4 ms·
This is why I set most services to listen only on localhost. When I need to expose them externally, I put them behind nginx with http basic auth. It's not top
by mises 7y ago
This is why I set most services to listen only on localhost. When I need to expose them externally, I put them behind nginx with http basic auth. It's not top security by any means, but it does the job and provides enough security to stop stuff like this. It's like the old saying about outrunning a bear: you don't have to be the fastest guy, you just have to be faster than the slowest guy.
- tenebrisalietum 7y agoClient side cetificates are also convenient for this purpose.
- edoceo 7y agoYes! From your own CA. This is a great method.
- o-__-o 7y agoAll of my servers are isolated from the internet by......namespaces. One kernel vulnerability and I’m cooked
- fulafel 7y agoThis is I think better than the corporate-legacy style VPN solution. Nginx is not too bad but what's the most secure frontend proxy these days? Ideally written in a memory safe language.