8 ms·
> So… practically: how to achieve this in 2022? I'll paraphrase myself from a few days ago[0]: The reality is that we've let you down. Self-hosting shouldn't
by anderspitman 4y ago
> So… practically: how to achieve this in 2022?
I'll paraphrase myself from a few days ago[0]:
The reality is that we've let you down. Self-hosting shouldn't be any more complicated or less secure than installing an app on your phone. You shouldn't need to understand DNS, TLS, NAT, HTTP, TCP, UDP, etc, etc. Domain names shouldn't be any more difficult to buy or use than phone numbers. Apps should be sandboxed in KVM/WHPX/HVP-accelerated virtual machines that run on Windows, Mac, and Linux and are secure-by-default. Tunneling out to the public internet should be a quick OAuth flow that lets you connect a given app to a specific subdomain, with TLS certs automatically obtained from Let's Encrypt and stored locally for end-to-end encryption.
The technology exists to do all of these things, but no one has taken the time to glue it all together in a truly good UX (we're working on it). Pretty much every solution in this space is targeted at the developer market, not self-hosters.
[0]: https://news.ycombinator.com/item?id=33098471 https://news.ycombinator.com/item?id=33098471
- sneak 4y agoAlmost no individual user has an internet connection that allows self-hosting.
- anderspitman 4y agoAre you referring to reachability or bandwidth? Reachability is solved by tunneling[0] and SNI routing. 1Mbps upload is plenty for many self-hosting uses. Or are you talking about something else? [0]: https://github.com/anderspitman/awesome-tunneling https://github.com/anderspitman/awesome-tunneling
- Rebelgecko 4y agoProbably TOS. My ISP provider technically bans running any type of server, but it hasn't been an issue for me.
- anderspitman 4y agoAh that makes more sense. Also very sad. Hopefully as fiber becomes more prevalent that will become less common.
- ulimn 4y agoOut of curiosity, if I may ask: where do you live? (Because I've never heard of such a thing.)
- Rebelgecko 4y agoLos Angeles, but I've had similar clauses everywhere I've lived and with multiple USPS (Starry, Charter, Time Warner, Verizon, university housing, etc)
- IggleSniggle 4y agoWhile my ISP, Comcast/Xfinity, does have a "Business Plan" that allows you to have a server, the normal residential plans prohibit it.
- mechanical_bear 4y agoI’m on comcast and self host. ¯\_(ツ)_/¯
- redavni 4y agoRealistically, anyone with an IP connection already self hosts a wide assortment of IP packets. As long as it isn't commercial or abusive, they are never going to know or care.
- sneak 4y agoThis is false. I got nastygrams from my residential ISP in the US accusing me of running servers because I rsynced 3TB of photos offsite as a backup. It was not a server, not commercial, and not abusive. I was threatened with disconnection.
- anderspitman 4y agoWow, that seems pretty extreme. What's your ISP?
- sneak 4y agoCox. I also pay extra each month for unlimited data transfer.
- dont__panic 4y agoWhat did you do to deal with those nastygrams? I'd probably try to feign ignorance, blame it on a computer virus or something, and avoid that kind of massive transfer in the future. I run my own server from home so I'm curious if I could get away with that, or if I should consider alternative solutions.
- sneak 4y ago3TB is not massive. I know professionals who shoot that much in a year; this was all my digital photos from 1997-2021.
- c_o_n_v_e_x 4y agoISPs don't like paying those data egress fees
- Havoc 4y agoThat's either one hell of a generalization or a USA specific thing. There are definitely some ISPs that don't prohibit it and even give you the tools for it - static IP, unlimited gigabit upload. I doubt mine would say anything even if I pushed 100TB a month through it. All their congestion issues are on download side thanks to residential traffic being mosty download (netflix etc).
- icedchai 4y agoI've had one at home for over 25 years. (Currently, I have to pay extra for a business cable connection, however!)
- arealaccount 4y agoISPs used to block port 80 and 443 but it seems they’ve relaxed that restriction for quite some time now. Maybe it’s regional.
- sneak 4y agoCox in Nevada just started blocking port 80 during the last year or two.
- kevin_thibedeau 4y agoEvery time a port is blocked an MBA gets his wings.
- anderspitman 4y agoIMO you should really be using tunneling anyway. I don't want anyone knowing my residential IP.
- dzikimarian 4y agoAll ISPs I had allowed it. UPC requires phone call, as by default they do CGNAT on their IPv6 configuration and need to switch you to IPv4 if you want incoming traffic. (if someone can explain what's the reason behind such approach, I would be thankful).
