Thursday, April 8, 2021

你戴错眼镜啦 读书笔记

 

1.
近视(Myopia/NearSightedness)

近视度数浅,看近有问题,近视度数深(超过350度),看近看远都有问题。

远视(Hyperopia/Farsightedness)眼球太短,看远没问题,看近费力。

老花眼(Presbyopia)是指人超过40岁以后,对近处物体的聚焦能力衰退。

散光(Astigmatism)因角膜不对称,看近看远都模糊。

2.

近视一般佩戴凹透镜矫正,凹透镜中心比边缘薄。

远视和老花眼用凸透镜。在国外,凸透镜称为阅读镜(Reading Glass)。

3.

角膜(Cornea)俗称黑眼珠,本身是透明组织,没有血管,是光线进入眼球的窗户。

虹膜(Iris)收缩可改变瞳孔大小,也决定眼镜本身的颜色。

4.

视学上以屈光度(Diopter,简写D)来反映眼睛付出的调节力,D越大代表付出的调节力越多。凡正常的眼睛看6米以内的物体都需要使用调节力。小孩可达12D的调节力,而老年时,调节力跌至1D,故年纪越大,看近越不清楚。

5.

近视度数又称为屈光度(Diopter),其实指透镜对光线的屈折能力,屈光度的计算公式:

D=F/100

F为镜片的焦距,以厘米为单位。

正常无限远看着清晰

100度近视100cm以内看着清晰

200度近视50cm以内看着清晰

500度近视20cm以内看着清晰

6.

痉挛性近视(Spastic myopia)又称假性近视(Pseudo myopia),或调节性近视(Accomodative myopia)。这类近视因为眼睛调节功能过度紧张而形成。

近视眼看近变的轻松,却失去看远清晰的能力。

7.

近视者看远时,可戴一副足够度数的近视镜片,看近时,则应戴一副较浅的近视镜片,以减轻眼睛的调节压力,防止度数不断加深。

8.

The Myopia myth by Donald 

The Myopia Myth: The Truth About Nearsightedness and How to Prevent It

How to avoid nearsightness (The amazon comment is pretty bad)

9. 戴远视镜,有放大效果,可减轻佩戴者看近的疲劳。要注意只有在长时间看近时才需要戴,平时不用戴。





Wednesday, April 7, 2021

孩子视力

在线视力检查:https://www.zeiss.ca/vision-care/en/better-vision/vision-screening.html  

医家秘传:http://blog.sina.com.cn/s/blog_643c2b690102vx5r.html 有用吗?

https://www.rolia.net/f/topic.php?v=p&f=0&p=11768842#p11768842

阿宝今天视力检查0.5,医生建议戴100度近视眼镜。一年半之前还是1.5的,这个covid19真恶心啊。希望还能恢复。

1. 是假性近视吗?

2. 眼药水会有帮助吗?


蓝莓、叶黄素有保护视网膜的作用,常看手机电脑的也可以适当补充。

户外活动。

【养眼操】

  第一节,双眼向左上左下看,6×8拍。

  第二节,双眼向右上右下看,6×8拍。

  第三节,双眼向左向右看,6×8拍。

  第四节,双眼顺时针转着看,四拍转一圈,把操作者的脸当成时钟的表面,眼球按左、下、右、上的方向依次转动,5×8拍。

  第五节,双眼逆时针转着看,四拍转一圈,转动方向与第四节相反,眼球按右、下、左、上的方向依次转动,5×8拍。

区分假性近视和真性近视需要做散瞳检测。向孩子的眼内滴入散瞳眼药水,如果孩子的眼睛没有度数,那就说明孩子是假性近视;相反,孩子的眼睛依然可以检测出度数,那就说明孩子是真性近视。

https://www.rolia.net/f/topic.php?f=0&t=864920
如果回国,可以试试青少年渐进多焦片眼镜,上海茂昌的。我家儿子4年级200度,用到现在高二还是200度。
这个青少年渐进片是茂昌和吴良材专利

https://www.rolia.net/f/post.php?f=0&p=8347107
Reading glasses也就是老花镜,只在看近的物体和阅读时使用.因为是凸透镜,所以物体的成像会落在视网膜前面,和近视眼看远处物体的效果一样. 为了看清落在视网膜前的成像,眼肌就会放松,使眼球尽量变圆.即使已经近视了,眼球不能变圆了,因为眼肌处于放松状态,因此也不会对眼球有拉长的作用,从而减缓和防止近视的加深. 但不会使视力恢复到正常水平.

