• 1 Post
  • 82 Comments
Joined 3 years ago
cake
Cake day: July 19th, 2023

help-circle








  • Personal privacy is a right. If someone commits a crime and the equivalent of a warrant is issued that data becomes evidence and it becomes your job to discover what’s on the devices.

    Jobs like these exist in that balance between privacy and justice. A judge or however your justice system works has said that the potential crimes that person has committed justifies waving that person’s right to privacy in the same way as searching a home.

    Your job and scope is narrow and you should take that seriously but would you rather someone who doesn’t respect privacy (e.g. a department inside the police force) does this job?

    For the tools, those are the industry standards. they’re just tools and yes they’ve been abused but they or tools like them are necessary to do that job.









  • I’m not entirely sure about the technical differences but from my understanding VPN connections are preferred. From a security perspective, ssh has some more considerations since it’s easier to detect it’s open, and you should lock down root access and other privileged accounts. but SSH seems simpler to actually get working vs a VPN solution which would probably require a reverse proxy or something to get the TV working.

    For example, compromising a ssh service gives you access to the shell immediately vs wireguard or similar that historically (from my knowledge) has had fewer critical vulnerabilities that could lead to remote code injection or access. This is also why many corporate and best practices recommend layering ssh through a private VPN like IPsec, OpenVPN, wireguard, etc.

    in practice it’s most likely fine as long as

    • you don’t use root or an account with sudo to do the ssh forwarding
    • require a ssh key for all connections (at minimum any remote/internet connections)
    • update the system regularly. you can automate security updates with unattended upgrades on debian-based systems.

  • Are you connecting from a public network or something? like a hotel wifi or other?

    The easiest solution would be to setup the pi as your router and use a VPN like wireguard (wg-easy) or tailscale.

    if it is a public network, you can double NAT. There’s dedicated boxes like the GL.inet travel routers that support wireguard/openVPN and beta for tailscale. they have some features that work well with captive portals.

    If it’s a home network, you can probably use your PI as a entry/exit node or VPN client instead of using ssh.


  • wireguard is self hosted and you do have to “expose” one UDP port. From the outside it’s difficult to detect that this “opening” exists because wireguard just listens and ignores everything unless you send the encrypted credentials. Compared to hosting a webpage or jellyfin directly this is much more secure. As long as you keep wireguard relatively up to date you don’t really have to worry much about it.

    I personally use wg-easy. It’s designed to be deployed into docker (using docker compose is by far the easiest).

    Then you can either use your IP address, or ideally a dynamic DNS provider so you’d connect to myexample.com:51820. Duckdns is free, otherwise options are available like cloudflare. If you can get jellyfin working, this should be relatively straightforward.



  • I recently had to increase my proxmox storage as well from an old 256 to 1TB. What I did was make a copy of /etc via PVE Host Backup and saved that on my NAS/external storage. Almost everything is in /etc/pve. Then I created backups of all the VMs and stored those on the same external storage. I then installed proxmox as normal and compared configs between backup and new configs then restored VMs from backup. The reason I did it this way is because 1) I had installed proxmox a while ago and new config > old config for stability after adding some necessary PVE scripts (e.g. intel chip, and 2) I’ve had weird issues before cloning drives and a fresh install was easier than risking some weird edge case troubleshooting. It also let me keep the old SSD as a backup in case something went wrong.

    Edit: Also recommend going with zfs mirrored on the new install during the setup: target disks options and zfs mirrored. ZFS offers some benefits vs the default lvm.