&gt;Chocolatey&lt;/a&gt;
then there is a port that can installed
be &lt;a href="https://community.chocolatey.org/packages/openconnect-gui"&gt;using this command&lt;/a&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;choco install openconnect-gui
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Disclaimer: I did not try it.&lt;/p&gt;
&lt;h2&gt;References&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Opeconnect web site with source code, documentation etc:
  &lt;a href="https://www.infradead.org/openconnect/"&gt;https://www.infradead.org/openconnect/&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Microsoft Windows port: &lt;a href="https://openconnect.github.io/openconnect-gui/"&gt;https://openconnect.github.io/openconnect-gui/&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Tim Hårek Andreassen had a similar howto in his blog:
  &lt;a href="https://timharek.no/blog/uib-vpn-without-cisco/"&gt;https://timharek.no/blog/uib-vpn-without-cisco/&lt;/a&gt;
  &lt;em&gt;Note: My openconnect was experience even more straightforward, e.g. in
  my case no certificate configuration was necessary.&lt;/em&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;</content><category term="VPN"></category><category term="privacy"></category><category term="UiB"></category></entry><entry><title>Are we going to work in a paper jail?</title><link href="https://budaev.info/are-we-going-to-work-in-a-paper-jail.html" rel="alternate"></link><published>2021-10-25T10:00:00+02:00</published><updated>2021-10-25T10:00:00+02:00</updated><author><name>Sergey Budaev</name></author><id>tag:budaev.info,2021-10-25:/are-we-going-to-work-in-a-paper-jail.html</id><summary type="html">&lt;p&gt;Are we going to work in a paper jail?&lt;/p&gt;</summary><content type="html">&lt;h3&gt;Main points&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Any major university IT infrastructure is huge and heterogeneous, it is
  used by lots of people, many of whom are experimenters and explorers,
  who like challenge, rather than office robots. Most users are busy,
  focus on research and study and hate additional (and especially sudden)
  hassle. This is why &lt;strong&gt;consideration of the usability cost is absolutely
  critical for IT security strategy.&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Creating a walled "trusted" area by a firewall--&lt;strong&gt;the perimeter model&lt;/strong&gt;--is
  an &lt;strong&gt;outdated&lt;/strong&gt; approach to security at the age of universal &lt;strong&gt;zero-trust&lt;/strong&gt;
  deployment. Instead of following an already outdated approach, a more
  sensible strategy is to start implementing components of the zero-trust
  model, including &lt;strong&gt;score-based trust&lt;/strong&gt; and wide use of &lt;strong&gt;personal identity
  hardware tokens&lt;/strong&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Major focus in security should be shifted from solely technology components
  to the end users, &lt;strong&gt;creating incentives to use more secure technology,&lt;/strong&gt;
  rather than making additional hassle.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;The great firewall&lt;/h3&gt;
&lt;p&gt;There was a very rapid trend towards an increasingly restrictive IT policies at
the University of Bergen implemented from October this year. While the aim of
“Increasing security” is laudable, I think the planning and implementation
of the policies has several flaws which may compromise its declared aim. The
biggest problem is that the UiB IT is huge and heterogeneous. There is a
variety of services with different levels of security risks, many users,
with diverse needs, user cases and environments, competences, personal
backgrounds and personalities. This requires a more sensible, flexible and
inclusive approach. If this is not the case, rigid policies will not make
the IT environment significantly safer. Instead, it may hamper normal work
for some users, and in the long run compromise both security and privacy
contrary to the declared aim.&lt;/p&gt;
&lt;p&gt;Security, including the computer security, is not a fixed state, it is
rather a continuous process. Security is not limited solely to the IT
technology. Technology alone cannot bring security. Security is primarily
a human rather than technical problem. Indeed, most dangerous security
breaches did not target encryption algorithms, many even only partly involved
exploitation of software and hardware vulnerabilities. They typically make
use of human factors, such as social engineering, trust exploitation, human
mistakes and so on. Successful tracking and catching cyber criminals do not
often primarily target technology, but usually depends on exploiting
human errors, negligence, laziness and other similar factors. This is why the
current primary focus on just technological restriction of the IT environment,
aimed barely to its isolation from the outside networks, is neither sufficient
nor efficient. A more balanced, flexible and holistic approach is needed.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Security can only work at a balance with usability.&lt;/strong&gt; Moreover, there is
often a trade-off: technological security restrictions often make for worse
usability. A completely “sealed” environment would be just too restricted
to be usable. Usability is indeed a primary factor: research shows that many
security problems and users’ hesitance or unwillingness to make use of
(more) secure tools is caused by their imperfect usability. Furthermore,
within a hugely heterogeneous environment, there would be no single optimal
balance between security and usability. An important consequence of this
is that a flexible and inclusive approach to security, aimed at different
degrees of balance with usability, is important.&lt;/p&gt;
&lt;p&gt;The technical part of security should start and primarily respond to specific
threat model(s), not theoretical or vaguely possible risks. And the threat
model(s) should be connected with the real life statistics, e.g. how many
breach attempts usually occur, to which of the services, from which IP
addresses etc. It does not make sense to install solid steel screens on
all windows in our department building to make it “more secure” from
any kind of possible breaches; even if there are crowds of hungry zombies
walking outside, it is just enough to protect the first floor.&lt;/p&gt;
&lt;p&gt;Blanket unconditional restriction of the UiB IT network environment as is
being implemented does not seem to respond to specific consideration of threat
model(s), the variety of users, needs, sub-environments etc. It looks like
a desperate attempt to seal everything in a hope that a jailed environment,
isolated from the outside, will be more secure. This is a wrong assumption.&lt;/p&gt;
&lt;h3&gt;Some specific problems&lt;/h3&gt;
&lt;h4&gt;Multi-factor authentication via TOTP: Not a panacea.&lt;/h4&gt;
&lt;p&gt;&lt;a href="https://hjelp.uib.no/solutions/open-knowledge-items/item/KI%200780/en_gb/"&gt;KI
0780&lt;/a&gt;
introduced multi-factor authentication policy. This is generally a crucial
component to improve security, if implemented sensibly. However, not all
implementations would automatically improve security or provide a sufficient
balance between security and usability. What is called “multi-factor
authentication” may not even be really multi-factor. The definition
of multi-factor authentication involves the use of several things for
authentication, typically something you know: password, plus something you
own, e.g. a mobile device (SIM) and something you are e.g. fingerprint. If
the password is entered using the password manager software saved on the
mobile device and the “multi-factor” SMS comes to the same mobile device
(or password entered and SMS read on the same computer that links to the
smartphone as is now the norm within the Apple ecosystem), the whole idea of
two factors is ridiculed: the smartphone becomes the single authentication
device. It can be at best called “two-step authentication,” a weaker
mechanism. The SMS (and anything based on phone-line or phone-number) is
actually one of the poorest authentication means due to the long known and
essentially unsolvable vulnerabilities in the GSM, SS7 and other related
protocols. SMS can be hijacked by malicious smartphone apps (e.g. Google Play
store does not even approach 100% safety, there are occasional scandals with
malware in apps with very substantial audience) or even basic GSM dumb phones
(there are reports about quite a few Chinese-made GSM button-phones having
factory-installed malware). Worse still, some of the modern and widespread
multi-factor mechanisms such as push-based popups are also easily exploited
(even worse, they make for a bad habit of clicking “approve” without
thinking). If authentication is done on a web page, it is usual to save
the authentication cookie to avoid repeated two-factor invocation. However,
cookies are not necessarily secure, long kept cookies might be hijacked by
malware, there is a well known mechanism of CSRF attacks, there is also a
big privacy drawback (e.g. tracking).  The current industry trend is to go
away from the cookie mechanism in the mainstream browsers (e.g. Google Chrome
will not allow any third-party cookies from 2022). A sensible user policy is
to reduce the lifetime of any cookie. However, it makes the “two-step”
authentication as is currently implemented at the UiB a hassle. Indeed,
the user then has to go via the SMS code process nearly every time he
or she logins, even if it is done from the same IP address and the same
device.&lt;/p&gt;
&lt;p&gt;The ssh access to the &lt;code&gt;login.uib.no&lt;/code&gt; server have apparently disabled the
best-practices secure mechanism of ssh-key authentication (&lt;em&gt;incidentally,
if the key is combined with a passphrase then it is actually a two-factor
authentication itself!&lt;/em&gt;) and forced the potentially week password-based
mechanism with SMS code. There seems to be &lt;em&gt;no other TOTP mechanisms except
SMS&lt;/em&gt; at the time of writing!&lt;/p&gt;
&lt;p&gt;A better mechanism is to use the time-based one-time password code (TOTP)
authenticator application on the mobile phone. This is in fact recommended at
the Microsoft and UiB web pages as a more secure alternative (via &lt;strong&gt;Microsoft
authenticator&lt;/strong&gt; app). While TOTP is better than SMS, it is far from perfect
because it is potentially vulnerable to phishing and the MITM attack and
the secret seed should be kept on the authenticator application as well as
on the server to make synchronised generation of TOTPs possible.&lt;/p&gt;
&lt;h4&gt;Personal hardware tokens&lt;/h4&gt;
&lt;p&gt;There is a much better and stronger two-factor authentication mechanism:
&lt;strong&gt;U2F&lt;/strong&gt; and &lt;strong&gt;FIDO2/WebAuthn&lt;/strong&gt; that use hardware security device keeping
the private key.  The security token, in the form of a small USB or
NFC key can both authenticate on the server and authenticate the server
itself with strong asymmetric crypto, making phishing and many other attacks
virtually impossible. Many such devices also implement biometric
(e.g. fingerprint) identification with privacy-respected way (e.g. biometric
data is not sent from the user's device). This is now a mature technology
that is implemented in all major web browsers, can be used with ssh key-based
authentication, GPG-enabled email etc.&lt;/p&gt;
&lt;p&gt;The best known hardware token is probably the
&lt;a href="https://www.yubico.com/"&gt;Yibikey&lt;/a&gt; and there are a few others on the market
(e.g. Google Titan, FEITIAN, Token2, Thetis etc.). They can be not very cheap,
but not prohibitively expensive either.&lt;/p&gt;
&lt;h4&gt;VPN needed for all, even the most essential everyday services&lt;/h4&gt;
&lt;p&gt;The UiB IT services have previously used several open and industry-standard
VPN mechanisms (IPsec, OpenVPN) so that different users could easily find a
solution working for them individually. Now, there is a single closed and
proprietary mechanism: Cisco AnyConnect including both unique protocol
(SSL-based) and the software client. This mechanism may work for many
but not necessarily for everyone (e.g. unlike open solution, it may not
be available on some computing platforms, some enthusiasts of the open
source might find restriction to a single proprietary tool unethical,
etc.). There are rumors about unreliable connections with Cisco AnyConnect,
and that OpenVPN was previously more stable for some users. It is indeed
likely if Cisco AnyConnect is used over certain restrictive environments
with DPI that block connections to certain ports or UDP traffic even at
the 443 port, or otherwise censor VPNs (e.g. some public WiFi networks may
have such limitations). Some implementations of the OpenVPN, in contrast,
can be configured to mimic normal SSL web traffic (e.g. shadowsocks) and
work even under the Great Chinese firewall. There is a clear benefit at not
prohibitively high cost to provide at least some limited support for such a
mechanism for certain users (e.g. special needs or during travel). It might
even be provided only on special request with some substantiation. Also, the
reliability statistics internally used by the IT department might be biased
if not all users report minor and transient VPN issues. So there is a case to
deploy and support alternative VPN solutions, perhaps even on a smaller scale.&lt;/p&gt;
&lt;p&gt;It sounds quite reasonable that providing and supporting a wider choice of VPN
solutions for a minority of users would not be economically feasible. However,
it is certainly not the case when just all the services become available
only from within the UiB internal network jail. Then, there should be more
flexibility and inclusion, several ways to get into a jailed environment
comfortably by a variety of users in different environments. It is just too
unbalanced limitation to mandate the use of a single restricted VPN to get
email from home or from an airport, for example. A better alternative is of
course to relax the policy moving at least the most essential but inherently
secure services out of the jail.&lt;/p&gt;
&lt;h4&gt;Is the universal jail really essential for everything?&lt;/h4&gt;
&lt;p&gt;One issue with unconditional moving of all the UiB IT services into a jailed
environment is that this would not reflect sufficient balance between security
and usability. It is of course good to keep potentially less secure services
(e.g. RDP) jailed. But are real threats substantial enough to hide just
everything into such a jail?&lt;/p&gt;
&lt;p&gt;Are there any real-life statistical or other data evidencing that accessing
the university email system from an IMAP client with normal SSL/TLS protection
can be dangerous? The user in such a case does not need to enter the UiB
password for login (it is saved into the software, often encrypted on devise),
so phishing risk is near zero. The authenticity of the IMAP server certificate
is usually checked through the standard SSL mechanism. So is there any real
security advantage to move such essential everyday tool as email into the
jail, does this just induces additional hurdle?&lt;/p&gt;
&lt;p&gt;Another example is connecting the UiB login.uib.no ssh server. Many (presumably
less advanced) users can use the ssh with their default password. Then,
the “two-factor” authentication is a serious security improvement of
course, even if it is in fact used in the weakened two-step authentication
mode. However, some other users can configure ssh-key authentication,
which is a much more secure mechanism. Will the manual entry password with
two-factor authentication really provide sufficient security improvement
in such a case? Will it provide anything beyond a negligible effect if the
user has already authenticated with SMS on the same device, or a different
device from the same IP address shortly before? Is there any improvement in
security that substantiates such degradation of usability?&lt;/p&gt;
&lt;p&gt;The question is this: is the same level of restriction and jailing really
essential for all services, often and rarely used, potentially less secure
and highly secure, easy and difficult to exploit, those with documented
attacks and those that present little interest to intruders? Does not it
just provide usability costs not balanced by any security improvement?&lt;/p&gt;
&lt;h4&gt;Human ingenuity: Is the jail actually made of paper?&lt;/h4&gt;
&lt;p&gt;It is clear that equally and unconditionally restricting just everything,
especially, without considering usability costs, will not automatically
increase security. The situation can well be worse: lower security as
well as compromised privacy.&lt;/p&gt;
&lt;p&gt;For example, to avoid all the nuisance, users may switch to using &lt;em&gt;third-party
commercial providers,&lt;/em&gt; such as increasingly use private gmail.com accounts,
Dropbox etc. Users may use smaller, more cryptic online tools and applications
(e.g. file sharing sites, communication tools, some advertised as encrypted)
with uncontrollable and unknown security. Some of them might be owned and
run by community and volunteers, some could be compromised or deliberately
devised to gather data, track users and spy.&lt;/p&gt;
&lt;p&gt;Some of more qualified "insider" users might successfully hack the system
to get nuisance-free access to the UiB jailed environment from outside. It
is actually not a hard problem. One possible solution is to use the reverse
&lt;code&gt;ssh&lt;/code&gt; proxy. It does not even require administrative rights and can be done
by a motivated average level computer user after 20 min of reading the
&lt;code&gt;ssh&lt;/code&gt; manual. More advanced users can create stable backdoors implementing
such things as proxy jump and port forwarding that will sustain reboots,
logouts etc. It is also easy to add various layers for plausible deniability
and obfuscation.&lt;/p&gt;
&lt;p&gt;There are much more tools, ways and possibilities to implant and efficiently
hide a backdoor into the UiB jailed environment. All that is required is
various open source components freely available on the net and an &lt;strong&gt;incentive&lt;/strong&gt;
to do such unauthorized actions. It is not just an abstract theoretical
threat but real and serious risk left behind the current jailing policy.&lt;/p&gt;
&lt;p&gt;Imposing a jailed environment without considering trade-off of flexibility
and usability has this biggest problem: &lt;strong&gt;It may create an incentive to break
the rules to make life more hassle-free.&lt;/strong&gt; A related and serious problem
is that the IT department would not be able to control this and in most
cases will remain unaware of the issue. It is virtually impossible to detect
that users communicate and share sensitive medical or personal data over a
private google mail account, for example. A cryptic backdoor implanted on
the computer within the UiB jail with sufficient plausible deniability can
remain long undetected without costly and tedious forensic analysis. But
such an analysis will be conducted only by the police after a catastrophic
break-in has occurred, too late.&lt;/p&gt;
&lt;p&gt;There are many advanced users, smart students, at the university. Many well
understand (and they do discuss!) the inconsistency of the restrictive jail
policies. Some people may find it quite fun to overcome the silly rules
imposing unneeded hassle. It can indeed be an interesting challenge but,
unfortunately, an additional incentive.&lt;/p&gt;
&lt;p&gt;A further problem is that many users usually do not bother to report
smaller or transient problems at the normal issue tracking channels such
as hjelp.uib.no. They may not be acquainted with it or just consider it a
hassle if they are very busy (and they are very busy with real things to
hang at tangential IT problems). A quite typical way of action is to ask
someone nearby for a help or workaround. Therefore, if the knowledge of
the ways for implanting backdoors and the obvious fact that it is quite
easy and just solves the problem, is spread within the student and staff,
it can create a real security disaster. Unfortunately, backdoor skills are
very likely to spread if the IT department continues to create more and more
restrictive jail and provide more incentives to break the rules. Then, it
would be essential to further tighten the jail: inspect all devices on entry
and refuse entry to everyone with IQ &amp;gt; 0.60. The simple fact is that the
jail that is being happily built is not made of rock and steel, it is paper.&lt;/p&gt;
&lt;p&gt;The situation at the UiB is quite different from a typical commercial
organization that the standard security recipes are based upon. There
are many brilliant students and staff out here, many are young and like
challenges. There can be those who would not hesitate to take risk, given
the benefit of making one’s own hassle-free environment is high, the cost
is zero while expected risk is rather low. Making a backdoor is indeed a
way of learning technology that is fun and another added incentive. Many
folks are already aware of various software tools and know how to use their
black magic. People are ingenious, and people at UiB are on average much more
ingenious than outside. What is the threat model for developing the jailed IT
environment? Is to protect the UiB from outside hackers? It is a wrong model
because many such hackers are already within the jailed environment and are
ready and to get the challenge to punch its feeble paper walls from inside.&lt;/p&gt;
&lt;h3&gt;What should be done?&lt;/h3&gt;
&lt;p&gt;Inconsiderate and inflexible jailing of the UiB IT networks should certainly
be slowed down before it is too low and people started using third-party
tools and making their own unauthorized solutions. There should be a serious
analysis on what must be implemented and over which time scale so the users
can get acquainted and do not just suddenly get huge hassle. As to now,
the “analysis” seems to be mainly focused on “what is suddenly broken
down once we put everything into a jail”; this is not acceptable. The
policies should not be based mechanistically on some manual made for a
different type of environment, they should be inclusive, flexible enough to
adapt to the complex, diverse and heterogeneous UiB environment. &lt;strong&gt;The main
focus should switch from technology to people:&lt;/strong&gt; how to reach most of them
(they are busy!), make security improvements minimally obtrusive, teach very
busy people sufficient security skills without much hassle. Specifically,
the most important information should not be sent by global mailing list
that may disappear in user’s mail filter, but must be directed personally
to each user (it isn’t prohibitively hard to write a script for this,
substituting &lt;code&gt;%NAME%&lt;/code&gt; with the real user’s name).&lt;/p&gt;
&lt;p&gt;The technological part of the solution should develop sensible threat models
based on attack and usage statistics. It should be governed by real risks
rather than desire to just protect everything quickly and at all costs. Some
of the restrictions already applied can be relaxed. A reasonable solution is
to apply more sensible &lt;strong&gt;score-based security mechanism,&lt;/strong&gt; e.g. including
IP based rules for two-factor or two-step authentication. Some of more
secure services, can for example, be available without firewall restriction
if the user comes from his/her frequently used Norwegian home IP address
(to improve usability while still reducing potential attack surface). This
efficiently transforms a jail into a continuum adapting for the threat
and uncertainty level. It will also pay back to demonstrate the practical
benefits of client-side certificate authentication, OAuth2 and similar more
phishing-resistant security token mechanisms (e.g. they can relax the need in
TOTP/SMS authentication) to all users. The university should also facilitate
much wider use of &lt;strong&gt;hardware-based authentication devices,&lt;/strong&gt; such as YubiKey,
for proper two-factor authentication, perhaps even distribute such devices
freely in some groups if universal deployment turns out expensive. Such
personal identity verification hardware devices are actually a crucial
component of modern &lt;strong&gt;zero-trust&lt;/strong&gt; security approaches.&lt;/p&gt;
&lt;p&gt;The crucial element of the whole policy is to &lt;strong&gt;create incentives for using
more secure tools.&lt;/strong&gt; For example, the use of hardware personal identity
verification tokens should allow to bypass all or most restrictions,
perhaps even the need in VPN. There would currently be little added risk
with such a policy, but the users would be much happier to do their work
securely whenever they need without hassle. This would require hard work,
additional integration and funding. But educating, helping and cooperating
with users—not restricting and obstructing them—would be the only viable
strategy to achieve increased security in the University environment in
reality, not just on paper.&lt;/p&gt;</content><category term="VPN"></category><category term="privacy"></category><category term="security"></category><category term="UiB"></category></entry><entry><title>XMPP direktemeldinger</title><link href="https://budaev.info/xmpp-direktemeldinger.html" rel="alternate"></link><published>2020-11-01T13:14:00+01:00</published><updated>2025-07-10T21:00:00+02:00</updated><author><name>Sergey Budaev</name></author><id>tag:budaev.info,2020-11-01:/xmpp-direktemeldinger.html</id><summary type="html">&lt;div class="sect1"&gt;
&lt;h2 id="_hva_er_xmpp"&gt;Hva er XMPP?&lt;/h2&gt;
&lt;div class="sectionbody"&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;XMPP (Jabber) er en åpen protokoll for direktemeldingskommunikasjon som
har vært under utvikling fra 1999. Alle tekniske detaljer er beskrevet av
&lt;a href="https://xmpp.org/extensions/"&gt;XEPs&lt;/a&gt;. Det finnes mange applikasjoner som
bruker denne standarden, men alle er kompatibel med hverandre.&lt;/p&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;De viktigste &lt;strong&gt;fordelene&lt;/strong&gt; med XMPP fremfor alle andre direktemeldingssystemer er
at …&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;</summary><content type="html">&lt;div class="sect1"&gt;
&lt;h2 id="_hva_er_xmpp"&gt;Hva er XMPP?&lt;/h2&gt;
&lt;div class="sectionbody"&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;XMPP (Jabber) er en åpen protokoll for direktemeldingskommunikasjon som
har vært under utvikling fra 1999. Alle tekniske detaljer er beskrevet av
&lt;a href="https://xmpp.org/extensions/"&gt;XEPs&lt;/a&gt;. Det finnes mange applikasjoner som
bruker denne standarden, men alle er kompatibel med hverandre.&lt;/p&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;De viktigste &lt;strong&gt;fordelene&lt;/strong&gt; med XMPP fremfor alle andre direktemeldingssystemer er
at XMPP er åpent, gratis, ikke tilhører eller styres av ett selskap. Det
er også føderert (distribuert), slik at alle kan kjøre sine egne
meldingsserver. Hvis ønskelig, kan serveren lukkes (så kommunikasjon med
andre servere er ikke tillat) eller fullt sammensatt så kommunikasjon går
mellom tvers av eksisterende servere (som i e-post). XMPP har mange innebygde
personverns- og sikkerhetsfunksjoner som gir sterk kryptografi ved hjelp av
standard og offentlige revidert algoritmer og programvarekomponenter. For
eksempel ende-til-ende-kryptering kan bruke GPG / PGP, OTR og OMEMO
protokoller (se &lt;a href="https://wiki.404.city/en/XMPP_client_encryption"&gt;wiki.404.city&lt;/a&gt;).&lt;/p&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;Muligheten til å kjøre sin egen private server og mange &lt;strong&gt;offentlige servere&lt;/strong&gt;
(se &lt;a href="#PUBLIC_SRV"&gt;offentlige serverer&lt;/a&gt;) som er åpne for gratis, anonym
registrering, gjør XMPP best egnet for &lt;strong&gt;høyt personvern og sikkerhet.&lt;/strong&gt;
En moderner åpen direktmeldingsløsning er &lt;a href="https://matrix.org/"&gt;Matrix&lt;/a&gt;.
Men Matrix har dårligere personvernfunksjoner med høyere oppblåsthet
(&lt;a href="https://lukesmith.xyz/articles/matrix-vs-xmpp"&gt;se her&lt;/a&gt;
og &lt;a href="https://github.com/libremonde-org/paper-research-privacy-matrix.org"&gt;Matrix personvernproblemer&lt;/a&gt;).
For eksempel, flere år siden den personvernplattformen Disroot har bestemt å flytte tilbake
fra &lt;a href="https://disroot.org/en/blog/disroot-joins-the-matrix-network"&gt;Matrix&lt;/a&gt;
til &lt;a href="https://disroot.org/it/blog/matrix-closure"&gt;XMPP&lt;/a&gt;.&lt;/p&gt;&lt;/div&gt;
&lt;div class="ulist"&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;
Sjekk ut forskjellige problemer med Matrix:
&lt;/p&gt;
&lt;div class="ulist"&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://github.com/libremonde-org/paper-research-privacy-matrix.org"&gt;https://github.com/libremonde-org/paper-research-privacy-matrix.org&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://www.nuegia.net/articles/matrix.xhtml"&gt;https://www.nuegia.net/articles/matrix.xhtml&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://hackea.org/notas/matrix.html"&gt;https://hackea.org/notas/matrix.html&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://github.com/matrix-org/matrix.org/issues/2483"&gt;https://github.com/matrix-org/matrix.org/issues/2483&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;strong&gt;Bli med i XMPP nettverket med en av &lt;a href="#PUBLIC_SRV"&gt;offentlige serverer&lt;/a&gt;.&lt;/strong&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="sect1"&gt;
&lt;h2 id="WHY_NOT_MONOPOLY_MESSENGER"&gt;Hvorfor ikke WhatsApp, Skype, Snapchat, Telegram osv?&lt;/h2&gt;
&lt;div class="sectionbody"&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;De fleste andre meldingssystemer har alvorlige personvernfeil og
sikkerhetsproblemer. Obligatorisk bruk av den eneste "offisielle"
programvare skaper en monokultur der sikkerhetsproblemer påvirker alle
brukere. Lukkede kildekoden tillater ikke å revidere disse systemene
offentlig. Men produsentene kan implementere skjulte udokumenterte funksjoner,
reklamesporere og bakdører.&lt;/p&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;En av de viktigste sårbarhetene er push-varslingsmekanismen i både Android og
IPhone plattformer. Dette påvirker alle apper som bruker
push-varsleringmekanismen, selv de som posisjonerer seg som "krypterte" og
"sikre." XMPP kan fungere uten pushvarsler.&lt;/p&gt;&lt;/div&gt;
&lt;div class="ulist"&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://www.schneier.com/blog/archives/2024/03/surveillance-through-push-notifications.html"&gt;Surveillance through Push Notifications&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://web.archive.org/web/20240301075856/https://www.washingtonpost.com/technology/2024/02/29/push-notification-surveillance-fbi/"&gt;The FBI’s new tactic: Catching suspects with push alerts&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="sect2"&gt;
&lt;h3 id="_flere_eksempler"&gt;Flere eksempler&lt;/h3&gt;
&lt;div class="ulist"&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://www.wired.com/story/the-kremlin-has-entered-the-chat/"&gt;The Kremlin Has Entered the Chat: Putin&amp;#8217;s regime may have access to Telegram chats&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://www.techradar.com/news/whatsapp-data-breach-sees-nearly-500-million-user-records-up-for-sale"&gt;WhatsApp data breach, 500 million user records for sale&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://www.rollingstone.com/politics/politics-features/whatsapp-imessage-facebook-apple-fbi-privacy-1261816/"&gt;FBI can get WhatsApp and iMessage data in realtime&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://www.businessinsider.com/whatsapp-hacked-attackers-installed-spyware-2019-5"&gt;WhatsApp was hacked and attackers installed spyware on people&amp;#8217;s phones&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://securitytoday.com/articles/2018/10/12/whatsapp-bug-allowed-hackers-to-hijack-accounts.aspx"&gt;WhatsApp Bug Allowed Hackers to Hijack Accounts&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://slate.com/technology/2018/06/paul-manafort-how-did-fbi-access-whatsapp-messages.html"&gt;How Did the FBI Access Paul Manafort’s Encrypted Messages?&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://hackernoon.com/encrypted-instant-messaging-recommendations-january-2017-711c03af02cc"&gt;Encrypted Instant Messaging Recommendations January 2017&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://www.eff.org/deeplinks/2016/10/where-whatsapp-went-wrong-effs-four-biggest-security-concerns"&gt;Where WhatsApp Went Wrong: EFF&amp;#8217;s Four Biggest Security Concerns&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://www.vice.com/en/article/xwnva7/snapchat-employees-abused-data-access-spy-on-users-snaplion"&gt;Snapchat Employees Abused Data Access to Spy on Users&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://www.vice.com/en/article/bjp9zv/facebook-employees-look-at-user-data"&gt;Sources: Facebook Has Fired Multiple Employees for Snooping on Users&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://seirdy.one/2021/01/27/whatsapp-and-the-domestication-of-users.html"&gt;WhatsApp and the domestication of users&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://www.justsecurity.org/79549/we-now-know-what-information-the-fbi-can-obtain-from-encrypted-messaging-apps"&gt;We Now Know What Information the FBI Can Obtain from Encrypted Messaging Apps&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;Er Signal åpnekilde? Hva er feil med det?&lt;/p&gt;&lt;/div&gt;