- sitzkrieg 4y agoits a lot easier to buy domains than phone numbers sadly
- anderspitman 4y agoTechnically true, but you have to create an account with a company that is targeted at very technical customers. And using them requires understanding DNS, which is an insane prerequisite. We need a consumer domain registrar.
- WanderPanda 4y agoI just saw that icloud.com has a domain registrar built in (for receiving emails) I would say that is as "consumer" as it gets, no?
- anderspitman 4y agoThat's good, but should every service have to implement their own registrar? We don't all have the resources of Apple. Plus, what if you want to host other services on subdomains? Even if you can manually set DNS records, you shouldn't have to. I should be able to use the registrar of my choice, and icloud should use an OAuth flow for me to approve them having control over a subdomain, and they make changes via a standardized protocol. There's some previous work in this space and I've also dabbled myself[0]. [0]: https://takingnames.io/blog/introducing-takingnames-io https://takingnames.io/blog/introducing-takingnames-io
- TrevorJ 4y agoYou mentioned phones, which reminds me how much I wish there was a nice toolchain that would allow for hosting a webserver or maybe a federated social network of some sort on old android hardware. There are millions of old smartphones sitting in junk drawers and it's a shame they can't be put to good use.
- anderspitman 4y agoI've done some work on this. Android is a very toxic environment for this sort of thing, primarily due to draconian filesystem permissions and aggressive killing of services. It's all in the name of security and battery life, but I wish there were an easy way to turn that all off for selfhosting. I've also seen people mention that apparently the flash memory doesn't do well with server type workloads, but a lot of that could probably be mitigated with logging to RAM, using a CDN, etc.
- _carbyau_ 4y agoWhat I want: 1. GP quote: "Domain names shouldn't be any more difficult to buy or use than phone numbers." 2. Your quote: "federated social network of some sort on old android hardware." Put 1 and 2 together. The only reason Facebook exists is as a middleman between people trying to pass messages to each other. If people could easily find each other and run trusted non-proprietary software: A. there'd be no ads B. all comms are direct so government agencies couldn't simply compel access from a single source
- anderspitman 4y agoThe tricky part is people have to be willing to pay for the plumbing in this case. I think that paradigm shift can take place, but we have to show them why it's worth it first, which is difficult due to network effects.
- _carbyau_ 4y agoGoogle could setup a domain and simply provide people freely with "[usersPublicKey].domain" subdomains updated by users with a dynamic dns client. Even if this were a google special DNS service not part of the global DNS this could work. Google could also then provide a messaging app to use this service but if some other open source app were to become the defacto and make facebook irrelevant that is still a big win for google. Advertising $$ with one less big competitor. If Google marketed this correctly then they could be seen as a champion of privacy too.
- Melatonic 4y agoI would not be too hard to use a Cloudflare Tunnel (free) or NoIP or similar. Really depends on what you want to host exactly though.
- anderspitman 4y agoCloudflare Tunnel solves part of the problem, but not nearly all of it. Plus it's targeted towards developers and operates as a loss-leader product. But I think a company that's similar in a lot of technical ways to Cloudflare but targeted towards self-hosters instead of developers could be successful.
- ocdtrekkie 4y agoSandstorm.io glued this all together in 2014 and it's still available today. https://sandstorm.io https://sandstorm.io
- anderspitman 4y agoSandstorm is awesome, and still way too hard for my dad to use.
- ocdtrekkie 4y agoWe have some ideas where to go on that, in general and especially for setup, though I am generally in favor of small community hosts, such that your dad should be able to use your server, instead of having to run his own.
- anderspitman 4y agoI do like the federated approach for many services, but for many others I think it should be individual. Sandstorm needs to run on Windows and Android, and support tunneling for those behind CGNAT et al.
- ocdtrekkie 4y agoCGNAT is definitely a scary thing I don't presently have to deal with, but yeah, ideally Sandstorm should get some sort of solution for it, yeah. I think it's important for self hosting solutions to not run Android or Windows: People tend to take those platforms out and about. But obviously the x86 server requirement is (currently) a big limitation for sure.
- anderspitman 4y ago> I think it's important for self hosting solutions to not run Android or Windows Not sure I follow. Those are the two most widely deployed operating systems. If you want people to be able to upcycle their old devices for selfhosting, I think that's where efforts should be focused.
- Tepix 4y agoIf you go the IPv6-only route it can still be very simple. Also if you buy a device such as a NAS, it often comes with its own webserver. On the other hand, i would strongly advise anyone not to expose a NAS to the internet...
- anderspitman 4y agoWith IPv6 the user still has to understand firewalls, and IPv6...