Show Sidebar

This is the home-page of Karl Voit.

On this page you can see the latest blog updates. For further articles, please use the search bar or navigate through the blue tags. My recommendations are pim, privacy, or security.

I recommend any decent RSS/Atom aggregator to get notified on blog updates.

Most recent articles or updates:

2024-12-25: UOMF: On How to Define Projects in Org Mode

This is an article from a series of blog postings. Please do read my "Using Org Mode Features" (UOMF) series page for explanations on articles of this series.

In my world, I tend to define "projects" as a construct that contains a set of tasks in order to reach a common project goal. A project may contain another (sub-) project.

Within Org mode, I need a syntax element to decorate my projects as such in order to make sure Org recognizes projects in case I need Org mode support for projects.

Read the whole article ...

2024-12-23: Feedback zur Podcastepisode FOCUS ON: Linux 140 zu Org-Tools

Update 2024-12-23: Aspekte für kollaboratives Arbeiten ergänzt

Der Podcast "FOCUS ON: Linux" (keine mir bekannte Homepage) brachte am 2024-12-19 eine Episode zu "Org-Tools" (vermutlich kurz für "Organisationstools").

Die Shownotes dazu findet man unter anderem unter podigee.io.

Für mch war die Episode insofern sehr spannend, weil ich wieder mal viel über die Anforderungen von Menschen lernen durfte, die sie an ihre PIM-Tools stellen. Sowas finde ich immer sehr aufschlussreich.

Ich habe allerdings auch einige Dinge auszusetzen beziehungsweise Falschinformation zu korrigieren.

Read the whole article ...

2024-12-22: Org Mode Syntax Is One of the Most Reasonable Markup Languages to Use for Text

Disclaimer: this is a very nerdy blog entry. It is about lightweight markup languages and why I think that Org mode syntax is the best lightweight markup language for many use-cases. And with lightweight markup language, I do mean the syntax, the way you express headings, lists, font variations such as bold face or italic, and such things.

Please do note that this is not about Emacs at all. This is about Org mode syntax and its advantages even when used outside of Emacs. You can type Org mode syntax in vim, notepad.exe, Atom, Notepad++, and all other text editors out there. And in my opinion it does have advantages compared to the other, common lightweight markup standards such as Markdown, AsciiDoc, Wikitext or reStructuredText.

Of course, Org mode syntax is my favorite syntax. Despite my personal choice you will see that I've got some pretty convincing arguments that underline my statement as well. So this is not just a matter of personal taste.

If you already have a grin on your face because you don't have any clue what this is all about: keep on reading. It makes an excellent example for making fun of nerds at your next dinner party. ;-)

Read the whole article ...

2024-12-16: Clippings

On this page, I collect my public/media appearances of any kind.

I do have a separate press information page with my bio in German and English, summary of my academic work and photographs to download. Drop me a line via email in order to get the URL.

Most recent updates:

Some of them are available in German language only.

Read the whole article ...

2024-12-01: Bluesky ist kein dezentrales soziales Netzwerk

Die Wochenzeitung Falter schreibt via Tessa Szyszkowitz in Ihrer Ausgabe 48/24 auf Seite 26:

2019 gab Jack Dorsey auf Twitter bekannt, dass er fünf „Open-Source-Architekten“ darauf ansetze, ein Produkt zu entwickeln, das „einen offenen und dezentralisierten Standard für soziale Medien“ entwickeln solle.

Und weiter:

Als CEO konzentrierte sich Graber ab 2021 auf den Kern der Gefahr: Soziale Medien besitzen nicht nur die Daten ihrer User, sie monetarisieren sie auch. Bei Bluesky kann eine Userin jetzt ihre Daten mitnehmen. Graber entwickelte das AT-Protokoll, ein dezentralisiertes System, damit nicht eine Firma alle Daten besitzt. Ob das in Zukunft klappen wird, ist bisher unklar.

Das stimmt soweit auch beinahe.

Allerdings liest sich dieser Artikel - wie auch so viele andere zur Zeit - so, als ob Bluesky tatsächlich ein dezentrales Medium wäre. Das ist allerdings falsch.