&lt;div class="ulist"&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="http://blog.dijit.sh/i-don-t-trust-signal"&gt;I don’t trust Signal&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://drewdevault.com/2018/08/08/Signal.html"&gt;I don&amp;#8217;t trust Signal&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="sect1"&gt;
&lt;h2 id="XMPP_CLIENTS"&gt;Anbefalte programvareklienter&lt;/h2&gt;
&lt;div class="sectionbody"&gt;
&lt;div class="ulist"&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;
Desktop PC
&lt;/p&gt;
&lt;div class="ulist"&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://pidgin.im/"&gt;Pidgin&lt;/a&gt;: Fungerer med mange meldingsprotokoller, f.eks. Telegram, Discord, Slack, Hangouts
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://miranda-ng.org/"&gt;Miranda NG&lt;/a&gt;: Fullt utstyrt (kun Microsoft Windows),  det beste for XMPP
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://gajim.org/"&gt;Gajim&lt;/a&gt;: Fullt utstyrt, det beste for XMPP
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://psi-im.org/"&gt;Psi&lt;/a&gt; and &lt;a href="https://psi-plus.com/"&gt;Psi+&lt;/a&gt;: Fullt utstyrt, det beste for XMPP
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://swift.im/"&gt;Swift&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Epost programvare, f.eks. &lt;a href="https://www.thunderbird.net/"&gt;Thunderbird&lt;/a&gt; og &lt;a href="https://www.emclient.com/"&gt;eM Client&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Android
&lt;/p&gt;
&lt;div class="ulist"&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://conversations.im/"&gt;Conversations&lt;/a&gt;: Fullt utstyrt og kraftig programvare (&lt;a href="https://f-droid.org/en/packages/eu.siacs.conversations/"&gt;Gratis på F-Droid&lt;/a&gt;)
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://monocles.social/@monocles"&gt;Monocles&lt;/a&gt; (eller &lt;a href="https://f-droid.org/en/packages/de.monocles.chat/"&gt;på f-droid&lt;/a&gt;)&amp;#8201;&amp;#8212;&amp;#8201;Conversations fork
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://snikket.org/"&gt;Snikket&lt;/a&gt; (eller &lt;a href="https://f-droid.org/en/packages/org.snikket.android/"&gt;på f-droid&lt;/a&gt;)&amp;#8201;&amp;#8212;&amp;#8201;Conversations fork
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://xabber.com/"&gt;Xabber&lt;/a&gt;: Fullt utstyrt og kraftig programvare
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://yaxim.org/"&gt;Yaxim&lt;/a&gt;: Veldig lett programvare
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://quicksy.im/"&gt;Quicksy&lt;/a&gt;: En enkelt-oppstart kodegaffel av
     Conversations&lt;br /&gt;
     NB: &lt;strong&gt;telefonnummer brukes for kontoregistrering,&lt;/strong&gt; dette er usikkert&lt;br /&gt;
     (pga iboende SS7 sårbarheter) og kompromitterer personvernet.
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
iOS and MacOS
&lt;/p&gt;
&lt;div class="ulist"&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://siskin.im/"&gt;Siskin IM&lt;/a&gt; og &lt;a href="https://beagle.im/"&gt;Beagle IM&lt;/a&gt;: kanskje den beste klienten
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://www.monal-im.org/"&gt;Monal&lt;/a&gt;: Fullt utstyrt og kraftig programvare
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://chatsecure.org/"&gt;ChatSecure&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Nettleserklient
&lt;/p&gt;
&lt;div class="ulist"&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://web.xabber.com/"&gt;Xabber.com&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://conversejs.org"&gt;Converse.js&lt;/a&gt; (&lt;a href="https://xmpp.budaev.info"&gt;xmpp.budaev.info&lt;/a&gt;)
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://movim.eu/"&gt;Movim&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
Mange andre klientprogramvare kan finnes på &lt;a href="https://xmpp.org/software/clients.html"&gt;XMPP.org&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;&lt;span class="image"&gt;
&lt;a class="image" href="https://pidgin.im/"&gt;
&lt;img src="https://budaev.info/images/logo-xmpp-pidgin.png" alt="https://budaev.info/images/logo-xmpp-pidgin.png" width="40" /&gt;
&lt;/a&gt;
&lt;/span&gt;&amp;nbsp;&amp;nbsp;
&lt;span class="image"&gt;
&lt;a class="image" href="https://gajim.org/"&gt;
&lt;img src="https://budaev.info/images/logo-xmpp-gajim.png" alt="https://budaev.info/images/logo-xmpp-gajim.png" width="40" /&gt;
&lt;/a&gt;
&lt;/span&gt;&amp;nbsp;&amp;nbsp;
&lt;span class="image"&gt;
&lt;a class="image" href="https://conversations.im/"&gt;
&lt;img src="https://budaev.info/images/logo-xmpp-conv.png" alt="https://budaev.info/images/logo-xmpp-conv.png" width="34" /&gt;
&lt;/a&gt;
&lt;/span&gt;&amp;nbsp;&amp;nbsp;
&lt;span class="image"&gt;
&lt;a class="image" href="https://blabber.im"&gt;
&lt;img src="https://budaev.info/images/logo-xmpp-blabber.png" alt="https://budaev.info/images/logo-xmpp-blabber.png" width="40" /&gt;
&lt;/a&gt;
&lt;/span&gt;&amp;nbsp;&amp;nbsp;
&lt;span class="image"&gt;
&lt;a class="image" href="https://xabber.com/"&gt;
&lt;img src="https://budaev.info/images/logo-xmpp-xabber.png" alt="https://budaev.info/images/logo-xmpp-xabber.png" width="40" /&gt;
&lt;/a&gt;
&lt;/span&gt;&amp;nbsp;&amp;nbsp;
&lt;span class="image"&gt;
&lt;a class="image" href="https://yaxim.org/"&gt;
&lt;img src="https://budaev.info/images/logo-xmpp-yaxim.png" alt="https://budaev.info/images/logo-xmpp-yaxim.png" width="40" /&gt;
&lt;/a&gt;
&lt;/span&gt;&amp;nbsp;&amp;nbsp;
&lt;span class="image"&gt;
&lt;a class="image" href="https://www.monal-im.org"&gt;
&lt;img src="https://budaev.info/images/logo-xmpp-monal.png" alt="https://budaev.info/images/logo-xmpp-monal.png" width="40" /&gt;
&lt;/a&gt;
&lt;/span&gt;&amp;nbsp;&amp;nbsp;
&lt;span class="image"&gt;
&lt;a class="image" href="https://chatsecure.org/"&gt;
&lt;img src="https://budaev.info/images/logo-xmpp-chatsec.png" alt="https://budaev.info/images/logo-xmpp-chatsec.png" width="40" /&gt;
&lt;/a&gt;
&lt;/span&gt;&amp;nbsp;&amp;nbsp;
&lt;span class="image"&gt;
&lt;a class="image" href="https://xmpp.budaev.info"&gt;
&lt;img src="https://budaev.info/images/logo-xmpp-cojs.png" alt="https://budaev.info/images/logo-xmpp-cojs.png" width="40" /&gt;
&lt;/a&gt;
&lt;/span&gt;&amp;nbsp;&amp;nbsp;&lt;/p&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;div class="sect1"&gt;
&lt;h2 id="_mer_informasjon"&gt;Mer informasjon&lt;/h2&gt;
&lt;div class="sectionbody"&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;Mer informasjon om XMPP finnes på &lt;a href="https://no.wikipedia.org/wiki/Extensible_Messaging_and_Presence_Protocol"&gt;Wikipedia&lt;/a&gt;, &lt;a href="https://wiki.xmpp.org/"&gt;XMPP wiki&lt;/a&gt; og &lt;a href="https://xmpp.org/"&gt;XMPP.org&lt;/a&gt;&lt;/p&gt;&lt;/div&gt;
&lt;div class="ulist"&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;
Også: &lt;a href="https://takebackourtech.org/xmpp-comeback/"&gt;XMPP, A Comeback Story: A 20 Year Old Messaging Protocol For Robust, Private and Decentralized Communications&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;&lt;strong&gt;Lister over offentlige serverer:&lt;/strong&gt; Det finnes mange offentlige servere på
Internet som er åpent for bruk av alle. Her ar noen få av disse:&lt;/p&gt;&lt;/div&gt;
&lt;div class="ulist" id="PUBLIC_SRV"&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://list.jabber.at/"&gt;Public XMPP servers at Jabber.at&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://xmpp-servers.404.city/"&gt;Open list of public XMPP servers at 404.city&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;
&lt;a href="https://www.jabber.no/"&gt;Jabber.no: den Norske XMPP serveren&lt;/a&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;div class="paragraph"&gt;&lt;p&gt;&lt;strong&gt;Ikke gratis tjenesteleverandør:&lt;/strong&gt; &lt;a href="https://jmp.chat/"&gt;jmp.chat&lt;/a&gt; er en betalt XMPP-basert
tjenesteleverandør som inkluderes direktmeldinger, VoIP, SMS, MMS, telefonnumere, osv.&lt;/p&gt;&lt;/div&gt;
&lt;div class="ulist"&gt;&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;
Også se &lt;a href="https://soprani.ca/"&gt;https://soprani.ca/&lt;/a&gt; og
  &lt;a href="https://cheogram.com/"&gt;https://cheogram.com/&lt;/a&gt; prosjekter for forening av
  åpne kommunikasjon nettverker.
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
</content><category term="wiki"></category><category term="Q&amp;A"></category><category term="XMPP"></category><category term="Jabber"></category><category term="chat"></category><category term="security"></category><category term="interoperability"></category></entry><entry><title>Using Subversion to manage Office files</title><link href="https://budaev.info/using-subversion-to-manage-office-files.html" rel="alternate"></link><published>2020-10-23T09:47:00+02:00</published><updated>2020-10-23T09:47:00+02:00</updated><author><name>Sergey Budaev</name></author><id>tag:budaev.info,2020-10-23:/using-subversion-to-manage-office-files.html</id><summary type="html">&lt;p&gt;Using Subversion to manage Office files&lt;/p&gt;</summary><content type="html">&lt;p&gt;Because &lt;strong&gt;Subversion&lt;/strong&gt; works best (and can track) &lt;strong&gt;plain text&lt;/strong&gt; files,
it is not well adapted for versioning normal &lt;strong&gt;Microsoft Office&lt;/strong&gt; or
&lt;strong&gt;LibreOffice/OpenOffice&lt;/strong&gt; documents. However, both are actually zipped XML
files. Therefore, it is possible both directly (binary) and using flat XML
text (full version control/merge support).&lt;/p&gt;
&lt;h2&gt;Microsoft Office&lt;/h2&gt;
&lt;p&gt;For &lt;strong&gt;Microsoft Office&lt;/strong&gt;, there are extensions for Subversion:
&lt;a href="https://sourceforge.net/projects/msofficesvn/"&gt;Msofficesvnf&lt;/a&gt;,
&lt;a href="https://archive.codeplex.com/?p=officesvn"&gt;OfficeSVN&lt;/a&gt; and
&lt;a href="https://www.youtube.com/watch?v=mN2vT1oS0DQ"&gt;MagnetSVN&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Also, &lt;a href="https://tortoisesvn.net/"&gt;TortoiseSVN&lt;/a&gt; can use native Microsoft Word
"compare versions" tool to check for differences between versions. Check out
the &lt;code&gt;Diff-Scripts&lt;/code&gt; in the TortoiseSVN installation directory. Note that these
scripts are js and can be blocked by corporate or university security policy:
ask the IT!&lt;/p&gt;
&lt;h3&gt;Subversion keywords&lt;/h3&gt;
&lt;p&gt;Subversion keywords (properties) can be managed in Microsoft Word files using
&lt;a href="https://insights.oetiker.ch/windows/SvnProperties4MSOffice/"&gt;SvnProperties4MSOffice&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;For more information see
&lt;a href="https://gotomation.info/2019/01/svn-version-control-office-documents/"&gt;https://gotomation.info/2019/01/svn-version-control-office-documents/&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If special software for adapting Office files is not used, it is
recommended to use Microsoft &lt;strong&gt;uncompressed XML&lt;/strong&gt; formats for all
outputs. While they take more disk space (because it is unzipped), these
are plain text XML, so Subversion treats them very efficiently. Also, svn keywords/tags
can be used within the text without any additional tools.&lt;/p&gt;
&lt;h2&gt;LibreOffice or OpenOffice&lt;/h2&gt;
&lt;p&gt;For &lt;strong&gt;LibreOffice&lt;/strong&gt;, the easiest way is to use &lt;strong&gt;.fodt&lt;/strong&gt; format for saving
the document (instead of .odt or .docx), FODT is a flat XML format. A drawback
is that it is unzipped and takes much more disk space. But Subversion does not
store all versions of the whole file, it saves effectively differences between
the versions. Therefore, there is little or no overhead within the version control system
of working with &lt;strong&gt;fodt&lt;/strong&gt; files.&lt;/p&gt;
&lt;p&gt;Quite importantly, it is then trivial to add keywords to the &lt;strong&gt;fodt&lt;/strong&gt;
file on the svn system. Then, it is easy to include normal  svn
keywords/tags] such as &lt;code&gt;$Revision 1234$&lt;/code&gt; into whenever needed into
the fodt file and it will autoupdate on every commit without any
additional tools. But note that the whole tag &lt;code&gt;$Revision 1234$&lt;/code&gt;
must have the same formatting (i.e. no bold/italic/other font within
and including the &lt;code&gt;$ $&lt;/code&gt; delimiters).&lt;/p&gt;
&lt;p&gt;For more information see
&lt;a href="https://wiki.documentfoundation.org/Libreoffice_and_subversion"&gt;https://wiki.documentfoundation.org/Libreoffice_and_subversion&lt;/a&gt;
and &lt;a href="https://wiki.documentfoundation.org/Svn:keywords"&gt;https://wiki.documentfoundation.org/Svn:keywords&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Conflicts&lt;/h2&gt;
&lt;p&gt;To avoid conflicts when several people are working concurrently with
svn-tracked files, &lt;strong&gt;use svn locks&lt;/strong&gt;. This is because the files are like
binary and cannot be easily merged, unlike normal plain text code. In fact,
they could be merged, but do not always expect merge to work as expected
because the text file includes complex tags and these may be broken at merge.&lt;/p&gt;
&lt;p&gt;It is also difficult to resolve conflicts visually. A useful trick is
to set this property on the file: &lt;code&gt;svn propset svn:needs-lock "true"
file_name.fodt&lt;/code&gt;. Then, any &lt;code&gt;svn update&lt;/code&gt; will result this file becoming
read-only. To allow editing, file lock must be enabled. This ensures that
only one user can edit the file at a time.&lt;/p&gt;
&lt;h2&gt;How differences between versions can be checked?&lt;/h2&gt;
&lt;p&gt;Because the Libreoffice files are not just text, checking differences
is not trivial. Normal diff tool will result in lots of messy XML
differences.&lt;/p&gt;
&lt;p&gt;But there is a Linux bash script that helps comparing
the files through converting FODT to PDF and then running diffpdf
utility:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://git.app.uib.no/Sergey.Budaev/lo_svn/-/blob/master/diffodt"&gt;https://git.app.uib.no/Sergey.Budaev/lo_svn/-/blob/master/diffodt&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;There is also a Windows/DOS batch script that does this trick:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://git.app.uib.no/Sergey.Budaev/lo_svn/-/blob/master/diffodt.bat"&gt;https://git.app.uib.no/Sergey.Budaev/lo_svn/-/blob/master/diffodt.bat&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The script requires &lt;code&gt;diffpdf&lt;/code&gt; program that is found in most Linux
distributions. A Windows version is open source but id not normally distributed
in the binary ".exe" form&lt;/p&gt;
&lt;h3&gt;How to use diffodt script&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Compare working copy with the latest revision from svn: &lt;code&gt;diffodt paper.fodt&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Compare the working document with r9925: &lt;code&gt;diffodt 9925 paper.fodt&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Compare two specific versions of the document: &lt;code&gt;diffodt 9925 9987 paper.fodt&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Integrating Subversion into LibreOffice User Interface&lt;/h2&gt;
&lt;p&gt;Lo_SVN is a LibreOffice extension that adds a basic Subversion functionality
into the LibreOffice interface. Then, basic svn commands are available from
the LibreOffice menu.&lt;/p&gt;
&lt;p&gt;&lt;img alt="Lo_SVN" src="https://budaev.info/images/losvn_scr.png" title="Lo_SVN screenshot"&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Source code: &lt;a href="https://git.app.uib.no/Sergey.Budaev/lo_svn"&gt;https://git.app.uib.no/Sergey.Budaev/lo_svn&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Official LibreOffice &lt;strong&gt;extension repository&lt;/strong&gt;:
  &lt;a href="https://extensions.libreoffice.org/en/extensions/show/4071"&gt;https://extensions.libreoffice.org/en/extensions/show/4071&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;User manual&lt;/strong&gt; for Lo_SVN is here:
  &lt;a href="https://budaev.info/pub/doc/Lo_SVN.pdf"&gt;https://budaev.info/pub/doc/Lo_SVN.pdf&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;</content><category term="Subversion"></category><category term="svn"></category><category term="wiki"></category><category term="Q&amp;A"></category></entry><entry><title>Is ​Zoom safe to use? Is the company marketing and other information correct and can be trusted?</title><link href="https://budaev.info/is-zoom-safe-to-use-is-the-company-marketing-and-other-information-correct-and-can-be-trusted.html" rel="alternate"></link><published>2020-04-03T11:10:00+02:00</published><updated>2020-04-03T11:10:00+02:00</updated><author><name>Sergey Budaev</name></author><id>tag:budaev.info,2020-04-03:/is-zoom-safe-to-use-is-the-company-marketing-and-other-information-correct-and-can-be-trusted.html</id><summary type="html">&lt;p&gt;Is ​Zoom safe to use? Is the company marketing and other information correct and can be trusted?&lt;/p&gt;</summary><content type="html">&lt;h2&gt;Zoom privacy and security problems&lt;/h2&gt;
&lt;p&gt;Zoom has demonstrated significant negligence with respect to
cybersecurity. Additionally, the company has shown aggressive marketing
campaigns and was caught at providing false information to its end users.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Zoom aggressively forces the user to download and install native
  application rather than use web browser for videoconferencing even
  though videoconferences will work in the web browser. This is a little
  suspicious. Browser-based conferences are more convenient for an occasional
  user and is safer due to browser sandboxing of network applications.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Serious security deficiency on the Apple Mac platform allowing
  any unauthorized remote attacker to activate web camera, connect
  to a conference and execute denial-of-service attack. Zoom tried
  to ignore and deliberately hide information about the very serious
  security vulnerability and was slow to fix it.
​  &lt;a href="https://medium.com/bugbountywriteup/zoom-zero-day-4-million-webcams-maybe-an-rce-just-get-them-to-visit-your-website-ac75c83f4ef5"&gt;See here for more details&lt;/a&gt;,
​  and &lt;a href="https://techcrunch.com/2019/07/10/apple-silent-update-zoom-app/"&gt;here&lt;/a&gt;
  (technical information is
​  &lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13449"&gt;here&lt;/a&gt; and
​  &lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-13450"&gt;here&lt;/a&gt;).
  Zoom management response seem to point to quite irresponsible corporate
  culture.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;More recently it appeared that Zoom was sending users' data
  to Facebook servers without the user's consent. This is now fixed. See
​  &lt;a href="https://www.vice.com/en_us/article/k7e599/zoom-ios-app-sends-data-to-facebook-even-if-you-dont-have-a-facebook-account"&gt;Vice paper&lt;/a&gt;
​  and &lt;a href="https://www.vice.com/en_au/article/z3b745/zoom-removes-code-that-sends-data-to-facebook"&gt;this follow-up&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Zoom was caught at providing false and misleading information that the
  videoconference has "end-to-end" encryption while this was not so. Check out &lt;a href="https://theintercept.com/2020/03/31/zoom-meeting-encryption/"&gt;this&lt;/a&gt;.
  The explanation for this provided by Zoom is unsatisfactory.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Zoom had a serious security vulnerability that could lead to
  user password leak in Microsoft Windows.
​  &lt;a href="https://www.bleepingcomputer.com/news/security/zoom-lets-attackers-steal-windows-credentials-run-programs-via-unc-links/"&gt;See here for details&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Zoom has a strange privacy policy that, even though states that "privacy
  is very important to us," requires quite large collection of private user's
  information. There is little explanation about to why this information
  is collected. Unlike many other similar companies, Zoom does not release
  transparency report(s). See here: ​&lt;a href="https://zoom.us/privacy"&gt;https://zoom.us/privacy&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Electronic Privacy Information Centre has filed complaint to FCC&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;alleging that the videoconferencing company Zoom has committed unfair
  and deceptive practices in violation of the FTC Act. According to EPIC,
  Zoom intentionally designed its web conferencing service to bypass
  browser security settings and remotely enable a user's web camera
  without the knowledge or consent of the user.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;See more details &lt;a href="https://epic.org/2019/07/epic-files-complaint-with-ftc-.html"&gt;here&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;There is a growing concern on the privacy deficiency in Zoom,
  for more details see ​&lt;a href="https://blogs.harvard.edu/doc/2020/03/27/zoom/"&gt;this&lt;/a&gt; and
​  &lt;a href="https://www.consumerreports.org/video-conferencing-services/zoom-teleconferencing-privacy-concerns/"&gt;this&lt;/a&gt;.
  Also see &lt;a href="https://www.theguardian.com/technology/2020/apr/02/zoom-technology-security-coronavirus-video-conferencing"&gt;The Guardian&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Recently SpaceX has banned Zoom because
  of privacy concerns, see
  &lt;a href="https://www.reuters.com/article/us-spacex-zoom-video-commn/elon-musks-spacex-bans-zoom-over-privacy-concerns-memo-idUSKBN21J71H"&gt;here for details&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Zoom has close links with China. Even though the intellectual property,
  management and marketing are based in the USA, many if not most developers and
  engineers are bsed in China (see &lt;a href="https://www.sec.gov/Archives/edgar/data/1585521/000119312519083351/d642624ds1.htm#toc642624_7"&gt;​Form S-1 registration statement&lt;/a&gt;). This
  can potentially lead to serious privacy and cybersecurity issues, given
  the Chinese regime tightening of Internet regulation (censorship, privacy
  etc.). One example is ​MLPS 2.0 legislation, 2019 mandating China residents
  and any foreign companies unrestricted access to user data. (In China, Zoom
  has a &lt;a href="​https://www.iyiou.com/p/96718.html"&gt;network of agents acting under different names but using the same
  platform&lt;/a&gt;. )&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Updates: More on Zoom problems&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Vulnerabilities:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://objective-see.com/blog/blog_0x56.html"&gt;https://objective-see.com/blog/blog_0x56.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;​&lt;a href="https://www.bleepingcomputer.com/news/security/zoom-lets-attackers-steal-windows-credentials-run-programs-via-unc-links/"&gt;https://www.bleepingcomputer.com/news/security/zoom-lets-attackers-steal-windows-credentials-run-programs-via-unc-links/&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Privacy holes:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://www.nytimes.com/2020/04/02/technology/zoom-linkedin-data.html"&gt;https://www.nytimes.com/2020/04/02/technology/zoom-linkedin-data.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="​https://techcrunch.com/2020/04/03/zoom-calls-routed-china"&gt;​https://techcrunch.com/2020/04/03/zoom-calls-routed-china&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;CitizenLab Report on Zoom:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;CitizenLab published a detailed report on Zoom security and privacy. Here are a few hlights:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Zoom documentation claims that the app uses “AES-256”
  encryption for meetings where possible. However, we find that
  in each Zoom meeting, a single AES-128 key is used in ECB mode
  by all participants to encrypt and decrypt audio and video. The
  use of ECB mode is not recommended because patterns present in
  the plaintext are preserved during encryption.  The AES-128 keys,
  which we verified are sufficient to decrypt Zoom packets intercepted
  in Internet traffic, appear to be generated by Zoom servers, and
  in some cases, are delivered to participants in a Zoom meeting
  through servers in China, even when all meeting participants,
  and the Zoom subscriber’s company, are outside of China.  Zoom,
  a Silicon Valley-based company, appears to own three companies in
  China through which at least 700 employees are paid to develop
  Zoom’s software. This arrangement is ostensibly an effort at
  labor arbitrage: Zoom can avoid paying US wages while selling
  to US customers, thus increasing their profit margin. However,
  this arrangement may make Zoom responsive to pressure from Chinese
  authorities.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;See the full report here: ​&lt;a href="https://citizenlab.ca/2020/04/move-fast-roll-your-own-crypto-a-quick-look-at-the-confidentiality-of-zoom-meetings/"&gt;Move Fast and Roll Your Own Crypto A Quick Look at the Confidentiality of Zoom Meetings&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Google now banned Zoom for its employees: Google has banned the popular
  videoconferencing software Zoom from its employees’ devices, BuzzFeed
  News has learned. Zoom, a competitor to Google’s own Meet app, has seen an
  explosion of people using it to work and socialize from home and has become
  a cultural touchstone during the coronavirus pandemic.
  &lt;a href="​https://www.buzzfeednews.com/article/pranavdixit/google-bans-zoom"&gt;Read here&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Zoom zero-days for sale: People who trade in zero-day
  exploits say there are two Zoom zero-days, one for Windows
  and one for MacOS, on the market.  &lt;a href="https://www.vice.com/en_us/article/qjdqgv/hackers-selling-critical-zoom-zero-day-exploit-for-500000"&gt;See here for more detail&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Zoom is using the microphone even when not in meeting on MacOSX.
  &lt;a href="https://community.zoom.com/t5/Meetings/Why-is-the-Zoom-app-listening-on-my-microphone-when-not-in-a/td-p/29019"&gt;Why is the Zoom app listening on my microphone when not in a meeting?&lt;/a&gt;
  An &lt;a href="https://support.zoom.us/hc/en-us/articles/201361963-New-Updates-for-Mac-OS"&gt;update fixed&lt;/a&gt; the problem... but NOT with microphone being activated, but with interface: microphone indicator.
  Zoom nevertheless &lt;a href="https://habr.com/ru/news/t/650539/"&gt;continues to activate microphone&lt;/a&gt; on MacOSX. Is CCP listening?&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;How to increase privacy and security of using Zoom on Linux&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Sandboxing.&lt;/strong&gt; On the Linux platform, one solution is always to run Zoom
videoconferencing software only in a &lt;strong&gt;limited sandbox.&lt;/strong&gt; Then, Zoom client
would not have access to user's files and other processes running on the
system.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Update: This recipe works for Zoom v. 3.5.361645.0301, but not for some
   later versions, e.g. 3.5.374815.0324, see update below on this.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Disable any unauthorized update/upgrade of Zoom client.&lt;/strong&gt; Do not install
Zoom software via the standard reopository. Use static tar.gz archive
instead. Select Other Linux OS for installation. Uncompress the static
distribution in a safe directory. &lt;em&gt;Disadvantage&lt;/em&gt; of this is that update is
only manual, check out Zoom web site for new releases and read changelog. But
&lt;em&gt;advantage&lt;/em&gt; is that zoom cannot silently install any unauthorized update or
software on the system.&lt;/p&gt;
&lt;p&gt;It also makes sense to register at Zoom with the institutional email but
separate password, so Zoom does not use the main institutional login (SSO
login). This might help against credentials leak in case of Zoom software
vulnerability. Using the institutional email to register would ensure Zoom
is registered as "licensed."&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Install firejail sandboxing.&lt;/strong&gt; ​&lt;a href="https://firejail.wordpress.com/"&gt;https://firejail.wordpress.com/&lt;/a&gt;:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo apt install firejail&lt;/code&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Firejail&lt;/strong&gt; is a SUID program that reduces the risk of security breaches
      by restricting the running environment of untrusted applications using
      Linux namespaces and seccomp-bpf. ... Firejail can sandbox any type
      of processes: servers, graphical applications, and even user login
      sessions. The software includes security profiles for a large number
      of Linux programs: Mozilla Firefox, Chromium, VLC, Transmission etc. To
      start the sandbox, prefix your command with “firejail.”&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Make a configuration file for Zoom in &lt;code&gt;.config/firejail/&lt;/code&gt;. Here is the
configuration file named as the main Zoom run executable: ZoomLauncher.profile
(given the running executable is ZoomLauncher):&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;# Note: to delete all firejail profiles for all local trusted apps
#  run sudo firecfg --clean
# ----------------------------------------------------------------
# Duplication of zoom configs in noblacklist and whitelist
# sections fixes login credentials no save problem:
noblacklist &lt;span class="cp"&gt;${&lt;/span&gt;&lt;span class="n"&gt;HOME&lt;/span&gt;&lt;span class="cp"&gt;}&lt;/span&gt;/.config/zoomus.conf
noblacklist &lt;span class="cp"&gt;${&lt;/span&gt;&lt;span class="n"&gt;HOME&lt;/span&gt;&lt;span class="cp"&gt;}&lt;/span&gt;/.zoom
include /etc/firejail/disable-common.inc
include /etc/firejail/disable-devel.inc
include /etc/firejail/disable-programs.inc
include /etc/firejail/disable-passwdmgr.inc
whitelist &lt;span class="cp"&gt;${&lt;/span&gt;&lt;span class="n"&gt;HOME&lt;/span&gt;&lt;span class="cp"&gt;}&lt;/span&gt;/bin/zoom
whitelist &lt;span class="cp"&gt;${&lt;/span&gt;&lt;span class="n"&gt;HOME&lt;/span&gt;&lt;span class="cp"&gt;}&lt;/span&gt;/.config/zoomus.conf
whitelist &lt;span class="cp"&gt;${&lt;/span&gt;&lt;span class="n"&gt;HOME&lt;/span&gt;&lt;span class="cp"&gt;}&lt;/span&gt;/.zoom
whitelist &lt;span class="cp"&gt;${&lt;/span&gt;&lt;span class="n"&gt;HOME&lt;/span&gt;&lt;span class="cp"&gt;}&lt;/span&gt;/.cache/zoom
whitelist &lt;span class="cp"&gt;${&lt;/span&gt;&lt;span class="n"&gt;HOME&lt;/span&gt;&lt;span class="cp"&gt;}&lt;/span&gt;/downloads
include /etc/firejail/whitelist-common.inc
caps.drop all
netfilter
nodvd
nonewprivs
noroot
notv
protocol unix,inet,inet6
seccomp
private-tmp
# Needed for latest versions of Zoom and perhaps certain other Qt/QML apps
env QML_DISABLE_DISK_CACHE=1
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Now Zoom client can be started from the firejail sandbox:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;firejail /path_to_safe_install_location/bin/zoom/ZoomLauncher
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;To make it possible to use standard graphical menus, one need
to make a zoom.desktop startup file in the user's directory
&lt;code&gt;.local/share/applications&lt;/code&gt;. The Exec entry of the file must include the
firejail-based startup:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="k"&gt;[Desktop Entry]&lt;/span&gt;
&lt;span class="na"&gt;Name&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;Zoom Desktop [Jailed]&lt;/span&gt;
&lt;span class="na"&gt;GenericName&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;Zoom videoconferencing&lt;/span&gt;
&lt;span class="na"&gt;Comment&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;Zoom Desktop Client jailed&lt;/span&gt;
&lt;span class="na"&gt;Exec&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;firejail /path_to_safe_install_location/bin/zoom/ZoomLauncher %f&lt;/span&gt;
&lt;span class="na"&gt;Icon&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;zoom.png&lt;/span&gt;
&lt;span class="na"&gt;Terminal&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;false&lt;/span&gt;
&lt;span class="na"&gt;Type&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;Application&lt;/span&gt;
&lt;span class="na"&gt;Categories&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;Network;Internet;Education;Qt;&lt;/span&gt;
&lt;span class="na"&gt;X-SuSE-translate&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s"&gt;false&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;


