Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Selfhosted
  3. Risks of self-hosting a public-facing forum?

Risks of self-hosting a public-facing forum?

Scheduled Pinned Locked Moved Selfhosted
selfhosted
68 Posts 32 Posters 473 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • N [email protected]

    it's settled law that you are absolved of responsibility if you don't moderate.

    E This user is from outside of this forum
    E This user is from outside of this forum
    [email protected]
    wrote on last edited by
    #40

    You chose to ignore OP's point.

    let’s stop pretending the law actually matters for the people in power.

    N 1 Reply Last reply
    0
    • E [email protected]

      You chose to ignore OP's point.

      let’s stop pretending the law actually matters for the people in power.

      N This user is from outside of this forum
      N This user is from outside of this forum
      [email protected]
      wrote on last edited by
      #41

      i mean... we're talking about civil torts here, not constitutional law. i think you can still count on a court to throw this out even with a pro se defense.

      E 1 Reply Last reply
      0
      • G [email protected]

        generating a decade long cert is a terrible idea.

        what if a malicious actor gets your private keys and can spoof you now?

        you're fucked unless you work through the vendor to blacklist that cert, which is a huge pita.

        certs should be done yearly at most. quarterly at best.

        S This user is from outside of this forum
        S This user is from outside of this forum
        [email protected]
        wrote on last edited by
        #42

        Plus certbot and acme easily auto renew the certs.

        1 Reply Last reply
        0
        • ? Guest

          I've wanted to do this for a long time. My current ADHD hyperfixation is NodeBB, but I think my questions fit most anything that you want to be available to the general public and not just yourself and your friends.

          Basically, I want to host a NodeBB instance intended for the general public out of my house. What are the risks of doing this? In particular, what are the risks of doling out a web address that points to my personal IP address? Is this even a good idea? Or should I just rent a VPS? This is 80% me wanting to improve my sysadmin skills, and 20% me wanting to create a community.

          I have a DMZ in place. Hosts in the DMZ cannot reach the LAN, but LAN hosts can reach the DMZ. If necessary, I can make sure DMZ hosts can't communicate with each other.

          I have synchronous 1 Gb fiber internet. Based on the user traffic of similar forums, I don't anticipate a crush of people.

          I know the basics of how to set up a NodeBB instance, and I've successfully backed up and restored an instance on another machine.

          I'm not 100% on things like HTTPS certs. I can paste a certbot command from a tutorial, that's it.

          Anything else I should know? Thanks!

          3 This user is from outside of this forum
          3 This user is from outside of this forum
          [email protected]
          wrote on last edited by
          #43

          Its so cheap to just get a vps from a littlecreekhosting deal, I checked them all on lowendtalk and its the cheapest for highest specs, you do have to comment your invoice to double ram, but its 4 core 8gb ram for 3.50 a month and 8core 16gb 7$ cogent amd epyc, and solid ssd space 140-160 idr exactly, they have multiple deals posted, the one with the prices I mention is the best one, they also had windows vps deals. Spent way too long testing hella, its not the best ping out there for me since I'm fairly far but I'm not hosting gameservers so its a non issue.

          There are many other deals on lowendtalk but they are typically for way less resources or way more expensive for a lot more resources

          downhomechunk@midwest.socialD C V 3 Replies Last reply
          0
          • G [email protected]

            I don't use shit-tier products like cloudflare so I don't bother knowing what their product line is or what it does.

            not knowing how a platform specific product works doesn't dictate intelligence.

            also, in your original comment you said "SSL cert" and never mentioned it was a platform specific cert.

            be clear when you say shit and people won't misunderstand you and treat you like a fucking moron.

            _cryptagion@lemmy.dbzer0.com_ This user is from outside of this forum
            _cryptagion@lemmy.dbzer0.com_ This user is from outside of this forum
            [email protected]
            wrote on last edited by
            #44

            be clear when you say shit and people won’t misunderstand you and treat you like a fucking moron.

            Obviously, when name Cloudflare specifically more than once, it can be so hard to tell which platform I mean. It's an easy mistake to make if you don't know how to read.

            not knowing how a platform specific product works doesn’t dictate intelligence.