Sie müssen nicht mein Wort dafür nehmen. Ich habe hier ein paar Quellen mal verlinkt, die sich mit dem Thema weitaus näher beschäftigt haben:

Read the whole article ...

2024-11-27: Nobody's Perfect: My Personal PIM Debt

I do write a lot about PIM topics, I did some PIM research about local file management, I love to give lectures on PIM topics. Therefore, it's quite natural that people start to believe that my personal PIM situation is near perfect.

As I once wrote on Mastodon, this is not the case at all:

A screenshot of a Mastodon message that reads
My Mastodon post about spring-cleaning my Org-mode inbox file.

I got great feedback from people writing that they are relieved that even "somebody like me" is really struggling with processing all the information as properly as desired.

Therefore, I want to update this persistent article from time to time, showing my current status of some digital debt in terms of unprocessed items in various inboxes of mine.

Read the whole article ...

2024-11-27: UOMF: Linking Headings

This is an article from a series of blog postings. Please do read my "Using Org Mode Features" (UOMF) series page for explanations on articles of this series.

In this article, I'm going to explain how I am using internal links to create links pointing to headings using unique :ID: properties.

Read the whole article ...

2024-11-12: Read That Before You Trust Anything by Microsoft Once Again

This is huge. This is important.

In July 2023 Microsoft had to announce a security incident which impact is more or less a total desaster for Microsoft and its trustworthyness. This was only the beginning of the story of the biggest security catastrophy I have heard so far.

When I tell people about that incident, they usually don't seem to believe. I blame the general media for not having properly covered the incident. This should have been in the headlines for weeks and Microsoft should be history by now. To my astonishment, this was not the case. Not even close. Even Wikipedia is not as alarming as the incident should indicate.

Why do I think that way? In short: basically any service provided by Microsoft and at least all Windows hosts need to be considered hacked beyond repair. This is the mother of worse case scenarios when it comes to security.

Let me explain - using sources we trust.

Read the whole article ...

2024-11-05: Wie man eine vertrauenswürdige Authentifizierungs-App auswählt

Ich war beim Podcast Methodisch inkorrekt! in Episode 239 mit einen Audiokommentar on air, wo ich etwas zu den Themen "Wie man eine Authentifizierungs-App auswählt" und Passwortsicherheit im Allgemeinen sagen durfte. Der bezog sich auf die Diskussion zum Thema "Google" der Podcast-Episode 238 "Mö Mö", wo Reini einen etwas saloppen Kommentar zu der Thematik geäußert hat.

In diesem Artikel möchte ich den Teil mit der Auswahl einer TOTP-Anwendung beschreiben. Die meisten Punkte können jedoch auch für die Auswahl von sicherer Software verallgemeinert weiterverwendet werden.

Für ganz allgemeine Tipps zur Auswahl von Werkzeugen wie Softwareprodukten, empfehle ich meinen (englischsprachigen) Artikel zur Tool-Auswahl.

Falls du zuvor noch generell etwas über Passwortsicherheit und Zweifaktor-Authentifizierung lernen willst, so lies dir meinen Artikel zu Passwortsicherheit durch und komm zum Thema Authentifizierungs-App und TOTP hierher zurück.

Es gibt verschiedene Authenticator-App-Typen. Deshalb sollte man sich zuerst bewusst werden, worüber man gerade spricht.

Neben proprietären Authenticator-Apps verschiedener Firmen, die keinem offenen Standard folgen, gibt es den aktuell weit verbreiteten Standard TOTP, der für "Time-based One-time Password" steht. Da zu ersterem mangels Einsicht in den Code keine sicherheitstechnische Aussage getroffen werden kann, kann ich hier nur zu TOTP schreiben.

TOTP ist den meisten Anwendern durch einen QR-Code bekannt, den man beim erstmaligen Einrichten einer neuen Zugangsberechtigung mit der TOTP-App einlesen muss.

Da es sich um einen offenen Standard handelt, gibt es hier etliche Apps, die TOTP-Funktionalität zur Verfügung stellen.

Meine persönlichen Kriterien zur App-Auswahl sind:

  1. möglichst eine freie Software mit großer Community
  2. vertrauenswürdige Hersteller- und Installations-Quellen
  3. keine unnötigen Berechtigungen

Read the whole article ...

