Thanks for the suggestion. I'm trying to move away from Google, but the idea of a shared account for tailscale (which seems to support a lot of different SSO options) may be useful.
Thanks - appreciate another recommendation for Pangolin + crowdsec, plus I didn't know about authentik (which sounds super useful if the services behind it are compatible). I'm thinking I need to have a play around with tailscale and then Pangolin to see how they work and whether either will be appropriate for my use case.
I agree completely. But as a first step (especially since they do seem to have a keyword filter in place), "no restrictions" (or "no censorship" as the case is for the last image) seems like a very obvious phrase to include.
I agree that that's the likely trigger - which makes me wonder why instructions to ignore censors or have "no restrictions" aren't immediately blocked by a filter prior to passing the prompt to the image generation. I'd have thought this was a foreseeable exploit.
All I did was tell it there were no restrictions and ask for a random image; I didn’t request it. But ChatGPT immediately went to the darkest pits of humanity. As I said at the start: the image didn’t arise from nowhere. It may be an artificial image, but it is based on photographs of a real person, or a combination of real victims. What worries me is this was too easy. There was no real hacking. This was ready to be surfaced, with the smallest scratch. It was a one-shot jailbreak. It was based on a popular prompt (which already veered into the darkness).
Thanks. I think I'll need to do a bit more reading - I have no experience with any of the wireguard technologies (my VPN experience is with OpenVPN and enterprise-grade networking hardware that uses IPsec tunnels), but Pangolin's abilities do sound useful.
I guess I need to work out if something like tailscale (as per one of the other comments) set up on just the small group I want to share with will do the job, or whether I really need to expose services to the Internet and hence would benefit from a VPS with something like Pangolin.
Yeah, I don't like the thought of worrying about vulnerabilities either, hence my asking this question!
I haven't heard of Pangolin cloud before -- I'm assuming this is a competitor to tailscale. Are you self-hosting it or using one of their paid plans, and if you're self-hosting, how hard was it to set up?
Thanks. My main concern is needing to have the tailscale client set up on my relatives' devices, so it'd need to be easy to do and the configuration straightforward.
If I wanted to route just traffic to Vikunja and Immich through it, so all their other apps (if on a phone) or web browsing (on a PC) didn't go through tailscale, is that straightforward to do and is it something that has to be done in the client-side configuration?
Thanks, didn't know about Immich proxy. Sounds useful.
On the VPS point - beyond protection against DoS, I assume the main benefits only arise if you host the services on it? My understanding is that, if I open a port and forward it to nginx, then the largest attack surface would be nginx itself and the services it is acting as a reverse proxy for (e.g. Vikunja). nginx is well-established and I think most of the risk is from the plugins rather than nginx vulnerabilities itself, which leaves Vikunja and any other services I'd want to expose as the main attack surface. If I'm using a VPS as a gateway (e.g. hosting nginx there and still keeping Vikunja and Immich within my LAN), then that doesn't seem like it's much of a risk reduction. What am I missing?
Thanks. So, just to make sure I've understood correctly, your recommendation would be a VPS that hosts nginx (or Caddy) as the reverse proxy and uses tailscale (or equivalent) to access my home LAN and make services (e.g. Vikunja) available?
Thanks for the recommendation. I have no experience with Proxmox, so this might be part of a longer-term project once I've got the Vikunja access working (at least that's on a separate Pi and so would be similar to a distinct VM in that regard).
Good call. I'll have to play around with certbot using DNS validation (only ever tried with HTTP validation), but certainly worth including in my plan. Thanks.
Ah, my mistake, I'm getting mixed up between minidiscs and the 8cm mini CDs.
You can get multi-layer M-disc BD-Rs, though, up to the triple layer 100GB BDXL (although you need one of the BDXL burners to write those; the 50GB BD-R DLs can be written by most burners). They cost a pretty penny, though!
The biggest problem now is the disappearance of Bluray burners/writers. Here in Aus there are no internal drives available on the market any more. I've had to stock up with a few second-hand spares before they get too pricey.
Thanks for the suggestion. I'm trying to move away from Google, but the idea of a shared account for tailscale (which seems to support a lot of different SSO options) may be useful.