Skip Navigation

Posts
5
Comments
327
Joined
2 yr. ago

  • To say it's debatable if it's a suite of tools is just wrong.

    How is it wrong to say it is debatable when Traefik and WireGuard have quite literally done majority of the development. Pangolin is just a man in the middle.


    Pangolin uses gerbil with newt for those wireguard tunnels. That's a massive improvement already. It also adds a bunch more features like vpn.

    According to the Newt ReadMe -

    Newt is a fully user space WireGuard tunnel client and TCP/UDP proxy, designed to securely expose private resources controlled by Pangolin. By using Newt, you don't need to manage complex WireGuard tunnels and NATing.

    Seems to me that WireGuard is their primary dependency, without WireGuard what use is it?


    you can crowdsec

    According to Pangolin docs they rely on the Crowdsec middleware offered by Traefik.

    By default, Crowdsec is installed with a basic configuration, which includes the Crowdsec Bouncer Traefik plugin

  • I can’t be much of a help with Caddy however, for Traefik you can use the OIDC Middleware to forward requests to your authentication service.

    Plus I worry I set something up wrong and expose my network

    The only port that would need opening is :443, leave port :80 closed so that people cannot connect to your services insecurely. Slap fail2ban or geoblock on it and call it a day. Also, DDNS allowlist for that deny-first approach.

  • Traefik is what it uses to proxy things. You're comparing a full suite of tools with just one piece.

    I mean, that’s debatable. Taking a look at their docker-compose.yml there are 3 containers they recommend running, with a 4 optional container.

    To say this is a “full-suite” is a bit much when majority of the heavy lifting is done by Traefik, the middleware’s you assign to Traefik and WireGuard. Pangolin if I’m reading this correctly;

    “Pangolin combines reverse proxy and VPN capabilities into one platform.”

    Which is great! However as I mentioned previously, does not integrate well when these services are already setup to work standalone.

    I suspect the same reaction from folks when they hear “download pangolin from the App Store, and use xyz credentials to connect.” And “download WireGuard from the App Store, and use xyz file to connect.”

  • and used a cloudflared tunnel to direct traffic to Caddy

    There is also a way to use the cloudflared tunnel for free that gives you a domain as well (sort of anyways).

    This is DDNS, a popular, free alternative would be ddclient. Essentially updating an A Record so that your dynamic IP is remains associated with your domain.

    While cloudflare is also my registrar as well, I don’t use any of the “features” they offer, and opted to use Keycloak for my authentication needs.

  • Free vps in oracle cloud with Pangolin

    If I’m not mistaken I tried setting up pangolin to work along side my already running Traefik setup and it was just an absolute nightmare.

    I just don’t have the time nor energy to reinvent my already running configuration.

  • Device -> VPN Tunnel (ideally WireGuard) -> Home Router / Server.

    The only port that needs to be opened is your WireGuard server which typically is :51820.

    The issue with this is you have explain VPN’s and WireGuard to people which, in my experience turns people away as they see it as a hassle.

    Alternatively buy a domain, setup DDNS so that your home IP is associated with your domain, setup a reverse proxy and open port :443 on your router however, I would suggest a blacklist-first approach and only whitelist the few known IP’s you can trust.

  • Funk and funky are still in my vocabulary.

  • I believe it still relies on Reddit’s APi however, the token used is regularly refreshed to circumvent their rate limiting.

    OAuth token spoofing: To circumvent rate limits imposed by Reddit, OAuth token spoofing is used to mimick the most common iOS and Android clients. While spoofing both iOS and Android clients was explored, only the Android client was chosen due to content restrictions when using an anonymous iOS client.

    Token refreshing: The authentication token is refreshed every 24 hours, emulating the behavior of the official Android app.

    HTTP header mimicking: Efforts are made to send along as many of the official app's headers as possible to reduce the likelihood of Reddit's crackdown on Redlib's requests.

  • Got to shout Redlib from the rafters.

  • Meanwhile here I am trying to upgrade my 512gb NVME drive to 2Tb while also still trying to afford car payments, rent and food. Rookie numbers on my part.

  • All the criminals wait for me to unlock and load a shotgun, they're real amenable about that sort of thing.

    I don’t disagree at all with this statement, that is the reason I keep a bayonet at the end of my shotgun.

    A secured firearm Is a good idea, that said a locked away firearm is useless in any meaningful self defense action. Secure ≠ locked

    This is a privilege for Americans, unfortunately as a Canadian if I were to draw my shotgun or rifle upon someone breaking into my house I need to prove there was a threat to life and that it was not just an attempt at theft, otherwise the courts may deem my force excessive.

  • In PA, where this bill is from, the state police already give out free gun locks, many other local police departments and community organizations do the same

    Don’t manufactures include trigger/chamber locks with the firearm upon purchase? I know they do for us up here in Canada but only because it’s legally required for safe storage laws.

  • Sane storage laws should be a requirement, especially around minors, Canadians can keep a (non-restricted) shotgun under their bed so long as a lock is on it and the ammo is locked and stored separately.

  • Deleted

    Permanently Deleted

    Jump
  • Murdering cops gonna murder.

    I’m still surprised Americans haven’t taken things into their own hands, the Movie Civil War certainly doesn’t feel far off.

  • I’m always going to say Windows is too heavy to be placed in a server environment but congrats nonetheless.

  • Might sound like a dumb question, but have you opened the port on your router?

    My ASUS router handles my WireGuard setup, I can forward my home VPN server through one of Protons VPN servers essentially creating a multi-hop setup.

  • Software has gone many decades without the need of LLM assistance, I vote to tag “Ai” and “Non-Ai” assisted posts.

    +1

  • YouTube

    Jump
  • No, but Invidious instances can. That was my response to “Just use brave browser”.

    Invidious + Firefox + Managed DNS Resolver yields similar results to YouTube + Brave and is open source.

  • YouTube

    Jump
  • Chromium is a hard no, host your own DNS resolver and create your own blocklist.