2024-11-03: What App am I Using for What and How?

Here is a list of tasks I do on my computers and the software I am using for accomplishing these tasks. The first column also links corresponding workflow descriptions with further information on how I am doing things which should be our focus, not the tool. At the very bottom, there are links to more workflow descriptions.

For all the Emacs people visiting this page: here, I just list a few Emacs packages. For more details on which packages I'm using for my workflows, please do visit my online Emacs config and check out the first chapters explaining my setup.

It is important to emphasize that you can not derive anything for your situation without knowing my requirements and how they lead to my choice for a tool. For some workflows, I've added a link to further information which might also contain a description of my requirements (first column).

Read the whole article ...

2024-10-17: Worklab 2023: "The Art of Organizing Yourself and Your Data"

Update 2024-10-17: sketchnote and captions by Sacha Chua

In June 2023, I got invited to give a short talk about local file management at the Worklab 2023 which was organized by mur.at. This time, I used a different idea and talked about a few general concepts and ideas related to this topic. A few things I took from my PIM lecture.

The talk was part of the session "Desire to collect - Tools & Roadmap".

Fortunately, the talk was recorded and got published in October 2023 (44min):

Here are the main topics of my talk with some links:

Sacha Chua created awesome sketchnotes for that talk:

Sacha Chua: Sketchnote for the talk. (click for a larger version)

Its licensed under a Creative Commons Attribution. She also published captions for the video recording file.

2024-10-13: The Average Price Per Month for My Smartphones so Far (2024-10 edition)

I've already calculated the average price for my smartphones twice:

You might want to skim over the older article in order to learn about my motivation to do the calculation and also some development here in the past.

Now as I've switched from my beloved Pixel 4a to a Pixel 8, I'm going to post an update with the current figures.

Read the whole article ...

2024-10-13: Switching from a Pixel 4a (Stock ROM) to Pixel 8 (GrapheneOS)

After losing security updates for my Google 4a for many months and open firmware vulnerabilities got exploited in the wild, I finally had to replace it with a smartphone that gets its updates on a regular basis.

I've been thinking of a replacement device starting with the release of the Pixel 8 series in autumn 2023. Too soon, as I've still got a bit of support range until end of 2023.

This is my story on getting a new smartphone in 2024.

Read the whole article ...

2024-10-06: Authentifizierung mit FIDO2 und Passkeys

In letzter Zeit wurde nicht zuletzt durch das Engagement der großen Megacorps Microsoft, Google, Apple und Amazon das Thema Passkeys in der breiten Bevölkerung bekannter.

Allerdings sind die zahlreichen Auswirkungen des Themas für IT-Sachkundige als auch für nicht IT-Sachkundige nicht so ganz einfach zu verstehen.

Ich habe einige allgemeine Dinge zu Passwortsicherheit unter diesen Artikel zusammengefasst und da kommen FIDO2 und Passkeys bereits vor:

In "Wie man eine vertrauenswürdige Authentifizierungs-App auswählt" erkläre ich, wie man sich gute mobile Authentifizierungslösungen aussucht, ohne, auf die Technik näher einzugehen.

FIDO2 und Passkeys sind sich recht ähnlich und werden oft auch verwechselt oder über einen Kamm geschert. Es gibt meiner Meinung nach auch keine genaue Definition von "Passkeys".

Für alle Menschen, die ein wenig mehr über die Unterschiede und jeweiligen Vor- und Nachteile lernen wollen, ist dieser Artikel geschrieben:

TL;DR: Zwei moderne FIDO2 Hardware-Token kaufen, die auch mit Passkeys umgehen können. Primär FIDO2 nutzen, wo es geht und ansonsten Passkeys oder mit niedrigerer Priorität auch andere Mehrfachauthentifizierungsmethoden.

Falls ich wo etwas falsch aufgefasst haben sollte oder wenn sich etwas an der beschriebenen Sachlage ändert, freue ich mich über Feedback (unten).

Read the whole article ...

2024-09-27: (Voit's) Law of Fanboy Appearance

The Internet is full of frequently mentioned laws. I wrote about that in this article. For personal reference, I would like to coin some common patterns for me as well. This is one of them. You might want to refer to it when appropriate.

