• 0 Posts
  • 84 Comments
Joined 1 year ago
cake
Cake day: June 29th, 2023

help-circle

  • I’m going to cast another vote for a reverse proxy, such as NginxProxyManager. It’s really easy to set everything up, and they’re usually very easy to run in Docker/Podman.

    One thing to note: if you end up with a domain with mandatory HSTS, you’ll have to use DNS-based certificate generation rather than HTTP based, since unencrypted HTTP is blocked (chicken/egg problem to get HTTPS working). It’s not hard, but you have to be aware of that limitation.


















  • Security is about understanding reasonable threat models. 99.99% of reasonable threats to your machine involve theft or loss of the entire machine and personal data or accounts being accessed…

    A thief is going to steal your computer and gut it, not apply liquid nitrogen to your RAM and attach a bunch of instruments with hopes of extracting a crypto key so he can have a small chance at accessing potentially interesting data.

    If you think a thief is going to do more, your threat model is very skewed. I suspect that you think you’re much more interesting than you actually are.

    Your cute statement about child porn is tasteless and thoughtless.

    But it was cute.