

You can’t be real 😂 best laugh I’ve had in a while. Thanks for that.


You can’t be real 😂 best laugh I’ve had in a while. Thanks for that.


I don’t think that word means what you think it means.
I don’t know if it’s on the icon, I believe you have to use the cli “tailscale status” to view your tailnet nodes connection types
Is it possible you misconfigured your tailnet and instead of using a direct connection to your local subnet router you were using an ethereal port via a DERP relay? You can read into it more on tailscales documentation, but essentially you need to leave UPD inbound port 41641 open to your subnet router inbound from WAN.
Tailscale, headscale, or something along those lines may help optimize the route but as others have said to resolve this is an actual fashion you’d need a cdn which requires significant geo-redundant hardware which comes at a pretty significant cost. That being said I think your friend has a good shot if you implement the former.
And definitely!
Since you clearly plan on keeping this equipment for the long-term, you may be better served by a newer lower power option that will likely be more performant for less long term cost.
Bringing non-disposable technology to China is a mistake in most circumstances.


Zero tier. I went tailscale originally, and they’re good, but their mdns support doesn’t exist and several services rely on it. (For me, the showstopper was time machine backups)


About to be 6.0000001% when my Kubuntu download finishes. I’m finally taking the dive boys, linux on main here we go.
Tape drives will be expensive and likely beyond overkill for this. I’d recommend you grab a blue ray DVD writer and use that instead. The discs are generally shelf stable for 25 years and hold about 50-128GB depending on the disc. Duplicates are cheap, storage is relatively easy, and it doesn’t require constant upkeep/power like a hard drive would. Downsides? They just stopped making the discs, so they’ll grow in cost over time. That’s about it that I can think of.


To be fair to bottles, they cité that even their hosting costs are usually barely covered, so I imagine it’s running on a pretty lean/Foss dev budget already.
Depends on the drive too, I have some insanely loud Ironwolf drives and you would never guess they’re from the same manufacturer as my practically silent Exos X18s.
I think of it as a lab because it’s my sandbox for me to do crazy server stuff at home that I’d never do on my production network at work, and I think that’s why the name stuck, because back when systems were expensive as heck it was pretty much just us sysadmin guys hauling home old gear to mess with.
My bad. I misread your previous post, specifically around “I agree with the other guy”. That being said, anyone with a functional device that can compute any amount of monero hashes is a proven target, granted, not specifically.
People like you in this industry are legitimately the reason botnets and significant compromise still exists. “You don’t need to be a genius to do all this additional config to make this thing I’m referring to as secure, secure.” Do you even read your own writings before you hit post? Also your final argument is so slathered in whataboutism I can’t even. Yes, any internet connectivity is going to be less secure than an air gap, but when you’re advising implementations you should keep security posture and best practices in mind. What you’re speaking on is more complex than any one person’s understanding of it due to significant layers of abstraction. Exhibit a? Ssh is not a codebase. It’s a network protocol. The codebase is literally different depending on implementation yet you continue to talk about it as if it’s a single piece of software that has been reviewed and like all ssh shares the same vulns but the software is entirely different depending on who implemented it so you have no real clue what you’re talking about and it’s actually sad people will be misled by your nonsense and false bravado. (https://en.wikipedia.org/wiki/Secure_Shell)
I’ve always disliked IT discussions for reasons like this. Everyone who comments seems to think that the mitigations, security considerations, and security compromises (IE, not caring if your images are leaked online) they’ve made are common knowledge… But, this is a forum advising people on how to configure their home severs for hobbiest use. Best practices should be the mantra, “just raw dog ssh on the internet with your 443/80 port mapping and you’re g2g” [sic] shouldn’t be an acceptable answer to you. If they’d stated that there are security considerations, but they like to implement them and expose ssh to the net for management purposes I’d have nothing to say, but to just advise people who lack that extra experience, without helping them understand why you’re okay doing what you’re doing and what you’ve done to solve for specific issues that the default configuration does not seems unhelpful at best.
Agreed, but best practices are meant to deal with the very rare. They didn’t put the vulnerabilities in the software due to negligence or malice, it’s just an ever evolving arms race with cracks that show up due to layer upon layer of abstraction. Again I’m not saying to never expose ssh to the net, quite the opposite, but as a best practice you should never do it unless you fully understand the risk and are prepared to deal with any potential consequences. That’s just a core tenant of understanding security posture.
🤔🤔🤔🤔🤔
Are we living in the same universe? In mine software doesn’t get patched all the time, in fact it’s usually a lack of patches that lead to any significant system compromise… Which happens time and time again. Also you’re on a thread that is advising hobbiests on how to configure and maintain their personal server, not the engineering meeting for a fortune 500. Yes, you can make ssh very secure. Yes, it’s very secure even by default. In the same regard, new vulnerabilities/exploits will be found, and it remains best practice not to expose ssh to raw internet unless absolutely necessary and with the considerations required to mitigate risk. Ssh isn’t even implemented identically on every device, so you literally cannot talk about it like you are. Idk why you’re arguing against the industry standard for best practices decided by people who have far more experience and engineering time than you or I.
Great! Migrated the rest of my devices over the past few months. Everything is now Linux aha, although I did end up switching to Cachyos but have since settled down with it (still Debian on my prod servers though). 0 regrets. Truly the year of the linux desktop is upon us.