(Voit's) Law of Fanboy appearance: As an online discussion about any topic grows longer, the probability of an appearance of an fanboy who could not reached by arguments any more approaches 1.

For reference, please do use the hashtag: #LawOfFanboyAppearance

Read the whole article ...

2024-09-27: (Voit's) Law of Tool Usefulness

The Internet is full of frequently mentioned laws. I wrote about that in this article. For personal reference, I would like to coin some common patterns for me as well. This is one of them. You might want to refer to it when appropriate.

Law of tool usefulness: Any tool can be a perfect fit for a given set of requirements.

For reference, please do use the hashtag: #LawOfToolUsefulness

Read the whole article ...

2024-09-27: (Voit's) Law of Workflow Usefulness

The Internet is full of frequently mentioned laws. I wrote about that in this article. For personal reference, I would like to coin some common patterns for me as well. This is one of them. You might want to refer to it when appropriate.

(Voit's) Law of Workflow Usefulness: anybody is able to come up with a management concept she/he finds useful while everybody else doesn't find it helpful.

For reference, please do use the hashtag: #LawOfWorkflowUsefulness

Read the whole article ...

2024-09-27: Eponymous Laws, Internet Laws, Meme-Laws, Principles, Patterns, ...

The Internet culture came up with frequently mentioned laws that describe common patterns.

Here are some examples you might already know:

Those laws are named after some persons that are connected to said laws. You can read about them on the very long page on Wikipedia about eponymous laws. Many are not named after persons and I won't limit myself to that here either.

A friend of mine posted an article with some rules on his blog. That got me interested and I discovered some really cool laws myself for the first time.

So you can find even more collections of laws on pages like:

In my personal bubble, I did find some common patterns, rules, laws myself. For personal reference, I would like to coin a few laws myself:

You might want to check them out yourself and refer to them when appropriate.

2024-08-17: UOMF: Managing web bookmarks with Org Mode

Please do read my "Using Org Mode Features" (UOMF) series page for explanations on articles of this series.

I now manage my web bookmarks with Org-mode and some glue I wrote by myself.

Read the whole article ...

2024-07-25: Don't Contribute Anything Relevant in Web Forums Like Reddit

If you're, for example, contributing to a reddit thread about something which is irrelevant or anything with only a short-term relevance, this article does not apply to you right now.

However, as soon as you're helping somebody solving an interesting issue, summarize your experiences with something or write anything that might be cool to be around in a couple of years as well, you do provide potential high-value content. My message to all those authors is: don't use web-based forums.

In 2022, I talked about this topic at the Grazer Linuxtage and there is a video on the pages of the CCC as well as on YT:

The initial slide of the slide deck for the talk.
My talk about this topic (45min).

In late 2023, I got the opportunity to give a talk at the 37C3 by the CCC in Hamburg. This talk was not recorded but overlaps in most parts with the recorded talk above.

TL;DR: all of the content of closed, centralized services will be lost in the long run. Choose the platform you contribute to wisely now instead of learning through more large data loss events later-on.

The longer version is worth your time:

Read the whole article ...

2024-07-13: AliExpress Is Annoying as Hell

I had to order some spare part which I could only find on AliExpress. Then I found a sub-1€ item which seemed a good idea to order as well.

AliExpress does seem to have some potential in shopping experience optimization.

Read the whole article ...

2024-07-13: Fediverse and Mastodon: Social Media, but in a Good Way: Sustainable, Healthy, Collaborative, ...

The Fediverse is an umbrella term for a federated set of social networking services that are able to exchange messages among each other.

You already know another federated Internet service: email. With your business email account, you can exchange mails with people using other email providers such as GMail, yahoo, hotmail, and so forth. It does not matter if your email partner is hosted on the very same email server as you. This is because both email services are able to talk to each other via an open standard.

Same as with email, you can decide to run your own server for a Fediverse service. Those servers are also called "instances". For instance, the instance graz.social (disclaimer: I'm affiliated) is running a few Fediverse services for our local community.

