Centralization is bad for everyone everywhere.

That bring said… I just moved my homeserver to another city… and I plugged in the power, then I plugged in the ethernet, and that was the whole shebang.

Tunnels made it very easy. No port forwarding no dns configuration no firewall fiddling no nothing.

Why do they have to make it so so easy…

You are viewing a single thread.
View all comments
24 points

Unless you are behind CGNAT; you would have had the same plug+play experience by using your own router instead of the ISP supplied one, and using DDNS.

At least, I did.

permalink
report
reply
2 points

No. You are skipping DNS.

permalink
report
parent
reply
1 point

and using DDNS

As in, running software to update your DNS records automatically based on your current system IP. Great for dynamic IPs, or just moving location.

permalink
report
parent
reply
2 points

I didn’t skip it, I installed ddclient.

Cloudflare is the devil!

permalink
report
parent
reply
6 points

Yes, but it does expose your own IP address and thus where you live. Tunnels don’t.

permalink
report
parent
reply
-1 points

@qaz @Darkassassin07 what are you even saying? Ip address doesn’t expose where you live. And better get off the internet right now if your concern is exposing your ip cause it was never secret to begin with.
Tunnels stop you from opening a port so nothing is exposed openly to the internet but it does not keep your ip private.

permalink
report
parent
reply
3 points
*

Ip address doesn’t expose where you live.

https://letmegooglethat.com/?q=geoip+lookup

Tunnels stop you from opening a port so nothing is exposed openly to the internet1 but it does not keep your ip private2.

This is also incorrect.

  1. The entire purpose of CF tunnels is to expose sites on the internet
  2. CF tunnels (and services like it e.g. ngrok) rely on shared proxy servers that forward traffic based on HTTP host headers (which is why you can’t forward arbitrary TCP traffic). The IP of the site will therefore have the shared IP of the company’s proxy server instead of your own.
permalink
report
parent
reply
2 points

How do you imagine that geoblocking content works if IP addresses don’t expose where you live?

And better get off the internet right now if your concern is exposing your ip cause it was never secret to begin with.

qaz could be using any of dozens of different methods to obfuscate their IP from the wider internet to write their comment, Tor or a VPN to name just a couple.

permalink
report
parent
reply
3 points

Your IP changes all the time, it doesn’t matter. The best someone can deduct from your IP is the country.

permalink
report
parent
reply
4 points
*

This is false. Some ISP’s change IP’s often, but some don’t and sometimes geoip lookups can be really accurate. My IP has remained the same since I moved in, and a geoip lookup results in a coordinate less than a kilometer away. It does matter.

permalink
report
parent
reply
11 points

True, but the downside of cloudflare is that they are a reverse proxy and can see all your https traffic unencrypted.

permalink
report
parent
reply
1 point
*
Deleted by creator
permalink
report
parent
reply
3 points
*

Yes, but if you host a public site it might be a better option, the content is public anyway, and you won’t get doxed if you publish something controversial. It’s a trade-off, between keeping traffic private or keeping your IP private. Wireguard works best for private traffic, but you can’t host a public site with that.

permalink
report
parent
reply
-3 points

Not entirely. CF can protect you from DDOS of up to a few millions of calls per minute. Your home router would melt with that traffic. They also act as a firewall if you enable the proxy dns feature. They do a sanity check before forwarding the call. Also a home router cannot do this. And there’s more.

permalink
report
parent
reply
2 points

@f2sfljLhdtTZ @Darkassassin07 Eveyone so worried about DDoS. They are not going to DDoS a resedential Ip address. Sure if youbpiss someone off they well they’re going to do it even without selfhosting anything.

permalink
report
parent
reply
1 point

I can assure you that before I set up Cloudflare, I was getting hit by SYN floods filling up the entire bandwidth of my home DSL2 connection multiple times a week.

permalink
report
parent
reply
2 points

Sure, cloudflare provides other security benefits; but that’s not what OP was talking about. They just wanted/liked the plug+play aspect, which doesn’t need cloudflare.

Those ‘benefits’ are also really not necessary for the vast majority of self hosters. What are you hosting, from your home, that garners that kind of attention?

The only things I host from home are private services for myself or a very limited group; which, as far as ‘attacks’ goes, just gets the occasional script kiddy looking for exposed endpoints. Nothing that needs mitigation.

permalink
report
parent
reply
12 points

Both your ISP and CF will drop you like a hot potato if you’re ever under that kind of attack.

CF has other features that are nice like, like WAF, bot detection, geo blocking, caching etc. But it’s only a taste.

All their real services are paid and the whole reason they offer a free tier is to upsell you to their paid services.

permalink
report
parent
reply
2 points

@lemmyvore @f2sfljLhdtTZ You can geoock without CloudFlare.

permalink
report
parent
reply

Selfhosted

!selfhosted@lemmy.world

Create post

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don’t control.

Rules:

  1. Be civil: we’re here to support and learn from one another. Insults won’t be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it’s not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don’t duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

Community stats

  • 3.7K

    Monthly active users

  • 2K

    Posts

  • 23K

    Comments