What format survives a decade of neglect?
Plain text and HTML with no build step, images in formats older than the archive itself. The test is not whether it opens today but whether it opens with no software you have to install first.
How do you decide what is worth archiving at all?
Keep what you cannot recreate and what you would miss. Everything downloadable again is a cache, not an archive, and treating the two the same is what turns 200 GB of real memories into 4 TB of noise.
Is bit rot a real concern for a home library?
Real but slow. A yearly checksum pass over a few terabytes catches it long before you notice visually, and the value is knowing which copy is the good one when two disagree. Without checksums, sync happily propagates the corrupted file over the intact one.
What do I collect before deleting an account?
The official export, a screenshot of the settings, and a note about what the export did not include. That last one is the part nobody writes down, and it is what you need when you open the archive years later and wonder what is missing.
Where should a local app keep an API key?
In the OS keychain, through the platform API rather than a file you encrypt yourself. Any scheme where the app can decrypt the key without user interaction is obfuscation, so the honest choice is the keychain, and telling the user plainly that anything on their disk is readable by anything running as them.
bcrypt, scrypt or argon2 for a new project?
Argon2id with the current OWASP parameters, and bcrypt only when a library constraint forces it. What matters more than the choice is that the cost parameter is revisited: a setting tuned five years ago is now cheap to attack.
What is a sane rate limit design for a public API?
Token bucket per key and per IP, with the limit expressed in the response headers so clients can behave. The subtle part is what you do on limit: a 429 with Retry-After is cooperative, silently dropping is what turns one misbehaving client into a retry storm.
Do I need CSRF protection if I use bearer tokens?
Not if the token lives in memory and is sent in a header, because the browser will not attach it automatically. The moment it moves into a cookie for convenience, CSRF is back, and SameSite=Lax becomes load-bearing.
How often should a small project bump dependencies?
Monthly for a project with a test suite, immediately for anything with a published advisory. Batch the routine bumps into a single change so the diff is reviewable, and keep security updates separate so they can go out without waiting for a release.
df says 96% full, du disagrees. What is going on?
Almost always a deleted file still held open by a process, so the space is gone but no path points at it. lsof +L1 lists them; restarting the holder releases the space instantly.
My service restarts in a loop and floods the journal.
Add a backoff. RestartSec=5 plus StartLimitIntervalSec=120 and StartLimitBurst=5 turns a hot loop into five attempts and then a stop, which is what you want: a service that cannot start should stay down loudly rather than churn quietly.
journalctl output is overwhelming during an incident.
Narrow before you read: journalctl -u myservice --since "10 min ago" -p warning gives the unit, the window and the severity in one line. -o cat strips the metadata once you know where you are.
Two users need to write to the same folder without stepping on each other.
A shared group plus the setgid bit: chgrp team dir && chmod 2775 dir. New files inherit the group, which is the part plain chmod 775 misses and the reason it stops working on the second day.
The script runs fine in my shell and does nothing from cron.
Cron runs with a minimal environment and no profile. Use absolute paths, set PATH at the top of the crontab, and redirect output to a file so the failure has somewhere to appear. Nine times in ten the missing piece is one of those three.
rsync of a directory with 2M small files takes forever.
The bottleneck is per-file syscalls, not bandwidth. tar piped over ssh moves them as a single stream and is often several times faster; rsync becomes the right tool again on the second run, when only the differences matter.
Which mini PC is quiet enough to sit in a bedroom?
Anything fanless with a passive case, or a laptop-class chip undervolted and capped below its turbo. The noise people actually notice is not the fan at load but the pulsing at idle, so a fan curve with a wide hysteresis matters more than the rated decibels.
My desk wobbles at full height. Anything short of replacing it?
A cross brace at the back removes most of the sway, and moving the heaviest item to the centre helps more than it should. If the wobble is front to back rather than side to side, the feet are the problem and shims fix it in five minutes.
What ratio and time for cold brew that does not taste harsh?
1:8 coffee to water by weight for a concentrate, 16 to 18 hours in the fridge, coarse grind. Harshness at that ratio is usually grind size rather than time: too fine and you over-extract even cold.
How do I plan dinners that still happen on the bad days?
Plan four, not seven, and make one of them deliberately trivial. The plans that fail are the ones with no slack, because a single late evening cascades into ordering food for the rest of the week.
The rear derailleur skips on the third gear when I push hard.
Cable tension first: a quarter turn on the barrel adjuster while pedalling usually finds it. If it only skips under load and shifts cleanly otherwise, suspect a worn cassette paired with a new chain, which no amount of adjustment fixes.
I come back from a trip with 2000 photos and never sort them.
Two passes, both fast. First pass rejects only: anything out of focus or duplicated, no thinking. Second pass picks the keepers from what survived. Trying to judge quality on the first pass is what makes people abandon the whole thing.
Is RAW worth the storage for holiday photos?
For photos you will edit, yes; for the rest it is a tax you pay forever. A practical middle ground is RAW plus JPEG on trips and JPEG only for everyday shots, then discarding the RAWs you never opened after a year.
My edits look wrong on the phone.
Untagged exports assume sRGB and phones do not. Export with the profile embedded and edit on a display you have calibrated at least once. Perfect agreement is not achievable, consistent-enough is.