Cockpit, to wireguard
@Cockpit@fosstodon.org avatar

#Cockpit 301 has been released!

#WireGuard #VPN support is now available on the Network page!

Network devices on the metrics page are now links.

https://cockpit-project.org/blog/cockpit-301.html

#Linux #server #UI

tek_dmn, to selfhosted
@tek_dmn@mastodon.tekdmn.me avatar

Okay nerds, it's #selfhosted #authentication #askFedi time.

I'm about to move a few parts of my network off-site. Anyone have any input for getting LDAP-based authentication to work across locations?

Like, LDAP+TLS with mutual certificate authentication is just fine, but I don't like the idea of exposing an LDAP port. Though a firewall rule to only allow the other side's IP to access it would probably be okay.

Given that this side still needs to access some internal services, it also makes sense just to #WireGuard it or something, that gives me everything in a manner that I believe is secure, I've yet to hear of any breaks on its encryption... just that if the remote host is compromised I have quite a wide open attack surface.

Any ideas?

#askFediverse #networking #networkSecurity

vazub, to MullvadVPN
@vazub@mastodon.online avatar

To my German friends. If you use a combination of #FritzBox router, #Vodafone ISP and #MullvadVPN - meaning you are trying to set up #Wireguard on the router itself - be wary, that this setup is known to leak your IPv6 address. On the other hand, if you use Mullvad VPN App on your OS, everything works fine. Not sure who to blame here specifically, but this has been a disturbing revelation to me. Be careful.

housepanther, to wireguard

TIL that #WireGuard essentially uses two different routing tables to make network routing decisions: it's own the the kernel's. Since I wasn't really aware of this, I got tripped up. The AllowedIPs config parameter creates entries in the kernel routing table and it also governs what traffic WireGuard will route. I used to think I was pretty good with it. Today, I ate humble pie.

housepanther, to wireguard

#wireguard is pissing me off. The peers can ping and communicate with the server but not each other. I've got no idea why . #linux

reginagrogan, to privacy
@reginagrogan@mastodon.social avatar

I feel like we are living in ad world and its sickening. 2049 style.

Uber? Ads
Plane? Ads
Watch a movie? Ads
Tiktok? Ads
Smart tv in home? Ads
Alexa? Ads

Its enough. Its a violation of our boundaries. Sick of it. And sick of breaches caused by selling data. #privacy #security

What are some ideas to stop ad proliferation?

d1sc,
@d1sc@social.tchncs.de avatar

@reginagrogan use #pihole or #adguard at home and #WireGuard with VPN on demand on your mobile and yes i hate ads, too 🙈👍 #privacy

Wander, to privacy
@Wander@packmates.org avatar

Federated wireguard network idea
Any feedback welcome.

Let's keep things stupidly simple and simply hash the domain name to get a unique IPv6 ULA prefix.

Then we would need a stupidly simple backend application to automatically fetch pubkeys and endpoints from DNS and make a request to add each others as peers.

Et voilà, you got a worldwide federated wireguard network resolving private ULA addresses. Sort of an internet on top of the internet .

The DNS entries with the public IPv4 / IPv6 addresses could even be delegated to other domains / endpoints which would act as reverse proxy (either routing or nesting tunnels) for further privacy.

Maybe my approach is too naïve and there are flaws I haven't considered, so don't be afraid to comment.

Exact use cases? Idk, but it sounds nifty.

cc: @fediverse

kuketzblog, to security German
@kuketzblog@social.tchncs.de avatar

Noch ist die Informationslage dünn, aber alle die können, sollten auf ihrer Fritz!Box das aktuell veröffentlichte Update FRITZ.OS 7.57 (7.31) einspielen. Offenbar hat AVM eine (schwerwiegende) Sicherheitslücke gefixt.

