• 2 Posts
  • 16 Comments
Joined 1 year ago
cake
Cake day: July 9th, 2023

help-circle



  • Yikes! I’d avoid leaving any services externally exposed unless they’re absolutely necessary…

    Tailscale+Headscale are pretty easy to implement these days. Since it’s effectively zero trust, the tunnels become the encrypted channel so there’s an argument that HTTPS isn’t really required unless some endpoints won’t be accessing services over the Tailnet. SmallStep and Caddy can be used to automatically manage certs if it’s needed though.

    You can even configure a PiHole (or derivative) to be your DNS server on the VPN, giving you ad blocking on the go.













  • Probably a poor decision to be creating accounts on government operated instances. Since they own the server, they’re in a position to:

    1. Siphon credentials and attempt reuse to gain access to distinct services
    2. Ban individual accounts
    3. Censor based on post content

    I’m all for government support and adoption of open-source software so long as they’re not in the position to disrupt how it’s used by the public at large.

    Edit (my perspective is relevant, but doesn’t apply in this case): My nerd impulses outran my willingness to read the link’s content. Seems it’s not for public registration.

    Edit 2: Like my cornbread eating American ass can read Dutch anyway 🤣