_cryptagion [he/him]

the only way to get into whatever version of heaven you believe in is to kill as many nazis and zionists as you can. fuck ICE, fuck trump, and fuck the liberals that put him into power.

proud member of the db0 grassroots left wing qanon Russian troll farm sent to divide you all.

Follow me on Mastodon: Unwillingly observing the end of democracy

  • 0 Posts
  • 16 Comments
Joined 8 months ago
cake
Cake day: November 4th, 2024

help-circle


  • It’s over man. You’re certified expert yapper but that’s not going to convince me or anyone else here that you know what you’re talking about.

    Is this Reddit? When were we supposed to be seeking the validation of random strangers on the net, especially ones who brag about their bona fides like it’s a CoD lobby? You keep saying it’s over, but for some reason you keep coming back here to try to get the last word. If I’m in a position of weakness, why is it you’re the one trying so hard? You’re in a dick measuring contest against yourself. I’m getting second-hand embarrassment.




  • Yeah, some random nobody trying to convince people they’re a cybersecurity expert is gonna be what shuts me up.

    I very clearly laid out my setup, and how you were wrong. If you can’t even read well enough to understand that, let alone form som kind of actual argument backed up by reality, that isn’t my problem to deal with.

    I would say stick to your own day job, but if this is actually your day job then maybe check out whether your local Burger King has openings, you’ll do less harm there.



  • Whoa whoa whoa. What malicious attempts?

    I said it would block all malicious attempts. I didn’t say the people trying to access my services were malicious. Clearly the OP is worried about that. I however, having just the meager experience of, you know, actually fucking running the a Jellyfin server, am not. But I’m also not trying convince people I’m a smug cybersecurity expert with a decade of experience.


  • Yes they are. The idea that they’re not would be a statistical wonder.

    Guess I’m a wonder then. I’ve always thought of myself as pretty wonderful, I’m glad to hear you agree.

    Are you logging into your Authelia login page 2k times a day? If not, I suspect that some (most) of those are malicious lol.

    That’s 2k requests made. None of them were served. Try to keep up.

    Well I am an expert with over a decade of experience in cybersecurity, but I’m not acting like an expert here, I’m acting like somebody with at least a rudimentary understanding of how these things work.

    Then I guess I should get a career in cybersecurity, because I obviously know more than someone with over a decade of supposed experience. If you were worth whatever your company is paying you in wages, you would know that a rule blocking connections from other countries, and also requiring the request for the login page come from one of the services on your domain, will block virtually all malicious attempts to access your services. Such a rule doesn’t work for a public site, but for a selfhosted setup it’s absolutely an easy option to reduce your bandwidth usage and make your setup far more secure.


  • No, they are actively trying to get in right now. If you have Authelia exposed they’re brute forcing it.

    No, they aren’t. Just to be sure, I just checked it, and out of the over 2k requests made to the Authelia login page in the last 24 hours, none have made it to the login page itself. You don’t know jack shit about what’s going on in another persons network, so I’m not sure why you’re acting like some kind of expert.


  • No, people are probing it right now. But looking at the logs, nobody has ever made it through. And I run a pretty basic setup, just Cloudflare and Authelia hooking into an LDAP server, which powers Jellyfin. Somebody who invests a little more time than me is probably a lot safer. Tailscale is nice, but it’s overkill for most people, and the majority of setups I see posted here are secure enough to stop any random scanning that happens across them, if not dedicated attention.