• 0 Posts
  • 6 Comments
Joined 3 years ago
cake
Cake day: August 19th, 2023

help-circle
  • Mio@feddit.nutoSelfhosted@lemmy.worldAnybody here does mTLS?
    link
    fedilink
    English
    arrow-up
    1
    ·
    59 minutes ago

    I have been thinking about it until I realize that nginx still can have zero days vulnerabilities that could be even in the tls layer or so and decided to actually close the port completely in the Firewall and just run Wireguard on devices. And as fallback I have external program that have a webbserver with qr code with link and ip query encrypted so when i scan it on smartphone i have to follow the link to internal server that i only can access with Wireguard so then only that public ip is then added to my Firewall rules temporary.




  • I have never understood why there is no protocol that allows for multi-master node setup(if a message is written to one, then queue to write to the second one and ignore timestamp missmatchning and conflict resolution(It does not have to be perfect) - matrix put too much effort into this IMO).

    For family i use Signal. My coworkers use IRC and I have it setup in link-mode for multi master support(but IRC does not have new features like send image, thread, reactions, emoji, text-styling, audio/video calls). Using unrealircd. Neat when the local city network is up but the fiber connection from the city network to the internet is down so I can still write to some friends, or dont care about uptime on my server since they fallback to the second, free, Oracle VM.


  • Mio@feddit.nutoSelfhosted@lemmy.worldThoughts on crowdsec
    link
    fedilink
    English
    arrow-up
    1
    arrow-down
    1
    ·
    1 month ago

    Yes, that is the hard part. But it can be done. Geoip blocking like only allow your country - blocking every China or Russian user etc. If you are selfhosting at home and worry about your SSH access, then you can do a lot of things to block then early. It is all about authentication. Lets say you require VPN access in - example Wireguard. You could require access only through somebody else, like Cloud flare tunnel. You could also do “port knocking” but that is not encrypted. You could require the user first has to be authenticated somewhere else, like require first Microsoft login and only then your ip is allowed.