

And you must not have read the relevant US laws.


And you must not have read the relevant US laws.


Both Italy and Austria are EU member states , fall under the GDPR AND NIS2 and while both government(even under the FPÖ) have their downsides neither has legislation that is even remotely close to what the US even have today (and had for decades) and unlike the US both countries still have a very well working judical system and the ECJ.
So. Yes. While not perfect, their situation is massively better than a US non for profit. Total different league. Not even in the same ballpark.
Seperate servers (with different locations - one in LAN,one with Hetzner, one with OVH) that provide intranet (only available in the HomeLAN or via Wireguard), extranet(“public” services as in “to friends and family”) and Backup/Monitoring services.
Everything behind OPNsenses, with strict firewall rules, crowdsec and acting as a reverse proxy. Additionally certain things are locked down via hosting provider based firewalls (as I have the luxury to have a static IP at home I can easily do limit ingress for some extranet services)
VLAN seperation both within HomeLAN and Proxmox. Proxmox firewall rules to limit intra VLAN access. Unpriviliged LXC containers - seperated per service. Anything needing docker runs in rootless podman within an unpriv. LXC. (If it does not run like that it won’t run. End of discussion) Authentik for OIDC. If it does not do OIDC/SAML is does not run. (Only exception is LDAP in HomeNet as I am running free IPA anyway) Also acts as Jumpserver via VNC/RDP.
As I am using ansible/Terraform (via Semaphore) for everything I also strictly enforce fail2ban and certain monitoring components. (Namely Zabbix and Wazuh)


What a badly written AI slop
OVH Storage Server with Proxmox Backup server (you can also use if for non-Proxmox clients,btw) and a additional S3 bucket at another hoster.
Sadly the realities are different: I visit around one healthcare facility every other week in all of Europe, far more infrequently in Africa, Asia and Oceania.
Hospitals consistently have the worst IT departments I ever see - outdated technology, budget constraints (I literally saw a full IT loss due to “we don’t pay for our firewall licences for over 3 years”) and a fucking lack of care. One of the most well known clinical information systems has a hardcoded admin account with a single letter as PW in it Another popular system will try to install an ancient version of TeamViewer. In other words: It’s a mess - btw often the budgets are huge and more than what nurses cost.
That’s why this unicorn stuck with me. They were “relaxed” - because they all had a workload that was “manageable”, there was someone to take over if shit hits the fan,etc. And they didn’t feel like they would need to do this and this - I know and fear this myself, it’s the bane of my existence as a project guy. They? They had a nice, lean but powerful project workflow and change management.
In the end it all came down to very very good management - a manager who knows their team that well is worth their weight iin gold.
Tbf, I might have seen a unicorn: A hospital with no tech debt neither me nor my technically more inclined colleagues could find. And we were literally paid for looking for things swept under the rug.
They had a top notch IT department with very professional management who (despite their limited budget) managed to attract talented people - simply with good working conditions, a room for creativity, etc. Everything they had was so well documented that it made me cry and think of my company’s documentation. And while they intentionally did not go with every trend and fad their stuff was rock solid and modern. I have seen much much larger companies with half their thought into infrastructure, etc.
I don’t know if they still maintain that standard,but it was a real unicorn.
I am not 100% sure it is available in English, but have a look at KiSi (Salfeld).
Imho the best parental control app - while it is not free it is run by a small German company (I had very delightful contact with the founder), falls under the GDPR, offers very flexible scenarios, a windows client that offers roaming, various options to lock down the internet (whitelist/blacklist both manually or curated), reporting (what webpages are consumed, which are blocked, what apps are used how long). Times can be set per group and both by the time of the day and by usages times (e.g. this group can always be used, this can only be used during the day and this group can only be used weekday afternoons and weekend all day but only for 2h per week across the PC and the smartphone). It also allows requesting access/more usage times via a “parents Version” of the app.
It’s not self hosted, it currently does not support Linux, but after testing basically everything on the market I accepted that one. Funny enough now eldest has asked for the already massively reduced access(no social media, only limited Youtube, mainly wikipedia and similar sites whitelisted) to be blocked during certain hours of the day (and their PC access blocked as well - which is a different beast as we use FreeIPA and Fedora) so they have 90min of focus time for homework.