dan

joined 3 years ago
[–] dan@upvote.au 5 points 13 hours ago

I'd like to see that too, but R&D costs for a product like this are enormous so I doubt it'd happen any time soon.

[–] dan@upvote.au 0 points 5 days ago* (last edited 5 days ago)

I still don't understand your point. With a firewall on the router, there's no difference between IPv4 and IPv6. Both are firewalled at the router. Where are the "bugs and vulns"?

If you mean my original point of the firewall not being enabled by default, I haven't seen that recently. It was a problem historically.

[–] dan@upvote.au 1 points 6 days ago (1 children)

I don't trust the prebuilt images that providers provide so I like installing from my own ISO.

cloud-init is useful sometimes, but I recently had an issue with Alpine's alternative implementation (tiny-init) where it was setting a root password I didn't know. It was pulling it from some sort of metadata, but there was nowhere in my provider's control panel to set the default root password. Alpine also doesn't have any documentation about how to disable tiny-init, so I had to read the code and figure it out myself (create a file called /etc/tiny-cloud.disabled before init runs).

cloud-init also can't configure LUKS encryption. I know its usefulness is limited on a VM (since the provider can snapshot the memory and retrieve the encryption key that way), but it's still useful when the VM isn't running or if you stop using that provider to ensure they can't recover the data, and it's required in some cases (eg Plaid required me to certify that all data is encrypted at-rest before they gave me access to their API)

[–] dan@upvote.au 4 points 6 days ago

Having a default firewall is also a blessing, which all good routers should do. NAT is a curse.

[–] dan@upvote.au 6 points 6 days ago (2 children)

The firewall is on the router.

[–] dan@upvote.au 7 points 6 days ago* (last edited 6 days ago) (3 children)

The underlying protocol (RFB) is very simple to implement, and in fact some friends and I implemented both a VNC client and server as part of a project we worked on at university nearly 20 years ago.

Because of this, it's common to find it in various places, especially for interacting with systems that don't have an OS installed yet:

Most good VPS providers provide VNC access so you can set up your own OS from an ISO, use Clonezilla to clone the drive over the network, recover files if the drive gets corrupted somehow, etc. It's a built-in feature of KVM/libvirt that the providers usually expose using something like NoVNC in their control panel. The common off-the-shelf control panels (Virtualizor, SolusVM, Virtfusion, Proxmox, etc) all have it as a standard feature.

A lot of IPMI/BMC and KVM-over-IP systems use VNC too, for a similar purpose, just for physical hardware rather than VMs. The protocol being very simple makes it easy to build a simple version into an embedded system. This is also usually accessed via NoVNC in a web UI.

[–] dan@upvote.au 22 points 6 days ago* (last edited 6 days ago) (7 children)

One of the ways it can happen is if a router doesn't have a proper IPv6 firewall.

The majority of internet users in the USA have IPv6 connectivity - something like 55-60% overall, and close to 100% on some networks. T-Mobile's network is 100% IPv6-only, using 464XLAT for connectivity to legacy IPv4-only servers. Most Comcast customers have IPv6 too, as they were the first major ISP to roll out IPv6, close to 15 years ago now.

Without an IPv6 firewall on the router, all devices on your network are directly accessible from the outside world (unless they're running their own firewall, of course). At least Windows ships with a firewall enabled by default, which reduces the impact for Windows users.

I've seen this in places you wouldn't expect it, too. TP-Link's prosumer/SMB 10Gbps router (Omada ER8411) didn't have an IPv6 firewall until about a year after launch. I had to disable IPv6 until then. They did add it, but I've since switched to a Unifi Cloud Gateway Fiber.

Thankfully I haven't seen it recently, so maybe it's not an issue any more on modern hardware.

NAT is a hack, not a security feature, and IPv6 removes the need for it. The firewall is the security feature. (edit: the firewall on the router)

[–] dan@upvote.au 1 points 1 week ago

I think people will eventually have to get used to paying for things though, if bots / AI / ad blockers kill off the feasibility of online advertising. Either that or everything becoming a freemium service with major limits for free users.

[–] dan@upvote.au 2 points 1 week ago (1 children)

So I can install any software I want. I'm running my own Lemmy server. I host Odoo and n8n for my wife's business. I have servers running Borgbackup and Borgmatic for backups. And a bunch of other stuff.

[–] dan@upvote.au 5 points 1 week ago* (last edited 1 week ago)

It's the same way that taxes work. Rich people contribute more than poorer people, but everyone can use things funded by public money (parks, police, fire fighters, public transport, schools, health care outside the USA, etc).

I actually wonder if there should be more taxpayer-funded online services. Lemmy's development was partially funded by government money (NLNet Foundation via the European Commission) for example.

[–] dan@upvote.au 5 points 1 week ago (2 children)

I've tried that before, but barely anyone donates. People expect the world for free.

[–] dan@upvote.au 1 points 1 week ago* (last edited 1 week ago) (1 children)

I agree about the automated scaling, but with VPS hosting you can usually have several hot spares to handle traffic spikes, and still spend less than something like AWS. Most good VPS hosts will let you create a private network between your VPSes. 1000x spikes aren't very common.

CDNs are pretty easy in general, especially if they support origin pull.

I don't like keeping all my eggs in one basket, so I use a few different providers.

view more: next ›