&lt;h3&gt;Firejail caveats&lt;/h3&gt;
&lt;p&gt;Firejail can start serving all user's applications in its jail, which is
often too restrictive (e.g. settings are not saved).&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;To force reconfiguring all application to run in firejail do (do not do
  this if you are unsure) this:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo firecfg&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;To disable configuring all local applications to run in jail, do this:&lt;/p&gt;
&lt;p&gt;&lt;code&gt;sudo firecfg --clean&lt;/code&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Do this (&lt;code&gt;sudo firecfg --clean&lt;/code&gt;) if you have problems starting applications
  after installing firejail.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;To check if an application is by default starting in a jail, run it
  from the terminal. If terminal shows several lines like Reading profile
  &lt;code&gt;/etc/firejail/disable-common.inc&lt;/code&gt; then the application runs in a jail.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;A newer version of Zoom client (3.5.374815.0324) refused to run in a jailed
environment and hanged.&lt;/p&gt;
&lt;p&gt;A &lt;em&gt;workaround&lt;/em&gt; for running recent Zoom in jail:&lt;/p&gt;
&lt;p&gt;add the below line &lt;code&gt;env QML_DISABLE_DISK_CACHE=1&lt;/code&gt;&lt;/p&gt;
&lt;p&gt;to the firejail config file.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;QML_DISABLE_DISK_CACHE&lt;/code&gt; Disables the disk cache and forces re-compilation
    from source for all QML and JavaScript files. (from QML Documentation)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;How to increase privacy and security of using Zoom on Microsoft Windows&lt;/h2&gt;
&lt;p&gt;Here is a link on sandbox in Windows 10: How to
use &lt;a href="https://www.windowscentral.com/how-use-windows-sandbox-windows-10-may-2019-update"&gt;Windows sandbox&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;I have not tested how this works.&lt;/p&gt;
&lt;h2&gt;Android sandbox&lt;/h2&gt;
&lt;p&gt;For Android, one solution is to use the open source ​&lt;strong&gt;Shelter&lt;/strong&gt; application,
then mobile Zoom can run in a secure container.&lt;/p&gt;
&lt;p&gt;I have been running several programs that I do not like to give access to
my data within Shelter. It works fine for me.&lt;/p&gt;
&lt;p&gt;Advantages:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Contacts (address book) are not leaked to Zoom if a separate address book
  is used within shelter&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;All apps can be frozen to avoid them run all the time at the background,
  this reduces the chances of data leaks as well as battery drain. Freezing
  can be done automatically, after timeout.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Links&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Google Play:
​  &lt;a href="https://play.google.com/store/apps/details?id=net.typeblog.shelter"&gt;https://play.google.com/store/apps/details?id=net.typeblog.shelter&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;F-Droid: &lt;a href="https://f-droid.org/en/packages/net.typeblog.shelter/"&gt;https://f-droid.org/en/packages/net.typeblog.shelter/&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Source code of Shelter is here: &lt;a href="https://github.com/PeterCxy/Shelter"&gt;https://github.com/PeterCxy/Shelter&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;</content><category term="privacy"></category><category term="security"></category></entry><entry><title>How to make an array and initialize it with a sequence of values in Fortran?</title><link href="https://budaev.info/how-to-make-an-array-and-initialize-it-with-a-sequence-of-values-in-fortran.html" rel="alternate"></link><published>2019-11-20T10:19:00+01:00</published><updated>2019-11-20T10:19:00+01:00</updated><author><name>Sergey Budaev</name></author><id>tag:budaev.info,2019-11-20:/how-to-make-an-array-and-initialize-it-with-a-sequence-of-values-in-fortran.html</id><summary type="html">&lt;p&gt;How to make an array and initialize it with a sequence of values in Fortran?&lt;/p&gt;</summary><content type="html">&lt;p&gt;How do you make an array and initialize it with a sequence of values? For
example, I want a list from 0.25 to 1.5 that is separated with 0.25. In
other words I want something similar to &lt;code&gt;seq(0.25,5,0.5)&lt;/code&gt; in R.&lt;/p&gt;
&lt;h2&gt;Equally spaced real array with fixed increment in Fortran&lt;/h2&gt;
&lt;p&gt;Producing an equally spaced array from V&lt;sub&gt;1&lt;/sub&gt; to V&lt;sub&gt;N&lt;/sub&gt; with
increments &amp;Delta;V&lt;/p&gt;
&lt;!--
Math in markdown:
https://stackoverflow.com/questions/11256433/how-to-show-math-equations-in-general-githubs-markdownnot-githubs-blog
Latex editor:
https://www.codecogs.com/latex/eqneditor.php
--&gt;

