Skip Navigation

User banner
Posts
9
Comments
57
Joined
2 yr. ago

  • i also think that it's overkill, especially for a minimalistic tool like wireguard. That's why I mentioned "if you want to be extra paranoid". This forum is for learning, and this question is an open ended learning question, hence, an opportunity to learn about port knocking, even if the actual real life benefit of that would be minuscule.

  • +1 on not using containers.for Network routing stuff That way lies pain and misery.

  • Good point, kernel updates should be paired with reboots to get kernel patches applied quickly.

    Yes wireguard would only accept connections clfrom clients with known certificates, but this is "belt and suspenders" approach. What happens if there's a bug in wireguards packet parsing or certificate processing? Using port knocking would protect against this —very remote— possibility.

  • VPN software usually is built strong to begin with, and any vulnerabilities discovered will be promptly fixed as well, so updating frequently should suffice. (Why not automate it with unattended-upgrades package?

    Using a random high port number will probably hide it well enough for Internet-wide port scanners as well.

    if you want to be extra paranoid, you can hide the VPN service behind a port knocker as well.

  • I recommend https://migadu.com. not free, but the lowest price tier has lots of features, unlimited mailboxes etc.

  • keepass2android is worth a try as well.

  • A good answer to a "why?" question is "why not?" This can be a great learning or practice opportunity for redundant network links and other interface challenges.

  • Nope, not realistic for "mirroring". Federated could be possible, but I wouldn't have high hopes about (good) latency and coverage.

  • Otoh, Spotify (and probably apple and other big corps) don't even allow you to add RSS URLs, so I wanted to point out they Google was one of the big players which was more open.

  • Ah true. Companies are great at hiding the open web that they (ab)use.

  • Google Podcasts also supported entering RSS feeds manually.

  • Huh, I wasn't so sure about Osiris-Rex but I totally remembered STEREO A & B as stationary at L4 and L5.

    Note to self: re-read the sources you quote.

  • No need for using sensational/clickbait headlines like this.

  • Yes it's a sci-fi anthology.