I have been thinking about self-hosting my personal photos on my linux server. After the recent backdoor was detected I’m more hesitant to do so especially because i’m no security expert and don’t have the time and knowledge to audit my server. All I’ve done so far is disabling password logins and changing the ssh port. I’m wondering if there are more backdoors and if new ones are made I can’t respond in time. Appreciate your thoughts on this for an ordinary user.
I’m not a security specialist either. I learn new things every day, but this is why my NextCloud is accessible through TailScale only and I have zero ports exposed to the outside world.
The only real convenience I lose is being able to say “check out this thing on my personal server” with a link to someone outside my network, but that’s easily worked around.
Next: how do we know tailscale’s network hasn’t been backdoored?
Headscale. And then you don’t even have to trust any outside auth provider to not log in in your name.
I figure there’s a certain amount of trust you have to have in strangers for a LOT of things we use every day.
I try to be selective with where I put that trust, especially when I can’t just homebrew an advanced custom solution, but I figure Tailscale is much better than attempting to just host it on my LAN with an open a port to the big scary web and hope a bot doesn’t find a gap and ransomware it all lol.
3-2-1 backups and a certain bit of trust.
Because heck, even CPUs have been found with exploitable microcode. (Spectre and Meltdown?) At some point you just gotta balance “best rational protection” with not going insane, right?
Headscale mentioned here is pretty neat too, but I feel like spinning up Dockers on Proxmox and Tailscale is as much moving parts as I’m willing to manage alongside everything else in life. :)
I think you can use Tailscale Funnels for that.