&lt;!--
{ V&lt;sub&gt;1&lt;/sub&gt;, V&lt;sub&gt;2&lt;/sub&gt;=V&lt;sub&gt;1&lt;/sub&gt; + &amp;Delta;V, V&lt;sub&gt;3&lt;/sub&gt;=V&lt;sub&gt;2&lt;/sub&gt; + &amp;Delta;V, V&lt;sub&gt;4&lt;/sub&gt;=V&lt;sub&gt;3&lt;/sub&gt; + &amp;Delta;V ... V&lt;sub&gt;N&lt;/sub&gt;=V&lt;sub&gt;N-1&lt;/sub&gt; + &amp;Delta;V}
--&gt;

&lt;p&gt;&lt;img src="https://latex.codecogs.com/svg.latex?\{V_1,V_2=V_1+\Delta V,V_3=V_2+\Delta V,V_4=V_3+\Delta V, ... V_N=V_{N-1}+\Delta V\}"&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;1.&lt;/strong&gt; Each of the values in the above vector can be calculated as:&lt;/p&gt;
&lt;p&gt;&lt;img src="https://latex.codecogs.com/svg.latex?V_i=V_1+\Delta V(i-1)"&gt;&lt;/p&gt;
&lt;!--
V&lt;sub&gt;i&lt;/sub&gt; = V&lt;sub&gt;1&lt;/sub&gt; + &amp;Delta;V (i-1)
--&gt;

