Comment on Wireguard over IPv6
jores@infosec.exchange 1 week ago@filister You should keep in mind that every "normal" HTTPS certificate is recorded publicly (certificate transparency, see e.g. crt.sh). If you do expose services, you most likely won't get security by obscurity. You might be able to keep your services a bit more hidden when you expose them with IPv6 only, but not when you use a Let's Encrypt certificate with a proper DNS entry.
filister@lemmy.world 1 week ago
True, maybe the best way then is to expose them only within your Wireguard network.