Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)T
Posts
1
Comments
167
Joined
3 yr. ago

  • I think their question is, what do you mean by "secure"? Because as the saying goes for internet services: usually, if you're not paying, you're not the customer, you're the product.

  • Agreed. Anyone who thinks it's ok to just expose ssh on 22 to the internet has never looked at their logs. The port will be found in minutes, and be hammered by thousands of login attempts by multiple bots 24/7. Sure you can block repeat failed logins, but that list will just always be growing.

  • Normal for who? I wouldn't expose SSH on 22 to the internet unless you have someone whose full time job is monitoring it for security and keeping it up to date. There are a whole lotta downsides and virtually no upsides given that more secure alternatives have almost zero overhead.

  • I see several Amcrest options that look like they have integrated AI object detection. Frigate on the other hand says you should get a "Google Coral Accelerator". Do you know if Frigate (or RTSP, I guess) has a way to leverage the built in detection capabilities of a camera (assuming they are built in, and not being offloaded to the cloud)? Or am I better of looking at the "dumb" Amcrest cameras, and just assuming all processing for all cameras will happen on my Frigate hardware?

  • I feel like this is the perfect place for Right to Repair legislation: the product is broken? And it's outside your support window? Then give customers what they need to make the fix themselves. It's not good enough to say "meh, guess you gotta buy one of our newer chips then 🤷"

  • It's not clear to me how tailscale does this without being a VPN of some kind. Is it just masking your IP and otherwise just forwarding packets to your open ports? Maybe also auto blocking suspicious behavior if they're clearly scanning or probing for vulnerabilities?

  • I need everything to be fully but securely accessible from outside the network

    I wouldn't be able to sleep at night. Who is going to need to access it from outside the network? Is it good enough for you to set up a VPN?

    The more stuff visible on the internet, the more you have to play IT to keep it safe. Personally, I don't have time for that. The safest and easiest system to maintain a system is one where possible connections are minimized.