this post was submitted on 28 Nov 2023
3 points (100.0% liked)

Self-Hosted Main

502 readers
1 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

For Example

We welcome posts that include suggestions for good self-hosted alternatives to popular online services, how they are better, or how they give back control of your data. Also include hints and tips for less technical readers.

Useful Lists

founded 1 year ago
MODERATORS
 

i want to remotely ssh to my home server, and I was wondering if I could just forward port 22 with disabling password login and use pubkey authentication will be safe enough?

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 1 points 9 months ago

Wireguard doesn't answer unless you hand shake with a valid package.

There are three 512 bit keys.

And you can put ssh behind it with ssh keys.

The extra later of defence is quite significant.

No "actual user" is blocked by fail2ban. They auth with keys, can't really fail.

Blocking after three fail is very reasonable and effective. It also keeps the logs noise down.