| ▲ | zamadatix 3 hours ago | |||||||||||||
It's the way the internet was meant to work but it doesn't make it any easier. Even when everything is in containers/VMs/users, if you don't put a decent amount of additional effort into automatic updates and keeping that context hardened as you tinker with it it's quite annoying when it gets pwned. There was a popular post less than a month ago about this recently https://news.ycombinator.com/item?id=46305585 I agree maintaining wireguard is a good compromise. It may not be "the way the internet was intended to work" but it lets you keep something which feels very close without relying on a 3rd party or exposing everything directly. On top of that, it's really not any more work than Tailscale to maintain. | ||||||||||||||
| ▲ | drnick1 2 hours ago | parent | next [-] | |||||||||||||
> There was a popular post less than a month ago about this recently https://news.ycombinator.com/item?id=46305585 This incident precisely shows that containerization worked as intended and protected the host. | ||||||||||||||
| ||||||||||||||
| ▲ | SoftTalker 3 hours ago | parent | prev [-] | |||||||||||||
I just run an SSH server and forward local ports through that as needed. Simple (at least to me). | ||||||||||||||
| ||||||||||||||