Skip Navigation
Security blindspots for selfhosted website
  • Alright everyone, thank you so much for your thoughtful recommendations! To sum it up, here's what I have done:

    • I used let's encrypt's Certbot to get my SSL certs and setup https, auto-renew every 3 months and I setup a reminder to update Certbot every month.
    • I setup a permanent redirect from http to https in Apache
    • I installed a firewall on the Pi, only 80, 443 and [22 from my computer to the RPi] are open. I couldn't find the firewall settings on my router but I assume they exist since I had to forward 80 and 443 there.
    • installed the following plugins: WordFence and WP Fail2Ban
    • changed the user password on the pi to a better longer one

    I think I should be all set, shouldn't I?

  • Security blindspots for selfhosted website
  • Noted ! I’ll make sure to set https up.

    Tbh, I haven’t heard the word firewall since probably 2005… would my router have a firewall built in or is that something I need to add on, let’s say, the RPi ?

  • Security blindspots for selfhosted website
  • Wow lots of info. I’ll check all of this out. You have a good point that I don’t need wordpress. Hugo looks interesting, thanks for the advice!

    And yes, as said above, I’ll look into the free SSL certs to setup https.

  • Security blindspots for selfhosted website
  • Your first point is a good point. I guess it’s ok for now if my rough location is accessible. It’s not like my art is worth anything.

    Regarding upload speed, yeah I know it could become an issue but since it’s just a portfolio website, I don’t expect more than a dozen visits a month.

  • Security blindspots for selfhosted website

    Hello. I’m pretty new here. I just managed to get my Raspberry Pi setup at home to selfhost a simple website that will act as my portfolio for some art I do.

    I’m using WordPress to make the content of the website, meaning it runs on Apache, MariaDB and MySQL in the background. It’s connected via port 80 since I don’t want to pay for SSL certificates to setup https. There will be no accounts or transactions happening on my website. I don’t have anything to manage my dynamic IP but I’ll figure that out later. I’ve deleted the default Pi user on the RPi.

    Are there security issues I should address preemptively? I’m worried for instance that I am exposing my home network, making it easier for someone to breach into whatever is connected there.

    Any tips on making sure my setup is secure?

    33
    Locked
    What are you buying now to avoid upcoming price increases?
  • Probably a computer. I still don’t know if I want a laptop or a desktop. Still don’t know if I want to stay with Apple products or try something new. The frameworks laptops look cool but not the best bang for the buck. I also assume the tariff will kill the supply chain of spare parts which makes them attractive in the first place.

  • Hacked Robot Vacuums Across the U.S. Started Yelling Slurs
  • Ok so I used to work for iRobot, the OG robot vacuum maker. Robot vacuums used to vacuum randomly. To make them vacuum systematically, they need to map your house. One cheap way to do that is to use a camera roughly pointing at your ceiling and do Video SLAM. The camera identifies features on your ceiling and how they are changing to know where the robot is and map the room.

    I guess ecovac thought they could add a camera feed feature for free since they already had a camera on the robot.

  • ‘It’s mindblowing’: US meteorologists face death threats as hurricane conspiracies surge
  • Honestly it would be funny to see Biden do some of this. He only has a few months left and can do whatever because of the supreme court. He could just go on TV an be like: “You know what? The conspiracies are true. We’re gonna turn off the doppler radars in southern states. No more flying. No more weather forecast. We’re going to ban farm laborers to come harvest your crops. The unpredicted weather is gonna ruin the crops anyways. We’re going to stop FEMA from giving aid in your republican states. Communism is unacceptable. We’re gonna ban fossil fuel in the south because that drives the weather crazy. No more cars. Enjoy the 1800s. Bye”

  • No ads here!
  • I assume something similar to sponsor block, some algorithm to identify ad segments and some user feedback to confirm. Unless I’m mistaken as to how sponsor block works?

  • It's always worth asking for a bike rack!
  • Sadly, this is the second worst bike rack design though. A lot of ebikes have wider tires. And the way it’s positioned, the bikes would block the sidewalk. A bunch of “staple” racks parallel to the road are good. Or a set of the Parisian coils taking over one car spot is best.

  • InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)PS
    PSoul•Lemmy @lemmy.world

    Here to enjoy lemmy. My other fedi accounts:

    Posts 1
    Comments 34