• guy@piefed.social
      link
      fedilink
      English
      arrow-up
      1
      ·
      3 days ago

      Would love to selfhost. However, I have no trust in my skills to secure my device in the same manner as a provider, and I do not wish my database to be compromised.

      • communism@lemmy.ml
        link
        fedilink
        English
        arrow-up
        0
        ·
        3 days ago

        I’ve had my VPS exposed to the internet for a while and never been pwned. No professional experience. Use SSH keys, not password authentication. Use FDE if physical access is in your threat model. Use a firewall to prevent connection on internal-only ports.

        Vaultwarden will store your passwords encrypted (obviously) so even if your database does get stolen, the attacker shouldn’t be able to read your passwords without your master password.

          • communism@lemmy.ml
            link
            fedilink
            English
            arrow-up
            2
            ·
            2 days ago

            I know about Tailscale. I don’t use it because I want my VPS to be exposed to the internet; some of my services are supposed to be public. And those that aren’t, have their own authentication systems that are adequately secure for their purposes. I just don’t need Tailscale so I’ve not bothered with the setup.