7 ms·
Knocker, a knock based access control system for your homelab
- kazinator 1y agoIt has sequence diagrams so it must be a good idea.
- myzek 1y agoI don't want to be a hater, but exposing access to your homelab through a "fully vibe coded" application (it's mentioned at the bottom of the README) is probably not a good idea. The idea itself sounds fun though
- sandblast 1y agoI guess I have to implement the habit of checking such things, since I never assume such a possibility. I prefer this info to be at the top of the readme, though – much more information value than the logo that deceived me into thinking this is a mature project. Regardless; what benefits this would have over Wireguard?
- gregoriol 1y agoGithub should have a tag about it on projects
- dugite-code 1y agoPerhaps not requiring a wireguard client installed on the machine you are accessing from. There are several circumstances where installing a VPN client isn't possible or practical
- jamesbelchamber 1y agoI guess at least they're being honest, but I would agree - there's a large delta between Al-assistance and Al-driven, and "vibe coding" is one step further (just accepting everything Al does without critique, so long as it "works"). Great for prototyping, really bad for exposing anything of any value to the internet. (Not Anti-Al, just pro-sensible)
- nextlevelwizard 1y agoGithub should have "LLM" as language for repos that self report to be vibe coded or at least this kind of disclosure should be at the top of the readme not after thought. Also the "If you're Anti-AI please don't use this." is pretty funny :D I guess I must be "Anti-AI" when I think this kind of code is wild to rely on.
- Eisenstein 1y agoI fully support the AI self-disclosure, but what I wonder what it is about AI generated code that makes this a separate problem from any other code where you don't know the programmer's competence? Is it because the AI can generate code that looks like it was made by a competent programmer, and is therefore deceiving you? But whatever the reason, I think that if we use it as a way to shame the people who do tell us then we can be assured that willingness to disclose it going forward will be pretty abysmal.
- fukka42 1y ago[dead]
- muvlon 1y agoI think it makes sense for stuff that is fully AI generated to the point where you commit the prompts to git. At that point, they become the real "source code" and the generated code is more of a build artifact. It makes sense to tag the language as "LLM" instead of e.g. "Python" because that's what contributors will be expected to touch when interacting with the codebase.
- GuinansEyebrows 1y agothere is a non-zero chance that the human programmer has an interest in producing correct, secure code. there is zero chance than an LLM has the same interest. maybe those two are closer together in some cases, but not in many others.
- nextlevelwizard 11mo ago
- V__ 1y ago> If you're Anti-AI please don't use this. I'm pro security. The gall to put something out there, pretend it being vibe coded is not a big deal and possibly exposing hundreds of people to security issues. Jesus.
- fariszr 1y agoI mean you are free to not use it, it's for personal use. I was annoyed by all the vpn based solutions and built knocker to have something that works without installing it on each and every device.
- sanex 1y agoIt's open source. Audit it like you would any other service that exposed your homelab to the Internet. How do you know XYZ repo isn't coded for some bootcampers capstone project? I bet those are even less secure. Edit: should have mentioned I am a bootcamp grad, not just throwing random shade.
- QuantumNomad_ 1y ago> How do you know XYZ repo isn't coded for some bootcampers capstone project? I gate access to my homelab using Wireguard. Wireguard is widely deployed across the world, and has been worked on for years. No random new repo that was vibe coded can measure up in the slightest to that.
- OrderlyTiamat 1y agoIf I had to audit security services for exposing homelab to the internet, I wouldn't use those services in the first place. I'm fine trying things out, but this is a very important security boundary, and it's a solved problem. Why risk it with an auditor who does it for a hobby (me)?
- dawnerd 1y agoIt’s getting scary how many security related apps are being vibe coded by people with very little security experience (not a knock heh on op, they could very well be experienced).
- muppetman 1y agoSuggesting people don't shoot themselves with a loaded gun is not being a hater, it's being a good person.
- fariszr 1y agoI mean it's just using firewalld. You can't inspect the rules. For me it's simple enough that it shouldn't be a big security issue, but I understand and that's why I wrote that in the readme.