Lars_Roskoden,
@Lars_Roskoden@machteburch.social avatar

@kuketzblog
Dankeschön. An dieser Stelle auch mal die Frage, ob mit dem nun möglichen #wireguard auch der zweite Teil Deines #nextcloudpi-Artikels veröffentlicht werden kann ;)

sonny, (edited ) to linux
@sonny@floss.social avatar

GNOME is shaping up really nicely for privacy

• Background App indicator
• App permissions
• Device Security Settings
• Mic / Camera* indicators
• Screen Sharing indicator
• Remote Desktop indicator
• Location indicator
• Incrementally better app sandboxing
• VPN (incl Wireguard) support
• Quick Network Toggles

Made possible by and our talented community.

  • Available in the upcoming GNOME 45 release
chfkch,
@chfkch@ruhr.social avatar

@sonny
App permissions like #AppArmor or something? Sounds interesting.
Very much needed for #MobileLinux aswell.

#Flatpak #Wayland #PipeWire #Linux #privacy #WireGuard #VPN #LinuxMobile

Linux_Is_Best, to debian

Surf Shark VPN on Debian (Mx Linux) has the annoying policy of wanting to install the latest Linux Kernel.

But I already have Liquorix Kernel (and XanMod).

I do not need Debian's older kernel for Wire Guard modules.

The solution:

sudo apt-get download surfshark

sudo dpkg --force-all -i FILE_NAME.deb

Reboot

It works just fine

(Just be sure to replace File_Name with the actual name of the file it downloaded)

#Debian #MxLinux #SurfSharkVPN #LinuxKernel #Kernel #Linux #WireGuard #VPN

Decentralize, to wireguard
@Decentralize@dt.gl avatar

#Rethinkdns has now built in #wireguard, firewall, dns and vpn in one app! #Android #fdroid

geo, to wireguard
@geo@mastodon.scot avatar

Been digesting the earlier meeting with Scottish Water on CSO activities and what the plan is going forward for the Water of Leith.

Before I write about that, I’m going to mention here that I had an ace evening reading about home networking, , and .

My PiHole has been running super well filtering out good stuff. Just got a VPN setup through it too - and it worked on the first try.

Feeling rather accomplished today, it gonna lie.

tristan, to wireguard

I know I've been talking a lot about Tailscale recently, but this is important enough to involve another mention - the latest version of Tailscale in the app store now supports VPN On Demand, a feature that let's you inform iOS when the VPN should and should not be activated, including whitelisting or blacklisting wifi networks. This was the final feature that Tailscale was lacking that vanilla Wireguard for iOS has had for a very long time. https://tailscale.com/kb/1291/ios-vpn-on-demand/
#Tailscale #wireguard

geerlingguy, to random
@geerlingguy@mastodon.social avatar
hanscees,

@geerlingguy And now try #wireguard?

abcdw, to guix
@abcdw@fosstodon.org avatar

A quick and practical WireGuard in Guix stream:

https://youtu.be/d02Ysd8bNso

techsaviours, to wireguard

#WireGuard joins our wiki

It also means that the #wiki or your digital #privacy have a good #base to start with. There will always be something, more or maybe even less for you. Other operating systems or just other services/apps that others or you prefer instead. And that's fine, we all even have options to choose from and don't have to rely only on #Microsoft & Co.

#Server: https://wiki.techsaviours.org/en/server/services/wireguard

#Phone: https://wiki.techsaviours.org/en/phone/apps/wireguard

#Desktop: https://wiki.techsaviours.org/en/desktop/services/wireguard

#german will follow

HF

stefano, to fediverse
@stefano@bsd.cafe avatar

Friends of #BSDCafe and the #Fediverse,
I want to share a funny incident that happened yesterday. A client called me, a bit annoyed, because they received a security report stating that their firewall is not secure.
Their firewall is a perfectly updated #OpenBSD machine, responsible for NAT from the internal LAN to the outside and only allowing an incoming #wireguard connection.
So, I asked them to send me the report. A lot of words were used to say that they detected the use of #Linux 2.6 and thus deemed it insecure.

How they came up with detecting Linux 2.6, I have no idea. I responded - I'll be curious to see their response in turn.

