• 0 Posts
  • 15 Comments
Joined 2 years ago
cake
Cake day: June 5th, 2024

help-circle


  • That sounds pretty good to me for self-hosted services you’re running just for you and yours. The only addition I have on the DR front is implementing an off-site backup as well. I prefer restic for file-level backups, Proxmox Backup Server for image backups (clonezilla works in a pinch), and Backblaze B2 for off-site storage. They’re reliable and reasonably priced. If a third party service isn’t in the cards then get a second SSD and put it in a safety deposit box or bury it on the other side of town or something. Swap the two backup disks once a month.

    The point is to make sure you’re following the 3-2-1 principal. Three copies of your data. Two different storage mediums. One remote location (at least). If disaster strikes and your home disappears you want something to restore from rather than losing absolutely everything.

    Extending your current set up to ship the external SSD’s contents out to B2 would likely just be pointing rsync at your B2 bucket and scheduling a cron or systemd timer to run it.

    After that if you’re itching for more I’d suggest reading/watching some Red Team content like the stuff at hacker101 dot com and sans dot org. OWASP dot org is also building some neat educational tools. Getting a better understanding of the what and why around internet background noise and threat actor patterns is powerful.

    You could also play around with Wazuh if you want to launch straight into the Blue Team weeds. Education of the attacking side is essential for us to be effective as defenders but deeper learning anywhere across the spectrum is always a good thing. Standing up a full blown SIEM XDR, for free, offers a lot of education.

    P. S. I realize this is all tangential to your OP. I don’t care for the grizzled killjoys who chime in with “that’s dumb don’t do that” or similar, offer little helpful insight, and trot off arrogantly over the horizon on their high horse. I wanted to be sure I offered actionable suggestions for improvement and was tangibly helpful.


  • You can meaningfully portscan the entire internet in a trivial amount of time. Security by obscurity doesn’t work. You just get blindsided. Switching to a non-standard port cleans the logs up because most of the background noise targets standard ports.

    It sounds like you’re doing alright so far. Trying not to get got is only part of the puzzle though. You also ought to have a backup and recovery strategy (one tactic is not a strategy). Figuring out how to turn worst-case scenarios into solvable annoyances instead of apocalypse is another (and almost equally as important). If you’re trying to increase your resiliency, and if your Disaster Recovery isn’t fully baked yet, then I’d toss effort that way.



  • Sure! That’s an SMTP Relay. A lot of folks jumped on the poopoo wagon. It’s common wisdom in IT that you don’t do your own email. There are good reasons for that, and you should know why that sentiment exists, however; if you’re interested in running your own email: try it! Just don’t put all of your eggs in one basket. Keep your third party service until you’re quite sure you want to move it all in-house (after due diligence is satisfied and you’ve successfully completed at least a few months of testing and smtp reputation warming).

    Email isn’t complex. It’s tough to get right at scale, a pain in the ass if it breaks, and not running afoul of spam filtering can be a challenge. It rarely makes sense for even a small business to roll their own email solution. For an individual approaching this investigatively it can make sense so long as you’re (a.) interested in learning about it, (b.) find the benefits outweigh the risks, and (c.) that the result is worth the ongoing investment (time and labor to set up, secure, update, maintain, etc).

    What’ll get you in trouble regardless is being dependent on that in-house email but not making your solution robust enough to always fill its role. Say you host at home and your house burns down. How inconvenient is it that your self-hosted services burned with it? Can you recover quickly enough, while dealing with tragedy, that the loss of common utility doesn’t make navigating your new reality much more difficult?

    That’s why it rarely makes sense for businesses. Email has become an essential gateway to other tooling and processes. It facilitates an incredible amount of our professional interactions. How many of your bills and bank statements and other important communication are delivered primarily by email? An unreliable email service is intolerable.

    If you’re going to do it make sure you’re doing it right, respecting your future self’s reliance on what present-you builds, and taking it slow while you learn (and document!) how all the pieces fit together. If you can check all of those boxes with a smile then good luck and godspeed says I.


  • You’ve fundamentally misunderstood this. Upholding Constitutional law cannot undermine the democratic process which it establishes.

    If I win a game by breaking its rules I am de-facto disqualified from that victory. Yes, all law is written by people, can be unmade by people, and is only in effect so long as we collectively agree to enforce it, however; if the law is not unmade and if we collectively sigh in apathy at its violation then we are no longer playing the game the rules have defined.

    This is the immense danger of the current Constitutional crisis. If there is no enforcement of the rules set forth in a government’s founding document then it can no longer be recognized as the body which that document defines.


  • I do. Thanks. You’re still focused on the wrong thing here.

    Section 3 of the 14th Amendment does not require any specific test which defines “insurrection”. The impeachment is a useful anchor for establishing an agreement that an insurrection did occur and that Trump was, at the very least, an active participant in that insurrection.

    The Insurrection Bar to Office: Section 3 of the Fourteenth Amendment (crsreports.congress.gov) provides an well crafted and neutral review of this. Its closing sentence is particularly relevant to our back and forth:

    Congress has previously viewed Section 3 of the Fourteenth Amendment as establishing an enumerated constitutional qualification for holding office and, consequently, a grounds for possible exclusion.

    Republican strategy has long revolved around the targeted devolution of norms. They hide in the cracks between definitions which assume good faith participation in the labor of mutually consensual governance and shield themselves in perpetual faux-victimhood. If Congress does not pursue the execution of Section 3 it is nothing less than an abdication of their duty to their Oath of Office.

    Your last paragraph is a result of misunderstandings and assumptions on your part.





  • It’s not too late. The 14th amendment Section 3 specifically prohibits an insurrectionist from holding public office unless a special Congressional vote is held and passes with a 2/3rds majority.

    Section 3. No person shall be a Senator or Representative in Congress, or elector of President and Vice President, or hold any office, civil or military, under the United States, or under any State, who, having previously taken an oath, as a member of Congress, or as an officer of the United States, or as a member of any State legislature, or as an executive or judicial officer of any State, to support the Constitution of the United States, shall have engaged in insurrection or rebellion against the same, or given aid or comfort to the enemies thereof. But Congress may, by a vote of two-thirds of each House, remove such disability.

    All US citizens should call their representatives and demand they uphold their sworn Constitutional duty to refuse the certification of Donald Trump’s victory as he is disqualified from holding office.

    This is not speculation. Donald Trump was successfully impeached for inciting insurrection. The US is in the middle of a Constitutional crisis which Congress must resolve.

    Finding your reps is easy. Go here:

    https://www.congress.gov/members/find-your-member

    Either let the site use your location or enter your home address. It’ll pull all the info you need in one click.




  • I have a deep appreciation for this level of discernment. Moderating posts and their discussions in good-faith and abiding by the spirit/intention of the rules instead of strict enforcement by letter fosters community trust and makes it more difficult to argue against removals/bans when they do happen.

    Thanks for volunteering and keeping the lights on.