5 ms·
All of my current side projects are focused on lowering the barrier of entry for self-hosting. As much as I would love for all devices to have their own public
by anderspitman 4y ago
All of my current side projects are focused on lowering the barrier of entry for self-hosting. As much as I would love for all devices to have their own public IP address, I think that ship may have sailed.
Fortunately, I've found TLS SNI routing to be a viable alternative for most use cases[0]. I think the future of self-hosting looks like users paying a "VPN" provider in their local city. The provider gives them a shared public IPv4 address. All their devices use WireGuard to tunnel all traffic through the VPN. Incoming traffic sent to the user's domains (obviously requires coordination with a registrar) is routed by SNI. This setup has several benefits:
* All traffic outgoing goes through a VPN, preventing your ISP from snooping. VPNs are much more competitive than ISPs which makes them easier for me at least to trust.
* Since IPs are shared, users also benefit from "hiding in the crowd" for outgoing traffic.
* When hosting services, your actual IP is hidden.
* VPNs can compete on features like ability to handle DDoS attacks, auto LetsEncrypt support, domain registrar integration for auto DNS, etc.
[0]: caveat: I haven't played around with getting UDP to work.
- ranger_danger 4y ago>preventing your ISP from snooping You're really just shifting the trust to someone else. Someone who probably has a LOT more interesting data in one place that a nefarious party/advertiser/agency may be interested in collecting or observing, secretly or not. At least your ISP really doesn't care about your actual data, just that you're paying for service and not causing trouble. >users also benefit from "hiding in the crowd" IP addresses are not even really used anymore for fingerprinting. Your browser is a whole lot more unique in and of itself, regardless of the connection you're using, so it's more reliable to track that instead. It sounds like you're trying to advocate for using VPNs for anonymity, which is the wrong solution. I would argue large MPRs like Tor/I2P do a better job at this, but even that is only part of the solution.
- anderspitman 4y agoNote that I'm not a big proponent of current consumer VPN products. They're useful for some things, but I think people are generally confused about what those things are. But on a technical level, these companies are well-positioned to facilitate self-hosting. That's what I'm interested in. The egress benefits are fairly orthogonal to that as far as I'm concerned. That said, what makes you think ISPs are less incentivized than VPNs to sell your data? There are VPN companies that have "proven" in court that they are unable to provide logs of user activity. That earns way more of my trust than I'd give any ISP. > IP addresses are not even really used anymore for fingerprinting IPs are used by ISPs for issuing DMCA emails. > It sounds like you're trying to advocate for using VPNs for anonymity I'm not. It's all about what you're trying to hide from whom. True anonymity is extreme and comes at a high cost in terms of performance.