🇨🇦

  • 11 Posts
  • 224 Comments
Joined 3 年前
cake
Cake day: 2023年7月1日

help-circle


  • For a while, the windows machine I was using kept randomly becoming unresponsive (both via network, as well as the keyboard+mouse) and I just could not figure out why. Everytime it did, I’d have to force a shutdown by holding the power button until it shutoff, then press it again to start back up. Sometimes this happened while I wasn’t home, so it had to just stay offline until I was.

    I got sick of having to do this; so I replaced the power button with a transistor and a RPI. The PI would ping the server every 5min; if it failed to get a response 3 times in a row, it would trigger the transistor for 10sec, release for 3sec, then press and release again; forcing a poweroff then starting the machine again. It’d also write these events to a log file. I think it was around twice a week ish.

    Never did figure out what the cause of the lockup was; but it stopped when I replaced windows with Debian.





  • ‘I’m not the problem, everyone else is’. 🤦

    I tried to carve out a space where those people and other rougher edges were not drowning out niche communities and hobbies and where people who choose to use the platform to harass others were also out of sight, out of mind.

    All he had to do was make his own instance, where he can defederate from/block whoever he likes. Let users decide if they want to be a part of it.

    Good intentions don’t justify bad actions, and abusing the trust instilled in you as a developer of a popular tool is rarely taken lightly.

    Imposing your own personal opinionated blacklists on other peoples platforms without their knowledge and consent was never going to go well, no matter what your intentions are. ESPECIALLY in the fediverse; a system built to prevent exactly that behaviour.


    The DDOS code however…

    Frankly that should be considered criminal. This dev should be facing jail time for that alone.






  • Fair points.

    I’ve been lucky enough to have never been behind cgnat, so I keep forgetting about it.


    My bigger concern with tailscale is being required to install software on the client. Not every device I use, I have permission to install a vpn client, nor would I want to.

    For example, I have a fileshare using Filebrowser where I store work related files that I don’t want to loose access to or need access to from multiple machines (non proprietary info, stuff IT/MGT wouldnt get mad at me for ofc. I’ve actually cleared it with my managers, so no worries). That’s also a handy way to (temporarily) share large files with people or provide a way for friends to upload large files to me.

    I also like to access my emby server (using sufficiently limited accounts), from things like the TV in the work break room, or a friends PC while I’m visiting.

    Tailscale is a hurdle that I just don’t need/want.



  • You don’t need a static IP, you just have to keep track of what your current dynamic IP is.

    You can do this with either a free or a paid DNS service.

    There are a few different ‘free dns’ services that will delegate a subdomain of theirs to you at no cost. Admittedly, I’ve never actually used one of these so their names escape me. Hopefully someone else can point one of those out if that’s what you really want.


    I purchased a domain via google domains, when they existed. It’s now transferred to squarespace, because they bought out google domains a few years ago.

    It was around $13/year when I first got it a decade ago. It’s now around $28/year.

    This allows me full control over the domain: I can use as many subdomains as I want to give each service I use it’s own unique name. (Instead of using their own separate ports that you’ve gotta remember) My domain will also forward all inbound email to my gmail account; this lets me use email addresses like <servicename>@mydomain.example. This way, I don’t share my real email and can immediately tell who sold my info to the highest bidder when I get spam. (I could also host my own email service if I really wanted, but I haven’t bothered)

    Add Cloudflare ontop (for free); and it can filter out known attacks, ddos attempts, geofence your services to regions you’ll actually be in, provide/autorenew ssl certs for https, show you usage analytics, cache static data reducing server/network load, etc.

    Ultimately, the paid option is well worth it IMO. $2/month (which I typically pay in 3-10 year blocks) is hardly anything.

    /edit; vpns are good and all, but they require you to setup software on the remote device to connect to it, and that typically routes most if not all your traffic back to the vpn server then out to the internet. That can create speed/bandwidth issues.

    A domain allows you to access your services from any Internet connection with 0 configuration on the client side. Just accessing it like any other website.

    I also host a vpn directly from my network, that I access/find via my domain. This means I’m not dependent on a public service like tailscale, but can still add additional security to access private only services (stuff I don’t expose to the open internet)


  • https://en.wikipedia.org/wiki/Network_address_translation#NAT_hairpinning

    TL;DR Your router sees you trying to reach your external address and routes the connection back to your LAN without leaving the network.

    This does still depend on a functional internet connection however, as your client gets your public IP from a public DNS server over the Internet.

    If you were to run a DNS server locally (I use pihole for this), you could have that DNS respond with your local IP, allowing clients within your LAN to resolve the name without needing to reach out to public DNS. This means your local connections will still work when your internet is down; it also provides more privacy by keeping those requests local and can let you make local-only names that aren’t publicly listed.

    Of the ~28 FQDNs in my setup, only 4 are public. The rest is local/vpn only and not publicly listed due the above. The reverse proxy then drops all connections that don’t use one of those recognised names, before even completing the TLS handshake. (So direct connections from someone port scanning my IP or using a domain name someone else has pointed at my IP are completely ignored/dropped without response. The server doesn’t even send the TLS cert so as to not expose the names defined in it.)


  • Darkassassin07@lemmy.caOPtoSelfhosted@lemmy.worldOpenVPN ipv4 troubles.
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    5 个月前

    To avoid this, you will need an IPv4 address on your client, or an IPv6 address on your server.

    This confuses me because I have an IPv4 address on the client, and that IPv4 is what the server is seeing make the connection…

    /edit

    I think I get it.

    The client actually only has IPv6. The IPv4 address I’m seeing in the log and whatismyipaddress.com is the address of my mobile providers NAT.

    Thanks. I still haven’t totally wrapped my head around IPv6. Stubbornly happy with IPv4 tbh, but it seems the rest of the world is moving on, understandably.





  • NSFW does not equal exclusively porn.

    I’m not looking to block out gore or triggering topics, particularly news stories such as what’s come out of Portland Minnesota lately. Hell some of my own posts are NSFW, but I’ve never posted porn.

    Disabling/blocking all NSFW entirely is not an acceptable solution when it’s only porn I’m trying to not be flooded with.


    At its peak, before instance blocking was a thing: 4/5 posts under the ‘All’ feed were porn. I posted a picture quite a while back (I’m not gonna go dig it out, but it’s in my comment history), from before we could block an instance, with just a massive list of communities in my block list almost entirely from lemmynsfw. It was way over the top.

    Now I can just block an instance or community that dedicates itself to porn and all is well. I still don’t think that content belongs on a platform like this. If people want porn, they can go to the MANY sites that serve porn; it shouldn’t be combined with your daily scrolling through news, current events, and funny cat videos*. But we have tools to work around it; so, moving on.

    * heavily paraphrasing for general everyday content that an average person may share with friends/family.

    Edit: I have no idea why I said Portland… I meant Minnesota, referring to Renee Good and Alex Pretti.