Live data from Hacker News

Locally hosting an internet-connected server

mjg59.dreamwidth.org

171–180 of 183 posts

Re: Locally hosting an internet-connected server

#171
post #99

Earlier quoted context omitted.

What the heck? That's like not wanting a street address because people might come to block your front door somehow, or burglars might find your building and steal from it. The big brothers you mention would be like gated/walled communities in this analogy I guess Saying this as someone who's hosted from at home for like 15 years Also realise that you're sending the IP address to every website you visit, and in most V…

I don’t think this is the right analogue. Having someone come to your door breaking things would take much larger effort, and easy to be caught. But DDoS or attack your service has minimal cost. Visiting sites and sending the IP address is not the problem, the router has firewall and basically blocking unwanted attention. But when you expose something without protection and allow someone to burn your CPU, or, in a wo…

> basically blocking unwanted attention. But when you expose something without protection and allow someone to burn your CPU

... sure. You'd think I'd have noticed that in nearly two decades of hosting all different kinds of services if this were a thing

Re: Locally hosting an internet-connected server

#172
post #99

Earlier quoted context omitted.

What the heck? That's like not wanting a street address because people might come to block your front door somehow, or burglars might find your building and steal from it. The big brothers you mention would be like gated/walled communities in this analogy I guess Saying this as someone who's hosted from at home for like 15 years Also realise that you're sending the IP address to every website you visit, and in most V…

Yeah and of course it will be depend on your personality and risk model. Compared to other things I don’t want to risk my data, whether leaked or damaged. And I make mistakes, a lot. If you are very meticulous and can ensure that you can put up all the security measures yourself and won’t expose something you don’t want to. I am just not that kind of person.

I'm not meticulous either. I had one responsible disclosure and a few times where I noticed issues myself but never that an attacker discovered it first. There's not that many malicious people. The only scenario where you realistically get pwned is when there is a stable and automated exploit for a widely spread service that can be automatically discovered, something like Heartbleed or maybe if a WordPress plugin has an SQL injection or so

Run unattended upgrades, or the equivalent for whatever update mechanism you use, and you'll be fine. I've seen banks with more outdated running services than me at home... (I do security consulting, hence)

Re: Locally hosting an internet-connected server

#173
post #132
post #99

Earlier quoted context omitted.

What the heck? That's like not wanting a street address because people might come to block your front door somehow, or burglars might find your building and steal from it. The big brothers you mention would be like gated/walled communities in this analogy I guess Saying this as someone who's hosted from at home for like 15 years Also realise that you're sending the IP address to every website you visit, and in most V…

To do that people have to physically come to my house and there are solutions to that, people can fuck with my internet from anywhere in the world. It's similar to why remote internet voting is such a pandora's box of issues.

There's 4 billion front doors on the v4 internet. Sending you a DDoS is transient (not like doing something to you physically) and doesn't scale to lots of websites, especially for no gain

In addition to myself, I know some people who self host but not any who ever had a meaningful DDoS. If you're hosting an unpopular website or NAS, nobody is going to be interested in wasting their capacity on bothering you for no reason

Anything that requires custom effort (not just sending the same packets to every host) doesn't scale either. You can host an SQL injection pretty much indefinitely with nobody discovering it, so long as it's not in standard software that someone might scan for, and if it is, then there'll be automatic updates for it. Not that I'd recommend hosting custom vulnerable software, but either way: in terms of `risk = chance × impact` the added risk of self hosting compared to datacentre hosting is absolutely negligible, so long as you apply the same apt upgrade policy in either situation

Online voting has nothing to do with these phantom risks of self hosting

Re: Locally hosting an internet-connected server

#174

Earlier quoted context omitted.

Once again I voice the only sane option: Skip IPv6 and the insanity that it is, and do IPv8 and simply double (or quadruple) the address space without introducing other new things.

