Comment on Nextcloud zero day security

JustinAngel@lemmy.world ⁨5⁩ ⁨months⁩ ago

Yikes! I’d avoid leaving any services externally exposed unless they’re absolutely necessary…

Tailscale+Headscale are pretty easy to implement these days. Since it’s effectively zero trust, the tunnels become the encrypted channel so there’s an argument that HTTPS isn’t really required unless some endpoints won’t be accessing services over the Tailnet. SmallStep and Caddy can be used to automatically manage certs if it’s needed though.

You can even configure a PiHole (or derivative) to be your DNS server on the VPN, giving you ad blocking on the go.

source
Sort:hotnewtop