&lt;p&gt;&lt;strong&gt;2.&lt;/strong&gt; The total number of values &lt;em&gt;N&lt;/em&gt; in the array ending with a fixed known
V&lt;sub&gt;N&lt;/sub&gt; is equal to&lt;/p&gt;
&lt;p&gt;&lt;img src="https://latex.codecogs.com/svg.latex?N=\frac{V_N-V_1}{\Delta V}+1"&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;3.&lt;/strong&gt; It is not possible to use a simple piece of code like this to produce real type
array in Fortran:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Array = [V1:VN:Incr]
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;&lt;strong&gt;4.&lt;/strong&gt; Such a construction cannot be used in modern Fortran, even though old
    versions could accept a similar construction based on implied loop with real
    type index counter:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;real :: r ! Index must be integer in loops!
print *, (r, r=V1,VN,Incr)
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;&lt;strong&gt;5.&lt;/strong&gt; In modern Fortran standard do loops can only have integer indexing
    variable. Real indexing in do loops is one of the very few features that
    had been deleted from the language because it can create lots of problems
    in float point computations due to finite precision in computer hardware.&lt;/p&gt;
&lt;p&gt;The old code might work with modern compilers but it may require special
legacy compiler options. The printing-only code as above may still work but
would issue a compiler warning.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;6.&lt;/strong&gt; Initialising such equally spaced real type arrays in Fortran implied
     loops must use the formulas defined in 1. and 2.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;# Produce exactly N_VALS values starting from INIT with increments INCR
Array = [( INIT + INCR * (i-1), i=1,N_VALS )]
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Where the number of array elements &lt;code&gt;N_VALS&lt;/code&gt; is calculated as:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;N_VALS = floor( (END - INIT) / INCR + 1 )

