Post AEC0upC1XHVBkImZge by deriver@fosstodon.org
 (DIR) More posts by deriver@fosstodon.org
 (DIR) Post #AEByggBW20vFqRfjH6 by PsychoLlama@fosstodon.org
       2021-12-08T03:06:20Z
       
       0 likes, 0 repeats
       
       This is a cool idea: https://eevans.co/blog/garage/Instead of port forwarding to self-hosted services, he runs a Cloudflare Tunnel that opens in a quarantined network.More resilient than DDNS, obscures your IP, safe against DDOS attacks, and doesn't open your entire LAN to the internet.
       
 (DIR) Post #AEByggZyZ4UL4J7GOu by deriver@fosstodon.org
       2021-12-08T06:01:36Z
       
       0 likes, 0 repeats
       
       @PsychoLlama don't you end up placing a lot of trust in Cloudflare with this approach? It seems like a great solution that solves a few big problems, but I believe Cloudflare is remotely decrypting (if its leaving your hardware encrypted) and re-encrypting the contents. If that's true, Cloudflare could MITM attack or read/collect/share your data. May not matter too much if its only serving up a public blog, but I'm hesitant to serve anything private/sensitive over this solution.
       
 (DIR) Post #AEByggxj8lUGFyEEQC by PsychoLlama@fosstodon.org
       2021-12-08T08:03:17Z
       
       0 likes, 0 repeats
       
       @deriver Great point. I think you're right, they control the certificates so they have a dangerous amount of power. I hadn't thought about that... 😦
       
 (DIR) Post #AEByghOJXukpaQfSrY by jrballesteros05@fosstodon.org
       2021-12-08T11:13:58Z
       
       0 likes, 0 repeats
       
       @PsychoLlama @deriver I read the post and I liked the idea too except the cloudfare part in the same way as @deriver said. So I was looking for an alternative and there are a lot, this is one I am reading and I found it interesting. https://github.com/fatedier/frp
       
 (DIR) Post #AEC0upC1XHVBkImZge by deriver@fosstodon.org
       2021-12-08T11:38:49Z
       
       0 likes, 0 repeats
       
       @jrballesteros05 @PsychoLlama hadn't heard of this before - it looks interesting. It seems conceptually similar to setting up a VPN on a VPS (including the amount of work/maintenance). Any reason to do this over using a VPN?
       
 (DIR) Post #AEC2KPkqpxluKkq3qS by jrballesteros05@fosstodon.org
       2021-12-08T11:54:47Z
       
       0 likes, 0 repeats
       
       @deriver @PsychoLlama I haven't used these kind of services, I actually rather the VPN but I find it interesting in case you have to expose a service to non-secure networks. With the VPN you have to connect to the VPN first before accessing to the service. Sometimes you need a service exposed directly without the need to configure a VPN access. These kind of tools sound interesting for people who normally self host their applications.
       
 (DIR) Post #AEC3LjSr8s8bhqc7rU by jrballesteros05@fosstodon.org
       2021-12-08T12:06:14Z
       
       0 likes, 0 repeats
       
       @deriver @PsychoLlama Actually I was looking for alternatives to "argo tunnel" and I found this list: https://pythonrepo.com/repo/anderspitman-awesome-tunneling-python-networking-programming