this post was submitted on 25 May 2024
10 points (100.0% liked)

Selfhosted

38707 readers
677 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 1 year ago
MODERATORS
 

Hi guys I was wondering if there is a streamlined way to disable remote acess to a selfhosted service (say at a reverse proxy level) if a published security vunerability is present.

I know, ideally you want to keep all your selfhosted services up to date. However on certain selfhosted service auto updates may not be viable (due to major changes between updates) and you being unavailable 24/7 to respond to vunerabilities.

Curious on your thoughts and suggestions. So far the only middle ground I can find is realying on a vpn wireguard, tailscale, etc.

Page regarding homeassistant remote ui autodisable: https://www.nabucasa.com/config/remote/

top 7 comments
sorted by: hot top controversial new old
[–] [email protected] 3 points 3 months ago

If you figure it out, I know several companies that would be more than willing to drop 7 figures a year to license the tech from you

[–] [email protected] 2 points 3 months ago (1 children)

If you know of a data source for these vulnerabilities, I'm all ears. Because currently, that aggregation work is done by companies selling the feeds for quite a lot of money.

Personally, I'd just put everything behind a VPN. The attack surface is much smaller.

[–] [email protected] 1 points 3 months ago* (last edited 3 months ago) (1 children)

I tried this for 2 months with tailscale and love it, however having it run 24/7 on both my wife's and my phone was too much. It literally wiped out the battery on my wife's iPhone 12 unless she charged it in the middle of the day. I lost about 40% more battery throughout the day on my android. I had to switch back to cloudflare and nginx proxy manager for now.

[–] [email protected] 1 points 3 months ago

Hmm. It shouldn't do that. If you try it again, I'd check the configuration, and if you verify it with the Android battery metrics, open an issue.

I assume it also supports split tunneling, which might help.

[–] [email protected] 1 points 3 months ago* (last edited 3 months ago) (1 children)

I can't help here, but:

The title would be less confusing if you didn't cram everything in one sentence. Potential help might be driven off by this, i was almost too.

[–] [email protected] 1 points 3 months ago

Sorry about that (didn't think that far when making the post 🫠 ).

I updated the title

[–] [email protected] 1 points 3 months ago* (last edited 3 months ago)

Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I've seen in this thread:

Fewer Letters More Letters
HTTP Hypertext Transfer Protocol, the Web
VPN Virtual Private Network
nginx Popular HTTP server

[Thread #762 for this sub, first seen 27th May 2024, 00:15] [FAQ] [Full list] [Contact] [Source code]