Skip Navigation

User banner

The 8232 Project

@ Charger8232 @lemmy.ml

Posts
12
Comments
61
Joined
2 yr. ago

I trust code more than politics.

  • Okay, so you might be unfamiliar with networking

    I'm familiar with some parts of networking, but selfhosted VPNs are something I am unfamiliar with, so thank you for helping me out!

    No need to use Tailscale if you’re just using your Wi-Fi or Ethernet.

    I want it to be encrypted during transit, even if it is over the LAN.

    Tailscale/Headscale creates it’s own VPN network which will need its own IP space.

    This is what I was afraid of, because this means it probably can't run alongside ProtonVPN, since it would fill up the VPN slot on Android, right?

    If so, it means we've come full circle. Unless there is a way to use Tailscale alongside ProtonVPN or a way to get Jellyfin clients to trust self-signed certificates, I don't see any other option than buying a domain and exposing the server to the internet. Am I missing something?

  • The only other providers I would use are Mullvad VPN or IVPN, both of which are paid.

    I agree it is ridiculous.

  • Wireguard was written with the explicit goal of having sane, secure defaults.

    Wireguard is much easier because it simply refuses to give you the choice to do things incorrectly.

    Security my beloved

    I totally feel you w.r.t. openvpn or ipsec, since it’s easy to do something wrong.

    This is one reason I've avoided selfhosting for this long. I am not a network engineer, and I have no plans to be. That means if I am managing an entire server from my physical home location, that's a recipe for disaster. There's simply no way to ensure you've done things correctly, especially since a lot of the selfhosting community has an... aversion to good security practices (which is why I had to make this post to begin with).

    w.r.t. the certificate thing, you could set up a reverse proxy and do HSTS to ensure nobody can load up a rogue CA on your devices.

    Would that work while having ProtonVPN still enabled?

    trust on first use

    My favorite food

    This would let you use a self-signed certificate if you do desired.

    Jellyfin clients don't accept self-signed certificates, as I mentioned. Is there a way around that (or does HSTS somehow solve it)? From what I've learned about HSTS up until know, it is simply there to require the use of proper certificates and HTTPS. Am I wrong about that?

  • I wish it were that simple, but as I mentioned that would require paying for ProtonVPN to allow LAN connections (which isn't the worst thing in the world, but I'd prefer to avoid subscriptions where possible) and clients don't allow self-signed certificates.

  • I know. It's very unfortunate, but I understand why.

  • You don’t need a VPN for LAN connections.

    ProtonVPN by default blocks LAN connections, and can only be changed using their paid tier.

  • You want to use it only locally (on your home), but it can’t be a local-only instance.

    By "local-only" I meant on-device

    You want to e2ee everything, but fail to mention why.

    Privacy and security.

    There is no reason to do that on your own network.

    Networks are not a trusted party in any capacity.

    I do not know why you want to use a VPN and what you want to do with it. Where do you want to connect to?

    A VPN such as ProtonVPN or Mullvad VPN are used to displace trust from your ISP into your VPN provider and obscure your IP address while web browsing (among other benefits that I don't utilize).

    What is the attack vector you’re worried about? Are there malicious entities on your network?

    These are good questions but not ones I can answer briefly.

  • Alright, I'm slowly learning, bare with me here:

    • ProtonVPN is always-on and blocks connections without VPN
    • Jellyfin and Headscale are hosted on the Pi (or does Headscale need its own server?)
    • Tailscale and a Jellyfin client are installed on the phone

    Then:

    • Will that will run fully on the LAN?
    • Will it be encrypted during transit?
    • Does ProtonVPN need to allow LAN connections?
  • So:

    • ProtonVPN is installed on my Android phone
    • Android has Always-on VPN enabled
    • Android has Block connections without VPN enabled
    • Host Jellyfin on my Raspberry Pi 5
    • Install Headscale on my Raspberry Pi 5
    • Install Headscale on my Android phone
    • Install a Jellyfin client on my Android phone
    • Configure everything

    And that will work? It will be encrypted during transit? And only run on the LAN? Does ProtonVPN need to allow LAN connections (I assume it does)?

