Post AEC0upC1XHVBkImZge by deriver@fosstodon.org
(DIR) More posts by deriver@fosstodon.org
(DIR) Post #AEByggBW20vFqRfjH6 by PsychoLlama@fosstodon.org
2021-12-08T03:06:20Z
0 likes, 0 repeats
This is a cool idea: https://eevans.co/blog/garage/Instead of port forwarding to self-hosted services, he runs a Cloudflare Tunnel that opens in a quarantined network.More resilient than DDNS, obscures your IP, safe against DDOS attacks, and doesn't open your entire LAN to the internet.
(DIR) Post #AEByggZyZ4UL4J7GOu by deriver@fosstodon.org
2021-12-08T06:01:36Z
0 likes, 0 repeats
@PsychoLlama don't you end up placing a lot of trust in Cloudflare with this approach? It seems like a great solution that solves a few big problems, but I believe Cloudflare is remotely decrypting (if its leaving your hardware encrypted) and re-encrypting the contents. If that's true, Cloudflare could MITM attack or read/collect/share your data. May not matter too much if its only serving up a public blog, but I'm hesitant to serve anything private/sensitive over this solution.
(DIR) Post #AEByggxj8lUGFyEEQC by PsychoLlama@fosstodon.org
2021-12-08T08:03:17Z
0 likes, 0 repeats
@deriver Great point. I think you're right, they control the certificates so they have a dangerous amount of power. I hadn't thought about that... 😦
(DIR) Post #AEByghOJXukpaQfSrY by jrballesteros05@fosstodon.org
2021-12-08T11:13:58Z
0 likes, 0 repeats
@PsychoLlama @deriver I read the post and I liked the idea too except the cloudfare part in the same way as @deriver said. So I was looking for an alternative and there are a lot, this is one I am reading and I found it interesting. https://github.com/fatedier/frp
(DIR) Post #AEC0upC1XHVBkImZge by deriver@fosstodon.org
2021-12-08T11:38:49Z
0 likes, 0 repeats
@jrballesteros05 @PsychoLlama hadn't heard of this before - it looks interesting. It seems conceptually similar to setting up a VPN on a VPS (including the amount of work/maintenance). Any reason to do this over using a VPN?
(DIR) Post #AEC2KPkqpxluKkq3qS by jrballesteros05@fosstodon.org
2021-12-08T11:54:47Z
0 likes, 0 repeats
@deriver @PsychoLlama I haven't used these kind of services, I actually rather the VPN but I find it interesting in case you have to expose a service to non-secure networks. With the VPN you have to connect to the VPN first before accessing to the service. Sometimes you need a service exposed directly without the need to configure a VPN access. These kind of tools sound interesting for people who normally self host their applications.
(DIR) Post #AEC3LjSr8s8bhqc7rU by jrballesteros05@fosstodon.org
2021-12-08T12:06:14Z
0 likes, 0 repeats
@deriver @PsychoLlama Actually I was looking for alternatives to "argo tunnel" and I found this list: https://pythonrepo.com/repo/anderspitman-awesome-tunneling-python-networking-programming