N_VALS = ceiling( (END - INIT) / INCR + 1 )
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;The &lt;code&gt;floor&lt;/code&gt; and &lt;code&gt;ceiling&lt;/code&gt; functions convert real value to integer as the lower
or upper nearest integer; they can give different values when division cannot
be done without the remainder&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;# All values starting from INIT with increments INCR and up to the limit END
Array = [( INIT + INCR * (i-1), i=1,floor((END-INIT)/INCR+1) )]
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;&lt;strong&gt;7.&lt;/strong&gt; This code does not seem to be a very simple and elegant solution.
   Ideally, the code should be packaged into a function returning the desired
   grid array. But such function could not be used in declarations of array
   parameters. In the later case the one-liner code should be used as above.&lt;/p&gt;
&lt;h2&gt;Integer arrays&lt;/h2&gt;
&lt;p&gt;By the way, it is quite easy to produce an &lt;strong&gt;integer array,&lt;/strong&gt; e.g. here is an
initialisation for array from &lt;code&gt;1&lt;/code&gt; to &lt;code&gt;100&lt;/code&gt; (&lt;code&gt;|1,2,3,...,100|&lt;/code&gt;). This can be
useful for indexing arrays.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;integer, parameter, dimension(*) :: IDX_ARRAY = (/(i,i=1,100)/)
&lt;/pre&gt;&lt;/div&gt;


