Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Selfhosted
  3. Risks of self-hosting a public-facing forum?

Risks of self-hosting a public-facing forum?

Scheduled Pinned Locked Moved Selfhosted
selfhosted
68 Posts 32 Posters 473 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • M [email protected]

    Don't do it.

    Hosting a public service with no real knowledge of security can only end badly.

    Get a vpc, do it there, learn from mistakes.

    It's more than just HTTPS, you also need proper authentication, regular updates, emergency updates for critical vulnerabilities, ideally some sort of monitoring to detect potential misuse of the service or any escalations from the service to the OS.

    Ask yourself this: If this was your first time driving a car, would you rather do it in an empty parking lot where at worst you will damage the car. Or would you rather do it in a busy street where at worst you can kill someone?

    ? Offline
    ? Offline
    Guest
    wrote on last edited by
    #49

    Have you ever tried Cloudflare Tunnels? I think this would solve most of those issues

    M 1 Reply Last reply
    0
    • _cryptagion@lemmy.dbzer0.com_ [email protected]

      be clear when you say shit and people won’t misunderstand you and treat you like a fucking moron.

      Obviously, when name Cloudflare specifically more than once, it can be so hard to tell which platform I mean. It's an easy mistake to make if you don't know how to read.

      not knowing how a platform specific product works doesn’t dictate intelligence.

      No, but using hostility as a way to distract from when you've gone and made yourself look like an idiot is certainly a defense commonly used by, as you put it, "fucking morons". Now, is there any other pearls of wisdom you want to offer us, Mr. Trump, or was your eternally youthful ardor spent on that one emission?

      G This user is from outside of this forum
      G This user is from outside of this forum
      [email protected]
      wrote on last edited by
      #50

      take a chill pill and come back to read from start to finish.

      you were the first one to respond with hostility, prick. I commented on how it's a bad idea to have SSL certs last for a decade.

      that's when you responded with heavy sarcasm, like a angsty child.

      maybe if you didn't have tissue paper for skin you could see how much of a petulant child you are. I can even see how fragile your ego is from all your interactions with others.

      I don't know what's more pathetic, your overwhelming desire to be right or your desperate need to prove you're smarter than somebody else.

      some friendly advice before I block you forever. if you think everyone around you is an asshole, you're the asshole.

      _cryptagion@lemmy.dbzer0.com_ 1 Reply Last reply
      0
      • G [email protected]

        take a chill pill and come back to read from start to finish.

        you were the first one to respond with hostility, prick. I commented on how it's a bad idea to have SSL certs last for a decade.

        that's when you responded with heavy sarcasm, like a angsty child.

        maybe if you didn't have tissue paper for skin you could see how much of a petulant child you are. I can even see how fragile your ego is from all your interactions with others.

        I don't know what's more pathetic, your overwhelming desire to be right or your desperate need to prove you're smarter than somebody else.

        some friendly advice before I block you forever. if you think everyone around you is an asshole, you're the asshole.

        _cryptagion@lemmy.dbzer0.com_ This user is from outside of this forum
        _cryptagion@lemmy.dbzer0.com_ This user is from outside of this forum
        [email protected]
        wrote on last edited by
        #51

        if you think everyone around you is an asshole, you’re the asshole.

        Most people I run across aren't assholes, you're just an exception.

        1 Reply Last reply
        0
        • 3 [email protected]

          Its so cheap to just get a vps from a littlecreekhosting deal, I checked them all on lowendtalk and its the cheapest for highest specs, you do have to comment your invoice to double ram, but its 4 core 8gb ram for 3.50 a month and 8core 16gb 7$ cogent amd epyc, and solid ssd space 140-160 idr exactly, they have multiple deals posted, the one with the prices I mention is the best one, they also had windows vps deals. Spent way too long testing hella, its not the best ping out there for me since I'm fairly far but I'm not hosting gameservers so its a non issue.

          There are many other deals on lowendtalk but they are typically for way less resources or way more expensive for a lot more resources

          C This user is from outside of this forum
          C This user is from outside of this forum
          [email protected]
          wrote on last edited by
          #52

          Its so cheap to just get a vps from a littlecreekhosting deal

          This site seems suspicious as hell. Incredibly basic site, no info on where they're located, and the "About Us" links aren't even links. There's no About Us page.

          3 1 Reply Last reply
          0
          • ? Guest

            Have you ever tried Cloudflare Tunnels? I think this would solve most of those issues

            M This user is from outside of this forum
            M This user is from outside of this forum
            [email protected]
            wrote on last edited by
            #53

            I have not, I tend to avoid services and diy it

            1 Reply Last reply
            0
            • 3 [email protected]

              Its so cheap to just get a vps from a littlecreekhosting deal, I checked them all on lowendtalk and its the cheapest for highest specs, you do have to comment your invoice to double ram, but its 4 core 8gb ram for 3.50 a month and 8core 16gb 7$ cogent amd epyc, and solid ssd space 140-160 idr exactly, they have multiple deals posted, the one with the prices I mention is the best one, they also had windows vps deals. Spent way too long testing hella, its not the best ping out there for me since I'm fairly far but I'm not hosting gameservers so its a non issue.