我的小孩发现近视时125度,我没有注意,以为少看书能控制住.但半年后发现加深了50度,速度相当惊人. 这才紧张起来,看了一些资料.没有佩近视镜,只佩了一副reading glasses. 小孩平时不戴眼镜也能看见老师黑板上的字,只是有些模糊. 放学回家看书看电脑戴reading galsses. 1年半时查视力没有改变,2年时查加深了25度,减缓了近视加深的速度.当然,这只是我们自己的体会,是不是对所有孩子适用,就不得而知了.


我女儿快6岁时,说有点近视,说必须带眼镜(没告诉度数),我坚持一年不给看电视,不给用电脑,每天读书+写作业时间不超过1小时,本来一年级也没什么作业,每周3次滑冰,1次跳舞,2次游泳。。。。上个月去查,说基本恢复了....参考

https://www.rolia.net/zh/post.php?f=0&p=11768842
低浓度阿托品眼药水本地没有成药,只能去药房配,北边的可以去IDA(9425 Lesile street, unit 150, 905-237-6937), 他们可以送,大约一个月50。

在一些护眼方法中,眼保健操可以改善眼睛局部血液循环,缓解一部分眼睛疲劳,闭眼的时候眼睛可以得到一定休息。把电脑屏幕底色调成绿色护眼方式,可以缓解视疲劳。


DHA是视网膜中含量最丰富的长链多不饱和脂肪酸,在眼睛视网膜中约占50%,对视力发育起到至关重要的作用。增加DHA的摄入量,会促进视网膜光感细胞的成熟,提高视敏感程度,对改善视力减退等问题都很有帮助。

如果放假之前孩子视力很好,看了一个假期的电子产品之后,视力忽然下降,到医院一查发现300°近视,这种短时间内的视力快速下降,很大可能是假性近视。


孩子到医院进行检查后,如果是假性近视,及时治疗后,视力还可以恢复到原来的状态。

是的,近视超过300度,那视力就真的不可逆了。原因就在于,300度是真性近视和假性近视的一个最高分界线。



1、每天2小时户外活动,凝视远方

保护视力,室内任何光都比不上自然光。建议每天2小时户外活动。

找一处10米以外的草地或绿树:绿色由于波长较短,成像在视网膜之前,促使眼部调节放松、眼睫状肌松弛,减轻眼疲劳。试着全神贯注凝视25秒,辨认草叶或树叶的轮廓;接着把左手掌略高于眼睛前方30厘米处,逐一从头到尾看清掌纹,大约5秒。看完掌纹后再凝视远方的草地或树叶25秒,然后再看掌纹。10分钟时间反复20次,一天做三回,视力下降厉害的要增加训练次数。

2、转眼法

选一安静场所,或坐或站,全身放松,清除杂念,二目睁开,头颈不动,独转眼球。

先将眼睛凝视正下方,缓慢转至左方,再转至凝视正上方,至右方,最后回到凝视正下方,这样,先顺时针转9圈,再逆时针方向转6圈,总共做4次。每次转动,眼球都应尽可能地达到极限。这种转眼法可以锻炼眼肌,改善营养,使眼灵活自如,炯炯有神。



作者:PiPi健康
链接:https://www.jianshu.com/p/58e16e0016ec
来源:简书
著作权归作者所有。商业转载请联系作者获得授权,非商业转载请注明出处。

Monday, April 5, 2021

CSR and SSL for Apache

 CSR and SSL for Apache

1. Create the CSR based on the https://www.digicert.com/kb/csr-ssl-installation/apache-openssl.htm 

you'll get the private key file and the csr file like 

openssl req -new -newkey rsa:2048 -nodes -out www_auspix_com.csr -keyout www_auspix_com.key -subj "/C=CA/ST=Ontario/L=Toronto/O=Peter/OU=Test/CN=www.auspix.com"

www_auspix_com.key

www_auspix_com.csr

2. Order Your SSL/TLS Certificate

You'll get the intermediate (DigiCertCA.crt) and your primary certificate (your_domain_name.crt) file.

3. Configure Apache

<VirtualHost 192.168.0.1:443> DocumentRoot /var/www/html2 ServerName www.yourdomain.com SSLEngine on SSLCertificateFile /path/to/your_domain_name.crt SSLCertificateKeyFile /path/to/your_private.key SSLCertificateChainFile /path/to/DigiCertCA.crt </VirtualHost>

4. Restart and Verify from the browser




https://www.venafi.com/blog/what-difference-between-root-certificates-and-intermediate-certificates

 

  • Root Certificate. A root certificate is a digital certificate that belongs to the issuing Certificate Authority. It comes pre-downloaded in most browsers and is stored in what is called a “trust store.” The root certificates are closely guarded by CAs.
     
