15 ms·
Tech Independence
- znpy 3y agoTech independence… then uses a third party service for outgoing email. Smh.
- neilv 3y agoThere are good reasons to use a third-party mail server, IMHO. (I recently made that decision again.) But the reader should be aware that these writeups of how to do X often involve the writer/publisher getting referral kickbacks from the commercial service they're describing. I'm about to be in a position of doing something like those writeups, as a microstartup, and I'm not entirely comfortable with the affiliate programs. But the companies monetizing with privacy-invading ubiquitous profiling trackers (sometimes euphemistically called "showing ads" and "analytics"), and otherwise selling personal data, have spoiled most potential willingness of readers to pay for content. So, affiliate programs with an obvious potential conflict of interest is the only way I've thought of to fund the work.
- alabhyajindal 3y agoI have been following Derek for a long time and know that he is not doing this for profit. More info if interested: https://sive.rs/trust https://sive.rs/trust
- neilv 3y agoAs in my case, there's a potential conflict of interest with the affiliate programs. In his case, he has an interest in funding the trust for charitable purposes and maybe for his 5% drawdown.
- gsuuon 3y agoI was going to mention this almost sounds like a vultr ad, but woah that's a really clever way to go about selling a company.
- macNchz 3y agoDeliverability from a cloud host IP is not going to be good.
- boomskats 3y agoCan you even host your own SMTP server in 2023 without it being shadow-blocklisted by default? What's your experience?
- johnea 3y agoYes, you can do it!
- wejn 3y agoYup. Been running my own for past two decades, still works.
- morjom 3y agoProbably the reason its working is because its been running for two decades.
- baz00 3y agoIt's fine until Yahoo hellbans you with no recourse for 6 months after sending you a cryptic message in an SMTP response to visit a form and fill it in which you do to the best of your ability. Oh and inevitably there's always someone you need to email on Yahoo.
- api 3y agoTrue but at this point if you don’t do that most e-mail servers will reject you. Spam pretty much destroyed e-mail as an actually open protocol. Spam destroys all open systems.
- jehb 3y agoIs this really the issue that it used to be, though? I'm curious if I'm the only person who just doesn't send email much anymore in my personal life. Yes, I get a lot of email. But it's almost all transactional or subscription. The number of emails I send or receive with other humans is pretty dang low. Most institutions these days require using their platform for communications. Most people I care about who I communicate with electronically I do over SMS or Signal or occasionally a Mastodon message. I still own the domain, so I could easily pick up up and move to a different mail service in probably just several minutes of setting up an account and changing some DNS values. So while not fully independent, the time spent getting outbound email right is going to have less impact than other changes I could make.
- zrail 3y agoYou're still independent of any given service. Outgoing mail is effectively stateless at this scale so the cost to switch to a different one us ~zero.
- sivers 3y agoMy previous version of https://sive.rs/ti https://sive.rs/ti (until a few hours ago) used the built-in OpenSMTPD server for outgoing email. But then Vultr.com is not un-blocking port 25 by request anymore. That's why I had to switch to a SMTP service.
- deleted 3y ago[deleted]
- december456 3y agoTeaching newbies 'independence' by downloading random untrusted files off the internet and running them as system admin...not a cool guide i would say.
- boomskats 3y agoThat derek.jpg sure looks shady.
- tkiolp4 3y agoC’mon. The scripts are public, you can inspect them before running them. The other alternative is to explain line by line the hundreds of lines in the scripts. Not very practical.
- december456 3y agoWhile i agree, the issue is the target audience. If this was directed at more technical and knowledgeable tech-savvy people one-upping their game, i would be very glad and thankful for a shell script. However, its not. Its a potential starting point for being, in cool nerd terms, webmaster, and that has its own set of responsibilites and habits, habits like not downloading files and packages without checking first. While some might change the habit after learning more, i doubt that many will do that.
- kopos 3y agoIf we don’t want to call the HN crowd non-technical
- sivers 3y agoMy previous version of https://sive.rs/ti https://sive.rs/ti (until a few hours ago) had no shell script, but just walked people through every step. It took like 50+ hours to write up. But so many people were getting stuck and frustrated trying to type in all those commands, (and mistaking "l" for "1" and such), that I realized I could help more people have their own server if I put most of those steps into a shell script. Hopefully it'll be enough to give them a taste of the benefits of having their own server, then they can learn more about the steps afterwards.
- johnea 3y agoI do agree that it's not exactly "self hosting" when you use vultr.com Once you've gone to all the other trouble, pay a little extra to the ISP for a static IP, and then any computer is your own "cloud"...
- nik282000 3y agoDepending on your setup you can use dynamic DNS and save yourself the cost of the static IP. Either way it will always be cheaper per GB of storage to host at home than in 'the cloud.'
- reidjs 3y agoI've read that this is potentially dangerous as you are opening up your home network to the Internet, is there any truth behind that?
- Tcepsa 3y agoYes, I believe that's correct. If any of the services that you are opening/exposing in this way contain vulnerabilities, those could be exploited to gain unauthorized access to the hosting machine. Attackers could then use the compromised machine as a staging area to launch attacks against other systems on your home network. Putting the hosted machine in a separate VLAN (like a guest network) can mitigate that, but it means you have to do that configuration correctly. (I am not confident enough in my own abilities/knowledge with respect to these vulnerabilities to try it, and so it may turn out to be very straightforward. I hope to do something along those lines someday but so far the risk has outweighed the reward for me.)
- iksm 3y agoVLAN is not intended to be used like that. You want to rely on a trusted firewall you own, with separate interfaces and appropriate firewalling rules. This can provide an isolation between networks. Behind this, any pirated server could decide to send VLAN tagged packets that may go trough the firewall if the rules are bad, or read any of them arriving to it. VLAN's are useful if you want to "tag" packets with ID's going trough specific interfaces for segmentation purposes. The tag is applied from the interface standpoint, so this gives a virtual segmentation between ports of machines you are supposed to always control, like between a port on your router and ports on a managed switch. In this case VLAN's are configured on the router's interface and the switch interfaces, but the exposed server is not aware about it, and can't change it, so you can know the ID is right. This is often believed this is required to isolate networks, this is wrong, you just need to have separate interfaces.
- baz00 3y agoRelying on your cloud provider's backup / restore solution is not a backup.
- chillbill 3y agoI'm all for tech independence. But if you need to be spoon-fed the instructions like this and you don't get what most of it is doing, YOU DON'T WANT TO DO THIS. Best case scenario you'll get locked out of your own stuff or important information. Yes, you should strive for that, and you start by learning. Contrary to popular belief, you don't need to be a linux ninja to be able to host your own website and calendar. The stuff mentioned in this article are the bare minimum, and you should want to do it yourself without being spoon fed the steps. With that aside, this is exactly the kind of guide I would expect a three-letter agency contractor or worker to spread in order to "help you" stay off the grid, then unceremoniously drop a disaster on your head.
- iksm 3y agoTotally agree. Better look for local associations that provides hosting services if you don't have any system administration knowledge. They'll help you more, and you'll waste less time and probably money, plus they may help you physically setting up your devices correctly with your services hosted on their servers. I mean, yeah it's a minimal step by step guide that just feel to be the poster's own todo list... As there's many like that. To get some entry-point information this is great but this is far from being useful in practice. Basically it hides everything useful to know behind a big script that the intended reader is not even supposed to understand. I did not have seen any protection for what's come from WAN, not even basic logging, investigation nor debugging methodology. No real backup methodology as well and the guide seems to not take system upgrades very seriously by saying "oh, it could run so for decades, but if you want you can do system upgrades". This is obviously false to any expert and a very risky approach. This is not how we are supposed to teach internet-connected services self-hosting.
- comte7092 3y agoPartially agree. A guide like this helps combat the potential overwhelm of feeing like you still have too much to learn/can’t possibly get started.
- chillbill 3y ago[dead]
- harryvederci 3y agoIgnore the snarky comments, this is a good initiative. Respect.
- deleted 3y ago[deleted]
- iksm 3y agoIndeed, it is a good initiative. And that may be useful. Keep in mind that there's many people self-hosting and exposing services to WAN that ends as spamboxes or worse from misconfigured bits. The thing is non-techy people would setup such thing and get it running, but have no technical way to maintain it. It's a flying plane in automatic mode with no competent pilot inside.
- alabhyajindal 3y agoI love this article. The section 'More Indie Tips' is great, especially if you don't plan to follow the guide: https://sive.rs/ti#indie https://sive.rs/ti#indie
- koch 3y agoI really can't believe there doesn't exist a good "home box." There should be a product that you can buy (a computer) that you bring home, plug in, set up via your phone or computer that: - can host websites - can store your files and sync them to other devices - control your home automation - host your email - anything else you might otherwise put on a server And does it all EASILY with a simple phone or web UI. Yes I know you can actually buy a computer or server or raspberry pi and put something like NextCloud or Home Assistant et al. on it, but the real barrier imo is the setup and configuration. Even I don't do all this because it seems daunting to configure all of it, and I consider myself a pretty technical person. I really just want to buy a box, plug it in, and like select which apps I want to use, and then it starts working for me.
- New_California 3y agoBut there is: https://umbrel.com/ https://umbrel.com/ (except for hosting email which is not realistic anymore).
- koch 3y agoThis looks about like what I want! I may give it a go...
- infogulch 3y agoLooks nice, but the marketing design ('make it just like Apple') doesn't match the product they're selling. Apple is technology for people afraid of technology, but self hosting is decidedly not for a technologically afraid audience. How will they pay for maintaining all the apps and making sure that they are properly integrated into the platform as they get updated?
- alabhyajindal 3y agoExactly. That would be great. But I think a large portion of the target audience of the home box would rather set this up themselves. Or not. I would much rather have something commercial (built on open source) like this so I can be more at ease that my data is safe, compared to doing everything myself.
- ojbyrne 3y agoMinor quibble/correction request - the FreeFileSync section (Windows specific) includes some Mac-specific instructions in Step 8.
- apitman 3y agoThe author talked about this a few months ago on Tim Ferriss' podcast[0]. One of my favorite episodes. I'm passionate[1] about the concept but articles like this are a reminder to me that we need to make self hosting an order of magnitude simpler and accessible to more people. It shouldn't need to involve any CLI, DNS, TLS certs, port forwarding/NAT traversal, IP addresses, etc etc. Self hosting shouldn't be any more difficult or less secure than installing an app on your phone. The flow should be 1) install the "self hosting app" on an old laptop or phone. 2) Go through a quick OAuth2 flow to connect your app to a tunnel that enables inbound traffic. 3) Use the self hosting app to install other apps like Jellyfin, Calendar, Nextcloud, etc. Everything should be sandboxed (containers work pretty well on Linux and Windows 10/11 via WSL2) and secure by default. Automatic backups (ideally an OAuth2 flow to your friends' self hosted installations) and auto app updates are table stakes. There's no technical reason this can't all be done, but lots of technical challenges, and it's unclear whether anyone will pay for tunnels. I'm currently trying to figure out how to do reliable auto backups without filesystem snapshots. [0]: https://youtu.be/0BaDQCjqUHU?si=0wDf-2RH-u9vdm3g&t=1380 https://youtu.be/0BaDQCjqUHU?si=0wDf-2RH-u9vdm3g&t=1380 [1]: https://github.com/anderspitman/awesome-tunneling https://github.com/anderspitman/awesome-tunneling
- lifty 3y agoI agree. I think people have just been used to the current state of affairs in managing servers. There’s no reason why they can’t be like appliances or mobile OSes.
- wildrhythms 3y agoThe problem is eventually this 'appliance' needs to connect to the public WWW and that is a problem for most residential connections because ISPs don't play nice with that sort of thing, at least in the U.S., and now you get into having to configure port forwarding and dynamic DNS and so on.
- anderspitman 3y agoTunneling solves the ISP problem and the complexity problem of handling inbound connections. It also has some nice security benefits
- akavel 3y agoFWIW, I recently found a VPS offering for $1.41/month (!) @ 1.5GB RAM & 30GB HDD via https://lowendbox.com/ https://lowendbox.com/, at https://my.racknerd.com/index.php?rp=/store/black-friday-2022 https://my.racknerd.com/index.php?rp=/store/black-friday-202... (please note I have no idea how reliable it is though!). I managed to deploy NixOS there through nixos-infect (https://github.com/elitak/nixos-infect https://github.com/elitak/nixos-infect), and then further configure it with NixOps. That said, using NixOps does currently require a Linux (or Mac, probably) box as the managing one, and some Nix-fu, which is definitely non-trivial. A draft (WIP) writeup on that, if you're interested: https://github.com/akavel/scribbles/blob/main/_drafts/20230830-%40nixops-howto.%40flakes.md https://github.com/akavel/scribbles/blob/main/_drafts/202308...
- ChrisArchitect 3y agoThis is posted every month for months and months --- anything new here?
- rhapsodic 3y ago[dead]
- deleted 3y ago[deleted]
- nyanpasu64 3y agoWould it be practical to use mesh networking (eg. Hyperboria, https://changelog.complete.org/archives/10478-easily-accessing-all-your-stuff-with-a-zero-trust-mesh-vpn https://changelog.complete.org/archives/10478-easily-accessi...) to access your machines from remotely using their public key rather than a domain name you have to pay for and renew?
- kartoshechka 3y agogreat post! I'd like to mention one more "indie" tip - physical security key is nice to have (2 even better) if you plan to lose/break your phone, or travel frequently. Add the most important auth keys (bank, email, etc) directly to the physical key, back them up on the second one, and now you're less "working smartphone with an active sim" dependent :)
- dusted 3y agoI upvoted this before realizing it's a just a plug for some stuff, "porkbun", "vultr", "freefilesync" and some app called "davx" yeah, no, just by the amount of stuff you need to sign up to outside of the base BSD system, this is not tech independence.
- DANmode 3y agoDomain registrar, webhost, and two widely trusted FOSS WebDAV/CardDAV clients. Nothing to be afraid of, here, that I can see.
- dusted 3y agoThe article starts with independence, and the first thing they instruct people in is becoming dependent on un-required third parties. Sure, becoming a registrar is overkill, but hosting a website on your own machine is a pretty low bar.
- 0pteron 3y agoAll good until Vultr or any of the services you rely on have to do maintenance (guaranteed to happen at least once in my 10+ years of VPS hosting) or even worse, one of the services loses data (Never happened to me, but I've seen it). I just want to throw out buyvm.net as a block storage alternative. Not as big as vultr but super reliable and affordable, they have a discord and the owner is great