              There are many other deals on lowendtalk but they are typically for way less resources or way more expensive for a lot more resources

              V This user is from outside of this forum
              V This user is from outside of this forum
              [email protected]
              wrote on last edited by
              #54

              OP asks for not doing exactly that though.

              3 1 Reply Last reply
              0
              • rubberelectrons@lemmy.worldR [email protected]

                Sounds like hosting outside the US is a possible solution. Many things to be careful of, regardless.

                V This user is from outside of this forum
                V This user is from outside of this forum
                [email protected]
                wrote on last edited by
                #55

                Don't chose china or russia though 😉

                1 Reply Last reply
                0
                • ? Guest

                  just cloudflare tunnel it - i set one up the other day and it works super well, proving external access to a locally hosted service all without having to set up your own SsL certs and worrying about exposing private ips or ports

                  ? Offline
                  ? Offline
                  Guest
                  wrote on last edited by
                  #56

                  I looked up Cloudflare tunnels and tried setting one up. Some things future readers may want to know:

                  1. You have to set Cloudflare as your domain's authoritative nameservers.
                  2. You need to set up an account (not a problem) but also have to register a payment method, even for the free tier (no me gusta).
                  3. Regarding NodeBB specifically, if you set up a tunnel, you can access the forum, even over HTTPS, but it fails when you try to log in. A few minutes of searching leads me to believe it has something to do with web sockets, and the solution requires you to partially expose your IP address, defeating the principle purpose for me to use cloudflare in the first place.
                  ? 1 Reply Last reply
                  0
                  • N [email protected]

                    i mean... we're talking about civil torts here, not constitutional law. i think you can still count on a court to throw this out even with a pro se defense.

                    E This user is from outside of this forum
                    E This user is from outside of this forum
                    [email protected]
                    wrote on last edited by
                    #57

                    I surely hope so.

                    1 Reply Last reply
                    0
                    • C [email protected]

                      Its so cheap to just get a vps from a littlecreekhosting deal

                      This site seems suspicious as hell. Incredibly basic site, no info on where they're located, and the "About Us" links aren't even links. There's no About Us page.

                      3 This user is from outside of this forum
                      3 This user is from outside of this forum
                      [email protected]
                      wrote on last edited by
                      #58

                      its one of the more trusted ones on lowendtalk?

                      C 1 Reply Last reply
                      0
                      • V [email protected]

                        OP asks for not doing exactly that though.

                        3 This user is from outside of this forum
                        3 This user is from outside of this forum
                        [email protected]
                        wrote on last edited by
                        #59

                        its just way less risky and not that expensive tho? I had the same idea as op til I realized that fit my needs and gave a lot more resources than hetzner.

                        1 Reply Last reply
                        0
                        • downhomechunk@midwest.socialD [email protected]

                          I've had good luck with these guys:
                          https://cloudfanatic.net/pricing/

                          I think they would fall in the less resources category. But they offer unlimited data transfer, and you can use any distro you want. I run slackware btw.

                          3 This user is from outside of this forum
                          3 This user is from outside of this forum
                          [email protected]
                          wrote on last edited by
                          #60

                          Ill check them out, been curious about unlimited data transfer, does it allow torrenting done through their hosting

                          1 Reply Last reply
                          0
                          • 3 [email protected]

                            its one of the more trusted ones on lowendtalk?

                            C This user is from outside of this forum
                            C This user is from outside of this forum
                            [email protected]
                            wrote on last edited by
                            #61

                            No, I didn't say this "isn't a nice site". I said it's "suspicious as hell".

                            Having a working site and a navigable "About Us" page isn't "nice". It's the bare minimum I would expect of any legitimate nice or ugly site.

                            There's just a lot on their site that reeks of sloppy scammers.

                            3 3 Replies Last reply
                            0
                            • C [email protected]

                              No, I didn't say this "isn't a nice site". I said it's "suspicious as hell".

                              Having a working site and a navigable "About Us" page isn't "nice". It's the bare minimum I would expect of any legitimate nice or ugly site.

                              There's just a lot on their site that reeks of sloppy scammers.

                              3 This user is from outside of this forum
                              3 This user is from outside of this forum
                              [email protected]
                              wrote on last edited by
                              #62

                              well, i have a lot of stuff running on it fine for the last 3 months, and lowendtalk is what I trust, I made a thread there asking about it and ppl trusted them.

                              You use a virtualizer panel and they provision from cogent, its pretty straightforward what you're getting and you can stress test it or whatever? Do you only trust the major players like digital ocean, aws, etc.?

                              1 Reply Last reply
                              0
                              • C [email protected]

                                No, I didn't say this "isn't a nice site". I said it's "suspicious as hell".

                                Having a working site and a navigable "About Us" page isn't "nice". It's the bare minimum I would expect of any legitimate nice or ugly site.