  • Intermediate Certificate. Intermediate certificates branch off root certificates like branches of trees. They act as middle-men between the protected root certificates and the server certificates issued out to the public. There will always be at least one intermediate certificate in a chain, but there can be more than one.
     
  • Server Certificate. The server certificate is the one issued to the specific domain the user is needing coverage for.

Wednesday, March 31, 2021

 Sams Teach yourself Apache 2 in 24 hours note

1. By default Mac BigSur has the apache

run the command to verify: httpd -v 

The installation path: /private/etc/apache2

The log location: /var/log/apache2

Document root: /Library/WebServer/Documents

2. httpd.conf

The ServerRoot directive takes a single argument: a directory path pointing to the directory where the server lives.

None disables per-directory files in that directory and any of its subdirectories. This improves performance and is the default Apache configuration.

1: <Directory />
2: AllowOverride none
3: </Directory>

3. control:

apachectl start/stop/restart/graceful

from the browser, http://localhost:80 will show "It works"

ErrorDocument 404 "Oops, we couldn't find your document!"

or

ErrorDocument 404 http://search.example.com
Alias /icons/ /usr/local/apache2/icons/

will cause a request for http://www.example.com/icons/image.gif to make Apache look for the /usr/local/apache2/icons/image.gif file.

4. reverse proxy

A reverse proxy is a Web server that sits in front of other Web servers, known as backend servers. The reverse proxy Web server can be configured to pass certain requests to the backend servers and return the result to the clients as if it were the reverse proxy that generated the content

You can use the ProxyPass and ProxyPassReverse directives to map URLs in the reverse proxy to URLs in the backend servers.

In certain situations, the backend server might issue redirects. These redirects will include a Location: header that contains a reference to the backend server (backend.example.com). The ProxyPassReverse directive will intercept these headers and rewrite them so that they include a reference to the reverse proxy (rproxy.example.com) instead.

The previous examples could be rewritten as follows:

ProxyPass /dynamic/ http://backend.example.com/
ProxyPassReverse /dynamic/ http://backend.example.com/
Note that the ProxyPassReverse directive operates only at the HTTP header level. It will not inspect or rewrite links inside HTML documents.

It is possible to prevent certain URLs from not being proxied by specifying an exclamation sign (!) as the remote site URL in ProxyPass directives. It is important that those directives are placed before other ProxyPass directives. For example, the following configuration will pass all requests to a backend site, except requests for images, which will be served locally:

ProxyPass /images/ !
ProxyPass / http://backend.example.com

5. SSL

If both sender and receiver share the same key, the process is referred to as symmetric cryptography. If sender and receiver have different, complementary keys, the process is called asymmetric or public key cryptography.

Public key cryptography takes a different approach. Instead of both parties sharing the same key, there is a pair of keys: one public and the other private. The public key can be widely distributed, whereas the owner keeps the private key secret. These two keys are complementary; a message encrypted with one of the keys can be decrypted only by the other key.

Anyone wanting to transmit a secure message to you can encrypt the message using your public key, assured that only the owner of the private key—you—can decrypt it. Even if the attacker has access to the public key, he cannot decrypt the communication. In fact, you want the public key to be as widely available as possible. Public key cryptography can also be used to provide message integrity and authentication. RSA is the most popular public key algorithm.

The SSL protocol uses public key cryptography in an initial handshake phase to securely exchange symmetric keys that can then be used to encrypt the communication.

SSL uses certificates to authenticate parties in a communication. Public key cryptography can be used to digitally sign messages. In fact, just by encrypting a message with your secret key, the receiver can guarantee it came from you. Other digital signature algorithms involve first calculating a digest of the message and then signing the digest.

Trust can be achieved by using digital certificates. Digital certificates are electronic documents that contain a public key and information about its owner (name, address, and so on). To be useful, the certificate must be signed by a trusted third party (certification authority, or CA) who certifies that the information is correct. 

Certificates have a period of validity and can expire or be revoked. Certificates can be chained so that the certification process can be delegated. For example, a trusted entity can certify companies, which in turn can take care of certifying its own employees.

If this whole process is to be effective and trusted, the certificate authority must require appropriate proof of identity from individuals and organizations before it issues a certificate.

The main standard defining certificates is X.509, adapted for Internet usage. An X.509 certificate contains the following information:

  • Issuer: The name of the signer of the certificate

  • Subject: The person holding the key being certified

  • Subject public key: The public key of the subject

  • Control information: Data such as the dates in which the certificate is valid

  • Signature: The signature that covers the previous data

6.