The most prominent Fediverse service is called Mastodon which is similar to X/Twitter. There are other Fediverse services you can imagine as free alternatives to some commercial networks:

Fediverse Service Similar to …
PeerTube YouTube, Vimeo, …
Pixelfed Instagramm, …
Lemmy reddit, …

... and many more!

I think that you definitely should start using free Social Network services from the Fediverse. Maybe as an additional network for starters. But then you really should think of stopping to use the commercial ones for multiple reasons.

And this is the story why this would be a very wise decision by you in the long run:

It's a long article. But you are free to skip sections that are not of interest to you right now. This article is not - and will never be - a complete guide for beginners. The main goal of this article is to express my arguments why it is a good idea to use Mastodon as your main social network and probably stop using all the others as they are unhealthy and manipulative.

Read the whole article ...

2024-07-13: Social Networks Are Lying to Manipulate You

Well, that's no news: social networks are not good for your health for many reasons. This one is an example that makes it very easy to understand for most people.

elieli0000 on the TikTok platform has published a video. You can watch it here:

In short, she is struck by the fact that her boyfriend sees totally different comments below a video than herself.

I have to say that this is somewhat naïve considering the fact that she is a content producer who obviously has no idea how the thing works that she is feeding with content.

This is a clear example how algorithms are one of the reasons why people aggregate to much hatred in the Internet. They are just fed by one single point of view and all other point of views are hidden from them. This way, your brain only gets fed more and more one-sided comments, postings, opinions, and so forth.

That also happens when political parties are using social networks to promote their programs. This way, they send customized messages to each social media consumer. Those customized messages reinforce the already existing opinions in a way that we only read what we want to read, totally independent of the main direction of the political program. I guess that's one of the reasons why right-wing parties get more and more voters among disadvantaged groups: they just give them some clever slogans and make people vote against their own interest.

However, there is an alternative which is not using manipulative algorithms to filter content for you: Fediverse and Mastodon: Social Media, but in a Good Way: Sustainable, Healthy, Collaborative, ...

You should think of using social networks that are good for you.

2024-07-08: Leserbrief an die Kleine Zeitung: sogenannte "Open Source" und Abhängigkeiten

Guten Tag,

Im Artikel vom 4. Juli 2024 schreiben sie unter anderen:

Bis zum 30. April eine Lösung auf sogenannter „Open Source“-Technologie zu entwickeln, die jede Abhängigkeit ausschließt.

Dieser eine Satz ist auf mehreren Ebenen für mich etwas befremdlich.

Warum setzen Sie "Open Source" in Anführungszeichen? Das ist, als ob sie den Begriff nicht kennen würden und bezweifeln, dass das legitim oder korrekt ist. Dies wird noch unterstrichen durch das vorangestellte "sogenannter". Sie würden sich auch wundern, wenn ich ihr Produkt als kleine "Zeitung" bezeichnen würde, oder?

FOSS (wird von vielen Menschen als Begriff gegenüber OS bevorzugt) schließt keine Abhängigkeiten aus. Wenn man Fremdsoftware einsetzt, hat man immer Abhängigkeiten. Es ist nur typischerweise keine von einem Konzern - in den meisten Fällen jedenfalls. Es gibt auch Konzerne, die FOSS erstellen.

FOSS ist kein sprachliches oder anderswertiges Alien. Das Internet besteht mehrheitlich aus FOSS-Komponenten. Ihr Unternehmen würde ohne FOSS nicht funktionieren.

Es wirkt fast so, als ob in Wirtschaftsresorts FOSS "Neuland" wäre.

2024-07-01: Searching and Downloading YouTube Videos Via Shellscripts

There are many reasons why someone would not want to use https://YouTube.com in a web browser to search for and watch videos.

My most important reasons are:

Therefore, I created a way to search for YouTube videos, download YouTube videos and watch them locally from my zsh command line interface.

If you don't want to use other solutions like Individous or FreeTube, you might want to check out my workflow.

You don't have to use a shell if you want to use my method. You can also wrap the shell scripts into easy to start temporary Terminal windows to interact with them. I didn't bother so far. I'm very fine with using the shell.

So here is my method which you can use and adapt to your personal taste in case you're familiar with basic shell scripting and how to invoke them.

Read the whole article ...