As the title says, I want to know the most paranoid security measures you’ve implemented in your homelab. I can think of SDN solutions with firewalls covering every interface, ACLs, locked-down/hardened OSes etc but not much beyond that. I’m wondering how deep this paranoia can go (and maybe even go down my own route too!).

Thanks!

-2 points
Deleted by creator
permalink
report
reply
5 points

Following for my own edification!

permalink
report
reply
4 points

Hope I get a lot of good answers!

permalink
report
parent
reply
90 points

Nice try, attacker trying to get me to do their reconnaissance work for them. I’m on to you.

permalink
report
reply
19 points

It would be funny if that were the case. I was just hoping to be a little more paranoid from you lot and maybe improve on the things I’ve thought about

permalink
report
parent
reply
21 points

Yeah, just having a little fun in the role of a paranoid admin. My setup isn’t worth mentioning since it fits my threat model (i.e. nobody gives a shit about my network, just don’t be the low hanging fruit) but I’m interested in other replies. Hope you get some useful responses here.

permalink
report
parent
reply
9 points

I’d love to play paranoid admin over my network. Thanks!

permalink
report
parent
reply
9 points

Spfff me, never Anyway please tell me more about your IP adress and your private keys.

permalink
report
parent
reply
8 points

My private key has a 3 in it

permalink
report
parent
reply
12 points

“I’m in”

permalink
report
parent
reply
7 points

Hey its me your friend Aaron how are you. Hey i was just wandering, what is your credit card details again? just wandering

permalink
report
parent
reply
8 points

Ok my ip address is 192.168.3.200.

permalink
report
parent
reply
1 point

Im gonna hack u now

permalink
report
parent
reply
14 points
*

No, honestly I’m not an attacker, but your local bank. We just need your help to update our systems. Please provide us the following credentials to continue using our phish- *ugh* services.

Credit card number: _____________
CVV: ___
Expiration date: ______

permalink
report
parent
reply
13 points

Using SPA firewall knocking (fwknop) to open ports to ssh in. I suppose if I was really paranoid, the most secure would be an air gap, but there’s only so much convenience I’ll give up for security.

permalink
report
reply
4 points

I’m going to save your comment because it has opened up a new technique for network security that I had never thought of before. Thanks a bunch

permalink
report
parent
reply
44 points

Logcheck. It took ages to make sure innocent logs are ignored, but now I get an email as soon as anything non-routine happens on my servers. I get emails with logs from every update, every time I log in, etc. This has given me the most confidence that nothing unexpected is happening on my servers. Of course, one needs to make sure that the firewall is configured well, and that you use ssh keys etc., but logcheck is how I know I’m doing enough.

permalink
report
reply
7 points
*

Very nice idea, and it’s quite simple too. Thanks

permalink
report
parent
reply

Selfhosted

!selfhosted@lemmy.world

Create post

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

Rules:

  1. Be civil: we’re here to support and learn from one another. Insults won’t be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it’s not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don’t duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

Community stats

  • 3.4K

    Monthly active users

  • 3.3K

    Posts

  • 71K

    Comments