[kwlug-disc] Home Web Servers Security
D. Hugh Redelmeier
hugh at mimosa.com
Thu Aug 6 10:34:43 EDT 2026
Risk is related the sizes of attack surfaces and the diligence maintaining
the security of each.
A VPS makes the risk of the web server "somewhere else". Do you trust
them with what you put there?
My home web servers have material that I really want to keep private.
They are not directly available on the internet, which is inconvenient but
safer.
=========
On my Bell fibre box (modem, router, etc.) I use PPPoE pass through to get
my own router a globally routable but changing IPv4 address. The other
ports on the Bell box are behind NAT with a different globally routable
address. Interesting.
I also have a Teksavvy fibre connection that I'm slowly setting up. I pay
a few bucks a month for a static IP address. Their modem is inferior: it
will support PPPoE pass-through but only at 1G, even though the service is
1.5G; when PPPoE pass-through is used, the other modem ports are not
connected to the internet.
The Teksavvy modem has a fibre-to-SFP dongle. Anyone know if it is
possible to plug that into another SFP port and skip the modem? What
magic settings do I need to know about? VLAN stuff, for example?
My own routers are mini-PCs running Fedora. Not much magic. Each has four
2.5G ethernet ports but no SFP ports. On the other hand, I have a few
2.5G ethernet switches which have a single SFP port.
More information about the kwlug-disc
mailing list