- mano78 1y agoI implemented something similar as a caddy module, then I realized that if I was connected to a public wifi network I was actually authorizing the whole bunch of people that were connected to it with me. How do you avoid this, or is it just not important?
- deleted 1y ago[deleted]
- OJFord 1y agoIt shouldn't be your only layer of security, and then it's not important. Think of it as replacing explicit IP black/whitelisting - you still want a login wall or something, but now you restrict access to guess logins or otherwise obtain access through app vulnerabilities etc.
- teddyh 1y agoIt’s the third option: Port knocking is stupid. <https://news.ycombinator.com/item?id=39898061 https://news.ycombinator.com/item?id=39898061>
- symbogra 1y agoI implemented port knocking couple decades ago as a teenager and it was stupid then too.
- TuxPowered 1y ago> How do you avoid this IPv6 of course. > or is it just not important Port knocking not a security feature anyway.
- fariszr 1y agoIt's a compromise.It's not as secure as using a VPN, but it's way more convenient, since only one device has to have a knocker client on it without needing any sort of VPN. The likelihood of someone is on the same network as you noticing your servic, try to hack it, before the TTL expires again is IMO quite low. This is without taking into account that the services themselves have their own security and login processes, getting a port open doesn't mean the service is hacked.
- eastabrooka 1y agoIts 2025, Just use Tailscale.
- lucideer 1y agoIf you're running a homelab, the likelihood that you're interested in removing cloud-dependencies from your stack is above average. If that's the case, Tailscale is out. Tailscale is just an added unnecessary external dependency layer (& security attack surface) on top of vanilla Wireguard. And in 2025 it's easier to run vanilla Wireguard than it's ever been.
- aspenmayer 1y agoAlso, Headscale exists.
- lucideer 1y agoI haven't tried Headscale but isn't it more complicated than Wireguard? The selling point of Tailscale is that they simplify Wireguard UX by adding a proprietary control server - this adds complexity to the stack (extra component) but simplifies user experience (Tailscale run the control server for you). Headscale seems like it's complicating the stack (adding an extra component) as well as complicating the user experience (you have to maintain two components yourself now instead of just the one Wireguard instance). Granted I presume the Headscale control server might simplify management of your Wireguard instance but... you're still maintaining the control server yourself.
- aspenmayer 1y agoIt likely does add some complexity, though it’s relative. Self-hosting is always going to have some overhead. Managing WireGuard servers and clients and associated keys etc is probably the part that is most annoying, so I can see how it might be easier to throw that over the fence to Headscale even though it is introducing another dependency. I was speaking more to doing it all in-house, versus outsourcing things to Tailscale, a third party not fully under one’s control, even if they act of behalf of the user. I think I largely agree with what you said.
- lucideer 1y ago> This is ideal for homelab environments where you want to expose services to the internet without a persistent VPN connection, while minimizing your public-facing attack surface. To an untrained eye, the wording here could be construed to imply that this is more secure than a VPN. Might be worth a reword to clarify why one might prefer it want to over a VPN.
- fariszr 1y agoSorry if i wasn't clear. It isn't more secure, it's just more convenient because it works in every network, without needing to set up a VPN connection on each device. I created this because I always have a VPN on my devices, and I can't have tailscale running with that, in addition to tailscale killing my battery life on android.
- yaris 1y agoThe authentication part does not look much different from password authentication (key ≈ password), and the "Configurable TTL" bit is somewhat confusing, the first part of the sentence assigns the TTL to API keys but the second part says it applies to IPs being whitelisted. I would expect that TTL for a key means that after the TTL expires the key itself becomes unusable.
- fariszr 1y agoThe TTL is for the whitelist. The whitelist rules aren't permanent.
