

These are going to be the people who think it’s smart to just open up RDP and SSH to the wide web though…they shouldn’t be forwarding ports…they should use a VPN.


These are going to be the people who think it’s smart to just open up RDP and SSH to the wide web though…they shouldn’t be forwarding ports…they should use a VPN.


I’d much rather deal with setting up a few VPN gateways which is trivial at most…than securing a public web service. I deal with that crap enough at work.
There are a lot less variables to contend with with a single VPN endpoint which undergoes considerably more security auditing than N public web services. Many of which I don’t have the time to review myself and mitigate if they decide to suck at coding.
Edit: I share my services with less than 5 households though.
Edit2: I’m not sure what public ipv4 or ipv6 has to do with this. My remote sites use starlink ipv4. I haven’t setup ipv6 on those internally at all. They all tunnel via wireguard to my homesite.


Setup a VPN gateway at Grandma’s house. Works fine for me.


For the vast majority of users? Yes. They shouldn’t forward ports.
Setup a VPN gateway at Grandma’s house.


I’ve found a lot more that needed to be blocked than I actually want to actively participate in. But maybe that’s just fatigue from all the churn here during the initial reddit API fiasco.
I guess if I blocked literally any community that got political the Truth Social comparison wouldn’t feel so apt to me.


Considering how much of an angry echo chamber it is, it really feels like a lefty truth social. Or at least that’s how I describe it to non-users.
Yeah. This is why you don’t encourage normies to port forward…they make everyone a domain admin and open up RDP…