chaplin2

joined 1 year ago
[–] [email protected] 1 points 11 months ago

Frankly these are useless. SSH is secure by default and will never support algorithms that could be possibly broken. Same for TLS 1.3

[–] [email protected] 1 points 11 months ago

Docker bypassing ufw is very bad

[–] [email protected] 3 points 1 year ago

If you disable password authentication, and use public key authentication, yes.

[–] [email protected] 1 points 1 year ago

The reason for downvotes is comparing apple and oranges, and also throwing FTP in the mix!

Let’s consider SFTP and nextcloud. SFTP is a secure respected protocol for file transfer. If you use key authentication and disable the password authentication, it approaches to be bulletproof security wise. SSH has rarely had a vulnerability that would allow attackers in. It’s even have post quantum cryptography. It’s rather easy to set up. But it doesn’t do more than file transfer. It also doesn’t have a lot of GUI apps.

Nextcloud is like Dropbox. You can find A LOT of things in it (though frankly the quality of most of them may be low). File transfer is just one of the things that it does. It uses https, why? Because the web technologies and developers have focused on this versatile protocol in the past decades. You access internet through port 443 not 22!

If I want to backup data or transfer files, I use SFTP. Over the internet, I trust SFTP not nextcloud. For other things, I use other tools such as Synchting, nextcloud etc. Synchting allows syncing over SSH.

[–] [email protected] 1 points 1 year ago

Wireguard is what you want!

[–] [email protected] 1 points 1 year ago (3 children)

The 2 in this rule isn’t clear: 2 different media?

Why is it important if it’s DVD & HDD or SSD & HDD?

[–] [email protected] 1 points 1 year ago (2 children)

How do you compare Caddy with nginx proxy manager?

[–] [email protected] 1 points 1 year ago

Yes. For example, I want to share all emails on a particular person.

The emails can be easily browsed, searched, etc. I don’t want to share my entire inbox.

[–] [email protected] 1 points 1 year ago

Is paperless-ngx useful for this too?

[–] [email protected] 1 points 1 year ago (1 children)

I’m referring to ZERO DAYs. OpenSSH is a serious security product. Those web apps are written by random people and probably riddled with vulnerabilities not known to public.

Here is the rule. Only a trusted vpn and ssh key authentication can be public.

[–] [email protected] 1 points 1 year ago (3 children)

You are doing it wrong: SSH with key authentication is the most secure piece, and could even be public. Immich and Jellyfin surely have zero days and should be behind VPN

[–] [email protected] 1 points 1 year ago

Off topic.

Jellyfin apps seem to me less user friendly than plex.

Plex iOS app moves back and forth in the video pretty fast. Why are there pictures of cups and tea etc instead of clear 10s back and forth? Common!

view more: next ›