I have to admit before I was like: "not your metal, not your server".

I chose sovereignty over security, without any nuance.

From now on, everything public goes to the VPS (with regular backups in case it gets taken down), everything private stays at home.

The only port I want open in my house is a single UDP port for wireguard. Good luck trying to break through that!

Reply to this note

Please Login to reply.

Discussion

Life hack:

Hybrid node on VPS private channel to Tor home node.

Privacy and comfort.

If by node you mean bitcoin, then absolutely no. Not your metal no your node.

Agree 100% with this stance.

nostr:note1n24kce5twttrnu9wyealxkkn2l74hgjeut7kmpe8sq5slm5jk60sx63n3z

yeah thats basicly how I think about it now a days. public shit is public with lots of backups and private is behind wireguard (also with lots of backups lol)

Thoughts on things like Cloudflare Tunnels to proxy public facing services in lieu of opening ports on your network?

I self-hosted behind a Cloudflare proxy as well. The fact is, it's impossible to fully secure a public webserver. Any motivated and resourceful attacker can find their way in.

The web (just http, not the Internet) is inherently insecure.

Yeah, very true. This is why we can’t have nice things πŸ˜