            No, but using hostility as a way to distract from when you've gone and made yourself look like an idiot is certainly a defense commonly used by, as you put it, "fucking morons". Now, is there any other pearls of wisdom you want to offer us, Mr. Trump, or was your eternally youthful ardor spent on that one emission?

            G 1 Reply Last reply
            0
            • rubberelectrons@lemmy.worldR [email protected]

              Somehow 4chan admins have largely escaped legal consequences for this stuff, and I don't think it's just because of sec230.

              Not a fan of 4chan, but I do note both their and the pirate bay's operation scheme.

              I This user is from outside of this forum
              I This user is from outside of this forum
              [email protected]
              wrote on last edited by
              #45

              I mean, in most cases this isn't criminal law (in the US at least), so it means you have to attract enough attention of a corporation since they're usually the only ones who can afford the legal costs to file the DMCA requests and responses for copyright violation. And with many other civil issues, often corporations with the money for it, don't have standing to sue, and if they did, would be required to sue each individual in the appropriate jurisdiction.

              With the removal of Section 230, these costs will go down significantly as a single user's violation could be enough to bankrupt or shut down an entire site of violating content or, if serious criminal violations like child porn, put the person who hosts the site in prison who, will be much easier to identify and sue in a single jurisdiction or arrest than a random internet user.

              1 Reply Last reply
              0
              • 3 [email protected]

                Its so cheap to just get a vps from a littlecreekhosting deal, I checked them all on lowendtalk and its the cheapest for highest specs, you do have to comment your invoice to double ram, but its 4 core 8gb ram for 3.50 a month and 8core 16gb 7$ cogent amd epyc, and solid ssd space 140-160 idr exactly, they have multiple deals posted, the one with the prices I mention is the best one, they also had windows vps deals. Spent way too long testing hella, its not the best ping out there for me since I'm fairly far but I'm not hosting gameservers so its a non issue.

                There are many other deals on lowendtalk but they are typically for way less resources or way more expensive for a lot more resources

                downhomechunk@midwest.socialD This user is from outside of this forum
                downhomechunk@midwest.socialD This user is from outside of this forum
                [email protected]
                wrote on last edited by
                #46

                I've had good luck with these guys:
                https://cloudfanatic.net/pricing/

                I think they would fall in the less resources category. But they offer unlimited data transfer, and you can use any distro you want. I run slackware btw.

                3 1 Reply Last reply
                0
                • ? Guest

                  I've wanted to do this for a long time. My current ADHD hyperfixation is NodeBB, but I think my questions fit most anything that you want to be available to the general public and not just yourself and your friends.

                  Basically, I want to host a NodeBB instance intended for the general public out of my house. What are the risks of doing this? In particular, what are the risks of doling out a web address that points to my personal IP address? Is this even a good idea? Or should I just rent a VPS? This is 80% me wanting to improve my sysadmin skills, and 20% me wanting to create a community.

                  I have a DMZ in place. Hosts in the DMZ cannot reach the LAN, but LAN hosts can reach the DMZ. If necessary, I can make sure DMZ hosts can't communicate with each other.

                  I have synchronous 1 Gb fiber internet. Based on the user traffic of similar forums, I don't anticipate a crush of people.

                  I know the basics of how to set up a NodeBB instance, and I've successfully backed up and restored an instance on another machine.

                  I'm not 100% on things like HTTPS certs. I can paste a certbot command from a tutorial, that's it.

                  Anything else I should know? Thanks!

                  ? Offline
                  ? Offline
                  Guest
                  wrote on last edited by
                  #47

                  just cloudflare tunnel it - i set one up the other day and it works super well, proving external access to a locally hosted service all without having to set up your own SsL certs and worrying about exposing private ips or ports

                  ? 1 Reply Last reply
                  0
                  • E [email protected]

                    Doesn't Cloudflare cost money for DDoS protection?

                    R This user is from outside of this forum
                    R This user is from outside of this forum
                    [email protected]
                    wrote on last edited by
                    #48

                    You get some coverage for free but if you're really getting slammed I wish to stay up they're not going to do everything for free. I believe They click here to prove you're not a butt is gratis.

