4 ms·
I'm thinking of doing this but at the same time I'm afraid of exposing my home network to a remote VPS. Am I being too paranoid about this? If I do go this rou
by quaintdev 4y ago
I'm thinking of doing this but at the same time I'm afraid of exposing my home network to a remote VPS. Am I being too paranoid about this?
If I do go this route do you have any suggestions with respect to security?
- VTimofeenko 4y agoI have a similar setup and I was also quite paranoid at first. Wireguard is a very solid solution that does precisely what it claims to do and allows you to layer extra network controls on top of it, so the vpn clients only get routed where you allow them to. A bit less hands-on solution could be something like tailscale.
- tbrownaw 4y agoThe VPS is running sshd (pubkey auth only) and Wireguard, and I also see bound UDP sockets for dhclient and ntpd. And that's it, at least for the public interface. Also, things I want to look at on my home network mostly work fine over ssh (console stuff, git, etc). So I haven't actually gotten around to setting up full routing yet, and use the wireguard endpoint box as an ssh jumphost / bastion (and can forward ports if I do have something to get at that doesn't like to play nice).
- stormbrew 4y agoYou can lock down a wireguard vpn server pretty hard, because wireguard itself is essentially invisible unless you know it's there. It doesn't respond to anything but well formed, correctly signed (in the case of connection initiation) or encrypted (for the actual network itself) packets. So conceivably, you can have your vpn server not respond to public icmp, not expose even ssh without wireguard under it, and be essentially invisible to the internet.
- fs111 4y agoIf you are not replying to ICMP you let everyone know that you are there. If you we're not there, the error would be 'no route to host', but there is a route, so you must bei there
- Fronzie 4y agoFor me, https://tailscale.com/ https://tailscale.com/ gives me an easy-to-use personal network. It uses wireguard with custom configuration on top of it.
- zxcvbn4038 4y agoOne of the benefits to Tor is you don’t need to open any ports, the Tor acts as a reverse proxy for onion services. A lot of Tor services run over port 443 because it gets passed through with little to no issue. With Wireguard you have to deal with all the networks, particularly airports and businesses, that don’t allow UDP. I’ve had a good bit of luck using the dns and ntp ports for wireguard but if your on a network that has something filtering/monitoring dns or only wants you to use their time server, those can stop you also. Once http/3 is official that should make things better for everyone using wireguard.
- TheaomBen 4y agoPlus tor hidden services -or whatever the current nomenclature is- offer a fairly robust and painless story for authentication in this "sorta VPN" scenario. Generate a couple extra keys and invite a friend and his bots. https://community.torproject.org/onion-services/advanced/client-auth/ https://community.torproject.org/onion-services/advanced/cli...
- zxcvbn4038 4y agoI do the client auth feature. The chances of someone stumbling across my hidden service is pretty low I think, but it’s not zero. With auth set up I don’t think a Tor client can even get the Id of the rendezvous server without having the correct key.
- deleted 4y ago[deleted]