#SecurityReport #ITHumor #ClientInteractions

jmhorner, to philosophy
@jmhorner@eattherich.club avatar

So, at home I have a laptop with a 4TB magnetic 2.5" external USB drive, which has a bunch of #western movies on it. This laptop has #nginx web server installed on it which allows access to the westerns. It also has #wireguard which is connected to a #vps I have in the US somewhere (not bragging, just saying). The connection at home is a 6Mbit/800k residential DSL line. Right now I am in the woods nowhere near home on another laptop, which is connected to my cell phone via hotspot, and which also has Wireguard connected to the same VPS. Through this VPN I am currently watching tonight's western. The Cariboo Trail [1950]

https://www.themoviedb.org/movie/215453-the-cariboo-trail

"A cattleman fights to establish a ranch in the middle of gold country."

iamdtms, to mastodon
@iamdtms@mas.to avatar

Best RSS reader:
Best desktop client: @elk
Best audio service:
Best Browser: @brave
Best VPN: @protonvpn
Best code editor:
Best file transfer client:
Best gaming platform:

What's in your best list?

penticore,

@iamdtms @elk @brave @protonvpn

Best RSS reader: #reeder
Best desktop #Mastodon client: @icecubes
Best audio service: #spotify
Best Browser: #firefox
Best VPN: #wireguard
Best code editor: #limetext
Best file transfer client: #openssh
Best gaming platform: #playstation

What's in your best list?

ashed, to infosec Russian
@ashed@mastodon.ml avatar

Для любителей однокнопочных настроек безопасности

#infosec #security #censorship_bypass

https://github.com/anticensority/runet-censorship-bypass/wiki

ashed,
@ashed@mastodon.ml avatar

Wireguard и авиарежим

#wireguard #censorship_bypass #infosec #information_security #network #tunnel

Если вы всё ещё используете wireguard туннелирование, то пора уже задуматься в переходе на более продвинутые вещи (Shadowsocks, Vless, Vmess).
Тучи сгущаются и опыт "китайских товарищей" перенимается
Роскомпозором семимильными шагами.

У Wireguard инициализацию соединения давит ТСПУ (Техническое Средство противодействия угрозам). Ваш провайдер интеренета доступа к их потрохам не имеет. Примитивный и пока рабочий способ расшевелить Wireguard - включить и выключить авиарежим в смартфоне, и туннель должен заработать. Смартфон считает что wg туннель жив и не инициализирует его заново, а для ТСПУ (железок РКН) после этого просто летает какой-то трафик по Х/udp, не поддающийся анализу и блокировке.

Способ временный, имейте в виду. Денег этим упырям подвезли пару камазов.

Время уходит.
Настройка клиента ShadowSocks+v2ray
Пошаговая инструкция
https://myvpn.run/support/shadowsocks-v2ray

meesj, to RaspberryPi

I'm looking for a router software that offers:

Any recommendations?

paulknightly, to random
@paulknightly@mstdn.social avatar

deleted_by_author

  • Loading...
  • abimelechbeutelbilch,

    @ohiorob @paulknightly
    For those technicans that are interested what can be achieved by the Power of and a on all (mobile/wired) devices everywhere you go…
    I've documented my setup for my "privacy to go" on GitHub:
    https://thomasmerz.github.io/pihole-wireguard-knowhow/

    animemer, to random

    hey, in a debate with @thecatcollective

    over parents being delusional,

    can you list any open source software that has become the industry standard, so far i got

    • obs- video-streaming
    • android
    • Linux and BSD on servers
    • both chrome and firefox are
      based on open source
    kkarhan,

    @animemer @thecatcollective

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • everett
  • osvaldo12
  • magazineikmin
  • thenastyranch
  • rosin
  • normalnudes
  • Youngstown
  • Durango
  • slotface
  • ngwrru68w68
  • kavyap
  • DreamBathrooms
  • tester
  • InstantRegret
  • ethstaker
  • GTA5RPClips
  • tacticalgear
  • Leos
  • anitta
  • modclub
  • khanakhh
  • cubers
  • cisconetworking
  • megavids
  • provamag3
  • lostlight
  • All magazines