- TZubiri 1y agoPort knocking is a very hacky technique that was used: 1- In the 90s were security was whatever 2- In modern days as a way to keep your logs squeaky clean ( although you get 99% there with custom ports) 3- As a cute warm up exercise that you code yourself with what's available in your system. (iptables? a couple of python scripts communicating with each other?) It's not a security mechanism, and downloading external dependencies or code (especially if vibecoded) is a net loss (by a huge margin). It's also a waste of time to overengineer for the reasons noted above, I've seen supposedly encrypted port knocking implementations. It feels as if someone had a security checklist and then a checklist for that checklist.
- imiric 1y agoThere's nothing "hacky" about port knocking. It was never meant to be a complete security solution—nothing is. But it works very well as an additional layer of security. Sec nerds often scoff at "security through obscurity", but it is a very valid strategy. Running sshd on a random high port is not inherently more secure, but it avoids the vast majority of dumb scanners that spam port 22, which is why all my systems do that. Camouflage is underrated, yet wildly effective. You can see how well it works in nature. In any case, this is not a port knocking solution anyway, as I mentioned in another comment.
- frumplestlatz 1y agoIt’s really, really not a valid strategy for anything. Just put your services behind WireGuard.
- abujazar 1y agoNowadays public facing client IPs are often shared by thousands of users behind CGNAT. IP based firewall rules are useful when the peers have their own static IP address, but provide no real security when the IP address is shared. This is vibe coded security through obscurity, i. e. quite useless. Use Tailscale or a self hosted VPN.
- nextlevelwizard 1y agoIt could be fun extra layer. Like of course you should always use VPN, but maybe a magic packet so your VPN server even opens a port could be fun.
- imiric 1y agoNeat project, thanks for sharing. I'll stay away since it was vibecoded, but I appreciate the honesty. Though this is not technically a "knocker", but a typical token-based auth gateway. I experimented with something similar recently as well, and think it has its use cases. But I would agree with some of the comments here. If you need to expose many services to the internet, especially if their protocols are not encrypted, then a tunneling/mesh/overlay network would be a better solution. I was a happy tinc user for several years, and WireGuard now fills that purpose well. As much as people use solutions like Tailscale, ZeroTier, etc., I personally don't trust them, and would prefer to roll my own with WG. It's not that difficult anyway. There's also Teleport, which is more of an identity-aware proxy, and it worked well last time I tried it, but I wouldn't use it for personal use.
- Halan 1y agoIP based exclusion should not be considered a security measure, not even for a low risk environment like a home lab
- password4321 1y ago> IP based exclusion should not be considered a security measure Apologies in advance if I'm missing something obvious here, but are you saying an IP allow list is not a standard security practice? If so I'd appreciate further explanation.
- abujazar 1y agoIt's useful when the client always has its own static IP that _doesn't change_ between sessions. In this case, where the public facing IP may be shared by thousands of users, it provides no real security. All you'd have to do to gain access would be getting the client IP and finding some way of getting on the same network. Which in many cases could be as easy as subscribing to the same cell network or other ISP, or connecting to the guest wifi network of an office building.
- password4321 1y agoThanks for filling in the details. I agree that an IP allow list works best for users who are alone on an IP that doesn't change often, which is the case for a majority of home internet users but not when they're away from home.
- yccs27 1y agoUnfortunately there's an increasing number of home internet connections behind CGNat, as IPv4 adresses run out (and IPv6 doesn't gain momentum, heaven knows why)
- abujazar 1y agoI guess it's partially because ISPs are perfectly happy selling crippled internet connectivity as the base service and charging hefty premiums for "luxuries" like static IPs. It has also become common to only offer static IPs to business customers.
- felixandersen 1y ago[dead]
- ohyoutravel 1y agoMore adoption and proliferation of vibe coded apps like yours and the OPs is going to end up being a major disaster. I find it strange for you to say you “released” this when, in the modern era, what you linked is the equivalent of a pastebin bash script. In your case, it looks like ChatGPT has barfed more lines of readme than lines of code!
