Remix.run Logo
My Homelab Got Hacked – A Postmortem(phunky.cafe)
26 points by birdculture 18 hours ago | 8 comments
petterroea 16 hours ago | parent | next [-]

Whelp. This is one of the reasons I stopped believing in exposing my homelab to the internet. Everything is now on my private VPN network. It means I don't have to worry about staying up to date all the time. For something that is ostensibly a hobby, it's nice. Only downside is that you can't share it with people.

8fingerlouie 10 hours ago | parent | next [-]

Especially because this is a hobby for most homelabbers, I've never understood why people insist on opening it to the internet.

Visiting various subreddits, people massively underestimate the amount of time required to host something in a secure matter, and just because their little corner of the internet hasn't been hacked yet doesn't mean it's safe.

Self hosting stuff means you have a side gig as an unpaid system administrator. Sharing it with other people also means you have a SLA.

I self hosted for decades, but 5-6 years ago I simply put everything important in the cloud. The only things I host at home are media and my home assistant, and access to that is guarded by a VPN. I have a site to site tunnel between my home and summerhouse to allow media streaming there, and otherwise it's just regular road warrior tunnels. Using wireguard allows me to keep the VPN up 24/7 because it supports routing only specific subnets as well as auto disabling on predefined networks.

I also "host" backups at home. Everything stored in the cloud is backed up at home, as well as with another cloud provider.

mikeydiamonds 6 hours ago | parent | prev | next [-]

Same. I tried making updates the security boundary too but it's not enough. Now public services terminate on a disposable VPS and reverse-tunnel home only where needed, although even that exception keeps shrinking. Pangolin ;)

doubled112 16 hours ago | parent | prev | next [-]

The chat server was the only thing I was sharing anyway, so it ended up on a boxing day sale VPS. Everything else became an internal service.

I thought it would eventually drive me crazy, but to this day I regret nothing.

mikeydiamonds 6 hours ago | parent | prev [-]

[dead]

mdotk 15 hours ago | parent | prev | next [-]

What's up with this bit?

Note: I know the LLM-use will (understandably) piss some people off.

They used it to be able to read the code better!

usr1106 12 hours ago | parent [-]

Haven't you noticed that LLM are a vastly unethical technology? Stolen content processed using amongst others slave labor from Africa and huge environmental impact. Paid by the average computer buyer today.

Yes, my employer strongly encourages me to act unethically. And in cases like in TFA I do.

burnt-resistor 5 hours ago | parent | prev [-]

I haven't left open ports since a 786k SDSL Linux router PC running CS and Quake servers in 2002. WireGuard these days.