                    1 Reply Last reply
                    0
                    • M [email protected]

                      Don't do it.

                      Hosting a public service with no real knowledge of security can only end badly.

                      Get a vpc, do it there, learn from mistakes.

                      It's more than just HTTPS, you also need proper authentication, regular updates, emergency updates for critical vulnerabilities, ideally some sort of monitoring to detect potential misuse of the service or any escalations from the service to the OS.

                      Ask yourself this: If this was your first time driving a car, would you rather do it in an empty parking lot where at worst you will damage the car. Or would you rather do it in a busy street where at worst you can kill someone?

                      ? Offline
                      ? Offline
                      Guest
                      wrote on last edited by
                      #49

                      Have you ever tried Cloudflare Tunnels? I think this would solve most of those issues

                      M 1 Reply Last reply
                      0
                      • _cryptagion@lemmy.dbzer0.com_ [email protected]

                        be clear when you say shit and people won’t misunderstand you and treat you like a fucking moron.

                        Obviously, when name Cloudflare specifically more than once, it can be so hard to tell which platform I mean. It's an easy mistake to make if you don't know how to read.

                        not knowing how a platform specific product works doesn’t dictate intelligence.

                        No, but using hostility as a way to distract from when you've gone and made yourself look like an idiot is certainly a defense commonly used by, as you put it, "fucking morons". Now, is there any other pearls of wisdom you want to offer us, Mr. Trump, or was your eternally youthful ardor spent on that one emission?

                        G This user is from outside of this forum
                        G This user is from outside of this forum
                        [email protected]
                        wrote on last edited by
                        #50

                        take a chill pill and come back to read from start to finish.

                        you were the first one to respond with hostility, prick. I commented on how it's a bad idea to have SSL certs last for a decade.

                        that's when you responded with heavy sarcasm, like a angsty child.

                        maybe if you didn't have tissue paper for skin you could see how much of a petulant child you are. I can even see how fragile your ego is from all your interactions with others.

                        I don't know what's more pathetic, your overwhelming desire to be right or your desperate need to prove you're smarter than somebody else.

                        some friendly advice before I block you forever. if you think everyone around you is an asshole, you're the asshole.

                        _cryptagion@lemmy.dbzer0.com_ 1 Reply Last reply
                        0
                        • G [email protected]

                          take a chill pill and come back to read from start to finish.

                          you were the first one to respond with hostility, prick. I commented on how it's a bad idea to have SSL certs last for a decade.

                          that's when you responded with heavy sarcasm, like a angsty child.

                          maybe if you didn't have tissue paper for skin you could see how much of a petulant child you are. I can even see how fragile your ego is from all your interactions with others.

                          I don't know what's more pathetic, your overwhelming desire to be right or your desperate need to prove you're smarter than somebody else.

                          some friendly advice before I block you forever. if you think everyone around you is an asshole, you're the asshole.

                          _cryptagion@lemmy.dbzer0.com_ This user is from outside of this forum
                          _cryptagion@lemmy.dbzer0.com_ This user is from outside of this forum
                          [email protected]
                          wrote on last edited by
                          #51

                          if you think everyone around you is an asshole, you’re the asshole.

                          Most people I run across aren't assholes, you're just an exception.

                          1 Reply Last reply
                          0
                          • 3 [email protected]

                            Its so cheap to just get a vps from a littlecreekhosting deal, I checked them all on lowendtalk and its the cheapest for highest specs, you do have to comment your invoice to double ram, but its 4 core 8gb ram for 3.50 a month and 8core 16gb 7$ cogent amd epyc, and solid ssd space 140-160 idr exactly, they have multiple deals posted, the one with the prices I mention is the best one, they also had windows vps deals. Spent way too long testing hella, its not the best ping out there for me since I'm fairly far but I'm not hosting gameservers so its a non issue.

