• 15 posts
  • 67 comments
Joined 4 years ago
Cake day: January 3rd, 2022
  • This is fine unless you have a slightly higher threat model.

    Me personally, I dislike the idea that if someone (VPS provider or LE) were to snoop inside my VPS, they would have all of my unencrypted data where TLS ends and wireguard picks it up.

    I don’t do anything illegal, but I do have photos, personal files, and deeply personal journals/notes for which I enjoy the comfort of mind when kept private and secure.

    My recommendation is always to have your TLS equipped reverse proxy on your own hardware. Then use a VPS as a SSL passthrough proxy that forwards requests to the locally hosted reverse proxy. You can connect the two via wireguard.

    This has a few benefits. It keeps encryption end to end. It also allows you to connect to your server via your domain name even in you LAN. You can hijack your domain at the router level DNS menu to reroute to your local reverse proxy. And it keeps the TLS connection.

Does this or has this existed?

A site where users can post a bounty for a bug fix on something and others can contribute. If the bug is fixed, an arbitrator determines if the solution meets all of the parameters and rewards the programmer with the pooled funds.

Beyond bug fixes, it could be used to fund entire applications or even specific feature requests.

Companies or software packages could have their own official pages, with separate sections for bug fixes, feature requests, or even future versions.

Contributors can pledge an amount with a lifespan attached. If the bug or feature isn’t materialized within that window it refunds their account. Otherwise the money is held in escrow until paid out.

  • There’s a few apps I need to split out. Top priority is the signiant app which according to their documentation requires various AWS subdomains as well as their own. Specific subdomains are not specified and are implied to change regularly/on demand.

    In an ideal world I would do my split tunneling on the device itself, but I don’t trust Windows and thus I run my VPN at the router level.

    This isn’t a problem for most things, but I need to utilize my full bandwidth to transfer large files to clients in a timely manner, and a VPN becomes a massive bottleneck.

    Pfsense lets you alias by domain name (I believe it regularly resolves down to an IP and uses that for filtering), but again, you need to supply the exact subdomain.

    Just wondering if there’s an alternative solution to this issue. If it’s external to pfsense that’s not the end of the world.

    Worst case scenario, I would set up a dedicated Linux box or maybe even a VM which could share access to the file transfer NAS and split tunnel the entire box around the VPN. Definitely less convenient.

Running pfsense, I was able to route my entire LAN subnet through a VPN. I have firewall and NAT rules that use an alias to filter outgoing connections to specific domains outside of the VPN gateway.

This works great. But here’s the problem. Wildcards are not supported within pfsense aliases, and therefore unless you know the specific subdomain for a service, there’s no way to reroute services that use rotating or load balancing subdomains.

Surely this is a big problem in large companies. I’m sure they utilize a paid solution to solve this problem.

Are there any solutions for self hosting that are FOSS or within pfsense?

I know there’s many questions about self hosted Spotify alternatives, but this one has a slight twist.

Does there exist a service or service stack that provides a single sign on web interface where friends/family can login to search for and download music, stream, and create playlists/share playlists (or even their entire library) with other users?

I’ve always used Spotify to an extent as a social network. Almost all playlists are shared with close friends, and we share essentially a unified library. I’d like to replicate this outside of Spotify.

Essentially what Immich does but for music, podcasts, and audio books.

Some type of iPhone & android compatible app would be necessary as well.

The ability to easily upload purchased music from bandcamp as well as download pirated music from something like soulseek would be needed too.

  • I recommend it every time this question pops up and I’m surprised more people aren’t privy to it:

    Rent a VPS as your public gateway. Connect the VPS to your server with a simple wireguard tunnel.

    The only thing on the VPS should be a reverse proxy with SSL/TLS pass through.

    Send the traffic at the VPS reverse proxy to a reverse proxy on the main server. Configure this proxy to use letsencrypt certs.

    The benefit and importance of the SSL pass through reverse proxy, is that it allows all data in transit to remain encrypted until it reaches your physical server. Traditionally, most would suggest the one and only reverse proxy exist on the VPS but all traffic would then be decrypted on the VPS. This could obviously compromise your traffic if the VPS provider snoops or your VPS is compromised.

    Cloudflare tunnels decrypt on their hardware as well, which is why I always recommend avoiding their services.

HDD Data Recovery Options?

English Removed by mod

It finally happened. I have an 8TB hdd that is completely dead. It was backed up through backblaze but they purged the entire drive a while back, way before I noticed the drive wasn’t working. So my backup is gone too.

I’m fairly certain the pcb died, so theoretically an easy fix for a specialist, I think.

I’ve never had a drive failure I couldn’t handle on my own. How much does something like this cost and is it better to find a local place or go with a ship-to-store website?

Any recommendations are appreciated.

  • I’m not disagreeing that a Nazi salute is hate speech. Im disagreeing that it’s a sensible course of action to give the government the power to put a human being in a cage for doing it.

    Using racial slurs is also hate speech, should a person be imprisoned for using the n-word?

    Where it becomes punishable via government intervention to me should be a direct threat of violence on a group of people or call to action to do so.

    I’m trying to comprehend what the intended outcome of this type of punishment is anyway. Out of sight, out of mind I guess?

  • Yes, stripping somebody of their freedom for using a hand gesture is dystopian. Maybe consider that you thinking otherwise makes you a radical on the other side of the spectrum.

    There’s a reason fascism is becoming more popular across the globe and it’s accelerated by these overreactions. It feeds into right wing narratives and pushes people on the fence into becoming radical right more than just letting these idiots babble their bullshit and be seen for the fools they are.