  • Does Headscale conflict with ProtonVPN/Mullvad VPN (i.e. can I use those alongside Headscale)? Android has a limited number of VPN slots, so that's why I ask.

  • You could do a vpn hosting by yourself.

    I'm uneasy about this, because I don't trust myself to do it securely. VPNs are a very complex piece of software, so I highly prefer to stick with widely used setups (i.e. "stock" VPN software such as ProtonVPN, Mullvad VPN, etc.)

  • I still want security in transit, no matter where it is being broadcast from.

  • but I’d suggest reconsidering the Pi

    It's what I have on hand at the moment. I don't have proper server hardware yet.

    and a microSD to host Jellyfin.

    Beyond that, SD cards are terrible for this kind of task and you’d be much better served with an SSD as your boot/data drive for robustness. I can’t even count the number of failed SD cards I’ve had over the years.

    I will keep this in mind, thank you!

    Neither one of these are a good fit unless you plan on sticking to very specific audio and video codecs to avoid all transcoding and your upload speeds are capable of serving the full bitrate of your files.

    I haven't tried playing videos from my Raspberry Pi, but I've been able to run extremely modern video codecs on some pretty old hardware without any issues. Since I've never had issues with video codecs, I'm not experienced in what hardware can and can't handle it.

  • Run in at home and get Tailscale setup with a Headscale server, or just use Tailscale straight out of you want. That’s the simplest.

    I have no idea how to do this. Do you have any resources? Does it cost a subscription fee?

    A better option would be getting an OpenWRT router

    This is what I have planned. OpenWrt Two my beloved

    You’ll have many different options for decentralized and NAT traversing VPNs with this option. GL.Inet Flint is a great choice.

    I also don't know how to do this. Resources are much appreciated :)

  • Just run it on the LAN and don’t expose it to the Internet.

    This would require paying for a VPN to allow LAN connections, which is an option but not my preferred one.

    HTTPS only secures the connection, and I doubt you’re sending any sensitive info to or from Jellyfin

    This is a matter of threat model, and I would prefer not to expose my TV preferences unencrypted over the network.

    but you can still run it in docker and use caddy or something

    Does Caddy require a custom DNS in order to point the domain to a local IP address?

    The bigger target is making sure jellyfin itself and the host it runs on are updated and protected.

    This is easy with securecore, since it updates daily. The rest of the semantics for the actual hosting side aren't too difficult.

  • !lemmysilver

    Other people beat me to it on the other post, but none here!

  • Not so new browser controls let you block all advertisers forever

  • I used GNOME Disks to modify /etc/crypttab and /etc/fstab to auto decrypt and auto mount on boot. Jellyfin still loses its access each time I restart, even though the jellyfin group still displays having access to the files.

    Edit: Turns out it does have access, but it's no longer under the /media/username directory. I have to point Jellyfin to /mnt/UUID instead. This fixed it!

  • And you don’t share your photos with family, friends, or the public? Or is your sharing solution to spam people with MMS text messages?

    If I need to quickly show somebody a photo, I'll physically show them by pulling it up on my phone. If I need to send photos to someone, I'll send them using a preferred messenger such as Signal. It allows you to send up to 32 images in a single message. If I need to send images to multiple people, I can send it in a group text or select multiple people to send them to at the same time.

    No, I don’t. If Immich provides a feature your phone doesn’t, then it’s not a good example of something that doesn’t need to be self-hosted.

    The point is that everything Immich offers is something that could be run entirely on-device. While AI image tagging isn't currently available for alternatives, I'm upset that Immich requires a server instead of making it optional and letting you do image tagging on-device.

    I’m interested in other examples you have; it sounds as if many self-host solutions perplex you, beyond Immich - what are they?

    What I missed in my initial post was availability across devices. So, something like Vaultwarden would have been useless by my criteria. I have two independent KeePass databases. One exclusively for desktop accounts and one exclusively for mobile accounts. I want to compartmentalize those, so I have no reason to selfhost Vaultwarden. As I've learned, Vaultwarden and other software is useful because of availability across devices.

  • I agree with this comment, it has very good points.

    You device has to do all the processing which would lead to lower battery life.

    The way iOS does it is it will only process it when your phone is plugged in and idle (e.g. when you're asleep at night).