                            There are many other deals on lowendtalk but they are typically for way less resources or way more expensive for a lot more resources

                            C This user is from outside of this forum
                            C This user is from outside of this forum
                            [email protected]
                            wrote on last edited by
                            #52

                            Its so cheap to just get a vps from a littlecreekhosting deal

                            This site seems suspicious as hell. Incredibly basic site, no info on where they're located, and the "About Us" links aren't even links. There's no About Us page.

                            3 1 Reply Last reply
                            0
                            • ? Guest

                              Have you ever tried Cloudflare Tunnels? I think this would solve most of those issues

                              M This user is from outside of this forum
                              M This user is from outside of this forum
                              [email protected]
                              wrote on last edited by
                              #53

                              I have not, I tend to avoid services and diy it

                              1 Reply Last reply
                              0
                              • 3 [email protected]

                                Its so cheap to just get a vps from a littlecreekhosting deal, I checked them all on lowendtalk and its the cheapest for highest specs, you do have to comment your invoice to double ram, but its 4 core 8gb ram for 3.50 a month and 8core 16gb 7$ cogent amd epyc, and solid ssd space 140-160 idr exactly, they have multiple deals posted, the one with the prices I mention is the best one, they also had windows vps deals. Spent way too long testing hella, its not the best ping out there for me since I'm fairly far but I'm not hosting gameservers so its a non issue.

                                There are many other deals on lowendtalk but they are typically for way less resources or way more expensive for a lot more resources

                                V This user is from outside of this forum
                                V This user is from outside of this forum
                                [email protected]
                                wrote on last edited by
                                #54

                                OP asks for not doing exactly that though.

                                3 1 Reply Last reply
                                0
                                • rubberelectrons@lemmy.worldR [email protected]

                                  Sounds like hosting outside the US is a possible solution. Many things to be careful of, regardless.

                                  V This user is from outside of this forum
                                  V This user is from outside of this forum
                                  [email protected]
                                  wrote on last edited by
                                  #55

                                  Don't chose china or russia though 😉

                                  1 Reply Last reply
                                  0
                                  • ? Guest

                                    just cloudflare tunnel it - i set one up the other day and it works super well, proving external access to a locally hosted service all without having to set up your own SsL certs and worrying about exposing private ips or ports

                                    ? Offline
                                    ? Offline
                                    Guest
                                    wrote on last edited by
                                    #56

                                    I looked up Cloudflare tunnels and tried setting one up. Some things future readers may want to know:

                                    1. You have to set Cloudflare as your domain's authoritative nameservers.
                                    2. You need to set up an account (not a problem) but also have to register a payment method, even for the free tier (no me gusta).
                                    3. Regarding NodeBB specifically, if you set up a tunnel, you can access the forum, even over HTTPS, but it fails when you try to log in. A few minutes of searching leads me to believe it has something to do with web sockets, and the solution requires you to partially expose your IP address, defeating the principle purpose for me to use cloudflare in the first place.
                                    ? 1 Reply Last reply
                                    0
                                    • N [email protected]

                                      i mean... we're talking about civil torts here, not constitutional law. i think you can still count on a court to throw this out even with a pro se defense.

                                      E This user is from outside of this forum
                                      E This user is from outside of this forum
                                      [email protected]
                                      wrote on last edited by
                                      #57

                                      I surely hope so.

                                      1 Reply Last reply
                                      0
                                      • C [email protected]

                                        Its so cheap to just get a vps from a littlecreekhosting deal

                                        This site seems suspicious as hell. Incredibly basic site, no info on where they're located, and the "About Us" links aren't even links. There's no About Us page.

                                        3 This user is from outside of this forum
                                        3 This user is from outside of this forum
                                        [email protected]
                                        wrote on last edited by
                                        #58

                                        its one of the more trusted ones on lowendtalk?

                                        C 1 Reply Last reply
                                        0
                                        • V [email protected]

                                          OP asks for not doing exactly that though.

                                          3 This user is from outside of this forum
                                          3 This user is from outside of this forum
                                          [email protected]
                                          wrote on last edited by
                                          #59

                                          its just way less risky and not that expensive tho? I had the same idea as op til I realized that fit my needs and gave a lot more resources than hetzner.

                                          1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups