Remix.run Logo
usernametaken29 17 hours ago

I don’t know why this wasn’t mentioned before but why not use a Firewall. If you’re using a virtual box like Hetzner or Scaleway you can specify an ip or range at the router level. For all intents and purposes this removes public exposure. Scaleway also has a cheap VPN bridge. So you never need to connect via the public internet if you don’t want to… hardly gets more secure than that

thayne 16 hours ago | parent | next [-]

If you are connecting from a residence or a mobile device (like a laptop), your ip address isn't fixed, so a firewall won't help.

tgv 16 hours ago | parent | next [-]

I use that strategy, as it's really simple, and I rarely have to change IP addresses. Many providers just hand out the same address every time, others as long as you keep your modem running. A colleague who regularly uses a mobile connection from abroad has a VPN with a fixed IP.

Password login is disabled. The only way to log in as root directly is via the terminal emulator on the coloc's admin page.

ozim 15 hours ago | parent | prev | next [-]

How this works in Hetzner web panel where you login you configure that firewall that is in front of your box.

In reality you should use that and then use host based firewall anyway.

vekntksijdhric 16 hours ago | parent | prev [-]

this

cyh555 14 hours ago | parent | prev [-]

They could be hosting on their own homelab network (without tailscale etc magic)