To get a certificate issued by a CA, you must submit what is called a certificate signing request. To create a request, issue the following command:

# ./usr/local/ssl/install/bin/openssl req -new -key www.example.com.key
 -out www.example.com.csr

You can also create a self-signed certificate. That is, you can be both the issuer and the subject of the certificate. Although this is not very useful for a commercial Web site, it will enable you to test your installation of mod_ssl or to have a secure Web server while you wait for the official certificate from the CA.

You need to indicate where to find the server's certificate and the file containing the associated key. You do so by using SSLCertificateFile and SSLCertificateKeyfile directives.

You can control which ciphers and protocols are used via the SSLCipherSuite and SSLProtocol commands

 The SSLMutex directive enables you to control the internal locking mechanism of the SSL engine. 


asdf

a

sdfa


asdf

nexus 5 root

 Nexus 5 root:

https://www.androidinfotech.com/root-google-nexus-5/

Just follow the tutorial, it's pretty good guide.

Sunday, March 28, 2021

小米3W手机刷ROM

小米系统刷ROM或者root,不需要借助任何第三方电脑或手机软件。

root的话,需要下载开发版的ROM。

现在打开以前5年前的小米3W手机,发现系统还挺流畅的,尽管Android版本比较低,是4.4.4.

发现小米手机自己刷ROM很方便,因为我的音量键坏了,无法卡刷,只能线刷。

下载ROM: https://mirom.ezbox.idv.tw/phone/cancro/

我使用的是国际稳定版:https://bigota.d.miui.com/V9.5.7.0.MXDMIFA/miui_MI3WMI4WGlobal_V9.5.7.0.MXDMIFA_df826857ee_6.0.zip 

拷贝到手机的downloaded_rom目录,从手机里的更新里面选手动更新,就可以了:https://jingyan.baidu.com/article/fec4bce297fd35f2608d8b7e.html

后期版本(MIUI9之后)该选项隐藏的比较深,可参考这个手工选择安装包:https://jingyan.baidu.com/article/295430f11bca3f4c7f00505c.html

但是小米官网做的太差,不能从官方下载ROM包,我的chrome浏览器进入,看到的是下面这个:

应该到这个地方:https://xiaomirom.com/rom/mi-4-mi-4-lte-ct-cancro-global-fastboot-recovery-rom/

如果出现无法启动,可以使用线刷:https://miuiver.com/how-to-flash-xiaomi-phone/



Wednesday, March 17, 2021

RxJS note

 1.

let​ myObs$ = clicksOnButton(myButton);

 $is a convention in the Rx world that indicates that the variable in question is an observable.

Much like a promise, we need to unwrap our observable to access the values it contains. The observable unwrapping method is called subscribe.

The function passed into subscribe is called every time the observable emits a value. 

  myObs$.subscribe(clickEvent => console.log(​'The button was clicked!'​));

2.

tsc stopwatch.ts

Got the below error:

node_modules/rxjs/internal/Observable.d.ts:89:59 - error TS2585: 'Promise' only refers to a type, but is being used as a value here. Do you need to change your target library? Try changing the `lib` compiler option to es2015 or later.

Need run the below to fix (editing the tsconfig.json doesn't work)

npm i @types/node

3.

delay: delay all events coming through the observable chain

​import​ { interval, of } ​from​ ​'rxjs'​;

import { delay, map, take } from 'rxjs/operators';

of​(​'hello'​, ​'world'​, ​'!'​).pipe(

    delay(5000),

    map(word=>word.split('')

    )

).subscribe(console.log);


​​let​ tenthSecond$ = interval(1000);

​tenthSecond$.pipe(

    map(num=>num/10),

    take(3)

).subscribe(console.log);


4. switchMap

The switchMap operator will create a derived observable (called inner observable) from a source observable and emit those values.

When the source emits a new value, it will create a new inner observable and switch to those values instead. What gets unsubscribed from are the inner observables that get created on the fly, and not the source observable.

5.

// RxJS v6+
import { Subject, BehaviorSubject } from 'rxjs';

const subject = new Subject();
const behaviorSubject = new BehaviorSubject('a');

const subjects = [subject, behaviorSubject];
const log = (subjectType: string) => (e: any) => console.log(`${subjectType}${e}`);

//log equals the below log2
const log2 = (subjectType: string)=>{
  return (e: any)=>{
    console.log(`${subjectType}${e}`);
  }
}

console.clear()
console.log('SUBSCRIBE 1');
subject.subscribe(log2('s1 subject'));
behaviorSubject.subscribe(log2('s1 behaviorSubject'));