&lt;h2&gt;Examples:&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;A.&lt;/strong&gt; Produce an array of 10 values starting from 1.0 with increments 0.1&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Array = [( 1.0 + (i-1) * 0.1, i=1,10 )]
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Result:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;1.00000000 1.10000002 1.20000005 1.29999995 1.39999998
1.50000000 1.60000002 1.70000005 1.79999995 1.90000010
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Declaration of a parameter array:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;real, parameter, dimension(*) :: Array = [( 1.0 + (i-1) * 0.1, i=1,10 )]
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;However, note that not all compilers may support assumed array size
&lt;code&gt;dimension(*)&lt;/code&gt; in such array declaration statement, this requires newer Fortran
standard (fortunately, recent versions of Intel and GNU Fortran do support
assumed size arrays). In such a case declaration must explicitly set the
number of array elements:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;real, parameter, dimension(10) :: Array = [( 1.0 + (i-1) * 0.1, i=1,10 )]
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;&lt;strong&gt;B.&lt;/strong&gt; Produce an array of starting from &lt;code&gt;1.0&lt;/code&gt; to &lt;code&gt;2.0&lt;/code&gt; with increments &lt;code&gt;0.145&lt;/code&gt;;
note that lower value (&lt;code&gt;floor&lt;/code&gt;) for the array size is used:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Array = [( 1.0 + 0.145 * (i-1), i=1, floor((2.0-1.0)/0.145 + 1) )]
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Result:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;1.00000000 1.14499998 1.28999996 1.43499994 1.57999992
1.72499990 1.87000000
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;&lt;strong&gt;C.&lt;/strong&gt; The same as (B) but the upper value (&lt;code&gt;ceiling&lt;/code&gt;) for the array size is used:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;Array = [( 1.0 + 0.145 * (i-1), i=1, ceiling((2.0-1.0)/0.145 + 1) )]
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;Result:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;1.00000000 1.14499998 1.28999996 1.43499994 1.57999992
1.72499990 1.87000000 2.01499987
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;&lt;strong&gt;D.&lt;/strong&gt; In the case B., declarations of parameter arrays can be done like this:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;real, parameter, dimension(*) :: Array =                                  &amp;amp;
                 [( 1.0 + 0.145 * (i-1), i=1, floor((2.0-1.0)/0.145 + 1) )]
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;or, if the compiler does not support assumed size arrays &lt;code&gt;(*)&lt;/code&gt;, with explicitly
calculated array size:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;real, parameter, dimension(floor((2.0-1.0)/0.145 + 1)) :: Array =         &amp;amp;
                 [( 1.0 + 0.145 * (i-1), i=1, floor((2.0-1.0)/0.145 + 1) )]
&lt;/pre&gt;&lt;/div&gt;


&lt;h2&gt;Test program&lt;/h2&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;! This program illustrates how to produce equally spaced real vectors with
! fixed increment in Fortran.
!
! 1. Produce exactly N_VALS values starting from INIT with increments INCR
! Array = [( INIT + INCR * (i-1), i=1,N_VALS )]
!
! 2. All values starting from INIT with increments INCR and up to the limit END
! Array = [( INIT + INCR * (i-1), i=1,floor((END-INIT)/INCR+1) )]
!-------------------------------------------------------------------------------
program spaced_array

    ! Integer counter for implied loops defining vectors.
    integer :: i

    ! Example A. Produce an array of 10 values
    ! starting from 1.0 with increments 0.1
    real, parameter, dimension(*) :: Array1 = [( 1.0 + (i-1) * 0.1, i=1,10 )]


    ! Example B. Produce an array of starting from 1.0 to 2.0
    ! with increments 0.145.
    ! Note that lower value (floor) for the array size is used.
    real, parameter, dimension(*) :: Array2 = &amp;amp;
    [( 1.0 + 0.145 * (i-1), i=1, floor((2.0-1.0)/0.145 + 1) )]

    ! Example C. The same as (B) but the upper value (ceiling) for the
    ! array size is used.
    real, parameter, dimension(*) :: Array3 = &amp;amp;
    [( 1.0 + 0.145 * (i-1), i=1, ceiling((2.0-1.0)/0.145 + 1) )]

    ! Print the sizes of the arrays that were declared above.
    print *, &amp;quot;Array sizes (Array1, Array2, Array3)&amp;quot;, &amp;amp;
    size(Array1), size(Array2), size(Array3)

    ! Print the parameter arrays that were declared above.
    print *, &amp;quot;Array1&amp;quot;, Array1
    print *, &amp;quot;Array2&amp;quot;, Array2
    print *, &amp;quot;Array3&amp;quot;, Array3

end program spaced_array
&lt;/pre&gt;&lt;/div&gt;


&lt;h2&gt;PDF Card&lt;/h2&gt;
&lt;p&gt;A PDF version of this document is available here: &lt;a href="https://budaev.info/images/spaced-array.pdf"&gt;https://budaev.info/images/spaced-array.pdf&lt;/a&gt;.&lt;/p&gt;</content><category term="Fortran"></category><category term="wiki"></category><category term="Q&amp;A"></category></entry><entry><title>How to produce a reverse of a vector in Fortran?</title><link href="https://budaev.info/how-to-produce-a-reverse-of-a-vector-in-fortran.html" rel="alternate"></link><published>2019-11-20T10:19:00+01:00</published><updated>2019-11-20T10:19:00+01:00</updated><author><name>Sergey Budaev</name></author><id>tag:budaev.info,2019-11-20:/how-to-produce-a-reverse-of-a-vector-in-fortran.html</id><summary type="html">&lt;p&gt;How to produce a reverse of a vector in Fortran?&lt;/p&gt;</summary><content type="html">&lt;p&gt;Let's we have a vector A, e.g.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;A = [1,2,3,4,5]
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;How to produce a vector with reverse indices, e.g.&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;B = [5,4,3,2,1]
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;The answer is this:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nv"&gt;B&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;A&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="nf"&gt;size&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;A&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="s s-Atom"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;:-&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt; &lt;span class="p"&gt;)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;To reverse A itself do&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;&lt;span class="nv"&gt;A&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nv"&gt;A&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt; &lt;span class="nf"&gt;size&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nv"&gt;A&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="s s-Atom"&gt;:&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;:-&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt; &lt;span class="p"&gt;)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;</content><category term="Fortran"></category><category term="wiki"></category><category term="Q&amp;A"></category></entry><entry><title>Gaussian random numbers in Fortran</title><link href="https://budaev.info/gaussian-random-numbers-in-fortran.html" rel="alternate"></link><published>2018-06-13T13:22:00+02:00</published><updated>2018-06-13T13:22:00+02:00</updated><author><name>Sergey Budaev</name></author><id>tag:budaev.info,2018-06-13:/gaussian-random-numbers-in-fortran.html</id><summary type="html">&lt;p&gt;Gaussian random numbers in Fortran&lt;/p&gt;</summary><content type="html">&lt;p&gt;The &lt;a href="https://ahamodel.uib.no/doc/#_introduction_to_the_aha_fortran_modules"&gt;HEDTOOLS&lt;/a&gt;
tools library has a module for working with random numbers
&lt;a href="https://ahamodel.uib.no/doc/#_module_base_random"&gt;BASE_RANDOM&lt;/a&gt;​. There is, in
particular, a set of procedures for generating
Gaussian random values: ​&lt;a href="https://ahamodel.uib.no/doc/#_functions_rnorm_r4_rnorm_r8_rnorm"&gt;RNORM&lt;/a&gt;
and &lt;a href="https://ahamodel.uib.no/doc/#_arrays_of_random_numbers_rand_array_and_rnorm_array"&gt;RNORM_ARRAY&lt;/a&gt;.
These are based on the Kinderman &amp;amp; Monahan, augmented with quadratic
bounding curves method (Leva, 1992: algorithm 712, Trans. Math. Software,
18, 4, 434-435​).&lt;/p&gt;
&lt;p&gt;I have made a quick comparison of the quality of the Gaussian random numbers
generated by the simple Box-Muller method (Box &amp;amp; Muller, 1958​)&lt;/p&gt;
&lt;p&gt;Classical (ancient) Fortran code:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;normrand_number = dsqrt(-2.*dlog(drand(0)))*dcos(2.*pi*drand(0))
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;that has been used in TEG codes so far...&lt;/p&gt;
&lt;p&gt;and the algorithm 712 as implemented in &lt;code&gt;HEDTOOLS&lt;/code&gt; using this test program
(see attachment).&lt;/p&gt;
&lt;p&gt;Fortran code for the test program:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;program test_bm
  use csv_io
  use base_random, rand_x =&amp;gt; rand     ! Alias rand() as rand_x() for ifort.
  !use IFPORT, only : rand_x =&amp;gt; rand  ! This is the Intel Fortran tweak.