- felixandersen 1y agoI'm sorry it didn't resonate with you. The accusation of vibe coding is a bit discouraging, but I don't feel the need to prove anything. I built this in my spare time and shared it in case it's useful to others. Some of the most helpful code I've used in my career started out as quick scripts or pastebin snippets. Yes, I used AI to help with the documentation, but I also put in time to edit it and make sure it clearly explains the concept.
- scottydelta 1y agoWhen every problem seems like a nail then every solution you come up with is a hammer. This is what it feels like people using AI for everything. AI is not good at telling you best solution but it will tell you that you can build it yourself since that approach is what AI is good at. Using self hosted vpn, cloudflare zero trust or Tailscale is the easiest way to go. I self host extensively and have multiple self hosted VPN(OpenVPN and WireGuard) along with Tailscale and cloudflare protecting my infra.
- OutOfHere 1y agoIf you're getting people to rely on external dependency services, e.g. Cloudflare or Tailscale, then you're a part of the problem, not the solution!
- fariszr 1y agoTailscale is not as easy as this. It has to be installed on every device or at the router level. And it will not work on mobile if you already use another VPN.
- foofoo12 1y agoAlso FWIW, if you're using nftables you can set up port knocking: https://wiki.nftables.org/wiki-nftables/index.php/Port_knocking_example https://wiki.nftables.org/wiki-nftables/index.php/Port_knock...
- giantg2 1y agoAw man, I thought this was going to be audio sensor that logs you in with a secret physical knocking pattern (like on a door or desk).
- jedimastert 1y agoThat's what I thought was well, like a Morse code detector tied to the lock on the door or something lol
- luc_ 1y agoMaybe I'll vibecode that this weekend...
- lugarlugarlugar 1y agohttps://www.youtube.com/watch?v=zE5PGeh2K9k&list=PL6AGg52_GzItFC7JxanHmHbCzX-aq_8wq https://www.youtube.com/watch?v=zE5PGeh2K9k&list=PL6AGg52_Gz...
- WJW 1y agoI had hoped this would allow me to use various patterns of knocking on my desk to perform system actions. Do the cut-and-a-hair-shave knock to log in, or taptaptaptap-wait-tap to lock the screen, etc. Maybe with two microphones you could even distinguish between left and right handed knocks. ...now I'll have to make this myself.
- spicybright 1y agoI was thinking exactly the same thing. Or maybe a knock on the door before you enter to set stuff in your room to a certain state.
- Dilettante_ 1y ago>Cut-and-a-hair-shave knock TIL that that has a name.[1] All I ever knew it as was "the knock from Roger Rabbit". [1]https://en.wikipedia.org/wiki/Shave_and_a_Haircut https://en.wikipedia.org/wiki/Shave_and_a_Haircut
- dugite-code 1y agoI use fwknop in a similar manner, the main advantage it has is it's using an encrypted UDP packet. It's ability to call shell scripts for more advanced uses is its best feature. I have a packet set up for a rolling restart of all my services as well as ssh access
- sneak 1y agoI use this thing called sshd that listens on only a single port and its main advantage is that it uses actual cryptography to authenticate using a client keypair.
- dugite-code 1y agoFwknop uses HMAC keys so quite good crypto by itself, but it's for single shot commands. Good for keeping the ssh port locked until you actually need it. I use it on top of SSH key pairs as part of my layered security, Just as any good access control strategy should.
- RickJWagner 1y agoSomebody must tell Mel Brooks about this.
- SoftTalker 1y agoYeah the urge to post a "What Knockers!" Gene Wilder gif is strong. Good thing HN doesn't allow that.
- tptacek 1y agoI will never, ever understand this "single-packet authentication" "port knocking" fetish. It has never made sense. Bin it, along with fail2ban, and just set up WireGuard. Your network authentication should not be a fun game or series of Rube Goldberg contraptions.
- mdhb 1y agoI mostly agree.. there’s a couple of very specific scenarios where maybe something like knockd makes sense I think but they are all scenarios where you’re doing things covertly, not as a general authentication mechanism. As a side note I just happen to be reading a book at the moment that contains a fairly detailed walkthrough of the procedure required to access the Russian SVRs headquarters in New York in 1995. Think of this as an analogue version and in no way a perfect analogy but it does include a step that has more or less the same security properties as this… anyways here’s a relevant quote: “After an SVR officer passed through various checkpoints in the mission’s lower floors, he would take an elevator or stairs to an eighth-floor lobby that had two steel doors. Neither had any identifying signs. One was used by the SVR, the other by the GRU. The SVR’s door had a brass plate and knob, but there was no keyhole. To open the door, the head of the screw in the lower right corner of the brass plate had to be touched with a metal object, such as a wedding ring or a coin. The metal would connect the screw to the brass plate, completing an electrical circuit that would snap open the door’s bolt lock and sometimes shock the person holding the coin.The door opened into a small cloakroom. No jackets or suit coats were allowed inside the rezidentura because they could be used to conceal documents and hide miniature cameras. SVR officers left their coats, cell phones, portable computers, and all other electronic devices in lockers. A camera videotaped everyone who entered the cloakroom. It was added after several officers discovered someone had stolen money from wallets left in jackets. Another solid steel door with a numeric lock that required a four-digit code to open led from the cloakroom into the rezidentura. A male secretary sat near the door and kept track of who entered, exited, and at what times. A hallway to the left led to the main corridor, which was ninety feet long and had offices along either side. ” Excerpt from Comrade J by Pete Earley As another funny side note… I once discovered years ago that the North Koreans had a facility like this that they used to run a bunch of financing intelligence operations using drugs in Singapore where I was at the time and thought it would be funny to go and visit. It was in a business complex rather than a dedicated diplomatic facility from memory. But as I recall it was a similar scenario of unmarked door with no keyhole.
- mondainx 1y agoSorry, but I felt a bit of nostalgia here; I wrote some port knocking code a couple decades ago, this is straight-up "neat" and I'm surprised it is still around.
- trashb 1y agoThe way I see it, port knocking may not be a valid security measure but it can be a good filter. It will allow you to filter out port scanning and other mass cracking attempts. My opinion is that being able to filter out noise and false positives from authentication logs allows you to improve your actual security measures. An other advantage is that it may hide information about your system making it harder for an attacker to target you based on a broad scan without doing some (usually detectable) targeted reconnaissance first. For example imagine someone found a 0-day in one of the services behind the port-knock and is scanning for the vulnerable version. It does however add another cog in the machine that may break.
- deleted 1y ago[deleted]
- aborsy 1y agoWireguard port is the only port that could be exposed to the Internet. With xz backdoor owning ssh, I wouldn’t completely trust ssh public key authentication either.
- parliament32 1y agoThe "port knocking" has surfaced often since the early 2000s, but it continues to be a rather silly exercise in making security-by-obscurity look more complicated while not really helping all that much. Briefly looking at the diagram at the top of the repo, it looks like you "knock" with an API key. Why not just run a reverse proxy in front of (whatever service you're trying to protect) and use the API keys there? To harden further, do some sort of real authentication (PKI, client certs). If you want your logs to look cleaner, install and actually configure fail2ban.
- fariszr 1y ago> Why not just run a reverse proxy in front of (whatever service you're trying to protect) and use the API keys there? Because it breaks the clients of most homelab services. That's what authelia does.
- NoPicklez 1y ago"Knock Knock" kinda sounds like a cool name for an access control system
- operrs 1y agoIf you need to manage risk for a legacy service that has a requirement to be internet exposed, I suggest checking out https://knocknoc.io/ https://knocknoc.io/ for a self-hosted and/or cloud based solution that was not built with vibe coding, but actual customer security use cases. They provide 2FA and/or single sign-on to allow just in time access to internet exposed applications which remain hidden from unauthenticated/approved users.
- fariszr 1y agoHey I'm the creator of knocker! I actually wanted to write a blog post about it before posting, but OP already did that. If you have any questions just let me know! Will go into more details why I created in the blog post coming very soon! Just doing the final touches right now.