                                There's just a lot on their site that reeks of sloppy scammers.

                                3 This user is from outside of this forum
                                3 This user is from outside of this forum
                                [email protected]
                                wrote on last edited by
                                #63

                                but thats the exact issue, the businesses with clean perfect sites tend to be the scams, while these where you need specific links off a forum like lownendtalm to even access the deal work well and are hella cheap in comparison? Racknerds also been great but way less resources, their deals also never go away if you get a link.

                                C 1 Reply Last reply
                                0
                                • C [email protected]

                                  No, I didn't say this "isn't a nice site". I said it's "suspicious as hell".

                                  Having a working site and a navigable "About Us" page isn't "nice". It's the bare minimum I would expect of any legitimate nice or ugly site.

                                  There's just a lot on their site that reeks of sloppy scammers.

                                  3 This user is from outside of this forum
                                  3 This user is from outside of this forum
                                  [email protected]
                                  wrote on last edited by
                                  #64

                                  either waymy suggestion was to find a deal that suits your needs at low end talk over trying to self host anything otherppl will be accessing from your home, you wont find good deals just googling around, or even on reddit

                                  1 Reply Last reply
                                  0
                                  • ? Guest

                                    I've wanted to do this for a long time. My current ADHD hyperfixation is NodeBB, but I think my questions fit most anything that you want to be available to the general public and not just yourself and your friends.

                                    Basically, I want to host a NodeBB instance intended for the general public out of my house. What are the risks of doing this? In particular, what are the risks of doling out a web address that points to my personal IP address? Is this even a good idea? Or should I just rent a VPS? This is 80% me wanting to improve my sysadmin skills, and 20% me wanting to create a community.

                                    I have a DMZ in place. Hosts in the DMZ cannot reach the LAN, but LAN hosts can reach the DMZ. If necessary, I can make sure DMZ hosts can't communicate with each other.

                                    I have synchronous 1 Gb fiber internet. Based on the user traffic of similar forums, I don't anticipate a crush of people.

                                    I know the basics of how to set up a NodeBB instance, and I've successfully backed up and restored an instance on another machine.

                                    I'm not 100% on things like HTTPS certs. I can paste a certbot command from a tutorial, that's it.

                                    Anything else I should know? Thanks!

                                    kolanaki@pawb.socialK This user is from outside of this forum
                                    kolanaki@pawb.socialK This user is from outside of this forum
                                    [email protected]
                                    wrote on last edited by
                                    #65

                                    Risk of people uploading images that are illegal and you would end up being liable for hosting them. Risk of being hacked...

                                    I don't know how big of a risk this really is these days... I used to host a PHPbb forum in the early 2000's off my personal computer and it didn't get any traffic beyond myself and the friends I told about it.

                                    1 Reply Last reply
                                    0
                                    • 3 [email protected]

                                      but thats the exact issue, the businesses with clean perfect sites tend to be the scams, while these where you need specific links off a forum like lownendtalm to even access the deal work well and are hella cheap in comparison? Racknerds also been great but way less resources, their deals also never go away if you get a link.

                                      C This user is from outside of this forum
                                      C This user is from outside of this forum
                                      [email protected]
                                      wrote on last edited by
                                      #66

                                      Three incoherent replies with jumbled run-on sentences.

                                      the businesses with clean perfect sites tend to be the scams

                                      Uhhh, no. Objectively no. A legit website is not going to have spelling mistakes and broken links. Looking professional and thorough is a direct lead to increased business. What you just said is completely false, and frankly idiotic.

                                      Everything else you said (in all three replies) is just a jumbled mess of a brain dump that I'm not even going to try and address any of it.

                                      1 Reply Last reply
                                      0
                                      • ? Guest

                                        I looked up Cloudflare tunnels and tried setting one up. Some things future readers may want to know:

                                        1. You have to set Cloudflare as your domain's authoritative nameservers.
                                        2. You need to set up an account (not a problem) but also have to register a payment method, even for the free tier (no me gusta).
                                        3. Regarding NodeBB specifically, if you set up a tunnel, you can access the forum, even over HTTPS, but it fails when you try to log in. A few minutes of searching leads me to believe it has something to do with web sockets, and the solution requires you to partially expose your IP address, defeating the principle purpose for me to use cloudflare in the first place.
                                        ? Offline
                                        ? Offline
                                        Guest
                                        wrote on last edited by
                                        #67

                                        i definitely didn’t have to enter my card details, could my region though

                                        ? 1 Reply Last reply
                                        0
                                        • ? Guest

                                          i definitely didn’t have to enter my card details, could my region though

                                          ? Offline
                                          ? Offline
                                          Guest
                                          wrote on last edited by
                                          #68

                                          I'm attempting to run a NodeBB forum. I'm only assuming that web sockets was the issue because the first search result I came up with that matched my symptoms mentioned it.

                                          1 Reply Last reply
                                          0
                                          • System shared this topic on
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups