5 ms·
I can't speak for you, but it's really not too difficult to host some static content on a VPS. At the very worst, the VPS is compromised somehow, and you refres
by bArray 3y ago
I can't speak for you, but it's really not too difficult to host some static content on a VPS. At the very worst, the VPS is compromised somehow, and you refresh it from the admin panel.
- ChrisMarshallNY 3y agoI'm not talking about static content. I need the whole enchilada: DB, Web Server, Dynamic Languages, etc. Also, for a shipping, production application, with hundreds of users; where privacy and security are of paramount importance. It's easy, sure. It's easy to create an insecure server, that can be pwned. I know of which I speak. I have done just that. "A man who holds a cat by the tail, learns a lesson he can learn in no other way." - Mark Twain
- bArray 3y ago> I'm not talking about static content. I think the person in the original article was, at least for the sound file. > I need the whole enchilada: DB, Web Server, Dynamic Languages, etc. Also, for a shipping, production application, with hundreds of users; where privacy and security are of paramount importance. It seems quite simple to me, you either learn security, or pay for the expertise of someone that has. You need to decide whether it's worth your time. I would suggest one thing, though - even with the likes of <big cloud>, they will only provide security in limited cases, i.e. DDoS. Nobody at <big cloud> is going to make sure your application logic works correctly - they clearly won't even make sure you use their resources within sensible bounds.
- arandomusername 3y agoIt's easy to create a secure server. Use private keys. Use a firewall (ufw is really simple) and only expose your reverse proxy (e.g nginx or haproxy). Use docker to run your crap. Any software engineer should be well capable of setting up a secure server. It really is simple.
- bingo-bongo 3y agoRight up until someone runs a container with 8080:8080, which unfortunately bypasses ufw and the container is suddenly exposed to the entire internet .. :|
- Vuizur 3y agoReading the GitHub issue about this is somewhat entertaining: https://github.com/docker/for-linux/issues/690 https://github.com/docker/for-linux/issues/690 People are getting hacked a lot because of this, and docker doesn't seem to care all that much.
- bArray 3y agoOh man, that really sucks, to the point I would consider against using Docker for anything deployed. 5 years and such a basic security issue goes unfixed.
- JackSlateur 3y agoThe minute you implement a firewall, you failed Firewalls are made for two things: - packets alteration (iptable table mangle) - applying filtering on behalf of a badly configured OS So, if your case and if you want to prevent remote access to your database, you have a bad way: create a firewall rule to drop connections to tcp/3306 And you have a good way: configure your sql to bind to ::1 The firewall way requires two configuration (hence: complexity) and hide your intent : the mysql say : "I accept connections from everybody", and then the firewall say "I deny all connections". While the good way is clear and sane : one component who say : "I only accept connections from localhost"
- cpursley 3y agoNone of that stuff is “simple”. Git pushing and having Render.com auto deploy is, however.
- arandomusername 3y agoUsing private keys is not simple? sudo apt-get install ufw and ufw allow https is not simple? The whole process takes maybe 30-60 minutes to setup for someone completely new and following guides. Render's is simple, true, you just pay $300 for 1TB of bandwidth. It's crazy how much Merchants of Complexity fooled devs into thinking that running your own server is complicated and you need to pay 1000x to save few minutes of your time.
- hnben 3y agowould a cloud be securer though? I guess you gain some security, when you don't have to worry about some things. But you also lose some security, because of the added complexity.
- tonyhart7 3y agogood thing there are easypanel, flightcontrol or portainer etc that can make it easier to self host app these days sure it still needs work but much much less everyday
- krisoft 3y ago> A man who holds a cat by the tail, learns a lesson he can learn in no other way. What a silly quote. “No other way” except all the other ones. Everyone watching the man and the cat will learn the same lesson. Everyone who hears the story will learn the same lesson. I never held a cat by the tail, nor have i ever seen anyone foolish enough to attempt it, yet I am certain I know what happens next.
- currency 3y agoI think part of the point of the quote is that a man who would try to hold a cat by the tail is an example of someone who can ignore the experiences of other people. People FAFO when they should know better all the time.
- cpursley 3y agoYes, it’s actually a pain in the ass.