• 0 Posts
  • 28 Comments
Joined 2 years ago
cake
Cake day: June 20th, 2023

help-circle






  • Tailscale is very popular among people I know who have similar problems. Supposedly it’s pretty transparent and easy to use.

    If you want to do it yourself, setting up dyndns and a wireguard node on your network (with the wireguard udp port forwarded to it) is probably the easiest path. The official wireguard vpn app is pretty good at least for android and mac, and for a linux client you can just set up the wireguard thing directly. There are pretty good tutorials for this iirc.

    Some dns name pointing to your home IP might in theory be an indication to potential hackers that there’s something there, but just having an alive IP on the internet will already get you malicious scans. Wireguard doesn’t respond unless the incoming packet is properly signed so it doesn’t show up in a regular scan.

    Geo-restriction might just give a false sense of security. Fail2ban is probably overkill for a single udp port. Better to invest in having automatic security upgrades on and making your internal network more zero trust




  • The headline overreaches as the article doesn’t support the passport dying as much as some early exploration into potential digital variants, and some convenience efforts to not have to show the passport.

    Dying would be “most people use the digital variant, it’s accepted everywhere and we’re phasing out the paper variant”… which sounds like it might happen on the same timeline as large scale fusion energy