• guy@piefed.social
    link
    fedilink
    English
    arrow-up
    1
    ·
    3 days ago

    Would love to selfhost. However, I have no trust in my skills to secure my device in the same manner as a provider, and I do not wish my database to be compromised.

    • communism@lemmy.ml
      link
      fedilink
      English
      arrow-up
      0
      ·
      3 days ago

      I’ve had my VPS exposed to the internet for a while and never been pwned. No professional experience. Use SSH keys, not password authentication. Use FDE if physical access is in your threat model. Use a firewall to prevent connection on internal-only ports.

      Vaultwarden will store your passwords encrypted (obviously) so even if your database does get stolen, the attacker shouldn’t be able to read your passwords without your master password.

        • communism@lemmy.ml
          link
          fedilink
          English
          arrow-up
          2
          ·
          2 days ago

          I know about Tailscale. I don’t use it because I want my VPS to be exposed to the internet; some of my services are supposed to be public. And those that aren’t, have their own authentication systems that are adequately secure for their purposes. I just don’t need Tailscale so I’ve not bothered with the setup.