  integer, parameter :: prec = 8, arrsize=100000
  character(len=255), parameter :: filename1=&amp;quot;file_01.csv&amp;quot;, filename2=&amp;quot;file_02.csv&amp;quot;
  real(kind=prec), dimension(arrsize) :: norand1, norand2
  real :: timer_start, timer_end
  !-------------------------------------------------------------------------------
  ! Generating Box-Muller random numbers
  call cpu_time(timer_start)  ! START
  do i=1, arrsize
    norand1(i) = sqrt(-2.*log(rand_x(0)))*cos(2.*pi*rand_x(0))
  end do
  call cpu_time(timer_end)    ! END
  print *, &amp;quot;Box-Muller took: &amp;quot;, timer_end - timer_start
  ! Write random normal data to CSV
  call CSV_MATRIX_WRITE(norand1, filename1)
  !-------------------------------------------------------------------------------

  !-------------------------------------------------------------------------------
  ! Generating based on algorithm 712
  call cpu_time(timer_start)  ! START
  call RNORM_ARRAY(norand2)
  call cpu_time(timer_end)    ! END
  print *, &amp;quot;Alg. 712 took: &amp;quot;, timer_end - timer_start
  ! Write random normal data to CSV
  call CSV_MATRIX_WRITE(norand2, filename2)
  !-------------------------------------------------------------------------------

end program test_bm
&lt;/pre&gt;&lt;/div&gt;


&lt;h2&gt;Comparison of Box-Muller and A712&lt;/h2&gt;
&lt;p&gt;The alg. 712 looks slightly faster than the simple Box-Muller transform.&lt;/p&gt;
&lt;p&gt;alg. 712 is much better, as the Box-Muller significantly deviates from the
normal distribution, alg. 712 does not (using the Anderson-Darling test from
the nortest R package).&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre&gt;&lt;span&gt;&lt;/span&gt;  # Gaussian random numbers by Box-Muller deviate from the Normal distribution:
  &amp;gt; ad.test(data_bm$X1)
      Anderson-Darling normality test
  data:  data_bm$X1
  A = 581.7, p-value &amp;lt; 2.2e-16
  # Gaussian random numbers by Kinderman &amp;amp; Monahan&amp;#39;s A712 do not deviate from the Normal distribution:
  &amp;gt; ad.test(data_a712$X1)
      Anderson-Darling normality test
  data:  data_a712$X1
  A = 0.46975, p-value = 0.2474
&lt;/pre&gt;&lt;/div&gt;


&lt;p&gt;So, the alg. 712 procedure implemented in HEDTOOLS should be used instead
of the Box-Muller method.&lt;/p&gt;
&lt;h2&gt;References&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Box, G. E. P., &amp;amp; Muller, M. E. (1958). A note on the generation of
  random normal deviates. The Annals of Mathematical Statistics, 29(2),
  610–611. ​http://doi.org/10.1214/aoms/1177706645&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Leva, J. L. (1992). Algorithm 712; a normal random number
  generator. ACM Transactions on Mathematical Software, 18(4),
  454–455. ​http://doi.org/10.1145/138351.138367&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;</content><category term="Fortran"></category><category term="wiki"></category><category term="Q&amp;A"></category></entry><entry><title>About me</title><link href="https://budaev.info/about-me.html" rel="alternate"></link><published>2018-05-06T21:30:00+02:00</published><updated>2018-05-06T21:30:00+02:00</updated><author><name>Sergey Budaev</name></author><id>tag:budaev.info,2018-05-06:/about-me.html</id><summary type="html">&lt;p&gt;I am a researcher at the Theoretical Ecology Group, the University of
Bergen, Norway. My current research focuses on animal and human behaviour
in the adaptive and evolutionary perspective. How cognition, behaviour and
personality have evolved through adaptation and natural selection? In my
work I try to integrate both proximate …&lt;/p&gt;</summary><content type="html">&lt;p&gt;I am a researcher at the Theoretical Ecology Group, the University of
Bergen, Norway. My current research focuses on animal and human behaviour
in the adaptive and evolutionary perspective. How cognition, behaviour and
personality have evolved through adaptation and natural selection? In my
work I try to integrate both proximate and ultimate causation and use both
experimental and &lt;a href="https://ahamodel.uib.no"&gt;modelling&lt;/a&gt; approaches.&lt;/p&gt;
&lt;h2&gt;Cognition and behaviour&lt;/h2&gt;
&lt;p&gt;The current work concerns developing a large scale simulation model
that implements a general decision-making architecture in evolutionary
agents. Each agent is programmed as a whole virtual organism including the
genome, rudimentary physiology, the hormonal system, a cognitive architecture
and behavioural repertoire. They "live" in a stochastic spatially explicit
virtual 3-D environment with physical gradients, predators and prey. The
primary aim of the whole modelling machinery is to understand the evolution
of decision making, personality, emotion and behavioural plasticity within
a realistic ecological framework.&lt;/p&gt;
&lt;p&gt;I believe that understanding and modelling complex adaptive behaviour
requires both extraneous factors and stimuli as well as endogeneous
architectural mechanisms (genetic, hormonal, cognitive etc.) that produce the
behaviour. Explicit proximate representation of the motivation and emotion
systems, prediction-oriented cognition provides a better approach to understand
the behaviour, adaptation and evolution of the whole organism. Ultimately,
such an approach can help us understand the evolutionary emergence of
consciousness and complex cognition.&lt;/p&gt;
&lt;p&gt;For more details, links to source codes etc. see
&lt;a href="https://ahamodel.uib.no"&gt;The AHA Model web page&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Animal personality&lt;/h2&gt;
&lt;p&gt;Although I am interested in any species, most of my work so far has been
conducted on fish. Using series of tests we have shown that individual fish
of several species have consistent personality traits that translate to
a variety of different adaptive contexts. Individual fish with different
personalities, such as shy and bold, may behave quite differently in their
natural environment, e.g. prefer different social strategies (school or not
to school) and different local habitats. Shy and bold fish choose their
mates based on personality, personality also significantly affects their
parental care tactics. Personality in fish can be linked to the operant
learning performance. For example, shy fish may be more susceptible to the
development of the conditioned fear, providing a link between emotion and
personality in such "lower" vertebrates. It is also possible to trace the
development and the appearance of consistent personality traits during the
ontogeny. Certain environmental effects, like exposure to light, acting early
in the ontogeny could significantly affect fish personality via the involvement
of specific brain structures, such as the photosensitive habenula. Personality
in fish and other species could be linked with lateral asymmetries via the
involvement of the morphologically asymmetrical habenula. I am also interested
in the adaptive and evolutionary mechanisms that bring about patterns of
consistent personality and alternative strategies. We have shown that gender
differences in personality follow from sex-related adaptive strategies in
humans. In another study we have shown how a trade-off between parental
food provisioning and the fry's own individual experience of searching for
cryptic food creates a range of parental strategies in a cichlid fish. This
reflects my specific interest in the evolution of mate choice and parental
care in fish, and their potential role in sympatric speciation. Currently,
we are developing models linking emotion and decision making to understand
the proximate and ultimate factors governing the evolution of consistent
personality.&lt;/p&gt;
&lt;h2&gt;Ecology and conservation&lt;/h2&gt;
&lt;p&gt;I am also interested in complex biological interactions at various levels,
e.g. competitive interactions between multiple cladoceran species and their
predators, and relationships between various associates and the host within
a symbiotic community. The former is closely linked with conservation and
species invasion. We have developed a model that allows to predict the
population dynamics and the invasion success among freshwater cladocerans
in various conditions. I took part in several conservation projects, ranging
from coral reef and freshwater conservation in Vietnam to fish monitoring and
protection in subarctic Siberian rivers and optimising sturgeon hatcheries. We
have developed a series of quick low-technology tests for rapid assessment of
the coral reef health. Additionally, we have developed hydroacoustic methods
for the assessment of the fish populations in very shallow water bodies,
such as large Siberian floodplains.&lt;/p&gt;
&lt;h2&gt;Links&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://scholar.google.com/citations?hl=en&amp;amp;user=RxvZR7UAAAAJ"&gt;Google Scholar&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://orcid.org/0000-0001-5079-9795"&gt;ORCID 0000-0001-5079-9795&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://www.uib.no/personer/Sergei.Budaev"&gt;Universitetet i Bergen&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://bio.uib.no/te/sb/"&gt;Theoretical Biology Group&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href="https://ahamodel.uib.no/"&gt;The AHA Model&lt;/a&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;</content><category term="research"></category><category term="behaviour"></category><category term="ecology"></category><category term="evolution"></category></entry><entry><title>Evolution again</title><link href="https://budaev.info/evolution-again.html" rel="alternate"></link><published>2009-11-15T11:00:00+01:00</published><updated>2009-11-15T11:00:00+01:00</updated><author><name>Sergey Budaev</name></author><id>tag:budaev.info,2009-11-15:/evolution-again.html</id><summary type="html">&lt;p&gt;Critics of the evolutionary theory (ET) are struggling against windmills.&lt;/p&gt;</summary><content type="html">&lt;p&gt;This is a copy of a letter published in &lt;a href="https://budaev.info/pub/pubs/mass-ages-letter-nov2009.pdf"&gt;Mass of Ages November 2009&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Critics of the evolutionary theory (ET) are struggling against windmills.  ET
is a specific biological theory based on a precise mechanism, natural
selection. When understood in its duly limited scientific context, it has
nothing to do with the spiritual, does not translate to the evolution of the
Universe, evolutionism in philosophy or theology. ET is not intrinsically
atheistic either.&lt;/p&gt;
&lt;p&gt;ET does not contradict the Genesis and the Catholic doctrine. The Church has
never condemned or even questioned scientific ET. “Evolution is scientifically
proven to be impossible and continues to lose credibility on scientific
grounds.” Wrong, ET has huge support in genetics, ecology, paleonthology,
mathematics etc. “Alternatives like the Creation science or Intelligent Design
are not religiously affiliated, and provide arguments against the ET.” Wrong,
these so-called “theories” are the invention of protestant fundamentalists.
They lack credibility and are not even considered seriously by most biologists.
ET “has brought us the mass murder of the unborn,” evolutionism in theology
etc. Wrong emotional argument, should we then question the scientific validity
of modern physics because of Hiroshima?&lt;/p&gt;
&lt;p&gt;ET is not incompatible with the Magisterium, but it is incompatible with the
false theology of fundamentalist protestants: impossibility of any creative
activity of the matter, synergism between the Creator and the created (hence
total depravity as a result of the fall, sola fide salvation, predestination),
sola scriptura and literate interpretation etc. Do not allow these false
doctrines to creep into the Catholic teaching.&lt;/p&gt;</content><category term="Blog"></category><category term="Catholicism"></category><category term="Faith"></category><category term="Evolution"></category><category term="Darwin"></category></entry></feed>