IPv6 is the reason why we can't have IPv6 Your IPv8 is what IPv6 should have been. Instead, IPv6 decided to re-invent way too much, and is why we can't have nice things are are stuck with IPv4 and NAT. Just doubling the address width would have given us 90% of the benefit of V6 with far less complexity and would have been adopted much, much, much faster. I just ported some (BSD) kernel code from V4 to V6. If the addr…

IPv6 reinvented hardly anything. It's pretty much IPv4, with longer addresses, and a handful of trivial things people wished were in IPv4 by consensus (e.g. fragmentation only at end hosts; less redundant checksums).

The main disagreements have been above what to do with the new addresses e.g. some platforms insist on SLAAC. (Which is good because it forces your ISP to give you a /64).

Devices operating at the IP layer aren't allowed to care about extension headers other than hop-by-hop, which must be the first header for this reason. Breaking your stupid middlebox is considered a good thing because these middleboxes are constantly breaking everyone's connections.

Your sockaddr complaints WOULD apply at double address length on platforms other than your favorite one. The IETF shouldn't be in charge of making BSD's API slightly more convenient at the expense of literally everything else. And with addresses twice as long, they wouldn't be as effectively infinite. You'd still need to be assigned one from your ISP. They'd still probably only give you one, or worse, charge you based on your number of devices. You'd still probably have NAT.

Re: Locally hosting an internet-connected server

#175

Earlier quoted context omitted.

Yes. Thats the one. Works really well. Basically a free version of tailscale. A bit more of a learning curve.

Headscale [1] has a stronger claim to "free version of Tailscale" - it's literally a self-hosted version of Tailscale's coordination server. It's even compatible with the Tailscale client. [1]: https://headscale.net/

The problem with Headscale is that it has absolutely no documentation. All of it is described in relation to Tailscale, which is what I don't want to use. Here are the Tailscale features we have, here are the differences with Tailscale. It's very weird.

Re: Locally hosting an internet-connected server

#176
post #43

Earlier quoted context omitted.

Not quite. I'm in the UK and some of our customers get blocked by overzealous CDNs and they're all on CGNAT.

It's not really overzealous since not banning the CGNAT IPs just gives the abusers safe harbor.

And banning them makes an entire country unable to use your site. That might be tolerable (to the site owner, but not in general) if the country is Argentina. Not if the site is France. Which is why Argentina gets blocked a lot more than France and if you want to scrape things you'd do better on a CGNAT network in France.

Re: Locally hosting an internet-connected server

#177
post #76

Things like this that go through some external VPS always seem a bit pointless to me. just host it on the VPS directly

I have workloads that need 32T of enterprise nvme that I run on a machine in my garage.

How much for a VPS that supports bandwidth to access those 32T data frequently?

Re: Locally hosting an internet-connected server

#178
Hm, 600 symmetric with monkeybrains?? I’ve had monkeybrains for over 3 years and have never seen over 200 down. In fact, I reached out to them today because for the last 3 months it’s been about 50 down or less. Like, I can barely stream content slow. What gives? I am in a 6 unit in lower haight. Most of the units also have MB. The hardware is relatively new (2019?). What gives?

Re: Locally hosting an internet-connected server

#179

Earlier quoted context omitted.

I wish I had access to a small ISP. It is comforting to know that if something goes wrong, on the other end of the line there is someone with a Cisco shell open ready to run a traceroute.

For sure…in case of reaction times and flexibility they are great…Until something serious happens outside of their scope.

Like what? Their scope is being an ISP, i.e. routing packets.

Re: Locally hosting an internet-connected server

#180

Earlier quoted context omitted.

For sure…in case of reaction times and flexibility they are great…Until something serious happens outside of their scope.

Like what? Their scope is being an ISP, i.e. routing packets.

Usually it‘s about standing, resources and options. Serious problems like fibre cuts, local power outages and DDoS attacks are usually not in their scope and they have to wait for 3rd parties to fix these problems with little iptions to speed up those processes. Bigger ISP usually have teams/departments which have well established processes/solutions to tackle these problems. That said, I‘m totally aware that each of them (small or big ISP) have their pros and cons - as always it mainly depends on your use case and requirements.
Post reply on HN